<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Infosec Events</title>
	
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Wed, 10 Mar 2010 04:37:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InfosecEvents" /><feedburner:info uri="infosecevents" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>InfosecEvents</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>RSA Conference 2010 – Wrap Up</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/ERAFOmvxvIs/</link>
		<comments>http://infosecevents.net/2010/03/09/rsa-conference-2010-wrap-up/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 04:37:16 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=875</guid>
		<description><![CDATA[The RSA Conference in San Francisco, CA just concluded and it was overflowing with the latest security information, insights and news. There&#8217;s been a lot of buzz about this security event and we&#8217;ve compiled a few of those links for you.
Studies and research

NSS Labs Study on social attack aversion &#8211; NSS Labs released its latest [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.rsaconference.com/2010/usa/index.htm">RSA Conference</a> in San Francisco, CA just concluded and it was overflowing with the latest security information, insights and news. There&#8217;s been a lot of buzz about this security event and we&#8217;ve compiled a few of those links for you.</p>
<p>Studies and research</p>
<ul>
<li><a href="http://nsslabs.com/test-reports/NSSLabs_Q12010_GTRBrowserSEM_FINAL.pdf">NSS Labs Study on social attack aversion</a> &#8211; NSS Labs released its latest study on how well web browsers avoid social engineering attacks.</li>
<li><a href="http://www.veracode.com/reports/index.html">Veracode&#8217;s State of Application Security</a> &#8211; Around 58 percent of the applications tested by application security testing service provider Veracode in the past year-and-a-half failed to achieve a successful rating in their first round of testing.</li>
<li><a href="http://news.cnet.com/8301-27080_3-10463240-245.html?tag=mncol;txt">McAfee on intellectual property risks</a> &#8211; McAfee analyzed a commonly used software for housing intellectual property called Perforce and released its findings during a session at the RSA security conference.</li>
<li>
<div><a href="http://www.informit.com/articles/article.aspx?p=1569495">Fifteen Common Activities from BSIMM2</a> - In addition to highlighting the fifteen most common BSIMM activities, the article also provides the 30 firm data for all 110 activities in public for the first time.</div>
</li>
</ul>
<p>Presentations and sessions</p>
<ul>
<li><span style="font-size: 13.1944px;"><a href="http://holisticinfosec.blogspot.com/2010/03/rsa-visualizing-zeus-attack-against.html">Visualizing the Zeus attack against government and military</a> &#8211; This presentation will focus on specific tools and methodology to aid you in establishing security data visualization practices in your environment.</span></li>
<li><span style="font-size: 13.1944px;"><a href="http://threatpost.com/en_us/blogs/experts-expect-several-ciphers-be-cracked-soon-030210">Cryptographers Panel</a> &#8211; Adi Shamir said that he is working with a team of researchers who have put together a paper that describes an attack that will break AES 128 within 10 rounds.</span></li>
<li><span style="font-size: 13.1944px;"><a href="http://threatpost.com/en_us/blogs/rsa-2010-cryptographers-discuss-wisdom-foolishness-030310">Wisdom of &#8216;Foolishness&#8217;</a> &#8211; A panel of leading cryptographers reveal some of the lessons they have learned while making seemingly imprudent decisions.</span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://www.tripwire.com/blog/security/rsa-2010-pre-debate-on-proving-the-worth-of-security-metrics-with-real-world-data/">Pre-debate on ‘Proving the Worth of Security Metrics with Real-World Data’</a> &#8211; A warm up session between the panelists who are up to discuss the value of security measurements.</span></span></li>
</ul>
<p>Some announcements and news from the conference floor</p>
<ul>
<li><a href="http://news.cnet.com/8301-27080_3-10464161-245.html?tag=mncol;txt">Symantec exhibit makes cybercrime tangible</a> &#8211; The security company gave tours of its Black Market at the RSA security conference here this week.</li>
<li><a href="http://news.cnet.com/8301-13578_3-10463665-38.html?tag=mncol;txt">DHS to extend Einstein technology to private sector</a> &#8211; The White House did confirm this week that the latest version, called Einstein 3, involves attempting to thwart in-progress cyberattacks by sharing information with the National Security Agency.</li>
<li><a href="http://www.theregister.co.uk/2010/03/02/microsoft_charney_rsa/">Microsoft wants to put infected PCs in rubber room</a> &#8211; Charney is the latest to champion the idea that infected PC users should be put in their own rubber room, so the malware, spam, and other attacks they generate can&#8217;t harm others.</li>
<li><a href="http://news.cnet.com/8301-13578_3-10462563-38.html?tag=mncol;txt">White House outlines secret cybersecurity plan</a> &#8211; Howard Schmidt gives a talk during a town hall meeting on how the nation will face impending attacks on the cyberspace front</li>
</ul>
<p>Interviews (link redirect to MP3 podcasts)</p>
<ul>
<li><a href="http://www.tripwire.com/blog/security/rsa-2010-why-do-organizations-respond-so-poorly-to-audits/">Jennifer Bayuk</a> &#8211; She says that audits do not break down, it&#8217;s the response to it that fails.</li>
<li><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-VoltageSecurity.mp3">Mark Bower, Voltage Security</a> &#8211; The director from Voltage Security speaks about E2EE, how it will affect merchants and what we might be seeing in the future from Voltage SecureData Payments POS SDK.</li>
<li><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ICSALab.mp3">Andy Hayter, ICSA Labs</a> &#8211; This interview with ICSA Labs discusses about anti-virus testing, education of consumers and a new initiative to use the testing ICSA does in the real world.</li>
<li><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-PandaSecurity.mp3">Pedro Bustamante, Panda Security</a> &#8211; A senior analyst at Panda Security explains<span style="font-size: 13.1944px;"> his company&#8217;s cloud AV product and USB vaccine.</span></li>
<li><a href="http://news.cnet.com/8301-27080_3-10462649-245.html?tag=mncol;txt">Scott Charney, Microsoft</a> &#8211;  A post-talk Q&amp;A with the VP of Trustworthy Computing at Microsoft about quarantining of infected computers away from the Internet.</li>
<li><a href="http://www.tripwire.com/blog/security/rsa-2010-if-youre-going-for-pci-compliance-just-shut-up-and-log/">Anton Chuvakin, &#8220;Security Warrior&#8221;</a> &#8211; Anton Chuvakin talks about PCI compliance and log management.</li>
<li><a href="http://www.tripwire.com/blog/security/rsa-2010-how-do-you-secure-14000-virtual-machines-on-15-servers/">Edward Haletky, Anton Chuvakin</a> &#8211; Edward Haletky chats with Anton Chuvakin about the benefits of virtualization and the issues it faces.</li>
<li><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-AstaroSecurity.mp3">Jan Hichert, Astaro Internet Security</a> &#8211; The CEO of Astaro shares their new security products and how they are using it in social media environments.</li>
<li><a href="http://www.tripwire.com/blog/security/rsa-2010-chris-hoff-on-the-state-of-data-in-a-virtualized-environment/">Chris Hoff, Cisco</a> &#8211; Chris Hoff explains  a bit on cloud computing and virtualization.</li>
<li><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-FSecure.mp3">Mikko Hypponen, F-Secure</a> &#8211; The chief research officer of F-Secure converses about malware and how it is evolving to new platforms.</li>
<li><span style="font-size: 13.1944px;"><a href="http://www.tripwire.com/blog/security/rsa-2010-start-thinking-about-security-beyond-just-compliance/">Jonathan Penn, Forrester</a> &#8211; Jonathan Penn of Forrester discusses compliance and why it isn&#8217;t equal to security.</span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-Sourcefire.mp3">Marty Roesch, Sourcefire</a> &#8211; Roesch talks on the security existential crisis, Immunet and virtual appliances.</span></span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://www.tripwire.com/blog/security/if-you-dont-look-at-your-log-data-how-are-you-going-to-catch-data-breaches/">Bob Russo, PCI Security Standards Council</a> &#8211; Bob Russo, general manager of PCI Security Standards Council, stresses the importance of looking at your security logs and not just turning them on.</span></span></span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-KasperskyLab.mp3">Roel Schouwenberg, Kaspersky Lab</a> &#8211; A conversation with the senior AV researcher of Kaspersky on APT, signature-based APT and other topics.</span></span></span></span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://media.libsyn.com/media/mckeay/NSP-RSAC2010-ISC2.mp3">Hord Tipton, (ISC)2</a> &#8211; The executive director of International Information Systems Security Certification Consortium expounds on the Safe &amp; Secure Online program and other topics.</span></span></span></span></span></li>
<li><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><span style="font-size: 13.1944px;"><a href="http://www.tripwire.com/blog/security/rsa-2010-where-is-your-software-most-vulnerable/">Jacob West, Jeremiah Grossman</a> &#8211; Two security experts share what they see as the most common vulnerabilities out there and the incentives of the ones who exploit them.</span></span></span></span></span></span></li>
</ul>
<p>Software downloads</p>
<ul>
<li><a href="http://securityblog.verizonbusiness.com/2010/02/19/veris-framework/">VerIS Framework</a> &#8211; Verizon released its framework for analyzing forensics data to help give organizations a better look into their data breaches.</li>
<li><a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=211201140">Playbook</a> &#8211; Matasano offers a virtual appliance that scans for any firewall rules that are outdated, redundant, or could potentially expose a network to security threats.</li>
<li><a href="http://www.microsoft.com/forefront/identitymanager/en/us/default.aspx">Forefront Identity Manager 2010</a> &#8211; Microsoft released its new identity management software, a system corporations can use to manage employees and others within an organization.</li>
</ul>
<p>Finally, here is the <a href="http://www.flickr.com/photos/rsaconference">official photo set</a> from the conference and the <a href="http://www.rsaconference.com/2010/usa/recordings/keynote-catalog.htm">compilation of video and audio</a> from the keynote presentations. Watch out for RSA Europe coming this October.</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=875&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/k0G6shMfu-8eUvTJGByCqMhJ6Rw/0/da"><img src="http://feedads.g.doubleclick.net/~a/k0G6shMfu-8eUvTJGByCqMhJ6Rw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/k0G6shMfu-8eUvTJGByCqMhJ6Rw/1/da"><img src="http://feedads.g.doubleclick.net/~a/k0G6shMfu-8eUvTJGByCqMhJ6Rw/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/ERAFOmvxvIs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/03/09/rsa-conference-2010-wrap-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/03/09/rsa-conference-2010-wrap-up/</feedburner:origLink></item>
		<item>
		<title>ShmooCon 2010 Session Videos Now Available</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/3cC03_8aCI4/</link>
		<comments>http://infosecevents.net/2010/03/09/shmoocon-2010-session-videos-now-available/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 04:36:29 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=880</guid>
		<description><![CDATA[Some of you have been waiting for this and here it is, finally! The official site for ShmooCon just post the slides and video of the various sessions. Here are a few picks from this bunch. Each video file is about 100mb. Happy downloading!

Becoming Jack Flack: Real Life Cloak &#38; Dagger
A talk about how to [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you have been waiting for this and here it is, finally! The official site for ShmooCon just post the <a href="http://shmoocon.org/presentations-all.html">slides and video</a> of the various sessions. Here are a few picks from this bunch. Each video file is about 100mb. Happy downloading!</p>
<ul>
<li><strong>Becoming Jack Flack: Real Life Cloak &amp; Dagger<br />
<span style="font-weight: normal; font-size: 13.1944px;">A talk about how to keep your anonymity in a world that gets more and more connected each day. <a href="http://shmoocon.org/2010/slides/jackflack.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/JackFlack-Banks.m4v">M4V</a></span></strong></li>
<li><strong><span style="font-weight: normal;"><a href="http://shmoocon.org/2010/videos/JackFlack-Banks.m4v"></a><span style="font-size: 13.1944px;"><strong> </strong>
<div><strong>An Existential Threat To Security As We Know It?<br />
<span style="font-weight: normal;">This discussion centers on PCI, compliance and the existential threat to information security. <a href="http://shmoocon.org/2010/slides/PCI.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/PCI-Panel.flv">FLV</a></span></strong></div>
<p><strong> </strong></p>
<p></span></span></strong></li>
<li><strong><span style="font-weight: normal;"><span style="font-size: 13.1944px;"><strong> </strong>
<div>
<li><strong>Flying Instruments-Only: Legal and Privacy Issues in Cloud Computing<br />
<span style="font-weight: normal;">Here, Richard Goldberg reveals some big issues people will face as we move data to the cloud as well as what measures can be taken to protect this data. <a href="http://shmoocon.org/2010/videos/CloudComputing-Goldberg.m4v">M4V</a></span></strong></li>
<li><strong>Exposed | More: Attacking the Extended Web<br />
<span style="font-weight: normal;">Some insights are revealed on how APIs of some websites are being exploited and what measures can be taken to reduce this risk while keeping them open for access. <a href="http://shmoocon.org/2010/slides/exposedmore.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/ExtendedWeb-Hamiel.m4v">M4V</a></span></strong></li>
<li><strong><strong>The New World of Smartphone Security &#8211; What Your iPhone Disclosed About You<br />
<span style="font-weight: normal;">This talk examines mobile to mobile attacks within cellular IP networks, the iPhone attack surface, iPhone worms, iPhone location-based gaming privacy concerns, and iPhone web application security. <a href="http://shmoocon.org/2010/slides/smartphone.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/Smartphone-Hawthorn.m4v">M4V</a></span></strong></strong></li>
<p><strong><strong> </strong></strong></p>
<p><strong><strong> </strong></strong></p>
<li><strong><strong>The Friendly Traitor: Our Software Wants to Kill Us<br />
<span style="font-weight: normal;">This session explores the usage of browser hooks, client provided content and malicious flash applications in attacking client machines and organizations. <a href="http://shmoocon.org/2010/slides/friendlytraitor.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/FriendlyTraitor-Johnson.m4v">M4V</a></span></strong></strong></li>
<li><strong><strong>Back to the Glass House<br />
<span style="font-weight: normal;">A presentation of how virtualization technologies could be deployed to counter hacking attacks and an update on the current status of an on-going pilot deployment of these technologies with a large organization&#8217;s desktop environment. <a href="http://shmoocon.org/2010/slides/2010_glasshouse.zip">PDF</a> | <a href="http://shmoocon.org/2010/videos/GlassHouse-Manley.m4v">M4V</a></span></strong></strong></li>
<li><strong><strong>Pulling the Plug: Security Risks in the Next Generation of Offline Web Applications<br />
<span style="font-weight: normal;">As the offline and online world begin to merge, new attacks shift from being temporal to persistent, giving the attacker almost an infinite array of resources to accomplish his goal. This talk breaks down the risks involved in offline technologies as well as some real-life examples. </span> <span style="font-weight: normal;"><a href="http://shmoocon.org/2010/videos/OfflineWeb-Sutton.m4v">M4V</a></span></strong></strong></li>
<p><strong><strong> </strong></strong></p>
</div>
<p><strong> </strong></p>
<p></span></span></strong></li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=880&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/SToBMfD85slVUwwmHlljlRZuJSQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/SToBMfD85slVUwwmHlljlRZuJSQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/SToBMfD85slVUwwmHlljlRZuJSQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/SToBMfD85slVUwwmHlljlRZuJSQ/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/3cC03_8aCI4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/03/09/shmoocon-2010-session-videos-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/03/09/shmoocon-2010-session-videos-now-available/</feedburner:origLink></item>
		<item>
		<title>Week 9 in Review – 2010</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/l1d53KbWaB8/</link>
		<comments>http://infosecevents.net/2010/03/09/week-9-in-review/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 07:05:47 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=870</guid>
		<description><![CDATA[



Events Related:

ShmooCon 2010 Presentations &#8211; shmoocon.org
Slides and video from sessions during the DC conference.
Some posts related to the RSA Conference

RSA 2010 Coverage &#8211; novainfosecportal.com
Videos from RSA Conference 2010 &#8211; rsa.com


Some BSides SF posts

BSidesSanFrancisco Official Site &#8211; securitybsides.org
BsidesSF Videos &#8211; ustream.com




Resources:

Verizon Incident Metrics Framework Released &#8211; verizonbusiness.com
Our goal is to be able to create data sets [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.shmoocon.org/presentations.html">ShmooCon 2010 Presentations</a> &#8211; shmoocon.org<br />
Slides and video from sessions during the DC conference.</li>
<li>Some posts related to the RSA Conference
<ul>
<li><a href="http://www.novainfosecportal.com/2010/03/04/rsa-2010-coverage/">RSA 2010 Coverage</a> &#8211; novainfosecportal.com</li>
<li><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1602">Videos from RSA Conference 2010</a> &#8211; rsa.com</li>
</ul>
</li>
<li>Some BSides SF posts
<ul>
<li><a href="http://www.securitybsides.org/BSidesSanFrancisco">BSidesSanFrancisco Official Site</a> &#8211; securitybsides.org</li>
<li><span style="font-size: 13.1944px"><a href="http://www.ustream.tv/user/richardebaker/videos">BsidesSF Videos</a></span><span style="font-size: 13.1944px"> &#8211; ustream.com</span></li>
</ul>
</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://securityblog.verizonbusiness.com/2010/02/19/veris-framework-2/">Verizon Incident Metrics Framework Released</a> &#8211; verizonbusiness.com<br />
Our goal is to be able to create data sets that can be used and compared because of their commonality.</li>
<li><a href="http://blog.cenzic.com/public/item/251943">Web Application Security Trends Report</a> &#8211; cenzic.com<br />
The report incorporates findings from Cenzic’s leading-edge managed security assessment (SaaS) and research from Cenzic Intelligent Analysis (CIA) Labs.</li>
<li><a href="http://www.ethicalhacker.net/content/view/299/24/">Final Course and Exam Review: Pen Testing with BackTrack</a> &#8211; ethicalhacker.net<br />
The Pentesting with BackTrack course was originally released as Offensive Security 101 and consists of 3 separate training segments.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.mavensecurity.com/dojo.php">Web Security Dojo</a> &#8211; mavensecurity.com<br />
A free open-source self-contained training environment for Web Application Security penetration testing.</li>
<li><a href="http://code.google.com/p/webraider/">WebRaider v0.2.3.8</a> &#8211; code.google.com/p/webraider<br />
WebRaider focuses on getting a shell from multiple targets or injection point.</li>
<li><a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=223100907">Product Watch: Free Tool Cleans Up &#8216;Rusty,&#8217; Unsafe Firewall Settings</a> &#8211; darkreading.com<br />
Matasano Security rolls out open-source product that cleans up and checks firewall configurations for security holes.</li>
<li><a href="http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1147">HPING3 Cheatsheet</a> &#8211; professionalsecuritytesters.org<br />
Also, some examples are enclosed in order to approach special requests with this awesome tool.</li>
<li><a href="http://skypher.com/index.php/2010/03/04/aspsh-a-remote-shell-written-in-asp/">ASPsh – A remote shell written in ASP.</a> &#8211; skypher.com<br />
The goal of this project was to create an ASP page that can be used on a server to provide a “command line shell”-like experience.</li>
<li><span style="font-size: 13.1944px"><a href="http://skypher.com/index.php/2010/03/01/internet-exploiter-2-dep/">Internet Exploiter 2 – bypassing DEP</a> &#8211; skypher.com<br />
I am releasing this because I feel it helps explain why ASLR+DEP are not a mitigation to put a lot of faith in.</span></li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.didierstevens.com/2010/03/01/quickpost-networkmashup-xls/">Quickpost: NetworkMashup.xls</a> &#8211; didierstevens.com<br />
NetworkMashup.xls is a spreadsheet with VBA macros to execute pings and name/address resolution from within Excel with WIN32 API calls.</li>
<li><span style="font-size: 13.1944px"><a href="http://silverstr.ufies.org/blog/archives/001081.html">Announcing Elevation of Privilege: The Threat Modeling Game</a> &#8211; silverstr.ufies.org<br />
If you have a team that is new to the whole process of threat modeling, you will want to check it out. </span></li>
<li><a href="http://threatpost.com/en_us/blogs/experts-expect-several-ciphers-be-cracked-soon-030210">RSA 2010: Experts Expect Several Ciphers to Be Cracked Soon</a> &#8211; threatpost.com<br />
Cryptographers are expecting several of the major cryptographic systems in use today to be broken in the near future.</li>
<li><a href="http://threatpost.com/en_us/blogs/rsa-2010-cryptographers-discuss-wisdom-foolishness-030310">RSA 2010: Cryptographers Discuss Wisdom of &#8216;Foolishness&#8217;</a> &#8211; threatpost.com<br />
By going against the grain, new objectives can be made and boundaries overcome.</li>
<li>Top 25 Series Posts<br />
A discussion of the top 25 security vulnerabilities</p>
<ul>
<li><a href="http://blogs.sans.org/appsecstreetfighter/2010/03/01/top-25-series-rank-2-sql-injection/">Top 25 Series – Rank 2 – SQL Injection</a> &#8211; sans.org</li>
<li><a href="http://blogs.sans.org/appsecstreetfighter/2010/03/02/top-25-series-%E2%80%93-rank-3-%E2%80%93-classic-buffer-overflow/">Top 25 Series – Rank 3 – Classic Buffer Overflow</a> &#8211; sans.org</li>
<li><a href="http://blogs.sans.org/appsecstreetfighter/2010/03/03/top-25-series-%E2%80%93-rank-4-%E2%80%93-cross-site-request-forgery/">Top 25 Series – Rank 4 – Cross Site Request Forgery</a> &#8211; sans.org</li>
</ul>
</li>
<li><a href="http://holisticinfosec.blogspot.com/2010/03/rsa-visualizing-zeus-attack-against.html">RSA: Visualizing the Zeus attack against government and military</a> &#8211; holisticinfosec.blogspot.com<br />
For the article I discuss NetGrok and AfterGlow.</li>
<li><a href="http://houseofhackers.ning.com/profiles/blogs/metasploit-auxilary-module">Metasploit auxilary module FILE_AUTOPWN</a> &#8211; houseofhackers.ning.com<br />
Metasploit auxilary file_autopwn module &#8211; Video Tutorial</li>
<li><a href="http://pauldotcom.com/2010/03/ssh-gymnastics-with-proxychain.html">SSH gymnastics with proxychains</a> &#8211; pauldotcom.com<br />
For this discussion I will be focusing on SOCKS4 proxies setup with the SSH -D parameter.</li>
<li><a href="http://tacticalwebappsec.blogspot.com/2010/03/top-10-hacks-of-2009-and-waf.html">Top 10 Hacks of 2009 and WAF Mitigations</a> &#8211; tacticalwebappsec.blogspot.com<br />
In case you were not able to attend his RSA talk, I am going to outline which items can been addressed by WAFs.</li>
<li><a href="http://www.h-online.com/security/news/item/Study-on-cloud-security-threats-944986.html">Study on cloud security threats</a> &#8211; h-online.com<br />
Among the identified potential threats are malicious programs such as the Zeus botnet and the InfoStealing trojan.</li>
<li><a href="http://www.informit.com/articles/article.aspx?p=1569495">Fifteen Common Activities from BSIMM2</a> &#8211; informit.com<br />
Part of what makes BSIMM interesting is its basis in actual data from real software security initiatives.</li>
<li><a href="http://blogs.sans.org/it-audit/2010/03/03/it-audit-3-easy-steps-to-finding-rogue-wireless-clients/">IT Audit: 3 Easy Steps to Finding Rogue Wireless Clients</a> &#8211; sans.org<br />
You can easily discover if there are hosts from your network connecting to unprotected networks nearby and figure out which hosts are the rogues.</li>
<li><a href="http://www.skullsecurity.org/blog/?p=516">How big is the ideal dick&#8230;tionary?</a> &#8211; skullsecurity.org<br />
I&#8217;ve been working on collecting leaked passwords/other dictionaries.</li>
<li><a href="http://threatcenter.smobilesystems.com/?p=1752">Study of BlackBerry Proof-of-Concept Malicious Applications</a> &#8211; smobilesystems.com<br />
This research exposes the weakened security posture of devices that operate under the BlackBerry Internet Service environment.</li>
<li>Proof-of-concept exploits IE using help files.<br />
It uses a malicious dialog box which will trigger the execution of arbitrary code when the user presses the F1 key.</p>
<ul>
<li><a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">Microsoft Security Advisory (981169)</a> &#8211; microsoft.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx">Help keypress vulnerability in VBScript enabling Remote Code Execution</a> &#8211; technet.com</li>
<li><a href="http://www.computerworld.com/s/article/9164038/Microsoft_Don_t_press_F1_key_in_Windows_XP">Microsoft: Don&#8217;t press F1 key in Windows XP</a> &#8211; computerworld.com</li>
</ul>
</li>
<li>RSA compromised?<br />
Researchers at the University of Michigan say they have uncovered a way to circumvent encryption used on many devices.</p>
<ul>
<li><a href="http://securitywatch.eweek.com/vulnerability_research/researchers_claim_rsa_authentication_crack.html">Researchers Claim RSA Authentication Crack</a> &#8211; eweek.com</li>
<li><a href="http://www.networkworld.com/news/2010/030410-rsa-security-attack.html?hpg1=bn">Researchers find way to zap RSA security scheme</a> &#8211; networkworld.com</li>
</ul>
</li>
<li><a href="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/">&#8216;Severe&#8217; OpenSSL vuln busts public key crypto</a> &#8211; theregister.co.uk<br />
Private keys pilfered through power supply</li>
</ul>
</div>
</div>
<p><strong>Other News:</strong></p>
<ul>
<li><span style="font-size: 13.1944px"><a href="http://www.readwriteweb.com/archives/us_department_of_defense_goes_social.php">U.S. Department of Defense Goes Social&#8230;Yes, Really!</a> &#8211; readwriteweb.com<br />
<span style="font-size: 13.1944px">The U.S. Department of Defense gave all users of unclassified computers in the .mil domain access to popular social networking sites</span></span></li>
<li><a href="http://www.sans.org/8570/">DoD 8570 and GIAC Certification</a> &#8211; sans.org<br />
Department of Defense Directive 8570 provides guidance and procedures for the Information Assurance functions in assigned duty positions.</li>
<li><a href="http://www.informit.com/blogs/blog.aspx?uk=On-the-EC-Councils-Certified-Ethical-Hacker-CEH-Certification">On the EC-Council&#8217;s Certified Ethical Hacker (CEH) Certification</a> &#8211; informit.com<br />
In my humble or not-so-humble opinion, the U.S. Department of Defense was wise to overlook the CEH.</li>
<li><a href="http://www.datacenterknowledge.com/archives/2010/03/01/feds-commence-huge-data-center-consolidation/">Feds Commence Huge Data Center Consolidation</a> &#8211; datacenterknowledge.com<br />
The federal government has begun what looms as the largest data center consolidation in history.</li>
<li><span style="font-size: 13.1944px"><a href="http://www.wired.com/threatlevel/2010/03/wiseguys-indicted/">Wiseguys Indicted in $25 Million Online Ticket Ring</a> &#8211; wired.com<br />
The defendants made more than $25 million in profits from the resale of the tickets between 2002 and 2009. </span></li>
<li><span style="font-size: 13.1944px"><a href="http://news.cnet.com/8301-27080_3-10460842-245.html">Qualys to scan Web sites for malware</a> &#8211; cnet.com<br />
Qualys is set to launch on Monday a free service for Web site operators that will scan their sites for malware. </span></li>
<li><span style="font-size: 13.1944px"><a href="http://www.theregister.co.uk/2010/03/01/aurora_resistence_futile/">Most resistance to &#8216;Aurora&#8217; hack attacks futile, says report</a> &#8211; theregister.co.uk<br />
Most businesses are defenseless against the types of attacks that recently hit Google and at least 33 other companies. </span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><span style="font-size: 13.1944px">Cyberwar hubbub<br />
All the latest buzz about the rumored war on the Internet</span></span></span></p>
<ul>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.wired.com/threatlevel/2010/03/cyber-war-hype/">Cyberwar Hype Intended to Destroy the Open Internet</a> &#8211; wired.com</span></span></span></span></li>
<li><a href="http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/">White House Cyber Czar: ‘There Is No Cyberwar’</a> &#8211; wired.com</li>
</ul>
</li>
<li><a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=223100875">State Of Application Security: Nearly 60 Percent Of Apps Fail First Security Test</a> &#8211; darkreading.com<br />
Veracode app-testing data demonstrates that application security still has a ways to go.</li>
<li><a href="http://itknowledgeexchange.techtarget.com/security-bytes/shamir-acknowledges-chip-and-pin-attack-as-his-favorite/">Shamir acknowledges chip-and-PIN attack as his favorite</a> &#8211; techtarget.com<br />
Every year Adi Shamir brings something new to the table at the annual RSA Conference Cryptographers’ Panel.</li>
<li><a href="http://www.theregister.co.uk/2010/03/02/microsoft_charney_rsa/">Microsoft wants to put infected PCs in rubber room</a> &#8211; theregister.co.uk<br />
A top Microsoft executive is floating the idea of creating mandatory quarantines for computers with malware infections that pose a risk to internet users.</li>
<li><a href="http://www.krebsonsecurity.com/2010/03/regulators-revisit-e-banking-security-guidelines/">Regulators Revisit E-Banking Security Guidelines</a> &#8211; krebsonsecurity.com<br />
The guidance was meant to prod banks to implement so-called “multifactor authentication”.</li>
<li><a href="http://www.h-online.com/security/news/item/Apple-hires-ex-Mozilla-security-chief-945573.html">Apple hires ex-Mozilla security chief</a> &#8211; h-online.com<br />
Snyder, head of security at the Mozilla Foundation, is joining Apple as senior security product manager.</li>
<li>Cybersecurity plan outed<br />
<span style="font-size: 13.1944px">Schmidt also announces release of unclassified version of Obama administration&#8217;s plan for securing government, private industry networks</span></p>
<ul>
<li><span style="font-size: 13.1944px"><a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=223101302">Cybersecurity Czar Outlines Priorities</a></span> &#8211; darkreading.com</li>
<li><span style="font-size: 13.1944px"><a href="http://www.wired.com/threatlevel/2010/03/us-declassifies-part-of-secret-cybersecurity-plan/">U.S. Declassifies Part of Secret Cybersecurity Plan</a> &#8211; wired.com</span></li>
<li><span style="font-size: 13.1944px"><a href="http://www.h-online.com/security/news/item/US-government-publishes-parts-of-its-cyber-security-directive-946695.html">US government publishes parts of its cyber security directive</a> &#8211; h-online.com</span></li>
</ul>
</li>
<li>Mariposa botnet taken down<br />
Three Spaniards have reportedly been arrested for gaining control of more than 13 million computers.</p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Spanish-police-release-details-about-Mariposa-arrests-945723.html">Spanish police release details about Mariposa arrests</a> &#8211; h-online.com</li>
<li><a href="http://www.theregister.co.uk/2010/03/03/mariposa_botnet_bust_analysis/">How FBI, police busted massive botnet</a> &#8211; theregister.co.uk</li>
<li><a href="http://pandalabs.pandasecurity.com/mariposa-botnet/">Mariposa botnet</a> &#8211; pandasecurity.com</li>
<li><a href="http://www.krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/">‘Mariposa’ Botnet Authors May Avoid Jail Time</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://blogs.technet.com/mmpc/archive/2010/03/04/in-focus-mariposa-botnet.aspx">In focus: Mariposa botnet</a> &#8211; technet.com</li>
</ul>
</li>
<li><a href="http://www.eset.com/threat-center/blog/2010/03/03/rsa-highlight-howard-a-schmidt">RSA Highlight: Howard A. Schmidt</a> &#8211; eset.com<br />
An interview with the cybersecurity coordinator</li>
<li><a href="http://www.networkworld.com/news/2010/030210-wifi-finders.html?hpg1=bn">Wi-Fi finders let thieves track down hidden laptops</a> &#8211; networkworld.com<br />
Theives with increasingly sophisticated, directional Wi-Fi detectors can home in on the laptop&#8217;s radio even when the PC is hidden away.</li>
<li><a href="http://www.itworld.com/internet/98652/narus-develops-a-scary-sleuth-social-media">Narus develops a scary sleuth for social media</a> &#8211; itworld.com<br />
The new program, code-named Hone, is designed to give intelligence and law enforcement agencies a leg up on criminals.</li>
<li><a href="http://it.slashdot.org/story/10/03/03/2235219/Privacy-With-a-4096-Bit-RSA-Key-mdash-Offline-On-Paper">Privacy With a 4096 Bit RSA Key — Offline, On Paper</a> &#8211; slashdot.org<br />
The Dutch security company Safeberg developed an Offline Private Key Protocol, with an asymmetric key scheme.</li>
<li><a href="http://snosoft.blogspot.com/2010/03/good-guys-in-security-world-are-no.html">Professional Script Kiddies vs Real Talent</a> &#8211; snosoft.blogspot.com<br />
Do want to work with a security company that launches attacks against your network with tools that they do not fully understand?</li>
<li><a href="http://www.krebsonsecurity.com/2010/03/krebsonsecurity-author-twice-honored/">Krebsonsecurity Author Twice Honored</a> &#8211; krebsonsecurity.com<br />
The SANS Institute polled 75 cybersecurity journalists and asked them to rank the top peers in their field.</li>
<li><a href="http://www.wired.com/threatlevel/2010/03/smart-grids-done-smartly/">Security Pros Question Deployment of Smart Meters</a> &#8211; wired.com<br />
<span style="font-size: 13.1944px">The country’s swift deployment of smart-grid technology has security professionals concerned.</span></li>
<li><a href="http://news.cnet.com/8301-27080_3-10464161-245.html">Symantec exhibit makes cybercrime tangible</a> &#8211; cnet.com<br />
Symantec has created a Black Market exhibit that attempts to make these virtual ideas more tangible.</li>
<li><a href="http://www.theregister.co.uk/2010/03/04/social_penetration/">Hacking human gullibility with social penetration</a> &#8211; theregister.co.uk<br />
So-called social penetration techniques are more reliable and easier to use in identifying chinks in client fortresses.</li>
</ul>
</div>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=870&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/OHz6GzkKYsKhk0uJZ2bVW_G7X0I/0/da"><img src="http://feedads.g.doubleclick.net/~a/OHz6GzkKYsKhk0uJZ2bVW_G7X0I/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/OHz6GzkKYsKhk0uJZ2bVW_G7X0I/1/da"><img src="http://feedads.g.doubleclick.net/~a/OHz6GzkKYsKhk0uJZ2bVW_G7X0I/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/l1d53KbWaB8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/03/09/week-9-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/03/09/week-9-in-review/</feedburner:origLink></item>
		<item>
		<title>Week 8 in  Review – 2010</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/eguMp7SLqRE/</link>
		<comments>http://infosecevents.net/2010/03/01/week-8-in-review/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 12:16:31 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=866</guid>
		<description><![CDATA[



Events Related:

Securosis&#8217; Guide to the RSA Conference 2010 &#8211; mckeay.com
If you want to do some research on specific technologies at the RSA Conference 2010, this should help.
ShmooCon 2010 Firetalks – Update 5 (aka – the Wrap-Up) &#8211; novainfosecportal.com
Presentation compilations and more.
Assured Exploitation Training &#8211; trailofbits.com
This training class is focused on various topics in advanced exploitation [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.mckeay.net/2010/02/24/securosis-guide-to-the-rsa-conference-2010/">Securosis&#8217; Guide to the RSA Conference 2010</a> &#8211; mckeay.com<br />
If you want to do some research on specific technologies at the RSA Conference 2010, this should help.</li>
<li><a href="http://www.novainfosecportal.com/2010/02/24/shmoocon-2010-firetalks-update-5-aka-the-wrap-up/">ShmooCon 2010 Firetalks – Update 5 (aka – the Wrap-Up)</a> &#8211; novainfosecportal.com<br />
Presentation compilations and more.</li>
<li><a href="http://trailofbits.com/2010/02/25/assured-exploitation-training/">Assured Exploitation Training</a> &#8211; trailofbits.com<br />
This training class is focused on various topics in advanced exploitation of memory corruption vulnerabilities.</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://blogs.sans.org/it-audit/2010/02/25/it-audit-6-vmware-settings-every-it-auditor-should-know-about/">IT Audit: 6 VMWare Settings Every IT Auditor Should Know About</a> &#8211; sans.org<br />
Here we’ll take a look at settings that impact security, and how they should ideally be configured.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.irongeek.com/i.php?page=security/zipit-z2-hacking-userland-side-track">Side-Track: Security/Pen-testing Distribution Of Linux For The ZipIt Z2</a> &#8211; irongeek.com<br />
The ZipIt Z2 is great platform for dropboxes since it runs Linux and is only $50.</li>
<li><a href="http://sahi.co.in/w/">Sahi v3.0</a> &#8211; sahi.co.in<br />
<span style="font-size: 13.1944px">Sahi injects javascript into web pages using a proxy and the javascript helps automate web applications.</span></li>
<li><span style="font-size: 13.1944px"><a href="https://www.sentrigo.com/Register_For_Repscan">Repscan v3.0</a> &#8211; sentrigo.com<br />
This new version supports MS SQL Server and Oracle databases. </span></li>
<li><span style="font-size: 13.1944px"><a href="http://wiki.eslimasec.com/esliwiki/ProjectsPost">NoMore and 1=1</a> &#8211; eslimasec.com<br />
This tool is used to minimize the time required to type malicious syntax and have a handy repository as well.</span></li>
<li><a href="http://www.hackfromacave.com/katana.html">Katana v1.5 (Z@toichi)</a> &#8211; hackfromacave.com<br />
Katana includes distributions which focus on Pen-Testing, Auditing, Forensics, System Recovery, Network Analysis, Malware Removal and more.</li>
<li><a href="http://www.openwall.com/john/">John the Ripper v1.7.5</a> &#8211; openwall.com<br />
Its primary purpose is to detect weak Unix passwords</li>
<li><a href="http://websecuritytool.codeplex.com/">Watcher version 1.3.0 released February 25, 2010</a> &#8211; websecuritytool.codeplex.com<br />
Watcher provides pen-testers hot-spot detection for vulnerabilities, developers quick sanity checks, and auditors PCI compliance auditing.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.red-database-security.com/2010/02/22/really-good-whitepaper-about-hacking-oracle-from-the-web/">Really good whitepaper about “Hacking Oracle from the Web”</a> &#8211; red-database-security.com<br />
This is the most comprehensive published collection of different techniques for attacking Oracle from the web.</li>
<li><a href="http://blog.didierstevens.com/2010/02/22/ping-shellcode/">Ping Shellcode</a> &#8211; didierstevens.com<br />
I’ve added 2 new assembly source files for shellcode to execute a ping.</li>
<li><a href="http://pauldotcom.com/2010/02/running-a-command-on-every-mac.html">Running a command on every machine in your domain from the command line</a> &#8211; pauldotcom.com<br />
You can run any command you want on every machine in your domain.</li>
<li><a href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">Man in the Browser</a> &#8211; fireeye.com<br />
Man in the Browser a.k.a MITB is a new breed of attacks whose primary objective is to spy on browser sessions.</li>
<li><a href="http://research.microsoft.com/apps/pubs/default.aspx?id=120428">How Secure are Secure Interdomain Routing Protocols?</a> &#8211; microsoft.com<br />
In response to high-profile Internet outages, BGP security variants have been proposed to prevent the propagation of bogus routing information.</li>
<li><a href="http://blog.red-database-security.com/2010/02/24/how-to-prevent-a-user-granted-the-alter-user-privilege-from-changing-syssystem-password-and-how-to-bypass-it/">How to prevent a user granted the ALTER USER priviledge from changing SYS/SYSTEM password and how to bypass it.</a> &#8211; red-database-security.com<br />
Many Oracle users are not aware that the grant command can also be used to change passwords or even create users.</li>
<li><a href="http://www.oracleforensics.com/wordpress/index.php/2010/02/25/securing-java-in-oracle-update-and-escalating-to-sysdba/">Securing Java in Oracle Update and escalating to SYSDBA</a> &#8211; oracleforensics.com<br />
Most organisations either take the risk of the change breaking functionality or decide to stay as they are.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/406">VMWare Directory Traversal Metasploit Module</a> &#8211; carnal0wnage.attackresearch.com<br />
I pushed up my checker module to the metasploit trunk as an auxiliary scanner module.</li>
<li><a href="http://pauldotcom.com/2010/02/killing-the-monkey-in-the-midd.html">Killing the Monkey in the Middle</a> &#8211; pauldotcom.com<br />
There are many ways for the attacker to insert themselves in the middle of a conversation.</li>
<li><a href="http://www.slaviks-blog.com/2010/02/26/enumerate-oracle-sids/">Enumerate Oracle SIDs</a> &#8211; slaviks-blog.com<br />
As promised, here is a small Python script to allow you to enumerate and find Oracle SIDs.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://www.cgisecurity.com/2010/02/multiple-adobe-products-vulnerable-to-xml-external-entity-injection-and-xml-injection.html">Multiple Adobe products vulnerable to XML External Entity Injection And XML Injection</a> &#8211; cgisecurity.com<br />
This advisory provides a good explanation and examples of these rarely discussed attack types.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://news.cnet.com/8301-27080_3-10458491-245.html">Adobe plugs critical hole in Download Manager</a> &#8211; cnet.com<br />
Download Manager is a tool that helps users efficiently download files from Web servers.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://www.daniweb.com/news/story262199.html">75 percent of enterprises have been hit by multi-million dollar cyber attacks</a> &#8211; daniweb.com<br />
Every enterprise, yes 100 percent, experienced cyber losses in 2009.</li>
<li><a href="http://threatpost.com/en_us/blogs/interview-howard-schmidt-022210">An Interview With Howard Schmidt</a> &#8211; threatpost.com<br />
Dennis Fisher talks with Schmidt about his career and what the priorities should be for the cybersecurity czar.</li>
<li><a href="http://www.abc.net.au/news/stories/2010/02/23/2828024.htm">Police called in over SMH leak</a> &#8211; abc.net.au<br />
An Australian transport minister says there were about 3,727 unauthorised hits on the website</li>
<li><a href="http://www.wired.com/threatlevel/2010/02/intel-hacked/">‘Sophisticated’ Hack Hit Intel in January</a> &#8211; wired.com<br />
<span style="font-size: 13.1944px">Intel acknowledged that it was hacked in January in a sophisticated attack at the same time that Google, Adobe and others were targeted.</span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.h-online.com/security/news/item/Credit-card-skimming-attacks-on-pay-at-the-pump-petrol-stations-938268.html">Credit card skimming attacks on pay-at-the-pump petrol stations</a> &#8211; h-online.com<br />
Skimming devices attached to petrol pump terminals use Bluetooth to transmit the data to criminals operating near by. </span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear.html">GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission</a> &#8211; sucuri.net<br />
Some scary stuff that might happen to you if you host your site with them, clearly violating on your privacy.</span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.net-security.org/secworld.php?id=8911">US unable to win a cyber war</a> &#8211; net-security.org<br />
If the US got involved in a cyber war at this moment, they would surely lose. </span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/">N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss</a> &#8211; krebsonsecurity.<br />
A New York marketing firm that was preparing to be acquired is now facing bankruptcy from a computer virus.</span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.gadling.com/2010/02/24/hotel-room-security-defeated-by-a-piece-of-wire-can-be-secured/">Hotel room security defeated by a piece of wire &#8211; can be secured with a towel</a> &#8211; gadling.com<br />
A piece of bent wire can defeat these magnetic swipe rooms.</span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.pcworld.com/article/190205/are_hollywood_hackers_bogus_or_bright.html">Are Hollywood Hackers Bogus or Bright?</a> &#8211; pcworld.com<br />
Gordon, a lecturer at the Dublin Institute of Technology, studied 50 movies, produced over five decades.</span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.darkreading.com/security/cybercrime/showArticle.jhtml?articleID=223100404">Navy Planning Prototype Cyber-Network Security System</a> &#8211; darkreading.com<br />
Seeking proposals for a system that ensures cyber operations aren&#8217;t shut down in the event of a cyber war.</span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.pcpro.co.uk/news/security/355852/microsoft-secretly-beheads-notorious-botnet">Microsoft secretly beheads notorious botnet</a> &#8211; pcpro.co.uk<br />
Microsoft has won court approval to deactivate 277 domain names that are being used to control a vast network of infected PCs. </span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://www.darkreading.com/security/privacy/showArticle.jhtml?articleID=223100764">Cryptome Back Online After Brief DMCA Battle</a> &#8211; darkreading.com<br />
Website reportedly taken down for posting sensitive Microsoft document on criminal investigation compliance. </span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://news.yahoo.com/s/pcworld/20100226/tc_pcworld/wyndhamhotelshackedagain">Wyndham Hotels Hacked Again </a> &#8211; yahoo.com<br />
This is the third data breach reported by Wyndham in the past year. </span></span></li>
<li><span style="font-size: 13.1944px"><span style="font-size: 13.1944px"><a href="http://wifinetnews.com/archives/2010/02/another_better_tkip_attack_thats_still_limited.html">Another, Better TKIP Attack That&#8217;s Still Limited</a> &#8211; wifinetnews.com<br />
One of the two researchers who brought us the TKIP Michael packet integrity attack has a refined technique. </span></span></li>
</ul>
</div>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=866&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/K6Xx1wDmjjrB0ndyeCkg3x_ip5Y/0/da"><img src="http://feedads.g.doubleclick.net/~a/K6Xx1wDmjjrB0ndyeCkg3x_ip5Y/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/K6Xx1wDmjjrB0ndyeCkg3x_ip5Y/1/da"><img src="http://feedads.g.doubleclick.net/~a/K6Xx1wDmjjrB0ndyeCkg3x_ip5Y/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/eguMp7SLqRE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/03/01/week-8-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/03/01/week-8-in-review/</feedburner:origLink></item>
		<item>
		<title>Vendor Parties @ RSA 2010</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/0G9tl5s50-Q/</link>
		<comments>http://infosecevents.net/2010/02/27/vendor-parties-rsa-2010/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 03:20:21 +0000</pubDate>
		<dc:creator>ggee</dc:creator>
				<category><![CDATA[Parties]]></category>

		<guid isPermaLink="false">http://infosecevents.net/2010/02/27/vendor-parties-rsa-2010/</guid>
		<description><![CDATA[The RSA conference is just around the corner, and that means the vendor parties are as well. I’m not sure who is behind the RSA party list on yahoo’s upcoming, but it contains a good list of parties. I’ve gone ahead and created a party map for Tuesday and Wednesday of next week. 
Tuesday Map:
&#160;
Wednesday [...]]]></description>
			<content:encoded><![CDATA[<p>The RSA conference is just around the corner, and that means the vendor parties are as well. I’m not sure who is behind the <a href="http://upcoming.yahoo.com/group/15660">RSA party list</a> on yahoo’s upcoming, but it contains a good list of parties. I’ve gone ahead and created a party map for Tuesday and Wednesday of next week. </p>
<p>Tuesday Map:</p>
<p><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="0302" border="0" alt="0302" src="http://infosecevents.net/wp-content/uploads/2010/02/0302.png" width="499" height="399" />&#160;</p>
<p>Wednesday Map:</p>
<p><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="0303" border="0" alt="0303" src="http://infosecevents.net/wp-content/uploads/2010/02/03031.png" width="391" height="335" /></p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=863&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/7Eoq8oEJ7Q7zJW4--ktQvOIUcj4/0/da"><img src="http://feedads.g.doubleclick.net/~a/7Eoq8oEJ7Q7zJW4--ktQvOIUcj4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/7Eoq8oEJ7Q7zJW4--ktQvOIUcj4/1/da"><img src="http://feedads.g.doubleclick.net/~a/7Eoq8oEJ7Q7zJW4--ktQvOIUcj4/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/0G9tl5s50-Q" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/27/vendor-parties-rsa-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/27/vendor-parties-rsa-2010/</feedburner:origLink></item>
		<item>
		<title>Information Security Events in March</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/hz1_1fBP7FI/</link>
		<comments>http://infosecevents.net/2010/02/27/information-security-events-in-march-2/#comments</comments>
		<pubDate>Sat, 27 Feb 2010 12:06:59 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Local Meetings]]></category>
		<category><![CDATA[Security Conferences]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=856</guid>
		<description><![CDATA[

Here are the information security events in North America this month:

17th Annual Network and Distributed System Security (NDSS) Symposium &#8211; February 28 to March 3 in San Diego
RSA Conference USA &#8211; March 1 &#8211; 5 in San Francisco
BSides San Francisco &#8211; March 2 &#8211; 3 in San Francisco
SecureIT 2010 &#8211; March 3 &#8211; 5 in [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>Here are the information security events in North America this month:</p>
<ul>
<li><a href="http://www.isoc.org/isoc/conferences/ndss/10/">17th Annual Network and Distributed System Security (NDSS) Symposium</a> &#8211; February 28 to March 3 in San Diego</li>
<li><a href="http://www.rsaconference.com/2010/usa/index.htm">RSA Conference USA</a> &#8211; March 1 &#8211; 5 in San Francisco</li>
<li><a href="http://www.securitybsides.org/BSidesSanFrancisco">BSides San Francisco</a> &#8211; March 2 &#8211; 3 in San Francisco</li>
<li><a href="http://www.secureitconf.com/">SecureIT 2010</a> &#8211; March 3 &#8211; 5 in Los Angeles</li>
<li><a href="http://www.sans.org/sans-2010/">SANS 2010</a> &#8211; March 6 &#8211; 15 in Orlando</li>
<li><a href="http://www.securitybsides.org/BSidesAustin">BSides Austin</a> &#8211; March 13 in Houston</li>
<li><a href="http://www.grcsummit2010.com/Home_Page.html">GRC Summit 2010</a> &#8211; March 14 &#8211; 17 in Amelia Island</li>
<li><a href="http://www.marcusevans.com/html/eventdetail.asp?eventID=16257&amp;SectorID=29">Corporate Fraud: Prevention, Detection &amp; Investigation in the Aftermath of the Global Economic Downturn</a> &#8211; March 15 &#8211; 16 in Boston</li>
<li><a href="http://www.carolinacon.org/">CarolinaCon 2010</a> &#8211; March 19 &#8211; 21 in Raleigh</li>
<li><a href="http://cansecwest.com">CanSecWest 2010</a> &#8211; March 22 &#8211; 26 in Vancouver</li>
<li><a href="http://projects.csail.mit.edu/spamconf/">MIT Spam Conference</a> &#8211; March 25 &#8211; 26 in Cambridge</li>
<li><a href="http://www.sans.org/scada-security-summit-2010/">The 2010 SCADA and Process Control Summit</a> &#8211; March 29 &#8211; 30 in Lake Buena Vista</li>
</ul>
<p>And here are the information security events in the other parts of the world:</p>
<ul>
<li><a href="http://europe.gartner.com/iam">Gartner Identity &amp; Access Management Summit</a> &#8211; March 3 &#8211; 4 in United Kingdom</li>
<li><a href="http://www.troopers.de">TROOPERS10</a> &#8211; March 8 &#8211; 12 in Germany</li>
<li><a href="http://www.sans.org/wellington-2010/">SANS Wellington</a> &#8211; March 15 &#8211; 20 in New Zealand</li>
<li><a href="http://cloudsecurityalliance.org/sc2010.html">SecureCloud 2010</a> &#8211; March 16 &#8211; 17 in Spain</li>
</ul>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=856&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/Aap1YkMbpRi1LIgrH7YMqA8z81k/0/da"><img src="http://feedads.g.doubleclick.net/~a/Aap1YkMbpRi1LIgrH7YMqA8z81k/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Aap1YkMbpRi1LIgrH7YMqA8z81k/1/da"><img src="http://feedads.g.doubleclick.net/~a/Aap1YkMbpRi1LIgrH7YMqA8z81k/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/hz1_1fBP7FI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/27/information-security-events-in-march-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/27/information-security-events-in-march-2/</feedburner:origLink></item>
		<item>
		<title>Week 7 in Review</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/1Avz6Zcg_vA/</link>
		<comments>http://infosecevents.net/2010/02/21/week-7-in-review/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 03:49:31 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=844</guid>
		<description><![CDATA[


Events Related:

Pwn2Own 2010
Now in its fourth year, the Pwn2Own competition will award up to $100,000 for exploits that successfully penetrate various hardware and software systems.

Contest offers $100,000 for smartphone, browser hacks &#8211; theregister.co.uk
Pwn2Own 2010 &#8211; tippingpoint.com




Resources:

2010 SANS Top 25 Most Dangerous Programming Errors Released &#8211; cgisecurity.com
This is a list of the most widespread and critical [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li>Pwn2Own 2010<br />
Now in its fourth year, the Pwn2Own competition will award up to $100,000 for exploits that successfully penetrate various hardware and software systems.</p>
<ul>
<li><a href="http://www.theregister.co.uk/2010/02/16/2010_pwn2own/">Contest offers $100,000 for smartphone, browser hacks</a> &#8211; theregister.co.uk</li>
<li><a href="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010">Pwn2Own 2010</a> &#8211; tippingpoint.com</li>
</ul>
</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.cgisecurity.com/2010/02/2010-sans-top-25-most-dangerous-programming-errors.html">2010 SANS Top 25 Most Dangerous Programming Errors Released</a> &#8211; cgisecurity.com<br />
This is a list of the most widespread and critical programming errors that can lead to serious software vulnerabilities.</li>
<li><a href="http://www.securityscoreboard.com/">Security Scoreboard</a> &#8211; securityscoreboard.com<br />
Think about a Zagat for security products, that is what it is.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://informationgift.com/macnikto/builds/MacNikto_1.1.1.dmg">MacNikto 1.1.1</a> &#8211; informationgift.com<br />
It provides easy access to a subset of the features available in the Open Source, command-line driven Nikto web security scanner.</li>
<li><a href="http://blog.g-sec.lu/2010/02/harden-ssltls-tool-release.html">Harden SSL/TLS &#8211; Tool release</a> &#8211; g-sec.lu<br />
It allows locally and remotely set SSL policies allowing or denying certain ciphers/hashes or complete ciphersuites.</li>
<li><a href="http://code.google.com/p/pyrit/">Pyrit 0.3.0</a> &#8211; code.google.com/p/pyrit/<br />
Pyrit allows to create massive databases, pre-computing part of the WPA/WPA2-PSK authentication phase in a space-time-tradeoff</li>
<li><a href="http://www.engineeringforfun.com/browserrider.html">Browser Rider v20090204 Released</a> &#8211; engineeringforfun.com<br />
The project aims to provide a powerful, simple and flexible interface to any client side exploit.</li>
<li><a href="http://code.google.com/p/websecurify/downloads/list">Websecurify v0.5 Beta 1</a> &#8211; code.google.com/p/websecurify/</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://mikesmithers.wordpress.com/2010/02/11/self-inflicted-sql-injection-%E2%80%93-dont-quote-me/">Self-Inflicted SQL Injection – don’t quote me !</a> &#8211; mikesmithers.wordpress.com<br />
But how can you be attacked when the attacker isn’t even around at the time ?</li>
<li><a href="http://blog.coresecurity.com/2010/02/16/integrating-core-impact-pro-with-metasploit/">Integrating Core Impact Pro With the Metasploit Project</a> &#8211; coresecurity.com<br />
Today we announced that CORE IMPACT Pro will be integrated with Metasploit in our next scheduled product release.</li>
<li><a href="http://hexblog.com/2010/02/scriptable_processor_modules.html">Scriptable Processor modules</a> &#8211; hexblog.com<br />
One of the new features we are preparing for the next version of IDA is the ability to write processor modules using your favorite scripting language.</li>
<li><a href="http://www.gdssecurity.com/l/b/2010/02/12/abusing-wcf-to-perform-remote-port-scans/">Abusing WCF to Perform Remote Port Scans</a> &#8211; gdssecurity.com<br />
The first step in establishing a session with WSDualHttpBinding requires the client and server to negotiate the duplex connection.</li>
<li><a href="http://relentless-coding.blogspot.com/2010/02/screen-unlock-meterpreter-script.html">Screen Unlock Meterpreter Script</a> &#8211; relentless-coding.blogspot.com<br />
The script needs SYSTEM privileges and patches the msv1_0.dll loaded by lsass.exe so that every password will be accepted to unlock the screen.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://ha.ckers.org/blog/20100216/google-buzz-security-flaw/">Google Buzz Security Flaw</a> &#8211; ha.ckers.org<br />
It’s yet another example of bad input validation/output encoding by your favorite advertising overlords at Google.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Adobe fixes Reader and Acrobat Flaws<br />
This vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests.</p>
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">Security updates available for Adobe Reader and Acrobat</a> &#8211; adobe.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=5492">Adobe plugs more gaping holes in PDF Reader</a> &#8211; zdnet.com</li>
<li><a href="http://threatpost.com/en_us/blogs/adobe-plugs-critical-pdf-code-execution-flaw-021610">Adobe Plugs Critical PDF Code Execution Flaw</a> &#8211; threatpost.com</li>
<li><a href="http://www.krebsonsecurity.com/2010/02/security-updates-for-adobe-reader-acrobat/">Security Updates for Adobe Reader, Acrobat</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
<li>Mozilla security updates<br />
Firefox and Seamonkey get a few bug fixes.</p>
<ul>
<li><a href="http://www.seamonkey-project.org/releases/seamonkey2.0.3/">SeaMonkey 2.0.3</a> - seamonkey-project.org</li>
<li><a href="http://www.mozilla.com/en-US/firefox/3.5.8/releasenotes/">Firefox 3.5 Release Notes</a> &#8211; mozilla.com</li>
<li><a href="http://www.mozilla.com/en-US/firefox/3.0.18/releasenotes/">Firefox 3 Release Notes v3.0.18</a> &#8211; mozilla.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://rdist.root.org/2010/02/15/reverse-engineering-a-smart-meter/">Reverse-engineering a smart meter</a> &#8211; root.org<br />
A software bug, typo at the control center, or hacker could potentially turn off my power and gas.</li>
<li><a href="http://hackaday.com/2010/02/15/electronic-key-impressioning/">Electronic key impressioning</a> &#8211; hackaday.com<br />
Apparently, a handheld impressioning device is about to hit the market that can tell you the key codes for a lock in a matter of seconds.</li>
<li><a href="http://www.inc.com/news/articles/2010/02/china-home-to-most-hacked-computers.html">China Home to Most Hacked Computers, Says Report</a> &#8211; inc.com<br />
In the last three months of 2009, about 1,095,000 computers in China were hacked.</li>
<li><a href="http://www.computerworld.com/s/article/9156658/Criminal_hacker_Iceman_gets_13_years">Criminal hacker &#8216;Iceman&#8217; gets 13 years</a> &#8211; computerworld.com<br />
Max Ray Butler, who used the hacker pseudonym Iceman, was sentenced Friday morning in Pittsburgh on charges of wire fraud and identity theft.</li>
<li><a href="http://securityblog.verizonbusiness.com/2010/02/16/sbir-2-dbir-comparison/">A Comparison of DBIR with UK breach report</a> &#8211; verizonbusiness.com<br />
The following is a high-level comparison of DBIR findings to the 7Safe report from the UK.</li>
<li><a href="http://gizmodo.com/5472859/even-kingston-knocks-off-kingston-microsd-cards">Even Kingston Knocks Off Kingston microSD Cards?</a> &#8211; gizmodo.com<br />
Bunnie Huang of the famous Chumby encountered some Kingston microSDs appeared to be dysfunctional counterfeits.</li>
<li><a href="http://net-security.org/secworld.php?id=8878">Mock cyber attack shows US unpreparedness</a> &#8211; net-security.org<br />
The simulated cyber attack in Washington showed that the US is still not ready to deflect or mitigate such an attack.</li>
<li><a href="http://www.wired.com/dangerroom/2010/02/hackers-troops-rejoice-pentagon-lifts-thumb-drive-ban/">Hackers, Troops Rejoice: Pentagon Lifts Thumb-Drive Ban (Updated)</a> &#8211; wired.com
<div>U.S. Strategic Command has lifted its ban on the tiny drives, memory sticks, CDs and other “removable flash media” on military networks.</div>
</li>
</ul>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=844&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/O3jovV3U9qLlmbIdaSxGaRmvbeY/0/da"><img src="http://feedads.g.doubleclick.net/~a/O3jovV3U9qLlmbIdaSxGaRmvbeY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/O3jovV3U9qLlmbIdaSxGaRmvbeY/1/da"><img src="http://feedads.g.doubleclick.net/~a/O3jovV3U9qLlmbIdaSxGaRmvbeY/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/1Avz6Zcg_vA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/21/week-7-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/21/week-7-in-review/</feedburner:origLink></item>
		<item>
		<title>RSA Conference 2010 (Free Expo Pass!)</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/40oLHWHv1z4/</link>
		<comments>http://infosecevents.net/2010/02/19/rsa-conference-2010-free-expo-pass/#comments</comments>
		<pubDate>Sat, 20 Feb 2010 00:25:46 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=837</guid>
		<description><![CDATA[
It&#8217;s time for the RSA Conference again! This year&#8217;s RSA Conference will be from March 1 &#8211; 5, 2010 at the Moscone Center in San Francisco. Featuring over 300 exhibitors and security vendors in the expo floor, this is one of the most comprehensive security events in the world. There will also be over 250 [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><a href="http://www.rsaconference.com/2010/usa/index.htm"><img class="size-full wp-image-838 aligncenter" src="http://infosecevents.net/wp-content/uploads/2010/02/RSA-Conference.jpg" alt="" width="500" height="67" /></a></p>
<p>It&#8217;s time for the <a href="http://www.rsaconference.com/2010/usa/index.htm">RSA Conference</a> again! This year&#8217;s RSA Conference will be from <strong>March 1 &#8211; 5, 2010</strong> at the <strong>Moscone Center in San Francisco</strong>. Featuring over 300 exhibitors and security vendors in the expo floor, this is one of the most comprehensive security events in the world. There will also be over 250 security sessions covering a variety of relevant topics such as darknets, the National Cyber Security Framework, cloud computing security, crowdsourcing fraud and business metrics for security and risk.</p>
<p>There&#8217;s a lot of info going on for this conference and we&#8217;ve compiled a few links below to help you digest it.</p>
<p><a href="http://www.nxtbook.com/nxtbooks/nthdegree/rsa10/#/0">Catalog Brochure</a> &#8211; A comprehensive guide of everything about the RSA Conference. Beware though, it&#8217;s in Flash but they do offer a downloadable <a href="http://pages.nxtbook.com/nxtbooks/nthdegree/rsa10/offline/nthdegree_rsa10_pdf.zip">PDF version</a> as an alternative.<a href="https://cm.rsaconference.com/US10/catalog/catalog/catalog.jsp"><br />
Session Catalog</a> &#8211; A list of all the talks, speakers and schedules during the conference, all bundled in a neat, search-friendly page. There&#8217;s also a <a href="https://cm.rsaconference.com/US10/catalog/catalog/catalog.jsp?printView=true">printable version</a> of this list available.<br />
<a href="http://twitter.com/RSAConference">Twitter Stream</a> &#8211; Keep your finger on the pulse via the conference&#8217;s official Twitter feed. Use #rsac for your related tweets.<br />
<a href="www.groups.to/rsaconferences">Facebook Group</a> &#8211; Socialize with other attendees online at this site.<a href="http://www.rsaconference.com/2010/usa/agenda-and-sessions/at-a-glance.htm"><br />
Agenda at a Glance</a> &#8211;  A basic overview of all the events including the <a href="http://www.rsaconference.com/2010/usa/agenda-and-sessions/keynote-speakers.htm">Keynotes</a>, <a href="http://www.rsaconference.com/2010/usa/agenda-and-sessions/peer2peer.htm">Peer2Peer</a> and <a href="http://www.rsaconference.com/2010/usa/agenda-and-sessions/track-descriptions.htm">Track Sessions</a>. Below is the expo schedule for a quick reference</p>
<p style="padding-left: 30px">Monday, March 1:       6 pm – 8 pm (Welcome Reception)<br />
Tuesday, March 2:      11 am – 6 pm<br />
Wednesday, March 3: 11 am – 6 pm<br />
Thursday, March 4:    11 am – 3 pm</p>
<p><a href="https://cm.rsaconference.com/US10/catalog/exhibitorCatalog.do">Exhibitor List</a> &#8211; Check out if your favorite security vendor is on-site. This list includes other details like the company website, booth number and company address.<br />
<a href="http://www.mapyourshow.com/shows/index.cfm?Show_ID=RSA10">Floor Plan</a> &#8211; You can map out your activities with this floor plan, courtesy of mapyourshow.com. This site is also in Flash so be forewarned.</p>
<p>If you&#8217;re interested in going to the expo floor, we can get you in for free! <a href="http://www.rsaconference.com/2010/usa/registration-and-rates.htm">Register here</a> then enter the complimentary expo pass code to save on the $100 fee! You only need to use one of these codes so just choose your favorite one from the list below.</p>
<ul>
<li>3Com &#8211; SC10TPP</li>
<li>ArcSight &#8211; EC10ARS</li>
<li>Blue Coat &#8211; EC10BLC</li>
<li>CA Security &#8211; SC10CA</li>
<li>Cloud Security Alliance &#8211; 1310CLEXPO</li>
<li>Collective Software &#8211; EC10CSO</li>
<li>Kantara Initiative &#8211; 1310KANEXPO, select Kantara Initiative from the Registration Package page to get free access to the March 1 workshop from the company.</li>
<li>Lieberman &#8211; EXH9LSC</li>
<li>nCircle &#8211; SC10NCR</li>
<li>PKWare &#8211; EC10PKW</li>
<li>Proofpoint &#8211; EC10PRF</li>
<li>Qualys &#8211; SC10QLS</li>
<li>Symantec &#8211; SC10SYM, expires February 26</li>
<li>Tipping Point &#8211; SC10TPP</li>
<li>WebRoot &#8211; EC10WBR</li>
</ul>
<p>We&#8217;ll be posting more about the event when it kicks of this coming March. Also check out the <a href="http://www.securitybsides.org/BSidesSanFrancisco">BSidesSanFrancisco event</a> as well while you&#8217;re out there.</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=837&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/g3S9iOmIGzuUQNhs1postdloQDI/0/da"><img src="http://feedads.g.doubleclick.net/~a/g3S9iOmIGzuUQNhs1postdloQDI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/g3S9iOmIGzuUQNhs1postdloQDI/1/da"><img src="http://feedads.g.doubleclick.net/~a/g3S9iOmIGzuUQNhs1postdloQDI/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/40oLHWHv1z4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/19/rsa-conference-2010-free-expo-pass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/19/rsa-conference-2010-free-expo-pass/</feedburner:origLink></item>
		<item>
		<title>Week 6 in Review – 2010</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/JNHg7sBwYTs/</link>
		<comments>http://infosecevents.net/2010/02/14/week-6-in-review/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 07:00:54 +0000</pubDate>
		<dc:creator>glenn</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=819</guid>
		<description><![CDATA[


Events Related:


ShmooCon related posts
A few stories about the recently concluded security conference.

ShmooCon 2010 – Show Notes &#8211; chuvakin.blogspot.com
FireTalks from Shmoocon 2010 &#8211; Videos &#8211; irongeek.com
Shmoocon 2010 Security Conference &#8211; tenablesecurity.com





Resources:

Social Engineering Framework &#8211; social-engineer.org
We will be developing this framework over time and there will be more to come.
DIY Hard Drive Diagnostics: Understanding a Broken Drive [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<div><strong>Events Related</strong>:</div>
<div>
<ul>
<li>ShmooCon related posts<br />
A few stories about the recently concluded security conference.</p>
<ul>
<li><a href="http://chuvakin.blogspot.com/2010/02/shmoocon-2010-show-notes.html">ShmooCon 2010 – Show Notes</a> &#8211; chuvakin.blogspot.com</li>
<li><a href="http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2010">FireTalks from Shmoocon 2010 &#8211; Videos</a> &#8211; irongeek.com</li>
<li><a href="http://blog.tenablesecurity.com/2010/02/shmoocon-2010-security-conference.html">Shmoocon 2010 Security Conference</a> &#8211; tenablesecurity.com</li>
</ul>
</li>
</ul>
</div>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.social-engineer.org/framework/Social_Engineering_Framework">Social Engineering Framework</a> &#8211; social-engineer.org<br />
We will be developing this framework over time and there will be more to come.</li>
<li><a href="http://www.myharddrivedied.com/shmoocon.html">DIY Hard Drive Diagnostics: Understanding a Broken Drive</a> &#8211; myharddrivedied.com<br />
This talk is the basic process to start doing diagnostics on your damaged hard drive.</li>
<li><a href="http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1139">Attack Simulation and Threat Modeling</a> &#8211; professionalsecuritytesters.org<br />
Attack Simulation and Threat Modeling is a book that explores advanced security data collection, classification, processing and mining.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://fyrmassociates.com/tools.html">GuestStealer v1.00</a> &#8211; fyrmassociates.com<br />
GuestStealer allows for the stealing of VMware guests from vulnerable hosts based on the Directory Traversal Vulnerability.</li>
<li><a href="http://keimpx.googlecode.com/files/keimpx-0.2.zip">Keimpx v0.2</a> &#8211; keimpx.googlecode.com<br />
It can be used to quickly check for the usefulness of credentials across a network over SMB.</li>
<li><a href="http://www.securityaegis.com/beef-browser-rider-and-xsstunnel-make-friends/">BeEF, Browser Rider, and XSSTunnel make friends…</a> &#8211; securityaegis.com<br />
A few browser attack tools band together to deliver a more exceptional product.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/">Excel with cmd.dll &amp; regedit.dll</a> &#8211; didierstevens.com<br />
Stevens modified source code from ReactOS to transform cmd.exe into cmd.dll and regedit into a dll.</li>
<li>Larry Suto Report Inaccurate, Says Vendors<br />
A couple of vendors have stepped up and found irregularities in the recent published web scanner report</p>
<ul>
<li><a href="http://www.acunetix.com/blog/news/latest-comparison-report-from-larry-suto/">Latest Comparison Report from Larry Suto</a> &#8211; acunetix.com</li>
<li><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/02/08/on-web-application-scanner-comparisons.aspx">On Web Application Scanner Comparisons&#8230;</a> &#8211; hp.com</li>
<li><a href="http://blog.cenzic.com/public/item/250026">Web Vulnerability Scanner Comparison</a> &#8211; cenzic.com</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/02/wheres-whitehat-re-scanner-comparisons.html">Where&#8217;s WhiteHat? Re: Scanner Comparisons</a> &#8211; jeremiahgrossman.blogspot.com</li>
</ul>
</li>
<li><a href="http://www.csoonline.com/article/533113/ShmooCon_Inside_FarmVille_s_Sinister_Underbelly">ShmooCon | Inside FarmVille&#8217;s Sinister Underbelly</a> &#8211; csonline.com<br />
A talk in the recent event about the dangers of online gaming and social networks</li>
<li><a href="http://www.csoonline.com/article/533163/ShmooCon_Your_iPhone_s_Dirty_Little_Security_Secret">ShmooCon | Your iPhone&#8217;s Dirty Little Security Secret</a> &#8211; csonline.com<br />
A discussion on how to hack smartphones</li>
<li>A few posts on BlackBerry spyware
<ul>
<li><a href="http://www.veracode.com/blog/2010/02/is-your-blackberry-app-spying-on-you/">Is Your BlackBerry App Spying on You?</a> &#8211; veracode.com<br />
A demo on how BlackBerry apps can access and leak sensitive info using only RIM-provided APIs and no exploits of any sort.</li>
<li><a href="http://threatpost.com/en_us/blogs/tyler-shields-blackberry-spyware-and-coming-wave-smartphone-attacks-020910">Tyler Shields on the BlackBerry Spyware and the Coming Wave of Smartphone Attacks</a> &#8211; threatpost.com<br />
Dennis Fisher talks with Tyler Shields of Veracode about his BlackBerry spyware application, txsBBSPY.</li>
</ul>
</li>
<li><a href="http://blog.metasploit.com/2010/02/automatically-routing-through-new.html">Automatically Routing Through New Subnets</a> &#8211; metasploit.com<br />
Among the coolest features in metasploit is the ability to pivot through a meterpreter session to the network on the other side.</li>
<li><a href="http://www.paloaltonetworks.com/researchcenter/2009/10/mariposa-tool/">Wireshark Plugin for Mariposa Botnet Command and Control</a> &#8211; paloaltonetworks.com<br />
Yamata Li has developed a Wireshark plugin that will allow you to view obfuscated pcaps of traffic from a Mariposa infected client.</li>
<li><a href="http://windowsteamblog.com/blogs/windowssecurity/archive/2010/02/10/black-hat-tpm-hack-and-bitlocker.aspx">Black Hat TPM Hack and BitLocker</a> &#8211; windowsteamblog.com<br />
We believe that using a TPM is still an effective means to help protect sensitive information.</li>
<li><a href="http://www.m86security.com/labs/traceitem.asp?article=1236">The Bad Guys Hate Security Folks</a> &#8211; m86security.com<br />
A Pushdo bot we analysed earlier this week uses domain names which taunt FireEye and Brian Krebs.</li>
<li><a href="http://www.securityaegis.com/nsploit-nmap-gets-grows-some-teeth/">Nsploit: Nmap grows some teeth</a> &#8211; securityaegis.com<br />
Ryan Linn has started a project to bridge Nmap Scans all the way to exploitation using Metasploit.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Oracle Zero-Day revealed<br />
It covers vulnerabilities that allow an attacker to escalate their privileges to sysdba and take complete control of the database.</p>
<ul>
<li><a href="http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html">Oracle Security Alert for CVE-2010-0073</a> &#8211; oracle.com</li>
<li><a href="http://blog.appsecinc.com/security_30/2010/02/litchfield-dbms_jvm_exp_perms-0day-on-oracle.html">Litchfield DBMS_JVM_EXP_PERMS 0-day on Oracle</a> &#8211; appsecinc.com</li>
</ul>
</li>
<li><a href="http://www.samba.org/samba/news/symlink_attack.html">Claimed Zero Day exploit in Samba</a> &#8211; samba.org<br />
The issue is actually a default insecure configuration in Samba.Events Related:</li>
<li><a href="http://blog.ivanristic.com/2010/02/firefox-extension-installation-process-vulnerable-to-mitm-attack-.html">Firefox extension installation process vulnerable to MITM attack</a> &#8211; ivanristic.com<br />
If a man in the middle is able to intercept the traffic of someone installing an extension, he will be able to get the user to install something else.</li>
<li><a href="http://hexale.blogspot.com/2010/02/windows-smb-ntlm-authentication-weak.html">Windows SMB NTLM Authentication Weak Nonce Vulnerability released</a> &#8211; hexale.blogspot.com<br />
It&#8217;s basically a 14/17-year old vulnerability in the Windows implementation of the NLTM Authentication protocol.</li>
<li><a href="http://www.ethicalhack3r.co.uk/2010/02/13/wordpress-2-9-failure-to-restrict-url-access/">WordPress &gt;= 2.9 Failure to Restrict URL Access</a> &#8211; ethicalhack3r.co.uk<br />
Security by obscurity is not sufficient to protect sensitive functions and data in an application.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Another Patch Tuesday from Microsoft<br />
The company has a heap of updates with this week&#8217;s security bulletins.</p>
<ul>
<li><a href="http://blogs.technet.com/msrc/archive/2010/02/09/february-2010-security-bulletin-release.aspx">February 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/02/09/details-on-the-new-tls-advisory.aspx">Details on the New TLS Advisory</a> &#8211; technet.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-003.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-003 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-004.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-004 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-005.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-005 &#8211; Moderate</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-006.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-006 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-007.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-007 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-008 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-009.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-009 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-010.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-010 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-011.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-011 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-012.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-012 &#8211; Important</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-013.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-013 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-014.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-014 &#8211; Important</a> &#8211; microsoft.com</li>
<li>
<div>
<div><a href="http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx?pubDate=2010-02-09">Microsoft Security Bulletin MS10-015 &#8211; Important</a> &#8211; microsoft.com</div>
</div>
</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx">MS10-006 and MS10-012: SMB security bulletins</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-007-additional-information-and-recommendations-for-developers.aspx">MS10-007: Additional information and recommendations for developers</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/msrc/archive/2010/02/11/restart-issues-after-installing-ms10-015.aspx">Restart issues after installing MS10-015</a> &#8211; technet.com</li>
<li><a href="http://blogs.technet.com/srd/archive/2010/02/09/assessing-the-risk-of-the-february-security-bulletins.aspx">Assessing the risk of the February Security Bulletins</a> &#8211; technet.com</li>
<li><a href="http://threatpost.com/en_us/blogs/ms-patch-tuesday-13-bulletins-26-vulnerabilities-020910">MS Patch Tuesday: 13 Bulletins, 26 Vulnerabilities</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://www.krebsonsecurity.com/2010/02/critical-security-update-for-adobe-flash-player/">Critical Security Update for Adobe Flash Player</a> &#8211; krebsonsecurity.com<br />
Adobe Systems Inc. today released an updated version of its Flash Player software to fix two critical security holes in the ubiquitous Web browser plugin.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://www.networkworld.com/news/2010/020610-chinese-man-gets-30-months.html?hpg1=bn">Chinese man gets 30 months for fake Cisco sales</a> &#8211; networkworld.com<br />
Yongcai Li, 33, will have to pay the networking company nearly $800,000 in restitution.</li>
<li><a href="http://news.cnet.com/8301-27080_3-10447627-245.html">U.S. House passes cybersecurity research bill</a> &#8211; cnet.com<br />
It calls for beefing up training, research, and coordination so the government can be better prepared to deal with cyberattacks</li>
<li><a href="http://www.net-security.org/secworld.php?id=8842">Zero-day vulnerabilities on the market</a> &#8211; net-security.org<br />
Even government agencies from all over the world are engaged in buying these zero-days.</li>
<li><a href="http://rdist.root.org/2010/02/08/ps3-hypervisor-exploit-reproduced/">PS3 hypervisor exploit reproduced</a> &#8211; root.org<br />
It remains to be seen what security measures Sony has taken to address a hypervisor compromise.</li>
<li><span style="color: #551a8b"><span style="color: #000000"><a href="http://arstechnica.com/tech-policy/news/2010/02/hacker-training-site-reappears-after-takedown-by-china.ars">Hacker training site backup lives after takedown by China</a> &#8211; arstechnica.com</span></span><br />
Black Hawk Safety Net, an online hacker training resource, was brought down recently by Chinese authorities.</li>
<li><a href="http://press-releases.techwhack.com/46058-7safe">UK Security Breach Investigations Report 2010 Published</a> &#8211; techwhack.com<br />
Anonymised data has been analysed from over 60 computer forensic investigations.</li>
<li><a href="http://www.avertlabs.com/research/blog/index.php/2010/02/09/mcafee-labs-q4-threat-report/">McAfee Labs Quarterly Threat Report Posted</a> &#8211; avertlabs.com<br />
It highlights many of the most significant spam-generating stories in 2009 as well as the rise of political hacktivism.</li>
<li><a href="http://hackaday.com/2010/02/09/tpm-crytography-cracked/">TPM crytography cracked</a> &#8211; hackaday.com<br />
Christopher Tarnovsky figured out how to defeat the hardware by spying on its communications.</li>
<li><a href="http://threatpost.com/en_us/blogs/researchers-discover-new-ach-banker-trojan-021010">Researchers Discover New ACH Banker Trojan</a> &#8211; threatpost.com<br />
The Bugat Trojan includes features commonly found in malware used to commit credential theft for financial fraud.</li>
<li><a href="http://news.zdnet.co.uk/security/0,1000000189,40022674,00.htm">Chip and PIN is broken, say researchers</a> &#8211; zdnet.com<br />
Researchers at Cambridge Unviersity have found a flaw in the Europay, Mastercard and Visa protocols.</li>
<li><a href="http://www.computerworlduk.com/management/government-law/public-sector/news/index.cfm?newsid=18787">Simulated hacker attack to test US government response</a> &#8211; computerworlduk.com<br />
Cyber ShockWave involves former administration staff, national security officials.</li>
<li><a href="http://www.wired.com/threatlevel/2010/02/max-vision-sentencing/">Record 13-Year Sentence for Hacker Max Vision</a> &#8211; wired.com<br />
A skilled San Francisco computer intruder was sentenced Friday to 13 years in federal prison for stealing nearly two million credit card numbers.</li>
<li><a href="http://www.krebsonsecurity.com/2010/02/rootkit-may-be-culprit-in-recent-windows-crashes/">Rootkit May Be Culprit in Recent Windows Crashes</a> &#8211; krebsonsecurity.com<br />
A sysad said he traced the problem on each machine back to “atapi.sys” — a Windows storage driver.</li>
</ul>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=819&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/VcSLoYGgc8As6UTtE47q6IPidbg/0/da"><img src="http://feedads.g.doubleclick.net/~a/VcSLoYGgc8As6UTtE47q6IPidbg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/VcSLoYGgc8As6UTtE47q6IPidbg/1/da"><img src="http://feedads.g.doubleclick.net/~a/VcSLoYGgc8As6UTtE47q6IPidbg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/JNHg7sBwYTs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/14/week-6-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/14/week-6-in-review/</feedburner:origLink></item>
		<item>
		<title>ShmooCon 2010 – Wrap Up</title>
		<link>http://feedproxy.google.com/~r/InfosecEvents/~3/ek8N_MrMziU/</link>
		<comments>http://infosecevents.net/2010/02/10/shmoocon-2010-wrap-up/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 07:11:43 +0000</pubDate>
		<dc:creator>ron</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[convention]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[shmoocon 2010]]></category>
		<category><![CDATA[ShmooCon Group]]></category>
		<category><![CDATA[Shmoopocalypse 2010]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=676</guid>
		<description><![CDATA[February 2010, concludes another exciting ShmooCon East coast hacker convention; Access ShmooCon 2010 related articles, blog posts, videos, “Shmoopocalypse 2010″ photos, tools and downloads, and other information security resources.]]></description>
			<content:encoded><![CDATA[<p><a title="ShmooCon 2010" href="http://shmoocon.org/index.html"><img class="size-full wp-image-697" style="border: 0pt none; margin: 6px 0px 6px 1px; float: left;" src="http://infosecevents.net/wp-content/uploads/2010/02/ShmooCon-2010-WrapUp.jpg" alt="ShmooCon 2010 - Wrap Up" width="570" height="125" /></a></p>
<p>This year&#8217;s <a title="ShmooCon 2010 East Coast Hacker Convention" href="http://shmoocon.org/index.html">ShmooCon 2010</a> East coast hacker convention was a three day event at the <a title="Wardman Park Marriott, Washington DC, USA" href="http://www.marriott.com/hotels/travel/wasdt-washington-marriott-wardman-park/">Wardman Park Marriott</a>, Washington DC, USA. The event took place according to <a title="ShmooCon 2010 - Schedule" href="http://shmoocon.org/presentations.html">schedule</a> from Friday, February 5 to Sunday, February 7, 2010.</p>
<p>The central theme for day one was “One Track Mind,” a single track consisting of seven 30-minute speed talks. Day two and day three each presented three tracks: Break It!, Build It!, and Bring It On! For those that did not attend ShmooCon this year, the ShmooCon Group broadcast <a title="ShmooCon Live Streaming Video" href="http://www.shmoocon.org/video.html">ShmooCon Live Streaming Video</a> of all presentations.</p>
<p>As with the past three ShmooCon conventions, tickets for ShmooCon 2010 had sold out early. About 1,500 fans attended ShmooCon 2010, despite the heavy snow that blanketed the greater Washington, DC, area. This post lists links to ShmooCon 2010 related articles, blog posts, videos, photos, tools and downloads.</p>
<p><strong>ShmoonCon 2010 East Coast Hacker Convention, Washington, DC, USA</strong></p>
<ul>
<li>The ShmooCon 2010 <a title="ShmooCon 2010 - Schedule" href="http://www.shmoocon.org/presentations.html">schedule</a>.</li>
<li>ShmooCon&#8217;s <a title="ShmooCon Hacker Arcade" href="http://www.shmoocon.org/arcade.html">Hacker Arcade</a>.</li>
<li>ShmooCon exclusive, <a title="ShmooCon Hack-or-Halo" href="http://www.shmoocon.org/hoh.html">Hack-or-Halo</a>.</li>
<li>The <a title="ShmooCon TF2 Lan Party" href="http://www.shmoocon.org/tf2.html">TF2 Lan Party</a> Cheater Tourney and TF2 Tourney <a title="Team Fortress 2 - TF2 Official Blog" href="http://www.teamfortress.com/">(Team Fortress 2- Blog)</a>.</li>
<li><a title="Disclosure: ShmooCon 2010 CFP" href="http://seclists.org/fulldisclosure/2009/Sep/114">Full Disclosure: ShmooCon 2010 CFP</a> – About the ShmooCon conference format and more.</li>
<li>ShmooCon 2010 <a title="ShmooCon 2010 - Washington, DC - Map" href="http://maps.google.com/maps?f=q&amp;source=s_q&amp;hl=en&amp;geocode=CXz4y1UwS2qJFQHxUQIdTjxo-ynj3-yR1Le3iTG2P6ivX0mwTQ&amp;q=bar+OR+cafe+OR+coffee+loc:+2660+Woodley+Rd+NW,+Washington,+DC+20008+%28Marriott+Wardman+Park+hotel+where+Shmoocon+is%29&amp;sll=38.926698,-77.048707&amp;sspn=0.018663,0.050941&amp;ie=UTF8&amp;hq=bar+OR+cafe+OR+coffee&amp;hnear=2660+Woodley+Rd+NW,+Washington,+DC+20008&amp;z=16">Washington, D.C.</a>, area map.</li>
</ul>
<p><strong>ShmooCon 2010 &#8211; InfosecEvents Previous Posts</strong></p>
<ul>
<li><a title="ShmooCon 2010 - Preview" href="http://infosecevents.net/2010/01/31/shmoocon-2010-preview/">ShmooCon 2010 &#8211; Preview</a></li>
<li><a title="ShmooCon 2010 - Day One" href="http://infosecevents.net/2010/02/05/shmoocon-2010-day-one/">ShmooCon 2010 &#8211; Day One</a></li>
<li><a title="ShmooCon 2010 - Day Two" href="http://infosecevents.net/2010/02/07/shmoocon-2010-day-two/">ShmooCon 2010 &#8211; Day Two</a></li>
<li><a title="ShmooCon 2010 – Day Three" href="http://infosecevents.net/2010/02/07/shmoocon-2010-day-three/">ShmooCon 2010 &#8211; Day Three</a></li>
<li><a title="ShmooCon 2010 - Photos" href="http://infosecevents.net/2010/02/08/shmoocon-2010-shmoo-photos/">ShmooCon 2010 &#8211; Shmoo Photos</a></li>
</ul>
<p><strong>ShmooCon 2010 &#8211; Resources and Tools</strong></p>
<p>Jsunpack-network Edition Release: JavaScript Decoding and Intrusion Detection by Blake Hartstein, Blake Hartstein.</p>
<ul>
<li>Download <a title="jsunpack-n.tgz" href="http://jsunpack.jeek.org/jsunpack-n.tgz">jsunpack-n.tgz</a>.</li>
<li>JavaScript unpacker <a href="http://jsunpack.jeek.org/dec/go">Jsunpack</a>.</li>
</ul>
<p>Blackberry Mobile Spyware – The Monkey Steals  the Berries, Tyler Shields.</p>
<ul>
<li><a title="Slides Blackberry Mobile Spyware — The Monkey Steals the Berries" href="http://www.veracode.com/images/TylerShields-MonkeyBerries-ShmooCon-2010.pdf">Slides: Blackberry Mobile Spyware</a> (PDF).</li>
<li><a title="Video TXSBBSpy Demo" href="http://vimeo.com/videos/search:tyler%20TXSBBSpy">TXSBBSpy Demo</a> by Tyler Shields at Veracode Research Lab.</li>
<li><a title="Source Code txsBBSpyDOTjava" href="http://www.veracode.com/images/txsBBSpy.java">txsBBSpy.java</a> source code.</li>
</ul>
<p>Cracking the Foundation: Attacking WCF Web Services, Brian Holyfield.</p>
<ul>
<li><a title="TFS Toys Subversion URL" href="https://tfstoys.svn.codeplex.com/svn">TFS Toys Subversion</a> download site.</li>
<li><a title="WcfTestClient" href="http://weblogs.asp.net/blogs/guillermo/code/WcfTestClient.zip">WcfTestClient</a> download.</li>
<li><a title="WCF Storm Free Lite Version" href="http://www.wcfstorm.com/wcf/download-wcfstorm-lite.aspx">WCF Storm Free Lite Version</a> download.</li>
</ul>
<p>DIY Hard Drive Diagnostics: Understanding a Broken Drive, by Scott Moulton. Be sure to get your free copy of <a title="DIY Hard Drive Diagnostics by Scott Moulton" href="http://www.myharddrivedied.com/shmoocon2010.pdf">DIY Hard Drive Diagnostics</a> (PDF). Visit Moulton&#8217;s web site, <a href="http://www.myharddrivedied.com/shmoocon.html">MyHardDriveDied</a>.</p>
<p>Information Disclosure via P2P Networks, Larry Pesce and Mick Douglas. Check out <a title="The Cactus Project" href="http://www.pauldotcom.com/cactusproject.html">The Cactus Project</a> at <a title="PaulDotCom" href="http://www.pauldotcom.com/">PaulDotCom</a>. The Cactus Project is a tool intended to be used for all sorts of purposes on the Gnutella bases P2P network.</p>
<p><strong>Articles and Blog Posts</strong></p>
<ul>
<li>NovaInfosecPortal&#8217;s coverage on ShmoonCon 2010 <a title="ShmoonCon 2010 FireTalks" href="http://www.novainfosecportal.com/2010/01/06/shmoocon-2010-firetalks/">FireTalks</a>.</li>
<li><a title="ShmooCon | Inside FarmVille's Sinister Underbelly" href="http://www.csoonline.com/article/533113/">ShmooCon | Inside FarmVille&#8217;s Sinister Underbelly</a> (CSO, Bill Brenner, Senior Editor). &#8220;You love Facebook apps like FarmVille and Mafia Wars and think they&#8217;re perfectly safe, right? Think again.&#8221;</li>
<li><a title="ShmooCon | Your iPhone's Dirty Little Security Secret" href="http://www.csoonline.com/article/533163/">ShmooCon | Your iPhone&#8217;s Dirty Little Security Secret</a> (CSO, Bill Brenner, Senior Editor). &#8220;Just how easy is it for the bad guys to use your iPhone against you . . . Trevor Hawthorn explains what to do about it.&#8221;</li>
</ul>
<p><strong>Videos</strong></p>
<ul>
<li>ShmooCon 2010 GSM: SRSLY? by Chris Paget and Karsten Nohl.  <a title="Shmoocon 2010 - Hak5 with Chris Paget" href="http://www.youtube.com/watch?v=ygsr0vW-Hng">Shmoocon 2010 &#8211; Hak5</a>, an intervew with Chris Paget via <a id="video-from-username-ygsr0vW-Hng" href="http://www.youtube.com/user/revision3">revision3</a> on YouTube.<br />
Paget, &#8220;Cloning, spoofing, man-in-the-middle, decrypting, sniffing, crashing, DoS&#8217;ing, or just plain having fun. If you can work a BitTorrent client and a standard GNU build process then you can do it all. . . .&#8221;</p>
<ul>
<li>The <a title="The OpenBTS Project" href="http://openbts.sourceforge.net/">OpenBTS Project</a> web page.</li>
<li><a title="OpenBTS download" href="http://sourceforge.net/projects/openbts/files/openbts-2.5.3Lacassine.tar.gz/download">OpenBTS</a> download.</li>
<li><a title="OpenBTS Hardware" href="http://kestrelsignalprocessing.mybigcommerce.com/categories/OpenBTS-Hardware/">OpenBTS Hardware</a> link from the OpenBTS web page.</li>
</ul>
</li>
<li>ShmooCon 2010 Social Zombies II: Your Friends Need More Brains by Tom Eston, Kevin Johnson, Robin Wood.  Facebook <a href="http://www.youtube.com/watch?v=chvwtGPkAIQ">Application Autopwn with BeEF</a>, via <a href="http://www.youtube.com/user/spylogicdotnet">spylogicdotnet</a> (Tom Eston) on YouTube. Demo showing  machine getting pwnd by simply viewing the profile page of a vulnerable Facebook application;  particular Facebook app found vulnerable to persistent XSS (via theharmonyguy).
<ul>
<li> <a href="http://www.bindshell.net/tools/beef/">BeEF Tool</a> (Browser Exploitation Framework) used to launch the Metasploit Browser Autopwn module to attack the victim machine.</li>
</ul>
</li>
</ul>
<p><strong>Twitter</strong></p>
<ul>
<li>There is a lot of valuable information security talk out there in the world of Twitter. The twitosphere was full of interesting streams about <a title="#shmoocon" href="http://twitter.com/search?q=%23shmoocon">#shmoocon</a>.</li>
<li><a title="OWASP BWA (Broken Web Application) Project" href="http://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project">OWASP BWA (Broken Web Application) Project</a> (BWA Main Page) via <a title="ChrisJohnRiley" href="http://twitter.com/ChrisJohnRiley/statuses/8697600487">ChrisJohnRiley</a> and <a title="danphilpott" href="http://twitter.com/danphilpott/statuses/8697843093">danphilpott</a>. Learn about the <a title="Learn about the OWASP" href="http://www.owasp.org/">OWASP</a> (Main Page), DVWA, WebGoat, Matiliday, and more.</li>
<li>VMWare <a title="vSphere Hardening Guide" href="http://blogs.vmware.com/security/2010/01/announcing-vsphere-40-hardening-guide-public-draft-release.html">vSphere Hardening Guide</a> via <a title="k4l4m4r1s" href="http://twitter.com/k4l4m4r1s/statuses/8698846443">k4l4m4r1s</a>. This guide represents a new approach to providing security guidance.</li>
<li>Secmaniac.com launched; <a title="Social Engineering Toolkit" href="http://www.secmaniac.com/january-2010/secmaniac-com-woot/">Social Engineering Toolkit</a>: SET v0.4 codename &#8220;pink pirate&#8221; (not making that up) talk at firetalks <a title="#shmoocon" href="http://twitter.com/search?q=%23shmoocon">#shmoocon</a> from <a title="Gal Shpantzer" href="http://twitter.com/Shpantzer">Shpantzer</a></li>
</ul>
<p><strong>InfosecEvents&#8217; Closing Comments</strong></p>
<p>February 2010, this concludes another exciting ShmooCon East coast hacker convention; held this year at the Wardman Park Marriott, Washington DC, USA. Be sure to  check back here at InfosecEvents for the latest information on hacking contests, security tools, training, vulnerabilities, workshops, and upcoming events.</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=676&type=feed" alt="" />
<p><a href="http://feedads.g.doubleclick.net/~a/aC6pVvoHdDbpib8wegNE4Ovk0Rw/0/da"><img src="http://feedads.g.doubleclick.net/~a/aC6pVvoHdDbpib8wegNE4Ovk0Rw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/aC6pVvoHdDbpib8wegNE4Ovk0Rw/1/da"><img src="http://feedads.g.doubleclick.net/~a/aC6pVvoHdDbpib8wegNE4Ovk0Rw/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/InfosecEvents/~4/ek8N_MrMziU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/02/10/shmoocon-2010-wrap-up/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://infosecevents.net/2010/02/10/shmoocon-2010-wrap-up/</feedburner:origLink></item>
	</channel>
</rss>
