<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DU8EQXs5eip7ImA9WxNUF0U.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166</id><updated>2009-11-09T12:30:00.522-05:00</updated><title>Devil's Advocate Security</title><subtitle type="html">&lt;center&gt;Devil's Advocate Security is a blog dedicated to even handed discussion of security topics, security news, and  observations from the front lines of the daily business of IT security.&lt;/center&gt;</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://devilsadvocatesecurity.blogspot.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>308</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/DevilsAdvocateSecurity" type="application/atom+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;DU8EQXs4eip7ImA9WxNUF0U.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-3058840933817618622</id><published>2009-11-09T12:30:00.000-05:00</published><updated>2009-11-09T12:30:00.532-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-09T12:30:00.532-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IPhone security" /><category scheme="http://www.blogger.com/atom/ns#" term="IPhone" /><category scheme="http://www.blogger.com/atom/ns#" term="iPhone worm" /><title>First iPhone Worm in the wild - for Jailbroken iPhones only</title><content type="html">PMP Today &lt;a href="http://www.pmptoday.com/2009/11/08/jailbroken-iphone-worm-found-dangers-of-jailbreak-rick-astley-photo/"&gt;reports&lt;/a&gt; that the first iPhone targeted worm is hitting jailbroken iPhones due to a standard SSH password. The worm is a mobile device &lt;a href="http://www.google.com/url?sa=t&amp;amp;source=web&amp;amp;ct=res&amp;amp;cd=2&amp;amp;ved=0CA8QFjAB&amp;amp;url=http%3A%2F%2Fen.wikipedia.org%2Fwiki%2FRickrolling&amp;amp;rct=j&amp;amp;q=rick+roll&amp;amp;ei=lBz4StqaIYzV8Ablj9TzCQ&amp;amp;usg=AFQjCNGN_tC0JjE4zrfjQLyzpk6jmalOPQ"&gt;Rick Roll&lt;/a&gt;, resulting in a Rick Astley photo being set as the phone's background.&lt;br /&gt;&lt;br /&gt;The easy fix is, of course, to not use a default SSH password - "&lt;a href="http://www.the-iblog.com/2008/11/24/tip-change-your-iphones-ssh-password/"&gt;alpine&lt;/a&gt;" wasn't exactly a good password to start with.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-3058840933817618622?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/3058840933817618622/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=3058840933817618622" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3058840933817618622?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3058840933817618622?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/b3lMae1dySU/first-iphone-worm-in-wild-for.html" title="First iPhone Worm in the wild - for Jailbroken iPhones only" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/11/first-iphone-worm-in-wild-for.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUNQ38zeyp7ImA9WxNUFEo.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-5994079194783384890</id><published>2009-11-05T21:03:00.004-05:00</published><updated>2009-11-05T21:08:12.183-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-05T21:08:12.183-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security humor" /><category scheme="http://www.blogger.com/atom/ns#" term="risk assessment" /><title>Risky Behavior: Making Risk Assessment Fun</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://safetycenter.navy.mil/PHOTO/archive/archive_351-400/photo354.asp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 360px; height: 582px;" src="http://safetycenter.navy.mil/PHOTO/images/images-351-400/photo354-2.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The Naval Safety Center's &lt;a href="http://safetycenter.navy.mil/PHOTO/index.asp"&gt;Picture of the Week&lt;/a&gt; often provides a great visual aid when discussing risks - I find that audiences get a kick out of them, and they can help break the ice when starting a risk assessment. This one? I'm pretty sure that's an integrity risk (for his bones), and an availability risk (to his services). Impact? High! Probability? Well...that depends.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-5994079194783384890?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/5994079194783384890/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=5994079194783384890" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5994079194783384890?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5994079194783384890?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/PjPIqE2dFsU/risky-behavior-making-risk-assessment.html" title="Risky Behavior: Making Risk Assessment Fun" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/11/risky-behavior-making-risk-assessment.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYHQHw5fSp7ImA9WxNUEU8.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-3976579689198556611</id><published>2009-11-01T20:34:00.006-05:00</published><updated>2009-11-01T20:42:11.225-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-01T20:42:11.225-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="risk word map" /><category scheme="http://www.blogger.com/atom/ns#" term="risk assessment" /><title>Visualizing a Risk Vocabulary</title><content type="html">&lt;a href="http://www.wordle.net/"&gt;Worlde.net&lt;/a&gt;'s word visualization tool can be a great way to map out words and concepts. The Wikipedia text for Risk Assessment became part of a presentation I am building for a presentation that I was asked to provide as a guest speaker in an MBA class. Here's what is looks like:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_wgqJ4KQQva8/Su43el1c9dI/AAAAAAAAALI/Q61YXbNcQfs/s1600-h/risk_wordmap.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 252px;" src="http://3.bp.blogspot.com/_wgqJ4KQQva8/Su43el1c9dI/AAAAAAAAALI/Q61YXbNcQfs/s400/risk_wordmap.jpg" alt="" id="BLOGGER_PHOTO_ID_5399314001955714514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The map for &lt;a href="http://en.wikipedia.org/wiki/Computer_virus"&gt;computer virus&lt;/a&gt; is also interesting:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wgqJ4KQQva8/Su44rcfMx_I/AAAAAAAAALQ/JlbG9oTl_Ic/s1600-h/virus_wordmap.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 263px;" src="http://2.bp.blogspot.com/_wgqJ4KQQva8/Su44rcfMx_I/AAAAAAAAALQ/JlbG9oTl_Ic/s400/virus_wordmap.jpg" alt="" id="BLOGGER_PHOTO_ID_5399315322296387570" border="0" /&gt;&lt;/a&gt;I suspect that these will be useful visual aids in my presentations - a new way to present security concepts is often helpful, particularly when dealing with a non-IT staff audience.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-3976579689198556611?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/3976579689198556611/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=3976579689198556611" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3976579689198556611?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3976579689198556611?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/QButxK1NRgc/visualizing-risk-vocabulary.html" title="Visualizing a Risk Vocabulary" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_wgqJ4KQQva8/Su43el1c9dI/AAAAAAAAALI/Q61YXbNcQfs/s72-c/risk_wordmap.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/11/visualizing-risk-vocabulary.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMEQno5cSp7ImA9WxNVGUw.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-656511323186605475</id><published>2009-10-30T12:00:00.000-04:00</published><updated>2009-10-30T12:00:03.429-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-30T12:00:03.429-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="information security jobs" /><category scheme="http://www.blogger.com/atom/ns#" term="security job skills" /><title>Future Proofing an Information Security Job</title><content type="html">One of the more interesting information security job questions that I've seen recently is "How do you future proof a security job?".&lt;br /&gt;&lt;br /&gt;That's an interesting question - security, like much of IT has changed significantly over the past few years, and the skillsets required have changed or matured. A decade ago, there were far fewer dedicated information security positions, web security was just starting to become a visible issue, and intrusion detection was in its infancy. We've come from a world where local networks mean that copied floppies and boot sector viruses were our main threat to a world where even our phones are possible threat vectors.&lt;br /&gt;&lt;br /&gt;How then, can an information technology security professional stay relevant?&lt;br /&gt;&lt;br /&gt;If you want to remain a technologist, rather than enter management, there are two popular paths: specialize or become a generalist.&lt;br /&gt;&lt;br /&gt;If you choose to specialize, your route will take you down the path of becoming ever more highly trained in one discipline, or possibly a few closely related areas. Penetration testers may become more skilled programmers, and could delve deeply into web technologies, or system kernel exploits. Network security experts might become a CCIE, or tackle high end certifications from specific vendors.&lt;br /&gt;&lt;br /&gt;The problem is that when that technology dies, you may have to re-train. That's nothing new in the world of information technology. Banyan Vines and Netware administrators have moved on to handle Active Directory and experts in Token Ring have trained to deal with gigabit switched ethernet and Internet protocols. What it does mean is that you have to keep an eye open to avoid being outdated with the technologies that you are expert in. Specialization is a great way to get a job - if that job is in demand, and the supply is small. Cobol programmers knew this in 1999 - but that was a relatively rare opportunity for a dying technology to make a brief comeback.&lt;br /&gt;&lt;br /&gt;The other route, of course, is that of the generalist. This tends to put you into a role that glues together security with other IT areas, and can be quite rewarding - but you may find that you're unable to operate at the same depth that your specialized peers can attain. Generalists may have a harder time justifying specialized training, and will not necessarily find that their resumes qualify them directly for the highly specialized jobs that require a single scarce skill.&lt;br /&gt;&lt;br /&gt;Which route should a security analyst take? That's a tough call. At the end of the day, your work environment and your own preferences will likely shape your futureproofing efforts. In either case, technology will change, new threats will appear, and the job will continue to provide the challenges that we all face.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-656511323186605475?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/656511323186605475/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=656511323186605475" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/656511323186605475?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/656511323186605475?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/XTTj6idTxf8/future-proofing-information-security.html" title="Future Proofing an Information Security Job" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/future-proofing-information-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEEQXkzfCp7ImA9WxNVGEs.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-1297908299320443762</id><published>2009-10-29T20:30:00.004-04:00</published><updated>2009-10-29T20:30:00.784-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-29T20:30:00.784-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="remove page from google" /><category scheme="http://www.blogger.com/atom/ns#" term="search engine removal" /><category scheme="http://www.blogger.com/atom/ns#" term="webpage removal" /><title>How To: Search Engine Webpage Removal - A Search Engine Entry Removal Roundup</title><content type="html">If you run a website of any type, there is a good chance that you'll want to remove content from Google, Bing, and other search engines at some point, either due to outdated information or sensitive data exposure. Below are links to the documentation provided by each of the major search engines for their removal process.&lt;br /&gt;&lt;br /&gt;Most search engines will tell you that your first action should be to create an appropriate &lt;a href="http://www.robotstxt.org/"&gt;robots.txt&lt;/a&gt;, and many want you to return a 404 error. If you don't, they may keep your content cached for even longer than they might otherwise.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Google&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;First, you can &lt;a href="https://www.google.com/webmasters/tools/removals?hl=zh&amp;amp;pli=1"&gt;build and submit a removal request&lt;/a&gt; for information, images, outdated or inappropriate content.&lt;br /&gt;&lt;a href="https://www.google.com/webmasters/tools/removals?hl=zh&amp;amp;pli=1"&gt;&lt;/a&gt;&lt;br /&gt;Then, you can remove your own content, then cause Google to re-index it more quickly using their webpage&lt;a href="http://www.google.com/support/webmasters/bin/answer.py?answer=92865"&gt; removal request tool&lt;/a&gt;.&lt;br /&gt;&lt;a href="http://www.google.com/support/webmasters/bin/answer.py?answer=92865"&gt;&lt;/a&gt;&lt;br /&gt;Finaly, make sure you follow Google's &lt;a href="http://www.google.com/support/webmasters/bin/answer.py?hl=en&amp;amp;answer=156412"&gt;noindex meta tag and robots.txt instructions&lt;/a&gt;.&lt;br /&gt;&lt;a href="http://www.google.com/support/webmasters/bin/answer.py?hl=en&amp;amp;answer=156412"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://services.google.com:8882/urlconsole/controller?cmd=reload&amp;amp;lastcmd=login"&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Yahoo!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;With Yahoo's move to the Bing search engine, their removal process has changed. You can use their &lt;a href="http://services.google.com:8882/urlconsole/"&gt;SiteExplorer tool&lt;/a&gt; to remove your site from their results.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://services.google.com:8882/urlconsole/controller?cmd=reload&amp;amp;lastcmd=login"&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Ask (formerly Ask Jeeves)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ask only provides robot.txt support, and has no formal published removal process.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Microsoft's new search engine has recently published &lt;a href="http://www.bing.com/community/blogs/webmaster/archive/2009/06/08/how-to-remove-urls-from-our-index-expanded-edition.aspx"&gt;removal instructions&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.bing.com/community/blogs/webmaster/archive/2009/06/08/how-to-remove-urls-from-our-index-expanded-edition.aspx"&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;AltaVista&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Per AltaVista's support information, &lt;blockquote&gt;"If an AltaVista user comes across web pages that contain private personal, professional or financial information that is not available to the public and/or may have been illegally obtained, he or she can write to legal-support-uk@av.com to request that the offending URL be removed from AltaVista's index. Please note that removing said URL from AltaVista's index does not remove the URL from the public internet or the indexes of other search engines."&lt;/blockquote&gt;&lt;span style="font-weight: bold;"&gt;Archive.org / the Wayback Machine&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Archive.org provides a long term snapshot of much of the Internet, dated by when the page was crawled. If your site has been available for any length of time, and if you have static content that it can crawl, there's a good chance you'll want to contact &lt;a href="http://www.archive.org/"&gt;Archive.org&lt;/a&gt; for &lt;a href="http://www.archive.org/about/exclude.php"&gt;exclusion&lt;/a&gt;.&lt;br /&gt;&lt;a href="http://www.archive.org/about/exclude.php"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-1297908299320443762?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/1297908299320443762/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=1297908299320443762" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/1297908299320443762?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/1297908299320443762?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/6hYdMd7YO6g/how-to-search-engine-webpage-removal.html" title="How To: Search Engine Webpage Removal - A Search Engine Entry Removal Roundup" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/how-to-search-engine-webpage-removal.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE8HSXk8cSp7ImA9WxNVFE0.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-7772236943367082124</id><published>2009-10-23T12:30:00.001-04:00</published><updated>2009-10-24T13:53:58.779-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-24T13:53:58.779-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity month" /><category scheme="http://www.blogger.com/atom/ns#" term="President Obama" /><title>President Obama on Cybersecurity Month</title><content type="html">President Obama's short &lt;a href="http://www.whitehouse.gov/video/National-Cybersecurity-Awareness-Month/"&gt;video on cybersecurity month&lt;/a&gt; is available. This is the first time I've heard the President outline our frequent security advice - verify identities before giving out information, update your software, beware of suspicious emails. You can watch for yourself below:&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/UIIY9AQSqbY&amp;amp;rel=0&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en&amp;amp;feature=player_embedded&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/UIIY9AQSqbY&amp;amp;rel=0&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en&amp;amp;feature=player_embedded&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-7772236943367082124?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/7772236943367082124/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=7772236943367082124" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7772236943367082124?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7772236943367082124?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/tRSE-bYl0F4/president-obama-on-cybersecurity-month.html" title="President Obama on Cybersecurity Month" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/president-obama-on-cybersecurity-month.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck4AQHY8fyp7ImA9WxNVEks.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-8602243832119979726</id><published>2009-10-22T20:56:00.004-04:00</published><updated>2009-10-22T21:22:21.877-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-22T21:22:21.877-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="evil maid" /><category scheme="http://www.blogger.com/atom/ns#" term="truecrypt" /><category scheme="http://www.blogger.com/atom/ns#" term="drive encryption" /><title>Worried About The Evil Maid?</title><content type="html">Joanna Rutkowska's "&lt;a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html"&gt;Evil Maid&lt;/a&gt;" TrueCrypt attack has been getting a lot of buzz in security circles today. In essence, the attack involves compromising the trust that TrueCrypt (and the user) places in the boot process. An evil maid (or other ne'er-do-well) exploits their physical access to a machine and that machine's capability to boot from external media such as a USB device to add a keylogger or other trojan to the boot sector or firmware, allowing capture of the presumably unchanging decryption key that the user enters to access their filesystem.&lt;br /&gt;&lt;br /&gt;Am I particularly concerned about this as an attack against my organization's resources? Of course not!&lt;br /&gt;&lt;br /&gt;We do use encryption on our mobile systems - not TrueCrypt, but the caution is largely against the concept, not necessarily only Rutkowska's specific implementation. With that said, a simple risk assessment serves us in good stead. Is our data so valuable, or are maids so twisted that we have to worry about them attempting to access our laptops which (hopefully) we lock in safes in hotel rooms, or otherwise appropriately protect? No - none of the people that I work with are in Her Majesty's Secret Service, or otherwise likely to be high value targets.&lt;br /&gt;&lt;br /&gt;The good news is that Rutkowska's implementation of this attack serves as a good reminder that our trust in enterprise drive encryption is much like any other technological solution in our daily security war - simply a stage in the escalation of tools.&lt;br /&gt;&lt;br /&gt;Years ago, we recommended passwords on laptops. Then, legislation and more technically aware users pushed us to drive encryption. Next, as attacks like this become more widely approachable, we'll worry about how to use TPM, drive hashing, two factor authentication, or technologies that can guarantee the state of a system between uses. For now, I'm far more worried about malware installed on systems either via a vulnerability or a user's mistake. Why? Because our drive encryption efforts do nothing when the drive is unlocked for the user's daily work.&lt;br /&gt;&lt;br /&gt;For your daily security efforts, you can likely worry about much more immediate security concerns - and in the meantime, if your maid cackles evilly, and speaks in l33t - you may want to guard your USB ports.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-8602243832119979726?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/8602243832119979726/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=8602243832119979726" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/8602243832119979726?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/8602243832119979726?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/Yyoq6FnzXU0/worried-about-evil-maid.html" title="Worried About The Evil Maid?" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/worried-about-evil-maid.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUEQXk7eip7ImA9WxNVEEo.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-7791962589885012437</id><published>2009-10-20T17:30:00.000-04:00</published><updated>2009-10-20T17:30:00.702-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-20T17:30:00.702-04:00</app:edited><title>VirusScan 8.7 and Security Center reporting</title><content type="html">If you've been driven to distraction recently by users who noticed that the Windows Security Center wasn't reporting their McAfee VirusScan 8.7 status correctly, you're in luck. Messages like "McAfee VirusScan Enterprise is on but reporting its status to Windows Security Center in a format that is no longer supported" on Windows 7 and Vista, while only a reporting issue, were resulting in a lot of questions.&lt;br /&gt;&lt;br /&gt;McAfee has released &lt;a href="https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/22000/PD22137/en_US/Release%20Notes%20for%20McAfee%20VirusScan%20Enterprise%208_7i%20Patch%202.pdf"&gt;Patch 2&lt;/a&gt; (link goes to the readme) for VirusScan 8.7 which fixes the issue. Along they way, they also improved the performance of On Access scans, which many users were complaining about as well.&lt;br /&gt;&lt;br /&gt;What went wrong? Well, the Microsoft API for this reporting was updated, and this required updates from vendors. McAfee's patch lagged behind, resulting in worried customers. The good news is that their AV was working. The bad news is that we've spent years making our customers more aware, and now even a false positive can cause a lot of helpdesk calls.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-7791962589885012437?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/7791962589885012437/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=7791962589885012437" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7791962589885012437?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7791962589885012437?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/z8zkkWvk8dE/virusscan-87-and-security-center.html" title="VirusScan 8.7 and Security Center reporting" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/virusscan-87-and-security-center.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cEQX88eyp7ImA9WxNWGEw.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-5184072664494480063</id><published>2009-10-17T17:30:00.000-04:00</published><updated>2009-10-17T17:30:00.173-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-17T17:30:00.173-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DHS" /><category scheme="http://www.blogger.com/atom/ns#" term="security experts" /><category scheme="http://www.blogger.com/atom/ns#" term="Cringely" /><title>1000 Security Experts? Not exactly what the doctor ordered.</title><content type="html">Bob Cringely &lt;a href="http://www.cringely.com/2009/10/the-cybersecurity-myth/"&gt;recently discussed&lt;/a&gt; the Department of Homeland Security's plan to hire 1,000 "cybersecurity experts" to defend U.S. computer networks. His take? That there aren't 1,000 cybersecurity experts to be found in the U.S. His unnamed cybersecurity expert friends tend to agree in various forms, ranging from a discussion of the semantics of the goal to a more in-depth discussion of the forms of expertise that can be found, and a note that there are 1,000 security experts - on the wrong side of the fence.&lt;br /&gt;&lt;br /&gt;Cringely also contends that no matter what the actual intent, this hiring is largely window dressing and that the end result won't be a sea change in how government information security is done. He points to low CCIE graduation rates as a good metric for how many security experts can be found, which may not be the best metric for security expertise across the board - to me, it indicates that holders of one brand of high level network security expertise do exist, but that the demand for CCIEs isn't sufficient to push further qualifiers into the certificate at a high rate. In addition, personal experience indicates to me that many qualified security experts don't carry all of the certifications that they could qualify for for any of a broad variety of reasons - that doesn't mean that we have hundreds of certification-less CCIEs around, but it does mean that we may have experts we're not counting if we only count certificates.&lt;br /&gt;&lt;br /&gt;The problem here is that security expertise covers a broad variety of fields from risk assessment to network security to physical security design and back again. Seeking a thousand cybersecurity experts is, in many ways more akin to seeking a thousand expert college professors in engineering. You many not find them all in nuclear engineering at the level that you desire, but you may very well find that many experts across all of the disciplines that you need - and then you'll realize that you really wanted some of them to be TA's, Ph.D. candidates, and others who many not yet be experts - but will be.&lt;br /&gt;&lt;br /&gt;Polymath experts with broad experience and deep expertise across the spectrum of information security are definitely necessary to tie those skillsets together, especially when you need to glue complex systems together, but you don't need - or necessary want hundreds of those big guns. Cringely notes that such experts aren't found in packs, and that is one point that I'll agree with. In any field the major experts hold a special place, and some take full advantage of it.&lt;br /&gt;&lt;br /&gt;One of Cringely's experts dismisses the DHS plan - "you will end up with 1,000 Security Managers in the government with Sec+, and CISSP certifications". This picture of outsourced expertise and a lack of true change doesn't reflect the fact that skilled security managers are just as necessary as the heavy hitter deep dive experts. If the Department of Homeland Security really wants to change the face of government information security, the program and these new hires must be run adeptly, and that can be a real challenge.&lt;br /&gt;&lt;br /&gt;DHS doesn't need to simply hire 1000 identical security superheroes. They need to embed employees with appropriate skillsets in those areas that face risk - after they assess the risk - and then they need to work out a coherent program to improve and manage both their security program and their security staffers. With the right guidance, 1000 security employees of many types could change how government information security is done.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-5184072664494480063?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/5184072664494480063/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=5184072664494480063" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5184072664494480063?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5184072664494480063?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/848smIuQcWQ/1000-security-experts-not-exactly-what.html" title="1000 Security Experts? Not exactly what the doctor ordered." /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/1000-security-experts-not-exactly-what.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4CR3Y_cCp7ImA9WxNWFkg.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-7585547439890272381</id><published>2009-10-15T21:00:00.001-04:00</published><updated>2009-10-15T21:02:46.848-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-15T21:02:46.848-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security models" /><category scheme="http://www.blogger.com/atom/ns#" term="security analysts" /><title>The Three Phases of the Security Analyst</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm3.static.flickr.com/2438/3643283079_f172b26309.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 338px; height: 500px;" src="http://farm3.static.flickr.com/2438/3643283079_f172b26309.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;Creative Commons attribution licensed image courtesy Flickr user &lt;a href="http://www.flickr.com/photos/49024304@N00/"&gt;anyjazz65&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;I spend a lot of time working with people outside of my own immediately group of security analysts, and I often find it useful to provide a model that will help them understand how security analysts work. Fortunately, I've found one that I like.&lt;br /&gt;&lt;br /&gt;Security staffers that I have known through the years tend to fall into one of three stages - typically depending on the phase of their career, with some variation depending on the person's personality, their workplace, and of course, their experience.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold;"&gt;The Phases:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. The Black and White Security Analyst&lt;/span&gt;: &lt;span style="font-style: italic;"&gt;A Binary Analysis&lt;/span&gt; - typical amongst newer security professionals, a Black and White analyst sees the world as a series of security issues. A system is either secure, or insecure. It complies with best practices, or it fails. Black and white analysts can drive outsiders nuts (and, at times, their non-black and white compatriots), but they also serve as a very useful check to the other phases - and they make very good auditors.&lt;br /&gt;&lt;br /&gt;Some black and white analysts find their role because of limited direct experience. Simple book knowledge rarely has a compromise solution, and forcing best practices can make an otherwise reasonable staffer look like a truly obstinate opponent. Every analyst needs to fall back on these behaviors at times, particularly for thorny problems that have a high risk solution. Of course, in some environments this is the desired mode of operation, and should be fostered.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Shades of Gray&lt;/span&gt;: &lt;span style="font-style: italic;"&gt;The Risk Modeller&lt;/span&gt; - as security professionals spend more time in the field - and, often, as they become more jaded, they often start to view the world as a series of risks. Training teaches you to do a risk assessment, to rate those risks, and to build controls based on that model.&lt;br /&gt;&lt;br /&gt;Their assessments start to balance these risks, and they become more flexible in their views. The danger? Making too many tradeoffs, whether for functionality or simply for the ease of implementation. This can have a benefit of course, as often the shades of gray allow the analyst to be more flexible when analyzing risks and controls.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. The Realist&lt;/span&gt;&lt;span&gt;:&lt;/span&gt; &lt;span style="font-style: italic;"&gt;Life Along the Continuum&lt;/span&gt;- some, but not all security staffers make it to a third phase. This third phase tends to emphasize the continuum of possible security options, and those who have reached this level will typically rate security based on the improvement along that continuum. Analysts often set a minimum acceptable level - and strive to ensure that a balance is maintained between improvements beyond that and the organizational costs of moving along the line. Realists are fully aware that security cannot always win, and instead choose their battles. This can mean that at times, they are more willing to accept compromise than they necessarily should be, and burnout can lead to a less effective analyst, but realists are often the best interfaces with outside organizations if you need to build bridges.&lt;br /&gt;&lt;br /&gt;In the end, all three stages are useful, and each has its place. What matters in the end is reaching an organizationally acceptable balance of risk, usability, and security, and that ebb and flow is what makes the job both a challenge and an adventure.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-7585547439890272381?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/7585547439890272381/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=7585547439890272381" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7585547439890272381?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7585547439890272381?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/8xPqeIA6hjM/three-phases-of-security-analyst.html" title="The Three Phases of the Security Analyst" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/three-phases-of-security-analyst.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQMQ384fyp7ImA9WxNWE0w.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-531240235147371317</id><published>2009-10-11T23:13:00.004-04:00</published><updated>2009-10-11T23:16:22.137-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-11T23:16:22.137-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="password security" /><category scheme="http://www.blogger.com/atom/ns#" term="password standards" /><title>Passwords...in Newsweek?</title><content type="html">You know that passwords and their problems have gone mainstream when Newsweek &lt;a href="http://www.newsweek.com/id/217014/page/1"&gt;carries an article about them&lt;/a&gt;. Nick Summers describes current password technology issues, as well as some of the potential future solutions. It even describes brute forcing and the issues with simple passwords - meaning that your users might come ask a few good questions.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-531240235147371317?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/531240235147371317/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=531240235147371317" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/531240235147371317?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/531240235147371317?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/1s_VR5PHxIg/passwordsin-newsweek.html" title="Passwords...in Newsweek?" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/passwordsin-newsweek.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8NQHszfip7ImA9WxNXGUg.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-2743159583881687633</id><published>2009-10-07T19:18:00.003-04:00</published><updated>2009-10-07T19:24:51.586-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-07T19:24:51.586-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="password security" /><category scheme="http://www.blogger.com/atom/ns#" term="password standards" /><title>That's amazing. I've got the same combination on my luggage...</title><content type="html">Wired's Danger Room blog &lt;a href="http://www.wired.com/threatlevel/2009/10/10000-passwords/"&gt;quotes&lt;/a&gt; analysis of a recent Hotmail, MSN, and Microsoft Live account leak which showed that 123456 was the most common password.&lt;br /&gt;&lt;br /&gt;In my experience universities tend to find that their most common passwords are catch phrases common to the school. Corporations that run password audits may find similar patterns in their own users passwords selections.&lt;br /&gt;&lt;br /&gt;Does your organization have a common password?&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-2743159583881687633?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/2743159583881687633/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=2743159583881687633" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/2743159583881687633?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/2743159583881687633?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/SjZxscspstQ/thats-amazing-ive-got-same-combination.html" title="That's amazing. I've got the same combination on my luggage..." /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/thats-amazing-ive-got-same-combination.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04GSHg-fCp7ImA9WxNXFEk.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-5113278029373062366</id><published>2009-10-01T21:00:00.000-04:00</published><updated>2009-10-01T21:12:09.654-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-01T21:12:09.654-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="hostage ware" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><category scheme="http://www.blogger.com/atom/ns#" term="hostageware" /><title>Hostageware Hits the Mainstream</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm3.static.flickr.com/2458/3800997267_a6d7244942.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 500px; height: 375px;" src="http://farm3.static.flickr.com/2458/3800997267_a6d7244942.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;Creative Commons Attribution licensed image courtesy &lt;a href="http://www.flickr.com/photos/alanrmiles/"&gt;Alan Miles NYC&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;The New York Times was &lt;a href="http://www.nytimes.com/2009/09/15/technology/internet/15adco.html?_r=1"&gt;recently hit&lt;/a&gt; with a hostageware ad that switched from a seemingly legitimate Vonage ad to virus warnings. The Times believed they were trusting a vendor that they had previously worked with, and allowed un-vetted servers to serve ads to their site. The Times isn't the only major site to have this occur, and my security threats crystal ball says that since we've all locked our computers down to prevent worms, the bad guys are going to target the places that they know that we go - and trust.&lt;br /&gt;&lt;br /&gt;As the New York Times article notes, "These so-called affiliates can mimic the advertisements of legitimate companies, learn their techniques for submitting ads to networks and sites, meddle with ad servers and then go so far as to provide customer support for people who install the software, keeping the scam running as long as possible."&lt;br /&gt;&lt;br /&gt;In my own recent experience, this type of ad is increasingly prevalent as a threat to users, and the malware itself is taking advantage of a number of browser bugs and plugin bugs to slide past users defenses. With threats that take advantage of PDF vulnerabilities, Java vulnerabilities, and more, users who navigate to trusted sites may still be compromised. This also means that the standard habits that we have taught users for years are no longer a panacea - simply not going to untrusted sites and not opening unexpected emails, or avoiding clicking untrusted links isn't the shield it was.&lt;br /&gt;&lt;br /&gt;Home users who find themselves staring at a popup screen that offers to save them from the malware that their PC is infected with can find some solace in the fact that capable anti-malware products like &lt;a href="http://www.malwarebytes.org/"&gt;MalwareBytes&lt;/a&gt; is available for free. Sadly, mainstream AV seems to have real problems with many of these hostageware packages, so a second layer of defense is key.&lt;br /&gt;&lt;br /&gt;So, what can you do from a corporate perspective? That's a bit tougher. Here's what I'm looking at:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;First, full patching for systems that includes browser plugins is really essential. I continue to see systems that have full OS patches that are behind on browser plugins. Comprehensive, system wide software management is becoming even more of a corporate necessity.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Second, enterprise AV can still be helpful, even if only for detection. Remember to have your support staffers check out machines that show continued issues, as some components of malware often gets removed, but the remaining parts can restore them. I've had organizations using central AV notice large numbers of their machines disappearing, which resulted in investigation that showed a widespread compromise. Not exactly how they expected to leverage their AV management console, but well worth the price of admission.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Third, investigate enterprise licenses for useful tools. MalwareBytes and other vendors do offer attractive pricing for enterprise licensing. I've found that a quick Google results survey can often indicate what secondary package is most recommended, and that can really help.&lt;/li&gt;&lt;li&gt;Fourth, monitoring outbound traffic for hits on known malware and scam sites gives you a chance to find infected hosts before they become problems.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Finally, user training and awareness is still key. Finding out when these hostageware programs are showing up, and what the user was doing when they got infected can help prevent widespread infections.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;How is your enterprise handling hostageware?&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-5113278029373062366?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/5113278029373062366/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=5113278029373062366" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5113278029373062366?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5113278029373062366?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/u3cSdGkk4Ws/hostageware-hits-mainstream.html" title="Hostageware Hits the Mainstream" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/10/hostageware-hits-mainstream.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUAQ34-fyp7ImA9WxNQGE8.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-4449811382929429710</id><published>2009-09-24T17:00:00.002-04:00</published><updated>2009-09-24T17:04:02.057-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-24T17:04:02.057-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Web of Trust" /><category scheme="http://www.blogger.com/atom/ns#" term="thawte" /><category scheme="http://www.blogger.com/atom/ns#" term="S/MIME certificates" /><title>Thawte Discontinues Free Email Certificates and the Web of Trust</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm4.static.flickr.com/3071/3021224568_e6af37a264.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 500px; height: 375px;" src="http://farm4.static.flickr.com/3071/3021224568_e6af37a264.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:78%;"&gt;Creative Commons Attribution License image courtesy Flickr user &lt;a href="http://www.flickr.com/photos/fristle/"&gt;Fristle&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;Thawte's &lt;a href="http://www.thawte.com/secure-email/web-of-trust-wot/"&gt;Web of Trust&lt;/a&gt; and free email certificates have been a great way to get S/MIME certificates signed for personal use by a large CA. I've been a notary for a few years, and I've found that being able to offer an easy to obtain certificate with a reasonably strong validation process was a great way to introduce S/MIME certificates and secure email to many people.&lt;br /&gt;&lt;br /&gt;Today Thawte announced that both their free personal email certificates and the Web of Trust will cease to exist after November 16th, 2009. Details of the impact are covered in their &lt;a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;amp;id=SO12658"&gt;FAQ&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This will remove one of the largest in-person vetted identity certification groups that I know of - a reasonably unique institution. Those who paid money for notarization to receive points in the Web of Trust will find that that investment no longer pays returns. Thawte's consolation prize is a single year of VeriSign's commercial personal email certificate service, and a free one year certificate of the member's choice.&lt;br /&gt;&lt;br /&gt;I'm not aware of any viable community replacement for this servicefor S/MIME certificate users, and I'm somewhat disappointed that Thawte hasn't pushed the idea of making this some form of community supported or managed service.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-4449811382929429710?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/4449811382929429710/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=4449811382929429710" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4449811382929429710?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4449811382929429710?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/4M70_PNgEvs/thawte-discontinues-free-email.html" title="Thawte Discontinues Free Email Certificates and the Web of Trust" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/thawte-discontinues-free-email.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQCQX4_fSp7ImA9WxNQFk8.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-5343839557591146253</id><published>2009-09-22T07:35:00.005-04:00</published><updated>2009-09-22T09:32:40.045-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-22T09:32:40.045-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="forensic imaging" /><category scheme="http://www.blogger.com/atom/ns#" term="forensic tools" /><category scheme="http://www.blogger.com/atom/ns#" term="computer forensics" /><title>Aquisition drive too small? Loop and offset to the rescue!</title><content type="html">On any given day, I might need to take an image of a physical drive to analyze offline.  In the past, our imaging target drives of 1TB were plenty to handle a raw dump of the drive as well as partition dumps or carves later on.  However, with the spate of large capacity drives being installed, even in laptops, I'm lucky to just get the raw dump of the drive with some working space for an evidence locker.  But what if I need to parse through the partitions individually or want to mount them remotely?  Loop device mounting and offset (commands operands supported within the mount command) to the rescue.  After imaging the entire drive and of course verifying the hash, I have everything I need.  Now for the fun. &lt;br /&gt;&lt;br /&gt;Typically, you can mount a raw image with the loop device operand:&lt;br /&gt;&lt;br /&gt;#mount -o loop,ro -t auto /some/image.raw /your/mountpoint&lt;br /&gt;&lt;br /&gt;I use this often when I only have an image of a partition.  However, this option will not work when trying to mount an image of an entire physical device with one or more logical drives defined within it.  So now what? &lt;br /&gt;&lt;br /&gt;Given that an image is really just a block level copy of data, we are only dealing with data.  Using the the loop device with further options - offset specifically - offers you the ability to tell it where you want it to consider the starting point within the string of data.    In essence, the offset operand tells mount  and the loop device to offset from the actual beginning of the string of data n bytes.  But where do my partitions start and end?&lt;br /&gt;&lt;br /&gt;To get an idea of what is contained inside the image, as far as file system information, logical drives etc, you will need to use a utility like fdisk.  fdisk is a partition table manipulator for Linux.  While it can be used to manipulate the partitions, we'll just use it to find out what's inside the image.  The following command will give you all the details we need about an image:&lt;br /&gt;&lt;br /&gt;# fdisk -ul image.001&lt;br /&gt;&lt;br /&gt;You must set cylinders.&lt;br /&gt;You can do this from the extra functions menu.&lt;br /&gt;&lt;br /&gt;Disk image.001: 0 MB, 0 bytes&lt;br /&gt;255 heads, 63 sectors/track, 0 cylinders, total 0 sectors&lt;br /&gt;Units = sectors of 1 * 512 = 512 bytes&lt;br /&gt;Disk identifier: 0xd42ad42a&lt;br /&gt;&lt;br /&gt;     Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;image.001p1   *          63    42154559    21077248+   7  HPFS/NTFS&lt;br /&gt;Partition 1 has different physical/logical endings:&lt;br /&gt;     phys=(1023, 254, 63) logical=(2623, 254, 63)&lt;br /&gt;image.001p2        42154560   156296384    57070912+   5  Extended&lt;br /&gt;Partition 2 has different physical/logical beginnings (non-Linux?):&lt;br /&gt;     phys=(1023, 0, 1) logical=(2624, 0, 1)&lt;br /&gt;Partition 2 has different physical/logical endings:&lt;br /&gt;     phys=(1023, 254, 63) logical=(9728, 254, 63)&lt;br /&gt;image.001p5        42154623   156296384    57070881    7  HPFS/NTFS&lt;br /&gt;&lt;br /&gt;In the example above, I pointed "fdisk -ul" at an image of a Windows drive that had two partitions.  I used option "u" to list the sizes in sectors instead of cylinders and "l" to list the partitions within the device and then exit.  So, from here, how do we calculate where the starting point is for each partition and then tell mount where we want the beginning to be?  First we start by determining the sector size.  This will be in bytes, and the number we use as a multiplier to determine how many bytes into the image we want to offset.  We can see in the output that the sector size is 512 bytes:&lt;br /&gt;&lt;br /&gt;Units = sectors of 1 * 512 = &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;512 bytes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next we need to know at what sector each partition starts.  In the example above, we see several partitions listed; image.001p1, image.001p2, image.001p5.  Each partition entry in the output has a start point denoted in sectors:&lt;br /&gt;&lt;br /&gt;Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;image.001p1   *          &lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;63&lt;/span&gt;    42154559    21077248+   7  HPFS/NTFS&lt;br /&gt;image.001p2        &lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;42154560&lt;/span&gt;&lt;span style="color: rgb(51, 204, 0);"&gt; &lt;/span&gt;  156296384    57070912+   5  Extended&lt;br /&gt;image.001p5        &lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;42154623&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;   &lt;/span&gt;156296384    57070881    7  HPFS/NTFS&lt;br /&gt;&lt;br /&gt;But wait - in this example I have a drive image that only contained two partitions - why are there three listed?  This is because the drive I  imaged was partitioned with one primary boot partition and an extended partition which contains another partition.  There are many religious debates on how to partition drives, but suffice it to say, this is by far more common than not.  Today, we are only concerned about mounting the two NTFS partitions listed.  In the fdisk output we can see that partition 1 starts at sector 63 and partition 5 starts at sector 42154623.  We'll multiply these starting sectors by our sector size to determine what our offset (in bytes) is for each mount operation:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;sector size&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; * &lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;starting sector&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; = &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;offset&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;512&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; * &lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;63&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; = &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;32256&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;512&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; * &lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;42154623&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; = &lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;21583166976&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now that we have the offset, in bytes, we can formulate our mount commands:&lt;br /&gt;&lt;br /&gt;#mount -o ro,loop,offset=&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;32256 &lt;/span&gt;-t ntfs-3g image.001 /some/mountpoint&lt;br /&gt;and&lt;br /&gt;#mount -o ro,loop,offset=&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;21583166976 &lt;/span&gt;-t ntfs-3g image.001 /another/mountpoint&lt;br /&gt;&lt;br /&gt;And there we have it - both partitions within a raw drive image mounted and ready to explore without having to take more images of just the logical drives - or carve them out of what we have.  Of course, file systems will vary along with disk geometry and associated mounting options.  However these basic steps can be used to identify and mount every partition contained within a raw disk image.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-5343839557591146253?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/5343839557591146253/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=5343839557591146253" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5343839557591146253?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5343839557591146253?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/Meb_9wvMIVY/aquisition-drive-too-small-loop-and.html" title="Aquisition drive too small? Loop and offset to the rescue!" /><author><name>MTI</name><uri>http://www.blogger.com/profile/16411573334562325587</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="12082728093499524839" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/aquisition-drive-too-small-loop-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MEQXs8cCp7ImA9WxNQEkQ.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-6444532750747736615</id><published>2009-09-18T12:30:00.000-04:00</published><updated>2009-09-18T12:30:00.578-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-18T12:30:00.578-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="LogMeIn" /><category scheme="http://www.blogger.com/atom/ns#" term="remote control software" /><category scheme="http://www.blogger.com/atom/ns#" term="laptop recovery" /><title>Stolen Laptop Recovery with LogMeIN - Round 2</title><content type="html">PC World has &lt;a href="http://www.pcworld.com/article/172093/An_Amazing_Laptop_Recovery_Story.html"&gt;David Krop's story&lt;/a&gt; of laptop recovery using LogMeIn. I've discussed a couple of  similar stories involving a &lt;a href="http://devilsadvocatesecurity.blogspot.com/2009/06/case-for-remote-control-theft-recovery.html"&gt;laptop&lt;/a&gt; and an &lt;a href="http://devilsadvocatesecurity.blogspot.com/2009/06/phone-recovery-true-story.html"&gt;iPhone&lt;/a&gt; previously, as well as the case for remote control software, and this is another example of a laptop that was not properly secured being used by a new user while remote login software was on.&lt;br /&gt;&lt;br /&gt;The buyer of the stolen laptop is quoted, saying  "I didn't care whether it was stolen, I buy stolen stuff all the time. I don't care... If I can save $600, I'll do it.". While he may not have learned a lesson, the owner of the stolen laptops did, noting that he won't leave the laptops unattended, that he takes only one with him, and that he uses passwords and remote tracking software now.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-6444532750747736615?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/6444532750747736615/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=6444532750747736615" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/6444532750747736615?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/6444532750747736615?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/6MI2bNBVSUY/stolen-laptop-recovery-with-logmein.html" title="Stolen Laptop Recovery with LogMeIN - Round 2" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/stolen-laptop-recovery-with-logmein.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIEQX8zeyp7ImA9WxNQEkQ.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-4407278716220158496</id><published>2009-09-18T12:15:00.001-04:00</published><updated>2009-09-18T12:15:00.183-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-18T12:15:00.183-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="dumb criminals" /><category scheme="http://www.blogger.com/atom/ns#" term="Facebook Security" /><title>What You Do on Facebook Can Cause You Harm is True For Criminals Too</title><content type="html">Jonathan G. Parker of Fort Loudon, Pennsylvania was arraigned on a burglary charge after he &lt;a href="http://www.journal-news.net/page/content.detail/id/525232.html"&gt;forgot to log out of Facebook&lt;/a&gt; on the computer at a house that he had robbed.&lt;br /&gt;&lt;br /&gt;We're all busy telling our users that what they do on Facebook can cause them problems in the future, but this is a slightly more direct example...&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-4407278716220158496?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/4407278716220158496/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=4407278716220158496" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4407278716220158496?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4407278716220158496?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/Pg0kUEJEDsE/what-you-do-on-facebook-can-cause-you.html" title="What You Do on Facebook Can Cause You Harm is True For Criminals Too" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/what-you-do-on-facebook-can-cause-you.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0AERX87eSp7ImA9WxNQEk4.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-6438654432616095489</id><published>2009-09-17T20:28:00.005-04:00</published><updated>2009-09-17T21:01:44.101-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-17T21:01:44.101-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="web application vulnerability scanning" /><category scheme="http://www.blogger.com/atom/ns#" term="webinspect" /><category scheme="http://www.blogger.com/atom/ns#" term="web application security" /><title>Making Web Application Security Controls Repeatable</title><content type="html">Raul Siles recently posted a &lt;a href="http://isc.sans.org/diary.html?storyid=7135"&gt;useful reminder&lt;/a&gt; as his ISC diary post - "Review the security controls of your Web Applications... all them!". He used the &lt;a href="http://tacticalwebappsec.blogspot.com/2009/09/distributed-brute-force-attacks-against.html"&gt;problems&lt;/a&gt; described by Ryan Barnett that were found in Yahoo's web API as an excellent example of this rule. Both posts point to a common problem in applications that I see - the loss of established controls in new code and new functionality.&lt;br /&gt;&lt;br /&gt;One way I've been working to help fix this in an organization that hasn't developed a comprehensive software develoment lifecycle or broad QA process is to build a multi-step process to handle security flaws found in an application. Typical steps are:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Determine whether the problem is unique to the application, or if it is a flaw that is likely found in other applications, either current or future.&lt;/li&gt;&lt;li&gt;If it is more than a one time problem, design a common library or technique to handle the problem.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Assess the severity of the problem, and apply the fix to other applications if the risk is determined to be high enough to justify the effort. If not, add the fix to the queue for the next update to those applications.&lt;/li&gt;&lt;li&gt;Re-test the application to verify that the fix works.&lt;/li&gt;&lt;li&gt;Document the library and ensure that the rest of the team is aware of it.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;One of the best things about this sort of process is that developers start to think about problems in a much broader context. Recently, I've seen two of the developers I work with frequently stop during a meeting and ask out loud "I wonder if that applies in application X too...". That thought process usually ends up in modifications to their standard application libraries which means that problems I saw once tend not to come back across their entire group.&lt;br /&gt;&lt;br /&gt;How are these vulnerabilities discovered? A web application vulnerability scanner - &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200%5E9570_4000_100__"&gt;WebInspect&lt;/a&gt; in this case - provides most of the vulnerability testing. Manual testing, while often deeper and more likely to find corner cases for vulnerabilities doesn't scale as well into an environment with limited resources and a large number of applications. Automated testing systems are also great to help cover some gaps in skillset. As Jeremiah Grossman &lt;a href="http://jeremiahgrossman.blogspot.com/2007/02/automated-scanners-vs-low-hanging-fruit.html"&gt;points out&lt;/a&gt;, they may simply cover low hanging fruit, but that can be very valuable.&lt;br /&gt;&lt;br /&gt;Do you have a unique or creative internal process to make sure that your organization keeps web application vulnerabilities from recurring?&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-6438654432616095489?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/6438654432616095489/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=6438654432616095489" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/6438654432616095489?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/6438654432616095489?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/5ijUCudyrWU/making-web-application-security.html" title="Making Web Application Security Controls Repeatable" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/making-web-application-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4EQXo5eyp7ImA9WxNRGUk.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-3060775372971744796</id><published>2009-09-14T12:15:00.001-04:00</published><updated>2009-09-14T12:15:00.423-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-14T12:15:00.423-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="atm skimming" /><category scheme="http://www.blogger.com/atom/ns#" term="ATM skimmers" /><title>Brazilian ATM Skimmer Installation Video</title><content type="html">LiveLeak has great footage of an ATM skimmer being installed in Brazil, as well as the police arrest that followed. Note - LiveLeak itself may be not safe for some work environments due to adult ads.&lt;br /&gt;&lt;br /&gt;&lt;object height="370" width="450"&gt;&lt;param name="movie" value="http://www.liveleak.com/e/074_1252777692"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.liveleak.com/e/074_1252777692" type="application/x-shockwave-flash" wmode="transparent" height="370" width="450"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;The first few seconds are a quick lesson in how easily these skimmers can be attached.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-3060775372971744796?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/3060775372971744796/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=3060775372971744796" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3060775372971744796?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3060775372971744796?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/aM8DjFeidEI/brazilian-atm-skimmer-installation.html" title="Brazilian ATM Skimmer Installation Video" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/brazilian-atm-skimmer-installation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMER349eip7ImA9WxNRFko.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-7043549624066326982</id><published>2009-09-11T08:00:00.001-04:00</published><updated>2009-09-11T08:00:06.062-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-11T08:00:06.062-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security humor" /><category scheme="http://www.blogger.com/atom/ns#" term="Ponzi schemes" /><title>Security Humor: Indiana State Government Ponzi Scheme Education</title><content type="html">Google text ads can sometimes be a bit humorous as seen in this example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wgqJ4KQQva8/SluEp-_phlI/AAAAAAAAAKw/bGonQUp6_xQ/s1600-h/in_ponzi.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 245px; height: 70px;" src="http://2.bp.blogspot.com/_wgqJ4KQQva8/SluEp-_phlI/AAAAAAAAAKw/bGonQUp6_xQ/s320/in_ponzi.jpg" alt="" id="BLOGGER_PHOTO_ID_5358022038506800722" border="0" /&gt;&lt;/a&gt;I knew there was a reason that our budget wasn't as bad as those in other states. Of course, I wonder if the Secretary of State also teaches advanced Ponzi schemes...&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-7043549624066326982?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/7043549624066326982/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=7043549624066326982" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7043549624066326982?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/7043549624066326982?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/VFB9v9WDWqI/security-humor-indiana-state-government.html" title="Security Humor: Indiana State Government Ponzi Scheme Education" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_wgqJ4KQQva8/SluEp-_phlI/AAAAAAAAAKw/bGonQUp6_xQ/s72-c/in_ponzi.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/security-humor-indiana-state-government.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAAQ3o6cCp7ImA9WxNRFk8.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-5206841037353749445</id><published>2009-09-10T20:25:00.000-04:00</published><updated>2009-09-10T20:25:42.418-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-10T20:25:42.418-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="securitye education" /><category scheme="http://www.blogger.com/atom/ns#" term="EDUCAUSE" /><category scheme="http://www.blogger.com/atom/ns#" term="security videos" /><title>EDUCAUSE's 2009 Video and Poster Contest Winners</title><content type="html">&lt;a href="http://educause.edu"&gt;EDUCAUSE&lt;/a&gt; has announced their 2009 security video and poster contest winners. They can be viewed at: &lt;a href="http://www.researchchannel.org/securityvideo2009/"&gt;http://www.researchchannel.org/securityvideo2009/&lt;/a&gt;. Previous years can be accessed from the main EDUCAUSE &lt;a href="http://www.educause.edu/SecurityVideoContest"&gt;contest site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The videos produced for this contest are typically aimed at students, but often address topics that are relevant to the general populace.&lt;br /&gt;&lt;br /&gt;This year, I particularly liked the &lt;a href="http://www.researchchannel.org/securityvideo2009/training_gold.html"&gt;Cyber Security Awareness&lt;/a&gt; video by Nathan Krochmal, and Lenae Boykin's &lt;a href="http://www.researchchannel.org/securityvideo2009/training_silver.html"&gt;10 Most Common Passwords&lt;/a&gt; is quite well done. In previous years, Adam Stackhouse's &lt;a href="http://www-cdn.educause.edu/elements/images/security/video/contest/SEC0601p.wmv"&gt;Laptop Theft&lt;/a&gt; video has been a big hit.&lt;br /&gt;&lt;br /&gt;As with the videos and other materials created each year for this contest, colleges and universities can use these videos as part of their education and awareness campaigns. They're a great way to add spice to typical student security awareness and education videos, and they've helped to inspire some of our staff and faculty awareness efforts as well.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-5206841037353749445?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/5206841037353749445/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=5206841037353749445" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5206841037353749445?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/5206841037353749445?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/sAJEtn6DKO8/educauses-2009-video-and-poster-contest.html" title="EDUCAUSE's 2009 Video and Poster Contest Winners" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/educauses-2009-video-and-poster-contest.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8EQXY5fip7ImA9WxNRFUw.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-4151147987302120657</id><published>2009-09-09T12:30:00.002-04:00</published><updated>2009-09-09T12:30:00.826-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-09T12:30:00.826-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SMB2" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows security" /><category scheme="http://www.blogger.com/atom/ns#" term="SMB" /><title>SMB2 - Breaking Windows From Afar</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm4.static.flickr.com/3463/3348377521_41f282e95c.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 428px; height: 500px;" src="http://farm4.static.flickr.com/3463/3348377521_41f282e95c.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;Creative Commons Attribution License Photo courtesy Justus Hayes / Shoes on Wires / &lt;a href="http://shoesonwires.com/" rel="nofollow"&gt;shoesonwires.com&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Announcements have been making the rounds about vulnerabilities in Windows Vista and Windows 7's implementation of SMB, SMB2. As posted on &lt;a href="http://seclists.org/fulldisclosure/2009/Sep/0039.html"&gt;Full Disclosure&lt;/a&gt;, this version of SMB "SRV2.SYS fails to handle malformed SMB headers for the NEGOTIATE PROTOCOL REQUEST functionnality.", which results in a remotely initiated crash for any Vista or Windows 7 machine with exposed SMB services.&lt;br /&gt;&lt;br /&gt;Older versions of Windows, including 2000 and XP are not affected, as they do not use the new SRV2.SYS driver.&lt;br /&gt;&lt;br /&gt;Another good reminder that SMB shouldn't be exposed on workstations in general, and that if it must be available, that it should be locked down to prevent access beyond your local trusted networks or workgroup.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-4151147987302120657?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/4151147987302120657/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=4151147987302120657" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4151147987302120657?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/4151147987302120657?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/A_et8LYlpLU/smb2-breaking-windows-from-afar.html" title="SMB2 - Breaking Windows From Afar" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/09/smb2-breaking-windows-from-afar.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cEQX89fyp7ImA9WxNSFEQ.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-164319144320225488</id><published>2009-08-28T17:30:00.000-04:00</published><updated>2009-08-28T17:30:00.167-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-28T17:30:00.167-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="physical security" /><category scheme="http://www.blogger.com/atom/ns#" term="non-lethal weapons" /><category scheme="http://www.blogger.com/atom/ns#" term="LRAD" /><category scheme="http://www.blogger.com/atom/ns#" term="Bang Goes The Theory" /><title>Defeating Acoustic Weapons</title><content type="html">&lt;a href="http://www.wired.com/dangerroom/2009/08/british-tv-boffins-battle-sonic-blaster/"&gt;Wired covers&lt;/a&gt; the BBC show &lt;em&gt;&lt;a href="http://www.bbc.co.uk/bang/"&gt;Bang Goes The Theory&lt;/a&gt;&lt;a href="http://www.bbc.co.uk/bang/"&gt;'s&lt;/a&gt; &lt;/em&gt;designs to defeat acoustic weapons like the &lt;a href="http://www.google.com/url?sa=t&amp;amp;source=web&amp;amp;ct=res&amp;amp;cd=1&amp;amp;url=http%3A%2F%2Fen.wikipedia.org%2Fwiki%2FLong_Range_Acoustic_Device&amp;amp;ei=aieYSrPJAdTFlAflk4GzBQ&amp;amp;rct=j&amp;amp;q=sound+cruise+ship+defend&amp;amp;usg=AFQjCNHudk0utjFSlanzeDj1Si2atp7FLg"&gt;LRAD&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;and other systems used to help protect cruise ships and for crowd control. As the article points out, simply defending from non-lethal systems may make users more of a target. Does this mean we'll see pirates attacking cruise ships &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/em&gt;while wearing giant fishbowl sound dampening helmets? Only time will tell...&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-164319144320225488?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/164319144320225488/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=164319144320225488" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/164319144320225488?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/164319144320225488?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/SOxIRV8B07M/defeating-acoustic-weapons.html" title="Defeating Acoustic Weapons" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/08/defeating-acoustic-weapons.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQGQ3g4eyp7ImA9WxNSE04.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-3485219885554792283</id><published>2009-08-26T21:17:00.003-04:00</published><updated>2009-08-26T21:25:22.633-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-26T21:25:22.633-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="counterfeiting" /><title>Details: The Most Notorious Counterfeiter</title><content type="html">Details has Albert Talton's &lt;a href="http://men.style.com/details/features/landing?id=content_10837"&gt;story online&lt;/a&gt; - he produced over 7 million dollars in counterfeit bills using commodity hardware. An interesting story, and a great lesson about how even the Secret Service can have problems finding counterfeiters, and how easily some of our currency protections can be avoided. Talton's process was ingenious, if flawed - he used the same scan for every bill, making them easier to identify. In the end, a series of mistakes, including those made by those he recruited to help him resulted in his capture.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-3485219885554792283?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/3485219885554792283/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=3485219885554792283" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3485219885554792283?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/3485219885554792283?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/qc68kuK7HEM/details-most-notorious-counterfeiter.html" title="Details: The Most Notorious Counterfeiter" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/08/details-most-notorious-counterfeiter.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAFRn0zeCp7ImA9WxNTEkw.&quot;"><id>tag:blogger.com,1999:blog-6936134049134982166.post-2288763522151038283</id><published>2009-08-13T21:05:00.003-04:00</published><updated>2009-08-13T21:18:37.380-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-13T21:18:37.380-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="forensic tools" /><category scheme="http://www.blogger.com/atom/ns#" term="computer forensics" /><title>Lessons Learned: Test Your Forensic Tools</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm4.static.flickr.com/3159/2787557572_e80bafc4ca.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 500px; height: 333px;" src="http://farm4.static.flickr.com/3159/2787557572_e80bafc4ca.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;Creative Commons attribution licensed image courtesy &lt;a href="http://www.flickr.com/photos/scimanal/"&gt;AlexWitherspoon&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;A recent call for a forensic drive copy which had to be done in a limited timeframe prompted a co-worker to dig out his USB to IDE/SATA bridge. Since we were asked to provide some time estimates, and to brush up on our imaging process, he ran a couple of tests on drives we keep for just those purposes. A quick boot of Helix on one of our laptops and he was ready to image the drive.&lt;br /&gt;&lt;br /&gt;As you would expect, he dd'ed the drives, and then checked MD5 sums. For the first test on a small partition, the MD5 sums matched. For the second, larger partition, the MD5 sums didn't. That's not normal - and not something we frequently see. Testing showed that this appeared to be repeatable.&lt;br /&gt;&lt;br /&gt;A repeat, with another USB bridge device returned a correct MD5 sum. If we had used the first bridge device for our image, we might have found out that our image wasn't provably correct hours after we began.&lt;br /&gt;&lt;br /&gt;The moral of the story? Test any device you use for forensic imaging before you have to face a real event. It will help you provide realistic time estimates, allows you to test your process, and might just save your day.&lt;br /&gt;&lt;br /&gt;As for the device? The manufacturer is sending a newer model - apparently this isn't an unknown issue.&lt;div class="blogger-post-footer"&gt;&lt;script src="http://www.google-analytics.com/urchin.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;script type="text/javascript"&gt;
_uacct = "UA-1423386-1";
urchinTracker();
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6936134049134982166-2288763522151038283?l=devilsadvocatesecurity.blogspot.com'/&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://devilsadvocatesecurity.blogspot.com/feeds/2288763522151038283/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6936134049134982166&amp;postID=2288763522151038283" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/2288763522151038283?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6936134049134982166/posts/default/2288763522151038283?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DevilsAdvocateSecurity/~3/21qx7Qu8iPY/lessons-learned-test-your-forensic.html" title="Lessons Learned: Test Your Forensic Tools" /><author><name>David</name><uri>http://www.blogger.com/profile/00465683521970634631</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="13971210731974409526" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://devilsadvocatesecurity.blogspot.com/2009/08/lessons-learned-test-your-forensic.html</feedburner:origLink></entry></feed>
