<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-4155089922457192489</id><updated>2011-02-16T12:23:05.983-05:00</updated><title type="text">Jorge Orchilles</title><subtitle type="html">Focused on IT and Information Security</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.orchilles.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.orchilles.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default?start-index=26&amp;max-results=25" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>67</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/JorgeOrchilles" /><feedburner:info uri="jorgeorchilles" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-7821749589192090221</id><published>2011-02-16T12:06:00.002-05:00</published><updated>2011-02-16T12:11:11.491-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Virtual Machine Escape by NSA (video)</title><content type="html">The NSA released a video demonstrating many attack vectors including VMEscape. The video stars ShmooCon's Bruce and Miami's Immunity Canvas software.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.nsa.gov/ia/media_center/video/orlando2010/flash.shtml" target="_blank"&gt;Check it out.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-7821749589192090221?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/85zVHe_KX6A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/7821749589192090221/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=7821749589192090221&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7821749589192090221" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7821749589192090221" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/85zVHe_KX6A/virtual-machine-escape-by-nsa-video.html" title="Virtual Machine Escape by NSA (video)" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2011/02/virtual-machine-escape-by-nsa-video.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4877987827227599679</id><published>2010-10-29T10:39:00.002-04:00</published><updated>2010-10-29T10:41:51.632-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Hacker Halted 2010 Presentations</title><content type="html">Hacker Halted 2010 presentations are up. If you were able to attend you know there were a few good talks. The event went way better than last years and EC-Council is making Miami, FL their home town for this conference. Check out the presentations &lt;a href="http://www.hackerhalted.com/2010/Speakers/PresentationArchives/tabid/307/Default.aspx" target="_new"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4877987827227599679?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/PiJDbz1wESo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4877987827227599679/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4877987827227599679&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4877987827227599679" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4877987827227599679" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/PiJDbz1wESo/hacker-halted-2010-presentations.html" title="Hacker Halted 2010 Presentations" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/10/hacker-halted-2010-presentations.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2257845088908702769</id><published>2010-10-27T12:14:00.003-04:00</published><updated>2010-10-27T12:17:55.544-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><title type="text">Windows 7 Service Pack 1 (Release Candidate)</title><content type="html">Microsoft announced today the Release Candidate (RC) of Windows 7 and Windows Server 2008 R2 Service Pack 1 (SP1) to the public. For those unaware of how these software rollouts "work," the RC release generally signals that a final build is almost ready. The only new features added to the SP1 are the Windows Server 2008 R2-related virtualization technologies, Dynamic Memory and RemoteFX, and while Windows 7 SP1 will enable PCs to take advantage of these server-based features to provide a more scalable and richer VDI experience for end users, there are no additional new features specific to Windows 7. &lt;br /&gt;&lt;br /&gt;If you do choose to install this Release Candidate make sure to backup your system. Microsoft usually makes you uninstall the RC before installing the final build of the service pack.&lt;br /&gt;&lt;br /&gt;Download &lt;a href="http://technet.microsoft.com/en-us/evalcenter/ff183870.aspx" target="_blank"&gt;here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2257845088908702769?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/F9vyI0AdaSk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2257845088908702769/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2257845088908702769&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2257845088908702769" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2257845088908702769" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/F9vyI0AdaSk/windows-7-service-pack-1-release.html" title="Windows 7 Service Pack 1 (Release Candidate)" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/10/windows-7-service-pack-1-release.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2019038399404533926</id><published>2010-09-27T19:20:00.003-04:00</published><updated>2010-09-27T19:27:59.014-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">VMware vCloud Director Security Hardening Guide</title><content type="html">VMware has released a technical white paper titled: VMware vCloud Directory Security Hardening Guide which may be downloaded &lt;a href="http://www.vmware.com/files/pdf/techpaper/VMW_10Q3_WP_vCloud_Director_Security.pdf" target="_blank"&gt;here.&lt;/a&gt; If you are looking into this technology definitely look into this:&lt;br /&gt;&lt;br /&gt;"The VMware® vCloud™ Director Security Hardening Guide helps users who are embarking into the journey of cloud computing understand key security elements and technologies found in VMware’s vCloud Director product. It also provides guidelines and best practices for installation, configuration and operation of secure clouds based on VMware’s vCloud Director."&lt;br /&gt;&lt;br /&gt;I have skimmed the document and it has many important points to consider at just 37 pages it isn't the definitive guide on cloud security but definitely a start.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2019038399404533926?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/V72a7UiLybE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2019038399404533926/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2019038399404533926&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2019038399404533926" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2019038399404533926" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/V72a7UiLybE/vmware-vcloud-director-security.html" title="VMware vCloud Director Security Hardening Guide" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/09/vmware-vcloud-director-security.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4967212854760569207</id><published>2010-09-26T18:21:00.002-04:00</published><updated>2010-09-26T18:57:49.444-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><title type="text">Running ESXi 4.1 on VMware Workstation 7.0 and above</title><content type="html">VMware is ditching ESX for ESXi which is smaller and, best of all, free. I have been running ESX 4.0 as a virtual machine in Windows using VMware Workstation for some time now but was never able to get ESXi to run as a virtual machine. One of the students in the &lt;a href="http://www.sans.org/security-training/virtualization-security-fundamentals-1412-mid" target="_blank"&gt;SANS Security 577: Virtualization Security Fundamentals&lt;/a&gt; class asked me if it was possible to run ESXi on VMware Workstation. Which made me wonder, now that ESXi will be the main hypervisor being pushed by VMware, would it be possible?&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The answer is YES! But with a few prerequisites:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://downloads.vmware.com/d/info/desktop_downloads/vmware_workstation/7_0" target="_blank"&gt;VMware Workstation 7.0&lt;/a&gt; or above (7.1.1 officially supports vSphere 4.1 guests)&lt;/li&gt;&lt;li&gt;Dual-Core or better CPU with Intel VT or AMD-V support (may have to turn on in BIOS).&lt;/li&gt;&lt;li&gt;At least 2GB of free RAM (I suggest 4GB-8GB)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Once you have downloaded &lt;a href=" p="https://www.vmware.com/tryvmware/index.php?p=free-esxi&amp;amp;lp=1" target="_blank"&gt;VMware ESXi 4.1&lt;/a&gt; and installed VMware Workstation you are ready to begin:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Open VMware Workstation&lt;/li&gt;&lt;li&gt;File-New-Virtual Machine...&lt;/li&gt;&lt;li&gt;Custom&lt;/li&gt;&lt;li&gt;Hardware compatibility: Workstation 6.5-7.0&lt;/li&gt;&lt;li&gt;Installer disc image file (iso): Click Browse... and select the iso file for VMware ESXi that you downloaded. Click Next.&lt;/li&gt;&lt;li&gt;Click the VMware ESX check box and select ESX Server 4.0 from Version drop down. Click Next.&lt;/li&gt;&lt;li&gt;Select the Virtual machine name and location. Click Next.&lt;/li&gt;&lt;li&gt;Processors must be at least 2 processors with 1 core each. Increase if your system can handle it. Click Next.&lt;/li&gt;&lt;li&gt;Memory must be at least 2048MB but if you can increase it, go for it. Click Next.&lt;/li&gt;&lt;li&gt;Select what type of network connection. Click Next.&lt;/li&gt;&lt;li&gt;For I/O Adapter select LSI Logic for SCSI Adapter. Click Next.&lt;/li&gt;&lt;li&gt;Create a new virtual disk. Click Next.&lt;/li&gt;&lt;li&gt;Virtual disk type: SCSI. Click Next.&lt;/li&gt;&lt;li&gt;Select the size of the disk. Remember you will be running virtual machines with local storage so plan accordingly. I recommend storing as a single file for performance. Click Next.&lt;/li&gt;&lt;li&gt;Specify the disk file name and location. Click Next.&lt;/li&gt;&lt;li&gt;Select Customize Hardware.&lt;/li&gt;&lt;li&gt;Click Floppy-Remove. Then add more network adapters if desired. Click OK&lt;/li&gt;&lt;li&gt;Click Finish.&lt;/li&gt;&lt;li&gt;Install ESXi as usual.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;If this does not work for you or you have questions or comments please comment below.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;I will be teaching the &lt;a href="http://www.sans.org/mentor/details.php?nid=23053"&gt;SANS Security 577: Virutalization Security Fundamentals course as a co-mentor&lt;/a&gt; with Robert Rounsavall in Miami, FL on Thursday October 28, 2010 6:00pm-8:00pm through Thursday November 18, 2010 at Terremark's NAP of the Americas. &lt;a href="https://www.sans.org/registration/register.php?conferenceid=23053"&gt;Register early!&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Till next time,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4967212854760569207?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/gzwY-kuzp9A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4967212854760569207/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4967212854760569207&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4967212854760569207" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4967212854760569207" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/gzwY-kuzp9A/running-esxi-41-on-vmware-workstation.html" title="Running ESXi 4.1 on VMware Workstation 7.0 and above" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2010/09/running-esxi-41-on-vmware-workstation.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-6380640658594481840</id><published>2010-08-23T14:08:00.002-04:00</published><updated>2010-08-23T14:15:48.556-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><title type="text">I'm Back!</title><content type="html">After a long break from blogging mostly due to the fact that I finally published &lt;a href="http://www.amazon.com/Microsoft-Windows-Administrators-Reference-Upgrading/dp/1597495611" target="_blank"&gt;Microsoft Windows 7 Administrator's Reference&lt;/a&gt;, finished a &lt;a href="http://business.fiu.edu/chapman/msmis/index.cfm" target="_blank"&gt;Master's of Science in Management Information Systems&lt;/a&gt;, and was hired by a Fortune 20 financial institution to perform vulnerability assessment/ethical hacking/penetration testing, I am officially back to blogging!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Many things coming soon:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;SANS Security 577 Virtualization Security Fundamentals course review&lt;/li&gt;&lt;li&gt;Speaking engagement and presentation at Hacker Halted titled "Vulnerability Ass... Penetration What?&lt;/li&gt;&lt;li&gt;Hacker Halted conference. If you want to attend email me for a student code!!!!! $100 before September 15.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Glad to be back and hope you are too.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Till next time,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-6380640658594481840?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/Oie51mfOx9E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/6380640658594481840/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=6380640658594481840&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6380640658594481840" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6380640658594481840" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/Oie51mfOx9E/im-back.html" title="I'm Back!" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/08/im-back.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4532888617894267428</id><published>2010-04-14T02:12:00.004-04:00</published><updated>2010-04-14T04:59:13.911-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida Information Security Community</title><content type="html">As you know, I am attempting to become more involved in the Information Security community and giving back to it as I have taken so much. One area I found to be lacking was that I kept sending users here for information about the next local event because there was no single resource providing information on the next meetings, events, or conferences. With the support of some local organizations (&lt;a href="http://www.sfissa.org/" target="_blank"&gt;South Florida ISSA&lt;/a&gt;, &lt;a href="http://www.owasp.org/index.php/Miami_Ft_Lauderdale" target="_blank"&gt;South Florida OWASP&lt;/a&gt;, &lt;a href="http://www.hackmiami.org/" target="_blank"&gt;Hack Miami&lt;/a&gt;, more coming) we are soft launching:&lt;br /&gt;&lt;br /&gt;The South Florida Information Security Community – &lt;a href="http://www.SFInfoSec.com/" target="_blank"&gt;http://www.SFInfoSec.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please take a look and provide feedback.&lt;br /&gt;&lt;br /&gt;The groups on the left are the organizations in the area with links to the site and a brief description. The events in the center provides the main content that brings people to the site. The rest of the site is a community where members can blog; ask questions in the forums; view videos, presentations, and/or photos from past local events; and connect with other members in the area.&lt;br /&gt;&lt;br /&gt;Please provide feedback of all kinds as we plan to launch soon.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Until next time,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4532888617894267428?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/3MQLkm7NYfg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4532888617894267428/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4532888617894267428&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4532888617894267428" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4532888617894267428" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/3MQLkm7NYfg/south-florida-information-security.html" title="South Florida Information Security Community" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/04/south-florida-information-security.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2982881692002797274</id><published>2010-04-13T02:08:00.002-04:00</published><updated>2010-04-13T02:36:37.927-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida ISSA April 15th Meeting</title><content type="html">&lt;span class="Apple-style-span"   style="  color: rgb(51, 51, 51); line-height: 18px; font-family:Arial, Helvetica, sans-serif;font-size:12px;"&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;The South Florida ISSA April 2010 meeting will be held on April 15, 2010 from 3:30pm - 5:30pm at Nova Southeastern University - Carl DeSantis Bldg - Room &lt;strong&gt;TBA&lt;/strong&gt;.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;As always, two great talks lined up. Daniel Molina from Kaspersky will talk on the cyber-threats that matter to your business followed by Kevin Noble's Tool Talk on security visualization.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;Talk Title: Protecting Against Cyber-threats That Matter to your Business&lt;/strong&gt;&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;IT Departments, unbeknownst to them, are empowering cyber-crime. Kaspersky Lab will present the 7 things  that IT may be doing in your organization to enable cybercrime.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;Daniel J. Molina, CISSP,&lt;/strong&gt; is a Field Marketing Manager for Kaspersky Lab, and is considered a thought leader in the security arena. His view on security maturity has made him a sought-after resource to help explain and justify, in business terms, what users, businesses, and government entities require.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;Tool Talk Title: Security Visualization&lt;/strong&gt;&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;This talk will cover how to convey information security data in a graphical or visualize form.  Visualized Data can be created for systems, networks, timelines, and important security concepts.  Kevin will demonstrate the value of tools that run the gambit from excel and visio to mindmaps and directed node graphs, GNUplot.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;This will not be a powerpoint slideshow but will demonstrate as many of the tools and instances where these tools can best represent the information. In some situations, visualized data or graphing does not get the point across, and time permitting we will look at instances of failure and not just success.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;Kevin Noble&lt;/strong&gt; has been an active member of SFISSA for 7 years and has present on a wide range of topics from malware analysis to VoIP security.  Kevin is the Director of Engagement Services for Terremark’s Secure Information Services and leads an experienced specialized team in the areas of incident response, computer intrusion and various aspects of vulnerability assessments including penetration testing.  Kevin and his team respond to clients needs around the world in the areas of medicine, finance, manufacturing, education, and government services.&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;a href="http://www.sfissa.org/index.php?option=com_dtregister&amp;amp;eventId=6&amp;amp;Itemid=&amp;amp;task=event_register&amp;amp;type=reg_individual" target="_blank" style="color: rgb(51, 51, 51); text-decoration: underline; "&gt;&lt;em&gt;&lt;strong&gt;CLICK HERE TO REGISTER&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;em&gt;&lt;strong&gt;FREE CPE CREDITS! &lt;/strong&gt;Did you know you earn &lt;strong&gt;2 CPE&lt;/strong&gt; credits for attending an ISSA Meeting?  If you are a CISSP and you provide your CISSP number at registration, we will submit your CPE credits automatically for you.&lt;br /&gt;&lt;/em&gt;&lt;/p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;&lt;strong&gt;&lt;em&gt;This event will be held at:&lt;/em&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;&lt;em&gt;NOVA SOUTHEASTERN UNIVERSITY&lt;br /&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;Room TBA, &lt;/strong&gt;&lt;strong&gt;&lt;em&gt;Carl DeSantis Building, Main Davie Campus&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;p style="margin-top: 1em; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;strong&gt;&lt;em&gt;3301 College Ave Fort Lauderdale, FL 33314-7796&lt;br /&gt;Phone: 800-541-NOVA (6682)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2982881692002797274?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/FKXbcSb1JSQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2982881692002797274/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2982881692002797274&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2982881692002797274" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2982881692002797274" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/FKXbcSb1JSQ/south-florida-issa-april-15th-meeting.html" title="South Florida ISSA April 15th Meeting" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/04/south-florida-issa-april-15th-meeting.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2414824432010287724</id><published>2010-04-07T20:24:00.002-04:00</published><updated>2010-04-07T20:26:32.754-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida HIMSS Event 4/8/10</title><content type="html">I will be speaking tomorrow, April 8th, 2010 at the South Florida HIMSS event on Emerging Threats to Infrastructure followed by a panel discussion. Here is the info:&lt;br /&gt;&lt;br /&gt;Join us for our next SFLHIMSS meeting on Apr. 8, 2010 from 5:30 PM - 8:00 PM at VITAS and hear what the industry experts have to say about IT Security.&lt;br /&gt;Location:&lt;br /&gt;Vitas&lt;br /&gt;100 South Biscayne Blvd.&lt;br /&gt;Suite 1700&lt;br /&gt;Miami, FL 33131&lt;div&gt;&lt;br /&gt;Speakers include:&lt;br /&gt;G. Mick Walsh, U.S. Secret Service, Miami Electronic Crimes Task Force, Miami Field Office&lt;br /&gt;Gregorio Chavarria, CIO Miami Police Department&lt;br /&gt;Fernando Martinez, Chief Technology &amp;amp; Security Officer, Broward Health&lt;br /&gt;Jorge Orchilles, Security Analyst, Terremark Worldwide, Inc.&lt;br /&gt;Gary Reiss, Director of Security, Memorial Healthcare System - South Campus&lt;br /&gt;&lt;br /&gt;We will also have a comprehensive panel discussion where you can ask the experts about their experience and recommendations.&lt;br /&gt;More information will be on &lt;a href="http://www.sflhimss.org" target="_blank"&gt;our website&lt;/a&gt; to register for the event.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2414824432010287724?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/edvIo31atr0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2414824432010287724/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2414824432010287724&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2414824432010287724" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2414824432010287724" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/edvIo31atr0/south-florida-himss-event-4810.html" title="South Florida HIMSS Event 4/8/10" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/04/south-florida-himss-event-4810.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-7793251731057949470</id><published>2010-03-30T16:53:00.002-04:00</published><updated>2010-03-30T16:56:06.898-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Out of band Microsoft patch for Internet Explorer</title><content type="html">Microsoft released a cumulative security update which resolves nine privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx" target="_blank"&gt;So patch now!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights as &lt;a href="http://www.orchilles.com/2010/03/windows-7-is-safer-as-standard-user.html" target="_blank"&gt;reported earlier today.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This security update is rated critical for all supported releases of Internet Explorer:&lt;br /&gt;Internet Explorer 5.01&lt;br /&gt;Internet Explorer 6 SP1&lt;br /&gt;Internet Explorer 6 on Windows clients&lt;br /&gt;Internet Explorer 7&lt;br /&gt;Internet Explorer 8 on Windows clients.&lt;br /&gt;For Internet Explorer 6 on Windows servers, this update is rated Important. And for Internet Explorer 8 on Windows servers, this update is rated Moderate.&lt;br /&gt;&lt;br /&gt;The security update addresses these vulnerabilities by modifying the way that Internet Explorer verifies the origin of scripts and handles objects in memory, content using encoding strings, and long URL.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Till next time,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-7793251731057949470?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/YF4vRR4f98k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/7793251731057949470/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=7793251731057949470&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7793251731057949470" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7793251731057949470" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/YF4vRR4f98k/out-of-band-microsoft-patch-for.html" title="Out of band Microsoft patch for Internet Explorer" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/out-of-band-microsoft-patch-for.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-7196630205659815665</id><published>2010-03-30T09:57:00.002-04:00</published><updated>2010-03-30T10:37:02.746-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Windows 7 is safer as a standard user</title><content type="html">This should be common sense and not require a whole research paper but &lt;a href="http://www.beyondtrust.com/downloads/whitepapers/documents/wp039_BeyondTrust_2009_Microsoft_Vulnerability_Analysis.pdf" target="_blank"&gt;Beyond Trust released a study&lt;/a&gt; stating that Windows 7 is safer when using it as a standard user. &lt;div&gt;I highlighted this fact in my &lt;a href="http://www.amazon.com/Microsoft-Windows-Administrators-Reference-Upgrading/dp/1597495611/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1269959676&amp;amp;sr=8-1" target="_blank"&gt;book&lt;/a&gt; but would like to share the results of the study as well:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.blogcdn.com/www.engadget.com/media/2010/03/30mar10iuob23ts.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 600px; height: 275px;" src="http://www.blogcdn.com/www.engadget.com/media/2010/03/30mar10iuob23ts.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;Microsoft and their partners regularly identify new security vulnerabilities in Microsoft software. In 2009 Microsoft published nearly 75 security bulletins documenting and providing patches for nearly 200 vulnerabilities. By examining all of the published Microsoft vulnerabilities in 2009 and all of the published Windows 7 vulnerabilities to date, this report quantifies the continued effectiveness of removing administrator rights at mitigating vulnerabilities in Microsoft software.&lt;br /&gt;Key findings from this report show that removing administrator rights will better protect companies against the exploitation of:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;90% of Critical Windows 7 vulnerabilities reported to date&lt;/li&gt;&lt;li&gt;100% of Microsoft Office vulnerabilities reported in 2009&lt;/li&gt;&lt;li&gt;94% of Internet Explorer and 100% of IE 8 vulnerabilities reported in 2009&lt;/li&gt;&lt;li&gt;64% of all Microsoft vulnerabilities reported in 2009&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;So please, use a standard user for day to day use like most Mac and *nix users do!&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-7196630205659815665?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/ObojHoqfUwY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/7196630205659815665/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=7196630205659815665&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7196630205659815665" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7196630205659815665" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/ObojHoqfUwY/windows-7-is-safer-as-standard-user.html" title="Windows 7 is safer as a standard user" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/windows-7-is-safer-as-standard-user.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2321726676079260057</id><published>2010-03-30T08:51:00.004-04:00</published><updated>2010-03-30T09:00:10.020-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida OWASP Meeting 3/31/2010</title><content type="html">I am looking forward to the &lt;a href="http://www.owasp.org/index.php/Miami_Ft_Lauderdale" target="_blank"&gt;South Florida OWASP&lt;/a&gt; meeting and hanging out with the local InfoSec people tomorrow Wednesday March 31, 2010 at 6pm at Nova Southeastern University Carl DeSantis Building Room 1124.&lt;div&gt;&lt;br /&gt;&lt;div&gt;The presentation is titled: &lt;b&gt;Adon't be an Adobe victim: An overview of how recent Adobe-related flaws affect your web application by Josh Stabiner. &lt;/b&gt;The talk will examine recent threats posed by PDF and Flash vulnerabilities to web applications and users. It will also examine ways to mitigate the potential threats to organizations due to these vulnerabilities.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Josh Stabiner is a manager in Ernst &amp;amp; Young's Advanced Security Center specializing in attack and penetration advisory services. He manages and executes assessments of web applications, external, internal and wireless networks, as well as physical security and social engineering. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hope to see you there,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2321726676079260057?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/QOK_ZCeAz9Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2321726676079260057/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2321726676079260057&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2321726676079260057" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2321726676079260057" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/QOK_ZCeAz9Y/south-florida-owasp-meeting-3312010.html" title="South Florida OWASP Meeting 3/31/2010" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/south-florida-owasp-meeting-3312010.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4881717833191041965</id><published>2010-03-23T00:22:00.002-04:00</published><updated>2010-03-23T00:30:17.670-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><title type="text">Final edits in! Microsoft Windows 7 Administrator's Reference</title><content type="html">Today I turned in the final revisions and edits to my first book coming out in the end of April: &lt;b&gt;Microsoft Windows 7 Administrator's Reference&lt;/b&gt;! If you are a Windows power user or system administrator or want to be one this is the book for you!&lt;div&gt;It is available for pre-order and purchase at:&lt;br /&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.amazon.com/Microsoft-Windows-Administrators-Reference-Upgrading/dp/1597495611/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1269318188&amp;amp;sr=8-1" target="_blank"&gt;Amazon&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.syngress.com/information-security-and-system-administrators/Microsoft-Windows-7-Administrator-s-Reference/" target="_blank"&gt;Syngress Publishing&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.elsevier.com/wps/find/bookdescription.cws_home/721442/description#description" target="_blank"&gt;Elsevier&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Writing a book and getting it published is a long journey but I can say I am one step closer to making this dream a reality. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Till next time,&lt;/div&gt;&lt;div&gt;Jorge Orchilles&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4881717833191041965?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/Qg64TqwSvR0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4881717833191041965/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4881717833191041965&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4881717833191041965" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4881717833191041965" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/Qg64TqwSvR0/final-edits-in-microsoft-windows-7.html" title="Final edits in! Microsoft Windows 7 Administrator's Reference" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/final-edits-in-microsoft-windows-7.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-1864229172014758220</id><published>2010-03-20T14:47:00.004-04:00</published><updated>2010-03-20T15:04:45.241-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida Information Security Events - March/April 2010</title><content type="html">Until I find another portal or means to share South Florida Infomation Security events I will use this forum.&lt;br /&gt;&lt;br /&gt;This is the March and April 2010 edition:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;March 27, 2010 - 1pm - &lt;a href="http://hackmiami.org/" target="_blank"&gt;Hack Miami&lt;/a&gt; - Pizza Mansion&lt;/li&gt;&lt;li&gt;March 31, 2010 - 6pm - &lt;a href="http://www.owasp.org/index.php/Miami_Ft_Lauderdale" target="_blank"&gt;South Florida OWASP&lt;/a&gt; meeting - Talk titled: &lt;span style="font-style:italic;"&gt;Adon't be an Adobe victim: An overview of how recent Adobe-related flaws affect your web application&lt;/span&gt; by Josh Stabiner at Nova Southeastern University&lt;/li&gt;&lt;li&gt;April 8, 2010 - 5:30pm - &lt;a href="http://sflhimss.org/" target="_blank"&gt;South Florida HIMSS&lt;/a&gt; - IT Security - I will be speaking on Emerging Threats to Infrastructure for Health Care IT - Vitas in Downtown Miami&lt;/li&gt;&lt;li&gt;April 10, 2010 - 1pm - &lt;a href="http://hackmiami.org/" target="_blank"&gt;Hack Miami&lt;/a&gt; - I will be talking on Emerging Threats and doing a few live demos. - Location TBA&lt;/li&gt;&lt;li&gt;April 15, 2010 - 3:30pm - &lt;a href="http://www.sfissa.org/" target="_blank"&gt;South Florida ISSA&lt;/a&gt; - Nova Southeastern University&lt;/li&gt;&lt;li&gt;April 17-23 - &lt;a href="http://www.misti.com/default.asp?page=65&amp;amp;Return=70&amp;amp;ProductID=5539&amp;amp;LS=infosecworld" target="_blank"&gt;InfoSec World 2010&lt;/a&gt; - Orlando, FL&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-1864229172014758220?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/CnVLRZJRMDw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/1864229172014758220/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=1864229172014758220&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/1864229172014758220" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/1864229172014758220" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/CnVLRZJRMDw/south-florida-information-security.html" title="South Florida Information Security Events - March/April 2010" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/south-florida-information-security.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-1328038128639812301</id><published>2010-03-20T14:07:00.004-04:00</published><updated>2010-03-20T14:44:00.186-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Podcasts</title><content type="html">Jorge Orchilles is now &lt;a href=http://en.wikipedia.org/wiki/Podcast" target="_blank"&gt;podcasting&lt;/a&gt;! I am co-hosting the &lt;a href="http://smbminute.com/" target="_blank"&gt;SMB Minute&lt;/a&gt; podcast with Tim Krabec and Aaron. The SMB Minute podcast is aimed at the Small and Medium Business market. Whether you are the designated IT guy/gal or own your own business, this podcast will give you an insight of what is going on in the Information Technology/Systems/Security world. You can subscribe to it on iTunes and it will automatically sync with your iPod every week when the podcast is released. Season 2 will begin release this week.&lt;br /&gt;&lt;br /&gt;These are other podcasts I listen to in no particular order:&lt;br /&gt;&lt;a href="http://www.sans.org/audiocasts/" target="_blank"&gt;SANS Audiocasts&lt;/a&gt; with John Strand&lt;br /&gt;&lt;a href="http://pauldotcom.com/" target="_blank"&gt;PaulDotCom Security Weekly&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.exoticliability.com/" target="_blank"&gt;Exotic Liability&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.social-engineer.org/framework/Podcast" target="_blank"&gt;Social Engineer&lt;/a&gt;&lt;br /&gt;&lt;a href="http://securityjustice.com/" target="_blank"&gt;Security Justice&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.hackernews.com/" target="_blank"&gt;The Hacker News Network&lt;/a&gt;&lt;br /&gt;&lt;a href="http://netsecpodcast.com/" target="_blank"&gt;Network Security Podcast&lt;/a&gt;&lt;br /&gt;&lt;a href="http://threatpost.com/" target="_blank"&gt;ThreatPost&lt;/a&gt;&lt;br /&gt;&lt;a href="http://itknowledgeexchange.techtarget.com/security-wire-weekly/" target="_blank"&gt;Security Wire Weekly&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And if you want to hear almost all of these people doing a podcast at ShmooCon 2010, check out the &lt;a href="http://www.odeo.com/episodes/25645226-Shmoocon-2010-Podcaster-Meetup" target="_blank"&gt;Podcaster's Meetup&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-1328038128639812301?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/Yjxwcv8YCOk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/1328038128639812301/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=1328038128639812301&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/1328038128639812301" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/1328038128639812301" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/Yjxwcv8YCOk/podcasts.html" title="Podcasts" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/podcasts.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-83930467113021204</id><published>2010-03-18T18:44:00.009-04:00</published><updated>2010-03-18T19:06:54.143-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Emerging Threats to Infrastructure</title><content type="html">I recently presented my talk on Emerging Threats to Infrastructure to the &lt;a href="http://www.isaca-jax.org/" target="_blank"&gt;Jacksonville ISACA chapter&lt;/a&gt; and targeted it for auditors. Thanks to all that made that possible and Blue Cross Blue Shield of Florida for hosting the event (loved the campus). It is the first time I present this topic and will be modifying it for a presentation April 8th for the &lt;a href="http://www.sflhimss.org/" target="_blank"&gt;South Florida HIMMS chapter.&lt;/a&gt; I will also be presenting it April 10th at the &lt;a href="http://www.hackmiami.org/" target="_blank"&gt;Hack Miami&lt;/a&gt; hacker space and will make it much more technical with include more technical demos.&lt;br /&gt;&lt;br /&gt;I recorded the first talk and am debating whether to post now or after the other presentations although they will be different.&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_3471502"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/jorgeorchilles/emerging-threats-to-infrastructure-3471502" title="Emerging Threats to Infrastructure"&gt;Emerging Threats to Infrastructure&lt;/a&gt;&lt;/strong&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=emergingthreatsjorgeorchilles-100318172000-phpapp01&amp;stripped_title=emerging-threats-to-infrastructure-3471502" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=emergingthreatsjorgeorchilles-100318172000-phpapp01&amp;stripped_title=emerging-threats-to-infrastructure-3471502" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/jorgeorchilles"&gt;Jorge Orchilles&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-83930467113021204?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/6D7dmchDPVw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/83930467113021204/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=83930467113021204&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/83930467113021204" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/83930467113021204" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/6D7dmchDPVw/emerging-threats-to-infrastructure.html" title="Emerging Threats to Infrastructure" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2010/03/emerging-threats-to-infrastructure.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-828605000404543704</id><published>2010-01-14T13:19:00.003-05:00</published><updated>2010-01-14T13:36:36.007-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">South Florida Information Security</title><content type="html">South Florida has a great Information Security community with different organizations targeting different aspects of the field. 2010 promises many good InfoSec events, conferences, and meetings in the area.&lt;br /&gt;Here is my list of South Florida Information Security events with the name, date, and topic:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://guest.cvent.com/EVENTS/Info/Invitation.aspx?i=c127809d-764c-4851-ad4e-2b0ff355e255" target="_blank"&gt;South Florida ISACA 3rd Annual WOW! Event&lt;/a&gt; - January 15, 2010 - Security and Governance&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hackmiami.org/" target="_blank"&gt;Hack Miami&lt;/a&gt; - January 16, 2010 and every other Saturday - Hacker Space&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sfissa.org/index.php/sfissa-mm-events/sfissa-mm-monthly-meetings/61-january-2010-meeting" target="_blank"&gt;South Florida ISSA January 2010 Meeting&lt;/a&gt; - January 21, 2010 and every 3rd Thursday of the month - Best Practices for Security Incident and Case Management&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sfissa.org/index.php/sfissa-mm-events/sfissa-mm-local-events/67-owasp-south-florida-jan-27-2010" target="_blank"&gt;South Florida OWASP January 2010 Meeting&lt;/a&gt; - January 27, 2010 - Zeus Botnet Research Presentation&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sans.org/sans-2010/" target="_blank"&gt;SANS 2010&lt;/a&gt; - March 6-15, 2010 - InfoSec Training&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.bankinfo-securitygroup.net/" target="_blank"&gt;2010 Bank Info-Security Group Conference&lt;/a&gt; - April 12-15, 2010 - Banking InfoSec&lt;/li&gt;&lt;li&gt;&lt;a href="http://conference.first.org/About/overview.aspx" target="_blank"&gt;22nd Annual FIRST Conference&lt;/a&gt; - June 13-18, 2010 - Forensics&lt;/li&gt;&lt;/ul&gt;Seven events already planned and the year is just getting started! Note that South Florida ISSA, OWASP, and Hack Miami have one or two events each month.&lt;br /&gt;&lt;br /&gt;If I am missing any other InfoSec related event in the South Florida area please let me know.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-828605000404543704?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/vtW36ay-yzw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/828605000404543704/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=828605000404543704&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/828605000404543704" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/828605000404543704" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/vtW36ay-yzw/south-florida-information-security.html" title="South Florida Information Security" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/01/south-florida-information-security.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4401349792469992005</id><published>2010-01-04T16:56:00.005-05:00</published><updated>2010-01-04T17:54:43.324-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><title type="text">Windows 7 Book Announcement and "God Mode"</title><content type="html">I have been slacking on the blog posts recently due to a few projects I am/was working on.&lt;br /&gt;&lt;br /&gt;First I would like to announce that I am finishing a Windows 7 book titled: &lt;a href="http://www.syngress.com/information-security-and-system-administrators/Microsoft-Windows-7-Administrator-s-Reference/"&gt;Microsoft Windows 7 Administrator's Reference&lt;/a&gt;. My publisher is &lt;a href="http://www.syngress.com/" target="_blank"&gt;Syngress&lt;/a&gt; and the book is expected to be available March 2010.&lt;br /&gt;&lt;br /&gt;Second, I have completed the &lt;a href="http://business.fiu.edu/chapman/msmis/" target="_blank"&gt;Master's of Science in Management Information Systems program at Florida International University&lt;/a&gt;. This program is aimed at working professionals and people with experience in both management and information systems. I recommend this program to anyone in the South Florida area. It is Saturday's only for a full year and worth every penny.&lt;br /&gt;&lt;br /&gt;Lastly, as I have been working on the Windows 7 book I was waiting to release the how-to for Windows 7 GodMode. Since news and blogs are releasing it already, I decided what the heck, here it is:&lt;br /&gt;&lt;br /&gt;Microsoft developers included a so called “God Mode” in Windows 7. In reality this is not a mode but a simple and single container with multiple shortcuts to Windows 7 options that are available through other methods. This may be helpful for administrators and power users alike to configure and manage single Windows 7 desktops.&lt;br /&gt;&lt;br /&gt;To create a God Mode shortcut:&lt;br /&gt;1.    Right click on the Desktop or anywhere in Windows Explorer where you would like this shortcut.&lt;br /&gt;2.    Select New – Folder&lt;br /&gt;3.    Name the folder: GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}&lt;br /&gt;4.    The folder icon will change to a Control Panel icon&lt;br /&gt;&lt;br /&gt;To use God Mode, simply double click the Control Panel icon just created called “GodMode”. A Windows Explorer window will open with shortcuts for many different configuration options in Windows 7. All of these options are available through other methods, mostly though the standard Control Panel shortcuts.&lt;br /&gt;&lt;br /&gt;Warning:&lt;br /&gt;The “GodMode” hack appears to work on Windows 7 32-bit and 64-bit versions. It also seems to work on 32-bit versions of Windows Vista and Windows Server 2008. Many users have reported problems with “GodMode” in 64-bit editions of Windows Vista and Windows Server 2008. If “GodMode” crashes the system, rebooting to safe mode and removing the shortcut should solve the issues.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4401349792469992005?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/k29vyVWvrOs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4401349792469992005/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4401349792469992005&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4401349792469992005" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4401349792469992005" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/k29vyVWvrOs/windows-7-book-announcement-and-god.html" title="Windows 7 Book Announcement and &quot;God Mode&quot;" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2010/01/windows-7-book-announcement-and-god.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-7003360985489779508</id><published>2009-11-03T16:05:00.005-05:00</published><updated>2009-11-03T16:30:58.031-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">July 4th DDOS Revisited</title><content type="html">Remember the &lt;a href="http://www.orchilles.com/2009/07/july-us-and-south-korea-ddos-attacks.html" target="_blank"&gt;July US and South Korea DDOS Attacks&lt;/a&gt; I reported on back in July?&lt;br /&gt;&lt;br /&gt;According to South Korea the attacks were launched from a Chinese IP leased to North Korea's Ministry of Post and Telecommunications. MSNBC reports &lt;a href="http://www.msnbc.msn.com/id/33550486/ns/technology_and_science-security/" target="_blank"&gt;North Korea source of DDOS&lt;/a&gt; and The Sydney Morning Herald&lt;a href="http://news.smh.com.au/breaking-news-technology/skorean-spy-chief-blames-nkorea-for-cyber-attacks-20091030-hp9n.html" target="_blank"&gt;report of South Korea Spy Chief blames North Korea&lt;/a&gt; and &lt;a href="http://news.smh.com.au/breaking-news-technology/skorea-seeks-chinese-help-to-track-cyber-attacks-20091102-htis.html" target="_blank"&gt;South Korea seeks Chinese help tracking DDOS&lt;/a&gt; all suggest two things:&lt;br /&gt;&lt;br /&gt;1. North Korea was behind the attacks.&lt;br /&gt;2. North Korea is preparing an army of cyber warfare.&lt;br /&gt;&lt;br /&gt;If we remember back to July 4th, North Korea was immediately blamed for this attack. After real research and removing the FUD, Information Security Professionals determined this could not be confirmed. The most that I remember was 6 command and control machines in Europe with an expert suggesting the master server located in Britain. Now, somehow, South Korean Spy Chief reports it was the North? I want proof!&lt;br /&gt;&lt;br /&gt;A quote I do believe is true from MSNBC: "South Korean media reported at the time that North Korea runs an Internet warfare unit that tries to hack into U.S. and South Korean military networks to gather confidential information and disrupt service, and that the regime has between 500 and 1,000 hacking specialists."&lt;br /&gt;&lt;br /&gt;In other words, cyber warfare is real!&lt;br /&gt;&lt;br /&gt;Thankfully, the US government is doing something about it:&lt;br /&gt;&lt;a href="http://www.msnbc.msn.com/id/33557123/ns/technology_and_science-security/" target="_blank"&gt;MSNBC: Security center opens to battle cyber attack&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.tgdaily.com/security-features/44495-us-government-opens-9m-cyber-security-center" target="_blank"&gt;TGDaily: US Government opens $9m Cyber Security Center&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;However, the US government alone is not enough! Everyone must be in on this. It begins with keeping your own computer secure, then your friends and families.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-7003360985489779508?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/XYsAQmaUm9A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/7003360985489779508/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=7003360985489779508&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7003360985489779508" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/7003360985489779508" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/XYsAQmaUm9A/july-4th-ddos-revisited.html" title="July 4th DDOS Revisited" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2009/11/july-4th-ddos-revisited.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-4044888681923844182</id><published>2009-10-06T09:26:00.003-04:00</published><updated>2009-10-06T10:00:03.353-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Time to change your password</title><content type="html">The BBC has released these three articles in the last two days suggesting that over 20,000 Microsoft web-based email accounts have been hacked. This includes Hotmail and Live email accounts. The third article suggests that GMail is being targeted as well:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/8291268.stm" target="_blank"&gt;Phishing attacks target Hotmail users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/8292928.stm" target="_blank"&gt;Google targeted in e-mail scam&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/8292299.stm" target="_blank"&gt;Scam hits more email accounts&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Here are some best practices for passwords and email use:&lt;br /&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;Do change your passwords on a regular basis (every six months or so)&lt;/li&gt;&lt;li&gt;Do use long complex pass-phrases rather than passwords where you can&lt;/li&gt;&lt;li&gt;Do change all of your passwords if you notice something suspicious&lt;/li&gt;&lt;li&gt;Do take identity theft seriously&lt;/li&gt;&lt;li&gt;Do use up-to-date anti-virus and a firewall&lt;/li&gt;&lt;li&gt;Do NOT click on links in emails, &lt;span style="font-weight: bold;"&gt;EVER&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Do NOT use the same password at multiple sites&lt;/li&gt;&lt;/ul&gt;Hope your accounts have not been compromised!&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-4044888681923844182?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/8JQtxyqKqM0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/4044888681923844182/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=4044888681923844182&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4044888681923844182" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/4044888681923844182" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/8JQtxyqKqM0/time-to-change-your-password.html" title="Time to change your password" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2009/10/time-to-change-your-password.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-6118104346209557252</id><published>2009-09-21T17:35:00.001-04:00</published><updated>2009-09-21T17:37:21.205-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Windows 7 Security Video</title><content type="html">I have posted the video of the Windows 7 Security presentation I did for South Florida ISSA. Enjoy&lt;br /&gt;&lt;br /&gt;&lt;object width="400" height="300"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=6673668&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=6673668&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;p&gt;&lt;a href="http://vimeo.com/6673668"&gt;Windows 7 Security Presentation&lt;/a&gt; from &lt;a href="http://vimeo.com/jorgeorchilles"&gt;Jorge Orchilles&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-6118104346209557252?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/l4xiVp8Zllc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/6118104346209557252/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=6118104346209557252&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6118104346209557252" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6118104346209557252" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/l4xiVp8Zllc/windows-7-security-video.html" title="Windows 7 Security Video" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2009/09/windows-7-security-video.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-5184310465229346081</id><published>2009-09-18T14:27:00.002-04:00</published><updated>2009-09-18T14:29:22.470-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IT" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Windows 7 Security Presentation</title><content type="html">Yesterday I had the honor of presenting to the &lt;a href="http://www.sfissa.org/" target="_blank"&gt;South Florida ISSA&lt;/a&gt; my talk on Windows 7 Security. Here is the presentation.&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px;text-align:left" id="__ss_2019089"&gt;&lt;a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/jorgeorchilles/windows-7-security-2019089" title="Windows 7 Security"&gt;Windows 7 Security&lt;/a&gt;&lt;object style="margin:0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=windows7securitypresentation-090918132224-phpapp02&amp;amp;stripped_title=windows-7-security-2019089"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=windows7securitypresentation-090918132224-phpapp02&amp;amp;stripped_title=windows-7-security-2019089" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"&gt;View more &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/jorgeorchilles"&gt;jorgeorchilles&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-5184310465229346081?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/Zcf2EtufwzQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/5184310465229346081/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=5184310465229346081&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/5184310465229346081" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/5184310465229346081" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/Zcf2EtufwzQ/windows-7-security-presentation.html" title="Windows 7 Security Presentation" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2009/09/windows-7-security-presentation.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-6540711936362000115</id><published>2009-08-28T01:49:00.004-04:00</published><updated>2009-08-28T01:53:33.888-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">2010 US Census Information and Awareness</title><content type="html">I work in security so am allowed to be ultra paranoid. However I think everyone should be a little aware of the 2010 US Census to not be victims of fraud or Identity theft. Additionally one should spread the awareness in good faith to avoid friends, family, or loved ones to be victimized.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Malicious Viewpoint &lt;/span&gt;&lt;br /&gt;Since everyone knows there is a Census and people are going to knock on doors, I will dress like a Census worker (what do they look like anyways) and go around a neighborhood knocking on doors. When someone opens I will be extremely nice (social engineering?), ask for all of the person's information (including Social? Credit Card? Bank account?), and then proceed to perform identity theft, credit card fraud, etc!&lt;br /&gt;Obviously this is a fictional scenario but I am sure in practice one will get a LOT of information.&lt;br /&gt;&lt;br /&gt;So don't let it happen to you or your friends, family, etc... continue reading, copied from a source I can't cite at the moment.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2010 U.S. Census Cautions to avoid Fraud or Identity Theft&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;With the U.S. Census process beginning, the Better Business Bureau (BBB) advises people to be cooperative, but cautious, so as not to become a victim of fraud or identity theft. The first phase of the 2010 U.S. Census is under way as workers have begun verifying the addresses of households across the country. Eventually, more than 140,000 U.S. Census workers will count every person in the United States and will gather information about every person living at each address including name,  age, gender, race, and other relevant data. The big question is - how do you tell the difference between a U.S. Census worker and a con artist? BBB offers the following advice:&lt;br /&gt;&lt;br /&gt;A· If a U.S. Census worker knocks on your door, they will have a badge, a handheld device, a Census Bureau canvas bag, and a confidentiality notice. Ask to see their identification and their badge before answering their questions. However, you should never invite anyone you don't know into your home.&lt;br /&gt;&lt;br /&gt;B· Census workers are currently only knocking on doors to verify address information. Do not give your Social Security number, credit card or banking information to anyone, even if they claim they need it for the U.S. Census. While the Census Bureau might ask for basic financial information, such as a salary range, it will not ask for Social Security, bank account, or credit card numbers nor will employees solicit donations.&lt;br /&gt;&lt;br /&gt;Eventually, Census workers may contact you by telephone, mail, or in person at home. However, they will not contact you by Email, so be on the lookout for Email scams impersonating the Census. Never click on a link or open any attachments in an Email that are supposedly from the U.S. Census Bureau.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-6540711936362000115?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/Kj6lPmzL0bY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/6540711936362000115/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=6540711936362000115&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6540711936362000115" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6540711936362000115" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/Kj6lPmzL0bY/2010-us-census-information-and.html" title="2010 US Census Information and Awareness" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2009/08/2010-us-census-information-and.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-6503331587833566544</id><published>2009-07-31T05:51:00.004-04:00</published><updated>2009-07-31T06:40:48.407-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">iPhone and SMS hack - what does it mean?</title><content type="html">Countless news articles are floating around about the iPhone and SMS hack. I will explain it here in "normal" terms and explain what all this means to you.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;br /&gt;Yesterday, Thursday 7/30/09, two security expert (also known as hackers), presented a way to hack an iPhone by sending it a specially made SMS (text) messages. This presentation was held at &lt;a href="http://blackhat.com/" target="_blank"&gt;Black Hat&lt;/a&gt; which is one of the largest hacker conference in the world. Since Wednesday all the buzz has been around this iPhone hack with a lot of speculation and rumors flying all over the place. Here are the facts I have captured.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;What is the hack?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;An attacker can send an iPhone or other vulnerable device a specially made SMS message. You will notice a single character, blank, or carrier SMS text coming from 611 or somewhere unknown. In the background the phone will be controlled by the attacker.&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;How does it work?&lt;/span&gt;&lt;br /&gt;The attack occurs by a memory corruption in the way the iPhone handles SMS messages. For the hack to work the attacker must send hundreds of SMS control messages which you do not see. You would only see one SMS message coming in. In the background you will be receiving the control messages that have the ability to do many different things.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;What can be done with this hack?&lt;/span&gt;&lt;br /&gt;An attacker could exploit this security hole to make calls, steal data, send text messages, and do more or less anything a person can do on their iPhone. Speculation around being able to put a virus on your phone before you can turn it off have been thrown around as well. Basically not a good thing if you receive a message like this.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Does this only affect the iPhone?&lt;/span&gt;&lt;br /&gt;No this hack works in conjunction with the way GSM networks work. GSM networks in the USA include AT&amp;amp;T and T-Mobile. The hackers also showed an Android phone (which Google claims they have already fixed the issues) and a Sony Ericsson phone beeing hacked in a live demonstration. Here are the&lt;a href="http://www.informationweek.com/blog/main/archives/2009/07/blackhat_bombsh.html;jsessionid=ZZIPAFM0RYV3KQSNDLRSKH0CJUNN2JVN" target="_blank"&gt; images&lt;/a&gt;. BlackBerry's have not been addressed but it is doubtful this hack works on those devices.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Who can do this?&lt;br /&gt;&lt;/span&gt;Currently only a limited amount of hackers have the capability to do this. However they will be releasing a tool that uses these vulnerabilities to the general public on August 15th through Cydia (the App Store for Jailbroken iPhones). So consider yourself semi-safe until that day.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What about Apple? Do they know about this? Fixing it?&lt;br /&gt;&lt;/span&gt;According to the researchers they notified Apple as long as 6 weeks ago about this vulnerability. Apple claims to be working on a fix. The hackers also notified the GSM alliance which has been working to fix this issue as well. Our best hope is that the fixes come out before August 15th.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;How do I know this is happening to me and what can I do?&lt;/span&gt;&lt;br /&gt;You will receive a text message from 611 or a strange number that looks weird, it might have one character or a message like the example the hackers gave: "You've received a free $20 credit..." or "New settings received. Install?".&lt;span style="font-weight: bold;"&gt; If this happens to you the only thing you can do to stop it is to turn off your phone immediately!&lt;/span&gt; Even then it might be too late.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I am paranoid is there a fix now?&lt;br /&gt;&lt;/span&gt;The only claim to fix this now on the iPhone involves disabling SMS text messages altogether. You would need to jailbreak your phone and log in via SSH. If those two sentences made sense, feel free to &lt;a href="http://www.quickpwn.com/2009/07/iphone-virus-patch.html" target="_blank"&gt;read the how to over at quickpwn.com&lt;/a&gt;.&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Further Reading&lt;/span&gt;&lt;br /&gt;News articles: &lt;a href="http://news.zdnet.com/2100-9595_22-326501.html?tag=nl.e539" target="_blank"&gt; ZDNet&lt;/a&gt; or &lt;a href="http://www.theiphoneblog.com/2009/07/30/black-hat-sms-attacks-iphones/" target="_blank"&gt;The iPhone Blog&lt;/a&gt; or &lt;a href="http://m.apnews.com/ap/db_16036/contentdetail.htm?contentguid=g0qyFbuM" target="_blank"&gt;AP News&lt;/a&gt;.&lt;br /&gt;White paper on &lt;a href="http://www.blackhat.com/presentations/bh-europe-09/Gassira_Piccirillo/BlackHat-Europe-2009-Gassira-Piccirillo-Hijacking-Mobile-Data-Connections-whitepaper.pdf" target="_blank"&gt;Hijacking Mobile Data Connections&lt;/a&gt; and a &lt;a href="http://it.toolbox.com/blogs/securitymonkey/live-blog-blackhat-2009-day-2-33168" target="_blank"&gt;detailed blog&lt;/a&gt; on the presentation.&lt;br /&gt;&lt;br /&gt;As you can see this can become a huge issue if Apple and GSM carriers do not fix the issue prior to August 15th. As soon as the newest iPhone software is released, update your phone, no questions asked. I will keep you updated on the latest findings.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-6503331587833566544?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/H-51eapfi9Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/6503331587833566544/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=6503331587833566544&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6503331587833566544" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/6503331587833566544" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/H-51eapfi9Y/iphone-and-sms-hack-what-does-it-mean.html" title="iPhone and SMS hack - what does it mean?" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.orchilles.com/2009/07/iphone-and-sms-hack-what-does-it-mean.html</feedburner:origLink></entry><entry><id>tag:blogger.com,1999:blog-4155089922457192489.post-2577892615725836367</id><published>2009-07-30T21:09:00.004-04:00</published><updated>2009-07-30T22:26:56.892-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title type="text">Following BlackHat from home - Day 2</title><content type="html">As Black Hat comes to an end we will begin to see all of it's content posted on the internet and have more than enough to read for the coming weeks. Today a lot has been released and I have filtered through most of the talks and presentations and would like to provide you with the best content organized in no order:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Apple iPhone and other GSM phone hack&lt;/span&gt; - This topic is hitting the news all over the place, here are the ones with the best content&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://it.toolbox.com/blogs/securitymonkey/live-blog-blackhat-2009-day-2-33168" target="_blank"&gt;Live Blog: Blackhat 2009 Day 2&lt;/a&gt; from Security Monkey &lt;- Best information on this topic&lt;/li&gt;&lt;li&gt;&lt;a href="http://news.zdnet.com/2100-9595_22-326501.html?tag=nl.e539" target="_blank"&gt;Introduction to the SMS hack&lt;/a&gt; the day prior to the presentation. Via ZDNet&lt;/li&gt;&lt;li&gt;A good &lt;a href="http://www.threatpost.com/blogs/researchers-reveal-fundamental-sms-flaws-black-hat" target="_blank"&gt;overview of the presentation&lt;/a&gt; from Threatpost.com&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.theiphoneblog.com/2009/07/30/black-hat-sms-attacks-iphones/" target="_blank"&gt;SMS attack is not just for the iPhone&lt;/a&gt; from theiphoneblog.com&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/blog/main/archives/2009/07/blackhat_bombsh.html;jsessionid=KJG1CUFHCADHUQSNDLRSKH0CJUNN2JVN" target="_blank"&gt;Images of the iPhone and Sony Ericsoon hack&lt;/a&gt; from Information Week.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Cloud Computing&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/blog/main/archives/2009/07/black_hat_resea_1.html;jsessionid=Q0LJELGPVQJUOQSNDLRSKHSCJUNN2JVN" target="_blank"&gt;Overview of Cloud Computing presentation by Alex Stamos&lt;/a&gt; via InformationWeek. Says the the term cloud computing is useless! Going to have to see this one for myself.&lt;/li&gt;&lt;li&gt;&lt;a href="http://i.cmpnet.com/infoweek/podcasts/TechRadarBlackHatAlexStamos.mp3" target="_blank"&gt;Link to podcast&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;US Cyber Security&lt;/span&gt; - the government really wants hackers to work for them!&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.internetnews.com/skerner/2009/07/post-1.html" target="_blank"&gt;Hackers: Uncle Sam wants you!&lt;/a&gt; via Internetnews.com&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.internetnews.com/skerner/2009/07/-from-the-fed-man.html" target="_blank"&gt;US falling behind on catching up with Cyber Security&lt;/a&gt; via Internetnews.com&lt;/li&gt;&lt;li&gt;Not part of Black Hat but have you heard of the &lt;a href="http://blog.internetnews.com/skerner/2009/07/-from-the-fed-man.html" target="_blank"&gt;US Cyber Security challenge&lt;/a&gt;? Three challenges aimed at recruiting the top 10,000 US Hackers!&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;SSL&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Summary of presentation to &lt;a href="http://www.theregister.co.uk/2009/07/30/universal_ssl_certificate/" target="_blank"&gt;spoof SSL certificates by Moxie&lt;/a&gt; via the Register&lt;/li&gt;&lt;li&gt;Video by Moxie on &lt;a href="https://media.blackhat.com/bh-usa-09/video/MARLINSPIKE/BHUSA09-Marlinspike-DefeatSSL-VIDEO.mov" target="_blank"&gt;More Tricks for Defeating SSL&lt;/a&gt; same presentation as previous.&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=218900008&amp;amp;cid=nl_DR_WEEKLY_H" target="_blank"&gt;PKI Hack Demonstrates flaws in digital certificate technology&lt;/a&gt; via darkreading.com presentation was by Dan Kaminsky&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Verisign &lt;a href="https://blogs.verisign.com/ssl-blog/2009/07/busy_day_at_black_hat.php" target="_blank"&gt;response to both SSL presentations&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Bonus blog by &lt;a href="http://www.schneier.com/blog/archives/2009/07/another_new_aes.html" target="_blank"&gt;Schneier on new AES Attack&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Parking Meters Hacked&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.pcworld.com/article/169376/meter_hackers_find_free_parking_in_san_francisco.html" target="_blank"&gt;San Francisco parking meters hacked&lt;/a&gt; via PC World&lt;/li&gt;&lt;li&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10300233-83.html?part=rss&amp;amp;subj=news&amp;amp;tag=2547-1_3-0-20" target="_blank"&gt;Second good article&lt;/a&gt; via cnet news, this one has pictures&lt;/li&gt;&lt;li&gt;&lt;a href="http://crypto.nsa.org/f-21/smart-parking-meters-bh.pdf"&gt;"Smart" Parking Meter Implementations, Globalism, and You&lt;/a&gt; presentation via crypto.nsa.org.&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.pcworld.com/article/169370/black_hat_researchers_find_free_parking_in_san_francisco.html" target="_blank"&gt;Pictures of presentation&lt;/a&gt; and small explanations thanks to PC World.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Misc&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://pwnie-awards.org/2009/awards.html" target="_blank"&gt;The Pwnie Award Winners&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=218900188&amp;amp;subSection=News" target="_blank"&gt;Mac OS X Rootkit Debuts&lt;/a&gt; via InformationWeek. Only a proof of concept.&lt;/li&gt;&lt;li&gt;Jeremiah Grossman presentation on &lt;a href="http://www.slideshare.net/jeremiahgrossman/mo-money-mo-problems-making-even-more-money-online-the-black-hat-way" target="_blank"&gt;Mo' Money Mo' Problems - Making even more money online the black hat way&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Other full day roundups and blogs&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Network World NetFlash: &lt;a href="http://www.networkworld.com/community/node/44006" target="_blank"&gt;Black Hat roundup&lt;/a&gt; (has repeat content from here, all links are NetworkWorld.com)&lt;/li&gt;&lt;li&gt;Security4all Blog: &lt;a href="http://blog.security4all.be/2009/07/day-2-collection-of-blackhat-articles.html" target="_blank"&gt;Day 2 collection of #blackhat articles&lt;/a&gt; Also some repeat content.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Follow &lt;a href="http://twitpicwall.com/?blackhat" target="_blank"&gt;live pictures&lt;/a&gt; from the event via TwitPicWall.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; When you are done catching up come back as DefCon is just getting started and more content will be posted as the conferences wrap up.&lt;br /&gt;&lt;br /&gt;Till next time,&lt;br /&gt;Jorge Orchilles&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4155089922457192489-2577892615725836367?l=www.orchilles.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JorgeOrchilles/~4/jZ4YhRV7az8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.orchilles.com/feeds/2577892615725836367/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=4155089922457192489&amp;postID=2577892615725836367&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2577892615725836367" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/4155089922457192489/posts/default/2577892615725836367" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/JorgeOrchilles/~3/jZ4YhRV7az8/following-blackhat-from-home-day-2.html" title="Following BlackHat from home - Day 2" /><author><name>Jorge Orchilles</name><uri>http://www.blogger.com/profile/17243003116362423749</uri><email>jorgeao@gmail.com</email><gd:extendedProperty xmlns:gd="http://schemas.google.com/g/2005" name="OpenSocialUserId" value="02600438946542446535" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.orchilles.com/2009/07/following-blackhat-from-home-day-2.html</feedburner:origLink></entry></feed>

