<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-15182237</id><updated>2024-03-07T04:52:11.099-05:00</updated><category term="Security"/><category term="Malware"/><category term="WV State Bar"/><category term="Data Breach"/><category term="Microsoft"/><category term="symantec"/><category term="0-day Mircrosoft"/><category term="Adobe"/><category term="Weak Passwords"/><category term="conflicker"/><category term="john strand"/><category term="Acrobat"/><category term="Antivirus2009"/><category term="Black Tuesday"/><category term="Breach Notification"/><category term="Cyber Security"/><category term="FBI"/><category term="PDFs"/><category term="Passwords"/><category term="PaulDotCom"/><category term="RBN"/><category term="SANS"/><category term="SQL Injection"/><category term="WV Record"/><category term="Windows Update"/><category term="cybercrime"/><category term="fake antivirus"/><category term="hackers"/><category term="malware servered via adserver"/><category term="304Geeks"/><category term="419 Scam"/><category term="60 Minutes"/><category term="ARP spoofing AV webserver javascript"/><category term="Appalachian Institute of Digital Evidence"/><category term="Daemon"/><category term="Dan Farmer"/><category term="Daniel Suarez"/><category term="Dictionary Attack"/><category term="Digital Evidence"/><category term="Electronic Discovery"/><category term="Elite"/><category term="Email"/><category term="Exchange"/><category term="FDA"/><category term="Facebook"/><category term="Fail"/><category term="FreedomTM"/><category term="Gonzalez"/><category term="Google Safe Browsing"/><category term="Gozi trojan"/><category term="Heartland"/><category term="Internet Investigations"/><category term="John Markoff"/><category term="John Sammons"/><category term="Kevin Metnick"/><category term="Louisville InfoSec"/><category term="Mac at 25"/><category term="Macintosh"/><category term="Mdropper"/><category term="Network Forensics"/><category term="Network Scan"/><category term="OWA"/><category term="Prolaw"/><category term="Russian Business Network"/><category term="SANS JBIG2 stream"/><category term="SATAN"/><category term="SET"/><category term="Security Bulletin Webcast Video"/><category term="Steve Jobs"/><category term="Sys Admin"/><category term="TJX"/><category term="The Long Now Foundation"/><category term="Thomson"/><category term="Trojan.Vundo"/><category term="Tsutomu Shimomura"/><category term="Twitter"/><category term="Twitter StalkDaily Worm"/><category term="Updates"/><category term="WSUS"/><category term="WV State Police. Antivirus2009"/><category term="Windows Update Server"/><category term="autorun conflicker cert"/><category term="backups"/><category term="botnet"/><category term="bots"/><category term="business continuituy"/><category term="computer crime"/><category term="crimeware"/><category term="disaster recovery"/><category term="disgruntled employee"/><category term="disgruntled ex-employee"/><category term="dojosec"/><category term="downadup/conflicker"/><category term="eWeek"/><category term="excel. security"/><category term="ghostnet"/><category term="how to"/><category term="iPhone"/><category term="iPhone App"/><category term="insider threat"/><category term="koobface"/><category term="law firm it"/><category term="mailware servered via adserver"/><category term="medical devices running windows"/><category term="nessus"/><category term="nmap"/><category term="organized crime"/><category term="spearfishing"/><category term="trojans"/><category term="virut"/><category term="virut virux security"/><category term="virux"/><category term="vundo"/><category term="wep"/><category term="wireless security"/><category term="wireshark ethereal"/><category term="worm"/><category term="zero-day"/><category term="zeus"/><title type='text'>Law Firm IT</title><subtitle type='html'>The view from the server room.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default?alt=atom'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default?alt=atom&amp;start-index=26&amp;max-results=25'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>415</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-15182237.post-2822667966682459217</id><published>2010-08-30T05:48:00.006-04:00</published><updated>2010-08-30T05:58:30.059-04:00</updated><title type='text'>Hack3rCon in Today&#39;s Charleston Daily Mail</title><content type='html'>There is a &lt;a href=&quot;http://www.dailymail.com/News/201008290407&quot;&gt;nice story&lt;/a&gt; about &lt;a href=&quot;http://hack3rcon.org/&quot;&gt;Hack3rCon&lt;/a&gt; in today&#39;s Charleston Daily Mail with info about the conference and interviews with me and Rob Dixon. Being a former journalist it is ofter uncomfortable to be the subject of an interview, but &lt;a href=&quot;http://www.dailymail.com/News/contact/cnhy.snyyba+qnvylznvy+pbz+return=/News/201008290407&quot; rel=&quot;nofollow&quot; title=&quot;Click to reveal email with your email client&quot; class=&quot;blue fn&quot;&gt;Paul Fallon&lt;/a&gt; does a pretty good job of not misquoting me.&lt;br /&gt;&lt;br /&gt;For more information about Hack3rCon visit &lt;a href=&quot;http://hack3rcon.org/&quot;&gt;http://hack3rcon.org/&lt;/a&gt;. A portion of the proceeds will benefit &lt;a href=&quot;http://www.hackersforcharity.org/&quot;&gt;Hackers for Charity&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;iframe src=&quot;http://player.vimeo.com/video/14326554&quot; width=&quot;400&quot; frameborder=&quot;0&quot; height=&quot;240&quot;&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href=&quot;http://vimeo.com/14326554&quot;&gt;Welcome to Hack3rCon 2010&lt;/a&gt; from &lt;a href=&quot;http://vimeo.com/user1234121&quot;&gt;The 304 Geeks&lt;/a&gt; on &lt;a href=&quot;http://vimeo.com/&quot;&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2822667966682459217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/2822667966682459217' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2822667966682459217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2822667966682459217'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/08/hack3rcon-in-todays-charleston-daily.html' title='Hack3rCon in Today&#39;s Charleston Daily Mail'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6930639185001942118</id><published>2010-08-21T16:09:00.001-04:00</published><updated>2010-08-21T16:11:11.189-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="304Geeks"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Security"/><category scheme="http://www.blogger.com/atom/ns#" term="hackers"/><category scheme="http://www.blogger.com/atom/ns#" term="SET"/><title type='text'>Hack3rCon</title><content type='html'>The 304Geeks will be hosting &quot;&lt;a href=&quot;http://hack3rcon.org/&quot; target=&quot;_blank&quot;&gt;Hack3rCon&lt;/a&gt;&quot;, the first of its kind Information  Security Conference in this State!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.hack3rcon.org/&quot; target=&quot;_blank&quot;&gt;http://www.hack3rcon.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.charcon.org/cart&quot; target=&quot;_blank&quot;&gt;Register Now!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Events:&lt;br /&gt;Ethical Hacking Workshops with the guys that created, teach and develop  Backtrack, the most widely distributed open source penetration testing  toolkit.&lt;br /&gt;&lt;br /&gt;We have a full day of special gust discussion on everything from  advanced password cracking in 2010 to detecting and stopping intruders  to hands on hacking lads.&lt;br /&gt;&lt;br /&gt;That is right, we will be holding a hacking village all weekend. Get  hands on experience on our private network. Experience mentor will be on  hand to guide you through the exercises. Prizes***&lt;br /&gt;&lt;br /&gt;We will also be hold a Hacker&#39;s Capture the Flag event! Go against other  ethical hackers in an attempt to get all the flags first!!!&lt;br /&gt;&lt;br /&gt;*****WINNER GETS A NETBOOK PREINSTALLED WITH BACKTRACK!!!&lt;br /&gt;&lt;br /&gt;Special Guests:&lt;br /&gt;&lt;br /&gt;Dave Kennedy a.k.a. Rel1k Creator of SET&lt;br /&gt;Adrian Crenshaw a.k.a. Irongeek - Security Researcher&lt;br /&gt;Dennis Boas - **Classified**&lt;br /&gt;Martin Bos a.k.a Purehate - Core Developer Backtrack-Linux&lt;br /&gt;Lee Baird a.k.a. LeeRock - Security Consultant, Ciphent&lt;br /&gt;Mark Baggett - SANS Instructor, Security Blogger - Pauldotcom&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$10 Hack3rCon All Access Weekend Pass when you purchase a CharCon  weekend pass. (requires pre-registration before the event)&lt;br /&gt;&lt;br /&gt;Keep an eye out for technology driven events and contest that will be  host by the 304geeks!!&lt;br /&gt;&lt;br /&gt;The 304Geeks is a local technology group here in Charleston. It was  founded in 2009 by Rob Dixon and myself.&lt;br /&gt;&lt;br /&gt;More on Hack3rCon to come!!</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6930639185001942118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/6930639185001942118' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6930639185001942118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6930639185001942118'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/08/hack3rcon.html' title='Hack3rCon'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-134678819434752104</id><published>2010-06-10T13:22:00.002-04:00</published><updated>2010-06-10T13:26:32.991-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Appalachian Institute of Digital Evidence"/><category scheme="http://www.blogger.com/atom/ns#" term="Cyber Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Digital Evidence"/><category scheme="http://www.blogger.com/atom/ns#" term="Electronic Discovery"/><category scheme="http://www.blogger.com/atom/ns#" term="Internet Investigations"/><category scheme="http://www.blogger.com/atom/ns#" term="John Sammons"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Forensics"/><title type='text'>Appalachian Institute of Digital Evidence First Annual Conference</title><content type='html'>Appalachian Institute of Digital Evidence&lt;br /&gt;First Annual Conference&lt;br /&gt;July 27- 30, 2010&lt;br /&gt;Marshall University Forensic Science Center&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Seating is limited. To reserve a seat, email John Sammons at sammons17@marshall.edu with name, agency and contact information.&lt;br /&gt;&lt;br /&gt;July 27  - 0800 to 1600 Cyber Security &amp;amp; Network Forensics&lt;br /&gt;&lt;br /&gt;Schedule coming soon!&lt;br /&gt;&lt;br /&gt;July 28  - 0800 to 1600 Law Enforcement&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Today&#39;s Smoking Gun: An Introduction to Digital Evidence&lt;br /&gt;John Sammons, Assistant Professor, Marshall University&lt;br /&gt;&lt;br /&gt;Are you leaving evidence behind? Computers are everywhere and as such, they need to be considered as a vital source of potential evidence. Valuable digital evidence may be discovered in nearly any case, not just child pornography and identity theft. Homicide, robbery, drug violations are just a few of the cases that could be solved with digital evidence.&lt;br /&gt;&lt;br /&gt;In this course learn the fundamentals of digital evidence, how it&#39;s different, how it&#39;s collected and how it could benefit your investigations.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Internet Investigations&lt;br /&gt;Josh Brunty&lt;br /&gt;Marshall University Forensic Science Center&lt;br /&gt;&lt;br /&gt;Investigating a cybercrime and/or cybercriminal can be one of the most complex tasks facing the law enforcement professional today and requires a multidisciplinary approach supported by technical expertise that was once not needed with traditional crime.  This session will focus on investigations and operations centered on the use of the internet and its many communities that are being exploited for criminal activity.&lt;br /&gt;&lt;br /&gt;This session will teach investigators how to retrieve and/or extract such evidence using a variety of tools and techniques.&lt;br /&gt;&lt;br /&gt;These two classes have already been submitted and approved for LET credit (4 hrs per).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;July 29 0800 – 1600 – Digital Forensics&lt;br /&gt;&lt;br /&gt;Windows 7 Forensics and USB Device Tracking&lt;br /&gt;&lt;br /&gt;This technically intensive class is designed for the experienced digital forensic investigator. This class will provide an introduction to the Windows 7 operating system from a forensic standpoint. It will also cover the techniques used to track USB devices. The course is taught by Dustin Hurlbut, an Instructor from AccessData. AccessData is the world&#39;s largest provider of digital forensic software.&lt;br /&gt;&lt;br /&gt;NOTE: LET credit approval pending&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;July 30 0800 – 1600 – Electronic Discovery&lt;br /&gt;&lt;br /&gt;“Zubulake Revisited” - 2010 Guidance on Preservation Obligations and Spoliation&lt;br /&gt;Douglas Crouse&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Tips For Developing an E-Discovery Response Action Plan&lt;br /&gt;Matthew A. Kelly&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;“Cull,” “Image,” “Early Case Assessment,” and Other Key Vocabulary&lt;br /&gt;Jill McIntyre&lt;br /&gt;(25 min.)&lt;br /&gt;&lt;br /&gt;How to Assess Reasonable Accessibility&lt;br /&gt;Jill McIntyre&lt;br /&gt;(25 min.)&lt;br /&gt;&lt;br /&gt;eDiscovery Collection&lt;br /&gt;Dustin Hurlbut&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;eDiscovery Analysis&lt;br /&gt;Dustin Hurlbut&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Reforms of Civil Pretrial Discovery on the Horizon&lt;br /&gt;Jill McIntyre&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Data as Evidence:  Issues Governing the Admissibility of Electronically&lt;br /&gt;Stored Information at Trial and in Summary Judgment Practice&lt;br /&gt;Douglas Crouse&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Controlling E-Discovery Costs in Litigation&lt;br /&gt;Jill McIntyre&lt;br /&gt;(50 min.)</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/134678819434752104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/134678819434752104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/134678819434752104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/134678819434752104'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/06/appalachian-institute-of-digital.html' title='Appalachian Institute of Digital Evidence First Annual Conference'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5453087712629207009</id><published>2010-03-20T10:03:00.003-04:00</published><updated>2010-03-20T10:21:41.995-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cybercrime"/><category scheme="http://www.blogger.com/atom/ns#" term="law firm it"/><title type='text'>A Chilling Article About Law Firms Becoming Targets of Cyber Criminals</title><content type='html'>I have long said that law firms are lucrative targets for hackers. Today &lt;a href=&quot;http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/03/19/BU3E1CIIGE.DTL&quot;&gt;a story&lt;/a&gt; appears on page DC - 1 of the San Francisco Chronicle called &quot;Law firms are lucrative targets of cyberscams&quot;.&lt;br /&gt;&lt;blockquote&gt;Last spring, a Long Beach law firm received an e-mail from a Hong Kong businessman seeking help collecting debts from American customers. An attorney with the firm saw it as a great opportunity to reel in more business during the economic downturn and agreed to help.&lt;br /&gt;&lt;br /&gt;After a month of signing paperwork and exchanging telephone calls with his client, the attorney received word from one debtor who sent a $200,000 cashier&#39;s check to pay off his balance. The attorney deposited it in his firm&#39;s account, subtracted his $10,000 fee and wired the remaining amount to his Hong Kong client.&lt;br /&gt;&lt;br /&gt;An hour-and-a-half later, the attorney&#39;s bank called and told him the check bounced. Fortunately, the bank was able to prevent the wire transfer from reaching its destination. He almost had been duped out of $190,000.&lt;br /&gt;&lt;br /&gt;&quot;They send me a nice, big, worthless check,&quot; said the attorney, who asked to remain anonymous. &quot;Needless to say that was not a fun day. They were the hardest 24 hours of my life.&lt;/blockquote&gt;&lt;br /&gt;The threat has been very real for a long time. Scammers have moved from just scamming &quot;rich americans&quot; and have moved on to targeting &quot;rich american lawyers&quot;. The best defense against these sorts of scams are a good spam filter and user education.&lt;br /&gt;&lt;br /&gt;If you don&#39;t have a user education program at your firm, start one. Your IT staff should be trained in security as well. Something like the CompTIA Security+ certification is a good start. Even the MCSE has track has security some great security components to it. You should also probably have a CEH or a CISSP on staff as well, or at least a security professional you can bring in to consult on a contract basis.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;...Alex Stamos, a founding partner at iSEC Partners, a San Francisco security consulting firm that recently published research identifying about 100 organizations hit by the attack, said that law firms are on the list of organizations most at risk of being targets in the future.&lt;br /&gt;&lt;br /&gt;&quot;Most law firms are going to be in trouble if this is the level of adversary they&#39;re going to deal with,&quot; he said. &quot;It&#39;s impossible even for the largest law firms to have a dedicated security team that can hold their own against these people.&quot;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;This threat isn&#39;t going away anytime soon. Be alert and be careful. The threat is no long the 14 year old in the basement. It&#39;s organized crime.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5453087712629207009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/5453087712629207009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5453087712629207009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5453087712629207009'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/03/chilling-article-about-law-firms.html' title='A Chilling Article About Law Firms Becoming Targets of Cyber Criminals'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2587132013360161367</id><published>2010-02-26T00:10:00.000-05:00</published><updated>2010-02-26T00:12:50.510-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="bots"/><category scheme="http://www.blogger.com/atom/ns#" term="cybercrime"/><category scheme="http://www.blogger.com/atom/ns#" term="hackers"/><category scheme="http://www.blogger.com/atom/ns#" term="organized crime"/><category scheme="http://www.blogger.com/atom/ns#" term="RBN"/><title type='text'>How Cybercriminals Steal Money</title><content type='html'>&lt;object width=&quot;425&quot; height=&quot;344&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en_US&amp;fs=1&amp;&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en_US&amp;fs=1&amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;425&quot; height=&quot;344&quot;&gt;&lt;/embed&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2587132013360161367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/2587132013360161367' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2587132013360161367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2587132013360161367'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/02/how-cybercriminals-steal-money.html' title='How Cybercriminals Steal Money'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7558489731324339399</id><published>2010-02-25T23:55:00.007-05:00</published><updated>2010-02-26T00:30:53.669-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Daemon"/><category scheme="http://www.blogger.com/atom/ns#" term="Daniel Suarez"/><category scheme="http://www.blogger.com/atom/ns#" term="FreedomTM"/><category scheme="http://www.blogger.com/atom/ns#" term="The Long Now Foundation"/><title type='text'>Two Great Novels</title><content type='html'>&lt;a href=&quot;http://www.amazon.com/Daemon-Daniel-Suarez/dp/0451228731/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1260943402&amp;amp;sr=1-1&quot;&gt;Daemon&lt;/a&gt; and its sequel, &lt;a href=&quot;http://www.amazon.com/Freedom-TM-Daniel-Suarez/dp/0525951571/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1257207412&amp;amp;sr=1-1&quot;&gt;FreedomTM&lt;/a&gt; may be the best novels I have ever read. Below is a video of the author, &lt;a href=&quot;http://thedaemon.com/&quot;&gt;Daniel Suarez&lt;/a&gt;, speaks on &quot;Bot-Mediated Reality&quot;.&lt;br /&gt;&lt;br /&gt;Bots, or hardware and software robots, are already a large part of human life. Including botnets used to send spam or generally threaten the Internet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object classid=&quot;clsid:d27cdb6e-ae6d-11cf-96b8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0&quot; width=&quot;400&quot; height=&quot;264&quot;&gt;&lt;param name=&quot;flashvars&quot; value=&quot;webhost=fora.tv&amp;amp;clipid=7142&amp;amp;cliptype=clip&quot;&gt;&lt;param name=&quot;allowScriptAccess&quot; value=&quot;always&quot;&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://fora.tv/embedded_player&quot;&gt;&lt;embed flashvars=&quot;webhost=fora.tv&amp;amp;clipid=7142&amp;amp;cliptype=clip&quot; src=&quot;http://fora.tv/embedded_player&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; type=&quot;application/x-shockwave-flash&quot; pluginspage=&quot;http://www.macromedia.com/go/getflashplayer&quot; width=&quot;400&quot; height=&quot;264&quot;&gt;&lt;/embed&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7558489731324339399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/7558489731324339399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7558489731324339399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7558489731324339399'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/02/two-great-novels.html' title='Two Great Novels'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7105463296481119723</id><published>2009-10-30T18:59:00.005-04:00</published><updated>2009-10-30T19:16:54.481-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="john strand"/><category scheme="http://www.blogger.com/atom/ns#" term="Louisville InfoSec"/><title type='text'>The Internet is Evil John Strand Louisville Infosec Conference Video</title><content type='html'>I had to miss &lt;a href=&quot;http://www.louisvilleinfosec.com/&quot;&gt;Louisville InfoSec&lt;/a&gt;, but &lt;a href=&quot;http://www.irongeek.com/&quot;&gt;Irongeek&lt;/a&gt; comes to the recuse with &lt;a href=&quot;http://www.irongeek.com/i.php?page=videos%2Flouisville-infosec-2009-videos&quot;&gt;videos from the conference&lt;/a&gt;. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Below is a talk by &lt;a href=&quot;http://lawfirmit.blogspot.com/&quot;&gt;Law Firm IT&lt;/a&gt; favorite &lt;a href=&quot;http://www.vimeo.com/user595761&quot;&gt;John Strand&lt;/a&gt;. John is a SANS instructor and a member of the &lt;a href=&quot;http://pauldotcom.com/&quot;&gt;PaulDotCom&lt;/a&gt; crew, called &quot;The Internet is Evil&quot;.  Thanks to &lt;a href=&quot;http://www.irongeek.com/&quot;&gt;Irongeek&lt;/a&gt; for taking the time to record, post and host these on &lt;a href=&quot;http://www.irongeek.com/i.php?page=security/hackingillustrated&quot;&gt;his site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;embed src=&quot;http://blip.tv/play/AYGriW0C&quot; type=&quot;application/x-shockwave-flash&quot; width=&quot;380&quot; height=&quot;290&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot;&gt;&lt;/embed&gt; &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7105463296481119723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/7105463296481119723' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7105463296481119723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7105463296481119723'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/10/internet-is-evil-john-strand-louisville.html' title='The Internet is Evil John Strand Louisville Infosec Conference Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4987720748954202790</id><published>2009-08-27T07:39:00.006-04:00</published><updated>2009-08-27T08:48:09.910-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="botnet"/><category scheme="http://www.blogger.com/atom/ns#" term="crimeware"/><category scheme="http://www.blogger.com/atom/ns#" term="trojans"/><category scheme="http://www.blogger.com/atom/ns#" term="zeus"/><title type='text'>Zeus, King of the Underground Crimeware Toolkits</title><content type='html'>This &lt;a href=&quot;ttp://www.symantec.com/connect/blogs/zeus-king-underground-crimeware-toolkits&quot;&gt;blog post&lt;/a&gt; and &lt;a href=&quot;http://www.youtube.com/watch?v=CzdBCDPETxk&quot;&gt;video&lt;/a&gt; explains how Zeus, currently the world&#39;s largest botnet, works.&lt;br /&gt;&lt;br /&gt;&lt;object width=&quot;80&quot; height=&quot;340&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/CzdBCDPETxk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;embed src=&quot;http://www.youtube.com/v/CzdBCDPETxk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;300&quot; height=&quot;240&quot;&gt;&lt;/embed&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4987720748954202790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/4987720748954202790' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4987720748954202790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4987720748954202790'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/zeus-king-of-underground-crimeware.html' title='Zeus, King of the Underground Crimeware Toolkits'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2288975095256641560</id><published>2009-08-25T04:28:00.003-04:00</published><updated>2009-08-25T04:34:44.909-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Email"/><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><category scheme="http://www.blogger.com/atom/ns#" term="OWA"/><category scheme="http://www.blogger.com/atom/ns#" term="Passwords"/><category scheme="http://www.blogger.com/atom/ns#" term="Weak Passwords"/><title type='text'>OWA+Weak Passwords=Big Trouble</title><content type='html'>Now&#39;s the time to make sure your users are using strong passwords. As pointed out in &lt;a href=&quot;http://www.redspin.com/blog/2009/08/04/attacking-webmail-user-accounts/&quot;&gt;this post&lt;/a&gt; from the RedSpin Security Blog, Outlook Web Access makes getting email on the go very easy for users, but it opens up yet another attack surface that is pretty easy to attack using commonly used tools.&lt;br /&gt;&lt;br /&gt;This an another example of why law firm IT folks needs to encourage the use of strong passwords.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2288975095256641560/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/2288975095256641560' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2288975095256641560'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2288975095256641560'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/owaweak-passwordsbig-trouble.html' title='OWA+Weak Passwords=Big Trouble'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7770776789896308767</id><published>2009-08-23T05:42:00.006-04:00</published><updated>2009-08-23T06:28:19.930-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Data Breach"/><category scheme="http://www.blogger.com/atom/ns#" term="Gonzalez"/><category scheme="http://www.blogger.com/atom/ns#" term="Heartland"/><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="TJX"/><title type='text'>What&#39;s so interesting about the TJX Hacker Charged With Heartland, Hannaford Breaches</title><content type='html'>Here&#39;s a few details I find interesting in &lt;a href=&quot;http://www.wired.com/threatlevel/2009/08/tjx-hacker-charged-with-heartland/&quot;&gt;this story&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;* The hackers allegedly stole more than 130 million credit and debit card numbers from Heartland and Hannaford combined.&lt;br /&gt;* Gonzalez and 10 others were charged in May and August 2008 with network intrusions into TJX, OfficeMax, Dave &amp;amp; Busters restaurant chain and other companies.&lt;br /&gt;* The attack vector was SQL-injection&lt;br /&gt;* The hackers tested their malware against some 20 different antivirus programs to make sure they wouldn’t be detected, and also programmed the malware to erase evidence from the hacked networks to avoid forensic detection.&lt;br /&gt;* The thieves captured card account numbers and expiration dates and, in 20 percent of cases, the customer’s name as well.&lt;br /&gt;* Gonzalez called his credit card theft ring “Operation Get Rich or Die Tryin.”&lt;br /&gt;* Another hacker &lt;a href=&quot;http://www.wired.com/threatlevel/2009/07/hacker/&quot;&gt;linked to the crime&lt;/a&gt; committed suicide in 2008.&lt;br /&gt;* Gonzalez &lt;a href=&quot;http://www.wired.com/threatlevel/2009/08/gonzalez-evidence/#more-8659&quot;&gt;goes to trial&lt;/a&gt; in New York on September 14th for the Dave &amp;amp; Buster’s hack.&lt;br /&gt;* Next year, Gonzalez &lt;a href=&quot;http://www.wired.com/threatlevel/2009/08/gonzalez-evidence/#more-8659&quot;&gt;faces trial&lt;/a&gt; in Massachusetts on the TJX hack and may eventually face trial in New Jersey on new charges levied against him this week for allegedly hacking into five other companies, including Heartland Payment Systems and 7-11, and stealing more than 130 million credit and debit card numbers — the largest data breach prosecuted in the United States to date.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Some are wondering if Gonzalez was hired to do these jobs for the Russian mob. I can find no coverage of such a link.&lt;br /&gt;&lt;br /&gt;Two of my debt cards were involved in these breaches. One was replaced. My bank give me one year of free fraud monitoring on the other.&lt;br /&gt;&lt;br /&gt;While we as law firm IT don&#39;t usually process credit card transactions, most of us have SQL databases, many of them Internet facing or running our websites.&lt;br /&gt;&lt;br /&gt;As defenders what can we learn from the breach? Secure your web applications. SQL-injection is a common thread in many recent breaches. It&#39;s a quick and easy way to get behind your firewall.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7770776789896308767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/7770776789896308767' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7770776789896308767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7770776789896308767'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/whats-so-interesting-about-tjx-hacker.html' title='What&#39;s so interesting about the TJX Hacker Charged With Heartland, Hannaford Breaches'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-793414948759690212</id><published>2009-06-28T13:54:00.003-04:00</published><updated>2009-06-28T14:47:42.475-04:00</updated><title type='text'>What a OS X exploit looks like</title><content type='html'>&lt;object width=&quot;380&quot; height=&quot;360&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/dpnWncJH-bk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1&quot;&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;embed src=&quot;http://www.youtube.com/v/dpnWncJH-bk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;380&quot; height=&quot;360&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;This video helped to convince me that I needed an antivirus program for my Mac. I didn&#39;t purchase Sophos since it requires a Windows server to manage the client installation on a Mac. I downloaded and installed &lt;a href=&quot;http://www.clamxav.com/index.php?page=dl&quot;&gt;ClamXAV&lt;/a&gt;. It&#39;s free.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/793414948759690212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/793414948759690212' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/793414948759690212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/793414948759690212'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/06/what-os-x-exploit-looks-like.html' title='What a OS X exploit looks like'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6416471450257835031</id><published>2009-06-27T10:55:00.002-04:00</published><updated>2009-06-28T13:42:02.273-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Passwords"/><category scheme="http://www.blogger.com/atom/ns#" term="Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Weak Passwords"/><title type='text'>Video: Simple Tips to Pick a Strong Password</title><content type='html'>&lt;object width=&quot;560&quot; height=&quot;340&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/VYzguTdOmmU&amp;amp;hl=en&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;embed src=&quot;http://www.youtube.com/v/VYzguTdOmmU&amp;amp;hl=en&amp;amp;fs=1&amp;amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;360&quot; height=&quot;340&quot;&gt;&lt;/embed&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6416471450257835031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/6416471450257835031' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6416471450257835031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6416471450257835031'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/06/video-simple-tips-to-pick-strong.html' title='Video: Simple Tips to Pick a Strong Password'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2995745040012851953</id><published>2009-05-25T09:48:00.008-04:00</published><updated>2009-05-25T10:25:07.059-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="419 Scam"/><category scheme="http://www.blogger.com/atom/ns#" term="Facebook"/><title type='text'>Facebook Spear Phishing, New 419 Scam</title><content type='html'>I received the follow email via Facebook last night that is a new variation on the &lt;a href=&quot;http://www.419eater.com/html/419faq.htm&quot;&gt;old 419 scam&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;Wilson sent you a message.&lt;br /&gt;&lt;br /&gt;--------------------&lt;br /&gt;Subject: Attn: Bill Gardner&lt;br /&gt;&lt;br /&gt;Alexander JLO - Solicitors&lt;br /&gt;11 Lanark Square&lt;br /&gt;Glengall Bridge&lt;br /&gt;London E14 9RE&lt;br /&gt;United Kingdom.&lt;br /&gt;TEL:+44 794 4145 981&lt;br /&gt;Fax:+44 794 4416 262&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Good day: Bill ,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is a personal E-mail directed to you and I request that&lt;br /&gt;it be treated as such.&lt;br /&gt;&lt;br /&gt;I am Barrister Wilson Baker, a solicitor at law. I am the personal attorney/sole executor to the late Engr Gerald Gardner herein after referred to as&#39;my client&#39; who worked as an independent oil magnate in my country and who died in a plane crash with his immediate family in December 2003.&lt;br /&gt;&lt;br /&gt;Since the death of my client, I have written several letters to the embassy with an intent to locate any of his extended relatives whom shall be&lt;br /&gt;claimants/beneficiaries of his abandoned personal estate and all such efforts have been to no avail.&lt;br /&gt;&lt;br /&gt;More-so, I have received official letters in the last few weeks suggesting a likely proceeding for confiscation of his abandoned personal assets in line with existing laws by the bank in which my client deposited a notably high amount of money.&lt;br /&gt;&lt;br /&gt;On this note i decided to search for a credible person and finding that you bear a similar last name, I was urged to contact you, that I may with your consent, present you to the &quot;trustee&quot; bank as my late client&#39;s surviving family member so as to enable you put up a claim to the bank in that capacity as a next of kin of my client.&lt;br /&gt;&lt;br /&gt;I find this possible for the fuller reasons that you bear a similar last name with my client making it a lot easier for you to put up a claim in that&lt;br /&gt;capacity.&lt;br /&gt;&lt;br /&gt;I propose that 35% of the net sum will accrue to you at the conclusion of this deal in so far as I do not incure further expenses.&lt;br /&gt;&lt;br /&gt;Therefore, to facilitate the immediate transfer of this funds, you need, first to contact me via my private email:(wilsonbaker3@yahoo.co.uk) for better confidentiality, signifying your interest and as soon as I obtain your confidence I will immediately appraise you with the complete details as well as fax you the documents, with which you are to proceed and i shall direct you on how to put up an application to the bank.&lt;br /&gt;&lt;br /&gt;However, you will have to accent to an express agreement which I will forward to you in order to bind us in this transaction.&lt;br /&gt;&lt;br /&gt;Upon the receipt of your reply,I will send you by fax or E-mail the next step to take.I will not fail to bring to your notice that this proposal is hitch-free and that you should not entertain any fears as the required arrangements have been made for the completion of this transfer.&lt;br /&gt;&lt;br /&gt;Like I said, I require only a solemn confidentiality on this.&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Wilson Baker Esq&lt;br /&gt;--------------------&lt;/blockquote&gt;&lt;br /&gt;I have to admit this version of the scam is compelling enough to make me actually read the email. This version of the scam actually lists an address and telephone number, but why would a lawyer use a Yahoo email address? This is just another example of how far people will go to attempt to get between you and your money.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2995745040012851953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/2995745040012851953' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2995745040012851953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2995745040012851953'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/facebook-spear-phishing-new-419-scam.html' title='Facebook Spear Phishing, New 419 Scam'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-9089301677718230206</id><published>2009-05-15T07:15:00.011-04:00</published><updated>2009-05-19T04:56:39.325-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Data Breach"/><category scheme="http://www.blogger.com/atom/ns#" term="WV State Bar"/><title type='text'>Lessons learned from the WV State Bar breach</title><content type='html'>According to the &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html&quot;&gt;FAQ&lt;/a&gt; released by the WV State Bar yesterday, the data breach reported a couple of weeks ago was the result of a unpatched Linux sever being compromised. The Bar further says it has &quot;an unsupported FoxPro database containing member information&quot; some where on its network that was also compromised.&lt;br /&gt;&lt;br /&gt;It&#39;s unclear from the FAQ how the hacker or hackers took control of the Bar&#39;s webserver and started &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-remains-offline-after.html&quot;&gt;serving malware&lt;/a&gt;. The bar does say, &quot;The State Bar will no longer host its own website internally, it will be hosted off-site at a secure location with a company that specializes in website development and internet security. The State Bar website will be completely re-written in a more secure manner.&quot;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://toolbar.netcraft.com/site_report?url=http://www.wvbar.org&quot;&gt;Netcraft shows&lt;/a&gt; the Bar site was running on Windows 2000 on Apache/2.0.54 Win32 PHP/5.0.4 on 22-Mar-2006. Previously the site ran Windows 2000, Microsoft-IIS/5.07 as of Nov-2004 &lt;a href=&quot;http://toolbar.netcraft.com/site_report?url=http://www.wvbar.org&quot;&gt;according to Netcraft&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;As far as secruity, they &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html&quot;&gt;say&lt;/a&gt; they had a firewall, &quot;The State Bar&#39;s computer system was equipped with a firewall, which previously was believed to be secure. However, the State Bar&#39;s forensic computer experts have advised that no firewall would have prevented the sophisticated hack of the website and database. The State Bar is taking extraordinary measures, as set forth in response to question number 1 above, to prevent a security breach from occurring again in the future.&quot;&lt;br /&gt;&lt;br /&gt;The Bar has pulled the unpatched Linus box off its network, has stopped hosting it&#39;s website internally, and has removed social security number from it&#39;s databases. Also it says it&#39;s website is being rewritten in a more secure manner.&lt;br /&gt;&lt;br /&gt;So what can we learn from the breach. First, don&#39;t run unpatched servers, Linux, Windows, or any other OS on your network.&lt;br /&gt;&lt;br /&gt;Second, attacks on webservers are very much in style by hackers. Since most of us have deployed firewalls, antivirus, patch management, vulnerability scanners, and intrusion detection systems, the webserver is often the weekest link in some networks. As a result, web application security has becoming very important. Secure you web apps and use web application firewalls. Also don&#39;t host websites in-house or on the same network as your production network.&lt;br /&gt;&lt;br /&gt;Third, know what applicatons, operating systems, and servers are on  your network and where they are, and document eveything.  The Bar says, &quot;Further complicating matters, there existed no documentation regarding the State Bar network layout, hardware, software and/or legacy applications. As such, the upgrade process has been a cycle of discovery and repair which has taken longer than anyone could have expected or foreseen.&quot;&lt;br /&gt;&lt;br /&gt;As far as the breach itself, the Bar say, &quot;The State Bar had social security numbers for approximately 4,000 members. Members whose social security numbers are believed to have been contained on the State Bar&#39;s database should have received a second and third email notifying them of that fact. Some members do not have an email address on file with the State Bar. For those members, a separate letter was mailed to them through the United States Postal Service.&quot;&lt;br /&gt;&lt;br /&gt;The Bar has turned hard drives over to the FBI and says it will keep it&#39;s member up-to-date on the investigation.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/9089301677718230206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/9089301677718230206' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9089301677718230206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9089301677718230206'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/what-wv-state-bar-faq-on-its-data.html' title='Lessons learned from the WV State Bar breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6319028442170428471</id><published>2009-05-14T14:43:00.003-04:00</published><updated>2009-05-15T08:24:26.957-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Data Breach"/><category scheme="http://www.blogger.com/atom/ns#" term="WV State Bar"/><title type='text'>The West Virginia State Bar Has Posted An FAQ on Its Recent Data Breach</title><content type='html'>The West Virginia State Bar has posted an FAQ on its recent data breach.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;COMPUTER SECURITY BREACH FAQ&lt;br /&gt;&lt;br /&gt;By now, most members of The West Virginia State Bar have received either one or two emails regarding the security breach at the State Bar website. If you received only one email, as far as the State Bar is aware, your social security number was not in the State Bar&#39;s database. Approximately 4,000 of the 7,000 State Bar members received a second email advising that we had your social security number was in the State Bar&#39;s database. As of this date, the State Bar has no knowledge that the hackers have looked at any personal information in the State Bar database and the State Bar has received no reports that any of its members have suffered any identity theft. Nonetheless, and out of an abundance of caution, the State Bar provided an alert to each of its members regarding this security breach. This alert has led to numerous questions which the State Bar has attempted to answer below so that all of its members will continue to be informed about this situation.&lt;br /&gt;&lt;br /&gt;1. Does the Bar have any idea of how this could happen?&lt;br /&gt;&lt;br /&gt;In late 2006 or early 2007, the State Bar determined that it needed to upgrade its computers, its network, its member database, and its website. All of these were hosted by the State Bar onsite. Since 2007, the State Bar has been working with computer consultants to upgrade the computers, network and security at the State Bar. The upgrade process has been hampered by the existence of an outdated Linux server, and an unsupported FoxPro database containing member information. Further complicating matters, there existed no documentation regarding the State Bar network layout, hardware, software and/or legacy applications. As such, the upgrade process has been a cycle of discovery and repair which has taken longer than anyone could have expected or foreseen.&lt;br /&gt;&lt;br /&gt;In working with the computer consultants, it was learned very recently that outside computer hackers were able to enter the State Bar computer system through the Linux server and State Bar website. From there they create access to the remainder of the State Bar network, including the member database. It is not possible for the computer consultants to determine whether the hackers did or did not look at the member database, they can only advise that the hackers had the opportunity to look at any and all computer data on the State Bar&#39;s network.&lt;br /&gt;&lt;br /&gt;2. What will the State Bar do to make sure this does not happen again?&lt;br /&gt;&lt;br /&gt;The State Bar has now shut down its Linux server and its website. The Linux server will be eliminated. All hard drives in the State Bar network and individual work stations were replaced. The hard drives are being turned over to the Federal Bureau of Investigation. The State Bar will no longer host its own website internally, it will be hosted off-site at a secure location with a company that specializes in website development and internet security. The State Bar website will be completely re-written in a more secure manner. These steps combined should prevent similar security breaches in the future.&lt;br /&gt;The State Bar has worked with its computer consultants to delete all social security numbers from the FoxPro database and no records will be kept in the future regarding social security numbers.&lt;br /&gt;&lt;br /&gt;3. Why did the State Bar have my social security number and when did it get it?&lt;br /&gt;&lt;br /&gt;At various points in time prior to 2007, the State Bar collected social security numbers. Many people provided this information at the time they were admitted to the State Bar. In addition, some social security numbers were collected by the State Bar when the West Virginia Supreme Court of Appeals first considered the possibility of e-filing. More recently, members provided social security numbers at the time they applied for a photo identification card. Beginning immediately, all communications regarding the applications for new photo identification cards will be via U.S. Mail and in paper form. No electronic records will be kept by the State Bar.&lt;br /&gt;&lt;br /&gt;4. Did the State Bar have my social security number or not?&lt;br /&gt;&lt;br /&gt;The State Bar had social security numbers for approximately 4,000 members. Members whose social security numbers are believed to have been contained on the State Bar&#39;s database should have received a second and third email notifying them of that fact. Some members do not have an email address on file with the State Bar. For those members, a separate letter was mailed to them through the United States Postal Service.&lt;br /&gt;&lt;br /&gt;5. Why did the State Bar wait so long to notify me of the breach?&lt;br /&gt;&lt;br /&gt;The State Bar acted very quickly after the computer consultants advised The Bar of the potential for a security breach. The State Bar Linux server and website were immediately brought down. The Linux server housed the State Bar&#39;s listserv which was its prior method of communicating with all members.&lt;br /&gt;The State Bar&#39;s Board of Governors was advised of the security breach and it authorized the dissemination of a press release. The Supreme Court of Appeals of West Virginia was contacted and provided technical assistance in sending out a press release advising of the compromise of the State Bar&#39;s network. During this time, the State Bar did not have any ability to mail or email its members as its membership database was inaccessible. The State Bar has now created a new email system to communicate with all members of the State Bar that have their emails on file. The State Bar sent an email to its members within a few hours of its membership database and email listserv being reinstated.&lt;br /&gt;&lt;br /&gt;6. What information did the hackers get in the security breach?&lt;br /&gt;&lt;br /&gt;It is not possible for the computer consultants to advise the State Bar that any information was reviewed during the security breach. The computer consultants can only advise that the outside hackers had access to the member database and all other data on the State Bar network. The computer consultants reviewed the data in the member database. They have advised that it is not infected with any virus.&lt;br /&gt;&lt;br /&gt;7. Why wasn&#39;t the site secure?&lt;br /&gt;&lt;br /&gt;The State Bar&#39;s computer system was equipped with a firewall, which previously was believed to be secure. However, the State Bar&#39;s forensic computer experts have advised that no firewall would have prevented the sophisticated hack of the website and database. The State Bar is taking extraordinary measures, as set forth in response to question number 1 above, to prevent a security breach from occurring again in the future.&lt;br /&gt;&lt;br /&gt;8. Did the State Bar report this to the credit reporting agencies?&lt;br /&gt;&lt;br /&gt;The State Bar has notified the credit reporting agencies of this security breach. The State Bar has also provided the contact information for all three major credit reporting agencies to our members and it has encouraged each member to separately contact those agencies.&lt;br /&gt;&lt;br /&gt;9. Is the State Bar going to pay for my credit monitoring costs?&lt;br /&gt;&lt;br /&gt;Some State Bar members have requested the State Bar to pay for credit monitoring. Unfortunately, the State Bar has no unallocated funds to pay for any credit monitoring services. To put such a program in place could require an assessment of the members as a whole. Given the lack of any reported identity theft affecting any of its members, the State Bar believes that a special dues assessment to pay for this credit monitoring is an unnecessary expense for its members at this time.&lt;br /&gt;&lt;br /&gt;10. Has this been reported to a law enforcement agency so I can file a 7 year report?&lt;br /&gt;&lt;br /&gt;Yes, this matter has been turned over to the Federal Bureau of Investigation. They are conducting a formal investigation of the security breach. Within the next few days, it is anticipated that the FBI will begin its forensic analysis of the removed hard drives. The FBI has assured the State Bar that it will pursue location and prosecution of the individual or individuals who breached the State Bar&#39;s system.&lt;br /&gt;&lt;br /&gt;11. Will we be advised of any information the State Bar receives from the FBI?&lt;br /&gt;&lt;br /&gt;Yes, the State Bar will keep its members up to date regarding any public results of the FBI investigation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Since 2007, the State Bar has been working to correct the flaws in the old computer system and to insure that a completely safe and fully operational system is up and running as soon as possible. The State Bar regrets any inconvenience to its members.&lt;/blockquote&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6319028442170428471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/6319028442170428471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6319028442170428471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6319028442170428471'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html' title='The West Virginia State Bar Has Posted An FAQ on Its Recent Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-714587068235197764</id><published>2009-05-08T07:57:00.005-04:00</published><updated>2009-05-08T08:07:05.634-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="malware servered via adserver"/><category scheme="http://www.blogger.com/atom/ns#" term="WV Record"/><title type='text'>The West Virginia Record Malware Problem Fixed</title><content type='html'>The problem with &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/05/another-west-virginia-law-related.html&quot;&gt;ads serving malware&lt;/a&gt; at &lt;a href=&quot;http://www.wvrecord.com/&quot;&gt;the West Virginia Record&lt;/a&gt; was corrected quickly after they learned of the problem, Chris Dickerson, Editor of the Record told me yesterday. He said the issue was with a compromised ad server that was a part of a ad network serving 100s of newspapers.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/714587068235197764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/714587068235197764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/714587068235197764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/714587068235197764'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/west-virginia-record-malware-problem.html' title='The West Virginia Record Malware Problem Fixed'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8354903069973081738</id><published>2009-05-05T15:44:00.006-04:00</published><updated>2009-05-08T09:08:07.875-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Breach Notification"/><category scheme="http://www.blogger.com/atom/ns#" term="Data Breach"/><category scheme="http://www.blogger.com/atom/ns#" term="FBI"/><category scheme="http://www.blogger.com/atom/ns#" term="WV State Bar"/><title type='text'>Attorneys Receiving Individual Notification of Social Security Number Compromise in Recent WV State Bar Data Breach</title><content type='html'>Individual attorneys began receiving notices this afternoon that their social security numbers we involved in the resent breach of the WV State Bar website and other computer system.&lt;br /&gt;&lt;blockquote&gt;Important Notice to Members Regarding Social Security Information&lt;br /&gt;&lt;br /&gt;From:&lt;br /&gt;The West Virginia State Bar&lt;br /&gt;2006 Kanawha Boulevard, East&lt;br /&gt;Charleston, WV 25311-2204&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar has learned that there are two sets of persons whose Social Security numbers were contained on its computer system, which was recently hacked.　The first group of persons are those who recently completed applications to receive the new West Virginia State Bar photo ID card.　 Those persons included their Social Security numbers on the application forms, which were sent to Cheryl Wright at The State Bar, scanned into The State Bar&#39;s computer system, and e-mailed or faxed back to the requesting members.&lt;br /&gt;&lt;br /&gt;　　&lt;br /&gt;The other group of persons whose Social Security numbers were contained on The State Bar&#39;s computer system are those who provided their Social Security numbers to The State Bar at some point in time during their membership tenure.　These Social Security numbers existed on The State Bar&#39;s membership database along with the members&#39; names, addresses, telephone numbers, email addresses, and dates of admittance.　It was not until late in the day on May 4, 2009, that The State Bar&#39;s retained experts were able to retrieve this information.　&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Unfortunately, you are receiving this email because you are among one or both of these groups of people.　Although, as has been explained in the two prior notices, The State Bar has received no evidence or reports of any identity theft, fraud or other unauthorized use of any member&#39;s personal information, because your Social Security number was contained on The State Bar&#39;s computer system, there is a possibility that it may have been viewed by the hackers.　&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar has notified the three major credit reporting agencies of this potential security breach and is working with the FBI to identify the person(s) or entity(s) responsible.　 If you have any evidence that your personal information has been compromised, please contact The West Virginia State Bar immediately.　 In addition, you also may wish to contact the major credit reporting agencies to ask that a fraud alert be placed in your file to notify potential creditors and others that you may be a victim of identity theft.　The contact information for the credit reporting agencies is as follows:&lt;br /&gt;&lt;br /&gt;Equifax Information Services&lt;br /&gt;PO Box 740256&lt;br /&gt;Atlanta, GA 30374&lt;br /&gt;1-877-576-5734&lt;br /&gt;www.fraudalerts.equifax.com&lt;br /&gt;&lt;br /&gt;　&lt;br /&gt;Experian&lt;br /&gt;NCAC&lt;br /&gt;PO Box 9556&lt;br /&gt;Allen, TX 750131-888-397-3742&lt;br /&gt;www.experian.com/fraud&lt;br /&gt;&lt;br /&gt;　&lt;br /&gt;TransUnion&lt;br /&gt;Customer Disclosure Center&lt;br /&gt;TransUnion Consumer Relations&lt;br /&gt;PO Box 2000&lt;br /&gt;Chester, PA 19022-2000&lt;br /&gt;1-800-680-7289&lt;br /&gt;www.transunion.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar deeply regrets any concern or stress that this has caused you.　If you have any additional questions, please send them to Anita Casey, Executive Director of The West Virginia State Bar.　Ms. Casey will work with The State Bar&#39;s Ad Hoc Technology Committee to respond to your questions as quickly as possible.&lt;/blockquote&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8354903069973081738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/8354903069973081738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8354903069973081738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8354903069973081738'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/attorneys-receiving-individual.html' title='Attorneys Receiving Individual Notification of Social Security Number Compromise in Recent WV State Bar Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4387212344207634827</id><published>2009-05-05T08:27:00.005-04:00</published><updated>2009-05-05T08:40:41.920-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Breach Notification"/><category scheme="http://www.blogger.com/atom/ns#" term="FBI"/><category scheme="http://www.blogger.com/atom/ns#" term="Malware"/><category scheme="http://www.blogger.com/atom/ns#" term="WV State Bar"/><title type='text'>WV State Bar Sends Member Notice of Data Breach</title><content type='html'>The West Virginia State bar sent notice of the breach of it&#39;s site and internal servers by hackers yesterday. The notice, posted below, shreds no new light on what happen or if person data was compromised, but it does disclose the FBI is now involved.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style=&quot;color: rgb(51, 51, 51);font-family:Arial,Helvetica,sans-serif;font-size:85%;&quot;  &gt; &lt;div   style=&quot;color: rgb(0, 0, 0);font-family:Arial Narrow,Arial MT Condensed Light,sans-serif;font-size:14pt;&quot; styleclass=&quot;style_ArticleHead&quot;&gt;&lt;span style=&quot;color: rgb(0, 0, 0);font-family:Arial Narrow,Arial MT Condensed Light,sans-serif;font-size:130%;&quot;  &gt;&lt;span style=&quot;font-size:100%;&quot;&gt;&lt;b&gt;Important Notice to Our Members&lt;/b&gt;&lt;/span&gt;  &lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-size:100%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-size:100%;&quot;&gt;From:&lt;span style=&quot;font-weight: bold;&quot;&gt; &lt;/span&gt;          &lt;br /&gt;&lt;span style=&quot;font-style: italic;&quot;&gt;The West Virginia State Bar &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size:100%;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;font-style: italic;&quot;&gt;2006 Kanawha Boulevard, East  &lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-style: italic;&quot;&gt;Charleston, WV 25311&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Using a sophisticated computer hack, an unknown person or entity gained  unauthorized access to The West Virginia State Bar website and internal computer  network, potentially compromising certain personal information The State Bar  maintains about its current and former members.&lt;br /&gt;&lt;br /&gt;The security breach was  discovered recently during an upgrade of The State Bar&#39;s website. The website  was taken offline on Friday, April 17, 2009.  The State Bar has retained  forensic computer experts to help investigate the suspected security breach. The  State Bar is also working with the FBI to investigate the breach and attempt to  locate the responsible party(s).&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar&#39;s Ad Hoc  Technology Committee met with its retained forensic computer experts and learned  that the security breach extended beyond the web server to the Bar&#39;s internal  computer network.  Given the sophistication of this security breach, and out of  an abundance of caution, the Committee is considering all personal information  on The State Bar&#39;s network as potentially compromised.&lt;br /&gt;&lt;br /&gt;The State Bar  provided notice to all of its members regarding this security breach through a  press release issued on April 28, 2009, with the assistance of the West Virginia  Supreme Court of Appeals as The West Virginia State Bar did not have computer  access to its member lists until May 4, 2009.  This second notice is being sent  to all members at this time because the State Bar&#39;s listserv capability was  reinstated late this afternoon.&lt;br /&gt;&lt;br /&gt;Members of the Ad Hoc Technology  Committee, representatives of the company which has been working with The State  Bar&#39;s computer system for the past several years, and the forensic computer  experts worked all last week and over the weekend to remediate the  problem.&lt;br /&gt;&lt;br /&gt;While the website itself contained no personal data, the  website was connected to The State Bar&#39;s internal database server which houses  the membership data.  Membership data includes names, mailing addresses, email  addresses, birth dates, lawyer identification numbers, and some members&#39; and  former members&#39; social security numbers.  The State Bar Ad Hoc Technology  Committee also has just obtained a list of the names of its members whose social  security numbers were on the system.  Those members will receive a separate  e-mail communication from The State Bar.&lt;br /&gt;&lt;br /&gt;Importantly, the Ad Hoc  Technology Committee has confirmed that information provided by clients to their  attorneys has never been maintained on The State Bar&#39;s computer systems and,  therefore, such information is unaffected by this recently discovered security  breach.&lt;br /&gt;&lt;br /&gt;The Ad Hoc Technology Committee has been advised by its forensic  computer experts that it is impossible to determine exactly when the security  breach occurred. The State Bar has no evidence and has received no reports of  any identity theft, fraud or other unauthorized use of its members&#39; personal  information at this time.  If any members of The West Virginia State Bar have  any evidence that their personal information has been compromised, they should  contact The West Virginia State Bar immediately.  Members may also contact the  major credit reporting agencies to ask that a fraud alert be placed in their  files to notify potential creditors and others that they may be victims of  identity theft.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Equifax Information  Services &lt;/span&gt;&lt;br /&gt;PO Box 740256&lt;br /&gt;Atlanta, GA 30374&lt;br /&gt;1-877-576-5734&lt;br /&gt;&lt;a title=&quot;blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZye_ejrWCxcuAzX3xs4M5jrARqFkYpD7RYzbroXxh4CAKe4gBOcWu2mPr2f51JXCRxshdgfrMNPyYq1LwD2j-_WdMFTzOIemdC2p41IpTX4NvUaCLe9OAc&quot; href=&quot;http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZye_ejrWCxcuAzX3xs4M5jrARqFkYpD7RYzbroXxh4CAKe4gBOcWu2mPr2f51JXCRxshdgfrMNPyYq1LwD2j-_WdMFTzOIemdC2p41IpTX4NvUaCLe9OAc&quot; target=&quot;_blank&quot; track=&quot;on&quot; linktype=&quot;link&quot;&gt;www.fraudalerts.equifax.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Experian&lt;/span&gt;&lt;br /&gt;NCAC&lt;br /&gt;PO Box 9556&lt;br /&gt;Allen, TX  75013&lt;br /&gt;1-888-397-3742&lt;br /&gt;&lt;a title=&quot;blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUbPNbihh77A5hjihma_O047Xv8AvmFgfXBSxv1fArKF4YGvzoirpyJIm6DeFbzT6DK2gIDUCIJ1A1_oy3lXWYLOMtOeQSXzdpJs3dROkgkPew==&quot; href=&quot;http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUbPNbihh77A5hjihma_O047Xv8AvmFgfXBSxv1fArKF4YGvzoirpyJIm6DeFbzT6DK2gIDUCIJ1A1_oy3lXWYLOMtOeQSXzdpJs3dROkgkPew==&quot; target=&quot;_blank&quot; track=&quot;on&quot; linktype=&quot;link&quot;&gt;www.experian.com/fraud&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;TransUnion &lt;/span&gt;&lt;br /&gt;Customer Disclosure  Center&lt;br /&gt;TransUnion Consumer Relations&lt;br /&gt;PO Box 2000&lt;br /&gt;Chester, PA  19022-2000&lt;br /&gt;1-800-680-7289&lt;br /&gt;&lt;a title=&quot;blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZU21LZlbkq3LKyGzXG4AKyHXcx4gWdLeWV_0pNy-4ckl9GsmfMAp9dN2HAYiDqhxpJHTGV00_ZVuvMFSaRgBDtSFDrUPmSuImp_XGWDnFulA==&quot; href=&quot;http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZU21LZlbkq3LKyGzXG4AKyHXcx4gWdLeWV_0pNy-4ckl9GsmfMAp9dN2HAYiDqhxpJHTGV00_ZVuvMFSaRgBDtSFDrUPmSuImp_XGWDnFulA==&quot; target=&quot;_blank&quot; track=&quot;on&quot; linktype=&quot;link&quot;&gt;www.transunion.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-style: italic;&quot;&gt;All questions should be directed to:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; The West Virginia State Bar&lt;br /&gt;2006 Kanawha Blvd., East&lt;br /&gt;Charleston, WV  25311&lt;br /&gt;c/o Anita Casey, Executive Director&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;Problems with the State Bar website go back to &lt;a href=&quot;http://www.charlestondailymail.com/News/200809100161&quot;&gt;September 2009&lt;/a&gt;, and I&#39;ve &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html&quot;&gt;posted&lt;/a&gt; previously about problems with the Bar&#39;s website &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html&quot;&gt;hosting malware&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4387212344207634827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/4387212344207634827' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4387212344207634827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4387212344207634827'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/wv-state-bar-sends-member-notice-of.html' title='WV State Bar Sends Member Notice of Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-824326126483245644</id><published>2009-05-04T11:08:00.003-04:00</published><updated>2009-05-04T11:29:26.957-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="malware servered via adserver"/><category scheme="http://www.blogger.com/atom/ns#" term="WV Record"/><title type='text'>Another West Virginia Law Related Website Compromised</title><content type='html'>The WV Record, a local newspaper that covers state legal matters, is server ads containing malware. It doesn&#39;t appears the site itself, www.wvrecord.com, is compromised this morning. The site is serving compromised ads. Until they get this problem cleared up, I wouldn&#39;t go there.&lt;br /&gt;&lt;br /&gt;This is the second WV law related site to be compromised recently. The WV State Bar &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html&quot;&gt;reported last week&lt;/a&gt; that its webserver and a number of internal servers were compromised.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/824326126483245644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/824326126483245644' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/824326126483245644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/824326126483245644'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/another-west-virginia-law-related.html' title='Another West Virginia Law Related Website Compromised'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2738479619396743122</id><published>2009-05-03T06:20:00.006-04:00</published><updated>2009-05-03T07:09:39.231-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="conflicker"/><category scheme="http://www.blogger.com/atom/ns#" term="FDA"/><category scheme="http://www.blogger.com/atom/ns#" term="medical devices running windows"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows Update"/><title type='text'>FDA Rule on Appying Windows Patches on Medical Devices Could Put Human Life at Risk</title><content type='html'>One of the scariest uses of Windows OS is that it is installed on medical devices. As a result, every piece of malware coming down the pike can infect this medical devices, putting human life at risk. SANS &lt;a href=&quot;http://www.mercurynews.com/breakingnews/ci_12257206&quot;&gt;announced last week&lt;/a&gt; that it had discovered Conficker worm infections on medical devices, including MRI machines.&lt;br /&gt;&lt;blockquote&gt;A few weeks ago, we discovered medical devices, MRI machines, infected with Conficker,&quot; said Marcus Sachs, director of the Internet Storm Center, an early warning system for Internet threats that is operated by the SANS Institute.&lt;br /&gt;&lt;br /&gt;Around March 24, researchers monitoring the worm noticed that an imaging machine used to review high-resolution images was reaching out over the Internet to get instructions — presumably from the programmers who created Conficker.&lt;br /&gt;&lt;br /&gt;The researchers dug deeper and discovered that more than 300 similar devices at hospitals around the world had been compromised. The manufacturer of the devices told them none of the machines were supposed to be connected to the Internet — and yet they were. And because the machines were running an unpatched version of Microsoft&#39;s operating system used in embedded devices they were vulnerable.&lt;br /&gt;&lt;br /&gt;Normally, the solution would be simply to install a patch, which Microsoft released in October. But the device manufacturer said rules from the U.S. Food and Drug Administration required that a 90-day notice be given before the machines could be patched.&lt;/blockquote&gt;&lt;br /&gt;Yes you read that correctly. Windows patches for medical devices must be approved by the FDA, and the FDA must receive a 90-day notice to apply patches. The result is epic fail that could put human life at risk. This FDA rule needs to be revisited.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2738479619396743122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/2738479619396743122' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2738479619396743122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2738479619396743122'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/fda-rule-on-appying-windows-patches.html' title='FDA Rule on Appying Windows Patches on Medical Devices Could Put Human Life at Risk'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-9186141510383104467</id><published>2009-04-29T08:09:00.004-04:00</published><updated>2009-04-29T08:20:30.899-04:00</updated><title type='text'>WV State Bar Data Breach</title><content type='html'>The WV State Bar &lt;a href=&quot;http://www.wsaz.com/news/headlines/43912207.html&quot;&gt;reported yesterday&lt;/a&gt; that the &lt;a href=&quot;http://www.wvbar.org/&quot;&gt;Bar&#39;s website&lt;/a&gt; and servers on its internal network have been compromised. The compromised data might include members&#39; names, mail and email addresses, lawyer identification numbers, and the Social Security numbers of some members and former members.&lt;br /&gt;&lt;br /&gt;The Bar says there is no evidence that the information listed above has been used for identity theft or fraud, but that members who have concerns should check their credit reports.&lt;br /&gt;&lt;br /&gt;The &lt;a href=&quot;http://www.wvbar.org/&quot;&gt;WV State Bar site&lt;/a&gt; remains offline this morning. The Bar has called in data forensics experts to try to determine the extent of the breach. They are in the process of rebuilding the site from scratch.&lt;br /&gt;&lt;br /&gt;The Bar&#39;s website &lt;a href=&quot;http://www.charlestondailymail.com/News/200809100161&quot;&gt;first showed signs of problems back in September&lt;/a&gt; when it was blocked by Google&#39;s Safe Browsing feature for serving malware.  And I&#39; ve posted about the &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html&quot;&gt;Bar&#39;s website hosting malware&lt;/a&gt; earlier this month.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/9186141510383104467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/9186141510383104467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9186141510383104467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9186141510383104467'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html' title='WV State Bar Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1908686881423221727</id><published>2009-04-23T08:16:00.004-04:00</published><updated>2009-04-23T08:30:06.970-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Elite"/><category scheme="http://www.blogger.com/atom/ns#" term="Prolaw"/><category scheme="http://www.blogger.com/atom/ns#" term="Thomson"/><title type='text'>Elite User Conference 2009 coming up Jun 9-11</title><content type='html'>Just saw a thread on the &lt;a href=&quot;http://tech.groups.yahoo.com/group/prolaw/&quot;&gt;FWMI ProLaw Yahoo Group&lt;/a&gt; about the &lt;a href=&quot;http://www.elite.com/uc09/&quot;&gt;Elite User Conference 2009&lt;/a&gt; coming up Jun 9-11 at the Hilton San Diego Bayfront in San Diego, CA. As in past years, Thomson is rolling Prolaw into the Elite Conference.&lt;br /&gt;&lt;br /&gt;Thomson is offering Individual and Multiple Registration discounts:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Receive a $100 discount off the $1,495 Standard Registration Fee when you register before May 8th. That means you attend for just $1,395.&lt;br /&gt;&lt;br /&gt;Multiple Registrations: Register multiple employees before May 8th and receive even more discounts. The second person you register pays only $1,095 and the third person pays just $795!&lt;/blockquote&gt;&lt;br /&gt;It would be nice to see Prolaw have its own user conference again. I&#39;m not sure how useful the Elite Conference is to Prolaw users.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1908686881423221727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/1908686881423221727' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1908686881423221727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1908686881423221727'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/elite-user-conference-2009-coming-up.html' title='Elite User Conference 2009 coming up Jun 9-11'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5105093853495623380</id><published>2009-04-23T05:54:00.007-04:00</published><updated>2009-04-23T06:10:45.111-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Antivirus2009"/><category scheme="http://www.blogger.com/atom/ns#" term="Google Safe Browsing"/><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection"/><category scheme="http://www.blogger.com/atom/ns#" term="WV State Bar"/><title type='text'>WV State Bar Site Remains Offline After Last Malware Infection</title><content type='html'>The WV State Bar site remains offline today. The site was taken offline last Friday, four days after it was discovered &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html&quot;&gt;the site was hosting malware&lt;/a&gt; yet again. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In an email, the Bar published information the site would be offline for maintenance:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;“SPECIAL EDITION BAR BLAST”&lt;br /&gt;&lt;br /&gt;* wvbar.org is currently offline for maintenance&lt;br /&gt;* For Casemaker access, click here - https://demo.lawriter.net &lt;https://demo.lawriter.net&gt;  - login and password are westva (lowercase)&lt;br /&gt;* For registration &amp;amp; other inquiries regarding the 2009 Annual Meeting, please contact Cheryl L. Wright at&lt;br /&gt;cheryl@wvbar.org or 304.558.0828&lt;br /&gt;*For Information regarding pro hac vice admissions, please contact Cheryl L. Wright at cheryl@wvbar.org &lt;mailto:cheryl@wvbar.org&gt;  or&lt;br /&gt;304.558.0828&lt;/mailto:cheryl@wvbar.org&gt;&lt;/https://demo.lawriter.net&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;https://demo.lawriter.net&gt;&lt;mailto:cheryl@wvbar.org&gt;This is the same information currently on the website at &lt;a href=&quot;http://www.wvbar.org/&quot;&gt;http://www.wvbar.org/&lt;/a&gt;. It appears the site has been taken down to fix whatever problem was causing the site &lt;a href=&quot;http://www.charlestondailymail.com/News/200809100161&quot;&gt;to be compromised&lt;/a&gt; on an almost monthly basis. &lt;/mailto:cheryl@wvbar.org&gt;&lt;/https://demo.lawriter.net&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While my firm has not reported any infections that can be traced to the Bar&#39;s website, it remains to be seen if others firms have been so lucky.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5105093853495623380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/5105093853495623380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5105093853495623380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5105093853495623380'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-remains-offline-after.html' title='WV State Bar Site Remains Offline After Last Malware Infection'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1036342709991873411</id><published>2009-04-18T05:39:00.003-04:00</published><updated>2009-04-18T05:41:24.381-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Bulletin Webcast Video"/><title type='text'>Microsoft April 2009 Security Bulletin Webcast Video</title><content type='html'>In case you missed it, here it is. I signed up for it, but had to miss it.&lt;br /&gt;&lt;br /&gt;&lt;object data=&quot;data:application/x-silverlight-2,&quot; type=&quot;application/x-silverlight-2&quot; height=&quot;240&quot; width=&quot;320&quot;&gt;&lt;br /&gt;&lt;param name=&quot;source&quot; value=&quot;http://edge.technet.com/App_Themes/default/VideoPlayer2009_01_29.xap&quot;&gt;&lt;br /&gt;&lt;param name=&quot;initParams&quot; value=&quot;m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/6/9/7/2/MSRCwebcastApril09_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/6/9/7/2/MSRCwebcastApril09_large_edge.png, postid=2796&quot;&gt;&lt;br /&gt;&lt;param name=&quot;background&quot; value=&quot;#00FFFFFF&quot;&gt;&lt;br /&gt;&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkID=124807&quot; style=&quot;text-decoration: none;&quot;&gt;&lt;br /&gt;&lt;img src=&quot;http://go.microsoft.com/fwlink/?LinkId=108181&quot; alt=&quot;Get Microsoft Silverlight&quot; style=&quot;border-style: none;&quot; /&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1036342709991873411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/1036342709991873411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1036342709991873411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1036342709991873411'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/microsoft-april-2009-security-bulletin.html' title='Microsoft April 2009 Security Bulletin Webcast Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6257161500094258385</id><published>2009-04-18T04:30:00.003-04:00</published><updated>2009-04-18T04:43:05.725-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Gozi trojan"/><category scheme="http://www.blogger.com/atom/ns#" term="RBN"/><category scheme="http://www.blogger.com/atom/ns#" term="Russian Business Network"/><title type='text'>Video: Gozi trojan</title><content type='html'>A member of my team forwarded &lt;a href=&quot;http://www.youtube.com/watch?v=lw9IeuKkNbc&quot;&gt;this video&lt;/a&gt; to me last week. (I&#39;m sorry I can&#39;t embed the video. Embedding disabled by request)  The video shows the Russian Business Network (RBN) partners HangUP Team and 76service subscription-based data mining service for stolen data gathered by the Gozi trojan.&lt;br /&gt;&lt;br /&gt;It&#39;s another fascinating look a tool build for hacker by hackers for profit rather than fun. For another fascinating look at a current hacking tool, take a look at &lt;a href=&quot;http://lawfirmit.blogspot.com/2009/04/symantec-video-using-backdoorghostnet.html&quot;&gt;the GhostNet video&lt;/a&gt; I previously posted.</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6257161500094258385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/15182237/6257161500094258385' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6257161500094258385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6257161500094258385'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/video-gozi-trojan.html' title='Video: Gozi trojan'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry></feed>