<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;C0UCQ3w_cSp7ImA9WhRVEkg.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938</id><updated>2012-01-11T14:07:42.249+11:00</updated><category term="pen test" /><category term="logging" /><category term="What's up" /><category term="clustering" /><category term="TTL" /><category term="Freedom" /><category term="Official CHFI Study Guide" /><category term="choasreader" /><category term="malware" /><category term="Misc" /><category term="Windows" /><category term="hping" /><category term="Exam 312-49" /><category term="cookie" /><category term="Private Investigator" /><category term="perception" /><category term="Code" /><category term="TCP" /><category term="GREP" /><category term="RFC791" /><category term="Sunday" /><category term="Text data mining" /><category term="University" /><category term="spam" /><category term="PI" /><category term="PhD" /><category term="lies" /><category term="email" /><category term="Certifications" /><category term="training" /><category term="W^X" /><category term="signitures" /><category term="IPv6" /><category term="virtue" /><category term="Nature" /><category term="attack" /><category term="TTCP" /><category term="mitm" /><category term="Network Address Translation" /><category term="Bayesian" /><category term="Benford's Law" /><category term="inflation" /><category term="rants" /><category term="Enthymeme" /><category term="GSE" /><category term="Exploiting" /><category term="experiment" /><category term="Arp" /><category term="networking" /><category term="NAT" /><category term="Forensic Investigations" /><category term="Bayes" /><category term="VoIP" /><category term="Assembly" /><category term="Quantification" /><category term="UCP 500" /><category term="power" /><category term="worm" /><category term="posts" /><category term="cattle" /><category term="corporations act" /><category term="ettercap" /><category term="hazard" /><category term="Qualitative research" /><category term="figure" /><category term="Bind" /><category term="cooking" /><category term="Unix" /><category term="NTFS" /><category term="education" /><category term="tcpdump" /><category term="podcast" /><category term="Microsoft" /><category term="ngrep" /><category term="IDS" /><category term="FUD" /><category term="Statistics" /><category term="Lisarow" /><category term="Consulting" /><category term="DaaS" /><category term="christmas" /><category term="Survey" /><category term="hacking" /><category term="web bugs" /><category term="wine" /><category term="Egress" /><category term="Naughty" /><category term="leadership" /><category term="vulnerability test" /><category term="Psychology" /><category term="grammar" /><category term="ISP" /><category term="BPF" /><category term="tau" /><category term="shell" /><category term="licensing" /><category term="digital certificates" /><category term="new year" /><category term="farm kangaroo" /><category term="SSL" /><category term="Routing" /><category term="firewall" /><category term="Risk" /><category term="India" /><category term="balance of payments" /><category term="splog" /><category term="Records" /><category term="paper" /><category term="Network" /><category term="other" /><category term="Updates" /><category term="CHFI" /><category term="Webinar" /><category term="giving" /><category term="Merchants" /><category term="SAM" /><category term="thanks" /><category term="alware" /><category term="ssh" /><category term="Chomsky" /><category term="Exploit" /><category term="a break" /><category term="Google" /><category term="AUSCERT" /><category term="company" /><category term="sudo" /><category term="plagiarism" /><category term="Checkpoint" /><category term="compliance" /><category term="DoS" /><category term="defamation" /><category term="vpn" /><category term="standards" /><category term="IP ID" /><category term="Australian Computer Crime and Security Survey" /><category term="CSU" /><category term="writing" /><category term="BIAS" /><category term="filtering" /><category term="NX" /><category term="Tooting one's own" /><category term="shovelling" /><category term="DNS" /><category term="data mining" /><category term="General Rant" /><category term="SQL" /><category term="PII" /><category term="cache poisoning" /><category term="web" /><category term="Emergence" /><category term="senses" /><category term="robustness" /><category term="game theory" /><category term="reward" /><category term="Digital Forensics" /><category term="Google Dork" /><category term="stupidity" /><category term="survival" /><category term="HTTP" /><category term="PCI-DSS" /><category term="UDP" /><category term="Travel" /><category term="Source routing" /><category term="Fraud" /><category term="keyboard" /><category term="IP" /><category term="HR" /><category term="Entropy" /><category term="PaX" /><category term="SCADA" /><category term="review" /><category term="Ingress" /><category term="News" /><category term="horse" /><category term="mafia" /><category term="Cross-site scripting" /><category term="security" /><category term="SANS" /><category term="cloud" /><category term="scan" /><category term="forensics" /><category term="Farm" /><category term="scanning" /><category term="coding" /><category term="dnstop" /><category term="ITE513" /><category term="XSS" /><category term="pet" /><category term="meterpreter" /><category term="mind" /><category term="Wireless" /><category term="RHEL" /><category term="trust" /><category term="risk analysis" /><category term="honeynet" /><category term="Charles Sturt University" /><category term="passwords" /><category term="IT" /><category term="Netdude" /><category term="Awareness" /><category term="Breakfast" /><category term="ediscovery" /><category term="corporate social responsibility" /><category term="Information Security" /><category term="Buffer Overflow" /><category term="RPC" /><category term="DD" /><category term="misleading" /><category term="Legals" /><category term="Anon" /><category term="browsers" /><category term="postal rule" /><category term="commands" /><category term="SMTP" /><category term="LINUX" /><category term="crime" /><category term="false representations" /><category term="Text mining" /><category term="Food" /><category term="script" /><category term="WLAN" /><category term="Software" /><category term="honeypot" /><category term="Book" /><category term="DATs" /><category term="database" /><category term="Retail" /><category term="thematic" /><category term="Anti-forensic" /><category term="PCI" /><category term="DF" /><category term="Internet" /><category term="consult" /><category term="law" /><category term="Music" /><category term="programming" /><category term="nmap" /><category term="IS" /><category term="syslog" /><category term="Loki" /><category term="pipeline" /><category term="monitoring" /><category term="Induction" /><category term="audit" /><category term="ICMP" /><category term="weekend" /><category term="LSOF" /><category term="Data Security" /><category term="stack" /><category term="Maths" /><category term="Echidna" /><category term="economics" /><category term="hacks" /><category term="Bagnoo" /><category term="flame" /><category term="Garden" /><category term="nc" /><category term="data" /><category term="Finance and Trade law" /><category term="Integyrs" /><category term="netcat" /><title>Cracked, inSecure and Generally Broken</title><subtitle type="html">The ravings of a SANS/GIAC GSE (Compliance &amp;amp; Malware)

For more information on my role as a presenter and commentator on IT Security, Digital Forensics Statistics and Data Mining; 
E-mail me: &amp;quot;craigswright @ acm.org&amp;quot;.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://gse-compliance.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>667</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/CrackedInsecureAndGenerallyBroken" /><feedburner:info uri="crackedinsecureandgenerallybroken" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;C0UCQ3w-fyp7ImA9WhRVEkg.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-3025983494004648204</id><published>2012-01-11T14:07:00.001+11:00</published><updated>2012-01-11T14:07:42.257+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-11T14:07:42.257+11:00</app:edited><title>Starting Metasploit</title><content type="html">&lt;p&gt;Well, we have installed Metasploit and now we need to start configuring it to run.&lt;/p&gt;  &lt;p&gt;First, as we have created a self-signed certificate, it is necessary to accept the validity of it. If you do not like this you can add the cert to the browsers list of trusted certs, but that is something for another time.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Click “Yes” to continue.&lt;/p&gt;  &lt;p&gt;From here we will need to setup a new user (at least one).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You can see I have filled this into the form displayed in the image above. What matters is that you have a username and password that you will remember and not forget. Also, the “&lt;em&gt;Password confirmation must contain letters, numbers, and at least one special character&lt;/em&gt;”.&lt;/p&gt;  &lt;p&gt;If you have a personal firewall and anti-virus – you may have to disable them. At the least it is likely that you will have a hard time configuring all of the exceptions. This is why using a distro is a good idea. &lt;/p&gt;  &lt;p&gt;Click “&lt;em&gt;Create Account&lt;/em&gt;” on the lower right hand side of the screen and move onto registering and Activating Metasploit&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Clicking “&lt;em&gt;Register your Metasploit license here!”&lt;/em&gt; will take you to the “Rapid7” website where you can select either the free (community) or commercial (Metasploit Pro) version. We will be using the free version for this exercise.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Enter your email and click “Go” to continue. A Product Key will be sent in email.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Enter the product key into the website and click on the “Next”tab:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Click “Activate License” to load the new license and start using Metasploit.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You will see below that we are redirected to our local instance.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Also notice that the product is activated as it displays “Activation Successful”.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;New Project&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;We are now ready to start exploiting systems. Let us start by clicking “New Project” and setting up the project we wish to run.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;After filling out the details, we are ready to start with clicking “Create Project”:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Tomorrow we will continue this with scanning and selecting a system to exploit. If you already know that a system exists (such as from the results of a Nessus scan) with a potential vulnerability, we can use Metasploit to validate it.&lt;/p&gt;  &lt;p&gt;This is important. Unless you have the time and money to fix ALL vulnerabilities found using a vulnerability scanner (such as OpenVAS or Nessus) it will be essential that you priorities the findings based on risk. This means you will need to validate the potential vulnerabilities discovered. This is what Metasploit does.&lt;/p&gt;  &lt;p&gt;It is difficult to argue if an exploit can occur or not once you have a video of breaking into the site. It also allows you to show just how Easy/Hard a particular exploit would be.&lt;/p&gt;  &lt;p&gt;The process is a four (4) step one and will incorporate the following:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Select the platform or application that you seek to exploit &lt;/li&gt;    &lt;li&gt;Select the exploit to use &lt;/li&gt;    &lt;li&gt;Select the payload (shellcode or other) &lt;/li&gt;    &lt;li&gt;Run and load the exploit&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Tomorrow we will run the scan and actually break into a system.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-3025983494004648204?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DKNa7yD5OEYG5x15OQ6xy-iig3M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DKNa7yD5OEYG5x15OQ6xy-iig3M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DKNa7yD5OEYG5x15OQ6xy-iig3M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DKNa7yD5OEYG5x15OQ6xy-iig3M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/LS9nKQHOSIs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/3025983494004648204/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=3025983494004648204" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/3025983494004648204?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/3025983494004648204?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/LS9nKQHOSIs/starting-metasploit.html" title="Starting Metasploit" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/starting-metasploit.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4DQXs_cSp7ImA9WhRVEkk.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-5903868212758391877</id><published>2012-01-11T13:24:00.001+11:00</published><updated>2012-01-11T13:29:30.549+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-11T13:29:30.549+11:00</app:edited><title>'Character Assassination attempt?'</title><content type="html">&lt;p&gt;I have seen a few posts talking about the issue in “&lt;a href="http://securityerrata.org/errata/plagiarism/it_regulatory_standards_compliance_handbook.html"&gt;attrition.org&lt;/a&gt;” as if it was an attempt at Character assassination.&lt;/p&gt;  &lt;p&gt;Honestly, what they are doing is important. I would have liked to have been contacted and given an opportunity to respond first, but this is something we all have to live with. Having come back from vacation to find the twit and the page was not something I enjoyed, but the reality is that I screwed up.&lt;/p&gt;  &lt;p&gt;I trusted too much in technology for a start, this is always an issue with me. I ASSUMED that turnitin and other checking tools would have worked more effectively. I am not too happy with them right now.&lt;/p&gt;  &lt;p&gt;Mostly, I am humbled by my stupid error. &lt;/p&gt;  &lt;p&gt;I do forensic work and I practice in an industry that requires care. The fact of the matter is that whether I was not intentionally doing the copy without permission is not the issue for me. I asked for permission from the wrong person and this is not something I am happy with. It is negligence and displays a lack of due care on my part.&lt;/p&gt;  &lt;p&gt;Having received permission from a person (inadvertently on his part as he also runs an XSS site) who has no authority over the material is a mistake I would not be happy from had an intern done it. &lt;/p&gt;  &lt;p&gt;The matter remains that I did use material without permission whether I did this intentionally or not (and I did not intentionally want to do this).&lt;/p&gt;  &lt;p&gt;The fact that I only just got the error after running about self-righteously thinking that I had permission was compounded on receiving a reply stating: “&lt;em&gt;Robert Auger, not Robert Hansen, is the author of the XSS FAQ&lt;/em&gt;.”&lt;/p&gt;  &lt;p&gt;It has been four (4) years and I have only just got this. It is my error and I will do my best to be humbled by it and to learn from it, but it is my error and I will live with it. I will still write and post and the other things I have planned for this year will go ahead, but I will also ensure that I take more care in checking these things in future.&lt;/p&gt;  &lt;p&gt;I will post more tomorrow, but for today, I actually need to do work. I am teaching tonight and need to make sure the lecture is prepared and to also get a few articles I am writing checked.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-5903868212758391877?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0BpNOLnyAkJrtQ6aFst2G989AaM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0BpNOLnyAkJrtQ6aFst2G989AaM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0BpNOLnyAkJrtQ6aFst2G989AaM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0BpNOLnyAkJrtQ6aFst2G989AaM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/m0xLetzekQg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/5903868212758391877/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=5903868212758391877" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/5903868212758391877?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/5903868212758391877?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/m0xLetzekQg/assassination-attempt.html" title="&amp;#39;Character Assassination attempt?&amp;#39;" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/assassination-attempt.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4GRX04fSp7ImA9WhRVEUo.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-4320732244252193955</id><published>2012-01-10T17:45:00.001+11:00</published><updated>2012-01-10T17:45:24.335+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T17:45:24.335+11:00</app:edited><title>Dumb thing for the decade.</title><content type="html">&lt;p&gt;Well, I have just realized I have made a really STUPID mistake.&lt;/p&gt;  &lt;p&gt;Well not just, but in 2008.&lt;/p&gt;  &lt;p&gt;Back then as I was rushing to complete a book, I asked a few people for permission to use material in a book. I sent an email to &lt;a href="mailto:&amp;ldquo;h@ckers.org"&gt;“h@ckers.org&lt;/a&gt;” and rsnake for XSS stuff I used. I have just had it pointed out to me that Robert Auger, and not Robert Hansen is the author of the XSS FAQ. I should have know this and more I SHOULD HAVE CHECKED!&lt;/p&gt;  &lt;p&gt;I asked Robert to use material from his XSS page but I did not ask both Robert’s and screwed up mixing the two people. I have to apologize to both Roberts for this.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;For this I ask forgiveness and offer a sincere apology.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;It just goes to show that even education does not stop stupidity. This is a true case of stupidity on my part and I am humbled by it. &lt;/p&gt;  &lt;p&gt;I do hope that people understand that this was not intentional and I do make &lt;strong&gt;stupid&lt;/strong&gt; mistakes. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-4320732244252193955?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gnIqMNqExbH3d8Yvaz_0DkqewrA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gnIqMNqExbH3d8Yvaz_0DkqewrA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gnIqMNqExbH3d8Yvaz_0DkqewrA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gnIqMNqExbH3d8Yvaz_0DkqewrA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/Yc5UoO2QM4Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/4320732244252193955/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=4320732244252193955" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4320732244252193955?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4320732244252193955?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/Yc5UoO2QM4Q/dumb-thing-for-decade.html" title="Dumb thing for the decade." /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/dumb-thing-for-decade.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUcGRXg9eCp7ImA9WhRVEUo.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-7271686755589426772</id><published>2012-01-10T17:30:00.001+11:00</published><updated>2012-01-10T17:30:24.660+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T17:30:24.660+11:00</app:edited><title>Installing Metasploit on Windows</title><content type="html">&lt;p&gt;Ok, we have downloaded the installer.&lt;/p&gt;  &lt;p&gt;Now, find where it has been saved and right click on it.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-0umydiAAD9A/Twvah-99YdI/AAAAAAAAGIM/Dq39tpI4ITs/s1600-h/image%25255B2%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-As9txKveWNE/TwvaiwHrroI/AAAAAAAAGIU/t9pRzfKAdnE/image_thumb.png?imgmax=800" width="244" height="53" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Run this as Administrator. Without, many things will not work. Do the normal bit to accept this and then you will come up with the install banner:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-htRPTcYcIhc/Twvaj3k5KjI/AAAAAAAAGIc/I4ZpMEzT7mI/s1600-h/image%25255B8%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-LWylhJOTGxw/TwvalOqDr2I/AAAAAAAAGIk/Rg01_iYYJZ8/image_thumb%25255B2%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Click next and accept the agreement:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-804FpRLNWGY/TwvamU0zIHI/AAAAAAAAGIs/y3Hm_KvO9eU/s1600-h/image%25255B11%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-gTBnnDAFhsg/TwvanTEWbqI/AAAAAAAAGI0/BYdclR2ILQM/image_thumb%25255B3%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Select the location to install this:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-B8nRUjYyEOw/Twvao0VrB4I/AAAAAAAAGI8/NNhq_wLEhsE/s1600-h/image%25255B14%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-IrFg93iBqoQ/Twvap_TH7lI/AAAAAAAAGJE/xMORif0ohcY/image_thumb%25255B4%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Select the port to run Metasploit on:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-qHo-mQ6UTt0/Twvaq9-KiuI/AAAAAAAAGJM/wAvQ21lIFLk/s1600-h/image%25255B17%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-kikDvrNRAtU/TwvasHQb6_I/AAAAAAAAGJU/tstSDd56lUE/image_thumb%25255B5%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Generate an SSL cert:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-r0syjW9bhXA/TwvatDr6sZI/AAAAAAAAGJc/xlCwT_KVoqk/s1600-h/image%25255B20%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-ugZ7CI2dE30/TwvauID9G8I/AAAAAAAAGJk/kEZnH6ucrYo/image_thumb%25255B6%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Then leave it as default as allow it to update:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-zY1BC4_iGYw/TwvavesRgJI/AAAAAAAAGJs/70-nV3qZYx8/s1600-h/image%25255B23%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-xNc9bRYoq2c/TwvawukM5JI/AAAAAAAAGJ0/PHVaXK1hjXk/image_thumb%25255B7%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And we are ready to install by clicking “Next”:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-_vt8TL_aM-M/Twvax8gpXNI/AAAAAAAAGJ8/Ad_tE-hqJAM/s1600-h/image%25255B26%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-JUK8uY0Lrw4/Twvay9z5mtI/AAAAAAAAGKE/mSbFPqaNmko/image_thumb%25255B8%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Make a coffee as it installs:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-TW2_2wtcTOY/TwvazzrdNsI/AAAAAAAAGKM/OJ0fGTrVN5s/s1600-h/image%25255B29%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-jL19cbHDu4o/Twva05NI8rI/AAAAAAAAGKU/nzEcapyfcR8/image_thumb%25255B9%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;You should also check that the files are not being stopped by your Anti-Virus program:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-SfI_ngp8KGg/Twva2FhVffI/AAAAAAAAGKc/cRjc_dOxkPU/s1600-h/image%25255B32%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-RZBY6ua2Sh8/Twva3QTis2I/AAAAAAAAGKk/lLtM4IdS9s8/image_thumb%25255B10%25255D.png?imgmax=800" width="244" height="155" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Well it is installed:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/--ymSQZEGdJk/Twva4Utr3JI/AAAAAAAAGKs/KBkPp6K-9TA/s1600-h/image%25255B35%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-EsFuu9GAMHE/Twva5jc8MEI/AAAAAAAAGK0/PdxJlQBAhjE/image_thumb%25255B11%25255D.png?imgmax=800" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Let us click “Finish” and run it.&lt;/p&gt;  &lt;p&gt;Click &lt;strong&gt;Start –&amp;gt; Run&lt;/strong&gt; and select the console (“Metasploit Console”):&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-eYotl21vTas/Twva6hIbpxI/AAAAAAAAGK8/v2NMcmMz0Og/s1600-h/image%25255B38%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-LpuJnOgOvUQ/Twva8QQdHlI/AAAAAAAAGLE/Psx1g42UuqA/image_thumb%25255B12%25255D.png?imgmax=800" width="160" height="244" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;From the console we have the start of our CLI:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-Ni7fcdlx6pQ/Twva9lQ491I/AAAAAAAAGLM/5vr2NeInYw0/s1600-h/image%25255B42%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-_An0jUpPXPM/Twva-gbj_XI/AAAAAAAAGLU/vE-D8c9MabQ/image_thumb%25255B14%25255D.png?imgmax=800" width="372" height="298" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Tomorrow we go through using it.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Some Specs:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;There are a number of &lt;a href="https://community.rapid7.com/message/1346#1346"&gt;specifications&lt;/a&gt; on the Metasploit site for the current Windows version. I would take these with a grain of salt. Like all developer specs, they relate mildly to a base install and a slow run. I would personally say the following as a minimum:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;2.8 GHz+ processor &lt;/li&gt;    &lt;li&gt;4 GB RAM&amp;#160; (If there are any VM targets on the same device just keep adding RAM) &lt;/li&gt;    &lt;li&gt;500MB+ available disk space &lt;/li&gt;    &lt;li&gt;100 Mbps/ 1 Gbps network interface card (add wireless for tests over wireless)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Less than this and it may run, but it is slow as a dog with a broken leg and it can crash making the process a waste of time.&lt;/p&gt;  &lt;p&gt;On top of this, I would change the systems to:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Windows XP SP2 or SP3,&lt;/li&gt;    &lt;li&gt;Windows 2003 Server, &lt;/li&gt;    &lt;li&gt;Windows Vista SP1 + (and 8 GB ram), &lt;/li&gt;    &lt;li&gt;Windows 2008 Server (with WAY more specs), and &lt;/li&gt;    &lt;li&gt;Windows 7 (make it 6 GB ram)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;In addition, you need to have a web browser. I would stick with one of the following (and prefer it not to be IE):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Mozilla Firefox 5.0+ &lt;/li&gt;    &lt;li&gt;Microsoft Internet Explorer 9 +&lt;/li&gt;    &lt;li&gt;Google Chrome 10+&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Tomorrow we will start to use Metasploit on a target.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-7271686755589426772?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oODAHEsDRD_pNcGq30AnHIGNDPU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oODAHEsDRD_pNcGq30AnHIGNDPU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oODAHEsDRD_pNcGq30AnHIGNDPU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oODAHEsDRD_pNcGq30AnHIGNDPU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/V82KLlnnGow" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/7271686755589426772/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=7271686755589426772" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/7271686755589426772?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/7271686755589426772?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/V82KLlnnGow/installing-metasploit-on-windows.html" title="Installing Metasploit on Windows" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh6.ggpht.com/-As9txKveWNE/TwvaiwHrroI/AAAAAAAAGIU/t9pRzfKAdnE/s72-c/image_thumb.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/installing-metasploit-on-windows.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMCSXk8fyp7ImA9WhRVEUo.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-8862618955605249687</id><published>2012-01-10T16:37:00.001+11:00</published><updated>2012-01-10T16:47:48.777+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T16:47:48.777+11:00</app:edited><title>More on what is plagiarism…</title><content type="html">&lt;p&gt;Today I will continue with checklists.&lt;/p&gt;  &lt;p&gt;T^his follows as a response to &lt;a href="http://securityerrata.org/errata/plagiarism/it_regulatory_standards_compliance_handbook.html"&gt;accusations that I plagiarized material&lt;/a&gt; in one of my books. &lt;/p&gt;  &lt;p&gt;I will look in particular at the section from the following pages.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;95 &lt;/li&gt;    &lt;li&gt;96 &lt;/li&gt;    &lt;li&gt;99 &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;This was attributed to &lt;strong&gt;Appendix 8A: Lan Audit Guide of &lt;/strong&gt;&lt;a href="http://www.amazon.com/Information-Technology-Audits-Xenia-Parker/dp/0808091840"&gt;&lt;strong&gt;Information Technology Audits&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;by &lt;strong&gt;Xenia Ley Parker&lt;/strong&gt; (June 15, 2007) in the &lt;a href="http://securityerrata.org/errata/plagiarism/it_regulatory_standards_compliance_handbook.html"&gt;Security Errata page&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;The reason, my book was published in 2008 (though I had already submitted this section in 2007). The section in Xena Parker’s book is not actually from that author in any event. There is an attribution from Xenia Ley Parker to JHU. These checklists do not start in 2007. They actually go back to the 90’s.&lt;/p&gt;  &lt;p&gt;I have uploaded a couple old DeMorgan documents (I am still searching the original ASX ones and will have these loaded as soon as I have found them). &lt;/p&gt;  &lt;p&gt;There are a couple for today:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a href="http://craigswright.podbean.com/2012/01/10/01-audit-definitions/"&gt;01 Audit definitions.pdf&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href="http://craigswright.podbean.com/2012/01/10/audit-manual/"&gt;Audit manual.pdf&lt;/a&gt; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;I have loaded and hyperlinked these documents above. &lt;/p&gt;  &lt;p&gt;Lucky for the &lt;a href="http://web.archive.org/web/20010517150028/http://www.demorgan.com.au/documents/nt-doco-index.html"&gt;wayback machine&lt;/a&gt;. The windows section was used as my submission to SANS for the Windows NT 4.0 security book. I will link this when I actually find it, but finding things from the 90’s, well it takes time (and I still have work as well strangely enough and an added 4-5 hours a day right now was not in my plan).&lt;/p&gt;  &lt;p&gt;The two manuals above became a DeMorgan template. I was only one of several people who worked to create these and they were edited to become FAR better by the others than I could have hoped for. &lt;/p&gt;  &lt;p&gt;In particular, I have to note the following people from the Australian Stock Exchange (and they are but a few of around 20 people involved in making those documents including others from outside the exchange and a few at PWC who also helped and Dave Maunsel who moved to Andersons to become an Andriod). &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Chris Fox &lt;/li&gt;    &lt;li&gt;Lesley Gear &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The original goes to 1996 with the majority of it in 1997.&lt;/p&gt;  &lt;p&gt;A real bugger for what I am being accused of plagiarizing as my document dates a decade before hers. Even used at BDO, this goes to 2005. Now, she has not plagiarized this, she has attributed the source she used. She attributed these to JHU (John Hopkins) which is also wrong. JHU placed these online in &lt;a href="http://www.jhu.edu/ohia/IT%20Control%20Questionnaire.doc"&gt;2010 in the current format&lt;/a&gt; and around 2007 before.&lt;/p&gt;  &lt;p&gt;I mentioned Treasury yesterday. I have to find a way to load old emails and more in such a way onto this site that offers them as proof. However, first I will remove Xena Parker’s supposed authorship of these documents in 2007 and that from around the time of JHU.&lt;/p&gt;  &lt;p&gt;To do this, have a look at the &lt;a href="http://www.treasury.gov/tigta/auditreports/reports/200020074fr.html"&gt;2000 Treasury report linked here&lt;/a&gt;. It only contains a small section of the ASX document, but this is a simple online section of the checklist predating Parker’s attribution to JHU in any event. We see the JHU document properties come to March 2007, well after mine.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-e2zQuRf9lWI/TwvQ_Pxzm8I/AAAAAAAAGH8/DBpSh9LPV_8/s1600-h/image%25255B4%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-H27O073p-84/TwvRAUQt7OI/AAAAAAAAGIE/7eJ04QdMDj4/image_thumb%25255B1%25255D.png?imgmax=800" width="228" height="460" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Also see: &lt;a href="http://www.scribd.com/doc/1218262/5/Audit-Objectives-and-Tests"&gt;http://www.scribd.com/doc/1218262/5/Audit-Objectives-and-Tests&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;So, the question is just how did these checklists get around?&lt;/p&gt;  &lt;p&gt;Well simple. They were issued to over 100 companies in Australia, India and the USA. More, we loaded them onto &lt;a href="http://www.Auditnet.org"&gt;Auditnet.org&lt;/a&gt;. I do not think you can access these without a membership from there, but I will do my best in the coming days to link these. More, in starting DeMorgan, we subcontracted a good deal. We handled a good deal of security work for IBM and CSC under a sub-contract arrangement. IBM said they did everything for the 2000 Olympics, in fact DeMorgan ran systems such as the OCAs (Olympic Co-ordination Authorities) and even some of the Police and traffic interfaces.&lt;/p&gt;  &lt;p&gt;So all of these documents were issued as PWC, IBM, CSC and other documents.&lt;/p&gt;  &lt;p&gt;I should have self-referenced this, but I did not. In future, I will do more to ensure that I do so. My crime here is not that I stole the works of Xena Parker, but that I did not attribute my own work (and more that I did not note those who had helped me create this.&lt;/p&gt;  &lt;p&gt;More importantly, I have not attributed those who helped me, made updates and who actually made these documents of use (they where so full of spelling and grammatical errors the first time). The early versions of this have flowed around for over 15 years now. They are not recent as is supposed.&lt;/p&gt;  &lt;p&gt;Those people from the ASX who reviewed my work also need a mention. The grammatical errors in my early work was appalling. &lt;/p&gt;  &lt;p&gt;Lesley Gear in particular truly helped. I was a good techie back than, but I could not write a report to save myself. When we worked together in the 90’s, she really helped me get on track and she added a good deal of insight and help into these checklists.&lt;/p&gt;  &lt;p&gt;Well, just how did this stuff get to JHU?&lt;/p&gt;  &lt;p&gt;I would guess from the auditors. I have not spoken to Chris for years now, he has moved to Queens and I do not get to NY as much as I have in the past. Chris was and is an auditor. He was my handler you may say when I was in the Australian Stock Exchange. He used to (with Lesley’s help) take the mash I created and make it legible (and intelligible). &lt;/p&gt;  &lt;p&gt;Chris worked for the Big 4 for some time and then others with more reach. We used and re-used each others work. These were the real Wild Wild days of the web. So, really, these documents are a collaboration. So many auditors and managers have reviewed them that they are not the original. &lt;/p&gt;  &lt;p&gt;He was my means to be able to survive a political animal such as the exchange and I learned many lessons from him.He took technical knowledge from me and I had a polished product when he had reviewed it. &lt;/p&gt;  &lt;p&gt;The original emails are available as are the documents if anyone wants to analyze them more.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Showing permissions 1&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Here is the email from the SQL cheat sheet section. I used some material there. Nothing complex on any of these and I guess I should really formally obtain permission to use the web pages and materials of others. &lt;/p&gt;  &lt;p&gt;I actually do have more formal permission sheets these days and publishers are more stringent than they used to be just a few years back. This is of course one of the reasons why.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-cWSnQvx7eSM/TwvOhqRxnhI/AAAAAAAAGHs/Ub0jlGqUXxg/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-jh2wmZolzT0/TwvOjHgBXCI/AAAAAAAAGH0/O4RKG9_9Li8/image_thumb%25255B1%25255D.png?imgmax=800" width="337" height="245" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;More emails like this later in the week. Right now, I am already behind on work and I promised a Metasploit step by step in parts. So… to it.&lt;/p&gt;  &lt;p&gt;More tomorrow…&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-8862618955605249687?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xUwJzbB2pfLDGG231rT2Qrtl5J8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xUwJzbB2pfLDGG231rT2Qrtl5J8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xUwJzbB2pfLDGG231rT2Qrtl5J8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xUwJzbB2pfLDGG231rT2Qrtl5J8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/zbebJgrgwtY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/8862618955605249687/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=8862618955605249687" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8862618955605249687?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8862618955605249687?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/zbebJgrgwtY/more-on-what-is-plagiarism.html" title="More on what is plagiarism…" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh6.ggpht.com/-H27O073p-84/TwvRAUQt7OI/AAAAAAAAGIE/7eJ04QdMDj4/s72-c/image_thumb%25255B1%25255D.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/more-on-what-is-plagiarism.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04FSXYyfyp7ImA9WhRVEUg.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-6838519150196121202</id><published>2012-01-10T12:39:00.001+11:00</published><updated>2012-01-10T12:45:18.897+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T12:45:18.897+11:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SSL" /><category scheme="http://www.blogger.com/atom/ns#" term="ssh" /><category scheme="http://www.blogger.com/atom/ns#" term="vpn" /><title>SSH Port Forwarding</title><content type="html">WAY back in 1998-2002 when I was with DeMorgan still, we had a project with F-Secure in Australia and a few overseas people (it never got anywhere, but it could have been great). The idea was to have an end to end secure tunnel, malware detection and control system. Basically much as NAP in windows does now.&lt;br /&gt;
&lt;br /&gt;
The project was called “Triple-S” and “BlackNet”. It was under the radar fairly well, but was listed with the Australian Government for research and development funding. A small deployment of the concept was used with CUSCAL and the ASX.&lt;br /&gt;
&lt;br /&gt;
The idea and concept was a little advanced for the time and many in F-Secure that I spoke to (mostly non-technical people) saw it as a threat. They wanted the sales leads but not the concept. This is a reason I like SourceFire at the moment, they have a great integrated anti-malware and IDS approach . &lt;br /&gt;
I guess a little of why this failed was the use of third party products to make things better. We used Snort as an IDS and integrated this and a couple other products. Back then, F-Secure could have bought out SNORT for a small stock swap. Now…&lt;br /&gt;
&lt;br /&gt;
As I have said, it is not always easy getting people to see what the future can bring.&lt;br /&gt;
&lt;br /&gt;
Well, here is a little from the project, just a snippet of SSH forwarding (originally using F-Secure SSH). This is now completed using open-ssh. The project involved automating SSH tunnels for Windows with software to see if the host was running the latest anti-malware definitions and was patched. All this is of course achievable using NAP in a Windows domain now. I have modified the post below using this material.&lt;br /&gt;
&lt;br /&gt;
We can use Port forwarding, or tunneling, as a means to forward otherwise insecure TCP traffic through SSH Secure Shell. Using an SSH tunnel, the host can communicate securely using common unprotected protocols (these can include POP3, SMTP, SMB and HTTP). That is, connections and communications that would otherwise be send across insecure channels. Through encryption, the tunnel allows us to ensure that all traffic is protected from eavesdropping and interception. &lt;br /&gt;
&amp;nbsp;&lt;img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAaEAAABeCAIAAAAFeTztAAAgAElEQVR4nO2deVwTR//4tz6ebalHf7QPiGil6oP6tRSePp5VqmjRUq1WQbkVEZDDioZDkMMDBAXkkiOEgIEgN+EKEAgEQaSKIFe4hHBGrYhHrRVbPr8/1mwjCAJJWMR9v+aP3cnszO7M5P3a2WMWAQICAoKJC4L3DhC8jzx69OjRo0ePHz+WUP59fX1oEU+ePJFQEQTi4unTp4/EwYsXL96YP+E4grHgwYMHd4X497//LS0tvWjRInT1wYMH4iro3r17d+/eraurk5aWlpaWXrVqlXC5jx49EldBBGLh4cOHGzdulBaN2bNnT506NTAw8I1FEI4jkCx3797l8Xjr16+XE6K9vZ3P53O5XHR1/fr1PB6Px+Pdu3dvdKV0dHSgOSxYsEBOTm7ZsmV8Pp/P5xcXFwuXq6enx+PxxKhUAlG4d+/ejz/+yGKx+CLQ1taWlZWlpqZGOI5grOno6Kivr9++fbuCgkJRUdEQ3bSoqEhBQUFBQWH37t319fVdXV3DL4XH49XX169atQrNAbXnYNDpdAUFhcOHD9fX19+/f19yx07wVjo7OzU1NTMzM0UUXE5OTlBQEOE4gjGlra3t9u3benp6S5cuzc7OHn6XTUtLW7p06YEDB27fvt3e3j50KU1NTbdv3966devSpUsrKiqGX0pYWNjSpUttbGxu37496jNHAlFobW3V19dPTU0dudb+obW1lcViBQUFEY4jGFNaWlrMzMyUlJRSUlJG13djY2OVlJSsrKxaW1sHK6Wurk5TU1NJSenatWujK8Xf319JScnFxYXP549l/RA0NzcbGxsnJSWNruFQeDweJjjCcQRjR1NT05EjR+h0uijdFyUyMvLYsWPNzc0DS6mpqdHX18/NzRW9lCNHjnh5eY19Rb23NDY2WlhYxMXFidJqPB4vNzc3SAjCcQRjQUNDw/Hjx2k0mujqQTl9+rSNjU2/UiorK42NjbOyssRShI+Pz+nTp9va2nCpsfeN+vr6o0ePxsTEiNJkAwVHOI5gLKivr7ezs4uMjBSLelAiIyPt7Ozq6+uxUsrLy83NzTMyMsRYipeX19mzZwnNSRoul7tjxw4DA4PLohEeHh40AMJxBJKFy+U6ODhQqVQxqgeFSqU6ODhwuVwAKCsr++WXX0S8UP1GvLy83N3dCc1JFHt7ewUFhQ2i8X//939ff/014TiCMYXL5To5OVEoFLGrB4VCoTg5OXG5XFNT04sXL0qolPPnzxOakyj29vbm5ub5ouHu7k44jmBMqa2tdXZ2lpzgUCgUirOzM4lEksRJHAaqubc+s0IwOjDH+fr6kkbI6dOnCccR4ENQUJCxsbHkvIMRFhY26odRhs+2bdsyMzPxrtSJCeY4dXX1//73vz8Nm02bNi1evJhwHAEOVFdXnzx5UhKX4fDC19f31KlTxIhVEgg77uTJk2fOnDEbBiQSiUqlEo4jwIGamhpHR8eIiAi8vSRmfH19nZ2dOzo68K7giUY/x61btw4ZBrKyspcvXyYcR4ADMTExWlpaeBtJIqxdu/batWt4V/BEY3SOmzt3Lp1Ol5Tjbt26NdJLg5KAT7xqM/6orq62tbWNjo7GW0cSITg42NbWtrOzE+9qnlC8wXFGCOKJ/HTkJ3t7e2tra1NT0xkzZiAI8sEHHxgZGUnccRUVFSQS6QzezJ07t6qqSmLVTjBKUlJSduzYgbeLJIiKikp5eTne1TyhGOi47ZTtlo2WicWJZWVl169fLygoOH78+NSpUw8fPpybm2tpabl//35JOa6qqsra2jo+Ph7fflZYWLh48WLCceON6upqa2vr4b9yaG9vr6urW1VVJdHeIl6oVKqlpSWfGEOIj4GOW7lypcYAJk+evG3bNnRZTU1NIo6rra21tLRMTEzEt5MVFhaGh4fPnz+fcNx4IysrS11dffhNqaSkhCDI0BOElJaW2tnZidxrBoXD4bi6uo5ok+XLl6PvVxCIhX6O8/PzOzkM3N3dxey4+vp6U1PT5ORkCXW1YYIKLigoiHDceKOmpsbMzIzBYAy/Nd/quJs3b65fv37lypXi6Dtv4OrVq2vWrNm8efOItoqJiTlw4AAxlaa46Oe4w4cPqw0DTU1NcTruzp07+/fvl+ij5MMBExzhuHFIQUGBqqrqiBpU2HF79uxRV1dva2tTV1ffvXs3n8+vqKhYu3YtgiCzZ88+duwYn89nMBjqAnx9fdFMvL29sciMjAwSiaSurl5cXGxsbKyurl5dXY0m6+rqwpLp6+vz+fySkpKVK1ciCCItLe3o6DiiPV+0aFFLSwveVT5BGDhW1dfXH/pyvI2NjZycXFxcnHgc19raum/fPvHO6DAKCgsLqVQqtuuE48YVXC7XwMBgpPMaCTvu008/RRBk48aN4eHhU6ZM+fnnn5ubmz08PBAE+c9//pOVlZWRkbFs2bJvv/2WTqfr6+vLy8sHBATw+fxDhw4hCGJqakqn06uqqr777jsEQVRUVAICAmRkZFavXl1fX8/n89XU1KZOnUqn0wMDA2fMmKGnp9fQ0ODs7IwgiLKy8kinnCMcJ0YGOm7x4sX/GxIlJSU5ObmEhAQxOK6rq2vnzp3impNr1Fy9erXfxCmE48YV169fX7169UibdaDj4uPjm5qa0Cc8+Xw+m81GEAQdq0ZGRiIIsmfPHj6ff/r0aQRB0JM71HHYO/mo486dO9fU1KSgoIAgCHpPY8qUKTNmzODz+eXl5QiCLFmyhM/nMxgMBEFGOlbl8/mZmZnbt2/v7u7Gu+InAqN7Pk48jnvw4MHXX389ffp0Fbw5cuRIv10nHIcjvb29q17n559/5nA4ojuuvb19aMd9+umnKioq8+bNG9px6LCjn+MmTZqkoqKyYsUK0R3H5/PnzZvH5/M3b96MVYKGhgbeLfNOMtBx5ubmgW8iICBAzI7r6upCEERGRoaMKxs3btTR0SEcN05YvXq1iooKS4iQkBBlZeVRaGIUjtu8eTNW7u3bt0fkuGnTpmHbFhYWiug4Doezfv36tLQ0LM/ExMSvv/56165deDfRO8ZAx8kmyX6598s3IhHHzZ8/f3QzOomLXbt2iddxZDIoKv4TkpMBAMzNX61WVr5KtnHjq5hly17bvKEB9ux5eymurqCoCOnpYGkJiopQWgp798I7/ciBqqqqoqIii8W6evWq8L+dx+P9+uuvY+M4dKzq7++/aNEiNze3ETkOHatWVVUtWrRoy5YtIjqOz+cXFxd3dnZiq+3t7YWFhbGxsYqKitra2ng31ztDP8clJSXFFMXEMGISEhKSkpLS09Mz3kR2dnZqairhuDfT0wPNzWBqCidPQnMzPH0KlpZAo0FzMzQ3w9atr0wkLw83bkBzMzQ1vaa5qir473/fXoqZGXh4wNOnsHMnUKnw/Dl0dsKLF6PbZfxRVVXNysoqLS3t6uoanREG8lbHtbW1UanUadOm7dmzp7m5+ezZsx999JG8vPzs2bP19PTq6ur4w3bc9evXP/jgA3l5+blz58rJyd26dYvP5/N4vICAgBkzZhgaGorroNra2kpLS2k0mo6ODt6N9m7Qz3Hbt2+XlZWVlZWdO3cu2lhv5JtvvklLSxOz4zIzMykUiohzrg+T5ORkyTkOxc4OLl58taylBSkpr5Z/+w16ewEA5OUB/cbmX3/BRx+9+rWlBaSlYcoU+OknKCwEWVmQlQVLS4iKerUsKwt+fuDsDB99BLNmgawsTJ8Oc+ZAcTFoaEB19at8Vqx4lfidQFVVlclkCp+ziIWampqKioqOjg4+n19ZWYl+C7Wrq6uioqKyshJTRkVFRW1tLZ/Pb2lpqRDQ2NiIJmhoaKioqGhubkZXa2trKyoq2tra+Hx+VVVVRUUFttvYtsJvVrS2tlZUVHC5XPEeWltbW0REhK6uLt5N9w4wunsO8+bNE7/jMjIyQkJCqBImLi4uLy+PzWbj5TgMeXmYNQvmzAFpaXj48FXkX39BUREoKcHjx8BiwfffQ3c3/P47/PkndHe/CidOwIULcOAA+PtDdzf88APExUFvL6xaBeibjkpKUF8P3d3w4ME7oLnvvvsuMzNT7IKb8LS3t4eHh+vr6+PdgOOd985x8fHxkh6rogzHcTwePHsGz569Fo+NVVksEL6TdukSfPghfPghTJkC3t5gZgbh4QAAO3cCkwkA/zhuwQK4e/fVVv0yH4eoqKgUFBTgbYx3ko6OjtDQ0P379+PdhuOa8eg4DofTJ0Rvb98ff7wKjx/3PXzYd/duX1dXX1dXH4/Xx+X21db2lZX1lZT05ef3MZl9GRl9SUl9MTF9dHofldpHofQFBfUFBvb5+PQFBfFSUlLG3nHa2pCUBL290NsLa9e+uu2AjVX7UVUFKirw8uVrjqNQwMoKnj+H58+BRHqL4778Ejo6oLcXXryAWbNEOQiJs379eiaTibcr3mHCw8N1dHT++usvvFty/NLPcQUFBRwOh8PhlJSUlJaWVlRU3L59+/bt23WvU19fn5OTI0HHCSd9+fLVf/v5c3jyBHp64N494POBz4fWVqirAy4XysqgpATy84HJhIwMSEqCmBig04FKBQoFgoIgMBB8fCAoqHXMHOfsDMLHvncvSEmBlBTcvPkqRlER3vhKYk0NSEnBli3AZr92gzUo6FUOUlIQEAC//AI0GgCAtjawWAAAGzfC7duvEi9cCFJS8MknohyBxPnjjz82btyYk5ODtyjebQIDA42MjPBuzPHLwPO4adOmzRiS6dOny8vLS9ZxfX2ABTE6LjS0PSMjY2wcRzA0jx8/1tDQwP0dvglAWFjYoUOHnj59ineTjlMGOs7DwyN/SOLj4yXrODabg0mtXxDdcZmZmYTjxgMaGhrDnwmOYGi8vb3Nzc3xbtJxykDHnThxIm5IgoODJe64P/6ANwYRHUehdOXk5BCOGx2tra1Pnjx5JiZ0dHQSEhJ4BOIgICDAxsZGLO3S09PT2Ng4keZb7+e4HTt2oE/AzZs3b968efIC5r/O6tWrJeg4FovT0wNDhFE7Ljycz2KxCMeNDkVFRSqVyiSYuDAYDGdn5yVLluzdu7e1tRXvHice+jkuMTExOjo6Ojo6Li4uISEhNTU1LS0tLS0t+3XYbLYEHZeTw8GeBXtjGLXjIiLuDRx7E44bDrW1tRs2bIiKisL7b0ggQQIDA1VUVPh8fnR09E8//YR3pxMPA8eqc+fOXTwkCxculOxYNSuLgyrsrWHkjrtfUFBAOG4UKCsrh4SE4P0fJJAs74njhnnPgcViScpxTCansxOGE3i8kTnu8uUHRUVFhONGAeG4CU9KSoq9vf2BAwcmvOOMjY29hsTZ2Xn+/PkFBQWSclxGBufOHRhmGJHjaLTu4uLitzrOxsbms89+unSJl5EBREDDl18SjpvgkMnk+fOXR0U9jIp6SCLlr159GvdeJ5agqRmhoXHpypUS1HFGRkZr1qxZs2bN2rVr161bt17AdwI2bdq0adOmffv2SdBxqamcqioYURim4+j0nhs3brzVcV9++SWC/IogQARBKPjqq500Gg3vvyGBBCGTYxDEGu+eJqlw9Gg96riQkBB3d3d3d/cLFy54eXn5CQgWQKFQKBRKTEyMBB2XmMgpKYGRhqKitzvuypXHt27dGtpxR48e/fxzHQS5g3urjKewxt/fH+//IIFkIZPTEYSJd0+TVMAct27dOiUlpU1Dsm7dOsmOVePiOPn5MLoguuMUFRW3bSvcvx+IgIXPPpOU406dOmUtRGpqqnjzd3JySkxMHDoNnU4/e/bsiLJ1cXGJi4sTjsnMzEQPwd7eXjg+KirKzc1tRJkPQVJS0smTJ8WVWz/IZPKsWSv27v0DDevWNSxcWIB73xM9rFhxU1GxxMenfET3HCTruNhYDosFowuZmUM5Ljb2SUVFxVsdV1hYOPRVzPeNNWsk5bhly5atW7fuBwHJycnizX/BggUUCmXoNOfPn1dWVh5RtkuWLAkMDBSOsbS0RA9h+/btNjY2WLybm9v//ve/EWU+BFQqVV5eXly59YNMJi9btgx7dyI8PHzfvn14dz0xMPCew86dO48OibGxsWQdR6dzUlNBlDCY4+Ljf6+qqiIcN1Ik6jg/Pz/hmMOHD5uYmJiYmFhZWaExV65cQWPQUxgymYyuenp6+vr6+vj4oMnc3d1NhIiKirK1tZ0zZ87evXuTkpKYTKa5ubmJiYm5uTmaPiEhAU25ffv2fo4LCAjA8gkICGAymWfPnsViaDTakiVLdu/eja6mpKQwmczdu3ej20ZFRcnIyGDLP/zwg7y8vKura2hoKHZC5+Pjc/HixfPnz2N5hoeHM5lMBwcHLAY7/TQzMzMxMbGwsGASjhsV/RxnZ2enpaWlpaWlra2to6OjL+CAAGNjY2NjY1tbWwk6LiqKEx8PIgbCcWJEoo778ccf9wtgMBjTp0/fs2ePpqamlpaWubl5XFycgYGBpqampqbmvn37HB0d7ezsFixYoKmp6eLi4uHhoaur6+Pj4+bmpq2tjb6CgybW19ffu3fvzJkzt23blpCQYGpqqinA1NQ0KSnJ0NAQXf3uu++EHRcYGKirq4sl9vLyOnPmjLa2NhZDpVKXLFmyZcsWdNXQ0BAbYjMYDENDQyMjI3Q1IiJiw4YNMjIyNjY26Men0Xg9PT0DA4Ndu3YpKytje0ulUr/66qtNmzZh2SYnJx86dAhd1dLSOnz4sOQcl5CQYGRkdPr0acxxBQUFNjY2GRkZePc+UennuKKiopKSkpKSkrKysvLy8traWi6Xy+VyWwQI14CkHBcRwaHRQPRw+TLhOPEgUcdt3bpVR0BKSsr06dMzMjKYTGZMTMxnn31GJpO/+OILNDGFQrGzs7Ozs9u8eTOWg46OzoEDB3bs2GFlZbVp0ybsctjy5ct9fX2xserMmTO1tLR0dXW1tLRmzpxJo9FkZWXRlP3Gqn5+fjo6Orq6urq6uhcuXGAyma6urroC0BMu4bHqrFmz0HOutLQ0XV1dY2Nj4QPExqpvdBx2UrlmzZrTp09/9dVX3t7eaMznn39Op9M/+uijffv2oc6dM2eO5BwXERHx5Zdf9nvVPygoaAJMwCnsuA0bNhw4cODgwYMHDx40MTExNTU1Nze3sLCwsLD4RcBxAYaGhpJyHIXCIZNBXCE09B/HJST8UVtbSzhupIzlWHUIx4WFhR0/fnzUjtPV1UXPFk1NTYdwHJPJ9PPzQ1Pq6Oh4eXkxmUxXV1c0Zt++feh5XD/HZWZmamlpmZiY9DtA0R2nr6+PFm1mZkY4bhRgjnN3dzceIba2thJxXGgox98fxBv8/MDHBxITn9fV1RGOGykSdZyqqupOAQPP4+Lj4w8cOID+qqWl5ezs3M9x3t7eOjo6enp6QUFBmzZt+uabb9DE+/fvp9PpCxYs2Lx5c3x8vKWl5a5du9Cf9u3bl5SUZGRkhK5+++23wo7z9vbG9kdXVzcgIMDBwQGLMTQ0RK/H9XPcrl27Jk+ejKYxMDDAcnNzc/v3v/9tbW0dGhqqr6+PJlBUVBym48zNzbGidXR0JOe4xMREExMTJycnTHBsNvv48ePZ2dl49z5RwRwnCmJ2XHAw5/x5kESIjyccNxok5zgnJycLIVJTU48cOZKZmclkMlNSUkgkEpPJjI2NRX91dXVlMpkUCuXcuXPCmezZs8fU1JTJZG7atOn7779HE0dHRzOZTHt7ewsLC/Sewy+//IL+ZG1tzWQyExISsHJdXFyw3EJCQrB49IbD+fPnsZjLly8zmUxHR8fY2Fg0vbW1dVpamqWlJZZG+L4qjUazsLA4c+ZMv5z9/f29vb2Dg4PRZGfOnLl8+bKzszOdTkdjSCQSejfDysoK3eTYsWOJiYl2dnYSaAcm8z2450ClUgMDAyMiImJjY9PS0vLy8nBzXFhYwqVLRcHBxWTydTL5enj4jYiIMhrtdnR0ZXR05ZUrtXFx3KSkxuTkprQ0Xnp6a3p6a1ZWV3b2q8Bm/yYUHly9+ggL5eXdhONGgeQcJyKnTp3asmWLnp4e+p6Z8FiVYKRMeMfFxcVFRUXFx8czGAwmkyn8cb7Y2Fh0lc1mp6enJycnR0dHh4aGkslkMTuOSqWmC0AHLEwmMysrKzs7m8Vi5ebm5ubmorvC4XAKCwuLioqKi4uLi4tLhPhViBs3bpS9zvXr19/uOLVC2AdEwMKa/zdOHRcSEmJra4u9SOvt7R0ZGYnvLr27pJPTM2ZmPN/5HA13Vt4pnl+Me98TPVQsrbix+EbFhf4PxmJcuXLl+vXrDAYDdUt2dnZmZmZKSkpcXBz2GT+xOY5Gow3/7FFcvMFxSCEgQAQsrCHe5XoPKCRP5G5ff7Q+NDTU29ubTCbT6XQGg4GNVW/evFlbW5udnZ2fn89ms9PS0hITEy9fvhwUFBQcHCxOx+Xm5jKZTHwd9+OPP178+GI30o17k4yrcA25tn3ZdvRSFMFEhU6mWyAWuHc2CYX6o/XJyclxcXEpKSnp6enoTL+oAUpLS4WnXMvJyWEymWlpaUlJSUlJSWikeBw3ZpytPKv8UFn5ofIJ7glhx2loaHz88cdKiNJGZONGZGNzWDPkARHQoLyImFtpgkMmk5cvWN4d390d3517ItdprRPuvU4sIWxfmN8Ov2vx1y5duuTp6RkcHBwVFZWSkoLDPYcxI7E40f+Wv/8t/9hrsflCjrty5UqqgEWLFhFzZApDzJE54WEwGCdPntTT05uoc2SeO3fO1tbW09MzNDQ0Pj4+NzcXcwKNRkOVx2azU1NT4+PjqVQqOueSGBw3derUoedWlzSzZs1CHXf58uUYAQsXLiQcJwzhuPeBiT3XeXp6OoPBSE9Pz8rKYrFY2FiVRqNFdyxlF776Kmlubi42XE1LSxOD42RlZcNfx8TE5Ntvv8VWf/zxR01NzXCJoaamRsx1/laamprWrVtHTJM5sQkMDJwxY8aSJUvk5OQmnuN8fX1Pnz7t7+8fERGRlJSEjVWzs7NZ1yPzC16dxzEYjNjY2LCwMG9vbx8fHzE4bvLkyXNfZ/bs2R9++CG2KiUlNXPmzLkS4+OPPyYcNxxaW1tZLBbef0MCCZKamurg4LBy5crGxsauri68e5x4wBzHZDIzMjKysrJycnKEB6r9yMvLY7FY2dnZaJ2I6ri5c+diT66xWCy3QfD09Bzs6xIBAQEBAQFkMjlMAE2IqKgo4c9fUyiUN+Z/8eJFCTruKIDc66FWhNwuAsgBkIeXuA9ADmCZCMW9zp9//vlcTOzduzc+Pr6NQBz4+/sfO3ZMLO3y9OnT+/fvi63HjAMwx3l7ezs7O1+8eDE8PDwxMXEIzQ1kNI579OjRp59+OmnSpE8FzJ49++NBkHobnwgxc3A++eSTwYo4ePCgpBz3BOA+wFYABIABcB/gpQi5PQO4D/DH8BL3ASAAs0UoTmI8fvxYQ0MjIyODTyAy3t7e5ubmeDfpOGU49xww2Gx2cnJyTExMcHCwh4eHp6fnEI7bsWPHlClTBnVcT0/P7NmzMzIyMjMz8waHw+EUDc6vv/56cxDKysqqB4fL5TYKoaWlZWhoKNmx6g4ABIAjFKMIIAUgBTAL4JlgeWDQB4gRLDsCnAOQAggAODog5a8Aa1+PeT5+HQcAampqDAYDbz+884SEhBgbGz9//hzv9hynYI7Lzc1FX5fKy8sTfpFroObYbHZeXh76YtUQjtu6daubm1tvb+8by0V6eno++OCDqUJMHoQpU6ZMHYRp4mDq1KmTJk0aa8ctA/gAoA3gOcAUgCkACIAsQC9AOQACsBagFyAZYBKAPkAvgA/AJIB/ASAA3gBmAAgADaAXYAsAAlAC8BLgT4DnAJ8BIOPdcS9fvly/fn12djbelniH6erqCggIOHjwIN6NOX7BHOfp6Wlvb3/hwgUymZyQkDDEeRydTr906ZKbm5u7u/sbHXfp0qUdO3acOXPm77//HqxcpKenR1paullAQkLCpEmTpkyZgiAIgiD/+te/Jk+ejC6QSCQ0TVtbW2tra3Nzc3t7O4/Ha36dzs7OfgstLS0dHR3Nzc08Hq+9vb1f+tbWVjQ3AwMDBEGEHefn57d48eKamhpx1nQ/xy0GQABmAHwoCAjAXAAAqAJAANYBAEAaAAKgBwAAfkLPbWOOowMAgLrAcc8BFgPMAPjgHXAcAKipqaWlpXV2duLtincVCoWira2NdzOOa8Q+t1JAQMDPP//s6uo6dLmvzuOwq2lSUlKrV692d3dHl7dv33706FEpKSkDA4P9+/ejkSQSSUNDQ0pKys3Nbe3atWgketdVSkoqMTFRWlp69uzZKSkp6NW3JUuWhIaGzpw5c9WqVR4eHuj1OOzinYGBwcGDB2fNmjVr1qypU6dijvPx8fnqq69u3bol5pru57hvACYB1AN0AzwE+F1MjlMCQAAqAKTfDccBgIqKSkFBAd6ueCdpa2sLDg42NjbGuw3HNZjjWCxWTk4OOlwdeqyKDlRZLBaLxernOH9//7179zo5Ob21XKSnp2fOnDno9oWFhQUFBbm5uejEIYWFhWw2u6SkBL0YV15eXl5eXlhYWFJSUl5ezuFwSktL0Ug2m52Tk1NVVZWXl1dTU8PlclksFjo7e1VVVUFBQUtLC5fLLSoqQmdqr6ysZLFY6OYVFRVYX9HV1UUd5+XltXLlyuvXr4u/pg0BZABKhGL+CyADIAMgB/AMQAZAGQAAuAAyADsAAIAFIANgCQAAFEF6GYAQADsAGYBkAADQBpABKAPYLJRGBuBPABkARfEfjRj5/vvvGQxGR0cHjrJ4F2ltbSWTyUZGRng34HgHc5yXl5eTk5OPj88Q91XZbHZKSsqVK1dCQkI8PT3Pnz8v7Dg/Pz89PT0HB4fhlPuP4zJZmR40jytXrmCTIxUXF6PzJpWUXLtx40Z5eXlZWdnNmzdv3brVbwG9e1BVVSgdTOgAAAp3SURBVFVVVdVvobq6uqWlpbm5uaGhobGxEV1oamq6c+dOQ0MDj8fj8/kdHR2tra0dHR2o4zw9PTds2HD16lVJVzpBP7Zs2ZKamlpaWkoMWodDa2traWkphUKZABORjwHiGqsuW7bM0NDQzs5umOX+47jo69Hf9Xx38+ZNgeKKWCxmdHR0enpKSUkR6riioiIWi4We4qEnYgUFBSwWq7Kyksvl5ufn5+bm1tTUoLdia2pqcnNz0ZO4+vr6vLy8a9eu1dbW5uXllZaWVlZW5uXloSdx6PdrampqdHV1d+7cuXnzZjabLdHqJhiMLVu2KCoqMpnMwsJCvB0yfmlrayssLIyKilJUVDQ0NMS70d4N7O3ttbW1k5OTs0dLamqqtbW1lJSUjY3N8MtFenp6Zs6ciT67Gzk40dHRVwYnMTExaRCSk5MzBgd9YQ3jhx9+mD9/fk5OjuQqmmA4qKqqKikp5eTksNls9F/N4/FYLFZxcTG+csEF9BJSV1cXn8/v6OhgsVixsbFKSkoTY3reMcPPz09aWlpdXf3EaNHW1v7kk0+OHz8+onKRJ0+erBpPZGZmSqiKCUbK6tWrN2zYgE4HHRkZuWLFCmVlZbyFM9awWCw1NbVVq1ahr5EnJCSsWrVq165deDfOO8nFixdF9IO1tfVIC0UkcSQEE4bff/9dVVVVVVVVV1e3qalJS0srNzcXb+2MKfPmzePz+QCwZcsWVVVVDQ0NvNuEYGQQjhsVzQCNeO8DHly/fn316tV4a2fsYDAYP//888OHD/GueILRQzhuVCQBROO9D3hQX19vZGSUlpaGt3zGiEWLFrW0tOBd6wQi8V46jgMQKwhPAAAgBSAWIE6Q4A+hBHkAANApFFMGwAXAXjC7KYjvAAAAtlDK38f0sMaGgoICVVVVvOUzFly5cmX//v0TbPKP95BhOa6mpga9u1pdXQ0A165du3PnDgDk5eUNc3Krhw8fZmRkiLKjYoMNcBRAXxD4AAkABwH0AQwAogH+BAgVSnAGoAvASyiGBuAJcBIAAG4AnBDEXwDoAFAF2CqICQGYcC9oc7lcCwuLhIQEvBUkcZYvX87lcvGu73HNy5cvUTMkJSW9MUFDQ0Npaelgm7NYLD6fL7G9e8XbHVdTU3Pq1KlDhw4dOnTo1KlT1dXVBw8epNFoAODv7z/MTlBRUbFy5UpRd1YsBAKcBwgBCAHoBgAAeYALACEAQQAfAfwOYC5IgDZcLQBJEIN+1Rpz3FGAS4KcdwIwAVSFXqJYAHB37I5szMjKylJXV8dbQZKFSqVaWlryJf8PfHfp6+sLCgpCzWBpaRkfHz8wTWhoqJWV1WA5qKur5+fnS3AXAWA4jgsMDMTu16akpHA4HMxxqampbW1t6E9RUVHopyXQuWX8BFCp1IcPH9ra2s6fPz8xMVFiBzISLgFYAlgCnAfoAZAHOCiIQZ+8eSRYJQGgDVctiHEEKHjfHVdbW0sikeh0Ot4ikiAqKirl5eV41/S45q+//vr444/R5fv377u7uwNAZ2cn9t/PyckJDQ3dsGEDunrjxg00MYvFQmMUFRVRx9HpdGyrFy9e9PX1ocsUCgUAuru70dWkpKSWlhbhEWFZWVlJSQkAXL16FU1TV1cHAAwGA129f//+yByHgjnuhx9+yM3NBYDIyEh7e3sSiUQikc6dO9fb2ztlyhR01c7Ozt3d3cDAQEZGJjg4WPSaFZUkAE9BsAe4D3AW4JwgxgfgD6EEbgCBADyhmFMAKUKOSwVwFfzkCFD3XjgOAFJSUnbs2IG3iCRFcHCwjY1NZ2cn3tU8rvn7779tbGw8PT3R2S4BgM/nnz17liQgJiYmNDRUWVkZXXVxcblx40ZOTs7JkyfRmC+++CI/P59Go2H2IJFIz58/9/LyQpdtbW1DQ0Orq6s///xzEokUEhJSW1vr6OiYnp4OAGVlZS4uLllZWYWFhU5OTugmp0+frq+v37Ztm5aWFolE6ujoEI/jVFRULCwsTp06derUqRkzZjx79mz69OloYh6Pt2TJknE0Vo0GOCkI2EDknCDmFMAzoQRBAADQJBSTAgAAVwX3IgAgVfATOnM6BaBN8JMXwNMxOqwxhsvlnjhxIjIyEm8dSYS1a9deu3YN7zp+B3jx4sVJAcHBwR0dHU5OTqgHEhIS4PWxqr29vbe3t5mZGZVKRWPQsWpISIirqyu61e+//w4A06ZNQ1dJJNLChQurq6tVVFSwQhMSEnR1dQHA398ffefBwcFBXV0d3WTFihWJiYnbtm3D3gcdmeOYTGZJSckbHWdlZXVGQG9v7/h1HIGYiImJ0dLSwltH4sfX19fZ2bmjowPvCh7v/P3339jcbY2NjcuXLweAtrY2VAKurq7x8fHDcRwAkMlkdCtHR8fnz59PmzYNk0lgYGA/x3G5XFdXVwcHB2dnZ9Q/Dg4OW7duxTapq6sbmePKy8tdXV2PHTt27NgxV1fXW7duDXQcjUaztbU9JuCNjpORkbl06dJQJRG8U3C5XGdn57CwMLylJGY2btxITAkxHPr6+s6fP4/+5W1tbSMiItra2jAJODg4ZGZmDnQci8VydHRE0yxYsCA/P9/X1xfbytPT888///T29sZi3Nzc+jkOAGg0GoIgFhYW6OrVq1ednJywTSorK0fmOAAoLy9HP7uFzljJZrPRC3tpaWnt7e1oGjqdHiDg5cuXQUHoMA+ePHkSFRX122+/BQQEJCcni1qvBOOJiae5CxcunD17ljiJGya9vb3oXx496bl37x4mASaTCQDV1dWFheizCIDOOwkAubm5WLKOjo74+Hhs9dmzZwDQ19eHxVy+fLm7uzs2Nla43Lq6uoCAAA7nn8+yFBUVYZs0NTWlpaVhjfhePgNMID6CgoKMjY3HwD7BwcFJSUmSLmXbtm3ErBATDMJxBCJRX1/v4uISEhIiUfWEhIS4uLgcP348OTlZcqW4u7t7enoSt1MnGITjCESloaHByckpNDRUQuoJDQ11cnJqaGgwNTW9ePGihEpBBUeMUicehOMIxEBjY6Ojo6MkLsyFhYU5Ojo2NjYCQGVlpZWVVUpKithL8fDw8PDwIAQ3ISEcRyAempqa7OzswsPDxaie8PBwOzu7pqYmrJTq6mozM7MNGzZkZWWJqxRPT093d3diiDpRIRxHIDaam5uPHTu2atUqsbzmFRkZeezYsebm5n6lcLlcDoejr68vltk6L1y4cObMGUJwExjCcQTihMfjlZaWmpmZxcbGiqKeqKgoKysrHo83WEF1dXWampoifhDW29vbxcWFT7x4P6EhHEcgftra2g4cOLB06dLRzaYZExNjYmKCPXo5GE1NTdu3bx/dZ3SCgoKWLl3q6Oh47969sakTArwgHEcgETo7O+vq6nbv3q2goIB93OutpKamKigoGBoa8od3btXa2qqmpqagoFBeXj7MIiIjIxUUFH755Ze6urrffvtN0vVAgDuE4wgkyN27d3k83ubNm+Xk5OTk5NDP6Q7k6tWraIKdO3fyeLwRqaerq4vH46moqKA5tLe3v7EIBoOBJjAyMuLxeN3d3ZI7aoJxxf8HpXMxByYd6oQAAAAASUVORK5CYII=" /&gt;&lt;br /&gt;
&lt;i&gt;Figure: Making insecure TCP connections secure using channels inside the encrypted ssh2 tunnel &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;SSH allows for two varieties of port forwarding. These are: &lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;local tunneling ( aka an outgoing tunnel), and &lt;/li&gt;
&lt;li&gt;remote forwarding (aka an incoming tunnel). &lt;/li&gt;
&lt;/ul&gt;
Local port forwarding forwards traffic coming to a local port to a specified remote port. &lt;br /&gt;
As an example, we could send the following command to set a local forwarder: &lt;br /&gt;
ssh -L [local_port:remote_port] &lt;a href="mailto:user@remote"&gt;user@remote&lt;/a&gt;&lt;br /&gt;
or…&lt;br /&gt;
&lt;pre&gt;ssh -L [bind_address:]local_port:remote_host:remote_port] &lt;a href="mailto:user@remote"&gt;user@remote&lt;/a&gt;&lt;/pre&gt;
&lt;br /&gt;
This command will send any (and all) traffic destined for the port set as &lt;code&gt;local_port&lt;/code&gt; on the local host and it will forward this to the port we have set as &lt;code&gt;remote_port&lt;/code&gt; on the remote host. &lt;br /&gt;
&lt;br /&gt;
Remote port forwarding does the opposite to local forwarding. That is, remote forwarding forwards any traffic that is destined for a remote port to be sent to specified local port. &lt;br /&gt;
&lt;br /&gt;
As an example, we could use the following command: &lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;ssh -R [remote_port:local_port] &lt;a href="mailto:user@remote"&gt;user@remote&lt;/a&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;pre&gt;or…&lt;/pre&gt;
&lt;br /&gt;
&lt;pre&gt;ssh -R [bind_address:]remote_port:host:local_port] &lt;a href="mailto:user@remote"&gt;user@remote&lt;/a&gt; &lt;/pre&gt;
&lt;br /&gt;
In this example, any traffic destined to go to the port defined as &lt;code&gt;remote_port&lt;/code&gt; on the remote host will be forwarded to the port defined on the local host by the value &lt;code&gt;local_port&lt;/code&gt;. &lt;br /&gt;
&lt;br /&gt;
In an event where there are three (3) or more hosts ( we will call these &lt;code&gt;client&lt;/code&gt;, &lt;code&gt;sshdserver&lt;/code&gt;, and &lt;code&gt;appserver).&lt;/code&gt; We can forward the traffic securely taking the traffic coming to &lt;code&gt;client&lt;/code&gt;'s port &lt;code&gt;x&lt;/code&gt; to &lt;code&gt;appserver&lt;/code&gt;'s port &lt;code&gt;y.&lt;/code&gt; Heree we create a gateway as we you connect through the system &lt;code&gt;sshdserver&lt;/code&gt;. &lt;br /&gt;
&lt;br /&gt;
The connection between &lt;code&gt;client&lt;/code&gt; and &lt;code&gt;sshdserver&lt;/code&gt; is secure and that between the systems &lt;code&gt;sshdserver&lt;/code&gt; and &lt;code&gt;appserver&lt;/code&gt; remains as clear text and can be monitored and scanned using an IDS. &lt;br /&gt;
&lt;br /&gt;
In order to create this type of tunnel, we can issue the following command on &lt;code&gt;client&lt;/code&gt;: &lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;ssh -L x:appserver:y user@sshdserver&lt;/pre&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAaUAAABNCAIAAACJ0OyiAAAgAElEQVR4nO2deVwT1964c+99e+/763vv27f3aq23t1qlgLaguFSLSFWoVStatSoWxAVQkU2EsMsqAUFkDYSQsCSBAIGww7CjbJE17AHZZA3WVtxFrH5/fxxJKQhCCAQhz+f8MWc4c2bmOzMPcyZnzuBAwgImIiLCeBhbW1sXFxcHBweU7ejoELra0NBQY2NjMzMzFxcXFxeXixcvCtbS09Mjus2fV1CpVCcnJ5epY2ZmJi0tXVhYKO49EDHe3t6XL18WIiAuLi5r1qxpamoaWydu9ndDwlygpqZGWVmZQCAkDlNTU8Pn81tbW1FWXV1dWVnZxcVl8nXev39fWVlZWVnZ3d09MTExNzeXz+fz+fyMjAzBWn788cczZ87M3H69o9BoNE9Pz9u3b/OnSGtrK4PB2LFjxzzznY+PT0BAQG9v71QDwufzy8vLlZSUJL6TAAMDAy0tLbt371ZXV29paenu7h7vpGlvb29paaFSqfLy8klJSZ2dnePV+fjx45aWFl1dXSUlpZaWlrdWi2GYvLx8QEDA4ODgbO773OS3336LiYlxdnaeIGgTBJNCoZBIpPnku+fPnwcHB/v6+vb09Ew1IH19feXl5WQyeePGjRLfLXTu3Lnj6OiopqZWXV09pdPI1NRUQ0Pj5s2bY+t8+vSpt7e3mpoahmFTqvPq1askEunVq1ezH4c5RWxsrLW19ZRCh+DxeHQ6nUQizTPfUSgUNzc3IQLC5/MrKytRQCS+W+g8ffrU2to6NjZWuDOJx+NZW1sXFBSMqtbV1ZVMJgtXp7e3t7+/v1iiMUeg0WiXL18WInSNjY1RUVGkYeaN7wIDA69duybc6VReXk6lUiW+kwAAcO7cubS0NOHOJERQUJC7u/vIOu3t7el0+nTqDAgI8Pb2FldMxAuDwXB3dxfumV1kZCRpBPPDd/7+/r6+vn19fUKcSBUVFWFhYYKASHy3cHn8+LGBgUFOTo4Qp9FIOjo6rK2tMQx7+fLl4OCgu7s7jUYT7omygO7ubn9/fzKZPDQ0JO44zSoYhi1evHjFihWrps66detIf2Qe+I7BYLz//vufffaZEAGRkpI6cuTIyIBIfLdAuXv3roODQ1JS0jRlJ8DIyCgjI4PNZltaWoqqTjc3NyqV+ttvv4k7WrNHQkLC6dOn86dOXl7esmXL5p/vyGQyDocjkUhCxMTd3X3Pnj0S3y10Hj9+7OjoGBUVJSoxIaysrOzt7ePi4kRYp7u7O5lMFnfAZg+B74yNjc9MGiqVOu99d+7cuckHJCIiQuI7Ca/p7+9XUVERoZUQbW1tycnJIq923bp14g7Y7CHw3fLly+0nx549e8zNzee975YuXTrJgGzbto1AIEh8JwEAYHBw8NChQ1VVVSIX0wwRFxeHx+PFHbZZQuA7aWlpb2/vTydkxYoV+fn5Fy5cWAi+k5aWzs/P19bWnjgmP/zww8mTJyW+k/Caffv2vUOy4/P55eXlenp6vb294o7cbDDSd25ubrgJee+99zgcDh6PXyC+KygoOHLkyMQxUVZW1tHREY3vBgYGiLMIg8GY4WAuOEpLS01MTJqamsQtsakREBBw7do1cQdvNhjtu424zT9tPnjw4IkTJw4fPvzJJ5/gcLhFixbJy8svXN8dwh04fOD06dPHjh1bvHjxDPru4sWL12YROTm5GQ7mgsPBwYFGo4lbX1OGw+FYWFjweDxxx2/GGeU7xfOKUZyo69evV1RUFBYWenl5LVmyxM3NLTQ0FI/HL126dAH6ToOpkV+Yz+VyS0pKrly58re//U1GRgaPx+PxeD09PZH5TldXNzMzc9ZOcfQ25czHcwFx48YNCwuL5ubmiSNPIpHWrFnD4XBm5ThPFj09vby8PHGHcMYZ5bt//etfMn8EXd6Iv//97wvQd59++unIgPz5z3/+xz/+gaZXrlwpAt/du3cPj8dnZGTMzpnd1dWVlpZGIpEk93ciZGhoKDQ01N3d/a3xv3z5Mg6Hy8/Pf+NfORzOmjVrRHWs29rajI2NfXx83lqyr69PSUnp/v374g7kzDLSd+np6bQJodPpC813SUlJE8eEzWZPy3cDAwMEAkHkfbXGo6urC8MwtHES34mQ7u7uXbt2TeYQCHzX0NDg5+dXXFzMYDDQ+2FpaWmfffbZ0qVLUUdlJpPp5+fn5+eH5Nja2uo3TGNjo5+fX05OTlxcXFBQkKDykJAQVODmzZs9PT0mJiY4HE5DQ4PH4711w2xsbGJiYsQdyJll1P3dypUrd43Phx9+WFZWZm5uvnB8d+TIkU2bNo0XkG3btn3zzTe6urrC+87S0nLWZMfn89PT0wUbJ/GdCLG3t5/kkzuB79LS0nA43DfffHPp0qVFixYFBQXFxcV9+umnH330EZPJDA0NXbp0qa2t7ZEjRzZv3lxUVFRWVobD4VRVVZ2cnEpKSnA43Pr1662trZcsWYLuK319fRcvXuzk5LR79+4dO3ZwuVxdXV0cDnfgwIH6+vrJbJuCgoK4AzmzjPLd6tWrD4/PokWLuFyulZXVgvLdjh07xgvI3r17t2/ffu7cOSF9p6+vP82XyadEZmZmUFCQxHczwdq1ayd5FEb57vz58y0tLX/60580NDT4fP6GDRtkZWX5fP6ZM2dwOFxra2tQUBAOh4uJiUG+Q++TcblcHA535MiRhoaGTz75ZNu2bXw+f9++ff/4xz/4fL6joyMOhysoKEhOTsbhcN7e3pPcNhqN5ujoKO5YziBT6o/y17/+VYS+q68vTUigzOjeCcFU+6MI7ztTU9O//OUvMjIysrPCxx9/bGVlNXLjJL4TjkePHrW3t2toaMgP8/HHH5eVlQnnO09PTz6fP57vvvjiC1lZ2WXLliUlJY31nampKZ/PH+m7P//5z3JycjIyMsuWLeNwOFP1XXl5+YkTJxwdHQW75ubm1t7ePm/esR3lu72aeymRlFGYm5vPhO9KSjAi0ebXX+/09rb39rY/ePArALx69Qple3vbh4aeP38+ODw9CABPnjxE2VevXj158ujRo/sA8OLF0K+/3nnw4Nfe3vb+/i4AePDgXm9vO58/7tCwEzDWd5a+lhTq6Jh8//330/Xd+fPncThcdna2EG/qCsHBgwfNzc2n47sXL4DNfp0SEwEA2tqAzYb4+NcFuNzXf62o+H2p7m64dWuiatPToagImpqAzYaBAZjj7YOkpCQPD4/vv/9+5A8OFhYWt27dmgnftba2VlVVhYSE1NXVTcZ36P6upKQkJCSkpaVlqr7j8/kpKSkhISGCLIlE+v777xkMRnFxsbhjLwJG+i44OHg7cft2y+0qKiqqqqo7x7Bnz57a2lobGxsR+s7C4rCh4S48/lBgoG1/f3dxMYbHH0Kpt7cjPj4YTSckUB4+HKDRPFC2pCQzLY0eGekFAJ2dt6ys1P38LHR0lAiEcz//3BsUZI/HH7K11aypmfIxGuU7a2vr7cXbVfaojBcTExMTPT29BeG758/B2Rn27IEffwQCAbq6wMEBnJ3B2RlIJACA8+fh7FlwdgZHR+BwXi/FZMLVqxNVKysLkZHg6grq6tDXB3T6lDZqVqFSqRYWFiN1IAQT+87b2/ujjz6iUqlRUVGffvqpoaHh3r17t23bVlpa+lbfUanUJUuWXLx4cdu2bXv37m1oaKisrPz222+/++479JUMoXF2drayssrJyRH3EZguI33HYDC0tbW1tbXPnDlz9uzZ82MwNDTk8Xh2dnai9V1PTxsA0OlXMzKYsbEBJJIdiWTX1MR98WJo9+5/o+yuXUt5vEpnZ+3hzaaM9d3Nm1kAkJcXf/bsdhLJ7tq1ixcu7J1qQEb57tq1ayggZ86cOXfu3NiYXL161cDAYLq+S0hIiIqKipkBsrKyROU7hLf3ayWVlIC+/uuZaPzd8+cBjT0eHg6+vgAAPT2wfj188QXU1MCxY7BvH7BY4OAA+/bBvn0QGQmXL8MHH8C+fbBqFWzYAK2tYGv7us7z52HfPggOFmIbZwQymezl5SXE6P6jKC0tpdPpLS0tTU1NdDq9oqKCz+fT6XTBd3YYDEZ2djafz09OTqbT6ahXBJ/Pb29vp9PpxcXFfD7/9u3bdDq9qKiIz+ezWCzBU+DY2Fi0iOCdtrKyMjqdPvnbz/Goq6uzsrIqKSkR93GYFlN9fjfTvnv58reCguSCgmRvb7OurpaDB2VQtqAguampSuA7T0+TCXx36dJxtEh9felUAzLV53cqKioi8F10dHRISEiYSImNjc3Ozs7Ly5sF3yHOnwcZGVBQADMzePQIAODFCyAS4dIlGByENWuguxsePoS7d6G6GrhcsLAAJhPk5KC7GywtISgI7t4FFRUAAENDKCqC7m4IDITkZCE2U8SwWCwnJ6fOzs5pWuOdpqWl5fTp0/X19eI+GsIjRt+Vl+eGhBCcnLT7+m4DQEwMMS+Pjccf1NBQ0NBQSEkJf/HieVlZLspqaCgMDT1PSgpF0/393c+ePSGTHTU0FI4elbt8WZdCcaqouA4Ag4NPw8LcUDEPD6OpBkScvmMwGJkjwLDXKS0tMzU1Mzk5Mzk5MzExMz4+k83OZLEyo6Mzo6IyIyIy6fRMGi0zLCwzNDQzJCSTQsmkUlPZbLZo27OIN/oO3dYJ7u9GImjPrl//ek5VFfzwA+zcCVJSkJT0er6rK8TGwsDAa99paAB6u6mzE8T+JvujR488PT3DwsLELZw5wdq1a8V8PKbBSN+RSKRNmzZt2rTp66+//vrrr7ds2bJly5atI9ixY0dzc7O9vf3C6Y+Cx+MFAVFUVBwVkK1btxoaGhoaGorGd2w2W1Di1St49ux1un8ffv0V+Hzg86GjA3g8qK2F0lK4fh1yciA5GVgsiIqCsDCgUoFEAh8fIBJ/TUpKmlHf3b4N9vbg4QEeHq9br+P5bu9e6Oz83XdUKly5Ah4esHPnuL5jMsHNDTw8wMnpD79+iIWamhp1dXVxe2aucOnSpXe3W/JI3zGZTHT1Xrhw4eLFi+gVUasR2NradnR0ODs7Lxzf+fv7GxoampiYmJiYmJqajgqIlZVVUFDQhQsX5pzvAgLupaamzoTvmpqgvf319K1bwGQCk/k6W1YGv/wyuvzt28BkQn8/YNjvM9ns1wv29Lye39AAXV3w/Dnk5r4uk5oKTKb4ZQei+ObOfILH43377bfiPiZCMqo9u3Xr1kvj88knnyw03x05cuTUqVPjBcTY2Hjnzp0i811cHHtwEARpOr4LDLyXlpY2E75baBw9erSkpETckplD9PT0BAcHX534R/e5yijfaWhoZI6PtLT0AvSdt7f3eAGJjIwUse+ePIGxSQjfkUj3Bb/MLmTfdXV1dXd3D0yDQ4cONTc3t0oYAZvNdnFxETqknZ2dHA5HLGMTjPQdkUiUk5OTk5OTl5dfs2bN2rVr165du24EmzZtmoO+a2mpBQA+vxN1P54mo3xnbGyMAiKIybo/cu7cOZH5LjaWPTAAb0xT9V1Q0IOcnByJ7y5duuTk5IRJmDPExcXp6emdPHnyypUrg4ODs3w+jPRdTEwMGgvAxsbG1tbWwcHBwcHh8uXLLsO4urrOQd9paq4HgPz8+I6OxunXNsp3QUFBKCA2NjZ2dnYODg4ufyQ8PFxkvmOx2D//DG9Md+5MzXdk8kOR9zd+56iqqtLX16fRaOK+xiX8DoVCOXDgAJ/PV1ZWvnfv3iyfEqPas19//bXZ+CxdunQ6vnv48B6BcJZAOHvrVjUAtLXVo+zAwN2ODh6adnc3BICyslyUDQ11RcuGhBAIhLOpqTSUvXJFn0A4W1qazWB4qqouio8Pzstjt7c3AkBTUxVa9tGj+y0ttWjay+viJAMytj177Nix8QJy9uxZUbZnWSw2ktoEaZK+o1AeFRYWLnDfxcfHnzhxQtwXuIQ/MKd8p6WllT8+MjIyvb29BAJBON9ZW6vX15fW15c6O+t0dDQ5OJxEWSuro2VluZcuHa+vL+Vyi1xczkRF+QYF2dfXl2Zns8LCroSGEnJy4urrS5lM35wclrOzTk1NcX19qZ+fJYZF/vijbHd3K+pvfPcu38XlDKrW2vpYYWGqs7NOfX1peXkeMulbGes7f3//8QLCYrF27dplamoqGt/FxLDb22Hi1NY2Wd8VFxdP4DsXFxdp6X319TCPk4+PxHdzDlnZg7m5/dev392w4URJyYNZPiV8fX/3na+v7+effy4YsGPVqlWrVq36Ypgvv/xSXl6ez+e7uroK5zvU8ASAnp62O3d6DA13C+aXleX6+OAB4NmzJzo6W6OifFNSwgGgvr7U1VXPxeXMoUOyGhoKx46tychgnj6t+Pz5IADcudPz5MkjVC3yXV/fbTz+oKDawsJUEskOAAYGftHX3ymE7/T09KSlpccLyJdffqmtrW1mZiYa30VFsevqYDKpuvotvgsJeVpWVjaB72RkZHC4BzgczN/0ePFiF3t7e3Ff4BJ+h0Aof++9l2I9K373XVxcHHpmhx7VeXh4eHh4eHl5eXt7+/r6EonEwMDA6fjOy8s0PZ2Rns7w8jLt7e3w9DRBWU9Pk4l9l5hIZbECUOHbt5uDgx1TU2np6YzAQNuODt6BA9JVVYXIdwMDd729X6/F29ts+r4LDQ11cHAgEAgEAsHNzc3Dw8N7GH9/fyKRyGazRea7yEh2cTFMMhUVQX7+uL4LDX1WWVk5nu/Onz//4Yc2ONxzcStpRtPtLVu2iPsCl/AHrKyq/+u/5orv3NzcNmzYMPaVeAEff/zxdHz35MlDBsOTwfDs7m4FgN7eDpR99Og+n99ZWXkdAF68GMrMjOLxKtva6gHgl1/4paXZAJCezkCFm5u5AMBkejMYno2NFQAQHe1XUJBSVXUDvZfW1dWCSj59+rinp626uggABgef5uTECuG7I0eOHDx4cLyAaGlp7dq1S2S+i4hg5+fDlJJwvlNVVb12LT83F+ZxYjJF5ruwsDCFYXbu3Dn9CrW1tcPCwsb7a3h4+OnTpydTDx6Pv3bt2sg5KioqCgoKhoaGgjl2dnaXL18WelMxDDt27FhMTMx0ahBw4MABJrM3NvZXlD7//OwsnxVOTlN7fjcd370TCPH8TmS+o9PZaWkw1fRG34WHD9bW1k7gu/z8/NkO7exy+7bIfBcYGLh9+3YWi8ViseLi4hISEtC3SyIiIlCBqKgoGo0WHR2NYVh0dDSNRouKioqLi0tMTMQwbOQ3UJhMZnx8/NatWwkEAoZh8fHxaD6qh8Vi0Wg0V1dXVVVVwdpHrS4uLg5lo6OjtbS0Lly4gFaHYdjhw4eDgoJYLJaurq6trS2GYcnJycePH9fR0UlJSWEymahCJpOZkpIi2KT09PSJ92jz5s2C+dNETk6ura1N0HV59oePH/l7hZeX17Jly6SlpdHHt0Y+tFq9evXq1aulpKQWmu90dHRWrlw5NiAoJqtWrdLQ0BCZ72g0tmBAzSmlmBiJ70YjWt8pKCjY29vb29u7ublZWlouX75cUVFRRUXF19eXTCarqakpKiru37+fQqFs3rx5/fr1WlpaNjY2enp6cXFxhoaGy5cvl5aWVlRU3LNnz6lTpxYvXrx+/frY2FhtbW1FRUVFRUV3d3cajXb06FFFRcW1a9cKfJeQkHD27FlUZs+ePZGRkZqamih74sQJLS0tWVlZRUVFNTU1MpmMFomJiTl58qSHhweGYcHBwStWrJCSkgoNDZWRkUEFZGRk/P39Fy9ejOohEAgWFhYT79G89N2NGzc4HA6Hw6mqqqqpqeHxeDwer729vaOjo7u7W7CRE/vO39/t+vXEdzeZmemP9B0KCJfL5XK5dXV1PB6vY5je3l4UEJH5LiyMzWCA0Eniu5GI1ncrV67U1NTU1NTU19e3tLTU1dXFMCw0NHTr1q3q6uouLi4YhlEoFHd3982bNzMYDLSgkpKSv7+/goKCjo6OpaUlhmFXr1794Ycfvv32WxKJ5OPjIyMjc/z48ePHj0tJSZmYmBgYGGAYFhQUJPBdTEyMpqYmKpOUlEQmk9H0mTNnMAzT0tJCP8gQCISjR49iwzd0aHsQ58+fv3jxYlpa2ijfCRrmn3/+uYWFBaowNDRUWVn56NGjKioqx48f37Ztm5aW1rz03X/+85/Tp0/r6urq6uqigS0FYwcIXpVHqKqqTuA7WVnchg3vcFq+HId8t2jRIkFA9PT09PT09PX1BWMHmJiYmJmZoYBs2bJFNL4LDWWTyTDNhHxHoz1vaGiQ+E4kV2lgYODIx3bj+c7Hx8fKympKvtu4cSO6bXR3d3+j7zAMYzAYqMz+/fsxDAsODra3t7e0tET3d6N898MPP3h6eo7ceOF8p6mpiVY6X+/vPDw8XCZNdHT0vPcdgUCYfEDQWHPT9V1ICNvbG0SSaLQhHo8n8Z1IrtKgoKDFixdLSUlJSUlt2bLF1tZWX18fw7Dw8PCdO3fGxsZ+9913UlJSe/bsiYuL2759u8AO0dHR69ati4qK0tHRWbJkiZSU1I4dO1gslpqa2sqVK5OTk42MjFC127Zti4+PV1dXl5KSWr58+d69e1ENNBpNahgKheLm5oamFRQUULXOzs4Yhl25ckVLS+vw4cMffvghKoDmYxhmbGz873//e+SyH374YWBg4L59+1CBNWvW2NraItWO2iMpKSljY+Pt27dHRkaKJJJzx3fZ2dnZ2dk5OTmCAXEnZjzfJSbG9fXdfneTh4cb8l1eXl5WVlZOTk5ubu5kAiIS38V4e/N9fPpR8vP72d//LpH4C5H4a2DgPRJpICjofnDww+DgRxTK45CQJyiFhT0TJBrtOUoJCU8kvhNvf5Tw8HA3N7dvv/0WwzDB/d0CZ+74zsfHx9/fn0ajJSQkjFVebm5uVlZWWlpaQkICGldt3v9ekZaW5uXlRaVSWSyWYKgRDMMEwcnJycEwLCkpKTY2NiMjY7q+i46OZrPZCQkJycOkp6dnZGSgf0T5+fk3btwoLCzkcDg3b94sKyurqKioqKiorKysGaa2trZhBBUVFRP57nw+eMI8Trdtxew7Nze3Q4cOsVgsDMPc3d2JRKIYN2aOoK+vf9fu7kOHhyhd+/e1WT4rEk699t1Ybt68WVNTk5mZmZ+fn52dnZKSwmKxQkNDo6OjF4LvxgYkLS0Nw7DExESUzcjIYLPZdDo9ICAAzZyW70YNVydyRvsOlw84mMfptqS/8Zzkt//+TYxnRcJwf+PAwEAymRwZGZmcnIxuYWpra9va2tCoQtnZ2cnJyVFRUWQyOSIiYiH4DsOwgIAAGo3GZrORlGJiYurq6gRewjAsNjY2JCTEy8srPj5+Wr7Lzs6efLN58uRez82+np1zPWek7/T09Oz/x34AN/DiTy/gPZivaei9oeB/BBsZGYn5+pbwRwb/3yA6QGI5/RL+8tp3KSkpqampGIYJPohaUFBQUVFx48YNZLfs7OzMzMy0tDTUdpv3vsvNzUVtyqysLPQPAEXgd5nk5mZlZaWnpycnJ6MG75z7/qxum+6qh6u+7f9W4DtXV1fBqwKysrKzHt5ZRTI+yhxERUUFfV5SvOOjoNdmSSQSi8VCtxrZ2dnY8OMq5DsMw5ACFoLvkpOT7ezsfHx8GAwGUnx+fv5I3+Xk5GRkZKSmpiYkJKD5wvgOdWyZBdatW2dubh4WFsYZ5p3+0NRkkPhuDjJHxoMik8noo+aC9mxcXJxLyoW0/MT84fZsdHQ0hUJhMpkLwXcYhpFIJAaDER8fL7gJu34dX1DwetjgjIyMuLi4sLAwX1/fhIQEIX1nbGx8cZhTp07JysqiaW1tbWlp6YuiQ0FBYaGNf9fe3m5iYoKOpYQ5AoVCWbFixcmTJ5cuXToXfJeSkoJ8h2EYpdw1ozA1f/j3ipiYGCqVunB8FxQUNMp3dXWEwsLckb4LDw/38/MT3nerV68WjDD1+eeff/DBB2haWlr6f//3f78QHf/85z8Xmu8AoKurCzVMJMwRkpKSTpw4YWhoyOFwXrx4Mcvng8B3SUlJgsdVYx8EoWdV2EJqz+bk5CQmJqalpWVmZr7xtwTUnk1JSYmPj59ye3ZgYODYsWP+/v6ouwmJRLIZg52dndMYnJ2d3dzcrl696uXlhcbqIg4TGBhIGYZIJI6t0N7ePjAwUDS+ew6gAPAZwH8DrAbQmHoNNwAUAK6/rRgR4L8BaoXZRsTL6aGhoVFcXNwnYQQsFsvS0lLokL548WL2TYcQ+M7JycnV1TUoKCg2Nnbs5Z2Xl5eTkzPx7xVeXl6bN2+eN75LTk52cHDw9fWNiIgQPL974/+AlJQUdAM4Bd9RKBRZWVlVVdXvxmH3OOwdh/3jcODAgYPD/Otf//Lz8xPl/V0AAA6gajhbDsAEYAJwACqGp0emQoAaACZAAkAPABOgByBxRIFYgP4R2WwAXwAcQM10t3Q6rFmzRgTfMZwvdHZ2urq6RkZGivOQCIvAdwEBAag/SlJS0tj+xllZWUlJSUwmMygoaLz+KCdPntywYcMbL+93iJHtWSKRGB4ezmaz33jPi2EYi8VC/VGm/D4ZhULZuHHjsWPHjo/DyXHQGYezZ8+eexPnz5/XH+bjjz+eQd+VAigAGAJcBJAD2ACAA3AB0ADAAZwFsAKQAXAE8AD4GOAQAA4gCeA/ALIAHgDyAP8H0AngAeAB8BHA1jnhO1dXVzKZLG7PzBXmx/e2qVRqWFhYTExMamrqWN9lZ2enpqayWKywsLA39je+cuXKyZMnK+bC1+Cnh8B3GRkZ6MeZxMTEN3YayczMjI+Pp9PpgYGBb+xvbGpqampq+uuvv45dC45CoWhra8fExMTExBgYGODGsHjx4hiRsmvXLhwON4O+CwbAAWwCUBzRw/MxABMAB5AL0A6AAyAAAMBHwwWQ79DI/ocB/g8AAFgAOwH+Z674rqamRl1dXdyemSscP3783b3OBb6LjyMQzhcAAA2/SURBVI9H74plZma+8X0y1Jgd732ynTt31tfXi3tvRIDAd9nZ2Ww2Ozk5GcOw8Z7fpaenJyUlsVisse+T2djYGBoa8vn8N64FR6FQlixZggbSW7FihZ6enqKi4kcffbR7924NDY1Fixb5+PigAfb8/f03b958+PBhPB6/evVqwQh8np6e33zzzf79+y9duvTFF1/Iy8uHhISsXr3a1dX1u+++++KLL2RlZVENDAZDTk5uxYoVf/3rX5HvvLy8tm/f3t3dPd1ojfRdJMDfAegAXIBmgDPC+q4A4H8AXAE+myu+e/HiBZlM9vT0FLdqxE9jY6OKioo4D8b0EPguIyMjMzNzvH7+eXl5ubm52dnZGRkZqHEn8N21a9e2bt36888/i3tXRIPAd3l5eWhnxxtDQdAHG8Mw9BYK8p2np6ejo6Ompubjx4/HWwuOQqGYmJigu8SsrCw00l5JScn169c5HE5+fn5lZSWXy+VwOGVlZZWVlYWFhWgQPlSyoqKCy+U2NjaWlJSgcQpv3rzZ0dFRV1dXX1/f0dHR3NxcWFhYX19fVlYmOFm/+uorPz8/Nze3n376qbZ2Gj8BCEgDUANoG84GAqgBqAF4A5AB1ACeAdwAUAOoAegHUANgAQDA8eGSNwFOATgAAIAbwDGAmuE/qQFYACQDqAF0iGBjp0NOTo6dnR2PxxOja8ROcXGxnp7enTt3xHwwpoHAd35+foGBgQwGIzEx8Y3P7xITEyMiIgICAuh0usB3BALhp59+am5uFvd+iAyB79LT0319fUNDQ2NjY8d7fhcTExMcHOzh4REXF4d8t2HDhh07dhw+fHjitfzuu9Mlp7OyslAH4KKiGykpKXl5ORxOSVVVVXl5eWFhYUVFRVFREYfDKS0tLSwsbGhoqKur43A4tbW1paWl5eXlyHdVVVUtLS3l5eVNTU3IjDwer7y8vLOzs7u7m8vltrW1ffXVV66uridOnCguLp6daM4nUlNTraysrly5Im7tiIG2tjYLCwtra+uGhgZxH4dpIfDdVMnLy/vggw9OnTpVVlYm7p0QJROMF/BW3N3dP//88/Dw8MHBwYnX8rvviI3E0tJS5Lvi4sKsrKwbN64j31VUVHA4nMrKSjQgSnl5OYfDaWhoqK+vr6ysrKurq6qqQl4rLS2trq5ubW2tra29detWfX19Q0PDrVu3amtru7q6enp6mpqaOjs7v/rqK1VV1Xl2wGaTGzduhIaGfv/99+Hh4eJW0OxhbW39448/stnsd112AJCQkLB8+XICgRAxRQ4ePCglJVVVVfX2dbxTIN85OTlNNSDBwcFycnIGBgYTNGMF4Gg02rJlywRfBhnLeN2Gv3wTq1at+vLLL+XehPwIPvroo7a2trdunIQJGBoaam9vt7Ozk5eX53K5zc3NDg4OK1eubGxsFLeXREBvb294eLi8vDyLxWpubo6IiJCXl4+Jiens7BR34EXDkydP8Hj8p59+KjVFFi1a1NPTI+7NFz0PHz7U0dFZvnz5VAMiJydHp9Mn+YYMbqZ3Q8IsoKamhkYzNjc3j42NFbesRACHwzly5AgA4PH47du329raijvGEuYDC953jwCSxL0NImXt2rXilpUIIBAI4eHh4o6lhPnGgvfdE4BccW+DSAkPD3d2dha3r6bL7A+wLmEh8BbfCd40RNMA8OrVq1evXk281GTKiJhXAI4ACgAKAM4ArwCOAygAXAJ4BfASQHH4r2UAXcPTCgCNAEYAAPASYBeAAoAvwCuA74cLpM3qfkyf7u7u3bt39/X1iVtZwvPTTz9VVlaKO5DC8+rVK8FVM/ZPb7w0xHDJiAnx7ulEvuvu7tbU1NywYYOurm5fX9+ePXv6+/sLCgqCgoImrrSoqMjIyEik2/k2WAC+ABUAjQAAcB4gHKACwBHAF0AXoASgAqAfAAAOA1QAVAA8AOgG2AcAAPsBUK9nV4BYgPXDNWsA8GZ1V6ZPUlISHo8Xt7WEpKqq6vDhw48ePRJ3FIXkyZMnfn5+GzZs2LBhQ3V19ai/WlpaZmVljV3q8uXL8fHxs7KB4uThw4dXrlwJCAh49uyZWDZgIt+Zm5vn5OQAQGVlZWpqKvJdZ2cn+t/77NkzKpVKpVLb29ufP39OHeaXX36xsrJSVVW9devWLO0EIhxAB+ACQCHAeYD9ADoAOgA5AACgD6AD4AzQC3B3+E+eALfmoe+4XK6VlVVFRYW43SUMenp6eXl54g6h8HC53NOnT6NpZ2dnALh58ya6NHJzcy0tLU1NTalUanZ2NioTGRlJpVIPHDgQHx8/ODgouI4ePHjQ19eHpu/du3fnzh3B9ZWYmChYXUJCAgBwOBwqlRobGwsApaWlVCo1JiZmtvd8EuTn51+8ePH48eMNDQ39/f2CnQUAHo+HpgXeT0lJQXPQKwl0Op1KpaJ/IREREVQqtaqqKisrS9ANJScn5+HDh729vWip+/fv8/l8QQBRmUn5DoF8l5KSYm9vDwAODg5o9Cdra+vW1lYZGRmUNTMzMzU13bZtG483i54oADAAMAAwA8gDuA6AH56TD+A9PO0E0A1gPpy9MsJ3aQAmAAYA9gCt77bvAMDBwYFGo4nbXVMGwzA7O7t3ur/F3bt3XVxcDAwMDAwMhoaGysrKnJyc0KWRkZFhaWlpaGhIJBLd3NwwDCORSD4+PkQiUU1NLT4+3tHRUTCoWn9/v7m5OZq2sLAoKSn55ptviETizz//7OnpyWQyAeDq1atMJvPmzZvOzs5EItHLyyssLAyPxxsbG9PpdHFHYjTPnj0zNzcvLCzMysqytLQsLi7etm0bkUj09/d3d3cnk8nHjh0jEomenp4MBoPFYnl4eKDd53K5vr6+vr6+RCLR3t6+sbER2aasrCw1NdXOzg4AMjIy3Nzc+Hy+hYUFWsrKyqqgoGD79u1EIvGXX35B2yC871auXKmkpKSkpLRo0aLKysodO3agYuvXrxdDe5YPUARQBCBoQNQMz+kDqB2eRtfRzeHsPYDnw01gACgHKAK4DQAj6mkGeDp7+yEqOjs7T506VV9fL26DTY2AgIBr166JO3jT5c6dO0VFRUVFRSdPnvz5558tLS2VlJSOHj0KI9qzCQkJzs7Oe/fu7evrg+H27I0bN9A1hW5VPvjgA5T98MMPS0pKDAwMUP0VFRVnzpwBgE2bNg0NDYWHh69YsUJJSWn9+vU//fQTHo/PzZ2Lv8E9ePBAsEf//Oc/i4uLDQ0NAeDly5cbN24kk8noQVlNTc2pU6fa2to0NTWVlJQcHR0BYMeOHZs3b1ZSUvrPf/6TkZGxfr3gfgTQtIuLS1xc3L179wSrWLRoUUFBwYULF0Zuw0S+8/DwQL09GQwGhUIZ5bt9+/Zxh7lz584o32lpaT148EDEAZMwFfT09NLT08VtsClQWFiopaU1NDQk7shNi6amposXLzY3Nzc3N//www8PHjyoq6vjcrkZGRkWFhajfHf27FkOh9Pc3HzhwoX4+Pi2tjZ0QZ09e7axsfHAgQMoW11dPdJ3L1++DAoKev/999EYn/Hx8a6urqhkR0fHnPVdfX29hobGkydPnjx5sn///ujo6OPHjzc3N/N4vEOHDpHJZCcnp+bm5szMTCsrqzt37tTU1HC5XBKJRKfTtbS0iouL0T4+fPhwpO86Ozvff/99W1vb33777cGDB4cOHULFampqpuY7ALh8+bK6ujr6l+vm5nb//v3KykoWiwUADx48UB+mvb3dyckJLWJlZdXU1KSurn79+luHDJYwsxgbGyckJIjbY5PF19fX399f3DETAfn5+ei6GBoaKigoQNPGxsYAEBkZWVNTAwBlZWVxcXEAcO7cOVSgtLTUwMAATZeUlABAQ0MDympqajY3N4eEhAhWkZOTo66u3tLSgrJhYWGopK+vL4PBqKurE8Nuvw0rKyvB9NDQkKqqqrS0tLq6+rFjxwCATCZv3LhRXV3d3NwcRuyRn58fWuTUqVNoTnV19ciq7t+/r66uHh0djbJ1dXWo2IkTJ3g83qhenAu+/928pr+/X0VFReRiampqIhKJIq923bp14g6YhNlD0J5FCNqzM4rEd/OZ58+fBwYG+vr6ilZMmpqavr6+gYGBIqzz3Llz+fn54g6YhNljYGCgsVHw7By6urq6urpmeqUS381zBgcHvb29qVRqT0/P9K3U0tKioaHR3t6elpZmaWl5+/bt6dfZ3t5uZmaWm5u7QDrcShAjEt8tCAgEQkhIyDTFVF1djcfjuVwuqpNOp3t4eExzeIKWlhZnZ+fk5GTxxkfCAkHiu4XC1atXrayshNYTj8eztrYuKCgYWSeNRrOxsRH6E0Le3t7W1tZsNltcMZGw0JD4bqHw/Pnz2NhYR0fHpKQkIdykra3N4XDGVvv06VNvb28hlHf16lUSifTGl6skSJghJL5bWAwMDOjr63/11Vetra2dnZ1vtVJ3d3dra6u6uvoEnzd9/PgxgUCIjIxsbW2djOlaW1sDAgICAgLeOvq2BAmiReK7hcizZ8+UlZUvXLiQmJg43u1eTk5OYmKiq6ursrLy2Pfex2JjY/Pdd98lJiYmJiY2NDSMrbC6ujoxMTEhIUFZWfnq1auzsJsSJIxC4ruFy/Xr142MjIyNjV3ehJmZmZGREYPBmHyFjx8/NjIyMjIyunTp0tgKbWxsjIyMRvV3lyBhNvn/SswzVSdQfV4AAAAASUVORK5CYII=" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Figure : Forwarding to a third host &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
These days of course, we have IPSec (and also SSL/TLS) so these types of SSH sessions are becoming less common. They do still offer an administrator an effective (and simple) means of securely connecting to remote servers and should not be discounted fully yet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-6838519150196121202?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bVGmZFGx8VNKIpkt5Xew0AtC5RE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bVGmZFGx8VNKIpkt5Xew0AtC5RE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bVGmZFGx8VNKIpkt5Xew0AtC5RE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bVGmZFGx8VNKIpkt5Xew0AtC5RE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/P3QF07uUb0I" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/6838519150196121202/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=6838519150196121202" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6838519150196121202?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6838519150196121202?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/P3QF07uUb0I/ssh-port-forwarding.html" title="SSH Port Forwarding" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/ssh-port-forwarding.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0AEQXc_cSp7ImA9WhRVEEU.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-8868499787264199408</id><published>2012-01-09T17:15:00.001+11:00</published><updated>2012-01-09T17:15:00.949+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T17:15:00.949+11:00</app:edited><title>A little on Metasploit</title><content type="html">&lt;p&gt;What is Metasploit firstly?&lt;/p&gt;  &lt;p&gt;Well, it is a simple way to exploit vulnerable systems. &lt;/p&gt;  &lt;p&gt;I have a few things to try and do this week. I have several Metasploit posts to complete as well as a couple on IPv6. &lt;/p&gt;  &lt;p&gt;First… Metasploit has been around since H.D. Moore released it in 2003. It has grown immensely and an entire community has arisen to support and develop it further. It can run on: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Windows, &lt;/li&gt;    &lt;li&gt;Linux, &lt;/li&gt;    &lt;li&gt;BSD, &lt;/li&gt;    &lt;li&gt;as well as on MacOS X&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Where to start…&lt;/p&gt;  &lt;p&gt;I would recommend starting with &lt;a href="http://www.irongeek.com/i.php?page=videos/metasploit1"&gt;IronGeek’s tutorials&lt;/a&gt;. These are an excellent start to understanding Metasploit. They start on the web interface which I do not like as much (I am still an old fuddy and love CLIs).&lt;/p&gt;  &lt;p&gt;Next, &lt;a href="http://metasploit.com/download/"&gt;download a copy&lt;/a&gt;…&lt;/p&gt;  &lt;p&gt;I will run through this in Windows for now… Linux later. Just:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Goto the site:&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&amp;#160;&lt;a href="http://lh6.ggpht.com/-MC2KK3XfhRQ/TwqF03i4LbI/AAAAAAAAGHM/48diyW3YKZ8/s1600-h/image%25255B4%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-kWhaZi1Ui10/TwqF15sT16I/AAAAAAAAGHU/ksP5arjbSDM/image_thumb%25255B2%25255D.png?imgmax=800" width="368" height="168" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Click download for the platform you are using. Save the file in Windows.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-6HYOKCNSy3k/TwqF2nBrsMI/AAAAAAAAGHc/FgN8AP4fgB4/s1600-h/image%25255B7%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-i5p-OjHATYY/TwqF38PnzBI/AAAAAAAAGHk/NEMfd4Xb9yE/image_thumb%25255B3%25255D.png?imgmax=800" width="244" height="116" /&gt;&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Install it in the normal way.&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Windows is rather simple – just a standard installer and you are done. &lt;/p&gt;  &lt;p&gt;I will be stepping through setting up and using Metasploit a little at a time this week. I am doing Windows this week and Linux next.&lt;/p&gt;  &lt;p&gt;In addition, you should really go to &lt;a href="http://www.tenable.com/products/nessus"&gt;Tenable Security&lt;/a&gt; and download Nessus. NMap is also a must have. &lt;a href="http://nmap.org/book/inst-windows.html"&gt;The windows installer is available&lt;/a&gt; here.&lt;/p&gt;  &lt;p&gt;Some of the other tools that work well with Metasploit include the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.sensepost.com/labs/tools/pentest/bidiblah"&gt;BiDiBLAH is an Automated Assessment Tool by SensePost&lt;/a&gt;. Now end of life and depreciated, but a good toy to play with and learn.&lt;/li&gt;    &lt;li&gt;&lt;a href="http://spyeti.blogspot.com/"&gt;Yeti&lt;/a&gt;. Early days still, but well worth watching.&lt;/li&gt;    &lt;li&gt;Nessus of course. Well we need a way to find what is actually vulnerable. Just network vulnerabilities really, but a start.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Tomorrow I will do a step by step install and configuration. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-8868499787264199408?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Ql4mn_xURTZi6XzKa_1fiDCMYa0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ql4mn_xURTZi6XzKa_1fiDCMYa0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Ql4mn_xURTZi6XzKa_1fiDCMYa0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Ql4mn_xURTZi6XzKa_1fiDCMYa0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/61rQ0sf1lpI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/8868499787264199408/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=8868499787264199408" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8868499787264199408?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8868499787264199408?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/61rQ0sf1lpI/little-on-metasploit.html" title="A little on Metasploit" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh5.ggpht.com/-kWhaZi1Ui10/TwqF15sT16I/AAAAAAAAGHU/ksP5arjbSDM/s72-c/image_thumb%25255B2%25255D.png?imgmax=800" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/little-on-metasploit.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QEQHczfSp7ImA9WhRVEEo.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-4654314108051185315</id><published>2012-01-09T14:07:00.001+11:00</published><updated>2012-01-09T14:21:41.985+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T14:21:41.985+11:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="plagiarism" /><title>What is plagiarism?</title><content type="html">&lt;p&gt;Well, I have a new port and not the IPv6 one I had planned to start this new year. I found it surprising to come back from a break &lt;a href="http://securityerrata.org/errata/plagiarism/it_regulatory_standards_compliance_handbook.html"&gt;accused of plagiarizing&lt;/a&gt; material in one of my books.&lt;/p&gt;  &lt;p&gt;It is surprising for a couple reasons:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;I am strongly opposed to the unauthorized and unattributed use of other’s works. &lt;/li&gt;    &lt;li&gt;I use &lt;a href="https://turnitin.com/static/index.php"&gt;Turn-it-in&lt;/a&gt; AND have a subscription to &lt;a href="http://www.grammarly.com"&gt;Grammarly&lt;/a&gt; (which includes plagiarism checks). &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Having used these services now for six (6) years, I found the accusations surprising. That said, I will go through each section one by one. This will of course take time and I will offer the supporting evidence this week as I progress through it.&lt;/p&gt;  &lt;p&gt;What I have done is missed the attributions for a total of under three pages of a 750 page book. The reasons are not excuses, but are offered below. &lt;/p&gt;  &lt;p&gt;Mostly, I have self plagurised a few sections of what I have created as far back as the 90’s and which has been re-used since. Not all of this material is easy to find in a Google search, but I will add the originals of this material. &lt;/p&gt;  &lt;p&gt;I will start with the areas I missed and did not attribute well. That is first the &lt;a href="http://boran.com/security/IT1x-3.html"&gt;IT Security Cookbook&lt;/a&gt; by Sean Boran. &lt;/p&gt;  &lt;p&gt;The section I used was from notes from a course I took in 2002. I did not reference this correctly and the notes I have are clearly copied. I am surprised that neither Turnitin nor Grammarly noted this. This I missed badly despite using these products.&lt;/p&gt;  &lt;p&gt;The section “Identifying Vulnerabilities” (1 page of list on pages 286-287) should have been referenced. I missed this as well (as did the checking software).&lt;/p&gt;  &lt;p&gt;I cannot excuse this but will say it was time constraints that led to it being missed. A shame in more ways than one as a whole set of pages were dropped that did reference that paper. The chapter was cut short and ended not having an entire section (one I think was necessary) on testing. For this, I offer my apologies to the authors of the paper as I dropped any reference to them and this was a paper that should have been linked (and was at one stage). &lt;/p&gt;  &lt;p&gt;This was originally chapter 15 but was merged with another to make chapter 11 without much of the material (and some referencing). I am good at writing voluminous amounts, but I am not good at editing my work down to a smaller size. When the page count was already at 750 and the deadline was approaching, I should have checked the editing more thoroughly, but losing pages and hence footnotes and references is not my strong point.&lt;/p&gt;  &lt;p&gt;When writing a book with time constraints, it is possible to miss many things. Hence why I use these services and why I was surprised I have missed a reference. This was inexcusable, the others are less of an issue and will be addressed below.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Page 13&lt;/strong&gt; has a section taken from COSO. This could have been referenced better, but it is referenced. The text from page 13 of the book states the following:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;font color="#0000ff"&gt;The Committee of Sponsoring Organizations of the Treadway Commission [COSO] defines an Internal Control as follows:&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;font color="#0000ff"&gt;Internal control is a process, affected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;So yes, I have taken material from COSO. I also referenced it. I saw no need and in fact a detriment in not using the material from COSO as this is the &lt;u&gt;Gold Standard for Internal Auditing&lt;/u&gt;. This is what referencing is for, to show where we have sourced material.&lt;/p&gt;  &lt;p&gt;Page 16 and pages 46-47 come to a standard refrain used to and spoken by auditors the world over. I have not seen nor even sighted “Ethics in Quality” by Mundel. &lt;/p&gt;  &lt;p&gt;I should have started that the original source is unknown as it is definitely not something that only dates to 1991. These statements on objectivity and ethics have been a professional refrain for at least 50 years now. It is something that has been used by the &lt;a href="http://www.google.com.au/url?sa=t&amp;amp;rct=j&amp;amp;q=objectivity%20is%20an%20independent%20mental%20attitude%20that%20you%20should%20maintain%20in%20performing%20any%20engagement%20&amp;amp;source=web&amp;amp;cd=1&amp;amp;ved=0CCAQFjAA&amp;amp;url=http%3A%2F%2Fwww.theiia.org%2Ftheiia%2Fabout-the-profession%2Finternal-audit-faqs%2F%3Fi%3D1084&amp;amp;ei=7CsKT4SLD4LYrQf3venKDw&amp;amp;usg=AFQjCNGSsAs3Pcrk-SS_uO5Zxp6BMnZsSA&amp;amp;cad=rja"&gt;IIA&lt;/a&gt;, ICA and more for as long as they have been professional bodies. I could have written what I did and added a reference to the end after searching (I do this sometimes), but I do see it silly adding a reference for the sake of adding a reference. &lt;/p&gt;  &lt;p&gt;If I write something and it is a common definition, then I am writing it. I do not remember nor reference each and everything I have learned nor do I seek references having written something.&lt;/p&gt;  &lt;p&gt;Having worked in an audit firm for years, the previous mater was something I spouted without reference much to the consternation of others. So, it was not referenced, but no, I also have never seen the site of the supposed match. I can (as with the IIA site) find many others that are equally close to my definition here.&lt;/p&gt;  &lt;p&gt;The same also applies to page 27.&lt;/p&gt;  &lt;p&gt;I have not read nor still seen a copy of&amp;#160; &lt;a href="http://www.amazon.com/Sawyers-Internal-Auditing-Practice-Modern/dp/0894135090"&gt;Sawyer's Internal Auditing : The Practice of Modern Internal Auditing&lt;/a&gt; by Lawrence B. Sawyer. So I cannot say what is and is not close. &lt;/p&gt;  &lt;p&gt;What I can say is that these are common refrains drilled into Internal Auditors. I have read and re-read the same for years and having worked for an audit firm, it was not something I needed a reference source to write. Yes, there will be some similarities, these are common terms and definitions and I did not need to use a source to have these definitions. I suspect many dictionaries have both similar and differing definitions. Yet this does not make them plagiarized. &lt;/p&gt;  &lt;p&gt;If anything and had I referenced this, it would have been the following as this is a paper I have read many times and in detail to the point I can quote some sections verbatim:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;The Professional Practices Framework IIA ; 20 Questions Directors should ask about Internal Audit By Fraser and Lindsay, ECIIA Position Paper on Internal Auditing in Europe; and Practice Advisories 1000-1,1100-1,1110-1,1120-1.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Page 37 is one that should have been picked up by Turnitin. It was written as it was as I had memorized it.&lt;/em&gt; I had not noted the source as CERT as I did not obtain it from there. I had studied for my GSE-Compliance the year before and I knew this rote as it was at that time. &lt;/p&gt;  &lt;p&gt;I read and re-read the definition of many terms over and over in 2007 in preparation for my SANS GSE exam. By the end of it, I could state many things word for word. This was a remnant that slipped through. I am sure that others also existed, but they should have been picked up using Turnitin. I am not happy that this, nor even some of the other services used (such as Eve) did not note this. &lt;/p&gt;  &lt;p&gt;That stated, as similar to the cert definition as this is, it was not actually copied. &lt;/p&gt;  &lt;p&gt;It is also possible to “&lt;strong&gt;mine&lt;/strong&gt;” for text and ensure that you match something another has also written. &lt;/p&gt;  &lt;p&gt;Now…. some things I have written and found used against me. I hate the notion of self-referencing, but I have actually started doing this. One reason is that it is becoming necessary to defend one’s self. &lt;/p&gt;  &lt;p&gt;This applies to the accusations in the following pages which will be addressed individually:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;50&lt;/li&gt;    &lt;li&gt;60-61&lt;/li&gt;    &lt;li&gt;95&lt;/li&gt;    &lt;li&gt;96&lt;/li&gt;    &lt;li&gt;99&lt;/li&gt;    &lt;li&gt;545&lt;/li&gt;    &lt;li&gt;593-594&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;First page 50.&lt;/p&gt;  &lt;p&gt;There are two parts to this, the Wiki one and that from IBM. &lt;/p&gt;  &lt;p&gt;First to the Wiki page I have to note that using Wiki as an authoritative source is a means to getting into trouble.&lt;/p&gt;  &lt;p&gt;The original source of the Wiki section was the BCP policy document written for Mikael Michau at the Australian Stock Exchange Ltd in 1996/1997. This was way back, but like many of the documents I created back then, it was re-used and distributed widely. I have not seen Mikael for more than a decade, but I did enjoy my time back then at the ASX.&lt;/p&gt;  &lt;p&gt;Like many consultants, this was not the end of the document and with modifications, it became a part of the policy and procedures for News Ltd here in Australia when I issued a copy to Nick Rishbeth and I will admit I even added some of this to policies I helped create for Vodafone. &lt;/p&gt;  &lt;p&gt;So, did I copy this, well yes, from myself. Have others also copied it? Copiously since it was first written in late 1996. The first draft of the Wiki article to include this was published in 17 Jan 2005. DeMorgan was no more at that stage so it is difficult to see how a document I will show as a DeMorgan template could be construed as not being the original over a Wiki post.&lt;/p&gt;  &lt;p&gt;Back in the 90’s I contracted to IBM. They have rights to use any of the material they paid me for in any format. The other sites using this do not.&lt;/p&gt;  &lt;p&gt;I was a contractor for a small time with them (that is IBM and sub contracting through DeMorgan). The document that Wiki has taken some material from is actually an IBM sales and template document I helped create. The BCP section is mine. This template has been used by several consulting firms and has evolved into what I have seen as the “BCP Master Plan” used by a number of organizations.&lt;/p&gt;  &lt;p&gt;I will download, scan and display some of the old DeMorgan material later in the week. A waste of time, but it offers proof that this was the original source.&lt;/p&gt;  &lt;p&gt;Now to page 61. Here I have &lt;strong&gt;self plagiarized&lt;/strong&gt; some earlier work that has been around a long time. This was in part taken from policy work I completed for a firm I started and ran for a time, DeMorgan. This policy was written and that segment was used for the following organizations (as well as others) that engaged me (between 1997 and 2002):&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;HREOC (Human rights and equal opportunities commission&lt;/li&gt;    &lt;li&gt;ASX (Australian Stock Exchange)&lt;/li&gt;    &lt;li&gt;Dept. Treasury&lt;/li&gt;    &lt;li&gt;Several Credit Unions&lt;/li&gt;    &lt;li&gt;Mahindra and Mahindra&lt;/li&gt;    &lt;li&gt;Railcorp&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Some of the policy documents have been loaded to &lt;em&gt;Auditnet.org.&lt;/em&gt; They were loaded around 2002, so I have no idea how current the versions there are. &lt;/p&gt;  &lt;p&gt;Again, I will waste time showing that the origins of these was my time at DeMorgan.&lt;/p&gt;  &lt;p&gt;Page 110, again… materials issued to IBM were allowed to be used by IBM… but they are still a part of what I created. The RBAC points date to 1999 with the ASX yet again. &lt;/p&gt;  &lt;p&gt;Next 110-111 (Bell La Padula).&lt;/p&gt;  &lt;p&gt;ACTUALLY… the source is way wrong. There is a reason this is “some text”. We have EACH taken from Bell (one of the creators of the model). I did reference this on page 108, but also needed to ensure that more footnotes existed later to stop confusion. The text was taken from old class notes.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-C6sy0PkGTuc/TwpZziQ1A6I/AAAAAAAAGG8/311MqS75IjM/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-uKe0JI3PgCU/TwpZ08o7dqI/AAAAAAAAGHE/GyyjZ66BgZU/image_thumb%25255B1%25255D.png?imgmax=800" width="443" height="317" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;These have bounced around since the late 80’s, but I have NO idea which class I actually got this page from any more. I have seen it used in several Universities as a handout. It is DIRECTLY based on the paper by Bell but the person to first summarize this is anonymous now. It dates back to at least 1989 and being that there was no web, there is no way to trace it I can see.&lt;/p&gt;  &lt;p&gt;Page 545 came from a longer document I also self plagiarized. It was first created in 2006 for selected clients of BDO. It was updated in late 2007 for Microsoft. So yes, this was copied, from myself. I do not see small sections of self-copied text as an issue personally. When entire documents are resubmitted or at least large sections thereof, well that is another issue. &lt;/p&gt;  &lt;p&gt;It could be argued that I have not attributed the source where I leant this material. That is true, it was SANS. I could have stated that on each page nearly from the start. &lt;/p&gt;  &lt;p&gt;Page 541 was badly referenced not plagiarized. &lt;/p&gt;  &lt;p&gt;I contacted several people to get permission for using material in the book. RSnake was very good as were the people at FWBuilder and other sites. It was noted that I used material from CGISecurity and &lt;a href="http://www.Ha.Ckers.org"&gt;Ha.Ckers.org&lt;/a&gt;, just badly.&lt;/p&gt;  &lt;p&gt;I will dig up and link copies of emails and permission forms that I have received for this section. Each party was sent a copy of what I was doing and only RSnake at Ha.Ckers.org corresponded to any extent about the materials (and nobody noted the mission attribution for their material at the time).&lt;/p&gt;  &lt;p&gt;So I did miss the XSS refernce to CGISecurity, but so did RSnake. I had contacted Robert Hansen regarding the use of the material as I stated and did send a chapter for review. I was given permission. I still have this and will link the permission received for this later this week. So yes, my referencing was not up to scratch on this section, but Robert did not ping me for it before publication.&lt;/p&gt;  &lt;p&gt;More on this later.&amp;#160; &lt;/p&gt;  &lt;p&gt;So in a 750 page book with over 2,000 included reference sources, I have missed three and also self plagiarized. I still think self referencing really sux. I do not like doing it, but I am seeing that it is necessary for reasons I did not think of.&lt;/p&gt;  &lt;p&gt;I will continue with the following pages tomorrow.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;95&lt;/li&gt;    &lt;li&gt;96&lt;/li&gt;    &lt;li&gt;99&lt;/li&gt;    &lt;li&gt;286-287&lt;/li&gt;    &lt;li&gt;482-486&lt;/li&gt;    &lt;li&gt;593-594&lt;/li&gt; &lt;!--EndFragment--&gt;&lt;/ul&gt;  &lt;p&gt;I will add more later, but there is also work to be done. I will load copies of some of the early documents later in the week as I have an opportunity. I still maintain the original emails and submitted documents, so I will load these.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-4654314108051185315?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Z2ANeZ1LWm_Wcaik7GT52cgeUAQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Z2ANeZ1LWm_Wcaik7GT52cgeUAQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Z2ANeZ1LWm_Wcaik7GT52cgeUAQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Z2ANeZ1LWm_Wcaik7GT52cgeUAQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/kk0Ts8OYjKA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/4654314108051185315/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=4654314108051185315" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4654314108051185315?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4654314108051185315?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/kk0Ts8OYjKA/what-is-plagiarism.html" title="What is plagiarism?" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh5.ggpht.com/-uKe0JI3PgCU/TwpZ08o7dqI/AAAAAAAAGHE/GyyjZ66BgZU/s72-c/image_thumb%25255B1%25255D.png?imgmax=800" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/what-is-plagiarism.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMNQno_cSp7ImA9WhRWFUo.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-195631685644165284</id><published>2012-01-03T17:01:00.001+11:00</published><updated>2012-01-03T17:01:33.449+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-03T17:01:33.449+11:00</app:edited><title>The holiday period</title><content type="html">How soon it all passes.&lt;br /&gt;
&lt;br /&gt;
Next week, we are all back to normal.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-195631685644165284?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0uIhUk9MyO2mS7ML95-C5sC7zaU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0uIhUk9MyO2mS7ML95-C5sC7zaU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0uIhUk9MyO2mS7ML95-C5sC7zaU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0uIhUk9MyO2mS7ML95-C5sC7zaU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/QxyrHmP2zdA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/195631685644165284/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=195631685644165284" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/195631685644165284?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/195631685644165284?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/QxyrHmP2zdA/holiday-period.html" title="The holiday period" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2012/01/holiday-period.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4FRXk4cSp7ImA9WhRXFU4.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-1358486911742751253</id><published>2011-12-22T18:28:00.002+11:00</published><updated>2011-12-22T18:28:34.739+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-22T18:28:34.739+11:00</app:edited><title>Christmas</title><content type="html">We will be back in the swing of things following Christmas.&lt;br /&gt;
&lt;br /&gt;
Tonight, the reversing code lecture is at 7PM AEST.&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-1358486911742751253?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6tEcoBy6aNcoDrum2vNQY-zf6q8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6tEcoBy6aNcoDrum2vNQY-zf6q8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6tEcoBy6aNcoDrum2vNQY-zf6q8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6tEcoBy6aNcoDrum2vNQY-zf6q8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/UvAnEM3pnlA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/1358486911742751253/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=1358486911742751253" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/1358486911742751253?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/1358486911742751253?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/UvAnEM3pnlA/christmas.html" title="Christmas" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/12/christmas.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08HQXw7cCp7ImA9WhRXEkg.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-737423880279292147</id><published>2011-12-19T12:57:00.000+11:00</published><updated>2011-12-19T12:57:10.208+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-19T12:57:10.208+11:00</app:edited><title>Cyber (Crime / Espionage / Terror)</title><content type="html">The lecture series, &lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:EnableOpenTypeKerning/&gt;
   &lt;w:DontFlipMirrorIndents/&gt;
   &lt;w:OverrideTableStyleHps/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:"";
 mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
 mso-para-margin:0cm;
 mso-para-margin-bottom:.0001pt;
 mso-pagination:widow-orphan;
 font-size:10.0pt;
 font-family:"Times New Roman","serif";}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;b&gt;&lt;span style="color: black; font-family: &amp;quot;Verdana&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 8.0pt; mso-ansi-language: EN-US; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-fareast-language: EN-US;"&gt;Cyber (Crime / Espionage / Terror)&lt;/span&gt;&lt;/b&gt; is on tonight.&lt;br /&gt;
&lt;br /&gt;
This is part 2 of "Cyber Terror" and is lecture 6 of 24.&lt;br /&gt;
&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:EnableOpenTypeKerning/&gt;
   &lt;w:DontFlipMirrorIndents/&gt;
   &lt;w:OverrideTableStyleHps/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:"";
 mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
 mso-para-margin:0cm;
 mso-para-margin-bottom:.0001pt;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;div class="MsoBodyText"&gt;
Reserve your Webinar seat now at:&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;a href="https://www2.gotomeeting.com/register/532843426"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10.0pt;"&gt;https://www2.gotomeeting.com/register/532843426&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Lecture 6 in a series of 24.&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
We have just seen the largest cyber espionage incident in
recorded history and it is only set to get bigger. The rise of cyber based
groups engaging in hactivism is creating chaos, but it is only the start as
these groups start to do more damage. Al-Qaeda and other pure terror groups
have been on the back foot unable to leverage the social aspects of Web 2.0,
but will this change as groups such as&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Anon and LulzSec define a distributed
model for social malfeasance? &lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&amp;nbsp;Add to this criminal controlled botnets of millions of
zombie hosts and the decade is set to be the decade of the hack! &lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
In this lecture, we focus on Cyber Terror. This will be
the next in 4 lectures detailing the rise and development of cyber terror and
its links to traditional criminal enterprises (including the drug trade,
prostitution and smuggling), states and more. &lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Presented by Dr Craig Wright of Charles Sturt University
[1] and the Global Institute for Cyber Security + Research [2]. &lt;/div&gt;
&lt;div class="MsoList"&gt;
1.&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;a href="http://www.csu.edu.au/"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10.0pt;"&gt;Http://www.csu.edu.au&lt;/span&gt;&lt;/a&gt;
&lt;/div&gt;
&lt;div class="MsoList"&gt;
2.&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;a href="http://www.gicsr.org/"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10.0pt;"&gt;Http://www.gicsr.org&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10.0pt;"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Title:&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Cyber (Crime / Espionage / Terror)&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Date:&lt;/div&gt;
&lt;div class="MsoDate"&gt;
Monday, December 19, 2011&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
Time:&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
7:00 PM - 8:00 PM AEDT&lt;/div&gt;
&lt;div class="MsoNormal" style="mso-layout-grid-align: none; text-autospace: none;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoBodyText"&gt;
After registering you will receive a confirmation email
containing information about joining the Webinar.&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-737423880279292147?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/UHBVXzweNshOUKhS-e4zO5LIjGQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UHBVXzweNshOUKhS-e4zO5LIjGQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/UHBVXzweNshOUKhS-e4zO5LIjGQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UHBVXzweNshOUKhS-e4zO5LIjGQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/82rMyDMb5HA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/737423880279292147/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=737423880279292147" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/737423880279292147?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/737423880279292147?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/82rMyDMb5HA/cyber-crime-espionage-terror.html" title="Cyber (Crime / Espionage / Terror)" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/12/cyber-crime-espionage-terror.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4DQnczfSp7ImA9WhRQEUk.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-6764919629164793455</id><published>2011-12-06T16:22:00.001+11:00</published><updated>2011-12-06T16:22:53.985+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-06T16:22:53.985+11:00</app:edited><title>Router Audit Tool (RAT)</title><content type="html">&lt;p&gt;The Router Audit Tool or RAT was designed to help audit the configurations of Cisco routers quickly and efficiently. RAT tests Cisco router configurations against a baseline. After performing the baseline test, it not only provides a list of the potential security vulnerabilities discovered but also a list of commands to be applied to the router in order to correct the potential security problems discovered. The router audit tool (RAT) is available from the Centre for Internet Security (CIS) website &lt;a href="http://www.cisecurity.org/bench_cisco.html"&gt;http://www.cisecurity.org/bench_cisco.html&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Aside from providing an industry-accepted benchmark for the CISCO IOS, RAT helps solve the following issues:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Difficulty maintaining consistency&lt;/li&gt;    &lt;li&gt;Difficulty detecting changes&lt;/li&gt;    &lt;li&gt;Need to quickly fix incorrect settings&lt;/li&gt;    &lt;li&gt;Need for reporting and customization&lt;/li&gt;    &lt;li&gt;Need to check non-IOS devices&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Although RAT does provide many useful functions, it is not actively updated and therefore requires the user to check from time to time the latest version releases and patches. Also, as powerful as it is, there are a number of issues that it does not address such as:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Management Issues&lt;/li&gt;    &lt;li&gt;Poor Ops Practices&lt;/li&gt;    &lt;li&gt;Vendor code&lt;/li&gt;    &lt;li&gt;Protocols weaknesses&lt;/li&gt;    &lt;li&gt;Host-based problems (viruses, code red….)&lt;/li&gt;    &lt;li&gt;Bandwidth based DoS New vulnerabilities&lt;/li&gt;    &lt;li&gt;Local configuration choices&lt;/li&gt;    &lt;li&gt;Need for competence and vigilance.&lt;/li&gt;    &lt;li&gt;Non-CISCO devices are not yet supported.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;How RAT works&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The Router Audit Tool was written in Perl. It is consists of 4 other Perl programs namely ncat, ncat_report, ncat_config and snarf.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;b&gt;Snarf&lt;/b&gt; is used to download the router settings. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Ncat&lt;/b&gt; reads the rule base and configuration files and provides output in a text file. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Ncat_report&lt;/b&gt; creates the html pages from the text files. &lt;/li&gt;    &lt;li&gt;&lt;b&gt;Ncat_config&lt;/b&gt; is used to perform localization of the rule base. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The rules and baseline document are licensed by the Center for Internet Security. RAT performs an audit by comparing text strings in the configuration file from the router with regular expressions in the rules. Each rule has either a “required” or “forbidden” regular expression element. Based on this element RAT determines if a rule is passed or failed. Due to the use of regular expressions, the RAT rule base is extremely flexible. There are currently Level 1 and Level 2 audits that can be performed. The Level 1 audit is based on the NSA guidelines. The Level 2 audit includes additional tests from several sources including Cisco. The majority of the rules are for the protection of the router. There are, however, several rules that provide limited protection to the networks they serve. Additional rules can be added to the rule base with relative ease. This allows RAT to work with any configuration. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;How to install RAT&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Installing RAT is fairly simple. First, download the installer from &lt;a href="http://www.cisecurity.org/bench_cisco.html"&gt;http://www.cisecurity.org/bench_cisco.html&lt;/a&gt;. For windows users, select the win32 native installer. &lt;/p&gt;  &lt;p&gt;1. Ensure that any previous versions of RAT are no longer installed; if necessary, use the Windows &amp;quot;Add/Remove Programs&amp;quot; control panel to uninstall a previous version of RAT.&lt;/p&gt;  &lt;p&gt;2. Run the installer, either by double-clicking on it, to selecting it through the Windows &amp;quot;Add/Remove Program&amp;quot; control panel. You may be asked to restart your computer at this point.&lt;/p&gt;  &lt;p&gt;3. At the CIS RAT logo splash image, click Next&amp;gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-QTFuKLqnw0M/Tt2mOWGoJRI/AAAAAAAAGD4/Q7duVpypes8/s1600-h/clip_image002%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://lh4.ggpht.com/-efJWJrzD1ps/Tt2mP5q3-8I/AAAAAAAAGEA/w--7O9vsVgM/clip_image002_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 1 CIS RAT Logo&lt;/p&gt;  &lt;p&gt;4. Click Next&amp;gt; again.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-809GUYmB_hY/Tt2mQymgnzI/AAAAAAAAGEI/2IiJz49Z8RU/s1600-h/clip_image004%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image004" border="0" alt="clip_image004" src="http://lh6.ggpht.com/-_yGukGplD20/Tt2mSBiIWZI/AAAAAAAAGEQ/EXUa4uFX-m0/clip_image004_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 2 CIS RAT Install Box&lt;/p&gt;  &lt;p&gt;5. After reading the Licensing Agreement, select &amp;quot;I accept the terms...&amp;quot; and click Next&amp;gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-TAQL4do18dg/Tt2mTU0M-NI/AAAAAAAAGEY/F5BYTvdFmz8/s1600-h/clip_image006%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image006" border="0" alt="clip_image006" src="http://lh5.ggpht.com/-UNjAMkHHVBw/Tt2mUhYBpGI/AAAAAAAAGEg/hN8ki8jxDio/clip_image006_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 3 CIS Accept Page&lt;/p&gt;  &lt;p&gt;6. Read the background information presented on the next page of the wizard, then click Next&amp;gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-HcZE3J1t8J4/Tt2mWKqoHOI/AAAAAAAAGEk/Ywv9txdC24E/s1600-h/clip_image008%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image008" border="0" alt="clip_image008" src="http://lh3.ggpht.com/-dw-Xgb6likw/Tt2mXcIAhPI/AAAAAAAAGEw/nkuE-LNwYGg/clip_image008_thumb.jpg?imgmax=800" width="244" height="186" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 4 CIS RAT Release Notes&lt;/p&gt;  &lt;p&gt;7. Select a directory where RAT should be installed. &lt;b&gt;For best results, do not select a directory with spaces or special characters in its name&lt;/b&gt;. If the default is acceptable on your system, then use it. Then click Next&amp;gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-aEdj5Kbqahs/Tt2mYQjFsXI/AAAAAAAAGE4/ax9v1PsfHSw/s1600-h/clip_image010%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image010" border="0" alt="clip_image010" src="http://lh3.ggpht.com/-GsdZBpIhWEU/Tt2mZnV3J6I/AAAAAAAAGFA/KRBKswixI4k/clip_image010_thumb.jpg?imgmax=800" width="244" height="174" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 5 CIS RAT Select where to install&lt;/p&gt;  &lt;p&gt;8. Choose an installation type. Most users require only the &lt;b&gt;&amp;quot;Basic&amp;quot; &lt;/b&gt;setup&lt;b&gt;.&lt;/b&gt; Then click Next&amp;gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-8hWp81AFjH8/Tt2max3VCKI/AAAAAAAAGFI/tFgVZaqbs_w/s1600-h/clip_image012%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image012" border="0" alt="clip_image012" src="http://lh3.ggpht.com/-D0a5dVu1Eeo/Tt2mcOR1v_I/AAAAAAAAGFQ/DRXNoD1DiJg/clip_image012_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 6 CIS RAT Install details&lt;/p&gt;  &lt;p&gt;9. Verify that the installation settings are correct and then click on Install.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-Mv0DZ-gI1xI/Tt2mdKuaOWI/AAAAAAAAGFY/vqmNRjVz4WE/s1600-h/clip_image014%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image014" border="0" alt="clip_image014" src="http://lh4.ggpht.com/-y4UZwecePAE/Tt2meb3twvI/AAAAAAAAGFg/_DPNpNKu0dY/clip_image014_thumb.jpg?imgmax=800" width="244" height="185" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 7 CIS RAT Ready to Install&lt;/p&gt;  &lt;p&gt;10. Wait patiently during installation; allow for about 5-15 seconds.&lt;/p&gt;  &lt;p&gt;11. Click on Finish.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-mQZjw8-umHc/Tt2mfioPkbI/AAAAAAAAGFo/_Qvf9lPIYqs/s1600-h/clip_image016%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image016" border="0" alt="clip_image016" src="http://lh4.ggpht.com/-M7XfuWi0_b0/Tt2mg6xXgsI/AAAAAAAAGFw/DikoSOPd0GE/clip_image016_thumb.jpg?imgmax=800" width="244" height="186" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 8 CIS RAT is installed and ready to go&lt;/p&gt;  &lt;p&gt;Read the documents &lt;b&gt;rat.html&lt;/b&gt; and &lt;b&gt;ncat_config.html&lt;/b&gt; in the \doc subfolder to view relevant options and files. For more information on running RAT on Windows, see the file &lt;b&gt;etc\README.WIN32.txt&lt;/b&gt;. For information on running RAT specifically for CISCO PIX, see the file &lt;b&gt;etc\README.PIX.txt&lt;/b&gt;.&lt;/p&gt;  &lt;p&gt;Note that the file &lt;b&gt;etc\OLD-INSTALL.WIN32.txt&lt;/b&gt; contains instructions for another, older, more complex method of installing RAT on windows. This involves installing ActiveState PERL and downloading and installing Perl (CPAN) modules. This is not recommended for most users.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;How to run RAT&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Prior to running RAT, first determine whether router configurations are going to be obtained directly from the router or if they have been already downloaded and saved into a file. In the case of the latter, the path to that file should be specified when invoking RAT on the command line. Alternately, with the use of the &lt;b&gt;&lt;i&gt;--snarf&lt;/i&gt;&lt;/b&gt; switch, RAT will log into the routers specified (you have to provide login info and the router’s IP address), pull down the configurations, audit them against a set of rules and produces several output files. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-iMoroYI2jU0/Tt2miMGurQI/AAAAAAAAGF4/YZeKMbYnSOA/s1600-h/clip_image018%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image018" border="0" alt="clip_image018" src="http://lh5.ggpht.com/-RTwSY89NuWk/Tt2mjRAKdAI/AAAAAAAAGGA/bafUDnd83-8/clip_image018_thumb.jpg?imgmax=800" width="244" height="78" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 9 Running RAT &lt;/p&gt;  &lt;p&gt;There are several options or “switches” that can be used to control the behavior of RAT. These switches are supplied later in the chapter. In the example of Figure 11.13, the configurations of the router are contained in a text file called syd_1760rt_06082007.txt. &lt;/p&gt;  &lt;p&gt;NOTE: In this example it is assumed that the path to the directory where the RAT executables and supporting files has already been established. In the default installation, those files and folders are located at C:\CIS\RAT. Also, there are several ways of saving the router configuration file to a file. However, HTTP, TFTP or Telnet methods are not recommended as they produce output in clear text and therefore poses a risk to confidentiality. Pressing the &amp;lt;RETURN&amp;gt; key in the above resulted to the following:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-PZ9ARyYXFgo/Tt2mkge37pI/AAAAAAAAGGI/f8zzcdl7Qh0/s1600-h/clip_image020%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image020" border="0" alt="clip_image020" src="http://lh3.ggpht.com/-4WCTYYZ7tsQ/Tt2mlyAGWuI/AAAAAAAAGGQ/RCcEjnzBYek/clip_image020_thumb.jpg?imgmax=800" width="244" height="120" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 10 CIS RAT Having been run&lt;/p&gt;  &lt;p&gt;Several files have been created after running RAT against the configuration file. If we list those files using the dir command we get:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-LBWrZ6a5MIo/Tt2mnGxEn2I/AAAAAAAAGGY/Xg3dN5pPBUk/s1600-h/clip_image022%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image022" border="0" alt="clip_image022" src="http://lh3.ggpht.com/-kynT-Kzj0N8/Tt2morzrQPI/AAAAAAAAGGg/obvlezys7jI/clip_image022_thumb.jpg?imgmax=800" width="244" height="145" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 11 CIS RAT Creates Several Output files&lt;/p&gt;  &lt;p&gt;The details of the output files that are created by RAT are included in the following table:   &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;       &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;syd_1760rt_06082007.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;Raw file containing router configurations. &lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;syd_1760rt_06082007.txt.ncat_out.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;raw ncat output. This is a &amp;quot;;&amp;quot; delimited file showing &lt;b&gt;pass/fail&lt;/b&gt; data for each rule&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;syd_1760rt_06082007.txt.html&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A HTML-based report showing fulll details of results, with links into rules.html&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;syd_1760rt_06082007.txt.ncat_fix.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A file containing commands to fix problems found.&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;syd_1760rt_06082007.txt.ncat_report.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A text based report showing summary of results, with links into rules.html&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;cisco-ios-benchmark.html&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;List of rules that were used to perform the audit&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;rules.html&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;An HTML version of the benchmark data&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;all.ncat_report.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A text based report showing summary of results, with links into rules.html, of all the routers included in the audit. In our sample, since there is only one router, this file is the same as syd_1760rt_06082007.txt.ncat_report.txt&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;all.ncat_fix.txt&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A file containing commands to fix problems found in all the routers included in the audit. In our sample, since there is only one router, this file is the same as syd_1760rt_06082007.txt.ncat_fix.txt.&lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;all.html&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A HTML report listing summary of pass/fail status for all rules checked on all devices. &lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;        &lt;tr&gt;         &lt;td width="177"&gt;           &lt;p&gt;index.html&lt;/p&gt;         &lt;/td&gt;          &lt;td width="466"&gt;           &lt;p&gt;A HTML index of reports. This is probably the file that most users will want to examine (with the aid of a browser) after running RAT. &lt;/p&gt;         &lt;/td&gt;       &lt;/tr&gt;     &lt;/tbody&gt;&lt;/table&gt; &lt;/p&gt;  &lt;p&gt;The generated &lt;b&gt;index.html&lt;/b&gt; file looks like this:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-KB5t-D5e-74/Tt2mpmPSeUI/AAAAAAAAGGo/LAG4n8YKmos/s1600-h/clip_image024%25255B3%25255D.jpg"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="clip_image024" border="0" alt="clip_image024" src="http://lh5.ggpht.com/-yg24iR6ZAJY/Tt2mqzWYs-I/AAAAAAAAGGw/Muqv2g_hTS0/clip_image024_thumb.jpg?imgmax=800" width="244" height="170" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 12 CIS RAT Report Page&lt;/p&gt;  &lt;p&gt;Clicking on the &lt;b&gt;&lt;u&gt;Description of Rules&lt;/u&gt;&lt;/b&gt; link brings up the &lt;b&gt;rules.html&lt;/b&gt; file&lt;/p&gt;  &lt;p&gt;Next, &lt;a href="http://ncat.sourceforge.net/"&gt;NCAT&lt;/a&gt;, the Network Config Audit Tool.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-6764919629164793455?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_2sL5q5sMrPHsDoOuVuEc38fJrk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_2sL5q5sMrPHsDoOuVuEc38fJrk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_2sL5q5sMrPHsDoOuVuEc38fJrk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_2sL5q5sMrPHsDoOuVuEc38fJrk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/G-OYjrCeymg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/6764919629164793455/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=6764919629164793455" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6764919629164793455?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6764919629164793455?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/G-OYjrCeymg/router-audit-tool-rat.html" title="Router Audit Tool (RAT)" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh4.ggpht.com/-efJWJrzD1ps/Tt2mP5q3-8I/AAAAAAAAGEA/w--7O9vsVgM/s72-c/clip_image002_thumb.jpg?imgmax=800" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/12/router-audit-tool-rat.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQNQ3g-cSp7ImA9WhRRFk4.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-3449983921259270548</id><published>2011-11-30T17:26:00.001+11:00</published><updated>2011-11-30T17:26:32.659+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-30T17:26:32.659+11:00</app:edited><title>Call for Adjunct Research Supervisors</title><content type="html">&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:EnableOpenTypeKerning/&gt;
   &lt;w:DontFlipMirrorIndents/&gt;
   &lt;w:OverrideTableStyleHps/&gt;
  &lt;/w:Compatibility&gt;
  &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:"";
 mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
 mso-para-margin:0cm;
 mso-para-margin-bottom:.0001pt;
 mso-pagination:widow-orphan;
 font-size:10.0pt;
 font-family:"Times New Roman","serif";}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;div class="MsoNormal" style="margin-left: 36.0pt;"&gt;
&lt;b&gt;&lt;span lang="EN-AU" style="color: #1f497d; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ansi-language: EN-AU;"&gt;Adjunct Doctoral Supervisors&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="margin-left: 36.0pt;"&gt;
&lt;span lang="EN-AU" style="color: #1f497d; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11.0pt; mso-ansi-language: EN-AU;"&gt;&lt;br /&gt;
- Part time, after hours&lt;br /&gt;
- Industry based&lt;br /&gt;
- Multiple Volunteer positions available &lt;br /&gt;
&lt;br /&gt;
Company Background &amp;amp; Job Purpose&lt;br /&gt;
&lt;br /&gt;
With over 1,000 IT professionals currently enrolled, Charles Sturt University
is one of Australia's largest providers of Postgraduate Information Technology
education to Australian students.&lt;br /&gt;
&lt;br /&gt;
Charles Sturt University has developed an innovative Doctor of Information
Technology which extends knowledge of the discipline of Information Technology
and develops the attributes required to successfully identify, investigate and
resolve problems confronting these fields. Students carry out research into a
current opportunity or problem confronting information and communication
technology, and present the findings in a thesis or portfolio. Students
studying the Doctor of Information Technology will generally be working full
time in the IT industry, and developing their Doctoral thesis after hours (&lt;a href="http://www.csu.edu.au/courses/postgraduate/information_technology_doctor/course-overview"&gt;http://www.csu.edu.au/courses/postgraduate/information_technology_doctor/course-overview&lt;/a&gt;
refers)&lt;br /&gt;
&lt;br /&gt;
We are seeking part time, industry-based volunteers to assist in supervising
Doctoral students conducting research in a wide range of Information Technology
topics. As an Adjunct Supervisor, you will work with the principal supervisor
at Charles Sturt University and provide expert technical input into the topic
being researched. This supervision will include after hours, Webinar-based
virtual meetings between you and the student and/or the principal supervisor.&lt;br /&gt;
&lt;br /&gt;
Successful applicants will:&lt;br /&gt;
&lt;br /&gt;
- be appointed as Adjunct Supervisor at Charles Sturt University.&lt;br /&gt;
- get the opportunity to network with an elite group of supervisors at the
University and in the IT industry.&lt;br /&gt;
- gain access to a range of University services such as the online research
library.&lt;br /&gt;
&lt;br /&gt;
Training on the technical, ethical, administrative and professional aspects of
supervision will be provided.&lt;br /&gt;
&lt;br /&gt;
Key Result Areas:&lt;br /&gt;
&lt;br /&gt;
Charles Sturt University's Doctor of Information Technology provides a complex
and challenging research experience and, at its heart, is the key educational
role of the supervisor. As a supervisor, your Key Performance Indicators will
reflect the crucial role that you play including: &lt;br /&gt;
- that you are holding regular, Webinar-based virtual meetings with the student
that you are supervising and that these meetings are well planned and have an
agenda&lt;br /&gt;
- that you are providing the required monthly reporting on the progress of the
student that you are supervising, including seeing that agreed targets for the
submission of chapters or parts of the project are being met.&lt;br /&gt;
- that the student you are supervising believes that you are supplying the
required level of support, encouragement, advice and guidance&lt;br /&gt;
- that you successfully complete the Charles Sturt University supervisor
training program&lt;br /&gt;
&lt;br /&gt;
Education:&lt;br /&gt;
Completion of a PhD, Doctorate, Research-based Master's degree or equivalent
experience in the commercial research industry (preferred).&lt;br /&gt;
&lt;br /&gt;
Experience:&lt;br /&gt;
Extensive experience in the IT industry (essential).&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-3449983921259270548?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iuujLkyLu5B94wwMsZXM1ymn5is/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iuujLkyLu5B94wwMsZXM1ymn5is/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iuujLkyLu5B94wwMsZXM1ymn5is/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iuujLkyLu5B94wwMsZXM1ymn5is/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/ykiqzgI3VOw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/3449983921259270548/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=3449983921259270548" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/3449983921259270548?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/3449983921259270548?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/ykiqzgI3VOw/call-for-adjunct-research-supervisors.html" title="Call for Adjunct Research Supervisors" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/call-for-adjunct-research-supervisors.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcESHw_fSp7ImA9WhRRFUg.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-1889305688362624349</id><published>2011-11-29T18:33:00.001+11:00</published><updated>2011-11-29T18:33:29.245+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-29T18:33:29.245+11:00</app:edited><title>Metadata</title><content type="html">&lt;p&gt;The following is a small extract from what will become the GPen Study Guide.&lt;/p&gt;  &lt;p&gt;As organizations create documents, the software that they use to create these documents embeds an enormous amount of information in the document files. A good deal of metadata is also included in the file. Much of this metadata is associated with formatting and display of the other data in the file. Besides this formatting metadata, a lot of file creation and editing tools include additional metadata entries that can be very useful for penetration testers during our reconnaissance phase, such as:&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;User names:&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;Penetration testers often need user names for exploitation and password-guessing attacks&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;File system paths&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: &lt;/i&gt;Knowing the full path of the original file when it was created can reveal useful tidbits about the target organization&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;E-mail addresses:&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;This data can be useful if the penetration test scope includes spear phishing tests&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;Client-side software in use:&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;Given that client-side exploitation is such a common attack vector, it can be helpful to penetration testers to know which client-side programs are in use&lt;/p&gt;  &lt;p&gt;Almost every document type has some form of metadata, but some are richer in metadata than others. The following types of documents, generated and used by most enterprises, are of particular interest to penetration testers:&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;pdf files:&lt;/b&gt;&lt;i&gt; &lt;/i&gt;These files are associated with Acrobat Reader and a variety of other pdf creation and editing tools.&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;doc/docx, xls/xlsx, and ppt/pptx files&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: &lt;/i&gt;These files are associated with Microsoft Office suite, but are also used by several other related tools. &lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;jpg and jpeg&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: &lt;/i&gt;These image files often contain a significant amount of metadata, including data about the camera used to take a picture, the file system of the machine where the image was edited, and details about the image-editing software.&lt;/p&gt;  &lt;p&gt;· &lt;b&gt;&lt;i&gt;html and htm&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: &lt;/i&gt;These file types contain web pages, and may at first seem uninteresting. However, their comments and hidden form elements could contain metadata that is very useful to a penetration tester. Additionally, scripts embedded in the HTML may reveal sensitive information or undocumented features of a web application.&lt;a name="id.59457005467e"&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-1889305688362624349?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xd14iUGaqyfzEe9povyLovoEDD4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xd14iUGaqyfzEe9povyLovoEDD4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xd14iUGaqyfzEe9povyLovoEDD4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xd14iUGaqyfzEe9povyLovoEDD4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/SQa0vBcrQjg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/1889305688362624349/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=1889305688362624349" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/1889305688362624349?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/1889305688362624349?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/SQa0vBcrQjg/metadata.html" title="Metadata" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/metadata.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMAQXg5fCp7ImA9WhRRFEk.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-6296745212156248499</id><published>2011-11-28T13:30:00.001+11:00</published><updated>2011-11-28T13:30:40.624+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-28T13:30:40.624+11:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Charles Sturt University" /><title>What is a hash</title><content type="html">&lt;p&gt;With conferences and the like I have been behind in writing up a load of material on topics such as NAP etc. I have not forgotten these. For now, I will start by detailing some terms I have seen used poorly.&lt;/p&gt;  &lt;p&gt;To start, I will look at what a hash function is.&lt;/p&gt;  &lt;p&gt;Formally, a hash function H is defined as a transformation that takes a variable-size input m and returns a fixed-size string. This fixed string is what we term the hash value h.&lt;/p&gt;  &lt;p&gt;We can express this as:&amp;#160;&amp;#160;&amp;#160; &lt;em&gt;&lt;strong&gt;h = H(m)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;There are some things we need to know in developing our function h:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;the input m can be or any length (this includes being smaller than the resulting hash output h, larger than the output or even of the same size).&lt;/li&gt;    &lt;li&gt;The size of the output h remains the same no matter what the input is. That is, if the output of the hash function returns a length of L bits for a given input m, it must return an output of length L bits for ANY input m. &lt;/li&gt;    &lt;li&gt;The hash function H(m) is one way. If we have a value h we cannot use this to determine the initial input m.&lt;/li&gt;    &lt;li&gt;The function, H(x) must be simple and computationally inexpensive to compute. That is, making a table of mapped values and indexing calculated hashes against input must be expensive when compared to making the hash.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Hashing is used primarily in digital signatures and for integrity checks. They also aid in time stamping. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Collisions&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;It is stated that a hash needs to be “collision free”. This is wrong. If we think that an 8-bit hash has only 256 possible values, we see that there is an infinite number of collisions as we can have an infinite variability in input. Collisions abound!&lt;/p&gt;  &lt;p&gt;Collisions always EXIST IN A HASH FUNCTION. This is NOT the issue. The issue is not the existence of a collision, but the fact that we may be able to calculate the collision and predict it. &lt;/p&gt;  &lt;p&gt;A hash function H(x) will have collisions, but the distribution of these collisions should be unpredictable.&lt;/p&gt;  &lt;p&gt;If we constrain the length of the input m to a certain value, the number of collisions can be stated to be in the order of:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;No. Input messages possible&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;--------------------------------------&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;No. Hashes by Hash length &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Where:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;No. Input messages possible = 2(length m)&lt;/li&gt;    &lt;li&gt;No. Hashes by Hash length = 2^(hash length)&lt;/li&gt; Collisions exist.&lt;/ul&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-6296745212156248499?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gAFbOUh7r6CwXwbjNREEe3Fwu_I/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gAFbOUh7r6CwXwbjNREEe3Fwu_I/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gAFbOUh7r6CwXwbjNREEe3Fwu_I/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gAFbOUh7r6CwXwbjNREEe3Fwu_I/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/F8Gx2Ypheuo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/6296745212156248499/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=6296745212156248499" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6296745212156248499?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6296745212156248499?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/F8Gx2Ypheuo/what-is-hash.html" title="What is a hash" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/what-is-hash.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUQHRXo9eCp7ImA9WhRREUs.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-2864213663054835991</id><published>2011-11-25T06:35:00.001+11:00</published><updated>2011-11-25T06:35:34.460+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-25T06:35:34.460+11:00</app:edited><title>Reversing Code</title><content type="html">The first webinar/lecture for the Reversing code series is up.&lt;br /&gt;&lt;br /&gt;https://www2.gotomeeting.com/archive/597275986&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-2864213663054835991?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Wu82yCKfnMW-gSWogI88f7Shr2A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Wu82yCKfnMW-gSWogI88f7Shr2A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Wu82yCKfnMW-gSWogI88f7Shr2A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Wu82yCKfnMW-gSWogI88f7Shr2A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/wAnAwcNbZCA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/2864213663054835991/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=2864213663054835991" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/2864213663054835991?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/2864213663054835991?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/wAnAwcNbZCA/reversing-code.html" title="Reversing Code" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/reversing-code.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8NSXgyeCp7ImA9WhRSGU0.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-8332104995945396348</id><published>2011-11-22T06:14:00.001+11:00</published><updated>2011-11-22T06:14:58.690+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-22T06:14:58.690+11:00</app:edited><title>Cyber (Crime / Espionage / Terror)</title><content type="html">&lt;br /&gt;
The webinar link for last night's lecture on "Cyber (Crime / Espionage / Terror)" is up and available.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www2.gotomeeting.com/register/532843426"&gt;https://www2.gotomeeting.com/register/532843426&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-8332104995945396348?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2w8S4nroTgVcCT8cGDxHmhHMkv4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2w8S4nroTgVcCT8cGDxHmhHMkv4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2w8S4nroTgVcCT8cGDxHmhHMkv4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2w8S4nroTgVcCT8cGDxHmhHMkv4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/TnGMO-cK6c0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/8332104995945396348/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=8332104995945396348" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8332104995945396348?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8332104995945396348?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/TnGMO-cK6c0/cyber-crime-espionage-terror.html" title="Cyber (Crime / Espionage / Terror)" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/cyber-crime-espionage-terror.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QCQng_cCp7ImA9WhRSF04.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-4307918442460999361</id><published>2011-11-20T06:36:00.001+11:00</published><updated>2011-11-20T06:36:03.648+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-20T06:36:03.648+11:00</app:edited><title>Windows Management Instrumentation Command-line (WMIC)</title><content type="html">&lt;p&gt;The WMIC is a Windows command line tool that will allow you to do many of the things we are used to doing at the shell in Unix. For instance, Windows does not have a “kill –9”command, but with WMIC you can do then same function using the following command:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;wmic process where name='winrar.exe' delete&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;wmic process process [pid] delete&lt;/em&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-62RFryTQnHc/TsgFA0d30pI/AAAAAAAAGDI/szLN36IcfcA/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-5SU0RQ2Oy8Q/TsgFCDKSqHI/AAAAAAAAGDQ/nuK5BRPMFEI/image_thumb%25255B1%25255D.png?imgmax=800" width="441" height="86" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;So, unlike Unix, we can kill a process using just the name of the executable as well as selecting the individual PID (Process ID). This is extremely useful in malware analysis.&lt;/p&gt;  &lt;p&gt;For auditing, you can also gather a lot of information. For instance, lists of users on the system.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-LovmDGsKJtA/TsgFD_yCAUI/AAAAAAAAGDY/bRtl66nwD5k/s1600-h/image%25255B7%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-Zt0GgcUyOhQ/TsgFFcGBNgI/AAAAAAAAGDg/YbQKrHqa3t4/image_thumb%25255B3%25255D.png?imgmax=800" width="430" height="249" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;More importantly, you can list the service patches and hotfixes that are installed on the system.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;wmic qfe&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-HjhnuEY9C_4/TsgFG1akQeI/AAAAAAAAGDo/Tggr1dZ3S9k/s1600-h/image%25255B11%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-9bMJQ5UBPaI/TsgFIfENK0I/AAAAAAAAGDw/4mHLkNDzByM/image_thumb%25255B5%25255D.png?imgmax=800" width="392" height="407" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;As you can see, this allows you to script a check of all the patches on a system and to even automate this over your domain.&lt;/p&gt;  &lt;p&gt;WMIC is one of the commands you really need to know if you are administrating a Windows system. I will post more on this command soon as well as more in the series on IPSec and NAP this week.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-4307918442460999361?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/SIAd2g2UcNRivAFWjZUBBCI9UM0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SIAd2g2UcNRivAFWjZUBBCI9UM0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/SIAd2g2UcNRivAFWjZUBBCI9UM0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SIAd2g2UcNRivAFWjZUBBCI9UM0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/ueRN44wmn-Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/4307918442460999361/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=4307918442460999361" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4307918442460999361?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4307918442460999361?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/ueRN44wmn-Q/wmic-is-windows-command-line-tool-that.html" title="Windows Management Instrumentation Command-line (WMIC)" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh3.ggpht.com/-5SU0RQ2Oy8Q/TsgFCDKSqHI/AAAAAAAAGDQ/nuK5BRPMFEI/s72-c/image_thumb%25255B1%25255D.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/wmic-is-windows-command-line-tool-that.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQDQXc5fyp7ImA9WhRSFUs.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-114321358068244171</id><published>2011-11-18T08:12:00.001+11:00</published><updated>2011-11-18T08:12:50.927+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-18T08:12:50.927+11:00</app:edited><title>Using Process explorer to discover network properties</title><content type="html">&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653"&gt;Process Explorer&lt;/a&gt; is a tool from Microsoft that is in effect Task Manager on steroids without all the bad consequences.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-S3Ibw1Q_1JM/TsV4s0mwoDI/AAAAAAAAGCU/Y0jTWbnzy50/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-wz887O8LZfE/TsV4uzSDxUI/AAAAAAAAGCc/91IAhKi7Gbk/image_thumb%25255B1%25255D.png?imgmax=800" width="419" height="345" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Right clicking on a running process allows you to select properties.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-bhHvUffdebQ/TsV4vqueH4I/AAAAAAAAGCk/NiBOiphS7YM/s1600-h/image%25255B9%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-xNoX5nj5-go/TsV4xVB2f3I/AAAAAAAAGCs/axZ_EaAL0Uw/image_thumb%25255B3%25255D.png?imgmax=800" width="244" height="237" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;From here, selecting the TCP/IP tab will display the connections in progress from this application.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-cC0XWUw9V68/TsV4ynv_AaI/AAAAAAAAGC0/NN7DwvdI6oA/s1600-h/image%25255B6%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-fRRrLpQtpcU/TsV4z5mvRWI/AAAAAAAAGC8/JSkxqcoh7zc/image_thumb%25255B2%25255D.png?imgmax=800" width="211" height="244" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;So, if you have a suspicious application, now you have a tool to watch what it is doing.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-114321358068244171?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fkH-M2UoWU66JVFW5cb30_4AvrU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fkH-M2UoWU66JVFW5cb30_4AvrU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fkH-M2UoWU66JVFW5cb30_4AvrU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fkH-M2UoWU66JVFW5cb30_4AvrU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/v6ROyW94n9g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/114321358068244171/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=114321358068244171" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/114321358068244171?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/114321358068244171?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/v6ROyW94n9g/process-explorer-is-tool-from-microsoft.html" title="Using Process explorer to discover network properties" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh4.ggpht.com/-wz887O8LZfE/TsV4uzSDxUI/AAAAAAAAGCc/91IAhKi7Gbk/s72-c/image_thumb%25255B1%25255D.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/process-explorer-is-tool-from-microsoft.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4MSHw4fSp7ImA9WhRSFEw.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-4065202890495842942</id><published>2011-11-16T15:49:00.001+11:00</published><updated>2011-11-16T15:49:49.235+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-16T15:49:49.235+11:00</app:edited><title>More Windows tasks</title><content type="html">&lt;p&gt;Most people know of the Windows Task-manager GUI application. There are many times when it is better to use a CLI (command line interface). One such example would be where a script tests what is running.&lt;/p&gt;  &lt;p&gt;The command “&lt;u&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;tasklist&lt;/font&gt;&lt;/strong&gt;&lt;/u&gt;” is a Windows command that allows just this.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh3.ggpht.com/-6xMSv5LIzXg/TsNA1Evj1cI/AAAAAAAAGBg/rwAJcB-lXbg/s1600-h/image%25255B3%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-Loqt75xwNI4/TsNA2I4IcNI/AAAAAAAAGBo/YOJFlJE_Tl0/image_thumb%25255B1%25255D.png?imgmax=800" width="433" height="206" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Just like its GUI cousin, you can also list services using this tool. The “/svc” option for instance displays the services hosted in each process.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh6.ggpht.com/-7gNGen7nEg0/TsNA3BrmM-I/AAAAAAAAGBw/_28qLrL2LQA/s1600-h/image%25255B7%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-YFHwSc1AI6Y/TsNA4Z-Ae1I/AAAAAAAAGB4/qpBZTt07oZw/image_thumb%25255B3%25255D.png?imgmax=800" width="443" height="211" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;More, you can filter such as in the example below where we have selected processes that do not respond to task-monitoring requests.&lt;a href="http://lh5.ggpht.com/-XqnqBjofky0/TsNA5HUlRyI/AAAAAAAAGCA/dz3mHE5QlK0/s1600-h/image%25255B11%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh5.ggpht.com/-p0kXXx_kpmY/TsNA6bk4o8I/AAAAAAAAGCI/Fu2ydaNlDII/image_thumb%25255B5%25255D.png?imgmax=800" width="436" height="137" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Knowing what you are running is the first part of stopping malware.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-4065202890495842942?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/AED2OcLrDtH0B2hn56TnRp-AYJs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AED2OcLrDtH0B2hn56TnRp-AYJs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/AED2OcLrDtH0B2hn56TnRp-AYJs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AED2OcLrDtH0B2hn56TnRp-AYJs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/nERU7jH9zAI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/4065202890495842942/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=4065202890495842942" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4065202890495842942?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/4065202890495842942?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/nERU7jH9zAI/most-people-know-of-windows-task.html" title="More Windows tasks" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh4.ggpht.com/-Loqt75xwNI4/TsNA2I4IcNI/AAAAAAAAGBo/YOJFlJE_Tl0/s72-c/image_thumb%25255B1%25255D.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/most-people-know-of-windows-task.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMCQHw5fSp7ImA9WhRSE0g.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-2824613130740246128</id><published>2011-11-15T22:27:00.001+11:00</published><updated>2011-11-15T22:27:41.225+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-15T22:27:41.225+11:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Charles Sturt University" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows" /><title>Investigating tasks in Windows</title><content type="html">&lt;p&gt;When investigating an incident in Windows environment, one of the things you should check is the scheduled tasks. Many malware varieties use startup processes to reload and maintain themselves. By seeking new and unusual tasks, you can quickly look for simple compromises and malicious processes.&lt;/p&gt;  &lt;p&gt;The inclusion of privileged processes (those running as SYSTEM and Admin for instance) are or particular concern. It is also not unusual to discover malicious code running using a blank username.&lt;/p&gt;  &lt;p&gt;To make a simple check of the running and scheduled tasks from the command line, type:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;strong&gt;&lt;u&gt;&lt;font color="#0000ff"&gt;schtasks&lt;/font&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-rxwxXiChCo0/TsJMjvdQYYI/AAAAAAAAGAg/dG30bxpoC84/s1600-h/image%25255B14%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh6.ggpht.com/-GVqdtDNNB30/TsJMk03A6qI/AAAAAAAAGAo/vfzaPPC3wQo/image_thumb%25255B6%25255D.png?imgmax=800" width="400" height="359" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;You can see in the image above that we have a number of scheduled tasks on the system that this was run from. This is divided into groups as follows:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;by folder &lt;/li&gt;    &lt;li&gt;Task name&lt;/li&gt;    &lt;li&gt;The next run time &lt;/li&gt;    &lt;li&gt;The status (ready to run or if it is running now)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;You can create tasks in Windows using these commands as well, but for now, we are simply seeking commands out that we did not expect. Diff’íng the results is a good way to look for system changes.&lt;/p&gt;  &lt;p&gt;You can see the help for this command using the “schtasks /?” extension as displayed below.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://lh4.ggpht.com/-DM0RE2i6FG4/TsJMl1SOvqI/AAAAAAAAGAw/3lNAbjpZ3zg/s1600-h/image%25255B10%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-tvDXHzYpDbE/TsJMm1th16I/AAAAAAAAGA4/mKrQ9VeuFpY/image_thumb%25255B4%25255D.png?imgmax=800" width="418" height="375" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Next is WMIC.&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;WMIC is great for doing malware analysis. It will display all of the files loaded at Startup. More, the Registry keys the system has associated with the “autostart” are also returned.&lt;/p&gt;  &lt;p&gt;You can see the values returned in the figure below:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;font color="#0000ff"&gt;&lt;strong&gt;&lt;u&gt;wmic startup list full&lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-5qqtVWBKzM8/TsJMnyQ3N0I/AAAAAAAAGBA/bWZbR6IDH9w/s1600-h/image%25255B6%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh3.ggpht.com/-twi4qfdXJhE/TsJMoxstH_I/AAAAAAAAGBI/9lOECaFkRT8/image_thumb%25255B2%25255D.png?imgmax=800" width="432" height="213" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;We can also use this to select individual processes.&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;u&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;wmic process list full | find &amp;quot;cmd.exe&amp;quot;&lt;/font&gt;&lt;/strong&gt;&lt;/u&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://lh5.ggpht.com/-gMPaozBENvE/TsJMpmb0FtI/AAAAAAAAGBQ/t9_A4sMoQ1o/s1600-h/image%25255B18%25255D.png"&gt;&lt;img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://lh4.ggpht.com/-yNrbw6vaxmU/TsJMqkXH3cI/AAAAAAAAGBY/LgHT0i-DJI8/image_thumb%25255B8%25255D.png?imgmax=800" width="447" height="165" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Here we have restricted the process search to just &lt;strong&gt;cmd.exe&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;This is useful in checking paths and if a process has inserted itself before the “true” system file.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-2824613130740246128?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ac3t9JobgkGnE5enBKfuPhWmUeo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ac3t9JobgkGnE5enBKfuPhWmUeo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ac3t9JobgkGnE5enBKfuPhWmUeo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ac3t9JobgkGnE5enBKfuPhWmUeo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/DaxmdV1X8yE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/2824613130740246128/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=2824613130740246128" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/2824613130740246128?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/2824613130740246128?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/DaxmdV1X8yE/when-investigating-incident-in-windows.html" title="Investigating tasks in Windows" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://lh6.ggpht.com/-GVqdtDNNB30/TsJMk03A6qI/AAAAAAAAGAo/vfzaPPC3wQo/s72-c/image_thumb%25255B6%25255D.png?imgmax=800" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/when-investigating-incident-in-windows.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8FRnYzeSp7ImA9WhRSEko.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-5395969642608764281</id><published>2011-11-14T22:40:00.001+11:00</published><updated>2011-11-14T22:40:17.881+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-14T22:40:17.881+11:00</app:edited><title>IPv6 RoutingHeader like Loose-Source Routing (LSR)?</title><content type="html">&lt;p&gt;A question to ask is whether the IPv6 Routing Header is like Loose-Source Routing? In many ways it is extremely similar and in fact, RH0 can be used in this way. Consequently, Routing Header Type 0 was depreciated in RFC5095.&lt;/p&gt;  &lt;p&gt;The Routing Header: Type 0 Routing Header (RH0) can be exploited in order to achieve traffic amplification over a remote path for the purposes of generating denial-of-service traffic just as with LSR.&lt;/p&gt;  &lt;p&gt;With Type 0 Routing Headers (RH0) a packet can be constructed such that it will oscillate between two RH0-processing hosts or routers many times. This is a serious amplification that lead to the end of RH0 in the standard track as it allows a stream of packets from an attacker to be amplified along the path between two remote routers and could be used to cause congestion along arbitrary remote paths and hence act as a denial-of-service mechanism.&lt;/p&gt;  &lt;p&gt;Worse, when coupled with the ability to assign Multiple addresses per node, we also have to ask, “Who needs spoofing”? With IPv6, spoofing becomes a non-issue as Renumbering means that for a certain lifetime, two (2) addresses are coexisting on the node.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://tools.ietf.org/html/rfc3775"&gt;Mobility support&lt;/a&gt; means that paths can be defined.&lt;/p&gt;  &lt;p&gt;The point is when deploying IPv6, we need to take care to ensure that we think of the traffic coming into and out of our networks. More, as this is commonly encrypted in IPv6 (using IPsec), we need to think seriously about design and trust.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-5395969642608764281?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B2YJJ10AvdYUQyst8TTQjk728Mo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B2YJJ10AvdYUQyst8TTQjk728Mo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B2YJJ10AvdYUQyst8TTQjk728Mo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B2YJJ10AvdYUQyst8TTQjk728Mo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/y4g0B37BsqY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/5395969642608764281/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=5395969642608764281" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/5395969642608764281?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/5395969642608764281?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/y4g0B37BsqY/ipv6-routingheader-like-loose-source.html" title="IPv6 RoutingHeader like Loose-Source Routing (LSR)?" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/ipv6-routingheader-like-loose-source.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAHRXk4eSp7ImA9WhRTF0U.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-6342687511504984622</id><published>2011-11-09T07:05:00.001+11:00</published><updated>2011-11-09T07:05:34.731+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-09T07:05:34.731+11:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="PII" /><category scheme="http://www.blogger.com/atom/ns#" term="Information Security" /><category scheme="http://www.blogger.com/atom/ns#" term="PCI-DSS" /><title>Obscurity and PII</title><content type="html">&lt;p&gt;PII is Personally Identifiable Information. Right now, I see and hear many people talking about just how easy it is to take and use PII. That it sells for cents in the dollar.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;WELL WHO CARES!&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I mean honestly, if all you do to manage the security of your finances is hide your head in the sand and trust to obscurity, then you deserve all that this approach entails. I may seem uncaring and I may come across as cruel here, but really, it is a simple process to actually protect your information.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;WHY?&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The most commonly missed issue in security is WHY. We commonly fail to investigate the cause and need. PII is not about privacy, it is about stoping unauthorised applications and changes to your credit file. This is, it is all about stopping people doing things such as applying for a credit card or a home loan in your name. The main issue being a credit card.&lt;/p&gt;  &lt;p&gt;In this, the issue is not whether a criminal can buy your information, but if they can steal money from you.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;So why are we looking at PII as the issue?&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The big issue is (as is common) awareness (or rather a lack thereof). There are real controls that stop the problem and are not ones that can fail catastrophically as obscurity does. This is something such as credit monitoring.&lt;/p&gt;  &lt;p&gt;I will first state, I an simply a client of Veda. I pay them money and they provide a service. I have not been approached to talk about their product. I am plugging it as I use it and like the service. It is a security solution to PII.&lt;/p&gt;  &lt;p&gt;I use “MyCreditFile”, a service by Veda (&lt;a title="http://www.mycreditfile.com.au/personal/" href="http://www.mycreditfile.com.au/personal/"&gt;http://www.mycreditfile.com.au/personal/&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;For a dollar a week, I have any changes to my credit file reported to me. I can stop applications cold. I have had three attempts to apply for loans under my name and I do not hide any information (privacy is dead). Each time I have been notified. I have lost nothing but the time to send an email with a dispute notification.&lt;/p&gt;  &lt;p&gt;It is that simple. There are similar agencies in the US, UK etc. SO I have to ask WHY? Why care about PII. Like many security solutions, they address a problem that is a symptom and do not offer solutions at all.&lt;/p&gt;  &lt;p&gt;It is about time we address the cause and implement solutions that actually solve the problem. Here, this is a simple solution to PII theft. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Next…&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I use Quicken and I load my statements into it and check what I have spent. I scan my receipts and I reconcile my accounts. Not only is this good from a point of view of&amp;#160; managing my accounts, I also know when something has occurred and I can lodge a hold within days.&lt;/p&gt;  &lt;p&gt;We only win when we actually find controls that solve the problem and not ones that look at the symptoms.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-6342687511504984622?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/b0iFsHBZmNm1tzpi9Zp74zUDNJQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b0iFsHBZmNm1tzpi9Zp74zUDNJQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/b0iFsHBZmNm1tzpi9Zp74zUDNJQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b0iFsHBZmNm1tzpi9Zp74zUDNJQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/bwrOKvIPl4c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/6342687511504984622/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=6342687511504984622" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6342687511504984622?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/6342687511504984622?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/bwrOKvIPl4c/obscurity-and-pii.html" title="Obscurity and PII" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/obscurity-and-pii.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UDQHs5eyp7ImA9WhRTF0w.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-8291415202283555234</id><published>2011-11-08T12:21:00.001+11:00</published><updated>2011-11-08T12:21:11.523+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-08T12:21:11.523+11:00</app:edited><title>Viewing Email headers</title><content type="html">&lt;p&gt;   &lt;p style="line-height: normal; margin: 12pt 0cm 3pt" class="H2"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Arial"&gt;&lt;font style="font-size: 14pt" color="#000000"&gt;&lt;u&gt;&lt;/u&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;   &lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 11pt" color="#000000"&gt;An e-mail message is composed of a message header and the subject body. An investigation involving e-mail may hinge on successfully capturing the e-mail header. The e-mail header is imperative as it holds information detailing the e-mail’s origin. This will include the source IP address of where it came from (this can be spoofed but it is less likely), &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;the method used to send it and potentially who sent it. The subject body of the e-mail contains the message. Subsequent to copying the email message, the e-mail header can be retrieved. This process is different for each e-mail program.           &lt;br /&gt;Below we detail the process used to display the email headers in a number of common email clients.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;strong&gt;&lt;u&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;Retrieving the Email Header (Microsoft Outlook&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;) &lt;/font&gt;&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0cm 0cm 0pt" class="BdyTxt1"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 11pt" color="#000000"&gt;&amp;#160;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open Outlook and open the copied email message. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Right-click the message and click Options to open the dialog box. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the header text and make a copy of it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Paste the header text in any text editor and save the file with as Filename.txt. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Save a Copy of the E-mail message as message.msg&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 12pt" color="#000000"&gt;&lt;strong&gt;&lt;u&gt;Retrieving the Email Header (Outlook Express) &lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open Outlook Express. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Right-click the message and click Properties. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;To view the header, click Details. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Click Message Source to view the details. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and copy it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Paste the text in any text editor and save the file as Filename.txt. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Save a copy of the e-mail (with the header) to disk.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;8.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l2 level1 lfo3" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;8.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;strong&gt;&lt;u&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;Retrieving the Email Header (Eudora&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;) &lt;/font&gt;&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open Eudora. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select and go to the Inbox folder. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Double-click the message to select and open it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and copy it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Paste the text in any text editor and save the file as Filename.txt. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Save a copy of the e-mail (with the header) to disk.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l6 level1 lfo5" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;9.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo4" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 12pt" color="#000000"&gt;&lt;strong&gt;&lt;u&gt;Retrieving the Email Header&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;(AOL) &lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open AOL. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open the e-mail message. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Click the “&lt;i style="mso-bidi-font-style: normal"&gt;DETAILS&lt;/i&gt;” link. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and copy it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and save the file as Filename.htm. This may also be achieved from saving the “view source” data associated with the header.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l5 level1 lfo6" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;strong&gt;&lt;u&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;Retrieving the Email Header&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;(Hotmail&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;font style="font-size: 12pt"&gt;) &lt;/font&gt;&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Go to Hotmail and login using your web browser. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;span style="mso-bidi-font-family: verdana" lang="EN-US"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open the relevant e-mail message. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Go to Options and click Preferences. For version No.8 click Mail Display Settings. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Click Advanced Header. For version No. 8 go to Message Headers and click Advanced option. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and copy it. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and save the file as Filename.htm. This may also be achieved from saving the “view source” data associated with the header.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l7 level1 lfo7" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;8.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 12pt" color="#000000"&gt;&lt;strong&gt;&lt;u&gt;Retrieving the Email Header (Yahoo) &lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Open Yahoo. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Go to Mail Options on the right hand side. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Go to the General Preferences link and click “&lt;i style="mso-bidi-font-style: normal"&gt;Show All Headers On Incoming Messages&lt;/i&gt;” and save the message. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Select the message header text and save the file as Filename.htm. This may also be achieved from saving the “view source” data associated with the header.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Hit &amp;lt;Alt-P&amp;gt; and take a screen image of the header. Print this Image.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l4 level1 lfo8" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: 0cm; margin: 12pt 0cm 3pt; mso-list: none" class="H3"&gt;&lt;span lang="EN-US"&gt;&lt;font face="Times New Roman"&gt;&lt;font style="font-size: 12pt" color="#000000"&gt;&lt;strong&gt;&lt;u&gt;Retrieving the Email Header&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;(Pine for UNIX) &lt;/u&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;1.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Start the e-mail client program by typing “pine” at the command prompt. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;2.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;For setup options press “S”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;3.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;For the e-mail configuration press “C”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;4.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Exit the mode of configuration by pressing “E”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;5.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Save the changes by typing “Y”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;6.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;After selecting the message using the arrow keys, select “O” from the lower screen. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;7.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;View the header by typing “H”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l3 level1 lfo2" class="BdyTxt1"&gt;&lt;font face="Times New Roman"&gt;&lt;font color="#000000"&gt;&lt;span lang="EN-US"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font style="font-size: 11pt"&gt;8.&lt;/font&gt;&lt;span style="line-height: normal; font-family: "&gt;&lt;font style="font-size: 7pt"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;font style="font-size: 11pt"&gt;Close the program by typing “Q”. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-8291415202283555234?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Av4kRdw80SoFVpAViIT38jx4MKo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Av4kRdw80SoFVpAViIT38jx4MKo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Av4kRdw80SoFVpAViIT38jx4MKo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Av4kRdw80SoFVpAViIT38jx4MKo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/tlvH_zQLOQA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/8291415202283555234/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=8291415202283555234" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8291415202283555234?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/8291415202283555234?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/tlvH_zQLOQA/viewing-email-headers.html" title="Viewing Email headers" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/viewing-email-headers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUAHQHoyeCp7ImA9WhRTFkQ.&quot;"><id>tag:blogger.com,1999:blog-5766614972114406938.post-796190941611521354</id><published>2011-11-08T07:24:00.001+11:00</published><updated>2011-11-08T07:28:51.490+11:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-08T07:28:51.490+11:00</app:edited><title>Effective Enforcement in the Wild Wild Web</title><content type="html">&lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;1 Introduction&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Some time ago Hilary E Pearson (1996) noted that&lt;em&gt;, “&lt;/em&gt;&lt;a href="http://www.leginetcy.com/articles/Liability%20of%20Internet%20Service%20Providers.pdf?&amp;amp;lang=en_us&amp;amp;output=json"&gt;&lt;em&gt;in many cases, liability will depend upon how a court faced with a case of first impression analogizes a particular Internet service provider to more conventional categories of information providers. For example, should the service provider be viewed as the equivalent of the telephone company, purely a conduit for information? This might be the right analogy for the telecommunications link provider, but clearly does not fit the publisher. On the other hand, if the provider is viewed as analogous to a publisher of a printed publication, there is a much greater exposure to liability&lt;/em&gt;&lt;/a&gt;&lt;em&gt;”&lt;/em&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn1_5031" name="_ftnref1_5031"&gt;&lt;b&gt;&lt;em&gt;[1]&lt;/em&gt;&lt;/b&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;Further, it was noted that &lt;em&gt;the provider of a host computer for third party web pages could be compared to a printer or perhaps a distributor of printed publications. It could also be argued that a Usenet group or bulletin board is analogous to a library, so that the provider should be treated as the librarian&lt;/em&gt;.&lt;/p&gt;  &lt;p&gt;The foremost dilemma with the study of electronic law is the complexity and difficulty in confining its study within simple parameters. Internet and e-commerce do not define a distinct area of law as with contract&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn2_5031" name="_ftnref2_5031"&gt;[2]&lt;/a&gt; and tort law. Electronic law crosses many legal disciplines, each of which can be studied individually. Examples of a range of areas of law that electronic, e-commerce, and Internet law touch upon can be seen in the following pages. &lt;/p&gt;  &lt;h3&gt;2 Remedy in Tort and Civil Suits&lt;/h3&gt;  &lt;p&gt;The availability of the Internet Intermediary as co-targets for actions makes them susceptible to the actions of both their clients and also uninterested third parties for passing off and misleading and deceptive conduct. An action for intentional interference with business by unlawful means may also be possible. The tort of intentional interference with business by unlawful means may be available where the use of the trade mark is unlawful. &lt;/p&gt;  &lt;p&gt;The courts generally seem willing to apply conventional fault-based tort principles to weigh up the behaviour of intermediaries. The instances in which comparatively egregious conduct has ended in the liability of the intermediary are few,&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn3_5031" name="_ftnref3_5031"&gt;[3]&lt;/a&gt; and the majority of cases conclude with the absolution of the intermediaries from blame.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn4_5031" name="_ftnref4_5031"&gt;[4]&lt;/a&gt; Those circumstances that have resulted in a decision by the court that in effect declare that the intermediaries hold considerable accountability for the behaviour of any primary malfeasors have mutually in the EU and the US Congress resulted in the respective parliaments acting to overrule the decision through the legislative conceding of expansive exemptions from liability to the intermediaries.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn5_5031" name="_ftnref5_5031"&gt;[5]&lt;/a&gt; “&lt;i&gt;The paths share not only the reflexive and unreflective fear that recognition of liability for intermediaries might be catastrophic to internet commerce; they also share a myopic focus on the idea that the inherent passivity of internet intermediaries makes it normatively inappropriate to impose responsibility on them for conduct of primary malfeasors. That idea is flawed both in its generalization about the passivity of intermediaries and in its failure to consider the possibility that the intermediaries might be the most effective sources of regulatory enforcement, without regard to their blameworthiness&lt;/i&gt;”&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn6_5031" name="_ftnref6_5031"&gt;[6]&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;In the US, Congress has endorsed legislative protections for intermediaries from liability through defamation with the introduction of the Communications Decency Act&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn7_5031" name="_ftnref7_5031"&gt;[7]&lt;/a&gt;. In 47 U.S.C. §230, it is unambiguously positioned as regarding internet regulation&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn8_5031" name="_ftnref8_5031"&gt;[8]&lt;/a&gt; that the act introduced a series of “Good Samaritan provisions” as a part of the &lt;i&gt;Telecommunications Act of 1996.&lt;/i&gt; This was tested in &lt;i&gt;DiMeo v Max&lt;/i&gt; (2007),&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn9_5031" name="_ftnref9_5031"&gt;[9]&lt;/a&gt; in which the court found the defendant not liable for comments left by third parties on a blog. The plaintiff alleged that the defendant was a publisher of the comments hosted on the website but did not allege that the defendant authored the comments on the website or that the defendant was an information content provider. Under 47 U.S.C. § 230 (f)(3), the court determined “&lt;i&gt;the website posts alleged in the complaint must constitute information furnished by third party information content providers&lt;/i&gt;&amp;quot; and as a consequence immunity applied to the forum board operator. The Court upheld the dismissal of the suit.&lt;/p&gt;  &lt;p&gt;The act, first passed in 1996&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn10_5031" name="_ftnref10_5031"&gt;[10]&lt;/a&gt; and subsequently amended in 1998,&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn11_5031" name="_ftnref11_5031"&gt;[11]&lt;/a&gt; has the apparent rationale of minimising Internet regulations in order to promote the development of the Internet and safeguard the market for Internet service. The internet has consequently become so essential to daily life that it is improbable that the addition of extra legislation would intimidate service providers away from the provision of services at a competitive rate.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn12_5031" name="_ftnref12_5031"&gt;[12]&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In the US, 47 U.S.C. § 230(c)(1) provides a defence for ISPs stating that, “&lt;i&gt;No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider&lt;/i&gt;.” This statute would seem&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn13_5031" name="_ftnref13_5031"&gt;[13]&lt;/a&gt; to afford absolute immunity from any responsibility. Contrasting the DMCA, the ISP or ICP could chose not to do away with material in the event that the ISP or ICP has tangible awareness of the defamatory nature of material it is in fact hosting.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn14_5031" name="_ftnref14_5031"&gt;[14]&lt;/a&gt; Notwithstanding the focal point of this legislation having been towards liability for defamation, it has pertained to seemingly unrelated auction intermediaries, including eBay.&lt;a name="_Ref93056278"&gt;&lt;/a&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn15_5031" name="_ftnref15_5031"&gt;[15]&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Inside the European Union, judgments obtained in the courts of one state are enforceable in any other state included within the Brussels Convention. If not, a judgment in one state will be enforceable in another only where there is a bilateral treaty creating the provision for such reciprocal enforcement between them. Frequently, these treaties add formalities surrounding the enforcement process that offer the courts of the jurisdiction in which the defendant is situated prudence both as to a decision to enforce, or to what degree. It is consequently vital when deciding on a jurisdiction to bring suit to decide if any judgment obtained is enforceable against a defendant who may in effect be judgement proof.&lt;/p&gt;  &lt;h3&gt;&lt;a name="_Toc191786247"&gt;2. Cyber Negligence&lt;/a&gt;&lt;/h3&gt;  &lt;p&gt;Not acting to correct a vulnerability in a computer system may give rise to an action in negligence if another party suffers loss or damage as the result of a cyber-attack or employee fraud. Given proximity&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn16_5031" name="_ftnref16_5031"&gt;[16]&lt;/a&gt;, a conception first established in &lt;i&gt;Caparo Industries Plc. v. Dickman&lt;/i&gt;, [1990]&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn17_5031" name="_ftnref17_5031"&gt;[17]&lt;/a&gt; and reasonable foreseeability as established in &lt;a name="OLE_LINK2"&gt;&lt;i&gt;Anns v. Merton London Borough Council&lt;/i&gt;, [1978]&lt;/a&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn18_5031" name="_ftnref18_5031"&gt;[18]&lt;/a&gt; A.C. 728, the question of whether there exists a positive duty on a party to act so as to prevent criminals causing harm or economic loss to others will be likely found to exist in the cyber world. The test of reasonable foreseeability has however been rendered to a preliminary factual enquiry not to be incorporated into the legal test.&lt;/p&gt;  &lt;p&gt;The Australian High Court regarded a parallel scenario, whether a party has a duty to take reasonable steps to prevent criminals causing injury to others in &lt;i&gt;Triangle Shopping Centre Pty Ltd v Anzil&lt;/i&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn19_5031" name="_ftnref19_5031"&gt;[19]&lt;/a&gt;. The judgment restated the principle established by Brennan CJ in &lt;i&gt;Sutherland Shire Council v Heyman&lt;/i&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn20_5031" name="_ftnref20_5031"&gt;[20]&lt;/a&gt;. The capacity of a plaintiff to recover hinges on the plaintiff’s ability to demonstrate a satisfactory nexus (e.g. a dependence or assumption of responsibility) between the plaintiff and the defendant such that it gives rise to a duty on the defendant to take reasonable steps to prevent third parties causing loss to the plaintiff&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn21_5031" name="_ftnref21_5031"&gt;[21]&lt;/a&gt;. Consequently, if a plaintiff in a case involving a breach of computer security could both demonstrate that the defendant did not in fact take reasonable measures to ensure the security of their computer systems (as against both internal and external assault), and they show the act of the third person (e.g. an attacker/hacker or even a fraudulent employee) occurred as a direct consequence of the defendant's own fault or breach of duty, then an action in negligence is likely to succeed&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn22_5031" name="_ftnref22_5031"&gt;[22]&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Many organisations state that current standards of corporate governance for IT systems pose a problem due to the large number of competing standards. However, it needs to be taken into account that all of these standards maintain a minimum set of analogous requirements that few companies presently meet. Most of these standards, such as the PCI-DSS&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn23_5031" name="_ftnref23_5031"&gt;[23]&lt;/a&gt; and COBIT&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn24_5031" name="_ftnref24_5031"&gt;[24]&lt;/a&gt;, set a requirement to monitor systems. COBIT control ME2 (Monitor and Evaluate Internal Controls) is measured through recording the “&lt;i&gt;number of major internal control breaches&lt;/i&gt;”. PCI-DSS at 10.5.5 states a minimum requirement to “&lt;i&gt;use file integrity monitoring and change detection software on logs to ensure that existing log data cannot be changed without generating alerts (although new data being added should not cause an alert)”.&lt;/i&gt; As a general minimum, it may be seen that an organisation needs to maintain a sufficiently rigorous monitoring regime to meet these standards.&lt;/p&gt;  &lt;p&gt;Installation guidelines provided by the Centre for Internet Security (CIS)&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn25_5031" name="_ftnref25_5031"&gt;[25]&lt;/a&gt; openly provide system benchmarks and scoring tools that contain the “&lt;i&gt;consensus minimum due care security configuration recommendations&lt;/i&gt;” for the most widely deployed operating systems and applications in use. The baseline templates will not themselves stop a determined attacker, but could be used to demonstrate minimum due care and diligence. &lt;/p&gt;  &lt;p&gt;It is interesting to contrast this general proposition with a peculiar case where the plaintiff went to great lengths in an attempt to recover loss caused by its own negligence, namely loss suffered due to computer fraud perpetrated by its own employee in its own system. &lt;/p&gt;  &lt;p&gt;In &lt;i&gt;Mercedes Benz (NSW) v ANZ and National Mutual Royal Savings Bank Ltd&lt;/i&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn26_5031" name="_ftnref26_5031"&gt;[26]&lt;/a&gt; (unreported), the Supreme Court of New South Wales considered if a duty to avert fraud would occur in cases where there is an anticipated prospect of loss. The Mercedes Benz employee responsible for the payroll system fraudulently misappropriated nearly $1.5 million by circumventing controls in the payroll software. Mercedes Benz alleged that the defendants, ANZ and NMRB, were negligent in paying on cheques that where fraudulently procured by the employee and in following her direction. The plaintiff's claim was dismissed by the court. It was held that employers who are careless in their controls to prevent fraud using only very simple systems for the analysis of employee activities will be responsible for the losses that result as a consequence of deceitful acts committed by the organisations’ employees. It takes little deliberation to extend this finding to payment intermediaries.&lt;/p&gt;  &lt;p&gt;The decision was founded on the judgment of Holt CJ in &lt;i&gt;Hern v Nichols&lt;/i&gt; (1701)&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn27_5031" name="_ftnref27_5031"&gt;[27]&lt;/a&gt; that stated in &amp;quot;&lt;i&gt;seeing somebody must be a loser by this deceit, it is more reason that he that employs and puts a trust and confidence in the deceiver should be a loser than a stranger&lt;/i&gt;&amp;quot;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn28_5031" name="_ftnref28_5031"&gt;[28]&lt;/a&gt;. The question remains open as to the position that may result from unsound practices operated not by the plaintiff but by an organisation in supplying services under an outsourcing agreement. In either event, the requirement for an organisation to provide controls to ensure a minimum level of system security is clear.&lt;/p&gt;  &lt;p&gt;The situation is further compounded in instances of cyber-attack that lead to a loss. An innocent third party that suffers an attack that originates from an inadequately secured system would be able to easily demonstrate a lack of reasonable care if the minimum consensus standards mentioned above are not achieved. Coupled with facts demonstrating that the attack originated from the defendant’s insecure system, the evidence would provide the requisite substantiation of both proximity and reasonable foreseeability.&lt;/p&gt;  &lt;h3&gt;&lt;a name="_Toc191786258"&gt;3. Prevention is the key&lt;/a&gt;&lt;/h3&gt;  &lt;p&gt;The vast majority of illicit activity and fraud committed across the Internet could be averted at least curtailed if destination ISP and payment intermediaries implemented effective processes for monitoring and controlling access to, and use of, their networks. Denning (1999) expresses that, &amp;quot;&lt;i&gt;even if an offensive operation is not prevented, monitoring might detect it while it is in progress, allowing the possibility of aborting it before any serious damage is done and enabling a timely response&lt;/i&gt;”&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn29_5031" name="_ftnref29_5031"&gt;[29]&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;As is being noted above, there are a wide variety of commonly accepted practices, standards and means of ensuring that systems are secured. Many of the current economic arguments used by Internet intermediaries are short-sighted to say the best. The growing awareness of remedies that may be attained through litigation coupled with greater calls for corporate responsibility&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn30_5031" name="_ftnref30_5031"&gt;[30]&lt;/a&gt; have placed an ever growing burden on organisations that fail to implement a culture of strong corporate governance. In the short term the economic effects of implementing sound monitoring and security controls may seem high, but when compared to the increasing volume of litigation that is starting to incorporate Internet intermediaries, the option of not securing a system and implement in monitoring begins to pale.&lt;/p&gt;  &lt;p&gt;The Internet remains the wild, wild, web not because of a lack of laws, but rather the difficulty surrounding enforcement. The Internet’s role is growing on a daily basis and has reached a point where it has become ubiquitous and an essential feature of daily life both from a personal perspective and due to its role in the international economy. If an ISP is to be held liable for authorisation as an intermediary, it must have knowledge, or otherwise deduce that infringements are proceeding.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn31_5031" name="_ftnref31_5031"&gt;[31]&lt;/a&gt; Although, intermediaries commonly monitor their systems and have the means to suspect when infringements are occurring, Internet intermediaries also require the authority to prevent infringement if they are to be held liable for authorisation, a condition that entails an aspect of control.&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftn32_5031" name="_ftnref32_5031"&gt;[32]&lt;/a&gt;&lt;/p&gt;  &lt;h3&gt;References&lt;/h3&gt;  &lt;p&gt;1. Barker, J. Cam, (2004) “Grossly Excessive Penalties in the Battle Against Illegal File-Sharing: The Troubling Effects of Aggregating Minimum Statutory Damages for Copyright Infringement”, 83 Texas L. Rev. 525 &lt;/p&gt;  &lt;p&gt;2. Bick, Jonathan D., (1998) “Why Should the Internet Be Any Different?” 19 Pace L. Rev. 41, 63 &lt;/p&gt;  &lt;p&gt;3. Bowne, A (1997) “Trade Marks and Copyright on the Internet” 2 Media and Arts Law Review 135&lt;/p&gt;  &lt;p&gt;4. Collins M, (2000) “Liability of internet intermediaries in Australian defamation law” Media &amp;amp; Arts Law Review 209&lt;/p&gt;  &lt;p&gt;5. Cooney, K (1997) “Liability for On-line Images: How an Ancient Right Protects the Latest in Net Functions” 16 Communications Law Bulletin 5 &lt;/p&gt;  &lt;p&gt;6. Demott, Deborah A. (2003) &amp;quot;When is a Principal Charged with an Agent's Knowledge?&amp;quot; 13 Duke Journal of Comparative &amp;amp; International Law. 291&lt;/p&gt;  &lt;p&gt;7. Denning, Dorothy E. “Information Warfare and Security”, ACM Press, New York, 1999&lt;/p&gt;  &lt;p&gt;8. Eisenberg J, (2000) “Safely out of site: the impact of the new online content legislation on defamation law” UNSW Law Journal&lt;/p&gt;  &lt;p&gt;9. Gilchrist, Simon (1998) “Telstra v Apra –Implications for the Internet” [1998] CTLR 16.&lt;/p&gt;  &lt;p&gt;10. Hare, Christopher (2004) “Identity Mistakes: A Missed Opportunity?” The Modern Law Review, Volume 67 Page 993 - November 2004 Volume 67 Issue 6&lt;/p&gt;  &lt;p&gt;11. Harmon, Amy (2003) “Subpoenas Sent to File Sharers Prompt Anger and Remorse”, N.Y. Times, July 28, 2003, at C1.&lt;/p&gt;  &lt;p&gt;12. Hazen, Thomas L. (1977) “Transfers of Corporate Control and Duties of Controlling Shareholders. Common Law, Tender Offers, Investment Companies. And a Proposal for Reform” University of Pennsylvania Law Review, Vol. 125, No. 5 (May, 1977), pp. 1023-1067&lt;/p&gt;  &lt;p&gt;13. Kao, A. (2005) “RIAA v. Verizon: Applying the Subpoena Provision of the DMCA”, 19 Berkeley Tech. L.J. 405, 408.&lt;/p&gt;  &lt;p&gt;14. Kraakman, Reinier H. (1984) “857 CORPORATE LIABILITY STRATEGIES AND THE COSTS OF LEGAL CONTROLS”, Yale Law Journal April, 1984 (93 Yale L.J. 857)&lt;/p&gt;  &lt;p&gt;15. Landes, William &amp;amp; Lichtman, Douglas, (2003) “Indirect Liability for Copyright Infringement: An Economic Perspective”, 16 HARV. J.L. &amp;amp; TECH. 395.&lt;/p&gt;  &lt;p&gt;16. Lemley Mark A. &amp;amp; Reese, R. A., (2004) “Reducing Digital Copyright Infringement without Restricting Innovation”, 56 STAN. L. REV. 1345.&lt;/p&gt;  &lt;p&gt;17. Leroux, Olivier (2004) “Legal admissibility of electronic evidence 1”, International Review of Law, Computers &amp;amp; Technology; Volume 18, Number 2 / July 2004; Pp 193-220&lt;/p&gt;  &lt;p&gt;18. Lichtman, Douglas Gary &amp;amp; Posner, Eric A., (July 2004). &amp;quot;Holding Internet Service Providers Accountable&amp;quot;. U Chicago Law &amp;amp; Economics, Olin Working Paper No. 217. Available at SSRN: http://ssrn.com/abstract=573502 or DOI: 10.2139/ssrn.573502 (viewed 15 Jan 2008)&lt;/p&gt;  &lt;p&gt;19. Lim, YF, (1997) “Internet Service Providers and Liability for Copyright Infringement through Authorisation” 8 Australian Intellectual Property Law Journal 192. &lt;/p&gt;  &lt;p&gt;20. Loughnan, S., (1997) “Service Provider Liability for User Copyright Infringement on the Internet” 8 Australian Intellectual Property Law Journal 18 &lt;/p&gt;  &lt;p&gt;21. MacMillian, Blakeney “The Internet and Communications Carriers’ Copyright Liability” [1998] EIPR 52&lt;/p&gt;  &lt;p&gt;22. Mann, Ronald J., (2004) “Regulating Internet Payment Intermediaries”, 82 Texas L. Rev. 681, 681&lt;/p&gt;  &lt;p&gt;23. Mann, R. &amp;amp; Belzley, S (2005) “The Promise of the Internet Intermediary Liability” 47 William and Mary Law Review 1 &amp;lt;http://ssrn.com/abstract=696601&amp;gt; at 27 July 2007]&lt;/p&gt;  &lt;p&gt;24. Olovsson, Tomas, (1992) “A Structured Approach to Computer Security”, Department of Computer Engineering Chalmers University of Technology, Gothenburg SWEDEN, Technical Report No 122, 1992&lt;/p&gt;  &lt;p&gt;25. Paynter, H &amp;amp; Foreman, R (1998) “Liability of Internet Service Providers for Copyright Infringement”, University of NSW Law Journal, [1998] UNSWLJ 61&lt;/p&gt;  &lt;p&gt;26. Quimbo, Rodolfo Noel S (2003) “Legal Regulatory Issues in the Information Economy”, e-ASEAN Task Force, UNDP-APDIP (MAY 2003)&lt;/p&gt;  &lt;p&gt;27. Reidenberg, J (2004) “States and Internet Enforcement”, 1 UNIV. OTTAWA L. &amp;amp; TECH. J. 1&lt;/p&gt;  &lt;p&gt;28. Scandariato, R.; Knight, J.C. (2004) “The design and evaluation of a defense system for Internet worms” Proceedings of the 23rd IEEE International Symposium on Reliable Distributed Systems, 2004. Volume, Issue, 18-20 Oct. 2004 Pp 164 - 173&lt;/p&gt;  &lt;p&gt;29. 28Shapiro, Andrew L., (1998) “Digital Middlemen and the Architecture of Electronic Commerce”, 24 OHIO N.U. L. REV. 795 &lt;/p&gt;  &lt;p&gt;30. Slawotsky, Joel (2005) “Doing Business around the World: Corporate Liability under the Alien Tort Claims Act” 2005 MICH. ST. L. REV. 1065&lt;/p&gt;  &lt;p&gt;31. 30Smith, Russell. (2000) “Confronting fraud in the digital age”, Presented at Fraud prevention and control conference, Gold Coast Australia 24-25 August 2000&lt;/p&gt;  &lt;p&gt;32. Tickle, K. (1995) “The Vicarious Liability of Electronic Bulletin Board Operators for the Copyright Infringement Occurring on Their Bulletin Boards”, 80 Iowa Law Review 391 at 397&lt;/p&gt;  &lt;p&gt;33. Williams, K. S. (2003) “Child Pornography and Regulation on the Internet in the United Kingdom: The Impact on Fundamental Rights and International Relations”, Child Abuse Review, Volume 14, Issue 6 , Pages 415 – 429 (Special Issue: New Technologies . Issue Edited by Bernard Gallagher). Published Online: 20 Dec 2005, John Wiley &amp;amp; Sons, Ltd.&lt;/p&gt;  &lt;p&gt;34. Wu, Tim, (2003) “When Code Isn’t Law”, 89 Va. L. Rev. 679 &lt;/p&gt;  &lt;p&gt;35. Zittrain, Jonathan (2003) “Internet Points of Control”, 44 B.C. L. REV. 65&lt;/p&gt;  &lt;hr align="left" size="1" width="33%" /&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref1_5031" name="_ftn1_5031"&gt;[1]&lt;/a&gt; The distributed nature of the Internet means that a publisher can reach far more people. A company with a web site in the UK for instance has direct access to the US, Canada, Australia and many other countries with the primary limitations being language.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref2_5031" name="_ftn2_5031"&gt;[2]&lt;/a&gt; It has been argued that the digital contract may appear on the computer screen to consist of words in a written form but merely consist of a virtual representation . The &lt;b&gt;Electronic Communications Act 2000&lt;/b&gt; [ECA] has removed the uncertainty and doubt surrounding the question as to the nature of electronic form used in the construction of a contract. In this, the ECA specifies that the electronic form of a contract is to be accepted as equivalent to a contract in writing&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref3_5031" name="_ftn3_5031"&gt;[3]&lt;/a&gt;&lt;i&gt;.See&lt;/i&gt; A &amp;amp; M Records, Inc. v. Napster, Inc., 114 F. Supp. 2d 896 (N.D. Cal. 2000).&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref4_5031" name="_ftn4_5031"&gt;[4]&lt;/a&gt;.For criticism of this perspective, see Landes &amp;amp; Lichtman.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref5_5031" name="_ftn5_5031"&gt;[5]&lt;/a&gt;.The most obvious example of this action can be found in the history of the Communications Decency Act. Congress directly responded to the ISP liability found in &lt;i&gt;Stratton Oakmont, Inc. v. Prodigy Services&lt;/i&gt;, 23 Media L. Rep. (BNA) 1794 (N.Y. Sup. Ct. 1995), 1995 WL 323710, by including immunity for ISPs in the CDA, 47 U.S.C. § 230(c)(1) (2004) (exempting ISPs for liability as the “publisher or speaker of any information provided by another information content provider”), which was pending at the time of the case. Similarly, Title II of the Digital Millennium Copyright Act, codified at 17 U.S.C. § 512, settled tension over ISP liability for copyright infringement committed by their subscribers that had been created by the opposite approaches to the issue by courts. &lt;i&gt;Compare &lt;/i&gt;Playboy Enters., Inc. v. Frena, 839 F. Supp. 1552, 1556 (M.D. Fla. 1993) (finding liability), &lt;i&gt;with&lt;/i&gt; Religious Tech. Ctr. v. Netcom, Inc., 907 F. Supp. 1361, 1372 (N.D. Cal. 1995) (refusing to find liability).&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref6_5031" name="_ftn6_5031"&gt;[6]&lt;/a&gt; Mann, R. &amp;amp; Belzley, S (2005) “The Promise of the Internet Intermediary Liability” 47 William and Mary Law Review 1 &amp;lt;http://ssrn.com/abstract=696601&amp;gt; at 27 July 2007]&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref7_5031" name="_ftn7_5031"&gt;[7]&lt;/a&gt; The Communications Decency Act of 1996 (CDA)&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref8_5031" name="_ftn8_5031"&gt;[8]&lt;/a&gt;.47 U.S.C. § 230(b) (2004) (emphasis added)&lt;/p&gt;  &lt;p&gt;“&lt;i&gt;It is the policy of the United States—&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;(1) to promote the continued development of the Internet and other interactive computer services and other interactive media;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;(2) to preserve the vibrant and competitive free market that presently exists for the Internet and other interactive computer services, unfettered by Federal or State regulation;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;(3) to encourage the development of technologies which maximize user control over what information is received by individuals, families, and schools who use the Internet and other interactive computer services;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;(4) to remove disincentives for the development and utilization of blocking and filtering technologies that empower parents to restrict their children’s access to objectionable or inappropriate online material; and&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;(5) to ensure vigorous enforcement of Federal criminal laws to deter and punish trafficking in obscenity, stalking, and harassment by means of computer&lt;/i&gt;”.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref9_5031" name="_ftn9_5031"&gt;[9]&lt;/a&gt; WL 2717865 (3rd Cir. Sept. 19, 2007); See also &lt;i&gt;Fair Housing Council of San Fernando Valley v. Roommates.com, LLC&lt;/i&gt; , CV-03-09386-PA (9th Cir. May 15, 2007); and &lt;i&gt;Universal Communication Systems, Inc. v. Lycos, Inc&lt;/i&gt;. , 2007 WL 549111 (1st Cir. Feb. 23, 2007)&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref10_5031" name="_ftn10_5031"&gt;[10]&lt;/a&gt;.&lt;a href="http://web2.westlaw.com/find/default.wl?DB=1000819&amp;amp;DocName=USPL104%2D104&amp;amp;FindType=L&amp;amp;AP=&amp;amp;RS=WLW4.09&amp;amp;VR=2.0&amp;amp;FN=_top&amp;amp;SV=Split&amp;amp;MT=Westlaw"&gt;1996, Pub. L. 104-104, Title I, § 509&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref11_5031" name="_ftn11_5031"&gt;[11]&lt;/a&gt;.&lt;a href="http://web2.westlaw.com/find/default.wl?DB=1000819&amp;amp;DocName=USPL105%2D277&amp;amp;FindType=L&amp;amp;AP=&amp;amp;RS=WLW4.09&amp;amp;VR=2.0&amp;amp;FN=_top&amp;amp;SV=Split&amp;amp;MT=Westlaw"&gt;1998, Pub. L. 105-277, Div. C, Title XIV, § 1404(a)&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref12_5031" name="_ftn12_5031"&gt;[12]&lt;/a&gt;.There remains, however, the fear that additional regulation will stifle innovation in the industry. Would, for instance, eBay enter the market as a new company today if it were liable for trademark infringement it facilitated? Such liability adds new start-up and ongoing costs that may make some new ventures unprofitable (or even more unprofitable). For an article addressing regulation in this way, see Lemley &amp;amp; Reese.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref13_5031" name="_ftn13_5031"&gt;[13]&lt;/a&gt;.There is at least the possibility that the statute would permit a State to require intermediaries to act. &lt;i&gt;See &lt;/i&gt;Doe v. GTE Corp. 347 F.3d 655 (7th Cir. 2003) (per Easterbrook, J.) (suggesting that Section 230(e)(3) “would not pre-empt state laws or common-law doctrines that induce or require ISPs to protect the interests of third parties”).&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref14_5031" name="_ftn14_5031"&gt;[14]&lt;/a&gt;.Thus minimising the likelihood of a decision such as &lt;i&gt;Godfrey &lt;/i&gt;in the United States. &lt;i&gt;See supra &lt;/i&gt;note 102.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref15_5031" name="_ftn15_5031"&gt;[15]&lt;/a&gt;.Gentry v. eBay, Inc., 121 Cal. Rptr. 2d 703 (Ct. App. 2002)&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref16_5031" name="_ftn16_5031"&gt;[16]&lt;/a&gt; Proximity, a notion first established in &lt;i&gt;Caparo Industries Plc. v. Dickman&lt;/i&gt;, [1990] 2 A.C. 605, is the initial phase of the assessment. The subsequent phase enquires as to whether there are policy considerations which would reduce or counteract the duty created under the initial stage. Mutually, the phases are to be met with reference to the facts of cases previously determined. The dearth of such cases would not however avert the courts from finding a duty of care.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref17_5031" name="_ftn17_5031"&gt;&lt;i&gt;&lt;b&gt;[17]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; [1990] 2 A.C. 605&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref18_5031" name="_ftn18_5031"&gt;&lt;i&gt;&lt;b&gt;[18]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; [1978] A.C. 728&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref19_5031" name="_ftn19_5031"&gt;&lt;i&gt;&lt;b&gt;[19]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt;&lt;i&gt; &lt;/i&gt;Modbury Triangle Shopping Centre Pty Ltd v Anzil&lt;i&gt; [2000] HCA 61.&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref20_5031" name="_ftn20_5031"&gt;&lt;i&gt;&lt;b&gt;[20]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; (1985) 157 CLR 424.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref21_5031" name="_ftn21_5031"&gt;&lt;i&gt;&lt;b&gt;[21]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; Dixon J elucidated how a “special relationship” of this variety may occur in Smith v Leurs (1945) 70 CLR 256. This case was derived from an indication of occurrences that entail a special danger and the control or of actions or conduct of the third person; See also [2000] HCA 61, para 140.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref22_5031" name="_ftn22_5031"&gt;[22]&lt;/a&gt; See: Clerk and Lindsell on Torts, 19th Edition (2006), Chapter 28, paragraph 28-05&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref23_5031" name="_ftn23_5031"&gt;[23]&lt;/a&gt; PCI-DSS (version 1.1) is the Payment Card Industry Data Security Standard and is contractually required to be adhered to by all merchants that process VISA, Mastercard and other payment card products. This requirement and standard is maintained by the PCI Standards Council at &lt;a href="https://www.pcisecuritystandards.org/"&gt;https://www.pcisecuritystandards.org/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref24_5031" name="_ftn24_5031"&gt;[24]&lt;/a&gt; COBIT v 4.1 is the computer control objectives and standard maintained by ISACA at &lt;a href="http://www.cobitonline.info"&gt;http://www.cobitonline.info&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref25_5031" name="_ftn25_5031"&gt;[25]&lt;/a&gt; CIS benchmark and scoring tools are available from &lt;a href="http://www.cisecurity.org/"&gt;http://www.cisecurity.org/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref26_5031" name="_ftn26_5031"&gt;&lt;i&gt;&lt;b&gt;[26]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; No. 50549 of 1990.&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref27_5031" name="_ftn27_5031"&gt;[27]&lt;/a&gt; (1701) 1 Salk 289&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref28_5031" name="_ftn28_5031"&gt;&lt;i&gt;&lt;b&gt;[28]&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; Id., at 358. &lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref29_5031" name="_ftn29_5031"&gt;[29]&lt;/a&gt; Dorothy E. Denning, Information Warfare and Security, ACM Press, New York, 1999&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref30_5031" name="_ftn30_5031"&gt;[30]&lt;/a&gt; See for instance Hazen (1977); Gagnon, Macklin &amp;amp; Simons (2003) and Slawotsky (2005)&lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref31_5031" name="_ftn31_5031"&gt;[31]&lt;/a&gt; Ibid, Gibbs J at 12-13; cf Jacobs J at 21-2. See also Microsoft Corporation v Marks (1995) 33 IPR 15. &lt;/p&gt;  &lt;p&gt;&lt;a href="file:///D:/Data/Publishing/2010 PhD/2011 PhD 11 - SECAU 1/#_ftnref32_5031" name="_ftn32_5031"&gt;[32]&lt;/a&gt; Ibid, University of New South Wales v Moorhouse, supra, per Gibbs J at 12; WEA International Inc v Hanimex Corp Limited (1987) 10 IPR 349 at 362; Australasian Performing Right Association v Jain (1990) 18 IPR 663. See also Lim YF, 199-201; S Loughnan, See also BF Fitzgerald, “Internet Service Provider Liability” in Fitzgerald, A., Fitzgerald, B., Cook, P. &amp;amp; Cifuentes, C. (Eds.), Going Digital: Legal Issues for Electronic Commerce, Multimedia and the Internet, Prospect (1998) 153.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5766614972114406938-796190941611521354?l=gse-compliance.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3SS9K4Y0naP_SVOIV83DnMHeNck/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3SS9K4Y0naP_SVOIV83DnMHeNck/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3SS9K4Y0naP_SVOIV83DnMHeNck/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3SS9K4Y0naP_SVOIV83DnMHeNck/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/CrackedInsecureAndGenerallyBroken/~4/Bd1Dm4Pb_ho" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://gse-compliance.blogspot.com/feeds/796190941611521354/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5766614972114406938&amp;postID=796190941611521354" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/796190941611521354?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5766614972114406938/posts/default/796190941611521354?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/CrackedInsecureAndGenerallyBroken/~3/Bd1Dm4Pb_ho/effective-enforcement-in-wild-wild-web.html" title="Effective Enforcement in the Wild Wild Web" /><author><name>Dr Craig S Wright GSE</name><uri>http://www.blogger.com/profile/08415993939211056384</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://3.bp.blogspot.com/-NsnvOGGy5E0/TqCy_3bVqCI/AAAAAAAAFHY/_wJnnUJZV5M/s220/276291_1455443729_1771437217_q.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://gse-compliance.blogspot.com/2011/11/effective-enforcement-in-wild-wild-web.html</feedburner:origLink></entry></feed>

