<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fit]]></title>
    <link>http://www.securityratty.com/tag/fit</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Be Wary of Adele Services Small Charges in Your Bank Account]]></title>
      <link>http://www.securityratty.com/article/61bf4ecda7594a4d126788f0ed500965</link>
      <guid>http://www.securityratty.com/article/61bf4ecda7594a4d126788f0ed500965</guid>
      <description><![CDATA[Check your account balances carefully to make sure this isnt happening to you
According to Ars Technica , there are a wave of fraudsters right now who are taking small amounts out of consumer bank...]]></description>
      <content:encoded><![CDATA[<p>Check your account balances carefully to make sure this isn&#8217;t happening to you&#8211;</p>
<p>According to <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081202-odd-microtransactions-may-point-to-credit-card-breach.html">Ars Technica</a>, there are a wave of fraudsters right now who are taking small amounts out of consumer bank accounts. They do this to test whether the account is good and verify it. First, they take somewhere between 19-29 cents. Then, when they&#8217;ve verified the account, they make as many charges as possible before they get noticed:</p>
<blockquote><p>Beginning on or about November 20, various card holders began complaining online about unauthorized microtransactions that were suddenly showing up on their accounts. The charges fit the model described above, and were labeled as coming from Adele Services. Adele Services appears to be a dummy corporation; the 1-800 number listed as the customer contact point is disconnected and there&#8217;s no official website.</p>
<p>The company may not officially exist, but that hasn&#8217;t stopped it from continuing to test accounts. It&#8217;s impossible to state how many card holders have been pinged in this manner, but the number of online reports is growing steadily. Theories on which company&#8217;s security was breached abound, although the mob of sages has collectively ruled out PayPal, given the number of non-PayPal users affected.</p></blockquote>
<p>Be careful shopping online this holiday season, and don&#8217;t ignore little changes in your account, and hopefully you&#8217;ll have a safe secure shopping season.</p>]]></content:encoded>
      <pubDate>Wed, 03 Dec 2008 08:21:48 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/account">account</category>
      <category domain="http://www.securityratty.com/tag/adele services">adele services</category>
      <category domain="http://www.securityratty.com/tag/consumer bank accounts">consumer bank accounts</category>
      <category domain="http://www.securityratty.com/tag/accounts">accounts</category>
      <category domain="http://www.securityratty.com/tag/charges">charges</category>
      <category domain="http://www.securityratty.com/tag/account balances">account balances</category>
      <category domain="http://www.securityratty.com/tag/adele services appears">adele services appears</category>
      <category domain="http://www.securityratty.com/tag/test accounts">test accounts</category>
      <category domain="http://www.securityratty.com/tag/card holders">card holders</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/473921238/">Be Wary of Adele Services Small Charges in Your Bank Account</source>
    </item>
    <item>
      <title><![CDATA[Vulnerabilities and Office Versions]]></title>
      <link>http://www.securityratty.com/article/33580f773ea9bcdfab98d5db31b1fd04</link>
      <guid>http://www.securityratty.com/article/33580f773ea9bcdfab98d5db31b1fd04</guid>
      <description><![CDATA[Most of the ink on Microsoft vulnerability coverage goes to browsers and operating systems, but in a way the best progress vulnerabilities have made has been in Microsoft Office. Some of the great...]]></description>
      <content:encoded><![CDATA[Most of the ink on Microsoft vulnerability coverage goes to browsers and operating systems, but in a way the best progress vulnerabilities have made has been in Microsoft Office. Some of the great attacks of all time (remember LoveLetter?) have been through Office bugs, and I believe most targeted attacks over the last few years have utilized vulnerabilities in Office document parsers.

That's why it's encouraging that Microsoft has done a much better job in making current versions of Office secure, as <a href="http://blogs.msdn.com/david_leblanc/archive/2008/11/17/improvements-in-office-security.aspx">David LeBlanc's recent blog shows</a>. He claims that the company has really stepped up the security testing for Office 2003 SP3 and Office 2007, and that it shows up in the number of reported vulnerabilities. The trend is clear: There are about half as many vulnerabilities as for earlier versions.

There may be a little flaw in the analysis in that LeBlanc studied reports during the period from 9/18/2007 to 11/17/2008. By that time earlier Office versions had been around for a long time and many vulnerabilities had already been reported on them. But even so, it makes the numbers all the more impressive for the new versions; the older ones had already had the low-hanging fruit picked clean and yet they still had CVE numbers in excess of the new ones. It seems there is no low-hanging vulnerability fruit in new versions of Office.

Are you running an old version of Office? Are you running Office 2003 SP2, which <a href="http://blogs.eweek.com/cheap_hack/content/office/office_2003_sp2_approaching_end_of_life.html">reached the end of support life in October</a>? If so, you are exposing yourself to more known threats than you may think.

Office versions are not plug-and-play interchangeable. It's unfortunate that Microsoft saw fit to accompany Office 2007's security enhancements with a radical user interface change. I personally have gotten used to it, but I can see an enterprise being intimidated by the training it would necessitate.

If you feel you're stuck in Office 2003, at the very least it's irresponsible to linger on in an old service pack. Do what you can to move on to SP3.
<p><a href="http://feedads.googleadservices.com/~at/4uM3tOE5mU12QfUHAZpBRMt2y_E/a"><img src="http://feedads.googleadservices.com/~at/4uM3tOE5mU12QfUHAZpBRMt2y_E/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/cnC-qNVdwk4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 04:19:33 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/office versions">office versions</category>
      <category domain="http://www.securityratty.com/tag/office">office</category>
      <category domain="http://www.securityratty.com/tag/microsoft office">microsoft office</category>
      <category domain="http://www.securityratty.com/tag/versions">versions</category>
      <category domain="http://www.securityratty.com/tag/office secure">office secure</category>
      <category domain="http://www.securityratty.com/tag/office bugs">office bugs</category>
      <category domain="http://www.securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://www.securityratty.com/tag/office document parsers">office document parsers</category>
      <category domain="http://www.securityratty.com/tag/accompany office">accompany office</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/cnC-qNVdwk4/vulnerabilities_and_office_versions.html">Vulnerabilities and Office Versions</source>
    </item>
    <item>
      <title><![CDATA[Skein and SHA-3 News]]></title>
      <link>http://www.securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</link>
      <guid>http://www.securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</guid>
      <description><![CDATA[There are two bugs in the Skein code. They are subtle and esoteric, but they're there. We have revised both the reference and optimized code -- and provided new test vectors -- on the Skein website ....]]></description>
      <content:encoded><![CDATA[<p>There are two bugs in the Skein code.  They are subtle and esoteric, but they're there.  We have revised both the reference and optimized code -- and provided new test vectors -- on the <a href="http://www.schneier.com/skein.html">Skein website</a>.  A <a href="http://www.schneier.com/skein.pdf">revision of the paper</a> -- Version 1.1 -- has new IVs, new test vectors, and also fixes a few typos in the paper.</p>

<blockquote>Errata: Version 1.1 of the paper, reference, and optimized code corrects an error in which the length of the configuration string was passed in as the size of the internal block (256 bits for Skein-256, 512 for Skein-512, and 1024 for Skein-1024), instead of a constant 256 bits for all three sizes.  This error has no cryptographic significance, but affected the test vectors and the initialization values.  The revised code also fixes a bug in the MAC mode key processing.  This bug does not affect the NIST submission in any way.</blockquote>

<p><a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">NIST has received</a> 64 submissions.  (<a href="http://www.cio.com/article/461164/Amateurs_and_Pros_Vie_to_Build_New_Crypto_Standard">This article</a> interviews one of the submitters, who is fifteen.)  Of those, <a href="http://ehash.iaik.tugraz.at/wiki/The_SHA-3_Zoo">28 are public</a> and six have been broken.  NIST is going through the submissions right now, making sure they are complete and proper.  Their goal is to publish the accepted submissions by the end of the month, in advance of the <a href="http://csrc.nist.gov/groups/ST/hash/timeline.html">Third Cryptographic Hash Workshop</a> to be held in Belgium right after <a href="https://www.cosic.esat.kuleuven.be/fse2009/index.shtml">FSE</a> in February.  They expect to quickly make a first cut of algorithms -- hopefully to about a dozen -- and then give the community about a year of cryptanalysis before making a second cut in 2010.</p>

<p>Lastly, <a href="http://www.darkreading.com/blog/archives/2008/11/bending_skein_c.html">this</a> is a really nice article on Skein.</p>

<blockquote>These submissions make some accommodation to the Core 2 processor. They operate in "<a href="http://en.wikipedia.org/wiki/Little_endian" target="new">little-endian</a>" mode (a quirk of the <a href="http://en.wikipedia.org/wiki/X86" target="new">Intel-like processors</a> that reads some bytes in reverse order). They also allow a large file to be broken into chunks to split the work across multiple processors.

<p>However, virtually all of the contest submissions share the performance problem mentioned above. The logic they use won't optimally fit within the constraints of a Intel Core 2 processor. Most will perform as bad or worse than the existing SHA-1 algorithm.</p>

<p>One exception to this is <a href="http://www.schneier.com/skein.html" target="new">Skein</a>, created by several well-known cryptographers and noted pundit <a href="http://www.schneier.com/" target="new">Bruce Schneier</a>. It was designed specifically to exploit all three of the Core 2 execution units and to run at a full 64-bits. This gives it roughly four to 10 times the logic density of competing submissions.</p>

<p>This is what I meant by the <i><a href="http://www.imdb.com/title/tt0133093/" target="new">Matrix</a></i> quote above. They didn't bend the spoon; they bent the crypto algorithm. They moved the logic operations around in a way that wouldn't weaken the crypto, but would strengthen its speed on the Intel Core 2.</p>

<p>In their <a href="http://www.schneier.com/skein.pdf" target="new">paper</a> (PDF), the authors of Skein express surprise that a custom silicon <a href="http://en.wikipedia.org/wiki/Application-specific_integrated_circuit" target="new">ASIC</a> implementation is not any faster than the software implementation. They shouldn't be surprised. Every time you can redefine a problem to run optimally in software, you will reach the same speeds you get with optimized ASIC hardware. The reason software has a reputation of being slow is because people don't redefine the original problem.</blockquote></p>

<p>That's exactly what we were trying to do.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=98JTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=98JTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=diffN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=diffN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 03:14:48 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/skein">skein</category>
      <category domain="http://www.securityratty.com/tag/skein-1024">skein-1024</category>
      <category domain="http://www.securityratty.com/tag/skein-512">skein-512</category>
      <category domain="http://www.securityratty.com/tag/skein express surprise">skein express surprise</category>
      <category domain="http://www.securityratty.com/tag/skein website">skein website</category>
      <category domain="http://www.securityratty.com/tag/skein code">skein code</category>
      <category domain="http://www.securityratty.com/tag/submissions share">submissions share</category>
      <category domain="http://www.securityratty.com/tag/submissions">submissions</category>
      <category domain="http://www.securityratty.com/tag/code">code</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/skein_and_sha-3.html">Skein and SHA-3 News</source>
    </item>
    <item>
      <title><![CDATA[MSDN Security Issue Articles]]></title>
      <link>http://www.securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</link>
      <guid>http://www.securityratty.com/article/1074b3008b822d4dbf799e92676f81a1</guid>
      <description><![CDATA[Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine we have three articles that might be interesting to you, given that you read the SDL Blog
First up is a code...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. The SDL team is well represented in the annual security issue of MSDN magazine – we have three articles that might be interesting to you, given that you read the SDL Blog!</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>First up is a code review quiz, “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc982154.aspx"><FONT face=Calibri size=3>Test Your Security IQ</FONT></A><FONT face=Calibri size=3>”. Put your C/C++/C# security skills to the challenge by reviewing ten tricky code snippets that Michael and I devised. As an added incentive, I’ll post public congratulations here in the SDL blog to the first person who reverses the insecure hash found somewhere in the exam (not to give too much of a hint).</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up, we have “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd153756.aspx"><FONT face=Calibri size=3>Agile SDL: Streamline Security Practices for Agile Development</FONT></A><FONT face=Calibri size=3>”. I’ve been talking about web application security issues in the SDL blog (and in the </FONT><A href="http://msdn.microsoft.com/en-us/magazine/cc794277.aspx"><FONT face=Calibri size=3>September</FONT></A><FONT face=Calibri size=3> issue of MSDN magazine, if you missed it). However, while it’s essential to make sure that web-specific issues are covered in the SDL, it’s equally important to make sure that web development teams – and other Agile development teams – can use the SDL effectively, and the classic, phased SDL approach is not always a good fit for these teams. This MSDN article is the first public look at the new SDL/Agile methodology that we’ve been working on for the last year. This process is currently in beta with some internal Microsoft product teams and online services. We’d love to get some external feedback on it before we release it to the entire company, so please send us your thoughts.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, be sure to check out Michael’s Security Briefs column “</FONT><A href="http://msdn.microsoft.com/en-us/magazine/dd148644.aspx"><FONT face=Calibri size=3>Threat Models Improve Your Security Process</FONT></A><FONT face=Calibri size=3>”. Regular readers of this blog know how important threat modeling is to secure development. This article describes methods of using threat modeling not just to identify security vulnerabilities outright, but how to use it to make other SDL activities such as fuzzing and reducing attack surface more effective.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Three articles are more than enough for one team for one month! But be on the lookout for more articles from the usual SDL suspects in the near future. As always, keep watching this space for details.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9067921" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 20:58:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/sdl">sdl</category>
      <category domain="http://www.securityratty.com/tag/usual sdl suspects">usual sdl suspects</category>
      <category domain="http://www.securityratty.com/tag/sdl approach">sdl approach</category>
      <category domain="http://www.securityratty.com/tag/annual security issue">annual security issue</category>
      <category domain="http://www.securityratty.com/tag/agile sdl">agile sdl</category>
      <category domain="http://www.securityratty.com/tag/sdl activities">sdl activities</category>
      <category domain="http://www.securityratty.com/tag/security process">security process</category>
      <category domain="http://www.securityratty.com/tag/sdl team">sdl team</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/11/13/msdn-security-issue-articles.aspx">MSDN Security Issue Articles</source>
    </item>
    <item>
      <title><![CDATA[XSS Comedy III: Tax Cheats with Small Equipment]]></title>
      <link>http://www.securityratty.com/article/231bdf97af3811aa73d852717e216a77</link>
      <guid>http://www.securityratty.com/article/231bdf97af3811aa73d852717e216a77</guid>
      <description><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the first and second in the series
I don't know about you, but I enjoy...]]></description>
      <content:encoded><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the <a href="http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html" target="_blank">first</a> and <a href="http://holisticinfosec.blogspot.com/2008/09/xss-fortune-cookie.html" target="_blank">second</a> in the series.<br />I don't know about you, but I enjoy occasionally watching offerings like the History Channel, AMC, or the Military Channel. I'm a 40ish, white male and as such I likely fit the general demographic as perceived by the marketing geniuses who buy the late evening advertising blocks on these channels. <br />That does NOT mean that I cheat of my taxes and thus need the services of a plethora of scam artists selling tax relief. Nor does it mean that I have any interest in "enhancement" opportunities like Enzyte or ExtenZe. <br />I just love people who choose to skip out on a primary obligation of citizenship that most of us choose to meet, and expect to magically turn $100,000 in tax debt into $999. Then there are the "businesses" who exploit these folks and willingly convince them of their "success" via the power of advertising, at which point my patience just snaps, as it did last night. <br />Thus, part one of this rant is a mighty <span style="font-weight:bold;">bugger off</span> to all the "tax relief" companies. To their patrons, may I suggest simply paying taxes like the rest of us?<br />Here's an XSS vulnerability in the Freedom Financial Network, "as seen on TV", designed to express precisely how I feel: <br /><br /><a href="http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />If and when they fix this issue, here's the <a href="http://holisticinfosec.org/video/freedomtaxrelief/nothingisfree.html" target="_blank">video</a> for posterity.<br /><br />Part two of this rant will get you more bang for your buck, and I'm not talking enhancement.<br />Thanks to my utter disdain for the endlessly annoying advertising I went to the ExtenZe site to see what might be broken which immediately led me to discover an entire platform vulnerability in the ColdFusion application built by <a href="http://www.internet-direct-response.com/portfolio.html" target="_blank">Internet Direct Response (IDR)</a>, the wankers who proudly bring you Maxoderm, Vivaxa, Vazomyne, Smoke Away, and Hydroxydrene; all such reputable products, and all repetitively wearing me out via DirectTV. At the ExtenZe site I spotted a variable that seemed worthy of building a <a href="http://www.google.com/search?hl=en&q=inurl:%22microppcsite%22&start=0&sa=N" target="_blank">Googledork</a> from, and I soon discovered that it was a consistent variable in most of the sites pimping this crap; specifically, <span style="font-style:italic;">microppcsite</span>. You can follow all the search results back to our friends at IDR. <br />A little experimentation and I quickly discovered that the similar <span style="font-style:italic;">microppcterm</span> variable was vulnerable to entertaining XSS exploitation so I started with:<br /><br /><a href="http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA" target="_blank">http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA</a><br /><br />Pick your poison, it works on most IDR gems.<br /><br /><a href="http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />Again, a <a href="http://holisticinfosec.org/video/enhancement/enhancement.html" target="_blank">video</a>, should IDR choose to fix their app.<br /><br />And now, the grand prize for pathetic: The ExtenZe site is <a href="https://www.mcafeesecure.com/RatingVerify?ref=www.extenzeforlife.com" target="_blank">McAfee Secure</a>. <br /><br />I couldn't make this stuff up if I tried.<br />You thought www stood for world wide web. Try wee willy wankers. *sigh*<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html&title=XSS%20Comedy%20III:%20Tax%20Cheats%20with%20Small%20Equipment " title="XSS Comedy III: Tax Cheats with Small Equipment ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html" title="XSS Comedy III: Tax Cheats with Small Equipment ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 13:52:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/idr">idr</category>
      <category domain="http://www.securityratty.com/tag/idr choose">idr choose</category>
      <category domain="http://www.securityratty.com/tag/extenze site">extenze site</category>
      <category domain="http://www.securityratty.com/tag/extenze">extenze</category>
      <category domain="http://www.securityratty.com/tag/variable">variable</category>
      <category domain="http://www.securityratty.com/tag/consistent variable">consistent variable</category>
      <category domain="http://www.securityratty.com/tag/wankers">wankers</category>
      <category domain="http://www.securityratty.com/tag/choose">choose</category>
      <category domain="http://www.securityratty.com/tag/tax relief">tax relief</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">XSS Comedy III: Tax Cheats with Small Equipment</source>
    </item>
    <item>
      <title><![CDATA[Pseudo Email Marketing Tools Empowering Spammers]]></title>
      <link>http://www.securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</link>
      <guid>http://www.securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</guid>
      <description><![CDATA[Largely ignoring its real life applicability, a vendor of &quot;email marketing&quot; tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years....]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/eVrvlQbC73Y/s1600-h/marketing_spamming_6.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/ByNNe5khEhY/s200-R/marketing_spamming_6.gif" /></a>Largely ignoring its real life applicability, a vendor of "email marketing" tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years. Originally released in 2004, the vendor appears to have been actively improving the real-time metrics of the campaigns, next to building interactivity into the spamming process through the WYSIWYG editor.<br />
<br />
For better or worse, despite that these applications are empowering spammers and lowering down the entry barriers into spamming, the tools have gotten <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">largely replaced</a> by the <a href="http://ddanchev.blogspot.com/2008/10/inside-managed-spam-service.html">increasing number</a> of <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming services</a>, whose quality assurance features of bypassing spam filters act as a main differentiation factor. Here are some of this tool's features :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/IJaKNStG3tY/s1600-h/marketing_spamming_1.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="151" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/A906A5o9i1I/s200-R/marketing_spamming_1.gif" width="200" /></a><i>"- High speed distribution - 200,000 letters per hour.</i><br />
<i>- Contains an embedded SMTP server that allows you to send letters directly to the recipient's mailbox without using your provider's SMTP server.</i><br />
<i>-&nbsp; If you are accessing the Internet via modem, and distribution using the SMTP server, you do not fit - also allowed to send mail through any number of remote SMTP servers (relay), or via SMTP server provider.</i><br />
<i>- Support for SMTP authentication.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/V9kNzRzibCQ/s1600-h/marketing_spamming_2.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/_uP9YfEEhEk/s200-R/marketing_spamming_2.gif" /></a><i>- Supports up to 500 concurrent streams to send to each mailing.</i><br />
<i>- Automatic caching DNS requests to speed up distribution and reducing the load on the DNS server.</i><br />
<i>- Ability to run multiple independent shots at the same time.</i><br />
<i>- Ability to suspend delivery and continue later with a point.</i><br />
<i>- All modes distribution - TO, CC, BCC and PersonalCopy. In the latter case, the program generates a personal letter to each recipient.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/-Zr9CYINTlY/s1600-h/marketing_spamming_3.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/aJp3Ub3Uwfo/s200-R/marketing_spamming_3.gif" /></a><i>- Ability to specify the size of BCC package regimes TO, CC, and BCC.</i><br />
<i>- Ability to specify the TO: field for mailing regimes and CS BCC.</i><br />
<i>- Full emulation signature letters Outlook Express to increase cross-your-mails through spam filters.</i><br />
<i>- Support for distribution via a proxy server.</i><br />
<i>- Automatically detect the bad (non-existent) and not by E-Mail addresses directly in the process of distribution based on a flexible, user SMTP rules. Thanks SMTP rules achieved a very precise definition of bad addresses virtually no false positives.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/Rf_WZkjuJ84/s1600-h/marketing_spamming_7.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/kujVnisjcjY/s200-R/marketing_spamming_7.gif" /></a><i>- Ability to create lists of addresses, depending on the specific responses of remote servers for SMTP commands.</i><br />
<i>- Organize automatically subscribe / unsubscribe to the mailing addresses.</i><br />
<i>- Perform any processing of existing lists.</i><br />
<i>- Develop a letter to the powerful WYSIWYG Html editor.</i><br />
<br />
<i>- Automatically apply to each recipient by name, as well as paste in a letter to a specific, personalized information through powerful Mail Merge templates.</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/dlmHlT-5hyw/s1600-h/marketing_spamming_8.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/fRcQsC-6XlY/s200-R/marketing_spamming_8.gif" /></a><i>- Set the calendar to automatically launch shots at the right time.</i><br />
<i>- Quickly send out mail.</i>"<br />
<br />
With managed spam services' on-demand, risk forwarding and completely outsourced processes, they're not only going to replace such DIY tools, but also, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">position them as a dynamically</a> evolving <a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">cybercrime platforms</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CqO0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CqO0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HbgzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HbgzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KVshm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KVshm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJpMm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJpMm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ON79M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ON79M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nKPXM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nKPXM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hPU3m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hPU3m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/436383197" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 16:28:30 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/bad addresses">bad addresses</category>
      <category domain="http://www.securityratty.com/tag/addresses">addresses</category>
      <category domain="http://www.securityratty.com/tag/tools">tools</category>
      <category domain="http://www.securityratty.com/tag/smtp server">smtp server</category>
      <category domain="http://www.securityratty.com/tag/smtp server provider">smtp server provider</category>
      <category domain="http://www.securityratty.com/tag/e-mail addresses directly">e-mail addresses directly</category>
      <category domain="http://www.securityratty.com/tag/distribution">distribution</category>
      <category domain="http://www.securityratty.com/tag/modes distribution">modes distribution</category>
      <category domain="http://www.securityratty.com/tag/speed distribution">speed distribution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/436383197/pseudo-email-marketing-tools-empowering.html">Pseudo Email Marketing Tools Empowering Spammers</source>
    </item>
    <item>
      <title><![CDATA[How to exploit a down economy to get special security needs satisfied]]></title>
      <link>http://www.securityratty.com/article/a82608bb51e73553f52c79409ff96e69</link>
      <guid>http://www.securityratty.com/article/a82608bb51e73553f52c79409ff96e69</guid>
      <description><![CDATA[When there's not quite the right fit in network security gear to meet your needs and goals, you might wind up settling for some distant second choice, if one exists. But enterprise technology managers...]]></description>
      <content:encoded><![CDATA[When there's not quite the right fit in network security gear to meet your needs and goals, you might wind up settling for some distant second choice, if one exists. But enterprise technology managers are proving you can get what you want by pushing vendors to innovate -- a trend that may be growing because of the economic downturn. ]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/network security gear">network security gear</category>
      <category domain="http://www.securityratty.com/tag/enterprise technology managers">enterprise technology managers</category>
      <category domain="http://www.securityratty.com/tag/economic downturn">economic downturn</category>
      <category domain="http://www.securityratty.com/tag/distant">distant</category>
      <category domain="http://www.securityratty.com/tag/fit">fit</category>
      <category domain="http://www.securityratty.com/tag/vendors">vendors</category>
      <category domain="http://www.securityratty.com/tag/goals">goals</category>
      <category domain="http://www.securityratty.com/tag/choice">choice</category>
      <category domain="http://www.securityratty.com/tag/exists">exists</category>
      <source url="http://www.networkworld.com/news/2008/101608-security-stories.html?fsrc=rss-security">How to exploit a down economy to get special security needs satisfied</source>
    </item>
    <item>
      <title><![CDATA[Integrating Event/Incident and Problem Management]]></title>
      <link>http://www.securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</link>
      <guid>http://www.securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</guid>
      <description><![CDATA[Change, Change, Change. What needs to change as IT organizations move towards sophisticated virtualized infrastructure ? Event/Incident and Problem Management integration of course
We have been...]]></description>
      <content:encoded><![CDATA[<p>Change, Change, Change. What needs to change as IT organizations move towards sophisticated <a href="http://blog.taragana.com/index.php/archive/virtualization-technologies-full-virtualization-versus-para-virtualization/" target="_blank">virtualized infrastructure</a>? Event/Incident and Problem Management integration of course!</p>
<p>We have been conducting polls of our customers and of IT professionals at technology trade shows for the past two years and the results are in: Pulling together all of the management pieces and processes is even more crucial in a virtualized environment.</p>
<p>So what does this mean for you? You will need to refine your <a href="http://blog.evergreensys.com/2008/01/10/meeting-tough-customers-over-incident-management/" target="_blank">incident and problem management</a> processes with new technologies in order to reduce downtime and maintain end user performance. But of course even the most basic technologies are not well integrated even in today’s world.</p>
<p>I recently participated in a <a href="Gartner%20Conference" target="_blank">Gartner Conference</a> and watched to my amazement a real-time electronic survey of the audience. To my disbelief, the audience, filled with 300+ people from Fortune 2000 companies provided real-time responses to the question:</p>
<p><em>What level of integration does your IT org have between event management and service desk applications?</em></p>
<ul>
<li>None: 10%</li>
<li><strong>Manual Phone call from IT ops to IT service desk staff member: 46%</strong></li>
<li>Manual click button on event manager to open trouble ticket: 20%</li>
<li>Automated event management system automatically opens trouble ticket without requiring human oversight or approval: 24%</li>
</ul>
<p>Unbelievable… still very few of the survey respondents have yet to formalize problem management systems with event management systems. For 56% of the audience the process is still manual!</p>
<p>Another interesting real-time survey question at the Gartner Conference was:</p>
<p><em>Who in your organization is responsible for critical problem processes and resolution?</em></p>
<ul>
<li>IT Service Desk 13%</li>
<li>IT Operations 49%</li>
<li>Process Team 12%</li>
<li>Other 9%</li>
<li>Responsibility not formalized 17%</li>
</ul>
<p><a href="http://blogs.technet.com/virtualization/archive/2008/10/10/Guest-post_3A00_-virtualization-requires-the-proper-perspective-.aspx" target="_blank">Virtualization adoption</a> and the speed with which things change in a virtualized environment require automation and will transform <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">Incident and Problem Management</a>. Clearly with <a href="http://tarrysingh.blogspot.com/2008/10/microsoft-to-train-thousands-in.html" target="_blank">this new technology we are required to re-think</a> Organizational, Behavioral and Cultural Challenges required to take advantage of the opportunities that virtualization provides.</p>
<p>Incident and problem management processes and metrics must bridge organizational silos that have been the norm within IT. With virtualization, people have to work more closely together in the different silos than ever before. IT leaders need to break down the walls between the technology-centric silo mentalities.</p>
<p>Business Imperative Action Plan:</p>
<ol>
<li>What can you do<strong> today</strong>? &#8211;Understand the impact of virtualization on incident and problem mgt. workload, provide technology training for helpdesk/service desk staff.</li>
<li>What can you do in the <strong>next 12 months</strong>?</li>
</ol>
<p>Formalize problem management processes, metrics and personnel.<br />
Invest in tools and processes for systems on virtualized servers.<br />
Long term: On the Radar Screen!<br />
Instill teamwork into all groups responsible for the <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">virtualized environment</a> service and support. Map components and configuration items directly to end user services.</p>
<p>Final Thoughts: Know the management pieces and ensure that they fit together. It’s great to buy new technology, but be demanding to ensure that your vendors show you have they will help to link all these pieces together - Change, Inventory, Incident, Problem, Server, Capacity, Performance, Configuration, Event, and Integrated Workflow.</p>
]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 14:00:59 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/management">management</category>
      <category domain="http://www.securityratty.com/tag/event management systems">event management systems</category>
      <category domain="http://www.securityratty.com/tag/event">event</category>
      <category domain="http://www.securityratty.com/tag/management processes">management processes</category>
      <category domain="http://www.securityratty.com/tag/management pieces">management pieces</category>
      <category domain="http://www.securityratty.com/tag/management systems">management systems</category>
      <category domain="http://www.securityratty.com/tag/management integration">management integration</category>
      <category domain="http://www.securityratty.com/tag/event management system">event management system</category>
      <category domain="http://www.securityratty.com/tag/systems">systems</category>
      <source url="http://blog.sciencelogic.com/integrating-eventincident-and-problem-management/10/2008">Integrating Event/Incident and Problem Management</source>
    </item>
    <item>
      <title><![CDATA[M&A Patterns in the Security Space]]></title>
      <link>http://www.securityratty.com/article/02dbd407c40ad570cdb7e1bb486bbc22</link>
      <guid>http://www.securityratty.com/article/02dbd407c40ad570cdb7e1bb486bbc22</guid>
      <description><![CDATA[Mergers and acquisitions in the information security industry always come in waves, just like they do in the IT industry. After every wave, there is always talk of &quot;consolidation&quot; and &quot;enterprises...]]></description>
      <content:encoded><![CDATA[Mergers and acquisitions in the information security industry always come in waves, just like they do in the IT industry. After every wave, there is always talk of "consolidation" and "enterprises want one stop shopping"  and that talk is always proven wrong. Just as in the overall IT industry, the majority of mergers and acquisitions do <i>not</i> succeed and the ones that do are all about rationalization, not consolidation  adjacent areas of the market coming together into platforms that make sense to deliver security controls that have lower total cost of ownership to deal with older threats or provide more effective security against evolving threats. <br />
<br />
There are some clear failure patterns for mergers and acquisitions in the security space:<br />
<br />
	Those that <i>only</i> have the single vendor argument as justification  see Symantec exiting the network security space it got by acquiring Raptor and Recourse and CA selling what was left of SilentRunner. <br />
	Those that are essentially two sinking ships roping themselves together  too numerous to mention.<br />
<br />
Some clear patterns that can lead to success:<br />
<br />
	Host or network based security "platforms" acquiring technology to add protection vs. building it themselves: firewall companies acquire and integrate network IPS, AV companies acquiring anti-spyware and host-based IPS to integrate into end point protection platforms. <br />
	Major IT platform companies acquiring let the good guys in technology such as IAM products to embed access control and authentication capabilities into these business-driven products <br />
<br />
Easily six out of 10 mergers fit the failure pattern. Plus, after every wave of acquisitions, for every company that disappears two or three new ones pop up. That's one of the reasons why the information security space is so interesting and complex  between changing threats, changing business practices, and changing technology, nothing stays still.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 10:12:27 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security space">security space</category>
      <category domain="http://www.securityratty.com/tag/network security space">network security space</category>
      <category domain="http://www.securityratty.com/tag/companies">companies</category>
      <category domain="http://www.securityratty.com/tag/patterns">patterns</category>
      <category domain="http://www.securityratty.com/tag/firewall companies acquire">firewall companies acquire</category>
      <category domain="http://www.securityratty.com/tag/information security space">information security space</category>
      <category domain="http://www.securityratty.com/tag/mergers fit">mergers fit</category>
      <category domain="http://www.securityratty.com/tag/information security industry">information security industry</category>
      <category domain="http://www.securityratty.com/tag/mergers">mergers</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=3936">M&amp;A Patterns in the Security Space</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://www.securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://www.securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://www.securityratty.com/tag/oracle">oracle</category>
      <category domain="http://www.securityratty.com/tag/cloud">cloud</category>
      <category domain="http://www.securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://www.securityratty.com/tag/vmware">vmware</category>
      <category domain="http://www.securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://www.securityratty.com/tag/industry">industry</category>
      <category domain="http://www.securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://www.securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
  </channel>
</rss>
