<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>AttackVector.org</title>
	
	<link>http://www.attackvector.org</link>
	<description>Shedding Light on the Dark Side</description>
	<lastBuildDate>Sat, 26 May 2012 19:09:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/attackvector" /><feedburner:info uri="attackvector" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nd/2.5/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nd/2.5/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>attackvector</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Dwolla – Is it worth the risk?</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/uzSSjOGsEdQ/</link>
		<comments>http://www.attackvector.org/?p=676#comments</comments>
		<pubDate>Sat, 26 May 2012 19:01:57 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=676</guid>
		<description><![CDATA[I was recently discussing Dwolla with a colleague.   While I think it is a great idea, I&#8217;m not sure it will replace credit cards anytime soon. Here&#8217;s my thoughts: 1) Dwolla offers great benefits towards a merchant than an end-user who uses its services &#8211; There&#8217;s little incentive for a consumer to use this service [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/ERRXzfuK3FjWmzr_ozTL4CO80-0/0/da"><img src="http://feedads.g.doubleclick.net/~a/ERRXzfuK3FjWmzr_ozTL4CO80-0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/ERRXzfuK3FjWmzr_ozTL4CO80-0/1/da"><img src="http://feedads.g.doubleclick.net/~a/ERRXzfuK3FjWmzr_ozTL4CO80-0/1/di" border="0" ismap="true"></img></a></p><p>I was recently discussing <a title="Dwolla" href="https://www.dwolla.com">Dwolla</a> with a colleague.   While I think it is a great idea, I&#8217;m not sure it will replace credit cards anytime soon.</p>
<p><strong>Here&#8217;s my thoughts:</strong></p>
<p>1) Dwolla offers great benefits towards a merchant than an end-user who uses its services &#8211; There&#8217;s little incentive for a consumer to use this service to pay for common everyday purchases versus using a credit card.   The majority of the time, the merchant eats the costs of doing business charged by the credit card company.  This is rarely passed on to the consumer.  There are some exceptions to this but this is rare in my experience.   The merchant however will be saving big on this yearly.  2-5%  plus a transaction fee per item purchased adds up and would be significant savings to a merchant.</p>
<p>2) A consumer is safer using a credit card &#8211; The consumer has much less risk using a credit card than a service like Dwolla.   The maximum liability for most end-users is $50 or less with most credit card companies.   The money never goes directly from their bank account.  I, for one, am extremely hesitant to give any service my bank account information to anyone on the web. I understand the argument that people are smarter paying with cash.  However, I think someone can be just as smart paying with a credit card and paying off the bills before the end of the month.</p>
<p>If you compromise my credit card, I&#8217;m at fault for a maximum of $50 and the credit card company will do everything in their power to track down who committed the fraud, especially if a large amount was charged.  If the fraud occurs with a personal bank account, I don&#8217;t think a bank will be as eager to help and return your money, especially if it is a higher amount.  They may return what you lost if it is a smaller amount (under $1000 or relative to what you had in your bank account).  What could happen if my Dwolla account was compromised, it&#8217;s directly linked to my bank account.  It&#8217;s sort of the same risk as using PayPal.</p>
<p><strong>Instances where I believe Dwolla will be effectively used and may take off:</strong></p>
<p>1) Transfers between two or more 100% trusted parties &#8211; paying rent, paying utility bills, lending money to friends/family, etc.  This is better than PayPal, bank transfers or credit card charges, especially if you trust who you are sending money to and trust to get the money back.</p>
<p>I&#8217;m interested in hearing from people who are have used Dwolla and seeing what their thoughts and experiences are.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=uzSSjOGsEdQ:Md-5evxmVRg:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=uzSSjOGsEdQ:Md-5evxmVRg:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=uzSSjOGsEdQ:Md-5evxmVRg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=uzSSjOGsEdQ:Md-5evxmVRg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=uzSSjOGsEdQ:Md-5evxmVRg:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/uzSSjOGsEdQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=676</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=676</feedburner:origLink></item>
		<item>
		<title>SANS Work Study Program</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/1cd3TAF0H8E/</link>
		<comments>http://www.attackvector.org/?p=671#comments</comments>
		<pubDate>Sat, 19 May 2012 18:35:38 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=671</guid>
		<description><![CDATA[I just found out about this program recently.  I&#8217;m not endorsing SANS/GIAC so to each his/her own. I decided to give it a shot.  I applied and got accepted to the SANSFIRE 2012 conference helping out with the SEC660 &#8211; Advanced Penetration Testing, Exploits, and Ethical Hacking course.  I&#8217;ll post back after it is over [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/zBVl2IDcdz1Plc6eb9ph7UvqOVc/0/da"><img src="http://feedads.g.doubleclick.net/~a/zBVl2IDcdz1Plc6eb9ph7UvqOVc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/zBVl2IDcdz1Plc6eb9ph7UvqOVc/1/da"><img src="http://feedads.g.doubleclick.net/~a/zBVl2IDcdz1Plc6eb9ph7UvqOVc/1/di" border="0" ismap="true"></img></a></p><p>I just found out about this program recently.  I&#8217;m not endorsing SANS/GIAC so to each his/her own.</p>
<p>I decided to give it a shot.  I applied and got accepted to the SANSFIRE 2012 conference helping out with the <a title="SEC660 - Advanced Penetration Testing, Exploits, and Ethical Hacking" href="https://www.sans.org/sansfire-2012/description.php?tid=5285" target="_blank">SEC660 &#8211; Advanced Penetration Testing, Exploits, and Ethical Hacking </a>course.  I&#8217;ll post back after it is over and say how my experience was.</p>
<p>Basically for the $850, you get access to the class and materials, access to the on-demand training for the class for 4 months, access to after-hour events/training, and free exam (GXPN in my case) if you are local to the conference or stay at the conference hotel.   In exchange, you&#8217;re giving up a week to attend the conference (which you would have done anyway if you were taking a class) and you&#8217;re an extension of the SANS staff so you&#8217;re helping out where needed.</p>
<p><a title="SANS Work Study Program" href="https://www.sans.org/work-study/">SANS Work Study Program</a></p>
<p>&nbsp;</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=1cd3TAF0H8E:gjyMrVcIoiU:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=1cd3TAF0H8E:gjyMrVcIoiU:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=1cd3TAF0H8E:gjyMrVcIoiU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=1cd3TAF0H8E:gjyMrVcIoiU:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=1cd3TAF0H8E:gjyMrVcIoiU:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/1cd3TAF0H8E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=671</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=671</feedburner:origLink></item>
		<item>
		<title>Czech Social Engineers Steal a Bridge</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/4RIGoSVDpjU/</link>
		<comments>http://www.attackvector.org/?p=667#comments</comments>
		<pubDate>Tue, 08 May 2012 01:46:56 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=667</guid>
		<description><![CDATA[I just read this article on the Social-Engineer.org newsletter and couldn&#8217;t help but smile Two different perspectives: The Sydney Morning Herald &#8211; Thieves Steal 10-tonne bridge The Vancouver Sun &#8211; Czech thieves steal 10-tonne metal bridge Basically, they tricked the the local depot workers and supposedly the police with their story and fake documents.  Only [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/lLIDk8qKGhHe-91O5RKZ9E1YbKQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/lLIDk8qKGhHe-91O5RKZ9E1YbKQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/lLIDk8qKGhHe-91O5RKZ9E1YbKQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/lLIDk8qKGhHe-91O5RKZ9E1YbKQ/1/di" border="0" ismap="true"></img></a></p><p>I just read this article on the Social-Engineer.org newsletter and couldn&#8217;t help but smile <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Two different perspectives:</p>
<p><a title="Thieves steal 10-tonne bridge " href="http://www.smh.com.au/world/strangebuttrue/thieves-steal-10tonne-bridge-20120504-1y2rh.html">The Sydney Morning Herald &#8211; Thieves Steal 10-tonne bridge</a></p>
<p><a title="Czech thieves steal 10-tonne metal bridge" href="www.vancouversun.com/Czech+thieves+steal+tonne+metal+bridge/6560828/story.html" target="_blank">The Vancouver Sun &#8211; Czech thieves steal 10-tonne metal bridge</a></p>
<p>Basically, they tricked the the local depot workers and supposedly the police with their story and fake documents.  Only after the entire bridge and tracks were stolen did anyone from the rail station try to verify the authenticity of the paperwork.</p>
<p>I&#8217;m guessing it could also be an inside job?</p>
<p>Here&#8217;s Chris Hadnagy&#8217;s story from the Social-Engineer.org newsletter:</p>
<p>Czech Social Engineers Steal a Bridge</p>
<p>In the town of  Slavkov, Czechoslovakia, a gang of <a href="http://www.social-engineer.org/framework/Real_World_Social_Engineering_Examples:_Con_Men" target="_blank">social engineers</a> arrived at the train station one morning posing as construction workers. The gang approached the depot personnel with work orders to demolish the steel footbridge that went over the tracks as well as a portion of railway track supposedly to make room for a cycle path. Apparently, the documents and the story were official enough that depot personnel approved the work order and the gang began work dismantling the bridge.<br />
<img src="https://lh4.googleusercontent.com/ro6LeA-tT7jbSOqiedDwbgFRvuGBxeNBl5L5CgVd6tmzgjNOho7DGgUxD1XOwPqS-ONKlKA07Tinz5nLGaaftZHNyfCH7QOPcXGr1Ra7920dhVTHFGo" alt="" width="215px;" height="246px;" /></p>
<p>One Russian newspaper stated that a group of police stopped the thieves and when the men presented their forged paperwork, the police left them alone.  The paperwork looked legit and seemed to be in order.</p>
<p>Only after the bridge and tracks had been fully dismantled and hauled away did anyone from the rail station bother to verify the authenticity of the documentation along with the story told. Imagine their surprise when they learned there was no such work order to demolish the bridge and that thieves just stole a bridge right under their noses! It is estimated to cost millions of dollars in steel to rebuild the bridge.</p>
<p><a href="http://www.social-engineer.org/framework/Successful_Pretexting" target="_blank">Forged documentation </a>is one of the social engineer’s favorite tools and depending on the quality of the forgery, can yield devastating results. With a simple badge printing tool, found easily on the Internet, combined with the plethora of employee badges that can be found scattered about Facebook, Flickr, and Twitter, forged documents can go a long way. At last year’s Social Engineering Capture the Flag event, at least two contestants discovered badges that clearly identified every piece of information an attacker would need to duplicate the badge.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=4RIGoSVDpjU:eBN3TmdPDu8:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=4RIGoSVDpjU:eBN3TmdPDu8:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=4RIGoSVDpjU:eBN3TmdPDu8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=4RIGoSVDpjU:eBN3TmdPDu8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=4RIGoSVDpjU:eBN3TmdPDu8:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/4RIGoSVDpjU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=667</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=667</feedburner:origLink></item>
		<item>
		<title>Favorite IT/Security Related and General Podcasts</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/fHkvcpLbiA0/</link>
		<comments>http://www.attackvector.org/?p=665#comments</comments>
		<pubDate>Mon, 07 May 2012 22:18:19 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=665</guid>
		<description><![CDATA[Below are some of the IT/Security related and General pod-casts I try to keep up regularly.  I don&#8217;t have time to listen to them all but I use BeyondPod on my Android to automatically download them so I have them around when I do get time to listen.   It syncs up with Google Reader as [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/0kWqPP0r5SFO7vjukJwZhZuMFM8/0/da"><img src="http://feedads.g.doubleclick.net/~a/0kWqPP0r5SFO7vjukJwZhZuMFM8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/0kWqPP0r5SFO7vjukJwZhZuMFM8/1/da"><img src="http://feedads.g.doubleclick.net/~a/0kWqPP0r5SFO7vjukJwZhZuMFM8/1/di" border="0" ismap="true"></img></a></p><p>Below are some of the IT/Security related and General pod-casts I try to keep up regularly.  I don&#8217;t have time to listen to them all but I use BeyondPod on my Android to automatically download them so I have them around when I do get time to listen.   It syncs up with Google Reader as well so I throw all my pod-casts into a folder there and let BeyondPod automatically retrieve them.</p>
<p>If anyone has any recommendations for other good ones, let me know.</p>
<p>Bobby</p>
<p><a title="InfoSec Daily Podcast" href="http://www.isdpodcast.com/" target="_blank">InfoSec Daily Podcast</a> &#8211; Great team that does a daily catch-up and review of the news in the Information Security world.  They&#8217;re dedicated and I don&#8217;t think they&#8217;ve ever missed a day since they&#8217;ve started.  They usually keep the episodes at about 35-40 minutes.  Good enough for listening while working out <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a title="SecurityNow!" href="https://www.grc.com/securitynow.htm" target="_blank">SecurityNow!</a> &#8211; Leo and Steve are a good pair and this is a great podcast especially if you are just getting into security.  They do a 1-1 1/2 hour long podcast every week.</p>
<p><a title="Social-Engineering Podcast" href="http://www.social-engineer.org/podcast" target="_blank">Social-Engineer.org Podcast</a> &#8211; This is a great podcast if you are interested in social engineering.  Most of the major attacks you&#8217;ve heard about lately were due to social engineers (RSA, Google, major defense contractors, etc).   They usually have experts in various fields who do a talk on their professional insights into social engineering.</p>
<p><a title="Packet Pushers Podcast" href="http://packetpushers.net/" target="_blank">Packet Pushers Podcast</a> &#8211; This seems to be an interesting look at networking and security.  I&#8217;ve just started listening to it and it&#8217;s been good so far.</p>
<p><a title="CERT's Podcast Series: Security for Business Leaders" href="https://www.cert.org/podcast/" target="_blank">CERT&#8217;s Podcast Series: Security for Business Leaders</a> &#8211; This one can be dry most times to be honest but it&#8217;s an interesting look especially if you are working on the federal side as they tailor many of the talks towards different NIST and Federal related policies, publications, etc.</p>
<p><a title="Fareed Zakaria's GPS" href="http://globalpublicsquare.blogs.cnn.com/" target="_blank">Fareed Zakaria&#8217;s GPS</a> &#8211; If you ever seen the show on CNN, this is just the audio version of it on a podcast.  I like Fareed&#8217;s way of looking at the world and it&#8217;s a good way to catch up on the major news going on in the world</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=fHkvcpLbiA0:i7Kig0KdbTw:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=fHkvcpLbiA0:i7Kig0KdbTw:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=fHkvcpLbiA0:i7Kig0KdbTw:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=fHkvcpLbiA0:i7Kig0KdbTw:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=fHkvcpLbiA0:i7Kig0KdbTw:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/fHkvcpLbiA0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=665</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=665</feedburner:origLink></item>
		<item>
		<title>Ads on RSS feeds</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/l25C6XhDckI/</link>
		<comments>http://www.attackvector.org/?p=661#comments</comments>
		<pubDate>Mon, 07 May 2012 20:00:16 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=661</guid>
		<description><![CDATA[Is anyone seeing ads on the RSS feeds?  I was able to remove the ads from the web pages itself.  However, I&#8217;m still seeing ads on the RSS feeds from Google Ad Choices but a few friends who I&#8217;ve asked about it aren&#8217;t seeing it. If anyone else is seeing them, can you let me [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/uijB2oXUHgva0gJlMdnTb4bvjN4/0/da"><img src="http://feedads.g.doubleclick.net/~a/uijB2oXUHgva0gJlMdnTb4bvjN4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/uijB2oXUHgva0gJlMdnTb4bvjN4/1/da"><img src="http://feedads.g.doubleclick.net/~a/uijB2oXUHgva0gJlMdnTb4bvjN4/1/di" border="0" ismap="true"></img></a></p><p>Is anyone seeing ads on the RSS feeds?  I was able to remove the ads from the web pages itself.  However, I&#8217;m still seeing ads on the RSS feeds from Google Ad Choices but a few friends who I&#8217;ve asked about it aren&#8217;t seeing it.</p>
<p>If anyone else is seeing them, can you let me know?   Anyone know how to get rid of the Ad Choices ads from the RSS feeds?  I use Google Reader mostly to view all of the blog RSS feeds and I haven&#8217;t had it inject ads before.  I&#8217;m seeing ads through all of my devices&#8230;mobile phone, tablet and laptop.</p>
<p>Bobby</p>
<p>&nbsp;</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=l25C6XhDckI:I5Y-4Ph8yRc:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=l25C6XhDckI:I5Y-4Ph8yRc:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=l25C6XhDckI:I5Y-4Ph8yRc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=l25C6XhDckI:I5Y-4Ph8yRc:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=l25C6XhDckI:I5Y-4Ph8yRc:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/l25C6XhDckI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=661</wfw:commentRss>
		<slash:comments>6</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=661</feedburner:origLink></item>
		<item>
		<title>AttackVector.org – Under New Management</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/AbTrG0dBLiU/</link>
		<comments>http://www.attackvector.org/?p=658#comments</comments>
		<pubDate>Mon, 07 May 2012 15:18:20 +0000</pubDate>
		<dc:creator>Bobby</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[APOVPN]]></category>
		<category><![CDATA[TunnelGuard]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=658</guid>
		<description><![CDATA[Quick intro… I’m Bobby and I worked out an agreement with Matt to take over AttackVector.org.  Matt has the opportunity to come back and post whenever he has time again. I was a regular reader of this site and enjoyed reading Matt’s postings. A little about me, I’ve been in the U.S. military for 5 [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/Q8Ywi8K18sSvPhrELl_BLWJkmWI/0/da"><img src="http://feedads.g.doubleclick.net/~a/Q8Ywi8K18sSvPhrELl_BLWJkmWI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Q8Ywi8K18sSvPhrELl_BLWJkmWI/1/da"><img src="http://feedads.g.doubleclick.net/~a/Q8Ywi8K18sSvPhrELl_BLWJkmWI/1/di" border="0" ismap="true"></img></a></p><p>Quick intro…</p>
<p>I’m Bobby and I worked out an agreement with Matt to take over AttackVector.org.  Matt has the opportunity to come back and post whenever he has time again. I was a regular reader of this site and enjoyed reading Matt’s postings.</p>
<p>A little about me, I’ve been in the U.S. military for 5 years, worked as a government contractor for a few years and now work as a consultant through my own company, Guarded Horizons Inc.   Altogether,  I’ve been in the IT &amp; security world for 12 years now and was considering getting into blogging so this seemed like a good opportunity to give it a shot.   I also wanted to see the site continuing to offer security related information.  A lot of what I do nowadays is security and network architecture design and deployment. I’d like to get more into pen-testing and security research.</p>
<p>I’ve launched two websites over the last 6 months to a year and now spend a good deal of my time managing everything associated with it. The idea behind the VPN services I offer is to provide security/privacy when you are in public or open WiFi hotspots, in hotels, or traveling outside the U.S. Another use when you are overseas is that it will allow you to access U.S. content that is normally blocked (Netflix, Hulu, Pandora, etc).</p>
<p>You can check them out at <a href="http://www.tunnelguard.com" rel="nofollow">http://www.tunnelguard.com</a> and <a href="http://www.apovpn.com" rel="nofollow">http://www.apovpn.com</a></p>
<p>APOVPN is geared more towards the American &amp; military community living abroad. TunnelGuard is for everyone else. Basically I was getting a lot of questions about what the heck APO means. If you’re not associated with the military or government, it really doesn’t make sense and just sounds like a funny word <img src="https://www.attackvector.org/wp-includes/images/smilies/icon_wink.gif" alt=";-)" /></p>
<p>As far as the site content and moving forward, I moved over all of the site content I could. I don’t think the user accounts moved over properly so users may have to register again. If you have any issues, shoot me a message to <a href="mailto:bobby@attackvector.org">bobby@attackvector.org</a>.</p>
<p>I’m going to keep the website looking the same…minus the advertisements. I’m not a big fan of the Google Ads, I’ll keep one small banner up for my site TunnelGuard and that’s about it.</p>
<p>I’ll try to post regularly and share my thoughts and ideas with the info security world. I have some friends with similar mindsets as well so I’ll see if any of them would be interested in blogging as well.</p>
<p>If there are security minded people following this blog who would be interested in blogging periodically, send me an email!</p>
<p>Bobby</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=AbTrG0dBLiU:8rBwSkWOjeQ:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=AbTrG0dBLiU:8rBwSkWOjeQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=AbTrG0dBLiU:8rBwSkWOjeQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=AbTrG0dBLiU:8rBwSkWOjeQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=AbTrG0dBLiU:8rBwSkWOjeQ:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/AbTrG0dBLiU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=658</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=658</feedburner:origLink></item>
		<item>
		<title>Lets see if I still remember how to do this…</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/FeWc7I5Io2g/</link>
		<comments>http://www.attackvector.org/?p=633#comments</comments>
		<pubDate>Thu, 10 Mar 2011 19:56:15 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Krebs]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[ZeuS]]></category>
		<category><![CDATA[ZeusTracker]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=633</guid>
		<description><![CDATA[Do I still have any regular readers left? I hope so, even though I&#8217;ve greatly neglected you. I wont even bother with excuses. BUT, here&#8217;s a post to prove that I still know what I&#8217;m doing! So, if you&#8217;ve been following some of the other blogs (specifically, Krebs), you&#8217;ve probably seen the hubbub about ZeusTracker. [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/eu1KCOhG0D9PEpKzWW7u4_Db4WI/0/da"><img src="http://feedads.g.doubleclick.net/~a/eu1KCOhG0D9PEpKzWW7u4_Db4WI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/eu1KCOhG0D9PEpKzWW7u4_Db4WI/1/da"><img src="http://feedads.g.doubleclick.net/~a/eu1KCOhG0D9PEpKzWW7u4_Db4WI/1/di" border="0" ismap="true"></img></a></p><p>Do I still have any regular readers left?  I hope so, even though I&#8217;ve greatly neglected you.  I wont even bother with excuses.  BUT, here&#8217;s a post to prove that I still know what I&#8217;m doing!  <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>
<p>So, if you&#8217;ve been following some of the other blogs (specifically, <a href="http://krebsonsecurity.com/2011/03/spyeye-zeus-users-target-tracker-sites/?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29" ref="noindex" target="_blank">Krebs</a>), you&#8217;ve probably seen the hubbub about <a href="https://zeustracker.abuse.ch/" ref="noindex" target="_blank">ZeusTracker</a>.  If not, I highly recommend you click on that previous link and go read.  It&#8217;s long, but quite interesting.</p>
<p>ZeuS, if you&#8217;re unaware, is a big botnet that&#8217;s used heavily in cyber crime.  You don&#8217;t want to get infected by this.  To those who manage networks:  You don&#8217;t want your users to get infected by this.</p>
<p><span id="more-633"></span></p>
<p>ZeusTracker is watching for Zeus C&#038;C traffic via honeypots and documenting the known hosts/domains/IP&#8217;s associated with them.  They&#8217;ve created a nice list that can be easily imported in to iptables, Windows host files, Squid, et. al.</p>
<p>I run Squid on one of the gateways here, so I decided to utilize that to implement this blacklist.  Squid makes this incredibly simple, which is also a big plus.</p>
<p>In your Squid config file, you&#8217;ll see a section that&#8217;s all about ACL&#8217;s (access control lists).  If you scroll down far enough, you&#8217;ll see a section that says:</p>
<blockquote><p>
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
</p></blockquote>
<p>So, the simplest way to implement a blacklist is by adding the following just below that comment.  Mine looks like this:</p>
<pre lang="c">
# ZeuS C&#038;C domains
acl blocksites url_regex "/etc/squid/zeus.txt"
http_access deny blocksites
</pre>
<p>Pretty simple, eh?</p>
<p>&#8216;Course, now you have to create the &#8220;zeus.txt&#8221; file, otherwise that rule isn&#8217;t going to do you any good.  If you go to <a href="https://zeustracker.abuse.ch/blocklist.php" ref="noindex" target="_blank">here</a>, you&#8217;ll see a list of files that all contain the hosts &#038; ip&#8217;s that ZeusTracker knows about.  In this case, you want the one formatted for Squid.</p>
<p>Now, you&#8217;ll need for this to update, say, daily, so you&#8217;ll need to create a script and invoke it via Crontab.  Here&#8217;s my stupid-simple script:</p>
<pre lang="bash">
#!/bin/sh

/bin/rm /etc/squid/zeus.txt
/usr/bin/curl "https://zeustracker.abuse.ch/blocklist.php?download=squidblocklist" >> /etc/squid/zeus.txt
/etc/init.d/squid restart
</pre>
<p>It simply deletes the current zeus.txt file, downloads the newest version via Curl, and then restarts Squid.</p>
<p>This is a really quick &#038; easy way to (help) protect your network from this trojan/worm/whatever you want to call it.  I&#8217;ve noticed recently that even a user who is running a fully patched version of Windows (Vista), with Google Chrome, this thing is still capable of infecting the machine.  I haven&#8217;t found any real good information on how, but from what I&#8217;ve witnessed, it appears to be a Java exploit.</p>
<p>Anyway, give this a shot!</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=FeWc7I5Io2g:V7YKWTkjilo:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=FeWc7I5Io2g:V7YKWTkjilo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=FeWc7I5Io2g:V7YKWTkjilo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=FeWc7I5Io2g:V7YKWTkjilo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=FeWc7I5Io2g:V7YKWTkjilo:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/FeWc7I5Io2g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=633</wfw:commentRss>
		<slash:comments>19</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=633</feedburner:origLink></item>
		<item>
		<title>No, I’m not dead.</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/CxLbkNqG-ks/</link>
		<comments>http://www.attackvector.org/?p=626#comments</comments>
		<pubDate>Thu, 04 Nov 2010 15:37:38 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=626</guid>
		<description><![CDATA[OK, so I&#8217;ve received a couple of emails from different people wondering if I was abducted by the NSA, assassinated, or if I&#8217;m on the run with Julian Assange. No, no, and.. no. Though, that&#8217;d be pretty sweet. Minus being assassinated. That would suck. Honestly, right now, I&#8217;m being pulled in like, 73 different directions. [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/noeu8QEZB1yzNKLUIxFqG-pCHZM/0/da"><img src="http://feedads.g.doubleclick.net/~a/noeu8QEZB1yzNKLUIxFqG-pCHZM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/noeu8QEZB1yzNKLUIxFqG-pCHZM/1/da"><img src="http://feedads.g.doubleclick.net/~a/noeu8QEZB1yzNKLUIxFqG-pCHZM/1/di" border="0" ismap="true"></img></a></p><p>OK, so I&#8217;ve received a couple of emails from different people wondering if I was abducted by the NSA, assassinated, or if I&#8217;m on the run with Julian Assange.</p>
<p>No, no, and.. no.  Though, that&#8217;d be pretty sweet.  Minus being assassinated.  That would suck.</p>
<p>Honestly, right now, I&#8217;m being pulled in like, 73 different directions.  which doesn&#8217;t leave me with much time for anything else, including a social or blogging life.</p>
<p>But!  I expect that I will be able to begin blogging again within the next few weeks and hopefully will return to my regular production level.</p>
<p>I don&#8217;t want you guys to fall behind, though.. so let me summarize the past few weeks in the security world:</p>
<p>Microsoft 0day<br />
Microsoft 0day<br />
Stuxnet<br />
Adobe 0day<br />
Java 0day<br />
Microsoft 0day<br />
Adobe 0day<br />
Adobe 0day<br />
&#8230;Adobe 0day<br />
Facebook privacy<br />
Julian Assange</p>
<p>There, consider yourself up to date.  <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=CxLbkNqG-ks:-_-vj3CE6kQ:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=CxLbkNqG-ks:-_-vj3CE6kQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=CxLbkNqG-ks:-_-vj3CE6kQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=CxLbkNqG-ks:-_-vj3CE6kQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=CxLbkNqG-ks:-_-vj3CE6kQ:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/CxLbkNqG-ks" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=626</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=626</feedburner:origLink></item>
		<item>
		<title>Geolocation Using BSSID</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/h6YQWexDBOA/</link>
		<comments>http://www.attackvector.org/?p=613#comments</comments>
		<pubDate>Wed, 22 Sep 2010 16:25:41 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[BSSID]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[demo]]></category>
		<category><![CDATA[Geolocation]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[Skyhook]]></category>
		<category><![CDATA[SSID]]></category>
		<category><![CDATA[war]]></category>
		<category><![CDATA[WiFi]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=613</guid>
		<description><![CDATA[This was discussed at DefCon 18 in a talk by Sammy Kamkar, but as far as I know, Sammy didn&#8217;t release his code, so I had to come up with something on my own. First, one big difference. His version of this uses the Google Location Services API. I&#8217;ve opted to use the Skyhook service [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/lz09-hxpQCthpMuDGe2RovpzGt8/0/da"><img src="http://feedads.g.doubleclick.net/~a/lz09-hxpQCthpMuDGe2RovpzGt8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/lz09-hxpQCthpMuDGe2RovpzGt8/1/da"><img src="http://feedads.g.doubleclick.net/~a/lz09-hxpQCthpMuDGe2RovpzGt8/1/di" border="0" ismap="true"></img></a></p><p>This was discussed at DefCon 18 in a talk by <a href="http://samy.pl/talks/2010-defcon.ppt" rel="nofollow" target="_blank">Sammy Kamkar</a>, but as far as I know, Sammy didn&#8217;t release his code, so I had to come up with something on my own.</p>
<p>First, one big difference.  <a href="http://samy.pl/mapxss/" rel="nofollow" target="_blank">His version</a> of this uses the Google Location Services API.  I&#8217;ve opted to use the Skyhook service instead because there&#8217;s far more documentation and sample code that exists using this API, whereas I was unable to find anything too terribly helpful when it came to using the GLS API for this particular purpose.  If anyone has any insight on this, please, please, let me know.  I&#8217;d like to incorporate that into this script for comparison data.<br />
<span id="more-613"></span><br />
Ok, so, how does this work, exactly?  Both companies (Google &#038; Skyhook) have employed a large number of people to drive around with laptops, GPS&#8217;s, and cameras attached to the roofs of their car in order to create a database.  Everyone is aware of street view by Google, but were you aware of the fact that they also record wireless information?  Well, I guess probably most people are aware of that now, considering the issues they had in Germany, but what you probably weren&#8217;t aware of is what this data is used for.  Google and Skyhook both provide this database for software based location systems.</p>
<p>So, whats in the database?  Skyhook is pretty open about the fact that they&#8217;re collecting wifi data in order to provide better location services.  They call it &#8220;XPS&#8221;, which combines information from wifi, GPS, and cell phone towers to pin point an exact location.</p>
<p><center><img src="http://www.skyhookwireless.com/images/content/charts/xps.gif"></center></p>
<p>Anyway, what does that mean for us?  It means that we can query this database with a BSSID from a wireless network and get the nearest address and coordinates returned.  Thanks SkyHook!  <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Here&#8217;s an example.  Not too long ago I was in the cities and did some driving with a buddy of mine.  I&#8217;ll demonstrate this using a BSSID that was in the log created on that drive:</p>
<blockquote><p>
$ ./getloc.pl 00:24:B2:1E:24:FE<br />
490 Robert St N<br />
Ramsey county<br />
St. Paul, Minnesota 55101<br />
Latitude: 44.95063<br />
Longitude: -93.0940583</p>
<p>http://maps.google.com/maps?f=q&#038;source=s_q&#038;hl=en&#038;geocode=&#038;q=44.95063+-93.0940583&#038;sll=37.0625,-95.677068&#038;sspn=57.815136,114.169922&#038;ie=UTF8&#038;t=h&#038;z=17</p>
</blockquote>
<p>So, using just the BSSID I&#8217;m able to get a house number (in this case, a building number), street address, and the coordinates.</p>
<p>Here&#8217;s my code.. feel free to modify it/add to it/whatever.. but if you add anything cool, please let me know.  <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<pre lang="perl">
#!/usr/bin/perl
# www.attackvector.org
#
use LWP::UserAgent;
use XML::LibXML;

$url = "https://api.skyhookwireless.com/wps2/location";
$ua = LWP::UserAgent->new;
$handler = XML::LibXML->new();

$bssid= $ARGV[0];
$bssid =~ s/://g;

if($bssid eq "") {
 print "Usage: $0 <bssid>n";
 print "Example: $0 AA:BB:CC:DD:EE:FFn";
 exit(0);
}

sub response {
    my ($response) = @_;
    $xml = $response->content;
    $xml =~ s/n//g;
    $page = $handler->parse_string($xml);
    if((@{$page->getElementsByTagName('longitude')}[0]) ne "") {
        $lat = $page->getElementsByTagName('latitude');
        $long = $page->getElementsByTagName('longitude');
        $streetnum = $page->getElementsByTagName('street-number');
        $streetname = $page->getElementsByTagName('address-line');
        $city = $page->getElementsByTagName('city');
        $zip = $page->getElementsByTagName('postal-code');
        $co = $page->getElementsByTagName('county');
        $state = $page->getElementsByTagName('state');
        print "$streetnum $streetnamen";
        print "$co countyn";
        print "$city, $state $zipn";
        print "Latitude: $latn";
        print "Longitude: $longn";
        print "http://maps.google.com/maps?f=q&#038;source=s_q&#038;hl=en&#038;geocode=&#038;q=" . $lat . "+" . $long . "&#038;sll=37.0625,95.677068&#038;sspn=57.815136,114.169922&#038;ie=UTF8&#038;t=h&#038;z=17n";
    } else {
        print "No results for $bssidn";
    }
}

$request = "<?xml version='1.0'?>
<LocationRQ xmlns='http://skyhookwireless.com/wps/2005' version='2.6' street-address-lookup='full'>
  <authentication version='2.0'>
    <simple>
      <username>beta</username>
      <realm>js.loki.com</realm>
    </simple>
  </authentication>
  <access-point>
    <mac>$bssid</mac>
    <signal-strength>-50</signal-strength>
  </access-point>
</LocationRQ>";
$response = $ua->post( $url, 'Content-Type' => 'text/xml', Content => $request );
response($response);
</pre>
<p>If you come up with or know of any creative ways to remotely obtain a BSSID, please comment below.  Sammy mentions using XSS, but this only works against the Verizon FiOS router.  I&#8217;m thinking a Java applet or script and UPnP.  I&#8217;ll let you know if I come up with anything interesting.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=h6YQWexDBOA:-0ckGjTSMyE:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=h6YQWexDBOA:-0ckGjTSMyE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=h6YQWexDBOA:-0ckGjTSMyE:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=h6YQWexDBOA:-0ckGjTSMyE:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=h6YQWexDBOA:-0ckGjTSMyE:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/h6YQWexDBOA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=613</wfw:commentRss>
		<slash:comments>18</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=613</feedburner:origLink></item>
		<item>
		<title>Really, Adobe?</title>
		<link>http://feedproxy.google.com/~r/attackvector/~3/XID8eDC-vaw/</link>
		<comments>http://www.attackvector.org/?p=605#comments</comments>
		<pubDate>Mon, 20 Sep 2010 15:59:44 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[cooltype]]></category>
		<category><![CDATA[corporate]]></category>
		<category><![CDATA[dll]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[own]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[SING]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[strncat]]></category>
		<category><![CDATA[SumatraPDF]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Xpdf]]></category>

		<guid isPermaLink="false">http://www.attackvector.org/?p=605</guid>
		<description><![CDATA[So, I&#8217;ve come across a lot more information regarding the no-longer-0day Adobe vulnerability (oh, wait, that&#8217;s right.. there have been like, 12 in the last 30 days.. I&#8217;m referring just to the SING table one). Anyway, a penetration testing company named Ramz Afzar has released an unofficial patch to fix the Adobe vulnerability, because apparently [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://feedads.g.doubleclick.net/~a/UNS6I0238Vro7iYxVVLJIWzYsDs/0/da"><img src="http://feedads.g.doubleclick.net/~a/UNS6I0238Vro7iYxVVLJIWzYsDs/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/UNS6I0238Vro7iYxVVLJIWzYsDs/1/da"><img src="http://feedads.g.doubleclick.net/~a/UNS6I0238Vro7iYxVVLJIWzYsDs/1/di" border="0" ismap="true"></img></a></p><p>So, I&#8217;ve come across a lot more information regarding the no-longer-0day Adobe vulnerability (oh, wait, that&#8217;s right.. there have been like, 12 in the last 30 days.. I&#8217;m referring just to the SING table one).</p>
<p>Anyway, a penetration testing company named <a href="https://www.rafzar.com/" rel="nofollow" target="_blank">Ramz Afzar</a> has released an <a href="https://www.rafzar.com/node/22" rel="nofollow" target="_blank">unofficial patch</a> to fix the Adobe vulnerability, because apparently Adobe has had a difficult time figuring one out on their own.</p>
<p>After reading their analysis of the vulnerable code, this jumped out at me the most:<br />
<span id="more-605"></span></p>
<blockquote><p>
After initial analysis we&#8217;ve discovered that exploit exists in insecure strcat call located in CoolType.dll:<br />
(all addresses and names are from Latest Acrobat 9.3.4&#8242;s CoolType.dll)</p>
<p>0803DDAB E8 483D1300 CALL JMP.&#038;MSVCR80.strcat
</p></blockquote>
<p>So, what does &#8216;strcat&#8217; do, exactly?  It basically appends a copy of the source string to the destination string.  Example:</p>
<pre lang="c">
main () {
  char adobe_rulez[20];
  strcpy (adobe_rulez,"our ");
  strcat (adobe_rulez,"software ");
  strcat (adobe_rulez,"pwnz! ");
}
</pre>
<p>Pretty self explanatory.  HOWEVER.  What DOESN&#8217;T &#8216;strcat&#8217; (or any of the other strc* functions, for that matter) do?  Bounds checking!  This is a classic overflow due to idiotic programming practices.  Really, Adobe?  The 15 years of hounding from security researchers haven&#8217;t been enough for you to ingrain it into your programmers that the use of strc* will get them fired, or lynched, or burned at the stake?  Beyond that, your entire testing/debugging department missed this as well?</p>
<p>Heres&#8217; what they SHOULD be doing:</p>
<pre lang="c">
#define MAXLEN(s) ( sizeof(s)/sizeof(s[0]) - 1 )

char buf[20];

void write( char data[], int n ) {
   strncat( buf, data, __min( n, MAXLEN(buf)-strlen(buf)) );
}

main() {
   strcat(buf, "now it looks like ");
   write("we know what we're doing");
}
</pre>
<p>Note:  The above code is just an example &#8211; I don&#8217;t even know if it will compile or not.  The idea is simple, though.  You define the size of a buffer and you want to ensure that the data going in to that buffer doesn&#8217;t exceed the size of the buffer.  What a concept.  Bounds checking is nothing new, so there are plenty of resources out there to educate those who are unfamiliar with it.  But, if you&#8217;re getting paid big bucks as a programmer for a company, you should know what the hell you&#8217;re doing.  Sorry, that&#8217;s just my personal opinion.  *cough*.</p>
<p>Anyway, So, first they&#8217;re writing code using functions that have been known to be vulnerable to exploitation for about 15 years and second, they&#8217;re now being shown up by little companies who are writing patches to fix the holes that they&#8217;re not.  And apparently Adobe thinks it&#8217;s okay for this vulnerability to be left unpatched until the 4th of October??  Are you kidding me??</p>
<p>I caught some grief when I wrote the <a href="http://www.attackvector.org/an-open-letter-to-microsoft/">Open Letter to Microsoft</a> post about how it&#8217;s difficult to write code in a team setting and that it&#8217;s difficult for large companies to meet deadlines and whatnot, but honestly, how do you argue with this?</p>
<p>And, whats more, is that a company that does not have access to the source code of the DLL was able to fix the issue, yet the company responsible for the software is not/wont/doesn&#8217;t care/can&#8217;t find a way to patch it on an expedited schedule?  Seriously, this October 4th date is really feels like a, &#8220;Eh, we don&#8217;t mind that all of our customers are vulnerable to exploitation and corporate espionage.. we&#8217;ll patch it when we get around to it&#8221; kind of date.</p>
<p>Whats more, is that Adobe has apparently released a statement telling people to not install 3rd party patches or from &#8220;untrusted&#8221; publishers.  So, instead, just remain vulnerable until we get off our ass and do something about it.</p>
<p>Tell you what, Adobe, if you can&#8217;t figure out how to simply add some bounds checking to a routine and release a patch, I think maybe you are the &#8220;untrusted publisher&#8221;.</p>
<p>So, here are your options:</p>
<p>1) Uninstall Adobe (highly recommended.  Once this vulnerability is patched, there will be 6 more released, I&#8217;m sure &#8211; <a href="http://www.exploit-db.com/search/?action=search&#038;filter_page=1&#038;filter_description=adobe&#038;filter_author=&#038;filter_platform=0&#038;filter_type=0&#038;filter_port=&#038;filter_osvdb=&#038;filter_cve=" rel="nofollow" target="_blank">here&#8217;s a list</a> of all the vulnerabilities and associated exploits against Adobe products.  Look at how many came out in the past 60 days (granted, a chunk of them are DLL hijacking, but even ignoring those ones&#8230;))  Some options to replace Adobe include:<br />
     A) Install the Google Docs plugin and read your PDF&#8217;s from within Google Docs (this is what I do)<br />
     B) Install one of the many other software packages out there:<br />
         * Evince<br />
         * Foxit (Foxit is often vulnerable to the same issues as Adobe, though, so be a bit weary of this one)<br />
         * Okular<br />
         * GSView<br />
         * Xpdf<br />
         * NitroPDF<br />
         * SumatraPDF<br />
         * Please note that I haven&#8217;t used all of these, so if you have any input on them, please comment below<br />
2) Install <a href="https://www.rafzar.com/customers/patches/CoolType.tgz" rel="nofollow">this patch</a><br />
3) Or wait around for Adobe to do something about it, meanwhile leaving you vulnerable to attack.  Though, I&#8217;m sure there&#8217;s nothing important on your computer that you wouldn&#8217;t mind being stolen, right?</p>
<p>Sorry about this rant, I&#8217;m just getting tired of these companies writing absolutely terrible code, laughing at us as they head off to the bank with our money and then not taking it seriously when they get flooded with vulnerability discoveries.  I&#8217;m looking forward to the day when some big company gets pwned due to a vulnerability in a piece of software that a publisher has had ample time to patch and then gets sued for damages.  That&#8217;s when the face of internet security will change, because I guarantee that if you assign a price tag to apathy, we will begin to see same-day patches.</p>
<p>Oh, wait, we do already see that.. with Linux.  *plug*.  <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/attackvector?i=XID8eDC-vaw:HML6ZHnZn28:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/attackvector?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/attackvector?i=XID8eDC-vaw:HML6ZHnZn28:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/attackvector?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/attackvector?i=XID8eDC-vaw:HML6ZHnZn28:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/attackvector?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/attackvector?i=XID8eDC-vaw:HML6ZHnZn28:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/attackvector?a=XID8eDC-vaw:HML6ZHnZn28:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/attackvector?d=TzevzKxY174" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/attackvector/~4/XID8eDC-vaw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.attackvector.org/?feed=rss2&amp;p=605</wfw:commentRss>
		<slash:comments>9</slash:comments>
		<feedburner:origLink>http://www.attackvector.org/?p=605</feedburner:origLink></item>
	</channel>
</rss>

