<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><!-- generator="wordpress/2.2.2" --><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Dragos Lungu Dot Com | Security Tools And Tips</title>
	<link>http://www.dragoslungu.com</link>
	<description>100% Unbiased Security Tools Reviews. Computer Security Blog about Phishing, Spyware, Malware and other Threats and Vulnerabilities we face everyday .</description>
	<pubDate>Wed, 16 Jul 2008 21:18:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/DragosLunguDotCom" type="application/rss+xml" /><feedburner:emailServiceId>844459</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><item>
		<title>WordPress Exploit Scanner</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268251/</link>
		<comments>http://www.dragoslungu.com/2008/07/09/wordpress-exploit-scanner/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 15:08:05 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Code Audit]]></category>

		<category><![CDATA[Vuln. Scanner]]></category>

		<category><![CDATA[Penetration Testing]]></category>

		<category><![CDATA[Web Applications]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/07/09/wordpress-exploit-scanner/</guid>
		<description><![CDATA[This WordPress plugin searches the files on your site for a few known strings sometimes used by hackers, and lists them with code fragments taken from the files.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img hspace="5" height="100" width="67" vspace="5" src="http://www.dragoslungu.com/wp-content/uploads/Image/trojan_horse.jpg" alt="WordPress Exploit Scanner" />If you run your blog on&nbsp; WordPress 2.5.1 or higher , you might be interested in a new security plugin called <strong>WordPress Exploit Scanner</strong> . I find it very easy to use an also very useful because it has already detected a malicious comment on my blog which was already tagged as spam by <a href="http://akismet.com/">Akismet </a>;&nbsp; - lucky for me I guess .</p>
<p>From it&#8217;s creators:</p>
<blockquote><p>This WordPress plugin searches the files on your site for a few known strings sometimes used by hackers, and lists them with code fragments taken from the files. It also makes a few checks of the database, looking at the active_plugins blog option, the comments table, and the posts table.</p></blockquote>
<p>So go and get your<a href="http://ocaoimh.ie/exploit-scanner/"> WordPress Exploit Scanner </a>plugin for free !</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=188&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_188" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=KVOM8Z"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=KVOM8Z" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=RVJLVJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=RVJLVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=U3icwj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=U3icwj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=D2CHyj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=D2CHyj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=otDoxj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=otDoxj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268251" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/07/09/wordpress-exploit-scanner/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/07/09/wordpress-exploit-scanner/</feedburner:origLink></item>
		<item>
		<title>Phishing Exposed, Brands Secured</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268252/</link>
		<comments>http://www.dragoslungu.com/2008/06/06/phishing-exposed-brands-secured/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 20:57:02 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[phishing]]></category>

		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/06/06/phishing-exposed-brands-secured/</guid>
		<description><![CDATA[a presentation about professional services : Anti-phishing and brand identity. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="150" vspace="5" hspace="5" height="112" alt="professional anti-phishing services" src="http://www.dragoslungu.com/wp-content/uploads/Image/phish_inspector.jpg" />It&#8217;s been a while since I posted on the blog and even though I want to think the opposite, there is no acceptable explanation for it <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>But I&#8217;m coming back by showing the most recent &quot;work&quot; I&#8217;ve done in the security arena. A few days ago I gave a presentation about the latest addition to <a href="http://www.itsecurity.ro">my employer</a>&#8217;s portfolio of professional services : <strong>Anti-phishing and brand identity. </strong></p>
<p>Apparently <a href="http://en.wikipedia.org/wiki/Pareto_principle">Pareto principle</a> applies to anti-phishing and brand identity protection as well: 80% of the tasks take 20% of the time and the rest of 20% of the tasks are done in the remaining 80% long hours. </p>
<p>I&#8217;m proud to say we tackle the 20% of the tasks fast. <strong>Very fast.</strong> </p>
<p>So here is my presentation on &quot;Phishing Exposed, Brands Secured&quot;. I made it the same image intensive way like my previous <a href="http://www.dragoslungu.com/2007/05/29/e-banking-web-application-security-presentation/">&quot;E-Banking Web Application Security&quot;</a> presentation and I hope you like it <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&nbsp;</p>
<div id="__ss_452131" style="width: 425px; text-align: left;"><object width="425" height="355" style="margin: 0px;"></p>
<param value="http://static.slideshare.net/swf/ssplayer2.swf?doc=antiphishing-1212784376244434-9" name="movie" />
<param value="true" name="allowFullScreen" />
<param value="always" name="allowScriptAccess" /><embed width="425" height="355" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://static.slideshare.net/swf/ssplayer2.swf?doc=antiphishing-1212784376244434-9"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;"><a href="http://www.slideshare.net/?src=embed"><img alt="SlideShare" style="border: 0px none ; margin-bottom: -5px;" src="http://static.slideshare.net/swf/logo_embd.png" /></a> | <a title="View Phishing Exposed, Brands Secured on SlideShare" href="http://www.slideshare.net/dragoslungu/anti-phishing-professional-services?src=embed">View</a> | <a href="http://www.slideshare.net/upload?src=embed">Upload your own</a></div>
</div>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=187&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_187" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=1BRdwc"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=1BRdwc" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=C4uvDI"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=C4uvDI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=3oJORi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=3oJORi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=1iyBfi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=1iyBfi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=xksu3i"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=xksu3i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268252" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/06/06/phishing-exposed-brands-secured/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/06/06/phishing-exposed-brands-secured/</feedburner:origLink></item>
		<item>
		<title>Scanners: New Nessus Release; New eEye Web Scanner</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268253/</link>
		<comments>http://www.dragoslungu.com/2008/03/14/scanners-new-nessus-release-new-eeye-web-scanner/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 19:41:17 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Vuln. Scanner]]></category>

		<category><![CDATA[Web Applications]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/03/14/scanners-new-nessus-release-new-eeye-web-scanner/</guid>
		<description><![CDATA[Tenable released version 3.2.0 of their popular Nessus vulnerability scanner and eEye enters the arena of web application scanners by releasing Retina Web App Scanner.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="75" src="http://www.dragoslungu.com/wp-content/uploads/Image/radar.jpg" alt="Scanners: New Nessus Release; New eEye Web Scanner" />This must be the new scanners post. Tenable released version 3.2.0 of their popular Nessus vulnerability scanner and eEye enters the arena of web application scanners by releasing Retina Web App Scanner.</p>
<p><a href="http://www.tenablesecurity.com/solutions/">Tenable Network Security</a> announced the availability of the new Nessus 3.2.0. This release sure looks promising because it brings quite a few new or improved features. It&#8217;s refreshing to see a software release which is not &quot;security-bugs-fixing&quot; driven:</p>
<p>This new major release contains several improvements, including:</p>
<ul>
<li>IPv6 support</li>
<li>Improved control of network bandwidth usage during scanning</li>
<li>Granular access to control rules to limit users to specific ports and audits</li>
<li>Improved WMI support</li>
<li>Full support for the new .nessus file format</li>
</ul>
<p>The new <a href="http://www.eeye.com/html/products/RetinaWebScanner/index.html">Retina Web Security Scanner</a> is not exactly a new security tool since it&#8217;s a custom version of <a href="http://www.ntobjectives.com/products/ntospider.php">NT Objectives NTOSpider</a> Web app vulnerability scanner, and is integrated with eEye&rsquo;s management console, REM. </p>
<p>This release is just a phase of eEye&#8217;s plans concerning the Web Scanner. Web security spells big business for eEye which intends to release an appliance-based version of this new scanner, says Morey Haber, vice president of product management at eEye.</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=186&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_186" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=FAYBST"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=FAYBST" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=5a033I"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=5a033I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=NlYOIi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=NlYOIi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=brrwVi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=brrwVi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=tO7VBi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=tO7VBi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268253" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/03/14/scanners-new-nessus-release-new-eeye-web-scanner/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/03/14/scanners-new-nessus-release-new-eeye-web-scanner/</feedburner:origLink></item>
		<item>
		<title>Good News from ArcSight and Imperva</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268254/</link>
		<comments>http://www.dragoslungu.com/2008/03/11/good-news-from-arcsight-and-imperva/#comments</comments>
		<pubDate>Tue, 11 Mar 2008 22:14:12 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[Report]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/03/11/good-news-from-arcsight-and-imperva/</guid>
		<description><![CDATA[ArcSight announced that T-Mobile has chosen ArcSight ESM  for Security Information and Event Management (SIEM) and Imperva SecureSphere Web Application Firewall won Information Security Magazine  "strongest overall offering for application and database security" . Sweet !]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="74" src="http://www.dragoslungu.com/wp-content/uploads/Image/two donuts.jpg" alt="two donuts" />Today <strong>ArcSight </strong>announced that T-Mobile has chosen ArcSight ESM&nbsp; for Security Information and Event Management (SIEM) and <strong>Imperva </strong>SecureSphere Web Application Firewall won Information Security Magazine&nbsp; <em>&quot;strongest overall offering for application and database security&quot;</em> . Sweet !</p>
<p><strong>1st sweet news</strong> :&nbsp; I&#8217;m very happy to hear that <a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8001">ArcSight closed T-Mobile </a>deal because I hope that more and more industry big players will adopt and support ArcSight&rsquo;s technical innovations. I&#8217;m particularly keen to see widespread adoption of <a href="http://www.arcsight.com/solutions_cef.htm">Common Event Format (CEF)</a> promoted by Arcsight :</p>
<blockquote><p>The Common Event Format (CEF) is an open log management standard that improves the interoperability of security-related information from different security and network devices and applications.</p></blockquote>
<p>When CEF will become de-facto log management standard I&rsquo;m sure that we will be able to aggregate and correlate events generate by any CEF compliant source.</p>
<p>&nbsp;<strong>2nd sweet news </strong>:&nbsp; <a href="http://www.dragoslungu.com/2007/10/21/imperva-securesphere-review/">I love Imperva&rsquo;s SecureSphere</a> Web Application and Database Firewall and it&rsquo;s great to know that Information Security Magazine <a href="http://www.imperva.com/news/press/2008/03_10_imperva_wins_shoot-out_review_of_web_application_firewalls.html">named </a>it &ldquo;the strongest overall offering for application and database security&rdquo;. I still think Imperva is one of the most accurate web security controls and it&rsquo;s good to see some public recognition for all the hard work!</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=185&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_185" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=YcsK95"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=YcsK95" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=PWFJNJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=PWFJNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=bIG31j"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=bIG31j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=ftdLaj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=ftdLaj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=82l4Nj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=82l4Nj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268254" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/03/11/good-news-from-arcsight-and-imperva/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/03/11/good-news-from-arcsight-and-imperva/</feedburner:origLink></item>
		<item>
		<title>CCTV Security Camera and Surveillance Equipment</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268255/</link>
		<comments>http://www.dragoslungu.com/2008/02/28/cctv-security-camera-and-surveillance-equipment/#comments</comments>
		<pubDate>Thu, 28 Feb 2008 21:22:28 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Offtopic]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/02/28/cctv-security-camera-and-surveillance-equipment/</guid>
		<description><![CDATA[Either presented as an exterior wireless camera or hidden wireless camera, a modern CCTV Security System must include highly efficient H.264 video encoding, motion detection, email notification, digital watermark and remote management.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="94" vspace="5" hspace="5" height="84" alt="CCTV Security Camera" src="http://www.dragoslungu.com/wp-content/uploads/Image/cctv.jpg" />When I started this blog, I wanted to offer free insights and reviews of various security tools which could help in mitigating various security risks. I still do, but I realized that technology is not enough. People are still the weakest link in the chain of security custody of information assets. </p>
<p>A few weeks ago I&rsquo;ve met a UK security consultant who told me the latest cover-your-ass employee excuse for having too many beers at the local pub and losing a PDA or laptop stuffed with valuable information: My laptop was stolen from my desk! </p>
<p>It&rsquo;s a nice story and it holds most of the time. But there is a very simple way to prevent such incidents and I&rsquo;m not talking about a beer ban in pubs <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&rsquo;m talking about CCTV Security Camera and Surveillance Equipment which can be easily deployed as computer hardware <a href="http://www.123-cctv.com/seccams/remote.html">DVR Camera Systems</a> or standalone DVR appliances. </p>
<p>Either presented as an <a href="http://www.123-cctv.com/cctvcams/extwireless.html">exterior wireless camera</a> or <a href="http://www.123-cctv.com/survcams/hidwireless.html">hidden wireless camera</a>, a modern <a href="http://www.123-cctv.com/seccams/agora.cgi?product=createyourownsystem">CCTV Security System </a>must include highly efficient H.264 video encoding, motion detection, email notification, digital watermark and remote management. </p>
<p>One example of such system is the sponsor of this post, the&nbsp; DiGiCam DVR 120 FPS system by 123 CCTV Security Camera Surveillance Equipment. </p>
<p>I have not used the system yet but if I would go for building a CCTV Security System I would definitely get in contact with <a href="http://www.123-cctv.com">123 CCTV Security Camera Surveillance Equipment</a>.</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=184&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_184" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=Vpa75V"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=Vpa75V" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=LpD0tJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=LpD0tJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=ZPKzKj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=ZPKzKj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Tlcd3j"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Tlcd3j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=8qpbQj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=8qpbQj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268255" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/02/28/cctv-security-camera-and-surveillance-equipment/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/02/28/cctv-security-camera-and-surveillance-equipment/</feedburner:origLink></item>
		<item>
		<title>OpenDNS Offers Free Web Content Filtering</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268256/</link>
		<comments>http://www.dragoslungu.com/2008/02/20/opendns-offers-free-web-content-filtering/#comments</comments>
		<pubDate>Wed, 20 Feb 2008 21:34:05 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Firewalls]]></category>

		<category><![CDATA[Proxy]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/02/20/opendns-offers-free-web-content-filtering/</guid>
		<description><![CDATA[OpenDNS offers FREE Web content filtering across more than 30 categories as a service for your network.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="40" src="http://www.dragoslungu.com/wp-content/uploads/Image/opendns_logo_100.gif" alt="" />On May 5 2007 I <a href="http://www.dragoslungu.com/2007/05/15/domain-blocking-with-opendns-free-url-filtering/">wrote</a> about OpenDNS&#8217; initiative to offer web content filtering for the masses. At that time I thought the service will be offered for a fee, but to my complete surprise, David Uletvitch has decided to turn this project into a community effort.</p>
<p>Hundreds of thousands of websites have been manually tagged by volunteers and the result is given back to the public domain in the form of <a href="https://www.opendns.com/features/content_filtering/">free web content filtering</a>. </p>
<p>Deploying the system is straight forward:</p>
<ol>
<li>&nbsp;Use OpenDNS&#8217; servers for DNS resolution</li>
<li>&nbsp;Create a free account</li>
<li>&nbsp;Add a network to the account (Yes, dynamically assigned IP addressed are supported too! )</li>
<li>&nbsp;Pick the web categories you want to filter out - there are more than 30 categories!</li>
<li>&nbsp;Turn on content filtering</li>
<li>&nbsp;All done. Wait 3 minutes and test .</li>
</ol>
<p>I would definitely recommend this project to anybody looking for a way to control the web access. First thing that comes into mind is keeping kids safe online. However, I&#8217;m sure that it&#8217;s hard to practice what you preach so if you use this system to protect your child, remember to &quot;turn off&quot; the OpenDNS resolver whenever you want to browse the web <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . </p>
<p>Nevertheless, a great tool indeed!</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=183&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_183" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=KPnCkg"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=KPnCkg" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=RFbZDI"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=RFbZDI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=YU8f2i"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=YU8f2i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=lfuSzi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=lfuSzi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=CNY1ui"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=CNY1ui" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268256" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/02/20/opendns-offers-free-web-content-filtering/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/02/20/opendns-offers-free-web-content-filtering/</feedburner:origLink></item>
		<item>
		<title>Can I Evade ScanSafe Anywhere+ ?</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268257/</link>
		<comments>http://www.dragoslungu.com/2008/01/29/can-i-evade-scansafe-anywhere/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 20:02:00 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Firewalls]]></category>

		<category><![CDATA[Web Applications]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2008/01/29/can-i-evade-scansafe-anywhere/</guid>
		<description><![CDATA[ScanSafe Anywhere+ is a very cool web security service which is intended to provide web content security for roaming users. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="198" vspace="5" hspace="5" height="71" alt="scansafe anywhere plus" src="http://www.dragoslungu.com/wp-content/uploads/Image/scansafe_anywhere.jpg" />ScanSafe just launched <strong><a href="http://www.scansafe.com/anywhereplus3/index">Anywhere+</a></strong>, a very cool web security service which is intended to provide web content security for roaming users. </p>
<p>Well, securing the laptops used by sales or marketing staff&nbsp; *outside of the company&#8217;s premises* has always been a pain in the behind <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> and I&#8217;m afraid this will not change overnight. </p>
<p>However, I find ScanSafe&#8217;s approach interesting and it might just work this time&#8230; but how does it work? Is it a proxy setting? Is it a VPN connection? Is it a browser plugin? I don&#8217;t know so I had to find out. I applied for a trial account and I hope I will get to the bottom of this issue soon. </p>
<p>Sure, the marketing presentation looks nice:</p>
<div align="center"><img width="400" vspace="5" hspace="5" height="295" alt="" src="http://www.dragoslungu.com/wp-content/uploads/Image/anywhere_plus.jpg" /></div>
<p>And so does the explanatory text:</p>
<blockquote>
<ul>
<li>Authenticates and directs your external client Web traffic to our scanning infrastructure.&nbsp;</li>
<li>Numerous datacenters are located all over the world from Sydney to San Francisco ensuring that your employees are never too far from our in-the-cloud scanning services.</li>
<li>SSL-encryption of all Web traffic flowing to us improves security over public networks</li>
</ul>
</blockquote>
<p>So, I&#8217;m guessing that Anywhere+ alters the browser itself and no matter how you get on Internet, the web requests will be redirected to ScanSafe&#8217;s data centers where the response is checked for web malware. </p>
<p>This raises a few questions on the adoption of this technology:</p>
<ul>
<li>User&rsquo;s online privacy could be questioned &ndash; Lots of authentication pages don&rsquo;t use SSL</li>
<li>If this technology is browser dependant (my money is on Internet Explorer), what would prevent a smart a$$ user to use a different browser such as <a href="http://portableapps.com/">portable apps</a>&#8230;</li>
</ul>
<p>I wish <a href="http://www.scansafe.com/anywhereplus3/index">ScanSafe Anywhere+</a> best of luck because the service is much needed and it&rsquo;s distributed architecture looks promising.&nbsp; And guys, please don&rsquo;t forget my application for a trial version <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>UPDATE:</p>
<p>I got an email from Spencer Parker, Director of Product Management at ScanSafe and here are some clarifications:</p>
<blockquote>
<p>1. The software works at the protocol level, not application level. This means it works with any application that uses the HTTP or HTTPS protocols. This means if users go ahead and install another browser to bypass corporate proxy settings (which a lot do!) then the Anywhere+ driver still redirects the protocols correctly to the closest ScanSafe scanning tower.</p>
<p>2. We use an SSL tunnel to get all HTTP and HTTPS traffic to the scanning tower. It does this to add an extra level of security to the application (stop people sniffing your traffic at wireless hotspots etc) and for other reasons as well.</p>
</blockquote>
<p>
I&#8217;m still waiting for my trial account <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=182&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_182" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=blMlwo"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=blMlwo" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=zePSTJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=zePSTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=G3qTDj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=G3qTDj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=41raOj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=41raOj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=jD5KEj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=jD5KEj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268257" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2008/01/29/can-i-evade-scansafe-anywhere/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2008/01/29/can-i-evade-scansafe-anywhere/</feedburner:origLink></item>
		<item>
		<title>Googlehacks and Anti-Googlehacks</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268258/</link>
		<comments>http://www.dragoslungu.com/2007/12/05/googlehacks-and-anti-googlehacks/#comments</comments>
		<pubDate>Wed, 05 Dec 2007 21:39:37 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Web Applications]]></category>

		<category><![CDATA[Php]]></category>

		<category><![CDATA[Fingerprinting]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/12/05/googlehacks-and-anti-googlehacks/</guid>
		<description><![CDATA[I've found today 2 resources which are connected to good old Google Hacking Database : Googlehacks and Google Hacking Honeypot.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="42" src="http://www.dragoslungu.com/wp-content/uploads/Image/google.jpg" alt="Googlehacks and Anti-Googlehacks " />I&#8217;ve found today 2 resources which are connected to good old Google Hacking Database :</p>
<ol>
<li><a href="http://code.google.com/p/googlehacks/">Googlehacks</a> which is&nbsp; a dedicated application for Windows / Linux / Mac and allows you to easily run specialized Google queries (a.k.a <a href="http://johnny.ihackstuff.com/ghdb.php">googledorks</a>). I would say that it&#8217;s a &quot;must&quot; inclusion in&rdquo;Web Hacking for Dummies&quot;.</li>
<li><a href="http://ghh.sourceforge.net/index.php">Google Hack Honeypot</a> which is a set of PHP scripts used to detect any Google hacking attempts targeting your site. Well, it might me one of your friends using the tool described at #1 above <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ol>
<p>I find the Google Hacking Honeypot specifically interesting because I think it might be used as an IDS-like PHP class / module to identify who&#8217;s pulling some intelligence reports on your website.</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=181&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_181" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=x20U0i"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=x20U0i" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=k5H5sJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=k5H5sJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=jKg5Vj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=jKg5Vj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=k9MUQj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=k9MUQj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=N5ttFj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=N5ttFj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268258" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/12/05/googlehacks-and-anti-googlehacks/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/12/05/googlehacks-and-anti-googlehacks/</feedburner:origLink></item>
		<item>
		<title>Nikto 2 Is Out There</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268259/</link>
		<comments>http://www.dragoslungu.com/2007/11/14/nikto-2-is-out-there/#comments</comments>
		<pubDate>Wed, 14 Nov 2007 20:46:47 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Vuln. Scanner]]></category>

		<category><![CDATA[Web Applications]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/11/14/nikto-2-is-out-there/</guid>
		<description><![CDATA[Nikto 2 is out ! Finally :) I'm sure most of us have seen the funny message primisinf a new version real soon ; well, it happened and you can check the huge Changelog here.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="88" vspace="5" hspace="5" height="102" src="http://www.dragoslungu.com/wp-content/uploads/Image/nikto.jpg" alt="Nikto 2 Is Out There" />A very short post :</p>
<p><strong><a href="http://www.cirt.net/code/nikto.shtml">Nikto 2</a></strong> is out ! Finally <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I&#8217;m sure most of us have seen the funny message primisinf a new version real soon ; well, it happened and you can check the huge <a href="http://www.cirt.net/nikto/UPDATES/2.00/CHANGES.txt">Changelog here</a>.</p>
<p>Thanks to all the fine folks at CIRT.NET !</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=180&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_180" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=9oXkIv"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=9oXkIv" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=BA6MbJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=BA6MbJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=YZjgqj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=YZjgqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=bxRoFj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=bxRoFj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=9JSltj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=9JSltj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268259" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/11/14/nikto-2-is-out-there/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/11/14/nikto-2-is-out-there/</feedburner:origLink></item>
		<item>
		<title>USB Security Appliance - YOGGIE Pico</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268260/</link>
		<comments>http://www.dragoslungu.com/2007/11/13/usb-security-appliance-yoggie-pico/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 19:08:56 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Firewalls]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/11/13/usb-security-appliance-yoggie-pico/</guid>
		<description><![CDATA[The YOGGIE Pico Personal Security Server runs of an USB port and provides more than a dozen security features.No larger than a regular USB thumb drive, Yoggie Pico runs a custom Linux distribution and it packs almost all security functionality you could find in a large corporate network.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="150" vspace="5" hspace="5" height="111" border="1" src="http://www.dragoslungu.com/wp-content/uploads/Image/yoggie-pico-large.jpg" alt="USB Security Appliance - YOGGIE" />Today I&#8217;ve seen the smallest security appliance ever ! The <a href="http://www.yoggie.com/pico-personal"><strong>YOGGIE Pico Personal Security Server </strong></a>runs of an USB port and provides more than a dozen security features. At first I thought it&#8217;s an USB drive full of portable applications but I was wrong. The Yoggie Pico it is a server-server with proper CPU, SDRAM, Flash, Operating System, File System and all <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>No larger than a regular USB thumb drive, Yoggie Pico runs a custom Linux distribution and it packs almost all security functionality you could find in a large corporate network:</p>
<ul>
<li>&nbsp;Adaptive Security Policy&trade;</li>
<li>Multi-Layer Security Agent&trade;</li>
<li>Layer-8 Security Engine&trade;</li>
<li>URL Categorization &amp; Filtering</li>
<li>Anti-Spam</li>
<li>Anti-Phishing</li>
<li>Antispyware</li>
<li>Antivirus</li>
<li>Transparent Email Proxies (POP3; SMTP)</li>
<li>Transparent Web Proxies (HTTP; FTP)</li>
<li>Intrusion Detection System / Intrusion Prevention System</li>
<li>VPN Client</li>
<li>Stateful Inspection Firewall</li>
</ul>
<p>Awesome Tool // You can read about <a href="http://www.yoggie.com/how-it-works">how it works</a> or you can download the datasheet (PDF) <a href="http://www.yoggie.com/PDF/Personal%20DS.pdf">here</a> .</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=178&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_178" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=YHM4zH"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=YHM4zH" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=oTl52I"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=oTl52I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=AW4wwi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=AW4wwi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=A2jrKi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=A2jrKi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=ggmaWi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=ggmaWi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268260" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/11/13/usb-security-appliance-yoggie-pico/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/11/13/usb-security-appliance-yoggie-pico/</feedburner:origLink></item>
		<item>
		<title>GIAC Secure Software Programmer (GSSP) Certification</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268261/</link>
		<comments>http://www.dragoslungu.com/2007/11/06/giac-secure-software-programmer-gssp-certification/#comments</comments>
		<pubDate>Tue, 06 Nov 2007 20:10:18 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Code Audit]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/11/06/giac-secure-software-programmer-gssp-certification/</guid>
		<description><![CDATA[

Ha! Finally there is an official method to tell apart the security minded programmers from the rest of the coder crowd. GIAC Secure Software Programmer (GSSP) Certification is a brand new SANS exam designed to test the security knowledge of developers in an effort to reduce the application security vulnerabilities. 
It is an efficient example [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="150" vspace="5" hspace="5" height="140" src="http://www.dragoslungu.com/wp-content/uploads/Image/gssp_logo.gif" alt="GIAC Secure Software Programmer (GSSP) Certification   " />Ha! Finally there is an official method to tell apart the security minded programmers from the rest of the coder crowd. <a href="http://www.sans.org/gssp/"><strong>GIAC Secure Software Programmer (GSSP) Certification</strong></a> is a brand new SANS exam designed to test the security knowledge of developers in an effort to reduce the application security vulnerabilities. </p>
<p>It is an efficient example of fixing the cause of software vulnerabilities and I hope that it won&#8217;t turn into a paper certification like so many other security certs have done during the past years. </p>
<p>There are two tests available depending on the programming language chosen by the candidate and these are the exam blueprints:</p>
<ul>
<li><a href="http://www.sans.org/gssp/SANS-SSI%20C%20Blueprint%20(9-07).pdf?portal=e2c1849c893ee9f12b6a786601976541">C Exam</a></li>
<li><a href="http://www.sans.org/gssp/SANS-SSI%20Java_JavaEE%20Blueprint%20(9-07).pdf?portal=e2c1849c893ee9f12b6a786601976541">Java Exam</a></li>
</ul>
<p>According to the <a href="http://www.sans.org/gssp/locations.php?portal=e2c1849c893ee9f12b6a786601976541">calendar of events</a>, the first exam sessions will be held on Dec 2 in Orlando, FL and Dec 5 in London, GB.<br />
Good luck to all who consider talinkg this exam !</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=177&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_177" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=VQyPJw"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=VQyPJw" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=DGOAsJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=DGOAsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=iUeiMj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=iUeiMj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Ri2bXj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Ri2bXj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Yd4mhj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Yd4mhj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268261" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/11/06/giac-secure-software-programmer-gssp-certification/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/11/06/giac-secure-software-programmer-gssp-certification/</feedburner:origLink></item>
		<item>
		<title>Pixy is a Free PHP Code Audit Tool</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268262/</link>
		<comments>http://www.dragoslungu.com/2007/10/30/pixy-is-a-free-php-code-audit-tool/#comments</comments>
		<pubDate>Tue, 30 Oct 2007 21:24:56 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Code Audit]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/30/pixy-is-a-free-php-code-audit-tool/</guid>
		<description><![CDATA[today I've found a PHP XSS and SQL injection source code analyzer called Pixy]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="75" vspace="5" hspace="5" height="100" align="left" alt="Pixy : PHP Code Audit Tool" src="http://www.dragoslungu.com/wp-content/uploads/Image/brush.jpg" />I&#8217;ve always thought that secure web applications must be built secure and no matter how many patches are released during an application&#8217;s life cycle, secure coding and secure code are the fundamental pillars of secure web.&nbsp;</p>
<p>Defending a vulnerable web application with one Web Application Firewall should only buy you some time toactually fix the vulnerabilities. I strongly believe that virtual patching is just a buzz marketing crap word.&nbsp; Always fix the code !</p>
<p>Just a few days after I found a <a href="http://www.dragoslungu.com/2007/10/23/xssdetect-free-visual-studio-plugin/">static .Net&nbsp; XSS code analyzer</a> , today I&#8217;ve found a <a href="http://pixybox.seclab.tuwien.ac.at/pixy/">PHP XSS and SQL injection source code analyzer</a> called <strong>Pixy</strong>.</p>
<p><a href="http://pixybox.seclab.tuwien.ac.at/pixy/download.php">Download </a>and install Pixy today and please share the experience !</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=176&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_176" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=wgIf9G"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=wgIf9G" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=c5EpIJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=c5EpIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=7UF1sj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=7UF1sj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=UV1Awj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=UV1Awj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=2LHhPj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=2LHhPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268262" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/30/pixy-is-a-free-php-code-audit-tool/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/30/pixy-is-a-free-php-code-audit-tool/</feedburner:origLink></item>
		<item>
		<title>XSSDetect - Free Visual Studio Plugin</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268263/</link>
		<comments>http://www.dragoslungu.com/2007/10/23/xssdetect-free-visual-studio-plugin/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 18:46:41 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Code Audit]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/23/xssdetect-free-visual-studio-plugin/</guid>
		<description><![CDATA[NEW!  Microsoft just released XSSDetect,  which is a free VisualStudio plugin designed to detect XSS vulnerabilities in managed code. ]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="148" vspace="5" hspace="5" height="60" src="http://www.dragoslungu.com/wp-content/uploads/Image/visual_studio.jpg" alt="XSSDetect source code analysis" />NEW!&nbsp; Microsoft just released <strong>XSSDetect</strong>,&nbsp; which is a free VisualStudio plugin designed to detect XSS vulnerabilities in managed code.</p>
<p>My relationship with programming <em>has been going from bad to worse and we just decided it was time to call it quits</em> a few years ago and that&#8217;s the reason I won&#8217;t be able to test it first hand. Nevertheless I think&nbsp; we should support any effort to reduce software vulnerabiltiies and this time props go to Microsoft ! </p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=19a9e348-bdb9-45b3-a1b7-44ccdcb7cfbe&amp;displaylang=en">Download XSSDetect</a> from Microsoft</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=175&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_175" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=amWeBj"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=amWeBj" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=eUoptJ"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=eUoptJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=tSLg1j"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=tSLg1j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=7NbOMj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=7NbOMj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=4HFWjj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=4HFWjj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268263" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/23/xssdetect-free-visual-studio-plugin/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/23/xssdetect-free-visual-studio-plugin/</feedburner:origLink></item>
		<item>
		<title>Imperva SecureSphere Review</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268264/</link>
		<comments>http://www.dragoslungu.com/2007/10/21/imperva-securesphere-review/#comments</comments>
		<pubDate>Sun, 21 Oct 2007 16:24:52 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/21/imperva-securesphere-review/</guid>
		<description><![CDATA[Here are 10 reasons I liked Imperva SecureSphere, an awesome Web Application Firewall or should I say Business Application Firewall for obvious reasons which I will present below.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="150" vspace="5" hspace="5" height="36" src="http://www.dragoslungu.com/wp-content/uploads/Image/imperva.jpg" alt="Imperva SecureSphere Review" />Recently I took part in a training session on <a href="http://www.imperva.com/products/securesphere/"><strong>Imperva SecureSphere&reg;</strong> </a>and I must say I was impressed with the architecture, features and overall philosophy behind this product. </p>
<p>Here are 10 reasons I liked Imperva SecureSphere, an awesome Web Application Firewall or should I say Business Application Firewall for obvious reasons which I will present below. </p>
<p><em>Note : I am not affiliated with Imperva , and this is not a paid review . </em></p>
<p><strong>1. Dual Approach on Web Application Security : WWW + SQL </strong><br />
There are several <a href="http://www.owasp.org/index.php/Web_Application_Firewall ">Web Application Firewalls </a>&nbsp; available on the market and apparently Imperva is the only one who approaches Application Security the right way, as a multi-tier structure. Therefore, Imperva offers IPS-like protection both on presentation layer (HTTP traffic) and data layer (SQL Traffic).&nbsp; </p>
<p>The ability to monitor and block both HTTP and SQL traffic provides defense in depth and unmatched end-to-end user accountability (from browser to database). </p>
<p><strong>2. Architecture / Extremely Flexible Deployment&nbsp; </strong><br />
SecureSphere is offered as a hardened appliance withstanding impressive traffic values up to 2Gbps and 36,000 HTTP Transactions / sec. or 200,000 SQL Transactions / sec.&nbsp; </p>
<p>The Architecture of a SecureSphere solution is modular and scalable:</p>
<div align="center"><img width="392" vspace="5" hspace="5" height="202" align="middle" src="http://www.dragoslungu.com/wp-content/uploads/Image/Imperva_ssfamily_network_arch.jpg" alt="" /></div>
<p>
I liked the fact that there is a Management server and &ldquo;enforcement points&ldquo;in the form of Web Application Firewalls and Database Security Gateways. Yes, it looks similar to a CheckPoint architecture, and there is a <a href="http://www.imperva.com/company/directors.html">good reason </a>for this . </p>
<p>The deployment options blew me away because I was used only to reverse proxy and transparent proxy web application firewall. Well, Imperva offers a wide range of deployment scenarios which should fit any network requirement:</p>
<ul>
<li>Transparent Bridge (Layer 2)</li>
<li>Router/NAT (Layer 3)</li>
<li>Reverse Proxy (Layer 7)</li>
<li>Non-inline sniffer</li>
<li>Transparent Proxy (Layer 7).</li>
</ul>
<p><strong>3. Positive Security Model / Dynamic Profiling </strong><br />
The <a href="http://www.owasp.org/index.php/Positive_security_model">positive security model </a>is definitely not something new, especially in web application firewall design. But what I found to be very interesting about Imperva&rsquo;s approach was the semantic breakdown of both HTTP and SQL requests. Finally HTTP requests or SQL queries can be tokenized and each token can be fed to a correlation engine. Suddenly data has a meaning and actions can be taken based on the meaning of tokens. </p>
<p>One of the drawbacks of the positive security model is the taming (or should I say training <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> of the Firewall / IPS, etc. Lots of time spent on teaching a machine the difference between normal and ab-normal.</p>
<p>Imperva tackled this time &amp; resource consuming action by implementing a dynamic profiling functionality. Every new application is automatically set into &ldquo;Learning&rdquo; mode until a certain number of requests (in the order of thousands) or days have elapsed. At that point, based on the data gathered so far, the system defines a profile of acceptable requests and locks the application in &ldquo;Protection&rdquo; mode. Defining what is &ldquo;normal&rdquo; or &ldquo;acceptable&rdquo; is done by a statistical correlation of all values recorded for each token, much like a Gauss bell normal distribution. </p>
<p>At any future point in time the application lockdown can be removed by an administrator and tokens can be modified.</p>
<p><strong>4. HTTPS/SSL Inspection Passive decryption or termination</strong><br />
One of the common shortcomings of web application firewalls / IPS is the inability to look inside a SSL encrypted data stream without breaking the SSL connection between browser and web server. </p>
<p>Imperva SecureSphere acts as a transparent, passive SSL terminator and it can either store a copy of the web server&rsquo;s private key or can it leverage the key management &amp; encryption to an existing HSM unit.</p>
<p><strong>5. Imperva Application Defense Center (ADC)</strong><br />
Whenever one buys such a complex security solution, it&rsquo;s a good feeling to know that the product is actively supported and improved by a dedicated R&amp;D team. Think of <a href="http://xforce.iss.net/">ISS (IBM) X-Force</a>. </p>
<p>Imperva&rsquo;s own R&amp;D uber hacker team is called <a href="http://www.imperva.com/application_defense_center/">Application Defense Center (ADC)</a> and its leader is Amichai Shulman, Imperva&rsquo;s CTO. </p>
<p>I was told that the average time elapsed since a zero day vulnerability disclosure and a full signature release is 3 to 5 days. And we are talking multiple layer vulnerabilities: Network, Operating Systems, Protocol Anomalies (Http and Sql), Database Platforms, Web Application Platforms, etc. <br />
<strong><br />
6. Enterprise Ready Features </strong><br />
I call this set of features &ldquo;Enterprise-Ready Features&rdquo; because I&rsquo;ve come to understand that it&rsquo;s not enough for a product to be the best in its class, it has to fit in nicely within an established network and it has to be easy to manage, deploy and upgrade. Yeah, 21st century corporate <strike>bull</strike> requirements <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So here they are Imperva SecureSphere&rsquo;s Enterprise-Ready features</p>
<ul>
<li>High Availability
<ul>
<li>IMPVHA (Active/Active, Active/Passive) &ndash; proprietary protocol</li>
<li>Fail open interfaces (bridge mode only)</li>
<li>VRRP</li>
<li>STP and RSTP</li>
</ul>
</li>
<li>Alerting various monitoring and security event management systems trough&nbsp; SNMP, Syslog, Email,</li>
<li>Integrated graphical reporting</li>
<li>Real-time dashboard.</li>
<li>Pre-defined and custom correlation rules incorporate all security elements to detect complex, multi-stage attacks.</li>
</ul>
<p><strong>7. Data Base Security Assessment </strong><br />
I have been using SCUBA, Imperva&rsquo;s <a href="http://www.imperva.com/application_defense_center/scuba/">Free Database Vulnerability Scanner</a> for a while and it proved efficient in a few assignments. Little did I know that SecureSphere Database Security Gateway uses a 50 times larger database vulnerability scanner whenever a new database systems is included for monitoring / protection. </p>
<p>It just seems very logic for a Database IPS / Firewall to have inside knowledge about the configuration, patch level, roles, and data of the systems it&rsquo;s supposed to defend. It all comes down to the big importance of data profiling </p>
<p><strong> 8. Correlation Across Layers </strong><br />
One important evaluation criteria for any Firewall / IPS is the way it handles false positives and false negatives. Regardless of the layer it works on (network, application); the firewall should not block any legitimate request. Tough requirement to meet, especially when one has to cover multiple OSI layers (network, transport, presentation, application)!</p>
<p>Imperva has developed an internal correlation engine named Correlated Attack Validation (CAV) which tracks and correlates multiple events to accurately identify and block sophisticated attacks.</p>
<p>This is one example of blocking an attack which uses <a href="http://secunia.com/advisories/14530/ ">HTTP Request Smuggling</a>&nbsp; evasion technique:</p>
<div align="center"><img width="384" vspace="5" hspace="5" height="301" alt="Imperva SecureSphere Review" src="http://www.dragoslungu.com/wp-content/uploads/Image/correlated-attack-validatio.gif" /></div>
<p>
<strong> 9. SQL queries AND response </strong><br />
Many database monitoring and audit solutions will log the SQL queries but I&rsquo;m not sure how many would think of logging the SQL response as well thus leaving one open door for insider threats. </p>
<p>The sheer volume of data can render this logging unusable, but Imperva has managed to deploy a very simple and effective solution: it stores the audit logs (SQL request and response) as flat files and this has little to no effect on traffic inspection. </p>
<p><strong> 10. Universal User Tracking </strong><br />
Accountability and non- repudiation are two cornerstone requirements for any solid security management system but it&rsquo;s been very difficult to implement them because the way most web application work:</p>
<ul>
<li>Phase 1: The user logs into the web application using his username / token, etc. &ndash;</li>
<li>Phase 2: The user clicks on a link which translates into a series of SQL queries to be passed to the database layer.</li>
<li>Phase 3: The application server initiates a database connection using a generic application user.</li>
<li>Phase 4: The database executes the query and returns the data to the application server which in turn presents the data to the user.</li>
</ul>
<p>Somewhere between phase 2 and 4, the chain of accountability has been broken and there is no direct link between an user and the SQL query run on the database. </p>
<p>This is where Imperva&rsquo;s Universal User Tracking kicks in: it makes users accountable for their actions &ndash; even when they access data through business applications. To identify application IDs, a dedicated SecureSphere interface monitors application user sessions and correlates those sessions with specific database transactions.</p>
<p><strong>Conclusions </strong><br />
<a href="http://www.imperva.com/products/securesphere/"> Imperva SecureSphere</a> represents an advanced business application security control which has taken the concept of Firewall &amp; IPS to the application layer with great results. <br />
Just like CheckPoint in 1993 changed&nbsp; the network firewall forever, I wouldn&rsquo;t wonder if 15 year later Imperva establishes itself as a reference in Activity Monitoring, Audit and Security for Business Applications and Databases. </p>
<p>However, take my review with a grain of salt as I didn&#8217;t test the product myself. .. Yet <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I plan to set-up a head to head&nbsp; clash between an automatic web attack suite and an automatic web firewall . Now <strong>that</strong>&rsquo;s going to be fun <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=174&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_174" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=Ji3uXq"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=Ji3uXq" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=AQ22mI"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=AQ22mI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=wITx8i"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=wITx8i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=I3p8wi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=I3p8wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=4fXKsi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=4fXKsi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268264" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/21/imperva-securesphere-review/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/21/imperva-securesphere-review/</feedburner:origLink></item>
		<item>
		<title>Zend Powered FREE FastCGI Extension for Microsoft IIS</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268265/</link>
		<comments>http://www.dragoslungu.com/2007/10/12/zend-powered-free-fastcgi-extension-for-microsoft-iis/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 12:39:11 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Php]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/12/zend-powered-free-fastcgi-extension-for-microsoft-iis/</guid>
		<description><![CDATA[Microsoft has released FastCGI which is a free server component enabling hosting of PHP applications on Windows Server 2003 and IIS 6 with increased reliability, scalability, and security.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="149" vspace="5" hspace="5" height="33" alt="" src="http://www.dragoslungu.com/wp-content/uploads/Image/PHP on IIS.jpg" />Microsoft has released FastCGI which is a free server component enabling hosting of PHP applications on Windows Server 2003 and IIS 6 with increased reliability, scalability, and security. </p>
<p><!--adsense#200post-->Most of the applications built for IIS use the native multi-threaded application model. This was not the case for the applications initially written for Linux and ported on Windows such as PHP extensions. Even though the PHP engine is multi-threaded, many of the PHP extensions are not multi-threaded and this takes away the advantage of multiple concurrent request processing.</p>
<p>The <a href="http://www.iis.net/php">Microsoft FastCGI Extension for IIS</a>&nbsp; provides full support for hosting and executing FastCGI enabled applications on IIS in high performance and reliable way.</p>
<blockquote><p> Some of the important features provided in this release of FastCGI Extension are listed below:</p>
<p>&nbsp;</p>
<ul>
<li>Reliable hosting of non thread-safe applications (such as PHP) in FastCGI mode by enforcing single request concurrency per FastCGI process</li>
<li>Support for hosting of FastCGI application frameworks on shared servers by providing necessary configurable.</li>
<li>Rich set of configuration options for tweaking performance of FastCGI extension and FastCGI processes.</li>
</ul>
</blockquote>
<p>
The most surprising detail of FastCGI is the cost : <strong>FREE</strong> as in beer !</p>
<p><a href="http://www.iis.net/downloads/default.aspx?tabid=34&amp;g=6&amp;i=1521">Download</a> it and be gentle on Microsoft with the bug reports. After all&#8230;they are taking baby steps into free software business <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=173&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_173" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=Z7YMku"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=Z7YMku" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=ugx4vG26"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=ugx4vG26" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=PVSWolgi"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=PVSWolgi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Cco3mr88"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Cco3mr88" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268265" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/12/zend-powered-free-fastcgi-extension-for-microsoft-iis/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/12/zend-powered-free-fastcgi-extension-for-microsoft-iis/</feedburner:origLink></item>
		<item>
		<title>When the going gets tough, It’s time for school !</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268266/</link>
		<comments>http://www.dragoslungu.com/2007/10/11/when-the-going-gets-tough-it%e2%80%99s-time-for-school/#comments</comments>
		<pubDate>Thu, 11 Oct 2007 20:01:24 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Reviews]]></category>

		<category><![CDATA[Offtopic]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/11/when-the-going-gets-tough-it%e2%80%99s-time-for-school/</guid>
		<description><![CDATA[A very interesting online cybersecurity degree offered by the Utica College : it’s a Bachelor of Science degree in Cybersecurity]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="47" alt="" src="http://www.dragoslungu.com/wp-content/uploads/Image/pic-utica-college-logo.jpg" />I don&rsquo;t know about you, but I owe a big part of my education and career to my independent study and research because not many universities were offering Bachelor / Master Degrees in Information Security back then. </p>
<p><!--adsense#200post-->Times have changed and today I came across a very interesting <a href="http://www.onlineuticacollege.com/online-cyber-security-degree.asp">online cybersecurity degree</a> offered by the <a href="http://www.onlineuticacollege.com"><strong>Utica College</strong></a> : it&rsquo;s a Bachelor of Science degree in Cybersecurity and it provides two concentrations :</p>
<ul>
<li>Cybercrime Investigations and Forensics</li>
<li>Information Assurance</li>
</ul>
<p>Security vulnerabilities and threats have changed and the age-old saying &ldquo;follow the money&rdquo; seems more vivid than ever. The technology behind financial operations has induced a new breed of risks which must be addressed from both Accounting and Computer Science point of view. </p>
<p>In order to address this risk, Utica College offers an unique set of <a href="http://www.onlineuticacollege.com">Economic Crime Degrees</a> which focuses on Financial Investigation in order to detect and investigate fraud and other economic crimes.</p>
<p>It&rsquo;s good to see that the academic world&nbsp; is adapting to the security threats we face nowadays and I hope that more and more students will chose the path we got to love and hate everyday <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . Only they won&rsquo;t have to walk the same rough path thanks to new online education and training available today.</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=172&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_172" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=qH2igO"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=qH2igO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Z05dDsdM"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Z05dDsdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=dDVvfuDa"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=dDVvfuDa" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=OsfvQfzr"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=OsfvQfzr" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=9F66LEEd"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=9F66LEEd" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268266" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/11/when-the-going-gets-tough-it%e2%80%99s-time-for-school/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/11/when-the-going-gets-tough-it%e2%80%99s-time-for-school/</feedburner:origLink></item>
		<item>
		<title>Free Web Application Firewall - Armorlogic Profense</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268267/</link>
		<comments>http://www.dragoslungu.com/2007/10/01/free-web-application-firewall-armorlogic-profense/#comments</comments>
		<pubDate>Mon, 01 Oct 2007 17:57:10 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Firewalls]]></category>

		<category><![CDATA[Web Applications]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/10/01/free-web-application-firewall-armorlogic-profense/</guid>
		<description><![CDATA[

Although one may argue that a firewall does not really solve the security problems of an organization, I highly doubt anyone would design a modern network security schema without a solid firewall. 
There are many open source network firewalls available on the market and this is why I was very glad to discover an open [...]]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="74" alt="Free Web Application Firewall - Armorlogic Profense " src="http://www.dragoslungu.com/wp-content/uploads/Image/firewall.jpg" />Although one may argue that a firewall does not really solve the security problems of an organization, I highly doubt anyone would design a modern network security schema without a solid firewall. </p>
<p>There are many open source network firewalls available on the market and this is why I was very glad to discover an <a href="http://www.armorlogic.com/profense_profense_base.html">open source web application firewall</a> available for free. </p>
<p><!--adsense#200post--><strong>Profense </strong>is the flagship product of <strong>Armorlogic</strong>, a Danish software development company created in early 2005 by Jakob Frydendal Gercke and Srebrenko Sehic, internet security specialists working as Big 4 consultants.</p>
<p>Apparently they founded they own company around web application security and positive security models. It paid off and Profense is already shipping its version 2. </p>
<p>The free version of the product is based on a stripped and hardened OpenBSD platform making it a hard to break appliance .Profense Base is packed with commercial grade features such as</p>
<p><strong>Web Application Firewall </strong></p>
<ul>
<li>Positive filtering</li>
<li>Automatic Policy Generation</li>
<li>HTTPS (SSL) Aware</li>
</ul>
<p><strong>Web Accelerator </strong></p>
<ul>
<li>Traffic compression</li>
<li>TCP connection off-loading</li>
<li>Static content caching</li>
<li>Dynamic content caching</li>
</ul>
<p><strong>Load balancer:</strong></p>
<ul>
<li>HTTP / HTTPS Load balancer</li>
<li>Session Persistence</li>
</ul>
<p>I think that the kind folks at Armorlogic deserve all the community support they can get, so I invite you to <a href="http://http://www.armorlogic.com/download_software.html">download Profense Base </a>and give it a spin!</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=171&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_171" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=v3NFAB"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=v3NFAB" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=hhJHU7In"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=hhJHU7In" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=v10OwX8G"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=v10OwX8G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=Gp9HFfG9"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=Gp9HFfG9" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=2cfDHmEW"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=2cfDHmEW" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268267" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/10/01/free-web-application-firewall-armorlogic-profense/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/10/01/free-web-application-firewall-armorlogic-profense/</feedburner:origLink></item>
		<item>
		<title>Kerberos Consortium Targets Universal Authentication Platform</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268268/</link>
		<comments>http://www.dragoslungu.com/2007/09/28/kerberos-consortium-targets-universal-authentication-platform/#comments</comments>
		<pubDate>Fri, 28 Sep 2007 19:52:34 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/09/28/kerberos-consortium-targets-universal-authentication-platform/</guid>
		<description><![CDATA[The Kerberos Consortium  goal is to establish Kerberos as the universal authentication platform for the world's computer networks.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="88" vspace="5" hspace="5" height="120" src="http://www.dragoslungu.com/wp-content/uploads/Image/The One Ring.jpg" alt="Kerberos Consortium Targets Universal Authentication Platform" />As you know, Kerberos was originally developed at MIT as the authentication protocol for MIT&#8217;s Project Athena in 1983 and was adopted as an IETF standard in 1993. The quick release of Kerberos as an Open source tool in 1987 led to a massive adoption amongst IT vendors up to a point that there is no way back to a non Kerberos world. </p>
<p><!--adsense#200post-->This is the reason why seven large organizations have decided to form <a href="http://www.kerberos.org/">The Kerberos Consortium</a> whose goal is to establish Kerberos as the universal authentication platform for the world&#8217;s computer networks.</p>
<p>The Consortium Operating Principles:</p>
<ul>
<li>Be a not-for-profit consortium of companies led by MIT.</li>
<li>Develop authentication and authorization technologies for computer networks based on the Kerberos system.</li>
<li>Meet the needs of users, operating system vendors, application vendors, and other members of the Kerberos community</li>
<li>Expand, and accelerate, the implementation and standardization efforts that MIT currently undertakes.</li>
<li>Provide a valuable forum by which customers and vendors can communicate their needs for the future of Kerberos</li>
<li>Provide a neutral environment, interoperability and functionality issues of concern to the wider Kerberos community.</li>
</ul>
<p>The Consortium&#8217;s members (sponsors) include big names in the industry such as Google and Stanford Univ. so it might well be One ring to rule&#8217;m all <img src='http://www.dragoslungu.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=170&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_170" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=j910FJ"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=j910FJ" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=pkyCobEY"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=pkyCobEY" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=J4EAeN71"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=J4EAeN71" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=9B4KTzRE"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=9B4KTzRE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=H4KkdlMT"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=H4KkdlMT" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268268" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/09/28/kerberos-consortium-targets-universal-authentication-platform/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/09/28/kerberos-consortium-targets-universal-authentication-platform/</feedburner:origLink></item>
		<item>
		<title>Finjan Web Security Trends Report - Q3/2007</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268269/</link>
		<comments>http://www.dragoslungu.com/2007/09/18/finjan-web-security-trends-report-q32007/#comments</comments>
		<pubDate>Tue, 18 Sep 2007 20:52:48 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Web Applications]]></category>

		<category><![CDATA[Articles]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/09/18/finjan-web-security-trends-report-q32007/</guid>
		<description><![CDATA[One of the innovative research presented in the report is the security model and risk posed by the various widgets which seem to be the hottest trend in GUI design.Either built for WWW, Windows Vista or Macintosh OSX Dashboard,the widgets are everywhere and Finjan found vulnerabilities in widgets and gadgets that enable attackers to gain control of user machines.]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="150" vspace="5" hspace="5" height="60" src="http://www.dragoslungu.com/wp-content/uploads/Image/finjan.jpg" alt="" /></p>
<p><a href="http://finjan.com">Finjan </a>has released it&#8217;s <a href="http://www.finjan.com/GetObject.aspx?ObjId=506">Web Security Trends Report - Q3/2007</a> (PDF) and I found it quite interesting to read.</p>
<p>One of the innovative research presented in the report is the security model and risk posed by the various widgets which seem to be the hottest trend in GUI design.Either built for WWW, Windows Vista or Macintosh OSX Dashboard,the widgets are everywhere and Finjan found vulnerabilities in widgets and gadgets that enable attackers to gain control of user machines.</p>
<p><!--adsense#200post-->This report also presents a detailed analysis of a very special malware : <strong>the financial data trojan</strong> which gets&nbsp; activated whenever an user does internet banking or logs in a financial institution website . &quot;Financially-focused crimeware &ndash; what happens when a trojan goes phishing&quot; shows step by step all the Crimeware Trojan Workflow :</p>
<ol>
<li>Detect login page to a financial service</li>
<li>Send the login credentials to the financial service as well as the crimeware server</li>
<li>Crimeware server response contains custom designed page to get more sensitive information (designed for the service provider)</li>
<li>Crimeware on infected PC injects the custom page into the browser (which is already connected via SSL to the financial provider)</li>
<li>Victim enters sensitive data into customized form</li>
<li>Crimeware sends customized form data to crimeware server</li>
<li>Crimeware gets the financial service response to the original login credentials and shows them on the browser.</li>
</ol>
<p>Get a copy of this report <a href="http://www.finjan.com/Content.aspx?id=827">here</a> .</p>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=169&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_169" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=taTlJg"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=taTlJg" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=HfHIQtnv"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=HfHIQtnv" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=YZX09spa"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=YZX09spa" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=03eK6Ezd"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=03eK6Ezd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=DjW9lOAI"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=DjW9lOAI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268269" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/09/18/finjan-web-security-trends-report-q32007/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/09/18/finjan-web-security-trends-report-q32007/</feedburner:origLink></item>
		<item>
		<title>2007 Best of Open Source in Security Awards</title>
		<link>http://feeds.feedburner.com/~r/DragosLunguDotCom/~3/339268270/</link>
		<comments>http://www.dragoslungu.com/2007/09/11/2006-best-of-open-source-in-security-awards/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 21:26:23 +0000</pubDate>
		<dc:creator>Dragos Lungu</dc:creator>
		
		<category><![CDATA[Vuln. Scanner]]></category>

		<category><![CDATA[Articles]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.dragoslungu.com/2007/09/11/2006-best-of-open-source-in-security-awards/</guid>
		<description><![CDATA[InfoWorld has announced the 2007 Best of Open Source in Security Awards and as far as I can see nothing new showed up in the awards list.
]]></description>
			<content:encoded><![CDATA[
<!-- ALL ADSENSE ADS DISABLED -->
<p><img width="100" vspace="5" hspace="5" height="73" alt="2007 Best of Open Source in Security Awards" src="http://www.dragoslungu.com/wp-content/uploads/Image/bossie.jpg" />I&#8217;m reading today that InfoWorld has announced the <a href="http://www.infoworld.com/article/07/09/10/37FE-boss-security_1.html">2007 Best of Open Source in Security Awards</a> and as far as I can see nothing new showed up in the awards list. </p>
<p>There awards categories include vulnerability scanning, intrusion prevention, anti-virus, anti-spam, firewalls, VPNs, and security testing.</p>
<blockquote><p>In security, open source rushed in because commercial vendors fell down on the job. As security problems in the enterprise outstripped the capabilities of commercial solutions, a number of talented security researchers stepped into the breach via the open source model.</p></blockquote>
<p><!--adsense#200post-->
<p>As expected, the winners within each category are well established, widely used open source applications with milions of daily users. It&#8217;s really a tough job for a new OpenSource application to make it to the short list of nominees.</p>
<p>Without further ado, these is the Best of open source in security:</p>
<ul>
<li><strong>Network Vulnerability Assessment</strong> : <a href="http://www.nessus.org/nessus/">Nessus</a></li>
<li><strong>Intrusion Prevention </strong>: <a href="http://www.snort.org/">Snort</a></li>
<li><strong>Anti-Virus</strong> : <a href="http://www.clamav.net/">ClamAv</a> (recently&nbsp; <a href="http://www.clamav.org/2007/08/17/sourcefire-acquires-clamav/">acquired</a> by SourceFire)</li>
<li><strong>Anti-Spam</strong> : <a href="http://spamassassin.apache.org/">SpamAssassin</a></li>
<li><strong>Best Firewall</strong> : <a href="http://www.ipcop.org/">IPCop</a></li>
<li><strong>Best SSL VPN</strong> : <a href="http://openvpn.net/">OpenVPN</a></li>
<li><strong>Best Security Testing Resource</strong> : <a href="http://www.osstmm.org/">OSSTMM</a></li>
</ul>
<p class="akst_link"><a href="http://www.dragoslungu.com/?p=168&amp;akst_action=share-this"  title="E-mail this, post to del.icio.us, etc." id="akst_link_168" class="akst_share_link" rel="nofollow">Share This</a>
</p>
<p><a href="http://feeds.feedburner.com/~a/DragosLunguDotCom?a=dvcLzA"><img src="http://feeds.feedburner.com/~a/DragosLunguDotCom?i=dvcLzA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=z6Ev1anj"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=z6Ev1anj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=ToHmhzty"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=ToHmhzty" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=fYuULWNe"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=fYuULWNe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DragosLunguDotCom?a=d27FbQt3"><img src="http://feeds.feedburner.com/~f/DragosLunguDotCom?i=d27FbQt3" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DragosLunguDotCom/~4/339268270" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.dragoslungu.com/2007/09/11/2006-best-of-open-source-in-security-awards/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.dragoslungu.com/2007/09/11/2006-best-of-open-source-in-security-awards/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic Page Served (once) in 0.926 seconds --><!-- Cached page served by WP-Cache -->
