<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Liquidmatrix Security Digest</title>
	
	<link>http://www.liquidmatrix.org/blog</link>
	<description>Bringing Fire To The Village: Your Source For Computer, Network &amp; Information Security News from Dave Lewis, Security Blogger</description>
	<lastBuildDate>Sat, 13 Mar 2010 21:52:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Liquidmatrix" /><feedburner:info uri="liquidmatrix" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><image><link>http://www.liquidmatrix.org/blog/</link><url>http://www.liquidmatrix.org/images/logoLSDsmall.jpg</url><title>Liquidmatrix Security Digest</title></image><feedburner:emailServiceId>Liquidmatrix</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>South Korea Dealing With Massive Data Breach</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/t9kjsJxxQlk/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/13/south-korea-dealing-with-massive-data-breach/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 21:52:34 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Crime]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8773</guid>
		<description><![CDATA[
In what has the hallmarks of being the largest recorded data breach in South Korea ever, 20 million+ individuals have had their data exposed. As a result of this an investigation has begun.
From AFP:
South Korea said Friday it would launch a probe into security systems of major retailer Shinsegae and 24 other companies after private [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/southkorea.jpg" alt="" title="southkorea" width="450" height="299" class="aligncenter size-full wp-image-8775" /></p>
<p>In what has the hallmarks of being the largest recorded data breach in South Korea ever, 20 million+ individuals have had their data exposed. As a result of this an investigation has begun.</p>
<p>From AFP:</p>
<blockquote><p>South Korea said Friday it would launch a probe into security systems of major retailer Shinsegae and 24 other companies after private data on some 20 million customers was leaked.</p>
<p>The move came a day after police arrested three South Koreans for selling private information, including IDs, passwords and addresses, of more than 20 million compatriots online.</p>
<p>The three suspects bought the data from Chinese hackers who are still at large, police said.</p></blockquote>
<p>Ah, the spectre of the ever present Chinese hacker. The Korea legal structure is definitely taking this problem seriously. Just last month the heads of four ISPs were each sentenced to a month in jail for facilitating illegal online activity. Hmm. Now there&#8217;s a concept.</p>
<p><a href="http://www.google.com/hostednews/afp/article/ALeqM5gU4DwmPkiau1V6GE0blDIG8H6DTA">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/imcomkorea/3021129297/">US Army Korea &#8211; IMCOM</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/NZI7slPAaTfwGbv8ZLe255AFS70/0/da"><img src="http://feedads.g.doubleclick.net/~a/NZI7slPAaTfwGbv8ZLe255AFS70/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/NZI7slPAaTfwGbv8ZLe255AFS70/1/da"><img src="http://feedads.g.doubleclick.net/~a/NZI7slPAaTfwGbv8ZLe255AFS70/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=t9kjsJxxQlk:Uyunrlebapw:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=t9kjsJxxQlk:Uyunrlebapw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=t9kjsJxxQlk:Uyunrlebapw:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=t9kjsJxxQlk:Uyunrlebapw:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=t9kjsJxxQlk:Uyunrlebapw:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/t9kjsJxxQlk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/13/south-korea-dealing-with-massive-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/13/south-korea-dealing-with-massive-data-breach/</feedburner:origLink></item>
		<item>
		<title>Atlanta VA Hospital Breach Under Investigation</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/lPZIQ1VBmEE/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/13/atlanta-va-hospital-breach-under-investigation/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 21:27:31 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Crime]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8759</guid>
		<description><![CDATA[
This week it appears that the data breaches are falling from the trees. In this particular case a physicians assistant was alleged to have been collecting data on patients. It was apparently for some unsanctioned study. To make matters worse the data was being stored on an unencrypted laptop. 
Now a criminal investigation has begun [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/brokenbones.jpg" alt="" title="brokenbones" width="450" height="338" class="aligncenter size-full wp-image-8761" /></p>
<p>This week it appears that the data breaches are falling from the trees. In this particular case a physicians assistant was alleged to have been collecting data on patients. It was apparently for some unsanctioned study. To make matters worse the data was being stored on an unencrypted laptop. </p>
<p>Now a criminal investigation has begun into the allegations.</p>
<p>From Atlanta Journal Constitution:</p>
<blockquote><p>The inspector general is investigating a report that a physician assistant stored unauthorized clinical information on her personal laptop regarding veterans who were seen at one of the VA specialty clinics, according to the document.</p>
<p>The document said there are reportedly two sets of patient information involved &#8212; one that includes more than 18 years of data, and another that includes up to three years of data.</p>
<p>The agency has yet to determine how many veterans are affected or the degree to which the data contained personal and medical information.</p></blockquote>
<p>From the article it seems unclear as to whether or not any of the data was compromised beyond this particular individual. These are points that will no doubt be addressed as a part of the investigation.</p>
<p><a href="http://www.ajc.com/news/dekalb/security-breach-at-atlanta-365828.html">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/garrulus/113821726/">Garrulus</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/pZgxDVreTFJw082booQsRkoggPw/0/da"><img src="http://feedads.g.doubleclick.net/~a/pZgxDVreTFJw082booQsRkoggPw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/pZgxDVreTFJw082booQsRkoggPw/1/da"><img src="http://feedads.g.doubleclick.net/~a/pZgxDVreTFJw082booQsRkoggPw/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=lPZIQ1VBmEE:DCYE-UJqN8w:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=lPZIQ1VBmEE:DCYE-UJqN8w:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=lPZIQ1VBmEE:DCYE-UJqN8w:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=lPZIQ1VBmEE:DCYE-UJqN8w:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=lPZIQ1VBmEE:DCYE-UJqN8w:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/lPZIQ1VBmEE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/13/atlanta-va-hospital-breach-under-investigation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/13/atlanta-va-hospital-breach-under-investigation/</feedburner:origLink></item>
		<item>
		<title>Student Nabbed For Hacking School Computers</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/zA3INeuXPnU/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/12/student-nabbed-for-hacking-school-computers/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 21:57:45 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Crime]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8752</guid>
		<description><![CDATA[
Sometimes it appears that the influence of the 1983 film &#8220;War Games&#8221; continues to hold sway with people. 
Sometimes, it doesn&#8217;t end so well.
From My Fox Houston:
A 17-year-old Cy-Fair ISD student is facing a felony charge after he allegedly hacked into the district&#8217;s computer security network and caused more than $10,000 in damage.
Cy-Fair High School [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/wargames.jpg" alt="" title="wargames" width="365" height="500" class="aligncenter size-full wp-image-8753" /></p>
<p>Sometimes it appears that the influence of the 1983 film &#8220;<a href="http://www.imdb.com/title/tt0086567/">War Games</a>&#8221; continues to hold sway with people. </p>
<p>Sometimes, it doesn&#8217;t end so well.</p>
<p>From My Fox Houston:</p>
<blockquote><p>A 17-year-old Cy-Fair ISD student is facing a felony charge after he allegedly hacked into the district&#8217;s computer security network and caused more than $10,000 in damage.</p>
<p>Cy-Fair High School student Richard Alan Urban is scheduled to appear in court April 13 on a charge of computer security breach, a state jail felony.</p></blockquote>
<p>The odd thing that I found with this article, about this apparently hapless student from Houston, was that at the end of the article it says that &#8220;The breach only slowed down the servers.&#8221; However earlier in this passage, &#8220;By the next day, more users had been deleted from the network, so the school district&#8217;s technical team began searching for a possible hacker.&#8221;</p>
<p>I have the distinct impression that they do not in fact have a clear grasp on what this person was allegedly able to access. I&#8217;m imagining that this will come out in the wash later.</p>
<p>For more on the story, read on.</p>
<p><a href="http://www.myfoxhouston.com/dpp/news/local/100311-cyfair-student-hacker">Article Link</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/m3ByFKkP_0bUgxOVaCM9aUSgwUk/0/da"><img src="http://feedads.g.doubleclick.net/~a/m3ByFKkP_0bUgxOVaCM9aUSgwUk/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/m3ByFKkP_0bUgxOVaCM9aUSgwUk/1/da"><img src="http://feedads.g.doubleclick.net/~a/m3ByFKkP_0bUgxOVaCM9aUSgwUk/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=zA3INeuXPnU:wWrOl6MzcLk:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=zA3INeuXPnU:wWrOl6MzcLk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=zA3INeuXPnU:wWrOl6MzcLk:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=zA3INeuXPnU:wWrOl6MzcLk:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=zA3INeuXPnU:wWrOl6MzcLk:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/zA3INeuXPnU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/12/student-nabbed-for-hacking-school-computers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/12/student-nabbed-for-hacking-school-computers/</feedburner:origLink></item>
		<item>
		<title>Certified “Pre-Owned” Items</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/HIg6uFWTRtA/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/12/certified-pre-owned-items/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 21:25:23 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Dumbass]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8745</guid>
		<description><![CDATA[
Time and again I read stories about products that come pre-pwned with malicious software. Recently a few people were ruminating about pulling together a list of these battery chargers, digital frames and the like. 
Low and behold one already exists. Something tells me I should have assumed that it would be found here at attrition.org.
From [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/pwned.jpg" alt="" title="pwned" width="410" height="269" class="aligncenter size-full wp-image-8746" /></p>
<p>Time and again I read stories about products that come pre-pwned with malicious software. Recently a few people were ruminating about pulling together a list of these battery chargers, digital frames and the like. </p>
<p>Low and behold one already exists. Something tells me I should have assumed that it would be found here at attrition.org.</p>
<p>From Attrition.org:</p>
<blockquote><p>For reasons unknown, vendors occasionally fail to maintain quality control over the media they ship. Whether it is CD-ROM, DVD, USB or some other form of media, it may contain viruses, trojans or even drug-runner music. When this happens, the software you receive obviously can&#8217;t be trusted in any fashion, and installing software from already compromised media immediately puts your system&#8217;s integrity in question. </p></blockquote>
<p>For more on this be sure to check out their page.</p>
<p><a href="http://attrition.org/errata/cpo/">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/smailtronic/2790736988/">msmail</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/oKrA9LJIkol_A5cKwmmf30_4N4o/0/da"><img src="http://feedads.g.doubleclick.net/~a/oKrA9LJIkol_A5cKwmmf30_4N4o/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/oKrA9LJIkol_A5cKwmmf30_4N4o/1/da"><img src="http://feedads.g.doubleclick.net/~a/oKrA9LJIkol_A5cKwmmf30_4N4o/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=HIg6uFWTRtA:-RylswaSNfQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=HIg6uFWTRtA:-RylswaSNfQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=HIg6uFWTRtA:-RylswaSNfQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=HIg6uFWTRtA:-RylswaSNfQ:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=HIg6uFWTRtA:-RylswaSNfQ:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/HIg6uFWTRtA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/12/certified-pre-owned-items/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/12/certified-pre-owned-items/</feedburner:origLink></item>
		<item>
		<title>SecurityFocus To Shutter</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/GUeHh_ZrAUo/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/12/securityfocus-to-shutter/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 18:28:21 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8734</guid>
		<description><![CDATA[
Well, being buried in meetings this week I missed this announcement from Wednesday. And so ends another the life of another website in the security space. Securityfocus has announced that it has come to the end of its run. The content from SecurityFocus will ultimately be assimilated folded up into the Symantec Connect site.
From SecurityFocus:
&#8230;the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/LocutusOfBorg.jpg" alt="" title="LocutusOfBorg" width="461" height="357" class="aligncenter size-full wp-image-8735" /></p>
<p>Well, being buried in meetings this week I missed this announcement from Wednesday. And so ends another the life of another website in the security space. Securityfocus has announced that it has come to the end of its run. The content from SecurityFocus will ultimately be <strike>assimilated</strike> folded up into the Symantec Connect site.</p>
<p>From SecurityFocus:</p>
<blockquote><p>&#8230;the time is right for SecurityFocus to focus more on its core components. Beginning March 15, 2010 SecurityFocus will begin a transition of its content to Symantec Connect. As part of its continued commitment to the community, all of SecurityFocus’ mailing lists including Bugtraq and its Vulnerability Database will remain online at www.securityfocus.com There will not be any changes to any of the list charters or policies and the same teams who have moderated list traffic will continue to do so. The vulnerability database will continue to be updated and made available as it is currently. DeepSight and other security intelligence related offerings will remain unchanged while Infocus articles, whitepapers, and other SecurityFocus content will be available off of the main Symantec website in the coming months.</p></blockquote>
<p>Fair thee well.</p>
<p>For more on this read the full posting.</p>
<p><a href="http://www.securityfocus.com/news/11582">Article Link</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/rHFjBUIqpRJOXhvc2q7nmlIXq4M/0/da"><img src="http://feedads.g.doubleclick.net/~a/rHFjBUIqpRJOXhvc2q7nmlIXq4M/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rHFjBUIqpRJOXhvc2q7nmlIXq4M/1/da"><img src="http://feedads.g.doubleclick.net/~a/rHFjBUIqpRJOXhvc2q7nmlIXq4M/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=GUeHh_ZrAUo:w-qsKvd5Rbk:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=GUeHh_ZrAUo:w-qsKvd5Rbk:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=GUeHh_ZrAUo:w-qsKvd5Rbk:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=GUeHh_ZrAUo:w-qsKvd5Rbk:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=GUeHh_ZrAUo:w-qsKvd5Rbk:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/GUeHh_ZrAUo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/12/securityfocus-to-shutter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/12/securityfocus-to-shutter/</feedburner:origLink></item>
		<item>
		<title>Security Briefing: March 11th</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/aQpMPHGXyrY/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/11/security-briefing-march-11th-2/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 11:30:45 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8728</guid>
		<description><![CDATA[
Through the magic of my forgetting to schedule posts, it appears that I missed a couple news posts. My bad. 
Have a good day everyone!
cheers,
Dave
Click here to subscribe to Liquidmatrix Security Digest!.
And now, the news&#8230;

The Beginning of the End of Data Retention &#124; EFF
Thrivent Financial Suffers Breach Of Security &#124; Life and Health Insurance
Staying in [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img class="aligncenter" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg" alt="newspapera.jpg" width="361" height="270" /></p>
<p>Through the magic of my forgetting to schedule posts, it appears that I missed a couple news posts. My bad. </p>
<p>Have a good day everyone!</p>
<p>cheers,<br />
Dave</p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a>.</p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.eff.org/deeplinks/2010/03/beginning-end-data-retention">The Beginning of the End of Data Retention</a> | EFF</li>
<li><a href="http://www.lifeandhealthinsurancenews.com/News/2010/3/Pages/Thrivent-Financial-Suffers-Breach-of-Security.aspx">Thrivent Financial Suffers Breach Of Security</a> | Life and Health Insurance</li>
<li><a href="http://www.creditcardguide.com/creditcards/travel/staying-hotel-watch-credit-cards-231/">Staying in a Hotel? Watch Your Credit Cards</a> | Credit Card Guide</li>
<li><a href="http://www.montrealgazette.com/news/world/American+woman+from+Pennsylvania+arrested+Jihad+Jane/2668138/story.html">All-American &#8216;Jihad Jane&#8217; arrested in terror plot</a> | The Gazette</li>
<li><a href="http://www.theregister.co.uk/2010/03/10/cryptome_paypal/">Cryptome: PayPal a &#8216;liar, cheat and a thug&#8217;</a> | The Register</li>
<li><a href="http://news.bbc.co.uk/2/hi/science/nature/8543292.stm">Nose scanning techniques could sniff out criminals</a> | BBC <i>(WTF?)</i></li>
<li><a href="http://www.reuters.com/article/idUSN1017468320100310">Man charged over bid to damage US security database</a> | Reuters</li>
<li><a href="http://www.mn.ru/news/20100310/55419631.html">Russian hacker scams free flights and flowers</a> | The Moscow News</li>
<li><a href="http://www.hurriyetdailynews.com/n.php?n=police-detains-23-pkk-hackers-in-13-cities-2010-03-10">Police detain 23 PKK hackers in 13 provinces</a> | Hurriyet Daily News</li>
<li><a href="http://www.nextgov.com/nextgov/ng_20100309_9888.php?oref=topstory">VA investigating security breach of veterans&#8217; medical data</a> | Next Gov</li>
<li><a href="http://www.browndailyherald.com/breach-hits-hundreds-of-employees-1.2186648">Breach hits hundreds of employees</a> | Brown Daily Herald</li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feedads.g.doubleclick.net/~a/PDUdf4ZQfY1pHsf6ODXklje6oFU/0/da"><img src="http://feedads.g.doubleclick.net/~a/PDUdf4ZQfY1pHsf6ODXklje6oFU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/PDUdf4ZQfY1pHsf6ODXklje6oFU/1/da"><img src="http://feedads.g.doubleclick.net/~a/PDUdf4ZQfY1pHsf6ODXklje6oFU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=aQpMPHGXyrY:JfdlDF0eBMs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=aQpMPHGXyrY:JfdlDF0eBMs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=aQpMPHGXyrY:JfdlDF0eBMs:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=aQpMPHGXyrY:JfdlDF0eBMs:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=aQpMPHGXyrY:JfdlDF0eBMs:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/aQpMPHGXyrY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/11/security-briefing-march-11th-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/11/security-briefing-march-11th-2/</feedburner:origLink></item>
		<item>
		<title>Social Media Fail Of The Day</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/BwaNZQ3dz4c/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/10/social-media-fail-of-the-day/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 02:57:29 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Dumbass]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8719</guid>
		<description><![CDATA[
Sometimes you find yet another reason why people should be made to pass an intelligence test before they&#8217;re permitted to engage in social media.
Just saying. 
(Thanks to attrition.org for pointing that one out)
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/geebus.png" alt="" title="geebus" width="450" height="440" class="aligncenter size-full wp-image-8720" /></p>
<p>Sometimes you find yet another reason why people should be made to pass an intelligence test <b>before</b> they&#8217;re permitted to engage in social media.</p>
<p>Just saying. </p>
<p><i>(Thanks to attrition.org for pointing that one out)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/MA_Nmxb3GU2crqcr3fM2OBT1WjU/0/da"><img src="http://feedads.g.doubleclick.net/~a/MA_Nmxb3GU2crqcr3fM2OBT1WjU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/MA_Nmxb3GU2crqcr3fM2OBT1WjU/1/da"><img src="http://feedads.g.doubleclick.net/~a/MA_Nmxb3GU2crqcr3fM2OBT1WjU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=BwaNZQ3dz4c:iIwIy1Kqv2g:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=BwaNZQ3dz4c:iIwIy1Kqv2g:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=BwaNZQ3dz4c:iIwIy1Kqv2g:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=BwaNZQ3dz4c:iIwIy1Kqv2g:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=BwaNZQ3dz4c:iIwIy1Kqv2g:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/BwaNZQ3dz4c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/10/social-media-fail-of-the-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/10/social-media-fail-of-the-day/</feedburner:origLink></item>
		<item>
		<title>Pennsylvania CISO Dismissed From Post</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/K7cBxwv86zk/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/10/pennsylvania-ciso-dismissed-from-post/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 02:45:57 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Cyberdouchery]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8709</guid>
		<description><![CDATA[
How stupid is this? Last week Robert Maley was the CISO for the Commonwealth of Pennsylvania giving a presentation at the RSA conference. He was speaking about a hacking incident at PennDOT from last year.
This week? He&#8217;s on the pavement. It would appear that someone in PA overreacted. 
From Patriot News/Penn Live:
Danielle Klinger, a spokeswoman [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/morons.jpg" alt="" title="morons" width="450" height="337" class="aligncenter size-full wp-image-8708" /></p>
<p>How stupid is this? Last week Robert Maley was the CISO for the Commonwealth of Pennsylvania giving a presentation at the <a href="https://cm.rsaconference.com/US10/catalog/speakers/speaker.jsp?key=3141">RSA conference</a>. He was speaking about a hacking incident at PennDOT from last year.</p>
<p>This week? He&#8217;s on the pavement. It would appear that someone in PA overreacted. </p>
<p>From Patriot News/Penn Live:</p>
<blockquote><p>Danielle Klinger, a spokeswoman for the state Department of Transportation, said the agency is not aware of any hacking or breach that occurred involving scheduling system for its driving test. However, she said that a few weeks ago, “we did discover an anomaly and we have actually turned that over to [the state police] for further investigation. We’re not sure what that anomaly is, but it is being investigated. Unfortunately, I can’t provide any more details on it.”</p></blockquote>
<p>Maybe Maley didn&#8217;t have leave to speak publicly about this incident in question. Which is something that PennDOT appears to have developed an Ostrich complex over. Some myopic nitwit thought it merited removing Maley from his post? They claim however that his talk had nothing to do with his dismissal. I&#8217;m not sure I believe that. Timing seems rather odd.</p>
<p>So, what of the alleged hacking incident?</p>
<blockquote><p>Maley is reported to have said the hacker was later found to be someone with a driving school in Philadelphia who exploited a vulnerability in PennDOT’s system to schedule more driving tests than there were allotted slots.</p></blockquote>
<p>This situation seems muddy at best. For more on this story read the article at Penn Live from this morning.</p>
<p><a href="http://www.pennlive.com/midstate/index.ssf/2010/03/pennsylvanias_web_security_off.html">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/olivander/63317272/">Olivander</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/UMwgXJ0ordoNbDrta4AMfoT7JwE/0/da"><img src="http://feedads.g.doubleclick.net/~a/UMwgXJ0ordoNbDrta4AMfoT7JwE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/UMwgXJ0ordoNbDrta4AMfoT7JwE/1/da"><img src="http://feedads.g.doubleclick.net/~a/UMwgXJ0ordoNbDrta4AMfoT7JwE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=K7cBxwv86zk:eodE1PbkYRE:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=K7cBxwv86zk:eodE1PbkYRE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=K7cBxwv86zk:eodE1PbkYRE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=K7cBxwv86zk:eodE1PbkYRE:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=K7cBxwv86zk:eodE1PbkYRE:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/K7cBxwv86zk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/10/pennsylvania-ciso-dismissed-from-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/10/pennsylvania-ciso-dismissed-from-post/</feedburner:origLink></item>
		<item>
		<title>CSIS Goes Looking For Help</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/WB9PDc7eIuE/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/08/csis-goes-looking-for-help/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 03:14:31 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Spy Game]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8703</guid>
		<description><![CDATA[
With the rising tide of threats it has become apparent to the powers that be in Ottawa that they need some help. Now, they&#8217;ve turned to private industry for help. If film is any indication that isn&#8217;t always the best route. 
Sorry, couldn&#8217;t resist.
From The Globe and Mail:
CSIS&#8217;s corporate-outreach program, which started in the 1990s, [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/handout.jpg" alt="" title="handout" width="375" height="500" class="aligncenter size-full wp-image-8704" /></p>
<p>With the rising tide of threats it has become apparent to the powers that be in Ottawa that they need some help. Now, they&#8217;ve turned to private industry for help. If film is <a href="http://www.imdb.com/title/tt0107978/plotsummary">any indication</a> that isn&#8217;t always the best route. </p>
<p>Sorry, couldn&#8217;t resist.</p>
<p>From The Globe and Mail:</p>
<blockquote><p>CSIS&#8217;s corporate-outreach program, which started in the 1990s, largely fell by the wayside during the years after the Sept. 11 attacks in the United States, when fighting terrorism absorbed nearly all the spy service&#8217;s energies.</p>
<p>But emerging threats – including shadowy-but-powerful hacker networks based in China – are sparking a renewed federal interest in forging partnerships between the corporate and intelligence worlds.</p>
<p>“CSIS has and continues to speak with various corporations in Canada on potential security threats, which may have an impact on national security interests,” CSIS spokeswoman Isabelle Scott said in an e-mailed response to questions from The Globe and Mail. “CSIS alerts firms to common covert methods used by those who may target them.”</p></blockquote>
<p>The real harm here is that organization such as CSIS don&#8217;t have the resources to hire and retain the talent required to handle emerging threats.</p>
<p>For more on this, read on.</p>
<p><a href="http://www.theglobeandmail.com/news/technology/cyberattacks-push-csis-to-reach-out-to-business/article1494219/">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/romulusnr/414908896/">romulusnr</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/DZI8nIPRR5uVEQIcz0lzKqqzRzM/0/da"><img src="http://feedads.g.doubleclick.net/~a/DZI8nIPRR5uVEQIcz0lzKqqzRzM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/DZI8nIPRR5uVEQIcz0lzKqqzRzM/1/da"><img src="http://feedads.g.doubleclick.net/~a/DZI8nIPRR5uVEQIcz0lzKqqzRzM/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=WB9PDc7eIuE:fgIEcKAN2kA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=WB9PDc7eIuE:fgIEcKAN2kA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=WB9PDc7eIuE:fgIEcKAN2kA:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=WB9PDc7eIuE:fgIEcKAN2kA:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=WB9PDc7eIuE:fgIEcKAN2kA:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/WB9PDc7eIuE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/08/csis-goes-looking-for-help/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/08/csis-goes-looking-for-help/</feedburner:origLink></item>
		<item>
		<title>Remote Apache Vulnerability Announced</title>
		<link>http://feedproxy.google.com/~r/Liquidmatrix/~3/Hwblvi5koFE/</link>
		<comments>http://www.liquidmatrix.org/blog/2010/03/08/remote-apache-vulnerability-announced/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 17:01:56 +0000</pubDate>
		<dc:creator>Dave Lewis</dc:creator>
				<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=8697</guid>
		<description><![CDATA[
There was a new vulnerability announced today in Apache webserver. This affects all versions of the popular webserver software platform running on Windows operating systems.
From ZDNet Australia:
&#8220;The vulnerability means that you can take complete control of the web server remotely with system privileges — which is the highest privilege on Windows,&#8221; Edelstein told ZDNet.com.au. &#8220;An [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/03/fail.jpg" alt="" title="fail" width="450" height="337" class="aligncenter size-full wp-image-8698" /></p>
<p>There was a new vulnerability announced today in Apache webserver. This affects all versions of the popular webserver software platform running on Windows operating systems.</p>
<p>From ZDNet Australia:</p>
<blockquote><p>&#8220;The vulnerability means that you can take complete control of the web server remotely with system privileges — which is the highest privilege on Windows,&#8221; Edelstein told ZDNet.com.au. &#8220;An attacker could gain access to, modify and take away data.&#8221;</p>
<p>Edelstein advised users running Apache on Windows platforms to upgrade immediately as users have no way of knowing if their web servers have been compromised. The company&#8217;s security advisory can be accessed here.</p>
<p>&#8220;Whilst in the past it was more overt and attackers would deface website pages, they&#8217;re more likely now to conceal their access to maintain their foothold,&#8221; said Edelstein, giving examples of attackers potentially exploiting the vulnerability by placing hidden pieces of code to capture credit card details from online transactions and install root kits on compromised websites.</p>
</blockquote>
<p>Although, I do find it odd that people would be running Apache on Windows for anything other than a lab instance. But, that&#8217;s just me.</p>
<p><a href="http://www.zdnet.com.au/news/security/soa/Apache-bug-prompts-update-advice/0,130061744,339301617,00.htm">Article Link</a></p>
<p><i>(Image used under CC from <a href="http://www.flickr.com/photos/phobia/2308371224/">Hans Gerwitz</a>)</i></p>

<p><a href="http://feedads.g.doubleclick.net/~a/WDB5mfBDgPMu1fFYsf1Nuy-RULU/0/da"><img src="http://feedads.g.doubleclick.net/~a/WDB5mfBDgPMu1fFYsf1Nuy-RULU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/WDB5mfBDgPMu1fFYsf1Nuy-RULU/1/da"><img src="http://feedads.g.doubleclick.net/~a/WDB5mfBDgPMu1fFYsf1Nuy-RULU/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:j9gXZds__18"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=j9gXZds__18" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=Hwblvi5koFE:x1V5UvVPr7c:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=Hwblvi5koFE:x1V5UvVPr7c:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=Hwblvi5koFE:x1V5UvVPr7c:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?i=Hwblvi5koFE:x1V5UvVPr7c:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:I9og5sOYxJI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=I9og5sOYxJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Liquidmatrix?a=Hwblvi5koFE:x1V5UvVPr7c:cGdyc7Q-1BI"><img src="http://feeds.feedburner.com/~ff/Liquidmatrix?d=cGdyc7Q-1BI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/Hwblvi5koFE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.liquidmatrix.org/blog/2010/03/08/remote-apache-vulnerability-announced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.liquidmatrix.org/blog/2010/03/08/remote-apache-vulnerability-announced/</feedburner:origLink></item>
	</channel>
</rss>
