<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-968722795408899035</atom:id><lastBuildDate>Thu, 24 May 2012 11:22:17 +0000</lastBuildDate><category>9/11</category><category>business</category><category>Microsoft Security</category><category>Network Security</category><category>pci</category><category>defense in depth</category><category>Fraud</category><category>virtualization security</category><category>Web Security</category><category>pharming</category><category>trust zones</category><category>penetration testing</category><category>Airline Security</category><category>web site security</category><category>Security</category><category>Voter Security</category><category>patches</category><category>Security Audit</category><category>Internet Security</category><title>Grok Computer Security</title><description>One hacker's odyssey to understand computer security</description><link>http://grok-security.blogspot.com/</link><managingEditor>noreply@blogger.com (Michael Berman)</managingEditor><generator>Blogger</generator><openSearch:totalResults>73</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Grok-Security" /><feedburner:info uri="grok-security" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>Grok-Security</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-3666079237216017673</guid><pubDate>Wed, 18 Apr 2012 00:44:00 +0000</pubDate><atom:updated>2012-04-23T09:18:57.142-07:00</atom:updated><title>Today’s Phish</title><description>Like everyone on the planet, I am sent free phish every day. Since I can’t turn these into loaves or wine, I usually don’t waste time on them. Today’s phish caused me to reminisce, and when I reminisce, I get curious, so I looked further. First, here is the phish:&lt;br /&gt;&lt;blockquote class="tr_bq" style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;A document was scanned and sent to you using a Hewlett-Packard JET ON4412867SSent to you by: KRYSTIN&lt;br /&gt;Pages : 6&lt;br /&gt;Filetype: Image (.jpeg) &amp;nbsp;View&lt;br /&gt;&lt;br /&gt;Location: NPSK1.4FL.&lt;br /&gt;Device: OP218S5OD2054128Mailprint: d72e6d72-e624bbbb&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;hr align="CENTER" size="3" width="95%" /&gt;&lt;span style="font-size: x-small;"&gt;A document was scanned and sent to you using a Hewlett-Packard JET ON4412867S&lt;br /&gt;&lt;br /&gt;Sent to you by: KRYSTIN&lt;br /&gt;Pages : 6&lt;br /&gt;Filetype: Image (.jpeg) &amp;nbsp;View&amp;nbsp; &lt;span style="color: blue;"&gt;&lt;u&gt;http://donteverclickalinkinemail.example.com/oCzgKm43/index.html&lt;/u&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;Location: NPSK1.4FL.&lt;br /&gt;Device: OP218S5OD2054128&lt;br /&gt;&lt;br /&gt;Mailprint: d72e6d72-e624bbbb&amp;nbsp;&lt;/span&gt;  &lt;/blockquote&gt;Really, I think it's been years since I last saw this type of phish. The initial URL runs through three secondary URLs (a .com, .ro, and .ir) that in turn point to a single host (173.44.136.197). At the time of this phish all three secondaries and the host were alive and serving the scam. The &lt;a href="http://wepawet.iseclab.org/view.php?hash=0a444874958b80692a68844281dce6e3&amp;amp;t=1334707315&amp;amp;type=js" rel="nofollow" target="_blank"&gt;payload&lt;/a&gt; when I research the .ro link, the &lt;a href="http://wepawet.iseclab.org/view.php?hash=7ce390f6fa97852226dd71691686e1a3&amp;amp;type=js" rel="nofollow"&gt;payload&lt;/a&gt; (using curl) at 16:43 PDT. The &lt;a href="http://wepawet.iseclab.org/view.php?hash=c4283b2f43a515fe0ca4a195287600f4&amp;amp;t=1334663160&amp;amp;type=js" rel="nofollow"&gt;payload&lt;/a&gt; reported by another blogger &lt;a href="http://blog.dynamoo.com/" target="_blank"&gt;dynamoo&lt;/a&gt;. The &lt;a href="http://wepawet.iseclab.org/view.php?hash=98c1b029f6d5847bd1ed29b36c747ec2&amp;amp;t=1334707704&amp;amp;type=js" rel="nofollow" target="_blank"&gt;payload&lt;/a&gt; now on .ir link -- note that the folks in IR appear to have now blocked the scam, or are running something else, I am leaving their CGI alone.&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://wepawet.iseclab.org/about.php" target="_blank"&gt;wepawet&lt;/a&gt; the payload contains two vulnerabilities first reported in 2010, &lt;a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0188" target="_blank"&gt;here&lt;/a&gt;, and &lt;a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1885" target="_blank"&gt;here&lt;/a&gt;. The Adobe Reader vulnerability applies up to 9.3 and the Microsoft applies to Win2003sp2. So that's a decent target space.&lt;br /&gt;&lt;br /&gt;What did I learn today?&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.dynamoo.com/links/contact.htm" target="_blank"&gt;dynamoo&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.lastline.com/about-us.html" target="_blank"&gt;lastline&lt;/a&gt; some of the smart guys involved with wepawet and &lt;a href="http://anubis.iseclab.org/?action=about" target="_blank"&gt;anubis&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;A good day.&lt;br /&gt;&lt;br /&gt;(updated 4/23)&lt;br /&gt;This phish is harder to detect on my phone, see image : &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-pFJEH8ZcjGE/T5WAxDw6doI/AAAAAAAAAI8/Pew1-bG2utU/s1600/phish.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-pFJEH8ZcjGE/T5WAxDw6doI/AAAAAAAAAI8/Pew1-bG2utU/s320/phish.jpg" width="213" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;span style="font-family: inherit;"&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-3666079237216017673?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=IIiA5c26-aU:JJ2UZyHbf38:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=IIiA5c26-aU:JJ2UZyHbf38:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=IIiA5c26-aU:JJ2UZyHbf38:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=IIiA5c26-aU:JJ2UZyHbf38:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=IIiA5c26-aU:JJ2UZyHbf38:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=IIiA5c26-aU:JJ2UZyHbf38:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/IIiA5c26-aU/todays-phish.html</link><author>noreply@blogger.com (Michael Berman)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-pFJEH8ZcjGE/T5WAxDw6doI/AAAAAAAAAI8/Pew1-bG2utU/s72-c/phish.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2012/04/todays-phish.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-7463406655200648853</guid><pubDate>Sat, 04 Feb 2012 19:31:00 +0000</pubDate><atom:updated>2012-02-04T11:40:06.189-08:00</atom:updated><title>Hackers force us to make JSF more secure</title><description>&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;There's been some commentary on the recent article, "&lt;a href="http://bit.ly/zCdmXy"&gt;China's Role in JSF's Spiraling Costs&lt;/a&gt;."                 &lt;/span&gt;&lt;style&gt;&lt;!--  /* Font Definitions */ @font-face  {font-family:Cambria;  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:0;  mso-generic-font-family:auto;  mso-font-pitch:variable;  mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin-top:0in;  margin-right:0in;  margin-bottom:10.0pt;  margin-left:0in;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-ascii-font-family:Cambria;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Cambria;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Cambria;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.25in 1.0in 1.25in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt;&lt;/style&gt;&lt;span style="font-size: small;"&gt;TaoSecurity (Richard Bejtlich’s) has an &lt;a href="http://taosecurity.blogspot.com/2012/02/toughest-question-in-digital-security.html"&gt;excellent blog&lt;/a&gt; on this, which follows up on a &lt;a href="https://twitter.com/#%21/4n6ir/status/165657525599993857"&gt;tweet by @4n6ir&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style&gt;&lt;!--  /* Font Definitions */ @font-face  {font-family:Cambria;  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:0;  mso-generic-font-family:auto;  mso-font-pitch:variable;  mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin-top:0in;  margin-right:0in;  margin-bottom:10.0pt;  margin-left:0in;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-ascii-font-family:Cambria;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Cambria;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Cambria;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.25in 1.0in 1.25in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt;&lt;/style&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;However, I have a different take:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;“Before the intrusions were discovered nearly three years ago, Chinese hackers actually sat in on what were supposed to have been secure, online program-progress conferences, the officials say.”&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;This sounds a lot like “&lt;a href="http://nyti.ms/zCgIYl"&gt;FBI Admits Hacker Group’s Eavesdropping.&lt;/a&gt;”            So after at least three years we still haven’t learned how to keep our secure conference calls, well, um, actually secure – but that’s a digression.  &lt;/span&gt;&lt;style&gt;&lt;!--  /* Font Definitions */ @font-face  {font-family:Cambria;  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:0;  mso-generic-font-family:auto;  mso-font-pitch:variable;  mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin-top:0in;  margin-right:0in;  margin-bottom:10.0pt;  margin-left:0in;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-ascii-font-family:Cambria;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Cambria;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Cambria;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.25in 1.0in 1.25in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt;&lt;/style&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;The article on the Joint Strike Fighter (JSF) goes on: ”…need for redesign of critical equipment. Examples include specialized communications and antenna arrays for stealth aircraft, as well as significant rewriting of software to protect systems vulnerable to hacking.”&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;The JSF’s software systems had serious vulnerabilities: “Defense analysts note that the JSF’s information system was not designed with cyberespionage, now called advanced persistent threat, in mind.” The JSF’s Multifunction Advanced Data Link (MADL) was dropped entirely because of reported “money issues.”&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;We were building one of the most “computerized” and “networked” fighter planes in the world. Imagine if the plane went into production with those serious software vulnerabilities and it was open to attack via it’s own aerial network? It’s not like adversaries haven’t already demonstrated their ability to hack our communications channels in the field to hijack drone telemetry, video, and perhaps to crash them.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;If there is a silver lining here, it’s that when the JSF does fly it’s systems will be better protected against software vulnerabilities and it won’t be broadcasting a SSID, although a &lt;a href="http://en.wikipedia.org/wiki/Lockheed_Martin_F-35_Lightning_II"&gt;Mach-2 WAP&lt;/a&gt; would have been pretty cool.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-7463406655200648853?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=duXvLGjasTk:FN2zjOKxAo4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=duXvLGjasTk:FN2zjOKxAo4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=duXvLGjasTk:FN2zjOKxAo4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=duXvLGjasTk:FN2zjOKxAo4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=duXvLGjasTk:FN2zjOKxAo4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=duXvLGjasTk:FN2zjOKxAo4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/duXvLGjasTk/hackers-force-us-to-make-jsf-more.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2012/02/hackers-force-us-to-make-jsf-more.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-6705428086878995488</guid><pubDate>Wed, 25 Jan 2012 01:06:00 +0000</pubDate><atom:updated>2012-01-24T17:06:39.621-08:00</atom:updated><title>I’ll tell you what I want, what I really, really want from a Cloud Provider</title><description>&lt;style&gt;&lt;!--  /* Font Definitions */ @font-face  {font-family:Cambria;  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:0;  mso-generic-font-family:auto;  mso-font-pitch:variable;  mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin-top:0in;  margin-right:0in;  margin-bottom:10.0pt;  margin-left:0in;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-ascii-font-family:Cambria;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Cambria;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Cambria;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.25in 1.0in 1.25in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt;&lt;/style&gt;      &lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;If you want my business, you better make it fast&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Self-service&lt;/b&gt;: 7x24 add, remove, change resources, workloads, and connectivity&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Elastic&lt;/b&gt;: scale up or down automatically within the limits I set&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Available&lt;/b&gt;: stand up to hurricanes, DDOS, and replication storms. Your mistakes should never be my problem.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;If you want my data, you better make it secure&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Auditing&lt;/b&gt;: network and management&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Network&lt;/i&gt; – I need to audit and or inspect all the traffic between my systems. This includes but is not limited to traffic between users, systems, and applications even where they share the same physical host and virtual switch.&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Management&lt;/i&gt; – I need to see all management events that may impact the security or configuration of my systems. This includes but is not limited to privileged access to my systems or data through the hypervisor or cloud management APIs.&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Control&lt;/b&gt;: policy and assurance&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Policy &lt;/i&gt;– I need to express and apply security policies via a method that is both human understandable and translatable into a machine-interpreted language.&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Assurance &lt;/i&gt;– I need to know when an event or incident occurs that violates a policy and I need a method for testing that controls exist and are effective for enforcing my policies.&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Metrics&lt;/b&gt;: continuous and interoperable&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Continuous &lt;/i&gt;– Per our agreed standards of measurement I must be able to quantify the security attributes of my system. This may include but is not limited to measurements for: vulnerability, configuration, performance, incident detection, incident response, and incident containment.&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: 1.0in;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Interoperable &lt;/i&gt;– All security relevant data and events must be available in a documented machine-readable format. It should either comply with standards such as Cyberscope and SCAP or my preferred GR&amp;amp;C system.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;If you want my money, you better not ask for much&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Value &lt;/b&gt;– Not just cheaper than if I do it myself. Your services should give my organization new capabilities to meet our objectives. These capabilities could include user experience, logistic support, and accessibility …&lt;/div&gt;&lt;div class="MsoNormal" style="margin-left: .5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;No lock-in &lt;/b&gt;– I should be able to easily move my data and workloads back inside my enterprise or to one of your competitors.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-6705428086878995488?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=GAKtRUR02jQ:zWujUv04PiU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=GAKtRUR02jQ:zWujUv04PiU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=GAKtRUR02jQ:zWujUv04PiU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=GAKtRUR02jQ:zWujUv04PiU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=GAKtRUR02jQ:zWujUv04PiU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=GAKtRUR02jQ:zWujUv04PiU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/GAKtRUR02jQ/ill-tell-you-what-i-want-what-i-really.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>1</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2012/01/ill-tell-you-what-i-want-what-i-really.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-1570568694158414260</guid><pubDate>Fri, 20 Jan 2012 04:54:00 +0000</pubDate><atom:updated>2012-01-19T20:57:43.138-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>Tell me again where these devices are made?</title><description>&lt;span style="font-family:Calibri, Verdana, Helvetica, Arial;"&gt;&lt;span style="font-size:11pt"&gt;I’ve been “upgrading” my home infrastructure:&lt;br /&gt;&lt;br /&gt;Seagate GoFlex Network Storage&lt;br /&gt;Netgear WNDR3800&lt;br /&gt;(other stuff)&lt;br /&gt;&lt;br /&gt;All my toys run linux, so imagine my surprise when this starts showing in my logs:&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:Helvetica, Verdana, Arial;"&gt;&lt;span style="font-size:9pt"&gt;[LAN access from remote] from 210.51.17.227:40986 to 192.168.35.119:22, Thursday, January 19,2012 16:56:47&lt;br /&gt;[LAN access from remote] from 210.51.17.227:39316 to 192.168.35.119:22, Thursday, January 19,2012 16:56:36&lt;br /&gt;[LAN access from remote] from 210.51.17.227:37023 to 192.168.35.119:22, Thursday, January 19,2012 16:56:32&lt;br /&gt;[LAN access from remote] from 210.51.17.227:34192 to 192.168.35.119:22, Thursday, January 19,2012 16:56:28&lt;br /&gt;[LAN access from remote] from 210.51.17.227:50809 to 192.168.35.119:22, Thursday, January 19,2012 16:56:21&lt;br /&gt;[LAN access from remote] from 210.51.17.227:47558 to 192.168.35.119:22, Thursday, January 19,2012 16:56:16&lt;br /&gt;[LAN access from remote] from 210.51.17.227:44530 to 192.168.35.119:22, Thursday, January 19,2012 16:56:11&lt;br /&gt;[LAN access from remote] from 210.51.17.227:42159 to 192.168.35.119:22, Thursday, January 19,2012 16:56:07&lt;br /&gt;[LAN access from remote] from 210.51.17.227:39236 to 192.168.35.119:22, Thursday, January 19,2012 16:56:02&lt;br /&gt;(repeat about 500 times)&lt;br /&gt;&lt;br /&gt;whois 210.51.17.227?&lt;br /&gt;Answer someone inside a /16 registered to Beijing Tongtai IDC of China Netcom.&lt;br /&gt;&lt;br /&gt;Turns out my Seagate device was advertising port 22 via upnp and my Netgear was helpfully port mapping it to the Internet.&lt;br /&gt;&lt;br /&gt;Go figure.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-1570568694158414260?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=yJdiaCLGb_Y:W5BK9hwHDdw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=yJdiaCLGb_Y:W5BK9hwHDdw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=yJdiaCLGb_Y:W5BK9hwHDdw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=yJdiaCLGb_Y:W5BK9hwHDdw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=yJdiaCLGb_Y:W5BK9hwHDdw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=yJdiaCLGb_Y:W5BK9hwHDdw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/yJdiaCLGb_Y/tell-me-again-where-these-devices-are.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2012/01/tell-me-again-where-these-devices-are.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-5921276200548947282</guid><pubDate>Sat, 02 Apr 2011 15:03:00 +0000</pubDate><atom:updated>2011-04-02T10:04:12.561-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Web Security</category><title>SQL Injection and Cross-Site Scripting (XSS) are Hot</title><description>Custom and automated attacks against web sites continue as vendors and developers still have not gotten the hang of secure coding techniques.&lt;br /&gt;&lt;br /&gt;In one &lt;a href="http://www.thetechherald.com/article.php/201113/6994/SQL-Injection-attack-jumps-to-more-than-600-000-domains"&gt;case&lt;/a&gt;, an automated attack has infected more than 600,000 sites in about two days.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.pcworld.com/businesscenter/article/223457/mysql_website_falls_victim_to_sql_injection_attack.html"&gt;other&lt;/a&gt;, was a case of a targeted attack against MySQL. Interestingly, the attackers are taking credit for this exploit.&lt;br /&gt;&lt;br /&gt;Broad automated attacks like the first are usually driven by botnot groups who are ultimately seeking to compromise a large number of end-user systems.&lt;br /&gt;&lt;br /&gt;The second attack is becoming less common.  My guess, is that they are seeking to establish credibility for their attack skills and to demonstrate their ability to launch a 0-day hack. This sort of activity ranges from the somewhat benign: the hacker equivalent of resume fodder, or more malignantly: demonstrating value before selling their exploits to the criminal underground.&lt;br /&gt;&lt;br /&gt;While defects will always exist, it is clear that web site providers still fail to perform the security basics: vetting code before deployment and monitoring their site for compromise.&lt;br /&gt;&lt;br /&gt;(updated)&lt;br /&gt;Current infection counts can be found (for a few of  the domains hosting the malicious scripts) with Google:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.google.com/#q=%22%3Cscript%20src%3Dhttp%3A%2F%2Flizamoon.com%2Fur.php%22"&gt;Lizamoon&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.google.com/webhp?hl=en#q=%22%3Cscript%20src%3Dhttp%3A%2F%2Falisa-carter.com%2Fur.php%22"&gt;Alisa-carter&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.google.com/search?source=aig&amp;amp;hl=en&amp;amp;rlz=&amp;amp;=&amp;amp;q=%22%3Cscript+src%3Dhttp%3A%22+%22alexblane.com%2Fur.php%22"&gt;Alexblane&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-5921276200548947282?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=zH_VWdsDLNo:omt7GqFwQHA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=zH_VWdsDLNo:omt7GqFwQHA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=zH_VWdsDLNo:omt7GqFwQHA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=zH_VWdsDLNo:omt7GqFwQHA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=zH_VWdsDLNo:omt7GqFwQHA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=zH_VWdsDLNo:omt7GqFwQHA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/zH_VWdsDLNo/sql-injection-and-cross-site-scripting.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2011/04/sql-injection-and-cross-site-scripting.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-7723850245217666448</guid><pubDate>Wed, 22 Sep 2010 13:34:00 +0000</pubDate><atom:updated>2010-09-22T06:43:37.105-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virtualization security</category><title>HyperSentry</title><description>&lt;span&gt;&lt;span style="font-size: 12pt;"&gt;&lt;a href="http://darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=227500269"&gt;HyperSentry&lt;/a&gt; is a technology that uses IPMI to allow an out-of-band method for checking hypervisor integrity.&lt;br /&gt;&lt;br /&gt;IPMI is a backdoor to the system, so it is something that has to be managed carefully.   When I did pen-testing I often found that it was not secured properly. That said, it is a very interesting idea.&lt;br /&gt;&lt;br /&gt;I think the hardware "root-of-trust" technology: that has been developed by AMD and &lt;a href="http://www.intel.com/technology/security/"&gt;Intel&lt;/a&gt; is also interesting&lt;br /&gt;&lt;br /&gt;I think we will see availability of tools, including &lt;a href="http://www.catbird.com"&gt;Catbird&lt;/a&gt;, where a combination of these technologies is built-in to the system.  I do have to point out that IPMI based checks have been possible for years and yet no one has touted them as a solution for detecting conventional rootkits.  I've learned that anything with "IBM" in the release has a certain amount of FUD factor and it may be a year or longer before we see a real capability that can be built into a product.&lt;br /&gt;&lt;br /&gt;Perhaps the broader implication is that work like this is common on open-source hypervisors and is much harder to perform on proprietary systems.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-7723850245217666448?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=PP5FsCT81wk:cpzlZ_NGZ7o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=PP5FsCT81wk:cpzlZ_NGZ7o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=PP5FsCT81wk:cpzlZ_NGZ7o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=PP5FsCT81wk:cpzlZ_NGZ7o:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=PP5FsCT81wk:cpzlZ_NGZ7o:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=PP5FsCT81wk:cpzlZ_NGZ7o:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/PP5FsCT81wk/hypersentry.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>1</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/09/hypersentry.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-3441854402424568007</guid><pubDate>Thu, 02 Sep 2010 15:39:00 +0000</pubDate><atom:updated>2010-09-02T08:45:48.846-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">business</category><title>VA cloud outage</title><description>&lt;blockquote&gt; &lt;span style="font-size:85%;"&gt;--Virginia Gov't Agencies Suffer Massive Outage&lt;br /&gt;(August 27 &amp;amp; 30, 2010)&lt;br /&gt;A storage area network (SAN) memory card failure at the Virginia&lt;br /&gt;Information Technologies Agency (VITA) left at least two dozen agencies&lt;br /&gt;without the ability to conduct business.  Among the affected agencies&lt;br /&gt;are the Department of Motor Vehicles, which was unable to issue driver's&lt;br /&gt;licenses, and the Department of Social Services, which was unable to&lt;br /&gt;distribute benefits.  The data center where the failure occurred is run&lt;br /&gt;by Northrop Grumman.&lt;br /&gt;&lt;br /&gt;[Editor's Note (Northcutt): The state of Virginia was an early adopter&lt;br /&gt;of blades and virtualization. The advantages and economics are obvious.&lt;br /&gt;These outages may prove to be a cautionary tale. With virtualization,&lt;br /&gt;you end up with a lot of eggs concentrated in a fairly small basket so&lt;br /&gt;that if your continuity of operations plans fail, you go down pretty&lt;br /&gt;hard.&lt;br /&gt;&lt;br /&gt;(Schultz): This is a perfect example of what can go wrong when cloud&lt;br /&gt;services fail. People in general neither recognize the real risk nor&lt;br /&gt;plan for loss of availability in cloud services.]&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Wow, they were not running dual HBAs into the SAN?  Can't be.&lt;br /&gt;&lt;br /&gt;Outage report from VA is here: http://www.vita.virginia.gov/about/default.aspx?id=12596&lt;br /&gt;&lt;br /&gt;I am not sure the SANS editor comments are warranted.  This may be related to an architectural error in the deployment of the EMC DMX 3 and its backup.&lt;br /&gt;&lt;br /&gt;The DMX is an SMP-based HA system with a petabyte of capacity.  The comment about too many eggs in one basket is accurate with respect to the State of Virginia's use of a monster SAN, but not so much as per use of virtualization.&lt;br /&gt;&lt;br /&gt;The real failure here is whether or not they tested their COOP capability ... ever.  Then we have to ask when was the last time they ran a DR test because their time to recover seems a little long as well.&lt;br /&gt;&lt;br /&gt;My failure analysis: over reliance on a vendor's claim that their hardware never fails.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-3441854402424568007?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=UN_CSnwLtt8:mOsispZhQJk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=UN_CSnwLtt8:mOsispZhQJk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=UN_CSnwLtt8:mOsispZhQJk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=UN_CSnwLtt8:mOsispZhQJk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=UN_CSnwLtt8:mOsispZhQJk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=UN_CSnwLtt8:mOsispZhQJk:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/UN_CSnwLtt8/va-cloud-outage.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/09/va-cloud-outage.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-2219896060337104336</guid><pubDate>Sat, 28 Aug 2010 14:23:00 +0000</pubDate><atom:updated>2010-08-28T07:40:35.532-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">patches</category><category domain="http://www.blogger.com/atom/ns#">Internet Security</category><title>Web site reputation</title><description>Recently several companies have developed features or products to make web surfing more secure.  One of these technologies uses reputation.  Reputation is a measure of trust for a web site or web page.  In this case trust is typically measured by how much SPAM, malicious traffic, or attacks a site is known to generate.  It turns out that measuring these things is not that hard because a majority of web traffic flows through a relatively small number of gateways and backbone networks.&lt;br /&gt;&lt;br /&gt;This is a very good idea.  If a web site is known to host malware or send a lot of SPAM, then block or warn users before they visit a site.   Of course, cyber-criminals have started to figure out how to bypass these checks.  They simply attack sites with good reputations and get them to host the malware.  In some cases, it's just a matter of providing an advertisement.&lt;br /&gt;&lt;br /&gt;Reputation based security is still a great idea because it forces the crooks to work harder.  However, we can't get over confident and rely on this technique to always protect us.  This means keep your software patched, don't click on suspicious links, and ignore any offer that is to good to be true.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-2219896060337104336?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=SMwB5NTeo0Y:dXdzyZYbp9w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=SMwB5NTeo0Y:dXdzyZYbp9w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=SMwB5NTeo0Y:dXdzyZYbp9w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=SMwB5NTeo0Y:dXdzyZYbp9w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=SMwB5NTeo0Y:dXdzyZYbp9w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=SMwB5NTeo0Y:dXdzyZYbp9w:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/SMwB5NTeo0Y/web-site-reputation.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/08/web-site-reputation.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-6291992994271355987</guid><pubDate>Tue, 24 Aug 2010 13:41:00 +0000</pubDate><atom:updated>2010-08-24T06:43:28.178-07:00</atom:updated><title>Alert FOX News!</title><description>So, I got this funny SPAM email, and I thought someone will take this seriously and alert FOX news to yet another massive government intrusion into our lives... ;-)&lt;br /&gt;&lt;br /&gt;By the way the SPAM came with a ZIP file that will probably p&lt;span style="font-family: courier new;"&gt;0&lt;/span&gt;wn your computer if you install it...&lt;br /&gt;&lt;br /&gt;------ Begin Message&lt;br /&gt;From: Alfreda Robertson&lt;br /&gt;Date: Tue, 24 Aug 2010 16:04:07 +0200&lt;br /&gt;To: &lt;xxx-x-xxxx-x@catbird.com&gt;&lt;br /&gt;Subject: IRS Notification - For Tax Payer xxx-x-xxxx-x@catbird.com&lt;br /&gt;&lt;br /&gt;Dear Tax Payer,&lt;br /&gt;&lt;br /&gt;As part of new requirements from the IRS, all U.S. Citizens are required by law to update their computers with new tax software.&lt;br /&gt;&lt;br /&gt;To begin the update, install the attached file&lt;br /&gt;&lt;br /&gt;After doing so, no further action is required on your part.&lt;br /&gt;&lt;br /&gt;Thank you for your cooperation.&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;IRS Agent #175&lt;br /&gt;Alfreda Robertson&lt;br /&gt;&lt;br /&gt;------ End of Message&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-6291992994271355987?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=31N7rqFfWro:ZxwLNPo7xqA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=31N7rqFfWro:ZxwLNPo7xqA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=31N7rqFfWro:ZxwLNPo7xqA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=31N7rqFfWro:ZxwLNPo7xqA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=31N7rqFfWro:ZxwLNPo7xqA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=31N7rqFfWro:ZxwLNPo7xqA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/31N7rqFfWro/alert-fox-news.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/08/alert-fox-news.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-4219032093980484025</guid><pubDate>Fri, 02 Jul 2010 18:11:00 +0000</pubDate><atom:updated>2010-07-02T11:15:53.755-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">patches</category><title>Always a good idea to keep your BIOS up to date....</title><description>&lt;!--StartFragment--&gt;&lt;span style="font-family:Calibri,Verdana,Helvetica,Arial;"&gt;&lt;span style="font-size:11pt;"&gt;&lt;span style="font-weight: bold;"&gt;Looks like Sony has learned from Dell’s leaky capacitor debacle.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-family:Helvetica,Verdana,Arial;"&gt;&lt;span style="font-size:9pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:9pt;"&gt;&lt;span style="font-family:Times New Roman Bold;"&gt;Sony says 535,000 laptops at risk of&lt;br /&gt;overheating. &lt;/span&gt;&lt;span style="font-family:Times New Roman;"&gt;More than half a million Sony laptops sold this year contain a software&lt;br /&gt;bug that could lead them to overheat, the company said June 30. Sony has recorded 39&lt;br /&gt;cases of overheating among Vaio F and C series laptops that have been on sale since&lt;br /&gt;January. In some cases, the overheating has led the laptop case to deform. A bug in the&lt;br /&gt;heat-management system of the BIOS software is to blame. Sony is asking users to&lt;br /&gt;either update the software themselves or return their laptops so it can apply the update.&lt;br /&gt;The fault affects 535,000 computers, although Sony is asking a total of 646,000 owners&lt;br /&gt;to update their machines. The additional 111,000 machines are susceptible to several&lt;br /&gt;less serious problems that have also been found in the software, said Sony. BIOS is&lt;br /&gt;present in every PC and runs below the operating system, controlling the most basic&lt;br /&gt;functions of the computer and interaction between major components. It is usually&lt;br /&gt;invisible to users except for a BIOS start-up message that is typically seen when a PC&lt;br /&gt;boots. The problem affects machines sold both in Japan and the rest of the world.&lt;br /&gt;Affected models sold outside Japan are the VPCCW25FG/B, VPCCW25FG/P and&lt;br /&gt;VPCCW25FG/W.&lt;br /&gt;&lt;br /&gt;Source: Computerworld&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:Calibri,Verdana,Helvetica,Arial;"&gt;&lt;span style="font-size:11pt;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-4219032093980484025?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=ybJgyBfUt3w:Rv44OeyJSfw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=ybJgyBfUt3w:Rv44OeyJSfw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=ybJgyBfUt3w:Rv44OeyJSfw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=ybJgyBfUt3w:Rv44OeyJSfw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=ybJgyBfUt3w:Rv44OeyJSfw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=ybJgyBfUt3w:Rv44OeyJSfw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/ybJgyBfUt3w/always-good-idea-to-keep-your-bios-up.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/07/always-good-idea-to-keep-your-bios-up.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-8071753685966060594</guid><pubDate>Wed, 17 Mar 2010 13:08:00 +0000</pubDate><atom:updated>2010-03-17T06:31:48.849-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Internet Security</category><title>Are Open Source Applications More Secure?</title><description>Full Disclosure: I am a long time Firefox user&lt;br /&gt;&lt;br /&gt;Recently, there have been serious security advisories for Chrome, Safari, and Internet Explorer:&lt;br /&gt;&lt;blockquote&gt;http://www.eweek.com/c/a/Security/IE-Attacks-Circulate-as-Microsoft-&lt;br /&gt;Updates-Advisory-766154/&lt;br /&gt;http://www.v3.co.uk/v3/news/2259391/apple-updates-safari-browser &lt;/blockquote&gt;&lt;br /&gt;While a patch is now available for Safari (and perhaps Chrome), the community is still waiting on a fix from Microsoft.&lt;br /&gt;&lt;br /&gt;Browsers, and Internet Explorer in particular, are the most commonly used application in the world.  Additionally, most web users visit one of the &lt;a href="http://www.alexa.com/topsites"&gt;top 500 sites&lt;/a&gt; at least once a day.  This intersection makes for a very attractive target for criminals.  At any given moment, the site you are visiting, even the site you are using to read this post, could be attacking you through your browser and trying to seed your system with malware.&lt;br /&gt;&lt;br /&gt;Your first line of defense is a secure browser.  I can't &lt;a href="http://en.wikipedia.org/wiki/Open_source_software_security"&gt;prove this easily&lt;/a&gt;, but I think an open-source browser like &lt;a href="http://www.mozilla.com/firefox"&gt;Firefox&lt;/a&gt; will always be more secure than a proprietary browser.&lt;br /&gt;&lt;br /&gt;My advice:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Keep your browser up to date, note ie8 is not exposed by this current vulnerability&lt;/li&gt;&lt;li&gt;Keep your OS up to date&lt;/li&gt;&lt;li&gt;Run some sort of host-based intrusion protection system, if you have one of the consumer security suites you have this&lt;/li&gt;&lt;li&gt;Run at least a basic network firewall&lt;/li&gt;&lt;li&gt;Businesses should run a network intrusion protection system&lt;/li&gt;&lt;/ol&gt;For the really advanced users out there:&lt;br /&gt;&lt;br /&gt;Make use of virtualization software and run a special purpose virtual machine for your banking and financial applications, run another virtual machine for casual web browsing and entertainment.  Never ever browse the web using your host system.&lt;br /&gt;&lt;br /&gt;One last piece of advice:&lt;br /&gt;&lt;br /&gt;Don't forget to wear some green today!&lt;br /&gt;&lt;br /&gt;Michael&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-8071753685966060594?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=6pvyakYKq9M:xwqXJtmdrxo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=6pvyakYKq9M:xwqXJtmdrxo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=6pvyakYKq9M:xwqXJtmdrxo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=6pvyakYKq9M:xwqXJtmdrxo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=6pvyakYKq9M:xwqXJtmdrxo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=6pvyakYKq9M:xwqXJtmdrxo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/6pvyakYKq9M/are-open-source-applications-more.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>2</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/03/are-open-source-applications-more.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-6288549187799007103</guid><pubDate>Tue, 16 Mar 2010 14:05:00 +0000</pubDate><atom:updated>2010-03-16T07:16:07.491-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>Imagine a World where passwords were useless</title><description>Recently, in the press:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;March 12, The Register&lt;/span&gt; – (International) &lt;a href="source:%20http://www.theregister.co.uk/2010/03/12/password_cracking_on_crack/"&gt;SSD tools crack passwords 100 times&lt;br /&gt;faster.&lt;/a&gt; Password-cracking tools optimised to work with SSDs have achieved speeds up to 100 times quicker than previously possible. After optimizing its rainbow tables of password hashes to make use of SSDs Swiss security firm Objectif Securite was able to crack 14-digit WinXP passwords with special characters in just 5.3 seconds. Objectif Securite spokesman told Heise Security that the result was 100 times faster than possible with their old 8GB Rainbow Tables for XP hashes. The exercise illustrated that the speed of hard discs rather than processor speeds was the main bottleneck in password cracking based on password hash lookups. Objectif’s test rig featured an ageing Athlon 64 X2 4400+ with an SSD and optimised tables containing 80GB of password hashes. The system supports a brute force attack of 300 billion passwords per second, and is claimed to be 500 times faster than a password cracker from Russian firm Elcomsoft that takes advantages of the number crunching prowess of a graphics GPU from NVIDIA. &lt;/blockquote&gt;(By the way, SSD stands for &lt;a href="http://en.wikipedia.org/wiki/Solid-state_drive"&gt;Solid-State Drive&lt;/a&gt; -- a faster way to store data)&lt;br /&gt;&lt;br /&gt;An SSD is much faster than a hard drive but orders of magnitude slower than fast RAM, so if these folks ran the same test with the &lt;a href="http://en.wikipedia.org/wiki/Rainbow_tables"&gt;Rainbow Tables&lt;/a&gt; in local RAM they'd be cracking the same passwords in 0.0053 seconds (unless this moved the performance bottleneck to the CPU).&lt;br /&gt;&lt;br /&gt;If you want a solution, I recommend something like &lt;a href="http://www.myonelogin.com/?ref=tricipher_home"&gt;this&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-6288549187799007103?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=I7Jy7HrTUZw:yISIga-wbeU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=I7Jy7HrTUZw:yISIga-wbeU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=I7Jy7HrTUZw:yISIga-wbeU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=I7Jy7HrTUZw:yISIga-wbeU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=I7Jy7HrTUZw:yISIga-wbeU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=I7Jy7HrTUZw:yISIga-wbeU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/I7Jy7HrTUZw/imagine-world-where-passwords-were.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/03/imagine-world-where-passwords-were.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-8208135770945433930</guid><pubDate>Thu, 25 Feb 2010 15:44:00 +0000</pubDate><atom:updated>2010-02-25T08:50:29.823-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>Sometimes your already in the cloud</title><description>&lt;h1 style="margin-bottom: 10px;"&gt;&lt;span style="font-size:130%;"&gt;Federal Trade Commission links wide  data breach to file sharing&lt;/span&gt;&lt;/h1&gt;&lt;blockquote&gt;The Federal Trade Commission (FTC) said Monday that it has uncovered  widespread data breaches at companies, schools and local governments  whose employees are swapping music, software and movie files over the  Internet.&lt;br /&gt;&lt;br /&gt;http://www.washingtonpost.com/wp-dyn/content/article/2010/02/22/AR2010022204889.html?hpid=sec-tech&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Peer-to-Peer (P2P) file sharing was perhaps the second &lt;a href="http://en.wikipedia.org/wiki/Killer_application"&gt;killer app&lt;/a&gt; for the Internet (after Mosaic) because of its ease of use and utility for sharing free music and porn.&lt;br /&gt;&lt;br /&gt;P2P is very easy to use, after installing the application select the files you want to share,  then  start browsing and downloading files from other users.  P2P networks are comprised of millions&lt;br /&gt;and often tens of millions of users -- making these applications the largest compute and storage networks in the world.&lt;br /&gt;&lt;br /&gt;There are two big risks with P2P:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Oversharing -- incorrectly configuring the P2P application to share all of your files&lt;/li&gt;&lt;li&gt;Compromise -- P2P is often leveraged to download malware to unsuspecting users&lt;/li&gt;&lt;/ol&gt;The FTC warning described in the Post article arises from the problem of oversharing.  For business, the problem arises because the more P2P users you have, the more likely that one or more of them are sharing confidential information -- without realizing it.&lt;br /&gt;&lt;br /&gt;Assuring the secure configuration of P2P file sharing across more than a handful of users is very, very difficult.  For a large enterprise infeasible.  In an enterprise of any size, security depends on the detection of P2P and either on blocking all use or limiting use to selected systems that are subject to stringent access and configuration controls.&lt;br /&gt;&lt;br /&gt;Don't be fooled into thinking that your firewalls protect you from this threat.  Most P2P applications have been designed to bypass firewalls.  P2P detection and control requires the deployment of effective Intrusion Detection (IDS) or Intrusion Protection (IPS) systems.&lt;br /&gt;&lt;br /&gt;IPS systems will give you the capability of discriminating between types of P2P applications, selecting a response, and protecting your data.&lt;br /&gt;&lt;br /&gt;Michael&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-8208135770945433930?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=G7aTxqQwx4A:KXMdg2gJ688:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=G7aTxqQwx4A:KXMdg2gJ688:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=G7aTxqQwx4A:KXMdg2gJ688:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=G7aTxqQwx4A:KXMdg2gJ688:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=G7aTxqQwx4A:KXMdg2gJ688:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=G7aTxqQwx4A:KXMdg2gJ688:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/G7aTxqQwx4A/sometimes-your-already-in-cloud.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/02/sometimes-your-already-in-cloud.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-4259958324300557977</guid><pubDate>Wed, 24 Feb 2010 17:58:00 +0000</pubDate><atom:updated>2010-02-24T10:55:57.218-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>You Should Use Profiling</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.headlineshirts.net/media/catalog/product/cache/3/image/5e06319eda06f020e43594a9c230972d/p/a/packages_wht_il_258.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 258px; height: 297px;" src="http://www.headlineshirts.net/media/catalog/product/cache/3/image/5e06319eda06f020e43594a9c230972d/p/a/packages_wht_il_258.jpg" alt="" border="0" /&gt;&lt;/a&gt;Thanks to &lt;a href="http://www.headlineshirts.net/suspicious-packages.html"&gt;Headline T-shirts&lt;/a&gt; for this amusing image.&lt;br /&gt;&lt;br /&gt;Torn from the headline, "&lt;a href="http://www.computerworld.com/s/article/9159258/Chinese_school_linked_to_Google_attacks_also_linked_to_01_attacks_on_White_House_site"&gt;Chinese school linked to Google&lt;br /&gt;attacks also linked to ‘01 attacks on White House site.&lt;/a&gt;" Comes the thought that only idiots fail to profile threats.&lt;br /&gt;&lt;br /&gt;For network security this is a simple matter:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Know your services and&lt;/li&gt;&lt;li&gt;Know your users&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The first item requires that you self-check with port scans, vulnerability scans, and traffic analysis to understand your networked application and your potential vulnerabilities.  You should always plan that there will be defects you do not know about -- these are called zero-day attacks.  Always patch everything you can and what you can't patch will require even more protection.  Between zero-day worries and the things you can't patch, you'll need intrusion detection and prevention.&lt;br /&gt;&lt;br /&gt;The second item should be incorporated in your site user statistics and operation's processes.  This means understanding on a statistical and individual basis who, where, and how your users access your network applications.  Once you have a grasp of these behaviors it becomes very simple to develop two key profiles: one that describes how authorized users behave, and second, the converse -- how unauthorized users behave.  For example, an Austin Texas based music store will typically have many local customers and a few other customers from around Texas or perhaps more remote places like Nashville, New York, or Los Angeles.  Once you have the geographic profile of your customers it becomes very useful to think about places you don't have customers.  Places like South Korea, China, Eastern Europe, and Brazil; by extension everywhere except North America.  Obviously, the same store in Shanghai will have a different customer profile. &lt;br /&gt;&lt;br /&gt;Now comes the important part.&lt;br /&gt;&lt;br /&gt;USE THE PROFILE.&lt;br /&gt;&lt;br /&gt;If folks from Lilliput never visit your site, treat their traffic with care, blocking it is best, but if you can't bring yourself to block them then at least redirect Lilliputian visitors to an "interest" form, gather some marketing information and put them on a white list.  Now, that's for people from Lilliput visiting you, even less likely is authorized traffic from your network going to Lilliput (and really Lilliput is just a place holder for real threat countries: China for example.)  IDS and IPS exist for a reason, so do firewalls, make sure you are filtering, blocking, or at least detecting traffic to specific countries and regions of the world you are not doing business with.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-4259958324300557977?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=kiu3WBr2CO0:28WQ6UvO4Q4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=kiu3WBr2CO0:28WQ6UvO4Q4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=kiu3WBr2CO0:28WQ6UvO4Q4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=kiu3WBr2CO0:28WQ6UvO4Q4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=kiu3WBr2CO0:28WQ6UvO4Q4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=kiu3WBr2CO0:28WQ6UvO4Q4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/kiu3WBr2CO0/you-should-use-profiling.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/02/you-should-use-profiling.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-2945095286039652371</guid><pubDate>Fri, 22 Jan 2010 15:20:00 +0000</pubDate><atom:updated>2010-01-22T07:21:23.274-08:00</atom:updated><title>The Cloud is Attacking You</title><description>&lt;p&gt;Collected from US-CERT and other sources:&lt;/p&gt; &lt;p&gt;Microsoft has released out-of-band Security Bulletin MS10-002&lt;br /&gt;(&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-002.mspx" title="http://www.microsoft.com/technet/security/bulletin/MS10-002.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/MS10-002.mspx&lt;/a&gt;) to resolve seven privately reported vulnerabilities and one publicly disclosed vulnerability. This update includes resolution for a recently, reported zero-day vulnerability in Internet Explorer (IE) which is detailed in Microsoft Security Advisory 979352. (&lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" title="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;http://www.microsoft.com/technet/security/advisory/979352.mspx&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;This vulnerability may have been used in the recent attacks on Google and other organizations. Knowledge of this attack is now widely known and the broader criminal community is now leveraging this exploit.&lt;/p&gt; &lt;p&gt;Organizations should review Microsoft Security Bulletin MS10-002 and apply the patches as soon as possible. US-CERT recommends that the patches be tested within your organization enterprise first and then deployed in an expedited manor. In addition to patching, the recommendations below may be leveraged to better position your organization to withstand future serious vulnerabilities. &lt;/p&gt; &lt;p&gt;Enable Data Execution Prevention (DEP) both in software and hardware if supported (see Microsoft KB 912923). This may provide future vulnerability resiliency. (&lt;a href="http://support.microsoft.com/kb/912923" title="http://support.microsoft.com/kb/912923"&gt;http://support.microsoft.com/kb/912923&lt;/a&gt;)&lt;/p&gt; &lt;p&gt;Be proactive by defining internal servers that should generally be trusted that can be placed in Internet Explorer’s "Trusted Sites" list. By doing so, this may ease the impact to your organization should a future reactive measure be required to set the "Internet Zone" to a "High" security setting. (See Microsoft KB 174360 -- &lt;a href="http://support.microsoft.com/kb/174360" title="http://support.microsoft.com/kb/174360"&gt;http://support.microsoft.com/kb/174360&lt;/a&gt;)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-2945095286039652371?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=W-nmdos5iE8:wDoeoKoiJdo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=W-nmdos5iE8:wDoeoKoiJdo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=W-nmdos5iE8:wDoeoKoiJdo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=W-nmdos5iE8:wDoeoKoiJdo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=W-nmdos5iE8:wDoeoKoiJdo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=W-nmdos5iE8:wDoeoKoiJdo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/W-nmdos5iE8/cloud-is-attacking-you.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2010/01/cloud-is-attacking-you.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-5683524676920406638</guid><pubDate>Mon, 21 Dec 2009 18:32:00 +0000</pubDate><atom:updated>2009-12-21T10:34:48.528-08:00</atom:updated><title>PCI compliance in the cloud (Part B)</title><description>First published &lt;a href="http://www.cloudslamevent.com/cloud-pci-and-virtual-firewalls-part-b"&gt;here&lt;/a&gt; on 12/14/2009:&lt;br /&gt;&lt;br /&gt;In &lt;a href="http://www.cloudslamevent.com/making-cloud-pci-ready-one-step-time-part"&gt;Part A&lt;/a&gt;, I discussed the functional requirements for a virtual firewall.  Now let's take a look at the technologies required to make this work.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Traffic segmentation&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Firewalls segment traffic.  That's obvious, but think about this in the cloud.  For this to work, there must be a method to assure that all traffic to/from a tenant is available for inspection and the application of access controls by the firewall.  This means the virtualization host must support at least one of the following:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Routing traffic to/from a tenant system through the virtual firewall at the network layer, this is how "bump-in-the-wire" devices work.  This is a poor solution in virtual environments.&lt;br /&gt;&lt;li&gt;Routing traffic to/from a tenant system through the virtual firewall at the hypervisor layer.  This is a more efficient technique because it reduces latency and the number of CPU cycles needed to inspect packets.&lt;br /&gt;&lt;li&gt;Other novel techniques enabled by virtualization -- &lt;i&gt;Magic.&lt;/i&gt;  I call this "Magic" because it is now possible to create intelligence around which packets need to be inspected or filtered by the firewall.&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Configuration management&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Virtual firewalls must include configuration management capabilities.  Why?  Because it is much easier to reconfigure ports and networks in the virtual environment, or even configure a virtual machine to bridge networks.  This is a tricky situation in the cloud because this capability requires visibility and integration into the cloud provider’s management framework.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Dynamic policy enforcement&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Virtual machines migrate.  This requires policy enforcement capabilities that are independent of location and layer 2 and 3 connectivity.  Segmentation and access controls must transparently follow virtual machines as they migrate or are copied between virtualization hosts, data centers, or cloud providers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Cloud management&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Unless cloud providers wish to assume all of the responsibility for correct configuration of their customer's virtual firewalls, the provider must give their customers control of the firewall policies while at the same time preventing one customer from inappropriately blocking traffic to another customer.&lt;br /&gt;&lt;br /&gt;Can anyone name a cloud provider who makes this all possible?&lt;br /&gt;&lt;br /&gt;Michael&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.catbid.com"&gt;Catbird&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-5683524676920406638?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=mcqi461w42s:JoDRMZsJT9U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=mcqi461w42s:JoDRMZsJT9U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=mcqi461w42s:JoDRMZsJT9U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=mcqi461w42s:JoDRMZsJT9U:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=mcqi461w42s:JoDRMZsJT9U:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=mcqi461w42s:JoDRMZsJT9U:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/mcqi461w42s/pci-compliance-in-cloud-part-b.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/12/pci-compliance-in-cloud-part-b.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-247211911996367104</guid><pubDate>Mon, 21 Dec 2009 18:29:00 +0000</pubDate><atom:updated>2009-12-21T10:31:59.676-08:00</atom:updated><title>PCI compliance in the cloud (Part A)</title><description>First posted &lt;a href="https://www.cloudslamevent.com/making-cloud-pci-ready-one-step-time-part"&gt;here&lt;/a&gt; on 12/07/2009:&lt;br /&gt;&lt;br /&gt;The new cloud (or if you prefer hosted computing services, or IAAS) rests on top of virtualization.  If we’re going to take the cloud seriously, it will have to be compliant.  One of the more stringent compliance frameworks is PCI DSS.  Let’s look at requirement one and start building a solution for the cloud.&lt;br /&gt;&lt;br /&gt;PCI DSS 1.2.1, test procedure 1.1: Obtain and inspect the firewall and router configuration standards and other documentation specified below to verify that standards are complete.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Deploying virtual firewalls is insufficient, as the virtual firewall must share the support structure with the virtual machines, virtual switches, and hypervisor.  Technical controls must also be deployed to validate the configuration of a virtual firewall and to detect and alert if tampering occurs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Physical firewalls are insufficient unless every virtual machine is on a unique VLAN, VLAN hopping is mitigated, and all traffic must flow through the physical firewall.  Further, virtual machine mobility must be constrained and virtual machines must be subjected to the same firewall policy regardless of physical location or layer 2 connectivity.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;While sufficient, the physical solution may be impractical due to the constraints it places on deployment, consolidation, and high availability.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The optimal solution will be one that allows deployment of a best practice virtualization architecture for security, integrity, and availability, which also maximizes consolidation and the virtualization return on investment.&lt;br /&gt;This requires a virtualized firewall deployment with the following characteristics:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Assurance of integrity for the security management framework&lt;br /&gt;&lt;li&gt;Enforcement of separation of duties for server, network, and security operations&lt;br /&gt;&lt;li&gt;Enforcement of least privilege&lt;br /&gt;&lt;li&gt;Dynamic network segmentation that is independent of location, IP address, or layer 2 connectivity&lt;br /&gt;&lt;li&gt;Integrated auditing and configuration management for virtualization layers&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If that sounds like more than a firewall, you’re right.&lt;br /&gt;&lt;br /&gt;Michael&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-247211911996367104?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=gv3NCZeDql4:NzndHtdwrC0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=gv3NCZeDql4:NzndHtdwrC0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=gv3NCZeDql4:NzndHtdwrC0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=gv3NCZeDql4:NzndHtdwrC0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=gv3NCZeDql4:NzndHtdwrC0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=gv3NCZeDql4:NzndHtdwrC0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/gv3NCZeDql4/pci-compliance-in-cloud-part.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/12/pci-compliance-in-cloud-part.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-1986021862969113637</guid><pubDate>Thu, 13 Aug 2009 13:59:00 +0000</pubDate><atom:updated>2009-08-13T07:16:04.554-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">defense in depth</category><category domain="http://www.blogger.com/atom/ns#">9/11</category><title>Missing Russian Ship</title><description>Right out of a Tom Clancy &lt;a href="http://en.wikipedia.org/wiki/Sum_of_all_fears"&gt;novel&lt;/a&gt;, a 4,000 tonne cargo ship is missing.  Reportedly, this ship had nothing worth hijacking.  There are not a lot of facts about this available but there are some interesting bits:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;10 armed men boarded the ship about a week before it disappeared.  They left 12 hours later.&lt;/li&gt;&lt;li&gt;The ship spent two weeks in &lt;a href="http://en.wikipedia.org/wiki/Kaliningrad"&gt;Kaliningrad&lt;/a&gt; before beginning its voyage.&lt;/li&gt;&lt;li&gt;The Russians are searching for  the ship with all available resources.&lt;/li&gt;&lt;/ol&gt;As reported &lt;a href="http://www.encyclopedia.com/doc/1P2-8639619.html"&gt;here&lt;/a&gt;, the Russians have battlefield nuclear weapons in Kaliningrad.&lt;br /&gt;&lt;br /&gt;I wish the Russians good luck in their search and I hope the NATO forces provide all available resources to assist.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-1986021862969113637?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Gs8PocccTQw:S8tTlm6BCWA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Gs8PocccTQw:S8tTlm6BCWA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=Gs8PocccTQw:S8tTlm6BCWA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Gs8PocccTQw:S8tTlm6BCWA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=Gs8PocccTQw:S8tTlm6BCWA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Gs8PocccTQw:S8tTlm6BCWA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/Gs8PocccTQw/missing-russian-ship.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/08/missing-russian-ship.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-6032618850053678368</guid><pubDate>Fri, 24 Apr 2009 03:45:00 +0000</pubDate><atom:updated>2009-04-23T20:48:59.755-07:00</atom:updated><title>Data Protection for Virtualized Servers</title><description>I am recording a webcast live next Wednesday.  It's free and only requires a short pre-registration.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.brighttalk.com/webcasts/3762/attend"&gt;Data Protection for Virtualized Servers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="330" width="353"&gt;  &lt;param name="movie" value="http://www.brighttalk.com/dc/swf/dotcom_base.swf?212"&gt; &lt;/param&gt; &lt;param name="flashvars" value="channelid=286&amp;commid=2744&amp;autoStart=FALSE"&gt; &lt;/param&gt; &lt;embed src="http://www.brighttalk.com/dc/swf/dotcom_base.swf?234" type="application/x-shockwave-flash" width="353" height="330" wmode="transparent" flashvars="channelid=286&amp;commid=2744&amp;autoStart=FALSE"&gt; &lt;/embed&gt; &lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-6032618850053678368?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=S2NHlwqwFSk:-6cIMQ2cfvs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=S2NHlwqwFSk:-6cIMQ2cfvs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=S2NHlwqwFSk:-6cIMQ2cfvs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=S2NHlwqwFSk:-6cIMQ2cfvs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=S2NHlwqwFSk:-6cIMQ2cfvs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=S2NHlwqwFSk:-6cIMQ2cfvs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/S2NHlwqwFSk/data-protection-for-virtualized-servers.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/04/data-protection-for-virtualized-servers.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-8703151861581861943</guid><pubDate>Fri, 10 Apr 2009 14:05:00 +0000</pubDate><atom:updated>2009-04-10T07:26:39.123-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>How many manhole covers are in San Jose, CA?</title><description>&lt;a href="http://www.mercurynews.com/ci_12106300?source=most_viewed"&gt;From the Mercury News&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;John Britton, a spokesman for AT&amp;amp;T, said it appears somebody opened a manhole in South San Jose, climbed down eight to 10 feet and cut four or five fiber-optic cables.  Britton also said there was a report of underground cables being cut in San Carlos.&lt;br /&gt;AT&amp;amp;T's contract with the Communication Workers of America expired at 11:59 p.m. Saturday, but Britton said "we have a really good relationship with the union" and that negotiations continue between the two sides.&lt;/blockquote&gt;It's my understanding that a single cut in one location would not cause the outage we recently experienced.  There would need to be two or more cuts at strategic locations to cause an outage to cell phone, land line, and emergency services.&lt;br /&gt;&lt;br /&gt;Knowing which manhole covers to open would require very specific knowledge of the Bay Area fiber infrastructure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-8703151861581861943?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=8ipR7QtIIo4:0fDe3zCoj6Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=8ipR7QtIIo4:0fDe3zCoj6Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=8ipR7QtIIo4:0fDe3zCoj6Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=8ipR7QtIIo4:0fDe3zCoj6Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=8ipR7QtIIo4:0fDe3zCoj6Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=8ipR7QtIIo4:0fDe3zCoj6Q:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/8ipR7QtIIo4/how-many-manhole-covers-are-in-san-jose.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/04/how-many-manhole-covers-are-in-san-jose.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-2143446808421673859</guid><pubDate>Tue, 31 Mar 2009 19:56:00 +0000</pubDate><atom:updated>2009-03-31T16:11:22.673-07:00</atom:updated><title>Securing the Dynamic Data Center</title><description>I am recording a webcast live today.  It's free and only requires a short pre-registration.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.brighttalk.com/webcasts/3430/attend"&gt;Securing the Dynamic Data Center&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="353" height="330"&gt; &lt;param name="movie" value="http://www.brighttalk.com/dc/swf/dotcom_base.swf?212"&gt; &lt;/param&gt; &lt;param name="flashvars" value="channelid=679&amp;commid=2504&amp;autoStart=FALSE"&gt; &lt;/param&gt; &lt;embed src="http://www.brighttalk.com/dc/swf/dotcom_base.swf?234" type="application/x-shockwave-flash" width="353" height="330" wmode="transparent" flashvars="channelid=679&amp;commid=2504&amp;autoStart=FALSE"&gt; &lt;/embed&gt; &lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-2143446808421673859?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=0tg2XIu_AJU:iBo6q9LUwKE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=0tg2XIu_AJU:iBo6q9LUwKE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=0tg2XIu_AJU:iBo6q9LUwKE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=0tg2XIu_AJU:iBo6q9LUwKE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=0tg2XIu_AJU:iBo6q9LUwKE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=0tg2XIu_AJU:iBo6q9LUwKE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/0tg2XIu_AJU/securing-dynamic-data-center.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/03/securing-dynamic-data-center.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-2912540240012786060</guid><pubDate>Tue, 31 Mar 2009 04:13:00 +0000</pubDate><atom:updated>2009-03-30T21:16:35.915-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Internet Security</category><title>Conficker and April 1</title><description>Well, here’s the Wikipedia entries that got me thinking:&lt;br /&gt;&lt;blockquote&gt; As a countermeasure, ICANN and several TLD registrars began in February 2009 a coordinated barring of transfers and registrations for these domains”&lt;br /&gt;&lt;br /&gt;Variant C contains code to sidestep these countermeasures by generating an expanded daily list of 50000 domains across 110 TLDs. This new pull mechanism, however, is disabled until April 1&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;I’ve also been following the work at SRI regarding this threat.&lt;br /&gt;&lt;br /&gt;Even 1 million Variant C infections results in potentially 50 billion whois queries.&lt;br /&gt;&lt;br /&gt;I think Wednesday is going to be a slow day on the Internet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-2912540240012786060?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=lfnwtgtf5EQ:rAjbDTceswQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=lfnwtgtf5EQ:rAjbDTceswQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=lfnwtgtf5EQ:rAjbDTceswQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=lfnwtgtf5EQ:rAjbDTceswQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=lfnwtgtf5EQ:rAjbDTceswQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=lfnwtgtf5EQ:rAjbDTceswQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/lfnwtgtf5EQ/conficker-and-april-1.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/03/conficker-and-april-1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-2727489858495950725</guid><pubDate>Wed, 04 Feb 2009 04:37:00 +0000</pubDate><atom:updated>2009-02-03T20:45:58.787-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virtualization security</category><category domain="http://www.blogger.com/atom/ns#">trust zones</category><category domain="http://www.blogger.com/atom/ns#">Network Security</category><title>Heartland Breach</title><description>&lt;span style="font-size:130%;"&gt;Summary:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Level 1 credit card processor fails to prevent data loss effecting hundreds of millions of transactions. &lt;/li&gt;&lt;li&gt;Attacker installed tools on Heartland server, inside the PCI trust path network &lt;/li&gt;&lt;li&gt;Tools “sniffed” transactions and sent data to system(s) outside North America&lt;/li&gt;&lt;/ul&gt;&lt;blockquote&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=333222&amp;amp;intsrc=news_ts_head"&gt;“Heartland has said intruders broke into its systems sometime last year and planted malware that they used to steal the card data. The number of compromised cards still isn't known. But Heartland processes more than 100 million transactions per month.”&lt;br /&gt;- Banks, customers feel the fallout of the Heartland breach. 2/2/2009. Jalkumar Vijayan, Computer World, Security. &lt;/a&gt;&lt;/blockquote&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;Breach analysis:&lt;/span&gt;&lt;br /&gt;Root cause includes but is not limited to the following:&lt;ul&gt;&lt;li&gt;Failure of host based intrusion prevention system (HIPS) &lt;/li&gt;&lt;li&gt;Failure of network based intrusion prevention systems (IDP) &lt;/li&gt;&lt;li&gt;Failure of configuration management, to detect changes to host and network configuration &lt;/li&gt;&lt;li&gt;Failure of separation of duties and detection of abuse or escalation of privilege &lt;/li&gt;&lt;li&gt;Failure to segment the processor network and enforce a zone of trust&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;In summary, Heartland failed to properly implement and enforce defense-in-depth, network segmentation and separation of duties. Remember, Heartland is a level 1 PCI processor and was required by regulation to get this right.  This means Heartland's auditors failed.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;Solution:&lt;/span&gt;&lt;br /&gt;Catbird directly addresses all of the above, except for HIPS.  HIPS requires an agent on every end-point, this is not a component of our architecture, which is agent-less by design.  Our customers are able to implement and enforce defense-in-depth using Catbird TrustZones™ security policies, virtual infrastructure configuration management and virtual machine tracking technologies.  These technologies include but are not limited to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Policy and detection templates for IDP, to monitor and control network flows between zones and intra-machine flows inside a trust zone &lt;/li&gt;&lt;li&gt;Policy based configuration monitoring and enforcement using session blocking and quarantine, including quarantine of virtual machines &lt;/li&gt;&lt;li&gt;Monitoring of virtual administrator activities and enforcement of dual controls for virtual machine connection to network zones&lt;/li&gt;&lt;li&gt;Catbird TrustZones monitor and enforce network segmentation within and between machines on any network, VLAN or port group&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;In summary, proper deployment of Catbird TrustZones technology would have detected and prevented a data breach like the one that occurred at Heartland.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-2727489858495950725?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=MtyhQi6m5Wk:kP-VK-yAo70:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=MtyhQi6m5Wk:kP-VK-yAo70:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=MtyhQi6m5Wk:kP-VK-yAo70:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=MtyhQi6m5Wk:kP-VK-yAo70:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=MtyhQi6m5Wk:kP-VK-yAo70:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=MtyhQi6m5Wk:kP-VK-yAo70:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/MtyhQi6m5Wk/heartland-breach.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2009/02/heartland-breach.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-7074738675879953080</guid><pubDate>Fri, 12 Dec 2008 19:09:00 +0000</pubDate><atom:updated>2008-12-12T11:52:29.931-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virtualization security</category><title>Guardians?  What Guardians?</title><description>Yesterday, the &lt;a href="http://www.nytimes.com/"&gt;New York Times&lt;/a&gt; covered the recent arrest of &lt;a href="http://www.nytimes.com/2008/12/12/business/12scheme.html?em=&amp;amp;pagewanted=all"&gt;Bernard L. Madoff.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Madoff, a prominent Wall Street Hedge fund manager, has admitted to running a $50 Billion Ponzi scheme.&lt;br /&gt;&lt;br /&gt;While law enforcement has been quick to react, the revelation came when Mr. Madoff confessed to an associate.  While rival Hedge fund managers had been suspicious that Madoff's results were too good to be true, &lt;span style="font-weight: bold;"&gt;THE REGULATORS HAD NO CLUE&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Years ago, there were many warnings on and off the Hill.  Regulators, economists and many others sounded the alarm that allowing an entire financial industry to exist without regulations was a bad idea.  However, the standard responses were: regulations are bad, the market will police itself, we can trust our Hedge fund managers.  Well, look at what has happened.  AIG failed to accurately assess and hedge their risks.  Dozens of financial institutions have gone under and hundreds more are at risk.  Hedge fund managers have admitted to running a crooked game.&lt;br /&gt;&lt;br /&gt;The lesson is clear, &lt;span style="font-weight: bold;"&gt;systems and the people who work within them are not self-policing&lt;/span&gt;.  Shocker.  I am sure &lt;a href="http://en.wikipedia.org/wiki/Niccol%C3%83%C2%B2_Machiavelli"&gt;Machiavelli&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Juvenal"&gt;Juvenalis&lt;/a&gt; are laughing at the continuing naivete of the human race.&lt;br /&gt;&lt;br /&gt;Now, right now, we have a very similar pattern emerging in information technology.  Institutions around the world are virtualizing like crazy.   IT is deploying the vast majority of these virtual infrastructures without any of the protections I recommend &lt;a href="http://grok-security.blogspot.com/2008/11/risk-mitigation-for-virtual.html"&gt;here&lt;/a&gt;.  PCI, HIPAA, SOX, you name it, these IT Groups are putting sensitive data about you and me, valuable data worth billions of dollars is at risk.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Where are the Guardians?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Guardians are out to lunch, they missed the memo, they drank the Kool-aid from the platform vendors.&lt;br /&gt;&lt;br /&gt;People like myself, &lt;a href="http://rationalsecurity.typepad.com/"&gt;Chris Hoff&lt;/a&gt;, &lt;a href="http://gregness.wordpress.com/"&gt;Greg Ness&lt;/a&gt;, &lt;a href="http://www.usenix.org/events/nsdi08/tech/pratt.pdf"&gt;Ian Pratt&lt;/a&gt;, &lt;a href="http://www.blackhat.com/presentations/bh-usa-07/Baker/Presentation/BH07_Baker_WSV_Hypervisor_Security.pdf"&gt;Brandon Baker&lt;/a&gt; and many others are sounding the alarm.&lt;br /&gt;&lt;br /&gt;It's time for the Guardians to get to work.  It's time for the IT security team to get off their butts and start addressing this issue.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.catbird.com/"&gt;Michael&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-7074738675879953080?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Y-cvFKvTYvY:jVKH8jA9iZ0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Y-cvFKvTYvY:jVKH8jA9iZ0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=Y-cvFKvTYvY:jVKH8jA9iZ0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Y-cvFKvTYvY:jVKH8jA9iZ0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=Y-cvFKvTYvY:jVKH8jA9iZ0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=Y-cvFKvTYvY:jVKH8jA9iZ0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/Y-cvFKvTYvY/guardians-what-guardians.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>1</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2008/12/guardians-what-guardians.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-968722795408899035.post-7543061502259078334</guid><pubDate>Tue, 09 Dec 2008 18:16:00 +0000</pubDate><atom:updated>2008-12-09T10:37:35.140-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Web Security</category><category domain="http://www.blogger.com/atom/ns#">pharming</category><category domain="http://www.blogger.com/atom/ns#">Internet Security</category><title>Registrar's are still a weak link</title><description>Very nice article on the hack against &lt;a href="http://www.checkfree.com"&gt;Check Free&lt;/a&gt; &lt;a href="http://voices.washingtonpost.com/securityfix/2008/12/digging_deeper_into_the_checkf.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Current theories center on the likelihood that a Check Free employee got suckered by a phishing or straight-up social engineering attack.&lt;br /&gt;&lt;br /&gt;I'm going to hazard a guess that this was a spear-phish or more targeted form of attack.  A quick search of Linkedin, Facebook and other social networking applications finds a treasure trove of CheckFree/Fiserv employees.&lt;br /&gt;&lt;br /&gt;It's a small step to go from these links to a targeted attack against Fiserv IT staff.&lt;br /&gt;&lt;br /&gt;However, as the article notes Fiserv was not the only target in this attack and Financial Institutions (FI) are dangerously reliant on a single registrar.&lt;br /&gt;&lt;br /&gt;My recommendations:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;FI's and others must monitor and protect themselves from domain hijack -- I recommend &lt;a href="http://www.catbird.com/our_services/pharming_shield_s.shtml"&gt;Pharming Shield&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Get social networking applications out of the data center, IT personnel must not use corporate resources (including email) to access these sites&lt;/li&gt;&lt;li&gt;The Financial Industry is at risk from a single-point of failure at Network Solutions.  This must be addressed through community efforts and directly by the platform providers.&lt;/li&gt;&lt;/ol&gt;Happy Holidays!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/968722795408899035-7543061502259078334?l=grok-security.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=i39_Z1KBseU:1J5VuOWKduA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=i39_Z1KBseU:1J5VuOWKduA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=i39_Z1KBseU:1J5VuOWKduA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=i39_Z1KBseU:1J5VuOWKduA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?i=i39_Z1KBseU:1J5VuOWKduA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Grok-Security?a=i39_Z1KBseU:1J5VuOWKduA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Grok-Security?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://feedproxy.google.com/~r/Grok-Security/~3/i39_Z1KBseU/registrars-are-still-weak-link.html</link><author>noreply@blogger.com (Michael Berman)</author><thr:total>0</thr:total><feedburner:origLink>http://grok-security.blogspot.com/2008/12/registrars-are-still-weak-link.html</feedburner:origLink></item></channel></rss>

