<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: firewall]]></title>
    <link>http://www.securityratty.com/tag/firewall</link>
    <description></description>
    <pubDate>Fri, 15 Aug 2008 10:51:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Commoditization of Anti Debugging Features in RATs]]></title>
      <link>http://www.securityratty.com/article/d357b72fd1cde8f737f42b6043955d6b</link>
      <guid>http://www.securityratty.com/article/d357b72fd1cde8f737f42b6043955d6b</guid>
      <description><![CDATA[Is it a Remote Administration Tool (RAT) or is it malware ? That's the rhetorical question , since RATs are not supposed to have built-in Virustotal submission for the newly generated server,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SL1nh-1oqdI/AAAAAAAACJc/FJtmUCHs730/s1600-h/anti_debugging_rat_malware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SL1nh-1oqdI/AAAAAAAACJc/m8B4yux3_5I/s200-R/anti_debugging_rat_malware.png" /></a>Is it a <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Administration Tool</a> (RAT) or is it <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">malware</a>? That's the <a href="http://ddanchev.blogspot.com/2007/08/shark-2-diy-malware.html">rhetorical question</a>, since <a href="http://ddanchev.blogspot.com/2007/12/shark-malware-new-versions-coming.html">RATs are not supposed</a> to have built-in Virustotal submission for the newly generated server, antivirus software "killing" and <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">firewall bypassing capabilities</a>.<br />
<br />
Taking a peek into some of commodity features aiming to make it harder to analyze the malware found in pretty much all the average DIY malware builders available at the disposal at the average script kiddies, one of the latest releases pitched as RAT while it's malware clearly indicates the commoditization and availability of such modules :<br />
<br />
" <i>- FWB (DLL Injection, The DLL is Never Written to Disk)<br />
&nbsp;- Decent Strong Traffic Encryption<br />
&nbsp;- Try to Unhook UserMode APIs<br />
&nbsp;- No Plugins/3rd Party Applications<br />
&nbsp;- 4 Startup Methods (Shell, Policies, ActiveX, UserInIt)<br />
&nbsp;- Set Maximum Connections<br />
&nbsp;- Built In File Binder<br />
&nbsp;- Multi Threaded Transfers<br />
&nbsp;- Anti Debugging (Anti VMware, Anti Sandboxie, Anti Norman Sandbox, Anti VirtualPC, Anti Anubis Sandbox, Anti CW Sandbox)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SL6CyJQUdnI/AAAAAAAACJk/b4Erkx13fpg/s1600-h/anti_debugging_rat_malware_stats.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SL6CyJQUdnI/AAAAAAAACJk/Lum7M48FdSQ/s200-R/anti_debugging_rat_malware_stats.png" /></a>Malware coders or "malware modulators"? With the currently emerging <a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">malware as a web service</a> toolkits porting common malware tools to the web, drag and drop web interfaces for malware building are <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">definitely in the works</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2qWlBL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2qWlBL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BQjJaL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BQjJaL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6b1sjl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6b1sjl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CVEqWl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CVEqWl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BzubfL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BzubfL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7ZXFYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7ZXFYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LhD8dl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LhD8dl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382311481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:46:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/anti">anti</category>
      <category domain="http://www.securityratty.com/tag/anti vmware">anti vmware</category>
      <category domain="http://www.securityratty.com/tag/anti norman sandbox">anti norman sandbox</category>
      <category domain="http://www.securityratty.com/tag/common malware tools">common malware tools</category>
      <category domain="http://www.securityratty.com/tag/malware">malware</category>
      <category domain="http://www.securityratty.com/tag/anti virtualpc">anti virtualpc</category>
      <category domain="http://www.securityratty.com/tag/malware coders">malware coders</category>
      <category domain="http://www.securityratty.com/tag/anti anubis sandbox">anti anubis sandbox</category>
      <category domain="http://www.securityratty.com/tag/malware modulators">malware modulators</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382311481/commoditization-of-anti-debugging.html">The Commoditization of Anti Debugging Features in RATs</source>
    </item>
    <item>
      <title><![CDATA[NetBarrier X5]]></title>
      <link>http://www.securityratty.com/article/2b26807d12ce51084d97c0ba35b36100</link>
      <guid>http://www.securityratty.com/article/2b26807d12ce51084d97c0ba35b36100</guid>
      <description><![CDATA[Intego's NetBarrier X5 security suite offers several tools to protect your Mac from vandals and criminals. Its centerpiece is the NetBarrier firewall, but the package can also block cookies while your...]]></description>
      <content:encoded><![CDATA[Intego's NetBarrier X5 security suite offers several tools to protect your Mac from vandals and criminals. Its centerpiece is the NetBarrier firewall, but the package can also block cookies while your surf the Web, scrub personal data afterwards, and block Trojan horses. While NetBarrier X5's features are generally good, the $50 program has enough peculiarities that some users will be better off with the firewall tools that come with OS X for free.]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/netbarrier">netbarrier</category>
      <category domain="http://www.securityratty.com/tag/netbarrier firewall">netbarrier firewall</category>
      <category domain="http://www.securityratty.com/tag/block trojan horses">block trojan horses</category>
      <category domain="http://www.securityratty.com/tag/firewall tools">firewall tools</category>
      <category domain="http://www.securityratty.com/tag/security suite offers">security suite offers</category>
      <category domain="http://www.securityratty.com/tag/tools">tools</category>
      <category domain="http://www.securityratty.com/tag/scrub personal data">scrub personal data</category>
      <category domain="http://www.securityratty.com/tag/block cookies">block cookies</category>
      <category domain="http://www.securityratty.com/tag/users">users</category>
      <source url="http://www.networkworld.com/news/2008/090308-netbarrier.html?fsrc=rss-security">NetBarrier X5</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://www.securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://www.securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://www.securityratty.com/tag/security standards">security standards</category>
      <category domain="http://www.securityratty.com/tag/soa security">soa security</category>
      <category domain="http://www.securityratty.com/tag/soa">soa</category>
      <category domain="http://www.securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://www.securityratty.com/tag/information security">information security</category>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[In the News: Great Firewall of China, Online Privacy Rights]]></title>
      <link>http://www.securityratty.com/article/5f7a8312167d5caf14acb32657158d98</link>
      <guid>http://www.securityratty.com/article/5f7a8312167d5caf14acb32657158d98</guid>
      <description><![CDATA[Some Anti-Virus Programs More Equal than OthersLet's assume that the single most frequently asked IT-security question is: &quot;How the heck do I get Defender Pro off my computer?&quot; Then...]]></description>
      <content:encoded><![CDATA[Some Anti-Virus Programs More Equal than OthersLet's assume that the single most frequently asked IT-security question is: "How the heck do I get Defender Pro off my computer?" Then the ...]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 10:36:58 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/it-security question">it-security question</category>
      <category domain="http://www.securityratty.com/tag/anti-virus programs">anti-virus programs</category>
      <category domain="http://www.securityratty.com/tag/defender pro">defender pro</category>
      <category domain="http://www.securityratty.com/tag/assume">assume</category>
      <category domain="http://www.securityratty.com/tag/single">single</category>
      <category domain="http://www.securityratty.com/tag/frequently">frequently</category>
      <category domain="http://www.securityratty.com/tag/heck">heck</category>
      <category domain="http://www.securityratty.com/tag/computer">computer</category>
      <category domain="http://www.securityratty.com/tag/otherslet">otherslet</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382697980/">In the News: Great Firewall of China, Online Privacy Rights</source>
    </item>
    <item>
      <title><![CDATA[Run Through PCI DSS 1.2 Changes]]></title>
      <link>http://www.securityratty.com/article/ce0e02f57e234e1b64d186272da31186</link>
      <guid>http://www.securityratty.com/article/ce0e02f57e234e1b64d186272da31186</guid>
      <description><![CDATA[Finally, I found time to read PCI DSS 1.2. change doc. So
Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network...]]></description>
      <content:encoded><![CDATA[<p>Finally, I found time to read PCI DSS 1.2. change doc. So:</p>  <ul>   <li>Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network device&quot; cloud) - see Req 1 </li>    <li>From the &quot;WTH dept&quot;: anti-virus is a MUST on <strong>ALL</strong> platforms - Req 5. Please ship me some of the stuff they are smoking; I want it! BTW, I am <a href="http://www.govcert.nl/symposium/index.html">going to Amsterdam soon</a> :-) </li>    <li>WAF or code review for web application security is still a stupid &quot;OR&quot; - Req 6.6. OMG, please, <a href="http://www.tssci-security.com/archives/2008/06/27/week-of-war-on-wafs-day-5-final-thoughts/">software security folks</a>, teach them the truth.</li>    <li>Can we kill &quot;plain text passwords&quot; once and for all? Req 8 tries to achieve that noble goal (good thing!) </li>    <li>Visit your offsite data storage - good (if costly) idea - added to Req 9. Requirements to secure electronic AND&#160; paper media&#160; are solid too.</li>    <li>Love it, love it! Req 10 explains that logs needs to be actually available: 'three months of audit trail history must be &#8220;<strong>immediately available for analysis</strong>&#8221; or <strong>quickly accessible'</strong> (bye-bye, silly log dumps...)</li>    <li>Some vulnerability stuff clarified in Req 11, mostly about ASVs and pentesting.</li>    <li>Scope of security policy is expanded to &quot;employee-facing technologies&quot; (what a term!) - Req 12</li>    <li>All over: more references to wireless&#160; (WEP, access points, hidden SSIDs, etc) - indeed, recent data losses are often due to insecure wireless.</li> </ul>  <p>Overall, a minor change that, sadly, doesn't touch a few KEY areas, such as virtualization, for one.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oED2TK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oED2TK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pUb9XK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pUb9XK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bX5cGK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bX5cGK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375460383" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 07:38:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/req">req</category>
      <category domain="http://www.securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://www.securityratty.com/tag/offsite data storage">offsite data storage</category>
      <category domain="http://www.securityratty.com/tag/insecure wireless">insecure wireless</category>
      <category domain="http://www.securityratty.com/tag/audit trail history">audit trail history</category>
      <category domain="http://www.securityratty.com/tag/silly log dumps">silly log dumps</category>
      <category domain="http://www.securityratty.com/tag/wireless">wireless</category>
      <category domain="http://www.securityratty.com/tag/plain text passwords">plain text passwords</category>
      <category domain="http://www.securityratty.com/tag/vulnerability stuff">vulnerability stuff</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375460383/run-through-pci-dss-12-changes.html">Run Through PCI DSS 1.2 Changes</source>
    </item>
    <item>
      <title><![CDATA[Reputation Damage & Measurement]]></title>
      <link>http://www.securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</link>
      <guid>http://www.securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</guid>
      <description><![CDATA[Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things...]]></description>
      <content:encoded><![CDATA[<p>Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things like &#8220;corporate reputation&#8221; and &#8220;goodwill&#8221; and &#8220;brand equity&#8221; can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).</p>
<p>Complicating factors is the impact (or lack thereof) of incidents on stock price.  Many researchers who identify themselves with the <strong><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787">New School of Information Security</a></strong> (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact.  I think this stems from our days of slinging FUD, back when we could scream &#8220;Buy a firewall or we&#8217;ll have an incident and you&#8217;ll be on the front page of the paper and the stock price will go down!&#8221;  But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived.  <em><strong>With qualifications, of course.</strong></em></p>
<p>So what would/should we make of this from <a href="http://www.money.co.uk/article/1001229-12-million-wiped-off-helphire-stock-after-malicious-gmail-sent-to-clients.htm">Money.co.uk</a>?</p>
<p style="text-align: center;"><strong>£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients</strong></p>
<blockquote><p>Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.</p>
<p>The Bath-based business who specialise in providing replacement cars to &#8216;no-fault&#8217; drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.</p>
<p>Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.</p>
<p>Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done&#8230;</p>
<p>&#8230;The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.</p></blockquote>
<p>That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases.  It&#8217;s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down.  You know, the &#8220;Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area&#8221; type of headlines.  You really do have to question the causality and correlation.  So in the Helphire case above - is this new drop in stock really because of the email sent?  If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?</p>
<p>Even when we have &#8220;Objective Data&#8221; (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past.  The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.</p>
<p>So it&#8217;s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.</p>
<p>So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they&#8217;re not rhetorical.  I am very interested in your views and welcome your comments!</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/stock">stock</category>
      <category domain="http://www.securityratty.com/tag/helphire stock">helphire stock</category>
      <category domain="http://www.securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://www.securityratty.com/tag/reputation">reputation</category>
      <category domain="http://www.securityratty.com/tag/stock price">stock price</category>
      <category domain="http://www.securityratty.com/tag/damage">damage</category>
      <category domain="http://www.securityratty.com/tag/email">email</category>
      <category domain="http://www.securityratty.com/tag/email account">email account</category>
      <category domain="http://www.securityratty.com/tag/malicious email">malicious email</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=387">Reputation Damage &amp; Measurement</source>
    </item>
    <item>
      <title><![CDATA[Web Based Botnet Command and Control Kit 2.0]]></title>
      <link>http://www.securityratty.com/article/4f945955ba8a424fe6b9352583602062</link>
      <guid>http://www.securityratty.com/article/4f945955ba8a424fe6b9352583602062</guid>
      <description><![CDATA[The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/bFba_0dWvI4/s1600-h/web_botnet_cc_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/TqKIw6bxpjw/s200-R/web_botnet_cc_1.JPG" /></a>The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose features clearly indicate that the kit's coder know exactly which niches to fill - presumably based on his personal experience or market research into competing products.<br />
<br />
What are some its key differentiation factors? <b>Multitasking</b> at its best, for instance, the kits provides the botnet master with the opportunity to manage numerous different task such as several malware campaigns and DDoS attacks simultaneously, where each of these gets a separate metrics page.  <b>&nbsp;</b><br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/Yicbw9alvSs/s1600-h/web_botnet_cc_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/rzG7g1DxhQs/s200-R/web_botnet_cc_2.JPG" /></a><b>Automation</b> of malicious tasks, by setting up tasks, and issuing notices on the status of the task, when it was run and when it was ended. Just consider the possibilities for a scheduling malware and DDoS attacks for different quarters. <b>&nbsp;</b><br />
<br />
<b>Segmentation</b> in every aspect of the tasks, for instance, a DDoS attacks against a particular site can be scheduled to launched on a specific date from infected hosts based in chosen countries only. <b>&nbsp;</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/UMGxAh9uGF0/s1600-h/web_botnet_cc_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/ZlxV-mc44fM/s200-R/web_botnet_cc_3.JPG" /></a><b>Customized DDoS</b> in the sense of empowering the botnet master with point'n'click ability to dedicate a precise number of the bots to participate, which countries they should be based in, and for how long the attack should remain active. <b>Quality and assurance in DDoS attacks</b> based on the measurement of the bot's bandwidth against a particular country, in this case the object of the attack, so theoretically bots from neighboring countries would DDoS the country in question far more efficiently. <b>&nbsp;</b><br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/NKwLnKmmH44/s1600-h/web_botnet_cc_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/pVosEgAltxk/s200-R/web_botnet_cc_4.JPG" /></a><b>Historical malware campaign performance</b>, is perhaps the most quality assurance feature in the entire kit, presumably created in order to allow the person behind it to measure which were the most effective malware and DDoS campaigns that he executed in the past. From an OSINT perspective, sacrificing his operational security by maintaing detailed logs from previous attacks is a gold mine directly establishing his relationships with previous malware campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/BhFmeDoa8Lk/s1600-h/web_botnet_cc_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/vij9THb60ow/s200-R/web_botnet_cc_5.JPG" /></a><b>Bot Description</b>:  &nbsp; <br />
<div dir="ltr" id="result_box">1. Completely invisible Bot work in the system.  <br />
2. Not loads system.  <br />
3. Invisible in the process.  <br />
4. Workaround all firewall.  <br />
5. Bot implemented as a driver.  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/SzpE6NqryP8/s1600-h/web_botnet_cc_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/CptzW9_ji-k/s200-R/web_botnet_cc_6.JPG" /></a><b>Functions Bot</b> (constantly updated):&nbsp;</div><div dir="ltr" id="result_box">1. Downloading a file (many options). <br />
2. HTTP DDoS (many options, including http authentication).  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/LI52hSDJhpA/s1600-h/web_botnet_cc_7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/AIaGhGUL0Fk/s200-R/web_botnet_cc_7.JPG" /></a><b>The web interface</b>&nbsp;</div><div dir="ltr" id="result_box">-- Convenient manager tasks. <br />
-- Every task can be stopped, put on pause, etc. ... <br />
-- Interest and visual scale of the task.&nbsp;&nbsp;</div><div dir="ltr" id="result_box">-- A task manager for DDoS and Loader <br />
&nbsp;&nbsp;&nbsp;&nbsp;</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/Zqcrn6XWYEw/s1600-h/web_botnet_cc_8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/0PQgE_timh4/s200-R/web_botnet_cc_8.JPG" /></a>-- <b>For DDoS tasks</b> </div><div dir="ltr" id="result_box">Bots involved in DDoS 'f. <br />
Condition of the victim (works, fell).  <br />
</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/HNHO_ar0MgA/s1600-h/web_botnet_cc_9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/Y1z0VIR3B9k/s200-R/web_botnet_cc_9.JPG" /></a>2. <b>Bots manager  </b><br />
-- Displays a list of bots (postranichno). <br />
-- Obratseniya date of the first and last. <br />
-- ID Bot. <br />
-- Country Bot. <br />
-- Type Bot. <br />
-- The status Bot (online / offline). <br />
-- Bot bandwidth to different parts of the world (europe, asia). <br />
-- The possibility of removing bots</div><div dir="ltr" id="result_box">-- When you click on ID Bot loadable still a wealth of information about it</div><div dir="ltr" id="result_box"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/BM5pm1_Rtag/s1600-h/web_botnet_cc_11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/mQEa7wVxDNc/s200-R/web_botnet_cc_11.JPG" /></a>3. <b>Statistics botneta  </b><br />
-- Statistics both common and build Bot. <br />
-- Information on the growth and decline botneta dates (and build). <br />
-- Bots online <br />
-- All bots</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/JTOJS-ZHQek/s1600-h/web_botnet_cc_12.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/ujbOfFEX9TA/s200-R/web_botnet_cc_12.JPG" /></a>-- Dead bots. <br />
<br />
4. <b>Statistics botneta country</b></div><div dir="ltr" id="result_box">-- All countries to work on&nbsp;</div><div dir="ltr" id="result_box">-- New work by country&nbsp;</div><div dir="ltr" id="result_box">-- Online work from country to country</div><div dir="ltr" id="result_box">-- Dead bots by country</div><div dir="ltr" id="result_box"></div><div dir="ltr" id="result_box">5. <b>Detailed history botneta</b>&nbsp;</div><div dir="ltr" id="result_box">6. <b>Convenient user-friendly interface adding teams</b> <br />
8. <b>Admin minimal server loads</b>  <br />
-- Use php5/mysql  <br />
</div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/3oulo2cgTtM/s1600-h/web_botnet_cc_13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/xEI9xAwNGNM/s200-R/web_botnet_cc_13.JPG" /></a><b>Upcoming features : </b><br />
1. Form grabber (price increase substantially), for old customers will be charged as an upgrade <br />
2. Public key cryptography<br />
3. Clustering campaigns and DDoS attacks<br />
<br />
Despite it's proprietary nature, it's quality and innovative features will sooner or later leak out for everyone to take advantage of, a rather common lifecycle for the majority of proprietary malware kits in general.</div><div dir="ltr" id="result_box"><br />
<b>Related posts:</b></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy DDoS Bot Web Based<br />
</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot - Web Based Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot - Web Based Malware</a> </div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">Custom DDoS Capabilities Within a Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">Loads.cc - DDoS for Hire Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a>&nbsp;</div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">Botnet Communication Platforms</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">A Botnet Master's To-Do List</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/05/ddos-on-demand-vs-ddos-extortion.html">DDoS on Demand VS DDoS Extortion</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/how-does-botnet-with-100k-infected-pcs.html">How Does a Botnet with 100k Infected PCs Look Like?</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y5dBtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y5dBtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WsNccK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WsNccK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ToV4Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ToV4Pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=I6a7ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=I6a7ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2S7WNK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2S7WNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qk66sK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qk66sK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8S5ask"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8S5ask" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/372102101" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:02:15 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/ddos attacks based">ddos attacks based</category>
      <category domain="http://www.securityratty.com/tag/ddos attacks">ddos attacks</category>
      <category domain="http://www.securityratty.com/tag/malware">malware</category>
      <category domain="http://www.securityratty.com/tag/previous malware campaigns">previous malware campaigns</category>
      <category domain="http://www.securityratty.com/tag/ddos attacks simultaneously">ddos attacks simultaneously</category>
      <category domain="http://www.securityratty.com/tag/botnet">botnet</category>
      <category domain="http://www.securityratty.com/tag/country">country</category>
      <category domain="http://www.securityratty.com/tag/country bot">country bot</category>
      <category domain="http://www.securityratty.com/tag/ddos">ddos</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/372102101/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</source>
    </item>
    <item>
      <title><![CDATA[XKCD 463 - Security of Voting machines]]></title>
      <link>http://www.securityratty.com/article/97907328bba6052989a326160217fbbe</link>
      <guid>http://www.securityratty.com/article/97907328bba6052989a326160217fbbe</guid>
      <description><![CDATA[Priceless! Replace voting machine with Web Application Firewall for a second chuckle...]]></description>
      <content:encoded><![CDATA[
Priceless! Replace voting machine with Web Application Firewall for a second chuckle  
http://xkcd.com/463/
       ]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 03:46:15 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/web application firewall">web application firewall</category>
      <category domain="http://www.securityratty.com/tag/xkcd">xkcd</category>
      <category domain="http://www.securityratty.com/tag/priceless">priceless</category>
      <category domain="http://www.securityratty.com/tag/replace">replace</category>
      <category domain="http://www.securityratty.com/tag/com463">com463</category>
      <category domain="http://www.securityratty.com/tag/chuckle">chuckle</category>
      <category domain="http://www.securityratty.com/tag/machine">machine</category>
      <source url="http://securitybuddha.com/2008/08/18/xkcd-463-security-of-voting-machines/">XKCD 463 - Security of Voting machines</source>
    </item>
    <item>
      <title><![CDATA[Is Your Firewall a High Risk Entity]]></title>
      <link>http://www.securityratty.com/article/b83df16599a33872ec0881b1127c5aed</link>
      <guid>http://www.securityratty.com/article/b83df16599a33872ec0881b1127c5aed</guid>
      <description><![CDATA[Not trying to be overly snarky here, but I was reviewing some GRC product literature recently. And there was a screenshot of an application window showing how the software helps identify high risk...]]></description>
      <content:encoded><![CDATA[<p>Not trying to be overly snarky here, but I was reviewing some GRC product literature recently.  And there was a screenshot of an application window showing how the software helps identify &#8220;high risk entities&#8221;.  And in the screenshot, there were 5 of these entities listed, each with corresponding risk ratings (High/Medium/Low) and scores (really just non-measurement ordinal numbers).  The screenshot showed that the riskiest entity of the five shown was a Checkpoint Firewall-an assertion backed up by the non-measurement &#8220;Risk Score&#8221;.  The lowest risk scores were shared by a nameless Web Application and an entity called &#8220;Oracle App&#8221;.</p>
<p>My friend, I&#8217;m going to give you a hint.  If your firewall is &#8220;high risk&#8221; and your actual business applications are &#8220;low risk&#8221; - you might be doing it wrong.</p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 11:15:57 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/non-measurement risk score">non-measurement risk score</category>
      <category domain="http://www.securityratty.com/tag/low risk">low risk</category>
      <category domain="http://www.securityratty.com/tag/risk entities">risk entities</category>
      <category domain="http://www.securityratty.com/tag/firewall">firewall</category>
      <category domain="http://www.securityratty.com/tag/risk scores">risk scores</category>
      <category domain="http://www.securityratty.com/tag/checkpoint firewall-an assertion">checkpoint firewall-an assertion</category>
      <category domain="http://www.securityratty.com/tag/entity">entity</category>
      <category domain="http://www.securityratty.com/tag/actual business applications">actual business applications</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=383">Is Your Firewall a High Risk Entity</source>
    </item>
    <item>
      <title><![CDATA[A Few More Words on DLP and Compliance]]></title>
      <link>http://www.securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</link>
      <guid>http://www.securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</guid>
      <description><![CDATA[Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - CMF - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was...]]></description>
      <content:encoded><![CDATA[<p>Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - <a href="http://securosis.com">CMF</a> - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was truly amazing to me that DLP vendors &quot;under-utilize&quot; compliance in their messaging. In other words, they don't push the &quot;C-word&quot; as strongly as many other security companies. Compliance dog doesn't snarl at you from their front pages and it doesn't bite you in you ass when you read the whitepapers, etc. Sure, it is mentioned there, but, seemingly, as an after-thought.</p>  <p>For example, Reconnex that was recently absorbed by McAfee, touts &quot;information protection&quot; before compliance. Similarly, my friends from <a href="http://www.nextiernetworks.com">nexTier</a> only mention &quot;compliance&quot; on <a href="http://www.nextiernetworks.com/solutions.html">a few pages</a>. Even newly unveiled DLP resource&#160; (<a href="http://www.dlpindepth.org/">DLP In-Depth portal</a>) only contains a little bit&#160; of information on how DLP solutions help with various compliance projects. People tout &quot;data protection&quot;, &quot; data security&quot;, &quot;data governance&quot; (aka &quot;we know big words - bigger than you&quot;) or even &quot;data risk management&quot; (aka &quot;we are confused about what we sell&quot;)</p>  <p>I decide to explore this curious phenomenon. </p>  <p>Initially, I thought that it was <a href="http://chuvakin.blogspot.com/2008/05/reverse-compliance-or-as-proof-of.html">reverse compliance</a> at work? People not wanting to know what content packs up and leaves their network. Then I thought that maybe DLP vendors just aren't &quot;the bandwagon jumping kind&quot; (yeah, right!) Then I thought that they are &quot;beyond compliance&quot; already :-)</p>  <p>But you know what? I actually think that it is something different, much more sinister. It is the ominous <a href="http://chuvakin.blogspot.com/2008/04/rsa-impressions-2-compliance.html">checklist mentality</a> (<a href="http://chuvakin.blogspot.com/2007/02/so-is-security-art.html">here</a> too)!&#160; You know, DLP is newer than&#160; most regulations (PCI DSS, HIPAA, FISMA, etc) and - what a shock! - the documentation for these mandates just doesn't mention DLP (or CMF) by name. Sure, they talk about data protection (e.g. PCI DSS Requirements 3 and 4), but mostly in terms of encryption, access control, <a href="http://www.loglogic.com">logging</a> (of course!).</p>  <p>Also, PCI DSS directly and explicitly says &quot;get a firewall&quot;, &quot;deploy <a href="http://www.loglogic.com">log management</a>&quot;, &quot;get scanned&quot;, &quot;install and update AV&quot; - but where is DLP? Ain't there...</p>  <p>Yes, Virginia, folks who &quot;go by the book&quot; and just &quot;do the minimum&quot; are missing out on the chance to procure DLP while their compliance budgets are still flowing. To me that means that many still don't get the <em>&quot;compliance+&quot; model</em> - <strong>buy for compliance -&gt; use for security, operations, having fun, etc. </strong>Think what <a href="http://www.nextiernetworks.com">a good DLP solution</a>&#160; will do for you in discovering regulated data across the entire organization, blocking those pesky email with SSNs, PHI (hi, HIPAA) and CCs (hi, PCI) as well as solving plenty of other problems ...</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PKkyjK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PKkyjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xsv29K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xsv29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=cyhlHK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=cyhlHK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/366024281" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 10:51:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/dlp">dlp</category>
      <category domain="http://www.securityratty.com/tag/compliance">compliance</category>
      <category domain="http://www.securityratty.com/tag/dlp in-depth portal">dlp in-depth portal</category>
      <category domain="http://www.securityratty.com/tag/procure dlp">procure dlp</category>
      <category domain="http://www.securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/data governance">data governance</category>
      <category domain="http://www.securityratty.com/tag/pci dss requirements">pci dss requirements</category>
      <category domain="http://www.securityratty.com/tag/mention dlp">mention dlp</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/366024281/few-more-words-on-dlp-and-compliance.html">A Few More Words on DLP and Compliance</source>
    </item>
  </channel>
</rss>
