<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5240695539484007193</id><updated>2011-07-07T15:50:51.149-07:00</updated><title type='text'>Dave's CNG-275 Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-6905539557550972878</id><published>2009-11-16T20:34:00.000-08:00</published><updated>2009-11-16T20:41:50.326-08:00</updated><title type='text'>Most security products fail to perform</title><content type='html'>According to &lt;a href="http://www.net-security.org/secworld.php?id=8506"&gt;this article&lt;/a&gt;, nearly 80 percent of security products failed to perform as intended when first tested and generally required two or more cycles of testing before achieving certification, according to a new ICSA Labs report.  Having lived my prior professional life "in the belly of the software development beast" I can only say, 'Wow, 20% actually worked as advertised?"&lt;br /&gt;&lt;br /&gt;The other interesting finding included in the report was that 44 percent of security products had inherent security problems. Security testing issues range from vulnerabilities that compromise the confidentiality or integrity of the system to random behavior that affects product availability.&lt;br /&gt;&lt;br /&gt;Things to keep in mind (and ask pointed questions about) the next time a security systems vendor comes calling.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-6905539557550972878?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/6905539557550972878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/most-security-products-fail-to-perform.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/6905539557550972878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/6905539557550972878'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/most-security-products-fail-to-perform.html' title='Most security products fail to perform'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-2055117988419662363</id><published>2009-11-09T18:36:00.000-08:00</published><updated>2009-11-09T18:40:42.948-08:00</updated><title type='text'>Hacking to turn off the lights</title><content type='html'>CBS News is reporting that &lt;a href="http://www.cbsnews.com/stories/2009/11/06/60minutes/main5555565.shtml"&gt;several power outages in Brazil&lt;/a&gt; over the past several years were the result of hackers taking control of the power grid.  This was part of a "60 Minutes" segment on cyber warfare.  The scary part (the main thrust of the 60 Minutes segment) is that much of the U.S. power grid may also be vulnerable.&lt;br /&gt;&lt;br /&gt;Chers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-2055117988419662363?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/2055117988419662363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/hacking-to-turn-off-lights.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/2055117988419662363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/2055117988419662363'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/hacking-to-turn-off-lights.html' title='Hacking to turn off the lights'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-5970525115566353893</id><published>2009-11-02T18:42:00.000-08:00</published><updated>2009-11-02T18:58:31.502-08:00</updated><title type='text'>Peer-to-peer leaks</title><content type='html'>It seems a congressional staffer took home an Ethics Committee report that named names and deeds.  That's not so bad but they then put it on their home system and their peer-to-peer software shared it with the world.  The Washington dirt is interesting but the second page has just a little coverage of how the leak occurred toward the bottom of the page:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/10/29/AR2009102904597.html?hpid=topnews"&gt;The Washington Post article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;One of the selling points Vericept used when I worked there was that they monitored all network traffic; not just common ports.  We saw quite a bit of really interesting stuff that no one dreamed had been shared.  In this case, there's not much anyone could have done to stop this leak other than restricting access to the report and requiring that it not be taken home. &lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-5970525115566353893?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/5970525115566353893/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/peer-to-peer-leaks.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/5970525115566353893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/5970525115566353893'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/11/peer-to-peer-leaks.html' title='Peer-to-peer leaks'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-8569225719610744013</id><published>2009-10-19T06:58:00.000-07:00</published><updated>2009-10-19T07:10:36.827-07:00</updated><title type='text'>Another round of scareware</title><content type='html'>The BBC had &lt;a href="http://news.bbc.co.uk/2/hi/technology/8313678.stm"&gt;this article&lt;/a&gt; on the latest round of scareware.  Nothing like getting the end user to pay to install your trojan.  What's really sad is the people who get scammed this way not only pay for the trojan but then their identity gets stolen since they give a credit card number to the scammers.&lt;br /&gt;&lt;br /&gt;I had to laugh when I'd get these during an earlier round of scareware adverts a couple of years ago since I've been running Linux as my primary OS since 1998.  SIGH.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-8569225719610744013?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/8569225719610744013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/another-round-of-scareware.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8569225719610744013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8569225719610744013'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/another-round-of-scareware.html' title='Another round of scareware'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-1690451746318170532</id><published>2009-10-13T19:29:00.000-07:00</published><updated>2009-10-13T19:35:17.462-07:00</updated><title type='text'>In-depth Look at Wal-Mart Hack</title><content type='html'>Wired has a &lt;a href="http://www.wired.com/threatlevel/2009/10/walmart-hack/"&gt;long and detailed article&lt;/a&gt; looking into a hack of Wal-Mart in 2005 and 2006.  The hack wasn't reported because, apparently, no customer data was compromised.  Besides the discussion of how the attack was perpetrated the article also goes into some of the Payment Card Industry (PCI) requirements and how they should have played into making the hack impossible had Wal-Mart been in compliance.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-1690451746318170532?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/1690451746318170532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/in-depth-look-at-wal-mart-hack.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/1690451746318170532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/1690451746318170532'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/in-depth-look-at-wal-mart-hack.html' title='In-depth Look at Wal-Mart Hack'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-1450337879290918674</id><published>2009-10-12T21:52:00.000-07:00</published><updated>2009-10-12T22:02:09.183-07:00</updated><title type='text'>SSL Still Mostly Misunderstood</title><content type='html'>&lt;span class="smalltext"&gt;"The biggest issue is the general population doesn't know what SSL is, why they're using it, and it's ingrained in them that it always makes them secure, which is not always the case," says Tyler Reguly, senior security engineer for nCircle.  &lt;/span&gt;&lt;span class="smalltext"&gt;While 83 percent of users check they're using an SSL-secured session before entering their credit card information on a Website, only 41 percent do so when typing in their passwords.  To make matters even worse, &lt;/span&gt;&lt;span class="smalltext"&gt; "You see surveys saying that anywhere from 30 to 60 percent of users are using the same password everywhere, so they're probably using it for on-line banking, too."&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=220301548"&gt;this article&lt;/a&gt; at DarkReading, this problem isn't confined to just end-users.  &lt;/span&gt;More than half of the respondents don't know what Extended Validation SSL (EVSSL) is and how it differs from SSL, while 36 percent say they do.  Interestingly, most of them are aware that SSL traffic can be sniffed without their knowledge.   Even so, nearly one-third say the only purpose of SSL is to encrypt their traffic so it can't be sniffed.&lt;br /&gt;&lt;br /&gt;Lots more interesting statistics in the article regarding how many people in the survey commit a variety of security sins.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;span class="smalltext"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-1450337879290918674?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/1450337879290918674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/ssl-still-mostly-misunderstood.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/1450337879290918674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/1450337879290918674'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/ssl-still-mostly-misunderstood.html' title='SSL Still Mostly Misunderstood'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-7336957840422354805</id><published>2009-10-09T19:02:00.001-07:00</published><updated>2009-10-09T19:06:38.634-07:00</updated><title type='text'>A question of subnets and net masks</title><content type='html'>&lt;a href="http://article.gmane.org/gmane.linux.centos.general/83653"&gt;This &lt;/a&gt;really isn't a security story but I found it amusing and it includes some good stuff about netmasks, subnets and such.  As usual with stuff from the CentOS mailing list, click on the subject to get to the rest of the discussion thread.  The link I posted avoids some of the preliminaries.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-7336957840422354805?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/7336957840422354805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/question-of-subnets-and-net-masks.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7336957840422354805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7336957840422354805'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/question-of-subnets-and-net-masks.html' title='A question of subnets and net masks'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-8047449514637433586</id><published>2009-10-05T13:33:00.001-07:00</published><updated>2009-10-05T13:34:17.484-07:00</updated><title type='text'>They needed a flood wall instead of a firewall</title><content type='html'>The subject says it all.  Watching &lt;a href="http://idle.slashdot.org/article.pl?sid=09/09/16/1555252"&gt;the video&lt;/a&gt; is sort of like watching a train wreck.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-8047449514637433586?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/8047449514637433586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/they-needed-flood-wall-instead-of.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8047449514637433586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8047449514637433586'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/they-needed-flood-wall-instead-of.html' title='They needed a flood wall instead of a firewall'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-2240115482012089399</id><published>2009-10-04T21:23:00.000-07:00</published><updated>2009-10-04T21:26:38.076-07:00</updated><title type='text'>How to build/acquire a firewall</title><content type='html'>&lt;a href="http://article.gmane.org/gmane.linux.centos.general/83428"&gt;This discussion thread&lt;/a&gt; on the CentOS mailing list has some fairly good advice for deciding which of several options to go with for a home based business firewall.  Click on the e-mail's subject to get to the rest of the discussion thread.&lt;br /&gt;&lt;br /&gt;Most of the folks running CentOS (like me) are cheap (like me) and so the majority of the solutions are free.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-2240115482012089399?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/2240115482012089399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/how-to-buildacquire-firewall.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/2240115482012089399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/2240115482012089399'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/how-to-buildacquire-firewall.html' title='How to build/acquire a firewall'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-7949383743714906717</id><published>2009-10-04T21:05:00.000-07:00</published><updated>2009-10-04T21:16:57.902-07:00</updated><title type='text'>You aren't safe just because you run Linux</title><content type='html'>I picked up a link to &lt;a href="http://bsdly.blogspot.com/2009/10/third-time-uncharmed.html"&gt;this article&lt;/a&gt; that was posted on Slashdot.  It appears that the compromised systems were hacked by either exploiting an exposed user's ssh access (probably a brute force attack that found a weak password) or by finding an unpatched remote admin tool (e.g., roundcube was mentioned in one of the links that came up when I Googled the attack name).&lt;br /&gt;&lt;br /&gt;The sad thing is that there are a number of ways to keep brute force attackers at bay for ssh.  Fail2ban is probably the most comprehensive and can be used to protect other exposed logins such as web mail.  Another alternative is to use the built-in Linux firewall (iptables) to only allow so many connection attempts from a specific IP address before blocking future connections from the offending IP address.  I posted &lt;a href="http://davenjudy.org/davesBlog/node/24"&gt;an extensive article&lt;/a&gt; on my personal blog on how to set up this particular method (and a few other ssh "protection" tricks) if anyone is interested.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-7949383743714906717?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/7949383743714906717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/you-arent-safe-just-because-you-run.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7949383743714906717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7949383743714906717'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/10/you-arent-safe-just-because-you-run.html' title='You aren&apos;t safe just because you run Linux'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-452519766767521941</id><published>2009-09-25T07:33:00.000-07:00</published><updated>2009-09-25T07:44:27.641-07:00</updated><title type='text'>Enterprise bot-nets</title><content type='html'>Up to nine percent of machines in some enterprises are part of a bot net according to &lt;a href="http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=220200118"&gt;this article&lt;/a&gt; at Dark Reading.  It seems many of these enterprise bot nets are highly targeted and used multiple attack vectors to evade detection and establish the network.  Further, these are not the wide-spread "consumer oriented" bot nets that attack the typical home user system.&lt;br /&gt;&lt;br /&gt;The article also states that the bot nets demonstrate a level of insider knowledge of the targeted organization that implies someone on the inside is helping with the deployment and exploitation.  &lt;span class="smalltext"&gt;"They are very strongly associated with a lot of insider knowledge...and we see a lot of hands-on command and control with these small bot nets," &lt;/span&gt;&lt;span class="smalltext"&gt;says Gunter Ollmann, vice president of research for Damballa.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-452519766767521941?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/452519766767521941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/enterprise-bot-nets.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/452519766767521941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/452519766767521941'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/enterprise-bot-nets.html' title='Enterprise bot-nets'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-99090915827922473</id><published>2009-09-22T10:42:00.000-07:00</published><updated>2009-09-22T10:45:04.788-07:00</updated><title type='text'>$2,000 for a password?</title><content type='html'>&lt;a href="http://www.washingtonexaminer.com/local/crime/D_C_-tech-office-employee-pleads-in-kickback-scheme-8264916-59788832.html"&gt;This story&lt;/a&gt; is mainly a traditional bribery/kickback scam but one of the things provided was the password to the District of Columbia's purchase order system.  Why hack when you can just buy your way in?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-99090915827922473?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/99090915827922473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/2000-for-password.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/99090915827922473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/99090915827922473'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/2000-for-password.html' title='$2,000 for a password?'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-7150359215401514485</id><published>2009-09-21T12:41:00.000-07:00</published><updated>2009-09-21T12:55:17.986-07:00</updated><title type='text'>When Web 2.0 Becomes Security Risk 2.0</title><content type='html'>Kaspersky Labs has an &lt;a href="http://www.idgconnect.com/files/smfiledata/8/1/8/0/Kaspersky_Web_2_Becomes_Risk.pdf?CFID=14932351&amp;amp;CFTOKEN=17076234"&gt;interesting article&lt;/a&gt; on how the bad guys are exploiting the trusted nature of Facebook, MySpace and other social networking sites to launch attacks and spread malware.  Note that you may need to create an account at Kaspersky in order to access the article.&lt;br /&gt;&lt;br /&gt;Basically the idea is to exploit the poor security (e.g., passwords are sent in clear text for many social networking sites) to gain a position of trust that can then be exploited.  The exploits are frequently familiar such as "advanced fee fraud" (also known as a Nigerian 419 scam) but people who wouldn't think about responding to the traditional e-mail scam are being hooked by the same fraud since it appears to come from a "trusted" friend.  The level of trust users put into these sites makes tham a "social engineer's dream."&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-7150359215401514485?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/7150359215401514485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/whe-web-20-becomes-security-risk-20.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7150359215401514485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7150359215401514485'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/whe-web-20-becomes-security-risk-20.html' title='When Web 2.0 Becomes Security Risk 2.0'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-4407061681758380369</id><published>2009-09-17T19:19:00.000-07:00</published><updated>2009-09-17T20:07:11.292-07:00</updated><title type='text'>More progress with ESXi</title><content type='html'>OK.  I got the following virtual network configuration working on my ESXi installation here at home.  A little Googling resulted in a blog posting entitled "&lt;a href="http://kneew.com/node/32"&gt;Implement NAT under VMware ESX 3.5 using a Vyatta router&lt;/a&gt;" (how's that for finding exactly the "how to" I needed?).&lt;br /&gt;&lt;br /&gt;I ended up with a network that looks like:&lt;br /&gt;&lt;br /&gt;Virtual Network &lt;-&gt; Vyatta Router &lt;-&gt; VMware NIC &lt;-&gt; Network&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The Virtual Network has all of my VMs running on 172.16.0.0/24&lt;/li&gt;&lt;li&gt;The Vyatta Router routes traffic received on 172.16.0.1 to its other virtual NIC at 192.168.0.3 and applies NAT&lt;br /&gt;&lt;/li&gt;&lt;li&gt;VMware supplies the networking to take traffic from Vyatta's virtual NIC to the physical NIC at 192.168.0.4&lt;/li&gt;&lt;li&gt;My existing Linux router (CentOS 5.3 with IP tables configured to do NAT) does it's thing and routes the traffic, as appropriate, on my network or to the Internet.&lt;/li&gt;&lt;/ul&gt;As I was setting this up I realized that there isn't any need to run &lt;span style="font-weight: bold; font-style: italic; color: rgb(204, 0, 0);"&gt;ANY&lt;/span&gt; routing protocol on the Vyatta router (same as with my CentOS box that does my normal routing).  There is only "choice one of one" routes from the Vyatta router to both my network and the outside world.  You only need to run a routing protocol such as OSPF, BGP or RIP if there is a choice of routes.&lt;br /&gt;&lt;br /&gt;Vyatta reports my routing information as:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;vyatta:~# show ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: K - kernel route, C - connected, S - static, R - RIP, O - OSPF,&lt;/span&gt;&lt;span style="font-family:courier new;"&gt; I - ISIS, B - BGP, &gt; - selected route, * - FIB route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;S&gt;* 0.0.0.0/0 [1/0] via 192.168.0.1, eth0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C&gt;* 127.0.0.0/8 is directly connected, lo&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;C&gt;* 172.16.0.0/24 is directly connected, eth1&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;C&gt;* 192.168.0.0/24 is directly connected, eth0&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;The above configuration works just fine from each of the VMs.  I am able to browse the Internet, run the specific OS's update protocol, etc.  I dumped the "history" to a file.  This looks like (time stamps removed):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  204  configure&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  205  set interfaces ethernet eth0 address 192.168.0.4/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  206  set interfaces ethernet eth1 address 172.16.0.1/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  207  set service nat rule 1 source address 172.16.0.0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  208  set service nat rule 1 outbound-interface eth0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  209  set service nat rule 1 type masquerade&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  210  commit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  211  set system gateway-address 192.168.0.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  212  set system host-name vyatta&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  213  set system domain-name davenjudy.org&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  214  commit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There was a "save" after the last commit (that doesn't show up in the history) to make things "permanent."&lt;br /&gt;&lt;br /&gt;I'm guessing that we could run OSPF instead of setting up the static route to my real gateway (see the "set system gateway" command, above).  That seems like creating a lot of overhead for something that will "never" change.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave Miller&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-4407061681758380369?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/4407061681758380369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/more-progress-with-esxi.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4407061681758380369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4407061681758380369'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/more-progress-with-esxi.html' title='More progress with ESXi'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-8079881675586134978</id><published>2009-09-13T08:29:00.000-07:00</published><updated>2009-09-13T08:43:44.397-07:00</updated><title type='text'>Progress with ESXi at home</title><content type='html'>My new network card arrived on Friday so I swapped NICs in the old-ish dual Athlon box plus made a couple of other upgrades (e.g., 2GB more memory) and re-tried the ESXi install.  This time it worked so I now have three VMs on the box (Vyatta and Windows W2K3 server and W2K8 server).  I'm installing Ubuntu 9.04 (desktop) as I'm typing this.  Unfortunately, I don't have a recent ISO image for CentOS here at home and I'm still fighting a flaky Internet connection so downloading something large like a DVD ISO doesn't sound like a good idea nor does just letting it upgrade from an old release.&lt;br /&gt;&lt;br /&gt;I've been able to "get out" to the Internet from the VMs using the native ESXi virtual network.  This was a no brainer since it "just worked" with the VMs getting IP addresses, routing information, etc. through my DHCP server.  I guess the next thing to try is to configure Vyatta as the router/firewall for all the VMs.  Hmmmmmm........&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-8079881675586134978?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/8079881675586134978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/progress-with-esxi-at-home.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8079881675586134978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/8079881675586134978'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/progress-with-esxi-at-home.html' title='Progress with ESXi at home'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-7727107474817879072</id><published>2009-09-12T19:38:00.000-07:00</published><updated>2009-09-12T19:50:21.057-07:00</updated><title type='text'>A new first: a Linux botnet</title><content type='html'>The register &lt;a href="http://www.theregister.co.uk/2009/09/12/linux_zombies_push_malware/"&gt;is reporting&lt;/a&gt; that a botnet of Linux systems has been discovered.  Interestingly, the Linux boxes are left relatively unchanged but with a second web server activated and running on port 8080 that serves up malware.  The rest of the attack is to insert links into legitimate web sites that have also had passwords stolen.  The Linux boxes then serve up malware when an unsuspecting reader traverses the link on the otherwise legitimate site.&lt;br /&gt;&lt;br /&gt;It is not known how the Linux boxes were subverted but the best guess is that it was through sniffing the root password used during remote sessions.  The legitimate servers that have also been attacked to include links to the Linux bots apparently were attacked by sniffing ftp passwords.  That is, this attack is possible simply due to the use of insecure communication and update protocols; there is no inherent vulnerability of the attacked systems that is being exploited.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave Miller&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-7727107474817879072?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/7727107474817879072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/new-first-linux-botnet.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7727107474817879072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/7727107474817879072'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/new-first-linux-botnet.html' title='A new first: a Linux botnet'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-3637264661862035504</id><published>2009-09-10T19:56:00.000-07:00</published><updated>2009-09-10T20:24:22.475-07:00</updated><title type='text'>How much is your identity worth?</title><content type='html'>If you really want to know, click &lt;a href="http://everyclickmatters.com/preloader.html?redirect=/victim/assessment-tool.html"&gt;here&lt;/a&gt; and the Norton On-line Risk Calculator will let you determine how much your identity is worth on the black market.&lt;br /&gt;&lt;br /&gt;The calculator will ask you a few questions after which you get three results: how much your online assets are worth, how much your online identity would sell for on the black market, and your risk of becoming a victim of identity theft.&lt;br /&gt;&lt;br /&gt;This is both intriguing and scary.  The survey asks some pertinent questions but doesn't even consider the platform you're on, the browser you use or a number of factors that can make life more difficult for the bad guys.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-3637264661862035504?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/3637264661862035504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/how-much-is-your-identity-worth.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3637264661862035504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3637264661862035504'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/how-much-is-your-identity-worth.html' title='How much is your identity worth?'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-188259749368366123</id><published>2009-09-10T19:15:00.000-07:00</published><updated>2009-09-10T19:37:31.451-07:00</updated><title type='text'>Taking more than a few years</title><content type='html'>After about sixty years the Britsh government has finally gotten around to issuing an &lt;a href="http://www.number10.gov.uk/Page20571"&gt;official apology&lt;/a&gt; to the late Alan Turing.  Prime Minister termed his treatment "appalling."  What is particularly appalling is that Turning was being pilloried at the same time that real spies like Philby, Burgess, Blunt and MacLean were actively providing detailed information to the Soviet Union.  All were assumed to be above suspicion since they all came from "good families" and had attended the right schools.&lt;br /&gt;&lt;br /&gt;By way of background, Guy Burgess and Donald MacLean were British diplomats who disappeared in 1951 and surfaced in Moscow in 1956. There was speculation that Harold "Kim" Philby, head of the Soviet section of the British Secret Intelligence Service, was the "third man" who alerted them before they could be arrested for espionage.  Philby also defected but only after overwhelming evidence was provided to show he was a spy (the Brits hadn't learned a thing from Burgess and MacLean).  Anthony Blunt did not flee and continued to hold a position of trust until finally exposed in 1979.&lt;br /&gt;&lt;br /&gt;Besides the tie-in to cryptography with Alan Turing finally getting an apology, another lesson to be learned from this post is to be alert that anyone can be either an active or inadvertent security vulnerability.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-188259749368366123?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/188259749368366123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/taking-more-than-few-years.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/188259749368366123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/188259749368366123'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/taking-more-than-few-years.html' title='Taking more than a few years'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-427363081382464589</id><published>2009-09-08T16:22:00.000-07:00</published><updated>2009-09-10T19:12:30.060-07:00</updated><title type='text'>It only took several years...</title><content type='html'>Both &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-048.mspx"&gt;Microsoft&lt;/a&gt; and &lt;a href="http://www.cisco.com/warp/public/707/cisco-sa-20090908-tcp24.shtml"&gt;Cisco&lt;/a&gt; announced patches today (Tuesday, 8 September 2009) for a TCP flaw that has been around for several years.  The flaw allows an attacker to perform a denial of service attack against the vulnerable systems (Microsoft Windows 2000, Server 2003 and Server 2008, Vista and Windows 7; all versions of Cisco's IOS).&lt;br /&gt;&lt;br /&gt;Microsoft provided patches today (good old patch Tuesday) for the affected versions of Windows except Server 2000 which is no longer supported.&lt;br /&gt;&lt;br /&gt;A really good article explaining the flaw can be found at &lt;a href="http://threatpost.com/blogs/microsoft-cisco-issue-patches-tcp-dos-flaw-108"&gt;ThreatPost&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Folks may want to take a look at the ThreatPost &lt;a href="http://threatpost.com/"&gt;main page&lt;/a&gt;. Threat Post includes a link to &lt;a href="http://usa.kaspersky.com/"&gt;Kaspersky Lab Security News Service&lt;/a&gt; which you will also find interesting.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-427363081382464589?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/427363081382464589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/it-only-took-several-years.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/427363081382464589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/427363081382464589'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/09/it-only-took-several-years.html' title='It only took several years...'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-454867792531908782</id><published>2009-08-26T11:17:00.000-07:00</published><updated>2009-08-26T11:19:52.783-07:00</updated><title type='text'>Even legitimate appearing ISPs can be bad</title><content type='html'>This article showed up on slashdot today:&lt;br /&gt;&lt;br /&gt;http://tech.slashdot.org/story/09/08/26/1614206/Legitimate-ISP-a-Cover-up-For-a-Cybercrime-Network?art_pos=3&lt;br /&gt;&lt;br /&gt;It looks like you can't even trust what appears to be a legitimate ISP.  The really scary part is the DNS hijacking since lots of people trust their ISP.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-454867792531908782?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/454867792531908782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/even-legitimate-appearing-isps-can-be.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/454867792531908782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/454867792531908782'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/even-legitimate-appearing-isps-can-be.html' title='Even legitimate appearing ISPs can be bad'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-260313624042513531</id><published>2009-08-24T13:28:00.000-07:00</published><updated>2009-08-24T13:30:46.947-07:00</updated><title type='text'>Quick "how to" on my gmane posts....</title><content type='html'>I just realized that it isn't at all obvious how to get to the rest of the discussion thread from my gmane posts from the CentOS mailing list.  If you click on the post's subject, it's a link to a threaded view of the full discussion.  Once you get to the threaded view you can also navigate to other discussions.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-260313624042513531?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/260313624042513531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/quick-how-to-on-my-gmane-posts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/260313624042513531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/260313624042513531'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/quick-how-to-on-my-gmane-posts.html' title='Quick &quot;how to&quot; on my gmane posts....'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-4996813868351651881</id><published>2009-08-23T15:43:00.000-07:00</published><updated>2009-08-23T15:49:53.805-07:00</updated><title type='text'>Beware of phpMyAdmin</title><content type='html'>If you ever end up working on a web site that is being hosted by a hosting service you will probably get stuck with phpMyAdmin as the means of remotely administering the site.  The following thread again from the CentOS mailing list gives a good discussion as to why this isn't a good set up:&lt;br /&gt;&lt;br /&gt;http://article.gmane.org/gmane.linux.centos.general/81345&lt;br /&gt;&lt;br /&gt;There is also a discussion of some of the alternatives but the bottom line is that there aren't any really good alternatives.  The best is to get secure shell access (ssh) and then do your admin work from the command line but there are quite a few people who are intimidated by the command line.  SIGH.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-4996813868351651881?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/4996813868351651881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/beware-of-phpmyadmin.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4996813868351651881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4996813868351651881'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/beware-of-phpmyadmin.html' title='Beware of phpMyAdmin'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-3897693581489905230</id><published>2009-08-21T13:04:00.001-07:00</published><updated>2009-08-21T13:15:46.125-07:00</updated><title type='text'>Other resources</title><content type='html'>I subscribe to the CentOS (CentOS is a free clone of Red Hat Enterprise Linux) mailing list as a way to keep up with what's going on with CentOS and because I learn something just from reading about the problems that others have run into and gone to "the list" to get help or solutions.  The following thread showed up in today's mail concerning how to prevent brute force attacks against a server that allows secure shell (ssh) logins:&lt;br /&gt;&lt;br /&gt;http://article.gmane.org/gmane.linux.centos.general/81276&lt;br /&gt;&lt;br /&gt;There are a few other threads that are current (e.g., "How can I tell if I've been hacked") as well as other discussions.&lt;br /&gt;&lt;br /&gt;Besides just this particular mailing list, Gmane provides archives for pretty much any significant mailing list on the Internet.  I'm sure there are other lists that would be usefull if you have the time to keep up with the list traffic.  As with the thread I specified above, an appropriate mailing list is a great way to get help with a particular problem.  The only down side is that lists that will get you a quick response generally have enough traffic to swamp you while low volume lists mean you might not get a response ever or at least in the time frame that you need.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-3897693581489905230?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/3897693581489905230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/other-resources.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3897693581489905230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3897693581489905230'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/other-resources.html' title='Other resources'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-3406989723961453023</id><published>2009-08-20T21:36:00.000-07:00</published><updated>2009-08-20T22:04:11.306-07:00</updated><title type='text'>CNBC on DoS Attacks and Computer Security</title><content type='html'>Here is the CNBC video segment I mentioned in class.  Not unexpectedly, they emphasize the economic impact of computer security and DoS attacks against social networking sites in particular. While some of the numbers included were of interest, I found the very fact that "main stream" media such as CNBC would devote a prime time (while the markets are open) segment to computer security to be interesting.&lt;br /&gt;&lt;br /&gt;&lt;embed pluginspage="http://www.macromedia.com/go/getflashplayer" allowfullscreen="true" allowscriptaccess="always" bgcolor="#000000" quality="best" salign="lt" type="application/x-shockwave-flash" name="cnbcplayer" wmode="transparent" src="http://plus.cnbc.com/rssvideosearch/action/player/id/1219614333/code/cnbcpermalink/play/1/module/videomodule" height="370" width="580"&gt;&lt;/embed&gt;&lt;br /&gt;&lt;br /&gt;They also note that thwarting such attacks isn't just a question of buying enough hardware, software or a big enough pipe.  They point out that having the right people was instrumental in allowing several major government and financial sites to weather a similar attack earlier this year.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-3406989723961453023?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/3406989723961453023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/cnbc-on-dos-attacks-and-computer.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3406989723961453023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/3406989723961453023'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/cnbc-on-dos-attacks-and-computer.html' title='CNBC on DoS Attacks and Computer Security'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5240695539484007193.post-4203579854343257110</id><published>2009-08-19T18:13:00.000-07:00</published><updated>2009-08-19T18:15:49.280-07:00</updated><title type='text'>First Post!</title><content type='html'>Th is a test.  This is only a test. Had this been a real post I would have actually had something to say.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5240695539484007193-4203579854343257110?l=davescng275blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davescng275blog.blogspot.com/feeds/4203579854343257110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/first-post.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4203579854343257110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5240695539484007193/posts/default/4203579854343257110'/><link rel='alternate' type='text/html' href='http://davescng275blog.blogspot.com/2009/08/first-post.html' title='First Post!'/><author><name>DaveAtFraud</name><uri>http://www.blogger.com/profile/06646324281360661146</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_GSwiLdhhxVY/So2wWJ7J68I/AAAAAAAAAAM/Qg-2f_S4-zU/S220/me.jpg'/></author><thr:total>0</thr:total></entry></feed>
