<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2763509086404094443</id><updated>2011-11-27T15:26:29.036-08:00</updated><title type='text'>Julian's InfoSec Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-6918520211118187533</id><published>2010-04-14T07:22:00.000-07:00</published><updated>2010-04-14T07:22:42.720-07:00</updated><title type='text'>Meta-Information XSS</title><content type='html'>In his article "Introducing Meta-Information XSS", Tyler Reguly describes a method of XSS attack by proxy.&lt;br /&gt;&lt;br /&gt;The jist of it is, that most people trust the data returned from sources like ARIN.NET. The problem is that services like whois on ARIN may not filter the data that they retrieved on your behalf, thus possibly forwarding malicious content on to you.&lt;br /&gt;&lt;br /&gt;To read about his investigation into the matter, read his blog post and follow the links to his white paper and presentation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.ncircle.com/blogs/vert/archives/2010/04/introducing_metainformation_xs.html"&gt;http://blog.ncircle.com/blogs/vert/archives/2010/04/introducing_metainformation_xs.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-6918520211118187533?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/6918520211118187533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/04/meta-information-xss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/6918520211118187533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/6918520211118187533'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/04/meta-information-xss.html' title='Meta-Information XSS'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-5720386625075973650</id><published>2010-03-30T22:37:00.000-07:00</published><updated>2010-03-30T22:37:01.147-07:00</updated><title type='text'>Hacker exploits PDF files without using a vulnerability</title><content type='html'>&lt;blockquote&gt;A security researcher has managed to create a proof-of-concept PDF file that executes an embedded executable without exploiting any security vulnerabilities.&lt;br /&gt;&lt;div style="margin: 15px 0px; padding: 0px;"&gt;The PDF hack, when combined with clever social engineering techniques, could potentially allow code execution attacks if a user simply opens a rigged PDF file.&lt;/div&gt;&lt;/blockquote&gt;&amp;nbsp;&lt;a href="http://threatpost.com/en_us/blogs/hacker-finds-way-exploit-pdf-files-without-vulnerability-033010"&gt;http://threatpost.com/en_us/blogs/hacker-finds-way-exploit-pdf-files-without-vulnerability-033010&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-5720386625075973650?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/5720386625075973650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/hacker-exploits-pdf-files-without-using.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5720386625075973650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5720386625075973650'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/hacker-exploits-pdf-files-without-using.html' title='Hacker exploits PDF files without using a vulnerability'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-3129453275039819374</id><published>2010-03-22T20:23:00.000-07:00</published><updated>2010-03-22T20:23:05.521-07:00</updated><title type='text'>Academic Paper in China Sets Off Alarms in U.S.</title><content type='html'>&lt;blockquote&gt;&lt;a href="http://www.internationalrelations.house.gov/111/wor031010.pdf" title="Mr. Wortzel’s written testimony to the House Foreign Affairs Committee"&gt;Larry M. Wortzel&lt;/a&gt;, a military strategist and China specialist, told the House Foreign Affairs Committee on March 10 that it should be concerned because “Chinese researchers at the Institute of Systems Engineering of Dalian University of Technology published a paper on how to attack a small U.S. power grid sub-network in a way that would cause a cascading failure of the entire U.S.” &lt;/blockquote&gt;&lt;a href="http://www.nytimes.com/2010/03/21/world/asia/21grid.html"&gt;http://www.nytimes.com/2010/03/21/world/asia/21grid.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-3129453275039819374?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/3129453275039819374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/academic-paper-in-china-sets-off-alarms.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3129453275039819374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3129453275039819374'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/academic-paper-in-china-sets-off-alarms.html' title='Academic Paper in China Sets Off Alarms in U.S.'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-7223286096497138373</id><published>2010-03-07T22:44:00.000-08:00</published><updated>2010-03-07T22:44:53.292-08:00</updated><title type='text'>Thanks Captain Picard</title><content type='html'>I love this graphic. It says so much. I actually have it pinned up at my desk at work so it's easy for me to roll my eyes over and ask him the same question - usually several times a night.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_fsZeL9b0iok/S5Sc1vtmSgI/AAAAAAAABYU/hDcEDCermB0/s1600-h/PicardWTF.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_fsZeL9b0iok/S5Sc1vtmSgI/AAAAAAAABYU/hDcEDCermB0/s1600/PicardWTF.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Tonight I will share this graphic with you in response to this "Severe" OpenSSL vulnerability recently released. And this quote:&lt;br /&gt;&lt;blockquote&gt;The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device's power supply as it was processing encrypted messages. In a little more than 100 hours, they fed the device enough "transient faults" that they were able to assemble the entirety of its 1024-bit key.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.theregister.co.uk.nyud.net/2010/03/04/severe_openssl_vulnerability/"&gt;http://www.theregister.co.uk.nyud.net/2010/03/04/severe_openssl_vulnerability/&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-7223286096497138373?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/7223286096497138373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/thanks-captain-picard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7223286096497138373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7223286096497138373'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/thanks-captain-picard.html' title='Thanks Captain Picard'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_fsZeL9b0iok/S5Sc1vtmSgI/AAAAAAAABYU/hDcEDCermB0/s72-c/PicardWTF.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-5857144825201627633</id><published>2010-03-03T00:39:00.000-08:00</published><updated>2010-03-03T00:39:12.923-08:00</updated><title type='text'>Fraudsters target IT Workers</title><content type='html'>&lt;blockquote&gt;Dear Valued Customer,&lt;br /&gt;We are pleased to announce the go-live date for a new Data Center, scheduled to go live on April 19, 2010. &lt;br /&gt;Please update your firewall rules to allow SMTP traffic on port 25 from the following IP address ranges:xxx.xxx.xxx.xxx/xx (xxx.xxx.xxx.xxx - xxx.xxx.xxx.xxx)xx.xxx.xxx.xx/xx (xx.xxx.xxx.xx - xx.xxx.xxx.xxx)&lt;/blockquote&gt;&lt;a href="http://infoworld.com/print/115086"&gt;http://infoworld.com/print/115086&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-5857144825201627633?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/5857144825201627633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/fraudsters-target-it-workers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5857144825201627633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5857144825201627633'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/03/fraudsters-target-it-workers.html' title='Fraudsters target IT Workers'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-2804649650752041376</id><published>2010-02-28T23:57:00.000-08:00</published><updated>2010-02-28T23:57:52.882-08:00</updated><title type='text'>How to avoid rogue security software</title><content type='html'>&lt;blockquote&gt;What can you do to help prevent the spread of rogues and make sure that rogue software vendors stop profiting from their unscrupulous business? Follow these tips below to tell what's real and what's not when it comes to security software – and share them with friends and family who may be vulnerable to rogue threats.&lt;br /&gt;&lt;br /&gt;1. Do not fall for scare tactics.&lt;br /&gt;&lt;br /&gt;2. Use security software with real-time protection and keep it up-to-date.&lt;br /&gt;&lt;br /&gt;3. Access experts at security forums and ask about the software you are considering before you decide to purchase it.&lt;br /&gt;&lt;br /&gt;4. Read the software reviews at reputable sites like Download.com. Do not blindly trust individual sites offering security products.&lt;br /&gt;&lt;br /&gt;5. Ask knowledgeable friends and family members about quality software they use.&lt;br /&gt;6. Practice online skepticism.&lt;/blockquote&gt;&lt;a href="http://www.net-security.org/malware_news.php?id=1245"&gt;http://www.net-security.org/malware_news.php?id=1245&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-2804649650752041376?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/2804649650752041376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/how-to-avoid-rogue-security-software.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2804649650752041376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2804649650752041376'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/how-to-avoid-rogue-security-software.html' title='How to avoid rogue security software'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-7499119652685290012</id><published>2010-02-28T23:51:00.000-08:00</published><updated>2010-02-28T23:51:12.995-08:00</updated><title type='text'>Defense in Depth Protecting your Netowrk for Internal Attacks</title><content type='html'>&lt;blockquote&gt;...some tips on how to stop someone from exploiting vulnerabilities in your network by turning on some simple security features in your switches. Most people don’t know that the switches in their network can give a solid defense against several attack vectors. This article will focus on how just a few lines of configuration can harden your network to prevent the following attacks:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;DHCP starvation&lt;/li&gt;&lt;li&gt;Rogue DHCP servers&lt;/li&gt;&lt;li&gt;Client side exploitation&lt;/li&gt;&lt;li&gt;ARP spoofing&lt;/li&gt;&lt;li&gt;ARP poison routing&lt;/li&gt;&lt;li&gt;VLAN hopping&lt;/li&gt;&lt;li&gt;MAC address flooding&lt;/li&gt;&lt;li&gt;Connection of Rouge devices&lt;/li&gt;&lt;/ul&gt;This article illustrates configuration on products from Cisco Systems, which are most likely&lt;br /&gt;already in use in your network. If you aren’t using Cisco products consult your vendor’s&lt;br /&gt;literature to see if the equivalent commands/protections are available. &lt;/blockquote&gt;&lt;a href="http://pauldotcom.com/Defense%20in%20Depth%20Protecting%20your%20Netowrk%20for%20Internal%20Attacks.pdf"&gt;http://pauldotcom.com/Defense%20in%20Depth%20Protecting%20your%20Netowrk%20for%20Internal%20Attacks.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-7499119652685290012?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/7499119652685290012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/defense-in-depth-protecting-your.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7499119652685290012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7499119652685290012'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/defense-in-depth-protecting-your.html' title='Defense in Depth Protecting your Netowrk for Internal Attacks'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-5610865408163904078</id><published>2010-02-28T23:09:00.000-08:00</published><updated>2010-02-28T23:09:17.797-08:00</updated><title type='text'>A Guide to XSS</title><content type='html'>&lt;blockquote&gt;XSS is Cross Site Scripting. If you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to mitigate XSS vectors or how to write the actual cookie/credential stealing/replay/session riding portion of the attack. It will simply show the underlying methodology and you can infer the rest. Also, please note my XSS page has been replicated by the OWASP 2.0 Guide in the Appendix section with my permission. &lt;/blockquote&gt;&lt;a href="http://ha.ckers.org/xss.html"&gt;http://ha.ckers.org/xss.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-5610865408163904078?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/5610865408163904078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/guide-to-xss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5610865408163904078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5610865408163904078'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/guide-to-xss.html' title='A Guide to XSS'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1483970755999454999</id><published>2010-02-26T08:35:00.001-08:00</published><updated>2010-02-26T08:35:28.720-08:00</updated><title type='text'>Hitler and Cloud Computing Security</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/VjfaCoA2sQk&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/VjfaCoA2sQk&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1483970755999454999?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1483970755999454999/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/hitler-and-cloud-computing-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1483970755999454999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1483970755999454999'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/hitler-and-cloud-computing-security.html' title='Hitler and Cloud Computing Security'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-3793730133028533806</id><published>2010-02-23T22:19:00.001-08:00</published><updated>2010-02-23T22:19:53.483-08:00</updated><title type='text'>Police warn of credit card 'skimming' at gas stations</title><content type='html'>&lt;blockquote&gt;Utah police investigators said crooks have installed electronic "skimming" devices at 180 gas stations from Salt Lake to Provo in an attempt to steal bank card and pin numbers. &lt;br /&gt;&lt;br /&gt;“The skimming device is actually located inside the gas pump,” said Sandy Police Sgt. Troy Arnold, who estimated that hundreds of people used the pay-at-the-pump device at the 7-11 store located at 2185 East 9400 South in Sandy without knowing crooks had installed an electronic device inside pump. The “Skimmer” copied card and pin numbers giving the criminals free access to the victim’s bank accounts. “What they were able to do is to place a secondary pin pad inside this gas pump,” said Arnold. &lt;/blockquote&gt;&lt;a href="http://www.abc4.com/content/news/tagr/story/Police-warn-of-credit-card-skimming-at-gas/se4lev5CkkaTEsYIL57Uxw.cspx"&gt;http://www.abc4.com/content/news/tagr/story/Police-warn-of-credit-card-skimming-at-gas/se4lev5CkkaTEsYIL57Uxw.cspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-3793730133028533806?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/3793730133028533806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/police-warn-of-credit-card-skimming-at.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3793730133028533806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3793730133028533806'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/police-warn-of-credit-card-skimming-at.html' title='Police warn of credit card &apos;skimming&apos; at gas stations'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-911948332084314018</id><published>2010-02-23T21:53:00.000-08:00</published><updated>2010-02-23T21:53:42.831-08:00</updated><title type='text'>Intel Also The Target In Cyber Attacks</title><content type='html'>&lt;blockquote&gt;Intel this week said it was the victim of a sophisticated cyberattack that occurred in January around the same time cybercriminals compromised systems at Google, Adobe and more than 30 other large companies.&lt;/blockquote&gt;&lt;a href="http://www.scmagazineus.com/intel-the-victim-of-sophisticated-cyberattack/article/164382/"&gt;http://www.scmagazineus.com/intel-the-victim-of-sophisticated-cyberattack/article/164382/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-911948332084314018?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/911948332084314018/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/intel-also-target-in-cyber-attacks.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/911948332084314018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/911948332084314018'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/intel-also-target-in-cyber-attacks.html' title='Intel Also The Target In Cyber Attacks'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-5833880351308804742</id><published>2010-02-23T21:36:00.000-08:00</published><updated>2010-02-23T21:36:58.219-08:00</updated><title type='text'>VirusTotal.com</title><content type='html'>Have a suspicious file download and like to scan it before you download it?&lt;br /&gt;&lt;br /&gt;Check out &lt;a href="http://virustotal.com/"&gt;VirusTotal.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;The VirusTotal.com Web site offers a free but invaluable security service. It will scan any Web download, e-mail attachment or other file you send it with 40-odd different antivirus scanners to let you know whether it's safe for your computer. The free VirusTotal Uploader utility makes sending a file to the site a breeze by adding a new right-click option for any file. &lt;/blockquote&gt;&lt;a href="http://www.pcworld.com/article/189826/Virustotal_Uploader.html?tk=rss_reviews"&gt;http://www.pcworld.com/article/189826/Virustotal_Uploader.html?tk=rss_reviews&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-5833880351308804742?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/5833880351308804742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/virustotalcom.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5833880351308804742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5833880351308804742'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/virustotalcom.html' title='VirusTotal.com'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-3072381037734823832</id><published>2010-02-23T21:26:00.000-08:00</published><updated>2010-02-23T21:26:52.055-08:00</updated><title type='text'>How SQL Injection vulnerabilities work</title><content type='html'>In discussing how to prevent SQL injection attacks, Paul Rubens does a good job explaining how an SQL injection attack is performed in layman's terms.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.enterprisenetworkingplanet.com/_featured/article.php/3866756/10+Ways+to+Prevent+or+Mitigate+SQL+Injection+Attacks.htm"&gt;http://www.enterprisenetworkingplanet.com/_featured/article.php/3866756/10+Ways+to+Prevent+or+Mitigate+SQL+Injection+Attacks.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-3072381037734823832?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/3072381037734823832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/how-sql-injection-vulnerabilities-work.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3072381037734823832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3072381037734823832'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/how-sql-injection-vulnerabilities-work.html' title='How SQL Injection vulnerabilities work'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-7779264172073901455</id><published>2010-02-22T07:36:00.000-08:00</published><updated>2010-02-22T07:36:35.005-08:00</updated><title type='text'>New Report Examines Malware's Origins, Motivations</title><content type='html'>&lt;blockquote&gt;Nearly every day, industry analysts and security researchers warn IT professionals about the skyrocketing proliferation of malware. A simple Web search turns up many reports that dissect the technical nature of malicious software, how it works, and how it affects its victims. &lt;/blockquote&gt;&lt;blockquote&gt; But who develops malware, and who distributes it? Who buys it, and what do they hope to achieve? Ask these questions in a Web search, and you'll find far fewer results. &lt;/blockquote&gt;&lt;blockquote&gt; In a report issued last week, ScanSafe security researcher Mary Landesman offers some thoughts on the genesis and spread of malware -- this time from a business perspective, rather than a technical point of view. While Landesman's report -- part of ScanSafe's "Annual Global Threat Report" -- is far from the first to offer insight on the business of malware, it does offer a snapshot of the current state of the malware business and a clear categorization of the players. &lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=222900593"&gt;http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=222900593&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-7779264172073901455?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/7779264172073901455/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/new-report-examines-malwares-origins.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7779264172073901455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7779264172073901455'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/new-report-examines-malwares-origins.html' title='New Report Examines Malware&apos;s Origins, Motivations'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-4136181075700399572</id><published>2010-02-22T05:44:00.000-08:00</published><updated>2010-02-22T05:44:15.600-08:00</updated><title type='text'>Got Bluescreen? Check for Rootkits</title><content type='html'>&lt;blockquote&gt;Microsoft confirmed today that the recent spate of Windows XP crashes and blue-screens experienced by people who installed this month’s batch of security updates were found mainly on systems that were already infected with a rootkit, a tool designed to hide malware infestations on host computers. &lt;/blockquote&gt;&lt;a href="http://www.krebsonsecurity.com/2010/02/microsoft-got-bluescreen-check-for-rootkits/"&gt;http://www.krebsonsecurity.com/2010/02/microsoft-got-bluescreen-check-for-rootkits/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-4136181075700399572?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/4136181075700399572/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/got-bluescreen-check-for-rootkits.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4136181075700399572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4136181075700399572'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/got-bluescreen-check-for-rootkits.html' title='Got Bluescreen? Check for Rootkits'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-8838107323321754611</id><published>2010-02-22T02:45:00.000-08:00</published><updated>2010-02-22T02:45:12.339-08:00</updated><title type='text'>Irate parents in Pa. say schools use 'peeping tom technology'</title><content type='html'>Irate indeed... &lt;br /&gt;&lt;blockquote&gt;According to the original complaint, Robbins was accused by a Harriton High School assistant principal of "improper behavior in his home" and shown a photograph taken by his laptop as evidence. In an appearance on CBS' "Early Show Saturday Edition," Robbins said he was accused by the assistant principal of selling drugs and taking pills, but he claimed the pictures taken by his MacBook's camera showed him eating candy. &lt;/blockquote&gt;&lt;a href="http://www.networkworld.com/news/2010/022110-irate-parents-in-pa-say.html"&gt;http://www.networkworld.com/news/2010/022110-irate-parents-in-pa-say.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-8838107323321754611?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/8838107323321754611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/irate-parents-in-pa-say-schools-use.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8838107323321754611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8838107323321754611'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/irate-parents-in-pa-say-schools-use.html' title='Irate parents in Pa. say schools use &apos;peeping tom technology&apos;'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-4044353522326177</id><published>2010-02-22T01:24:00.001-08:00</published><updated>2010-02-22T01:24:31.822-08:00</updated><title type='text'>Experimenting with VLAN hopping</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;Most network engineers have been told at one point or another never to use VLAN 1 for user access. The motivation behind this warning is the result of fear concerning VLAN hopping attacks, wherein an attacker can send packets with a specially-crafted 802.1Q header(s) to "hop" from one VLAN to another. This theory relies on the assumption that a switch will happily forward 802.1Q-tagged frames ingressing an access port.&lt;/blockquote&gt;&lt;a href="http://packetlife.net/blog/2010/feb/22/experimenting-vlan-hopping/"&gt;http://packetlife.net/blog/2010/feb/22/experimenting-vlan-hopping/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-4044353522326177?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/4044353522326177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/experimenting-with-vlan-hopping.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4044353522326177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4044353522326177'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/experimenting-with-vlan-hopping.html' title='Experimenting with VLAN hopping'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-2521438634646065602</id><published>2010-02-22T01:15:00.000-08:00</published><updated>2010-02-22T01:15:21.902-08:00</updated><title type='text'>Two Chinese schools implicated in Google Aurora attacks</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;Two Chinese schools with links to the armed forces have become implicated as suspects in the ongoing Operations Aurora attacks against Google and at least 33 other western conglomerates last December.&lt;br /&gt;&lt;br /&gt;Security experts, including investigators from the National Security Agency, now reckon the attacks date from April last year, far earlier than previously suspected, the New York Times reports. Although the attacks originated from China, it's by no means clear that they were orchestrated by the Chinese government. It's even possible that hackers from outside China ran, or had an involvement in, at least some of the attacks.&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2010/02/19/aurora_china_probe_latest/"&gt;http://www.theregister.co.uk/2010/02/19/aurora_china_probe_latest/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-2521438634646065602?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/2521438634646065602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/two-chinese-schools-implicated-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2521438634646065602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2521438634646065602'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/two-chinese-schools-implicated-in.html' title='Two Chinese schools implicated in Google Aurora attacks'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1967919873169906145</id><published>2010-02-15T21:50:00.001-08:00</published><updated>2010-02-15T21:50:58.742-08:00</updated><title type='text'>The Four Myths Of Cyber Security</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;Governments and corporations around the globe are facing a crisis in the form of cyber security threats. Incidents and exploits crafted by an effective and growing menace are threatening the continuity of, and confidence in, the very core of our commercial and social infrastructure. In just 90 criminal investigations performed in 2008, where data compromise was confirmed, the Verizon Business RISK team (a leading computer forensics group) reported more than 285 million consumer credit records stolen. This number far exceeds the combined total confirmed for all their investigations from 2004 to 2007.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.net-security.org/article.php?id=1377"&gt;http://www.net-security.org/article.php?id=1377&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1967919873169906145?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1967919873169906145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/four-myths-of-cyber-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1967919873169906145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1967919873169906145'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/four-myths-of-cyber-security.html' title='The Four Myths Of Cyber Security'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1190898004006527054</id><published>2010-02-15T21:23:00.001-08:00</published><updated>2010-02-15T21:23:41.505-08:00</updated><title type='text'>New Russian Botnet Tries to Kill Rival</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;An upstart Trojan horse program has decided to take on its much-larger rival by stealing data and then removing the malicious program from infected computers.&lt;br /&gt;&lt;br /&gt;Security researchers say that the relatively unknown Spy Eye toolkit added this functionality just a few days ago in a bid to displace its larger rival, known as Zeus. &lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://news.yahoo.com/s/pcworld/20100210/tc_pcworld/newrussianbotnettriestokillrival"&gt;http://news.yahoo.com/s/pcworld/20100210/tc_pcworld/newrussianbotnettriestokillrival&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1190898004006527054?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1190898004006527054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/new-russian-botnet-tries-to-kill-rival.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1190898004006527054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1190898004006527054'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/new-russian-botnet-tries-to-kill-rival.html' title='New Russian Botnet Tries to Kill Rival'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-8295512944812474531</id><published>2010-02-15T20:18:00.001-08:00</published><updated>2010-02-15T20:18:43.141-08:00</updated><title type='text'>Einstein 2: U.S. government's 'enlightening' new cybersecurity weapon</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;The Department of Homeland Security is detecting new patterns of cyberattacks from foreign adversaries -- some targeted at particular agencies and others aimed at the entire U.S. government -- due to to special-purpose intrusion-detection systems that will be widely deployed in federal networks during 2010. &lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.networkworld.com/news/2010/021110-cybersecurity-einstein-2.html"&gt;http://www.networkworld.com/news/2010/021110-cybersecurity-einstein-2.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-8295512944812474531?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/8295512944812474531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/einstein-2-us-governments-enlightening.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8295512944812474531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8295512944812474531'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/einstein-2-us-governments-enlightening.html' title='Einstein 2: U.S. government&apos;s &apos;enlightening&apos; new cybersecurity weapon'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1467317645849972028</id><published>2010-02-15T20:01:00.000-08:00</published><updated>2010-02-15T20:01:53.398-08:00</updated><title type='text'>A Stick Figure Guide to the Advanced Encryption Standard (AES)</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_fsZeL9b0iok/S3oYqYwuMEI/AAAAAAAABKk/XIFK-b8WlN8/s1600-h/aes_act_1_scene_01_intro_576.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_fsZeL9b0iok/S3oYqYwuMEI/AAAAAAAABKk/XIFK-b8WlN8/s320/aes_act_1_scene_01_intro_576.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.moserware.com/2009/09/stick-figure-guide-to-advanced.html"&gt;http://www.moserware.com/2009/09/stick-figure-guide-to-advanced.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1467317645849972028?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1467317645849972028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/stick-figure-guide-to-advanced.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1467317645849972028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1467317645849972028'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/stick-figure-guide-to-advanced.html' title='A Stick Figure Guide to the Advanced Encryption Standard (AES)'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fsZeL9b0iok/S3oYqYwuMEI/AAAAAAAABKk/XIFK-b8WlN8/s72-c/aes_act_1_scene_01_intro_576.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-3454154842946709861</id><published>2010-02-15T19:25:00.000-08:00</published><updated>2010-02-15T19:25:33.239-08:00</updated><title type='text'>Mandatory certification &amp; licensing for IA professionals</title><content type='html'>I would only be interested in this certification if, upon receipt, it allows also licenses me to carry EMP weapons. I see no mention of EMP Weapons in the article, therefore, I do not support it.&lt;br /&gt;&lt;blockquote&gt;On April Fool's Day 2009, senators John D. "Jay" Rockefeller (D-W.V.) and Olympia Snow (R-Maine)&amp;gt; introduced Senate Bill 773, "A bill to ensure the continued free flow of commerce within the United States and with its global trading partners through secure cyber communications, to provide for the continued development and exploitation of the Internet and intranet communications for such purposes, to provide for the development of a cadre of information technology specialists to improve and maintain effective cybersecurity defenses against disruption, and for other purposes." The bill's short title is the "Cybersecurity Act of 2009."&amp;nbsp; &lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.networkworld.com/news/2010/021510-mandatory-certification.html"&gt;http://www.networkworld.com/news/2010/021510-mandatory-certification.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-3454154842946709861?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/3454154842946709861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/mandatory-certification-licensing-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3454154842946709861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3454154842946709861'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/mandatory-certification-licensing-for.html' title='Mandatory certification &amp; licensing for IA professionals'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1387887521000110321</id><published>2010-02-15T19:18:00.001-08:00</published><updated>2010-02-15T19:18:40.872-08:00</updated><title type='text'>China leads the world in hacked computers, McAfee study says</title><content type='html'>&lt;blockquote&gt;&lt;pre&gt;More private computers were commandeered by hackers for malicious &lt;br /&gt;purposes in China in the last quarter of 2009 than in any other country, &lt;br /&gt;including the United States, according to a new study by an Internet &lt;br /&gt;security company.&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.infosecnews.org/pipermail/isn/2010-February/018769.html"&gt;http://www.infosecnews.org/pipermail/isn/2010-February/018769.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1387887521000110321?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1387887521000110321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/china-leads-world-in-hacked-computers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1387887521000110321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1387887521000110321'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/china-leads-world-in-hacked-computers.html' title='China leads the world in hacked computers, McAfee study says'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-5570881984808574283</id><published>2010-02-15T02:41:00.001-08:00</published><updated>2010-02-15T02:41:49.893-08:00</updated><title type='text'>Security budget woes? Grab your management's attention!</title><content type='html'>&lt;blockquote&gt;A few years ago, I was called in by the CSO of a Fortune 25 company. He hired 4 of the best known companies that do penetration testing to find problems with their corporate network. All 4 companies came back two weeks and $100,000 later, and told the CEO that they had full control of his network. The CSO went immediately to the CEO, who basically replied, "I don't care."&lt;br /&gt;&lt;br /&gt;The CSO then hired me to perform an espionage simulation. I came back within one week, and handed the CSO their mergers and acquisitions plans, their new technologies that were being released in three years, multi-billion dollar proposals, pictures showing how I bugged the CEO's office, and told him that I had full control of their entire network. The next week, the CEO raised the security budget by $10,000,000 and they hired security managers for all business units.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.computerworld.com/s/article/9154918/Security_budget_woes_Grab_your_management_s_attention?taxonomyId=17"&gt;http://www.computerworld.com/s/article/9154918/Security_budget_woes_Grab_your_management_s_attention?taxonomyId=17&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-5570881984808574283?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/5570881984808574283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/security-budget-woes-grab-your.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5570881984808574283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/5570881984808574283'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/security-budget-woes-grab-your.html' title='Security budget woes? Grab your management&apos;s attention!'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-8464827966405409629</id><published>2010-02-15T02:15:00.000-08:00</published><updated>2010-02-15T02:15:24.448-08:00</updated><title type='text'>Twelve Principles of DoD Cyber Conflict</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;This article provides firsthand observations on twelve key principles of Computer Network Operations (CNO). I believe these observations can provide other CNO practitioners with a critical foundation required for successful CNO. These principles will also be of use to officers who whish to engage in the ongoing national security and policy discussions concerning CNO. After further examination and feedback from the field and the fleet, we expect them to become cornerstones of a new joint doctrine for CNO. Until then, I offer, Twelve Principles of CNO.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://smartdatacollective.com/Home/24933"&gt;http://smartdatacollective.com/Home/24933&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-8464827966405409629?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/8464827966405409629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/twelve-principles-of-dod-cyber-conflict.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8464827966405409629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8464827966405409629'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/twelve-principles-of-dod-cyber-conflict.html' title='Twelve Principles of DoD Cyber Conflict'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-8010404831178594980</id><published>2010-02-08T20:45:00.000-08:00</published><updated>2010-02-08T20:45:47.665-08:00</updated><title type='text'>A look at Sandia National Labs’ Threat Analysis Model and why it won’t work</title><content type='html'>&lt;blockquote&gt;&amp;nbsp;Today I’ll be taking an in depth look at an integral part of the National SCADA Test Bed -&amp;nbsp; Sandia’s Threat Analysis model – and its reliance on a flawed OSINT methodology. &lt;br /&gt;Sandia National Labs, in an ongoing effort to protect U.S. critical infrastructure from physical and network attacks, has developed a Threat Analysis Framework comprised of 5 elements:&lt;br /&gt;&lt;blockquote&gt;&lt;ol&gt;&lt;li&gt;the identification of an adversary&lt;/li&gt;&lt;li&gt;the development of generic threat profiles&lt;/li&gt;&lt;li&gt;the identification of generic attack paths&lt;/li&gt;&lt;li&gt;the discovery of adversary intent&lt;/li&gt;&lt;li&gt;the identification of mitigation strategies&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;Sandia researcher David Duggan and his colleagues, who are responsible for developing this tool, recognized the limitations of classified threat data (i.e., a very slow process to get it to the people who need it) and chose to develop an unclassified threat analysis framework instead. Duggan’s report “&lt;a href="http://www.oe.energy.gov/DocumentsandMedia/15-Threat_Analysis_Framework.pdf" onclick="javascript:pageTracker._trackPageview ('/outbound/www.oe.energy.gov');"&gt;Threat Analysis Framework&lt;/a&gt;” is available for public release and should be read if you want a full understanding of this model.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://intelfusion.net/wordpress/2010/02/03/a-look-at-sandia-national-labs-threat-analysis-model/"&gt;http://intelfusion.net/wordpress/2010/02/03/a-look-at-sandia-national-labs-threat-analysis-model/&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-8010404831178594980?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/8010404831178594980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/look-at-sandia-national-labs-threat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8010404831178594980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/8010404831178594980'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/look-at-sandia-national-labs-threat.html' title='A look at Sandia National Labs’ Threat Analysis Model and why it won’t work'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-4053638634073950291</id><published>2010-02-08T18:53:00.000-08:00</published><updated>2010-02-08T18:53:37.568-08:00</updated><title type='text'>National Data Privacy Day</title><content type='html'>I missed it this year, but it's on my calendar for next year! &lt;br /&gt;&lt;blockquote&gt;Data Privacy Day's educational initiative has focused on raising awareness among teens and young adults about the importance of protecting the privacy of their personal information online, particularly in the context of social networking. In addition to its educational initiative, Data Privacy Day promotes events and activities that stimulate the development of technology tools that promote individual control over personally identifiable information; encourage compliance with privacy laws and regulations; and create dialogues among stakeholders interested in advancing data protection and privacy. The international celebration offers many opportunities for collaboration among governments, industry, academia, nonprofits, privacy professionals and educators.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Data_Privacy_Day"&gt;http://en.wikipedia.org/wiki/Data_Privacy_Day&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-4053638634073950291?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/4053638634073950291/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/national-data-privacy-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4053638634073950291'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4053638634073950291'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/national-data-privacy-day.html' title='National Data Privacy Day'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1276914816701478143</id><published>2010-02-07T23:16:00.000-08:00</published><updated>2010-02-07T23:16:02.947-08:00</updated><title type='text'>Cisco's Backdoor For Hackers</title><content type='html'>&lt;blockquote&gt;Activists have long grumbled about the privacy implications of the legal "backdoors" that networking companies like Cisco build into their equipment--functions that let law enforcement quietly track the Internet activities of criminal suspects. Now an IBM researcher has revealed a more serious problem with those backdoors: They don't have particularly strong locks, and consumers are at risk.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.forbes.com/2010/02/03/hackers-networking-equipment-technology-security-cisco.html"&gt;http://www.forbes.com/2010/02/03/hackers-networking-equipment-technology-security-cisco.html&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1276914816701478143?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1276914816701478143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/ciscos-backdoor-for-hackers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1276914816701478143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1276914816701478143'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/ciscos-backdoor-for-hackers.html' title='Cisco&apos;s Backdoor For Hackers'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-3776160000928709159</id><published>2010-02-07T21:49:00.000-08:00</published><updated>2010-02-07T21:49:36.798-08:00</updated><title type='text'>Introduction to Reverse Engineering Software</title><content type='html'>&lt;a href="http://www.acm.uiuc.edu/sigmil/RevEng/"&gt;&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;This book is an attempt to provide an introduction to reverse    engineering software under both Linux and Microsoft Windows�.        The goal of this book is not to cover how to reproduce        an entire program from a binary, but instead how to use       the Scientific Method to deduce specific behavior and to target,       analyze, extract and modify specific operations of a program, usually       for interoperability purposes. As such, the book takes a top-down       approach, starting at the highest level (program behavior) and        drilling down to assembly when it is needed.&lt;/blockquote&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.acm.uiuc.edu/sigmil/RevEng/"&gt;http://www.acm.uiuc.edu/sigmil/RevEng/&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-3776160000928709159?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/3776160000928709159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/introduction-to-reverse-engineering.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3776160000928709159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/3776160000928709159'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/introduction-to-reverse-engineering.html' title='Introduction to Reverse Engineering Software'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1068715365591387502</id><published>2010-02-07T21:19:00.000-08:00</published><updated>2010-02-07T21:19:41.715-08:00</updated><title type='text'>Extracting a 3DES key from an IBM 4758</title><content type='html'>&amp;nbsp;A classic example of Cat-And-Mouse Security...&lt;br /&gt;&lt;blockquote&gt;The arrival of multi-user operating systems in the 1960s showed that it was extremely difficult to process sensitive data on a computer and protect it from other programs running on the same computer. The operating systems were meant to provide protection, but in practice there were bugs and design limitations that meant that cryptographic keys and personal identification numbers (PINs) were always at risk. This led to the development of standalone "security modules" such as the IBM 3848 and the VISA security module. These were basically just microprocessors in robust metal enclosures. When you opened the lid the power supply was disabled and they "forgot" their sensitive information.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.cl.cam.ac.uk/%7Ernc1/descrack/ibm4758.html"&gt;http://www.cl.cam.ac.uk/~rnc1/descrack/ibm4758.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1068715365591387502?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1068715365591387502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/extracting-3des-key-from-ibm-4758.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1068715365591387502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1068715365591387502'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/extracting-3des-key-from-ibm-4758.html' title='Extracting a 3DES key from an IBM 4758'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-1140842620712244377</id><published>2010-02-07T20:33:00.000-08:00</published><updated>2010-02-07T20:33:23.900-08:00</updated><title type='text'>Cybersecurity Enhancement Act passed by U.S. House</title><content type='html'>&lt;blockquote&gt;The act would authorize up to $396 million over the next four years to fund cybersecurity research and $94 million over that period to provide scholarships.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://feedproxy.google.com/%7Er/SCMagazineHome/%7E3/GFkUTyds47k/"&gt;Cybersecurity Enhancement Act passed by U.S. House&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-1140842620712244377?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/1140842620712244377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/cybersecurity-enhancement-act-passed-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1140842620712244377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/1140842620712244377'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/cybersecurity-enhancement-act-passed-by.html' title='Cybersecurity Enhancement Act passed by U.S. House'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-560765520152996031</id><published>2010-02-07T20:32:00.000-08:00</published><updated>2010-02-07T20:32:26.550-08:00</updated><title type='text'>Pentagon seeks billions to battle terror abroad     (AP) (Yahoo Security)</title><content type='html'>&lt;a href="http://us.rd.yahoo.com/dailynews/rss/security/*http://news.yahoo.com/s/ap/20100204/ap_on_go_ca_st_pe/us_terror_fight_spending"&gt;Pentagon seeks billions to battle terror abroad     (AP) (Yahoo Security)&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-560765520152996031?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://us.rd.yahoo.com/dailynews/rss/security/*http://news.yahoo.com/s/ap/20100204/ap_on_go_ca_st_pe/us_terror_fight_spending' title='Pentagon seeks billions to battle terror abroad     (AP) (Yahoo Security)'/><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/560765520152996031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/pentagon-seeks-billions-to-battle.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/560765520152996031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/560765520152996031'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/pentagon-seeks-billions-to-battle.html' title='Pentagon seeks billions to battle terror abroad     (AP) (Yahoo Security)'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-2660961035266213042</id><published>2010-02-07T20:30:00.000-08:00</published><updated>2010-02-07T20:30:41.966-08:00</updated><title type='text'>RIPE plays with 1.1.1.1 and 1.2.3.4 following APNIC allocation</title><content type='html'>&lt;blockquote&gt;Last month, IANA &lt;a href="http://www.iana.org/assignments/ipv4-address-space/"&gt;allocated&lt;/a&gt; the 1.0.0.0/8 and 27.0.0.0/8 networks to &lt;a href="http://www.apnic.net/"&gt;APNIC&lt;/a&gt; (the &lt;a href="http://en.wikipedia.org/wiki/Regional%20Internet%20registry"&gt;Internet registry&lt;/a&gt; for the Asia-Pacific region), pushing the total IPv4 address space utilization &lt;a href="http://arstechnica.com/tech-policy/news/2010/01/90-of-ipv4-address-space-used-ipv6-move-looking-messy.ars"&gt;above the ominous 90% mark&lt;/a&gt;. Passing this benchmark should not come as a surprise to anyone, given the painfully slow adoption of IPv6. But what's interesting about the first range in particular is the amount of junk traffic already present.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://packetlife.net/blog/2010/feb/5/ripe-plays-with-1-0-0-0-network-apnic-allocation/"&gt;RIPE plays with 1.1.1.1 and 1.2.3.4 following APNIC allocation&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-2660961035266213042?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/2660961035266213042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/ripe-plays-with-1111-and-1234-following.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2660961035266213042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/2660961035266213042'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/ripe-plays-with-1111-and-1234-following.html' title='RIPE plays with 1.1.1.1 and 1.2.3.4 following APNIC allocation'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-4518186384521762298</id><published>2010-02-07T20:25:00.000-08:00</published><updated>2010-02-07T20:25:43.334-08:00</updated><title type='text'>Microsoft to deliver 13 security patches for 26 bugs</title><content type='html'>&lt;blockquote&gt;After a relatively quiet January, administrators next week will have to deal with an unusually large security update from Microsoft, with 26 vulnerabilities in line for fixing.&lt;/blockquote&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://feedproxy.google.com/%7Er/SCMagazineHome/%7E3/-pvsPORwr8k/"&gt;Microsoft to deliver 13 security patches for 26 bugs&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-4518186384521762298?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/4518186384521762298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/microsoft-to-deliver-13-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4518186384521762298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/4518186384521762298'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/microsoft-to-deliver-13-security.html' title='Microsoft to deliver 13 security patches for 26 bugs'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-7210942726019465776</id><published>2010-02-07T20:22:00.000-08:00</published><updated>2010-02-15T02:44:07.927-08:00</updated><title type='text'>Mozilla confirms infected Firefox add-ons slipped through security</title><content type='html'>&lt;blockquote&gt;Mozilla confirmed that it had failed to detect malware in a pair of Firefox add-ons, which may have infected up to 4,600 users.&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://www.networkworld.com/news/2010/020510-mozilla-confirms-infected-firefox-add-ons.html"&gt;Mozilla confirms infected Firefox add-ons slipped through security&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2010-02-15 Update:&lt;br /&gt;&lt;a href="http://www.computerworld.com/s/article/9155158/Mozilla_retracts_Firefox_add_on_malware_claim?taxonomyId=17"&gt;Mozilla retracts Firefox add-on malware claim&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-7210942726019465776?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/7210942726019465776/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/mozilla-confirms-infected-firefox-add.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7210942726019465776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/7210942726019465776'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/mozilla-confirms-infected-firefox-add.html' title='Mozilla confirms infected Firefox add-ons slipped through security'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2763509086404094443.post-602047791565944696</id><published>2010-02-07T20:06:00.000-08:00</published><updated>2010-02-07T20:06:55.460-08:00</updated><title type='text'>Can you trust Chinese computer equipment?</title><content type='html'>&lt;blockquote&gt;"If I were in charge of any enterprise where I thought I had any reason to think that these Chinese authorities might be interested in what I was doing, I'd stop buying Chinese computer products today. Until this issue of Chinese cyber-espionage has been cleared up and cleaned up, I simply couldn't justify buying or using hardware that might be working against me,"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.net-security.org/secworld.php?id=8837"&gt;http://www.net-security.org/secworld.php?id=8837&lt;/a&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2763509086404094443-602047791565944696?l=julians-infosec-blog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://feedproxy.google.com/~r/HelpNetSecurity/~3/WLeTfj_NTBU/secworld.php' title='Can you trust Chinese computer equipment?'/><link rel='replies' type='application/atom+xml' href='http://julians-infosec-blog.blogspot.com/feeds/602047791565944696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/can-you-trust-chinese-computer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/602047791565944696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2763509086404094443/posts/default/602047791565944696'/><link rel='alternate' type='text/html' href='http://julians-infosec-blog.blogspot.com/2010/02/can-you-trust-chinese-computer.html' title='Can you trust Chinese computer equipment?'/><author><name>Julian Tosh</name><uri>http://www.blogger.com/profile/10341236933540913756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
