<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: aims]]></title>
    <link>http://www.securityratty.com/tag/aims</link>
    <description></description>
    <pubDate>Mon, 30 Jun 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Anti-Terror Law Mission Creep in the U.K.]]></title>
      <link>http://www.securityratty.com/article/d210842070419d07ee8cfee2be4e8e51</link>
      <guid>http://www.securityratty.com/article/d210842070419d07ee8cfee2be4e8e51</guid>
      <description><![CDATA[First terrorists, then trash cans : More than half of town halls admit using anti-terror laws to spy on families suspected of putting their rubbish out on the wrong day
Their tactics include putting...]]></description>
      <content:encoded><![CDATA[<p>First terrorists, then <a href="http://www.dailymail.co.uk/news/article-1082225/March-dustbin-Stasi-Half-councils-use-anti-terror-laws-watch-people-putting-rubbish-wrong-day.html?ITO=1490">trash cans</a>:</p>

<blockquote>More than half of town halls admit using anti-terror laws to spy on families suspected of putting their rubbish out on the wrong day. 

<p>Their tactics include putting secret cameras in tin cans, on lamp posts and even in the homes of 'friendly' residents. </p>

<p>The local authorities admitted that one of their main aims was to catch householders who put their bins out early.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=kcA9N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=kcA9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=uUuPN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=uUuPN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 05:18:44 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/town halls admit">town halls admit</category>
      <category domain="http://www.securityratty.com/tag/trash cans">trash cans</category>
      <category domain="http://www.securityratty.com/tag/main aims">main aims</category>
      <category domain="http://www.securityratty.com/tag/tactics include">tactics include</category>
      <category domain="http://www.securityratty.com/tag/wrong day">wrong day</category>
      <category domain="http://www.securityratty.com/tag/secret cameras">secret cameras</category>
      <category domain="http://www.securityratty.com/tag/tin cans">tin cans</category>
      <category domain="http://www.securityratty.com/tag/local authorities">local authorities</category>
      <category domain="http://www.securityratty.com/tag/lamp posts">lamp posts</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/anti-terror_law.html">Anti-Terror Law Mission Creep in the U.K.</source>
    </item>
    <item>
      <title><![CDATA[DIY Phishing Pages With Command and Control Interfaces]]></title>
      <link>http://www.securityratty.com/article/78a81ce667063a0a1268788bb3f66128</link>
      <guid>http://www.securityratty.com/article/78a81ce667063a0a1268788bb3f66128</guid>
      <description><![CDATA[The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s1600-h/rapidshare_phishing_admin_panel.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s200/rapidshare_phishing_admin_panel.jpg" /></a>The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more user-friendly compared to the old-fashioned -- yet effective -- <a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">rock phish directory listing</a>, a recently released command and control interface for Rapidshare phishing campaigns aims to empower its users with easy dynamic link generation for their campaigns.<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s1600-h/DIY_phishing_scripts.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s200/DIY_phishing_scripts.JPG" /></a>What they've managed to achieve is another trust factor since Rapidshare generates a second dynamic link upon clicking on the original one. The script not only generates a dynamically looking link, but also, actually logs in the victim into their account in order to avoid suspicion whereas it still logs all the accounting data.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s1600-h/rapidshare_phishing_insecure_directory_permissions.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s200/rapidshare_phishing_insecure_directory_permissions.JPG" /></a></div>Scammers also tend to be ironic every then and now. For instance, in this particular case, one of the users finds it ironic that the Rapidshare phishing page is hosted at Rapidshare itself. Is the script actually working? It appears so at least going through a misconfigured accounting data dump left by one of the phishers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">Phishing Pages for Every Bank are a Commodity</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/diy-phishing-kits.html">DIY Phishing Kits</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/diy-phishing-kit-goes-20.html">DIY Phishing Kit Goes 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY Phishing Kits Introducing New Features</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5kY3N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5kY3N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=r8EaN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=r8EaN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qtrtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qtrtn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qM6qn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qM6qn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T3U6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T3U6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YwrRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YwrRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nQNrn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nQNrn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/444324371" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 03:31:43 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/diy">diy</category>
      <category domain="http://www.securityratty.com/tag/pages">pages</category>
      <category domain="http://www.securityratty.com/tag/rapidshare">rapidshare</category>
      <category domain="http://www.securityratty.com/tag/data dump">data dump</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://www.securityratty.com/tag/dynamic link">dynamic link</category>
      <category domain="http://www.securityratty.com/tag/pages start">pages start</category>
      <category domain="http://www.securityratty.com/tag/link">link</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/444324371/diy-phishing-pages-with-command-and.html">DIY Phishing Pages With Command and Control Interfaces</source>
    </item>
    <item>
      <title><![CDATA[Hackers leverage Obama win for massive malware campaign]]></title>
      <link>http://www.securityratty.com/article/272ff342a60e171e33fe022b650c7da3</link>
      <guid>http://www.securityratty.com/article/272ff342a60e171e33fe022b650c7da3</guid>
      <description><![CDATA[Hackers are using the results of the U.S. presidential election to launch a major malware campaign that aims to trick users into installing a Flash update that actually plants a Trojan horse on...]]></description>
      <content:encoded><![CDATA[Hackers are using the results of the U.S. presidential election to launch a major malware campaign that aims to trick users into installing a Flash update that actually plants a Trojan horse on unprotected PCs.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e6f7bf1b390189ce80654a89b4264d2d:dpSUZMD78vOehEQeOBIWRCKJdA%2F3rN9BqoK3QykvqYAq05HJg9%2BBLI4errQb6B5N9LoI1m5Y5OjH'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2c55f75ef5ad898668b7f2197674ce9f:guTHD9LnrY%2BrQ5h7c1piIUtjxaL4Xwd8e%2Fj%2BwAiG6prQHrOPZZIny9LjIBDzjwSkrNNCuv5tEKATBw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c2ada204ded50890c7d72cd3dd977542:nnhHDQ%2Fi8eAf%2BjjIM1IGJUKc0fkNzaudioHOlNf4R4zvCgUiOECDWhJiVkjUg5d8ukkVHXWNUIHc5Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e2d0ba9d88458cceb79e5d681478a889:Vq2WjQ0zadrCTMgKrtCLpraqy58UM0TCT6noqBNuiJTgrVpuKBzchLKWbz9jTjmhSOO%2BNHZdSFL4Aw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=4e2439266c1074720a2836c96f587bbf" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4e2439266c1074720a2836c96f587bbf" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/major malware campaign">major malware campaign</category>
      <category domain="http://www.securityratty.com/tag/trojan horse">trojan horse</category>
      <category domain="http://www.securityratty.com/tag/presidential election">presidential election</category>
      <category domain="http://www.securityratty.com/tag/trick users">trick users</category>
      <category domain="http://www.securityratty.com/tag/hackers">hackers</category>
      <category domain="http://www.securityratty.com/tag/plants">plants</category>
      <category domain="http://www.securityratty.com/tag/launch">launch</category>
      <category domain="http://www.securityratty.com/tag/aims">aims</category>
      <category domain="http://www.securityratty.com/tag/pcs">pcs</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=4e2439266c1074720a2836c96f587bbf">Hackers leverage Obama win for massive malware campaign</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-09-22 [del.icio.us]]]></title>
      <link>http://www.securityratty.com/article/d6b0775b2abd9785ee0bf49ac86523ab</link>
      <guid>http://www.securityratty.com/article/d6b0775b2abd9785ee0bf49ac86523ab</guid>
      <description><![CDATA[McAfee acquires Secure Computing for $465 million VentureBeat
Anton Chuvakin Blog - &quot;Security Warrior&quot;: Is PCI DSS &quot;Too Prescriptive
McAfee aims to broaden portfolio with Secure Computing buy | News -...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://venturebeat.com/2008/09/22/mcafee-acquires-secure-computing-for-465-million/">McAfee acquires Secure Computing for $465 million &raquo; VentureBeat</a></li>
<li><a href="http://chuvakin.blogspot.com/2008/09/is-pci-dss-prescriptive.html">Anton Chuvakin Blog - &quot;Security Warrior&quot;: Is PCI DSS &quot;Too Prescriptive&quot;?</a></li>
<li><a href="http://news.cnet.com/8301-1009_3-10048011-83.html">McAfee aims to broaden portfolio with Secure Computing buy | News - Security - CNET News</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/400460799" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/secure">secure</category>
      <category domain="http://www.securityratty.com/tag/mcafee acquires secure">mcafee acquires secure</category>
      <category domain="http://www.securityratty.com/tag/security warrior">security warrior</category>
      <category domain="http://www.securityratty.com/tag/cnet news">cnet news</category>
      <category domain="http://www.securityratty.com/tag/anton chuvakin blog">anton chuvakin blog</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/news">news</category>
      <category domain="http://www.securityratty.com/tag/million venturebeat">million venturebeat</category>
      <category domain="http://www.securityratty.com/tag/mcafee aims">mcafee aims</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/400460799/anton18">Links for 2008-09-22 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Exposing Indias CAPTCHA Solving Economy]]></title>
      <link>http://www.securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</link>
      <guid>http://www.securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</guid>
      <description><![CDATA[Are you a Human?&quot; - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/6poURrjAkGI/s1600-h/india_captcha_breakers9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/HZ5BF3hc6nY/s200-R/india_captcha_breakers9.JPG" /></a>"Are you a Human?" - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based authentication in the face of human CAPTCHA solvers, seems to have evolved into a booming economy in India during the past 12 months, with thousands of people involved.<br />
<br />
The following article - "<a href="http://blogs.zdnet.com/security/?p=1835">Inside India’s CAPTCHA solving economy</a>" aims to expose legitimate data entry workers, whose business models and techniques are in fact used by Russian cybercriminals not only for personal phishing, spamming and malware spreading purposes, but also, to resell the bogus accounts and earn a premium in the process :<br />
<br />
"<i>No CAPTCHA can survive a human that’s receiving financial incentives for solving it, and with an army of low-wagedIndia CAPTCHA breakers human CAPTCHA solvers officially in the business of “data processing” while earning a mere $2 for solving a thousand CAPTCHA’s, I’m already starting to see evidence of consolidation between India’s major CAPTCHA solving companies. The consolidation logically leading to increased bargaining power, is resulting in an international franchising model recruiting data processing workers empowered with do-it-yourself CAPTCHA syndication web based kits, API keys, and thousands of proxies to make their work easier, and the process more efficient.</i>"<br />
<br />
Cybercrime is just as outsourceable as CAPTCHA breaking is these days.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a><br />
<a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing </a><br />
<a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers</a><br />
<a href="http://blogs.zdnet.com/security/?p=1232">Microsoft’s CAPTCHA successfully broken</a><br />
<a href="http://ddanchev.blogspot.com/2007/03/vladuzs-ebay-captcha-populator.html">Vladuz's Ebay CAPTCHA Populator</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/spammers-and-phishers-breaking-captchas.html">Spammers and Phishers Breaking CAPTCHAs</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/diy-captcha-breaking-service.html">DIY CAPTCHA Breaking Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/which-captcha-do-you-want-to-decode.html">Which CAPTCHA Do You Want to Decode Today?</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HJ3QtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HJ3QtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m6hgDK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m6hgDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0TXeOk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0TXeOk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4jwe6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4jwe6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9clPFK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9clPFK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JCXayK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JCXayK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5ic3Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5ic3Pk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/378395296" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 13:03:37 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/captcha">captcha</category>
      <category domain="http://www.securityratty.com/tag/microsofts captcha">microsofts captcha</category>
      <category domain="http://www.securityratty.com/tag/indias major captcha">indias major captcha</category>
      <category domain="http://www.securityratty.com/tag/hotmails captcha">hotmails captcha</category>
      <category domain="http://www.securityratty.com/tag/unbreakable captcha">unbreakable captcha</category>
      <category domain="http://www.securityratty.com/tag/human captcha solvers">human captcha solvers</category>
      <category domain="http://www.securityratty.com/tag/human">human</category>
      <category domain="http://www.securityratty.com/tag/inside indias captcha">inside indias captcha</category>
      <category domain="http://www.securityratty.com/tag/captcha based authentication">captcha based authentication</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/378395296/exposing-indias-captcha-solving-economy.html">Exposing Indias CAPTCHA Solving Economy</source>
    </item>
    <item>
      <title><![CDATA[A Security Assessment of the Internet Protocol]]></title>
      <link>http://www.securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</link>
      <guid>http://www.securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</guid>
      <description><![CDATA[Interesting : Preface
The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cpni.gov.uk/Docs/InternetProtocol.pdf">Interesting</a>:</p>

<blockquote><strong>Preface</strong>

<p>The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and widespread early adoption is that much of today's global economy remains dependent upon them.</p>

<p>While many textbooks and articles have created the myth that the Internet Protocols (IP) were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the ARPANET. As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications.</p>

<p>Though Internet technology has evolved, the building blocks are basically the same core protocols adopted by the ARPANET more than two decades ago. During the last twenty years many vulnerabilities have been identified in the TCP/IP stacks of a number of systems. Some were flaws in protocol implementations which affect only a reduced number of systems. Others were flaws in the protocols themselves affecting virtually every existing implementation. Even in the last couple of years researchers were still working on security problems in the core  protocols.</p>

<p>The discovery of vulnerabilities in the TCP/IP protocols led to reports being published by a number of CSIRTs (Computer Security Incident Response Teams) and vendors, which helped to raise awareness about the threats as well as the best mitigations known at the time the reports were published.</p>

<p>Much of the effort of the security community on the Internet protocols did not result in official documents (RFCs) being issued by the IETF (Internet Engineering Task Force) leading to a situation in which "known" security problems have not always been addressed by all vendors. In many cases vendors have implemented quick "fixes" to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability.</p>

<p>As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past.</p>

<p>Producing a secure TCP/IP implementation nowadays is a very difficult task partly because of no single document that can serve as a security roadmap for the protocols.</p>

<p>There is clearly a need for a companion document to the IETF specifications that discusses the security aspects and implications of the protocols, identifies the possible threats, proposes possible counter-measures, and analyses their respective effectiveness.</p>

<p>This document is the result of an assessment of the IETF specifications of the Internet Protocol from a security point of view. Possible threats were identified and, where possible, counter-measures were proposed.  Additionally, many implementation flaws that have led to security vulnerabilities have been referenced in the hope that future implementations will not incur the same problems. This document does not limit itself to performing a security assessment of the relevant IETF specification but also offers an assessment of common implementation strategies.</p>

<p>Whilst not aiming to be the final word on the security of the IP, this document aims to raise awareness about the many security threats based on the IP protocol that have been faced in the past, those that we are currently facing, and those we may still have to deal with in the future. It provides advice for the secure implementation of the IP, and also insights about the security aspects of the IP that may be of help to the Internet operations community.</p>

<p>Feedback from the community is more than encouraged to help this document be as accurate as possible and to keep it updated as new threats are discovered.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=klyypK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=klyypK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xR8bMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xR8bMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:48:56 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/internet">internet</category>
      <category domain="http://www.securityratty.com/tag/assessment">assessment</category>
      <category domain="http://www.securityratty.com/tag/security assessment">security assessment</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://www.securityratty.com/tag/flaws">flaws</category>
      <category domain="http://www.securityratty.com/tag/internet technology">internet technology</category>
      <category domain="http://www.securityratty.com/tag/internet operations community">internet operations community</category>
      <category domain="http://www.securityratty.com/tag/protocols">protocols</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/a_security_asse.html">A Security Assessment of the Internet Protocol</source>
    </item>
    <item>
      <title><![CDATA[Upping The IPS Ante]]></title>
      <link>http://www.securityratty.com/article/81aa745b480141b489146432f5c59ee0</link>
      <guid>http://www.securityratty.com/article/81aa745b480141b489146432f5c59ee0</guid>
      <description><![CDATA[My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola. Looking at the deal through the security lens, I completely agree with Chris that this...]]></description>
      <content:encoded><![CDATA[<p>My colleague at Forrester, Chris Silva, recently commented upon the recent Air Defense acquisition by Motorola.&nbsp; Looking at the deal through the security lens, I completely agree with Chris that this will help ease integration of wireless security into wireless infrastructure.&nbsp; It's good to see one of the major wireless brands step up and take wireless security seriously.&nbsp; Perhaps that other major wireless vendor will get the hint...</p>

<blockquote><p><span style="color: #636363;"><a href="http://blogs.forrester.com/it_infrastructure/2008/07/upping-the-ips.html">Upping The IPS Ante</a></span></p></blockquote>

<blockquote><p><span style="color: #8a8a8a;">	
Motorola <a href="http://www.airdefense.net/newsandpress/07_28_08.php">announced</a> this week its intentions to acquires Wireless IDS/IPS vendor <a href="http://www.airdefense.net/">AirDefense</a>.
The acquisition may provide a bit of deja vu to readers who recall the
acquisition of Network Chemistry's wireless IDS/IPS assets by Aruba
Networks <a href="http://www.arubanetworks.com/company/news/release.php?id=25">in 2007</a>. 

</span></p>

<p><span style="color: #8a8a8a;">Meru Networks, eschewing acquisition for product introduction made <a href="http://www.merunetworks.com/news/press_releases/index.php?articleID=072808">its own announcement</a>
on Monday, announcing the company's RF Barrier, an active RF management
solution that aims to solve the problem of what the vendor is calling
&quot;leaky RF.&quot; The Meru solution actively blocks 802.11 RF from escaping
the physical confines of a WLAN deployment to thwart external &quot;parking
lot&quot; attacks by closing Wi-Fi based attack avenues. </span></p>

<p><span style="color: #8a8a8a;">In fact, 2007 - 2008 has been a time focused on shoring up the security
of the WLAN as the networks become more critical to <a href="http://www.forrester.com/Research/Document/0,7211,42451,00.html">over 50%</a>
of
enterprises Forrester sees investing in the networks today. As the
networks are more pervasive, moving toward covering the entire physical
environment, and more employees are relying on Wi-Fi to access
corporate data and applications, it's high-time to secure the WLAN.</span></p>

<p><span style="color: #8a8a8a;">In the case of Motorola, the Wi-Fi network is especially critical. As the vendor embarks on selling its message of the <a href="http://www.informationweek.com/news/mobility/converence/showArticle.jhtml?articleID=206904190">all-wireless enterprise</a>,
where WLANs will interconnect not only users to the network, but
networke edge devices -- such as WLAN access points -- to the network
along with storage, printers and other peripheral devices, the WLAN is
citical and, therefore, a major focus for security. </span></p>

<p><span style="color: #8a8a8a;">In markets such as retail, standards like the Payment Card
Industry's Data Security Standard dictate wireless security, but
compliance and regulation aside, it is becoming easier to secure the
WLAN, regardless of the industry you are in. Vendors are rapily working
to close security gaps with product enhancements and new product
introductions. Look for a broader suite of solutions to address
security coming from your primary network vendor; while this won't
negate the need to&nbsp; integrate these add-on network elements, the single
source should ease integration to some degree. </span></p>

<p><span style="color: #8a8a8a;">How secure do you feel your organization's WLAN is today? What are
your concerns either about securing the network or its current lack of
security?</span></p></blockquote>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 11:14:48 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/address security">address security</category>
      <category domain="http://www.securityratty.com/tag/security lens">security lens</category>
      <category domain="http://www.securityratty.com/tag/data security standard">data security standard</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://www.securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://www.securityratty.com/tag/network">network</category>
      <category domain="http://www.securityratty.com/tag/wireless security">wireless security</category>
      <source url="http://blogs.forrester.com/srm/2008/07/upping-the-ips.html">Upping The IPS Ante</source>
    </item>
    <item>
      <title><![CDATA[Sophos plans to acquire German data security company]]></title>
      <link>http://www.securityratty.com/article/4c68143813033e1f42986b7a6b3338cc</link>
      <guid>http://www.securityratty.com/article/4c68143813033e1f42986b7a6b3338cc</guid>
      <description><![CDATA[Security vendor Sophos plans to acquire Utimaco, a German company specializing in software that aims to prevent sensitive data from escaping corporate networks, an increasing focus with the rise in...]]></description>
      <content:encoded><![CDATA[Security vendor Sophos plans to acquire Utimaco, a German company specializing in software that aims to prevent sensitive data from escaping corporate networks, an increasing focus with the rise in data breaches.]]></content:encoded>
      <pubDate>Sun, 27 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/prevent sensitive data">prevent sensitive data</category>
      <category domain="http://www.securityratty.com/tag/german company">german company</category>
      <category domain="http://www.securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://www.securityratty.com/tag/acquire utimaco">acquire utimaco</category>
      <category domain="http://www.securityratty.com/tag/focus">focus</category>
      <category domain="http://www.securityratty.com/tag/aims">aims</category>
      <category domain="http://www.securityratty.com/tag/networks">networks</category>
      <category domain="http://www.securityratty.com/tag/software">software</category>
      <source url="http://www.networkworld.com/news/2008/072808-sophos-plans-to-acquire-german.html?fsrc=rss-security">Sophos plans to acquire German data security company</source>
    </item>
    <item>
      <title><![CDATA[China aims to protect Olympic content from pirates]]></title>
      <link>http://www.securityratty.com/article/31b01ea8f041222ea79b269067f538e0</link>
      <guid>http://www.securityratty.com/article/31b01ea8f041222ea79b269067f538e0</guid>
      <description><![CDATA[China warned Web sites and mobile content providers not to violate the state-owned broadcaster's rights to cover the Olympic...]]></description>
      <content:encoded><![CDATA[China warned Web sites and mobile content providers not to violate the state-owned broadcaster's rights to cover the Olympic Games.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=dFQgzY"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=dFQgzY" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/330980309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/mobile content providers">mobile content providers</category>
      <category domain="http://www.securityratty.com/tag/olympic games">olympic games</category>
      <category domain="http://www.securityratty.com/tag/web sites">web sites</category>
      <category domain="http://www.securityratty.com/tag/china">china</category>
      <category domain="http://www.securityratty.com/tag/rights">rights</category>
      <category domain="http://www.securityratty.com/tag/cover">cover</category>
      <category domain="http://www.securityratty.com/tag/broadcaster">broadcaster</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/330980309/article.do">China aims to protect Olympic content from pirates</source>
    </item>
    <item>
      <title><![CDATA[Nigeria aims to end mobile phone theft]]></title>
      <link>http://www.securityratty.com/article/c4f15a8af237d2ed9a5c7fb40aa0f1f6</link>
      <guid>http://www.securityratty.com/article/c4f15a8af237d2ed9a5c7fb40aa0f1f6</guid>
      <description><![CDATA[Mobile phone theft in Nigeria could become a thing of the past by the end of the year, according to the Nigerian Communications Commission...]]></description>
      <content:encoded><![CDATA[Mobile phone theft in Nigeria could become a thing of the past by the end of the year, according to the Nigerian Communications Commission (NCC).]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/mobile phone theft">mobile phone theft</category>
      <category domain="http://www.securityratty.com/tag/nigerian communications commission">nigerian communications commission</category>
      <category domain="http://www.securityratty.com/tag/nigeria">nigeria</category>
      <category domain="http://www.securityratty.com/tag/ncc">ncc</category>
      <category domain="http://www.securityratty.com/tag/past">past</category>
      <source url="http://www.networkworld.com/news/2008/070108-nigeria-aims-to-end-mobile.html?fsrc=rss-security">Nigeria aims to end mobile phone theft</source>
    </item>
  </channel>
</rss>
