<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Applications</title>
	<atom:link href="http://infosec3t.com/category/applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>Will your Cloud Provider be around in two years?</title>
		<link>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/</link>
		<comments>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/#comments</comments>
		<pubDate>Sun, 12 Sep 2010 15:45:33 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2361</guid>
		<description><![CDATA[I just read that my hosting company, GoDaddy, is on the auction block to be sold to the highest bidder. Naturally, I&#8217;m thinking of how this change of ownership could adversely affect the service of my web sites, blogs, and virtual servers.  One never really knows until the new owners take over. Maybe they clean [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/09/Cloud.jpg"><img class="alignright size-full wp-image-2365" title="Cloud" src="http://infosec3t.com/wp-content/uploads/2010/09/Cloud.jpg" alt="" width="175" height="175" /></a>I just read that my hosting company, GoDaddy, is on the auction block to be sold to the highest bidder. Naturally, I&#8217;m thinking of how this change of ownership could adversely affect the service of my web sites, blogs, and virtual servers.  One never really knows until the new owners take over. Maybe they clean house and things change for the better. Or they may look to cut costs and things could take a downward turn. Migrating to a another service would a pain but I could do it if needed.</p>
<p>This brings to mind the current state of the <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> market. The mad gold rush of cloud services providers continues. Everyone wants a piece of the action.  These companies offer a variety of hosting services for IT infrastructure, platforms and applications.  The lure of moving to the cloud is obvious. Let someone else do it better, cheaper, more reliably and worry about the  details. More organizations are taking advantage. Companies, large and small, are moving their data, applications, and systems to one or more of the legion of providers out there.  This means more dependence on these providers for accessing business critical resources.  Although there are some obvious leaders in the cloud market today ( <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a>, Amazon, Salesforce), there are also a many smaller boutique providers that compete mostly on price.</p>
<p>In coming years, I expect the market to settle. Some providers will flourish, others will go down in flames or be acquired by one of the larger shops. These changes could have real consequences to customers. What happens if your provider is using proprietary technology and goes out of business?  Migrating to a new provider might be difficult. Doing your due diligence before selecting a provider is very important. Verifying the financial stability of the company and developing a strong service level agreement are key requirements.  Your SLA must address uptime, performance and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>. The ability to audit your provider is also very important.</p>
<p>Many small businesses would not exist without the cloud. Building, hosting, and managing an IT infrastructure can be cost prohibitive. Choosing the right provider, however, may be the difference between success and failure.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/' rel='bookmark' title='The real arguments for Cloud Computing'>The real arguments for Cloud Computing</a> <small>As more vendors dive into the cloud computing market, every...</small></li>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;</title>
		<link>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/</link>
		<comments>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 17:13:22 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2231</guid>
		<description><![CDATA[Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun telling new employees that they are no longer able to request Windows PCs, giving them the choice of Mac or Linux systems. Google has long offered its employees their choice of work operating system but [...]]]></description>
			<content:encoded><![CDATA[<p><em> </em><img class="alignright size-full wp-image-2230" title="microsoft_piss" src="http://infosec3t.com/wp-content/uploads/2010/06/microsoft_piss.jpeg" alt="" width="127" height="114" />Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun  telling new employees that they are no longer able to request <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a>  PCs, giving them the choice of <a href="http://infosec3t.com/tag/mac/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MAC">Mac</a> or <a href="http://infosec3t.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Linux">Linux</a> systems. Google has long  offered its employees their choice of work operating system but will no  longer do so. According to a Google employee, any exceptions will require will require CIO approval. [ <em>I find that assertion questionable though</em> ].</p>
<p>Google is apparently making this decision in response to the hacking attacks on late last year in China. The attackers  used vulnerabilities  in Microsoft&#8217;s <a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a> 6 to go after Google&#8217;s intellectual property, believed to be source code.  One could argue that if they had updated their browsers, the attacker would have had to find other vectors for attacks.</p>
<p>Could this be a strategic move by Google to prove that an Enterprise can survive WITHOUT Microsoft? With Google&#8217;s Chrome OS on the horizon, this may just be the warm-up act.</p>
<p>Source: <a href="http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html" target="_blank">http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
<li><a href='http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/' rel='bookmark' title='Microsoft says Do Not Call for Help!'>Microsoft says Do Not Call for Help!</a> <small>If it sounds like a horror movie&#8230;.well, that&#8217;s because is...</small></li>
<li><a href='http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/' rel='bookmark' title='Use Google Apps or Gmail? Avoid getting hacked!'>Use Google Apps or Gmail? Avoid getting hacked!</a> <small>It can happen to the best of us. Blogger and...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The real arguments for Cloud Computing</title>
		<link>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/</link>
		<comments>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/#comments</comments>
		<pubDate>Thu, 20 May 2010 19:07:11 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2209</guid>
		<description><![CDATA[As more vendors dive into the cloud computing market, every possible claim regarding the supposed benefits of moving to a cloud-based service is being made.  I ran across an article titled &#8221; Why Cloud-based Monitoring is more reliable and secure than Nagios. &#8221; The auth0r, who represented a cloud-based network monitoring company, contended that the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2211" title="cloud-computing" src="http://infosec3t.com/wp-content/uploads/2010/05/zenith-infotech-virtualized-cloud-computing-300x200.jpg" alt="" width="189" height="127" />As more vendors dive into the <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> market, every possible claim regarding the supposed benefits of moving to a cloud-based service is being made.  I ran across an article titled &#8221; Why Cloud-based Monitoring is more reliable and secure than Nagios. &#8221; The auth0r, who represented a cloud-based network monitoring company, contended that the Software-as-a-Service (SaaS) model offered by his company was better for companies than Nagios and other <a href="http://infosec3t.com/tag/open-source/" class="st_tag internal_tag" rel="tag" title="Posts tagged with open source">open source</a> products.</p>
<p>The question is not  Cloud Computing vs. Open Source.  In fact, there are open source SaaS providers like MindTouch out there.  If considering a product like Nagios, a better comparison would be open source vs. commercial.  In many cases, cost is the determining factor for companies to look  to open source technologies. Other considerations include flexibility and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>.</p>
<p>The more relevant  comparison would be hosting and managing a network monitoring system on site vs. moving to a SaaS provider. For many organizations,  IT is considered overhead and not the primary function of the organization. Companies move to the cloud for most of the same reasons companies out-source.  Can someone else do it better for less?  Cost is ually the easier consideration. Companies have to grapple with the &#8216;better&#8217;. Does it mean more security, <a href="http://infosec3t.com/tag/availability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with availability">availability</a>, capacity? Many cloud providers would say &#8216;yes&#8217; to all and then some.  Organizations have to really consider and make that determination themselves. Make a real comparision between their options and not just follow the typical vendor hype.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/' rel='bookmark' title='Exploring Cloud Computing Information Leakage'>Exploring Cloud Computing Information Leakage</a> <small>If you are in cloud computing security (or part of...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee to compensate businesses for buggy update</title>
		<link>http://infosec3t.com/2010/04/29/mcafee-to-compensate-businesses-for-buggy-update/</link>
		<comments>http://infosec3t.com/2010/04/29/mcafee-to-compensate-businesses-for-buggy-update/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 17:02:18 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2128</guid>
		<description><![CDATA[McAfee will provide restitution to businesses hit by a faulty virus definition update that rendered computers unusable, the company has confirmed. &#8220;Enterprise customers will get compensation tailored to each individual customer and will receive a combination including products, services and support,&#8221; a McAfee spokesman told ZDNet UK on Tuesday. The concept of companies paying for damages [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2132" title="cartoon_bug_farewell" src="http://infosec3t.com/wp-content/uploads/2010/04/cartoon_bug_farewell1-300x223.jpg" alt="" width="216" height="161" />McAfee will provide restitution to businesses hit by a faulty virus definition update that rendered computers unusable, the company has confirmed.</p>
<p>&#8220;Enterprise customers will get compensation tailored to each individual customer and will receive a combination including products, services and support,&#8221; a McAfee spokesman told ZDNet UK on Tuesday.</p>
<p>The concept of companies paying for damages caused by buggy <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> has been often discussed. Is this a step in that direction or is McAfee  just doing some good customer management ?</p>
<p>Source: http://www.zdnet.co.uk/<a href="http://infosec3t.com/tag/news/" class="st_tag internal_tag" rel="tag" title="Posts tagged with News">news</a>/<a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>-management/2010/04/27/mcafee-to-compensate-businesses-for-buggy-update-40088779/?s_cid=938</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/' rel='bookmark' title='If Microsoft can do it, why not McAfee?'>If Microsoft can do it, why not McAfee?</a> <small>Yesterday, a faulty McAfee anti-virus update labeled a critical Microsoft...</small></li>
<li><a href='http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/' rel='bookmark' title='SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks'>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</a> <small>Across all industries, small businesses are increasingly facing new threats...</small></li>
<li><a href='http://infosec3t.com/2010/03/23/skipfish-web-scanning-security-tool-from-google/' rel='bookmark' title='Skipfish-Web Scanning Security Tool from Google'>Skipfish-Web Scanning Security Tool from Google</a> <small>Google has released an open-source Web security scanner called Skipfish...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/29/mcafee-to-compensate-businesses-for-buggy-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers crack Ubisoft always-online DRM controls</title>
		<link>http://infosec3t.com/2010/04/28/hackers-crack-ubisoft-always-online-drm-controls/</link>
		<comments>http://infosec3t.com/2010/04/28/hackers-crack-ubisoft-always-online-drm-controls/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 22:10:24 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[DRM]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2121</guid>
		<description><![CDATA[Saw this coming a mile away. Why didn&#8217;t Ubisoft?.. I couldn&#8217;t wait to get my hands on Assassin&#8217;s Creed II. It&#8217;s nice to be able to unwind for an hour or so at night, running across rooftops in 15th Century Venice, leaping on an unsuspecting Templar and burying my dual hidden blades in his neck. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/04/assassins_creed_2_ezio1256262878.jpg"><img class="alignright size-medium wp-image-2122" title="assassins_creed_2_ezio1256262878" src="http://infosec3t.com/wp-content/uploads/2010/04/assassins_creed_2_ezio1256262878-300x241.jpg" alt="" width="300" height="241" /></a>Saw this coming a mile away. Why didn&#8217;t Ubisoft?..</p>
<p>I couldn&#8217;t wait to get my hands on Assassin&#8217;s Creed II. It&#8217;s nice to be able to unwind for an hour or so at night, running across rooftops in 15th Century Venice, leaping on an unsuspecting Templar and burying my dual hidden blades in his neck. Well, it would be nice accept my wireless signal in my bedroom isn&#8217;t all that great (or maybe it&#8217;s a laptop hardware issue) and the game hangs every 2 mins for about 30 seconds because I lose my connection. Thanks to the Ubisoft&#8217;s always-online <a href="http://infosec3t.com/tag/drm/" class="st_tag internal_tag" rel="tag" title="Posts tagged with DRM">DRM</a>. I have to be online at all times to play the game.</p>
<p>&#8220;Hackers have overcome Ubisoft&#8217;s controversial DRM system that relied on constant connection to the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">internet</a> for games to function.</p>
<p>A crack for Ubisoft’s anti-piracy system published by a group called Skid Row allows gamers to circumvent the controls. <em></em> A <a href="http://www.reddit.com/r/gaming/comments/bu69y/assassins_creed_2_drm_cracked_message_from" target="_blank">message</a> from the group on a gamers&#8217; forum sets out the group&#8217;s agenda: allowing legitimate copies of PC games to be played without an internet connection, rather than facilitating piracy. Skid Row cheekily thanks Ubisoft for posing an interesting intellectual challenge.&#8221;</p>
<p>I understand Ubisoft&#8217;s desire to protect its products from pirates but this causes a great inconvenience to legitimate customers like myself. Not to mention, it only took about a a dayto crack it. It causes me all this aggravation with controls that only held up for 24 hrs ?</p>
<blockquote><p>Silent Hunter NFO:</p>
<p><tt> Ü ß               ßÜ    ÜþßßßþÜ      Û                ÜþßßßþÜ<br />
°    ÛÜ     ²Ü     °    ÜÛÝ  ß       ²Ü     ßßÛÛÛÜÜ     ° ÜÛÜ     ²ÛÜ<br />
ßÛÛÛÜ ²ÛÛÜ     ÜÜÛÛÛÜÜß    °   ²ÛÛÜÜÜÜÜÜÜÛÛÛÛÛÜ ° ÜÛÛßÛÛÜ ° ²ÛÛ²  °     Ü<br />
ÜÛÛÛÛßßßßßß ²ÛÛ²  ²ÛÛÛÛßÛ²²²Û  ÜÜÜÜÜÜ²ÛÛ² ²ÛÛ²  ²ÛÛ²ß ÜÛÛ²   ²ÛÛÜ ²ÛÛ²  °°°  ÜÛ²<br />
ßßßßßß²²²²Üß²²²ßß²²²Ü   ßßß  Û²²²ß  ²²²² ²²²²ßß²²²ÜÜ ²²²² °  ²²²² ²²²² °°° ²²²²<br />
±±±±±  Þ±±±±ÛÞ±±  Þ±±±± ²²²²²Þ±±±± ° ±±±± ±±±±   Þ±±±±ÛÜ±±± ° ±±±± ±±±± °°° ±±±±<br />
°°°°° ° °°°°°Ý°° ° °°°°°°°°°°Þ°°°° °  °°°° °°°° ° °°°°°°°°° ° °°°° °°°°  Ü  °°°°<br />
±±±±± ° ±±±±±Ý±± °  ±±±±±Ü±±±±±±±±± ° ±±±± ±±±± ° ±±±±±Ý±±± ° ±±±± ±±²ßÜÛÛÛÜß²±±<br />
Þ²²²²  °Þ²²²²²²²² °Þ²²²²²Ý²²²²Þ²²²²Ý  ²²²² ²²²² °Þ²²²²²²²²² ° ²²²² ²²²²²ß  ß²²²²²<br />
ßÛÛ² ÜÛ²ÛÛßÜÛÛß  ²ÛÛÛÛ²ÛÛÛß  ²ÛÛÛ²ÜÜ²ÛÛ²Ü²Ûß   ²ÛÛÛ² ßÛÛ²    ²ÛÛß ²ÛÛß ° ° ßÛÛ²<br />
°  ßÜÛÛßß   Ûß   ÜÛ²ÛÛß Ûß  °  ÛÛÛÛÛßßß   ß  °  ÞÛÛ²ÛÝ ° ßÛÛÜÛÛß ° ²ß   °     ßÛ<br />
Üßß    °     ÜÛÛÛßß  ° ßþÜÜþß  ßßÛÛÛÛÜÜÜþß  °  ßßÛÛÛÜÜÜÜÜÛÛß Eboy<br />
ßÜÜþß     þßß                                      ßßßßßß<br />
S   K   i   D   R   O   W</tt></p>
<p><tt>Üß                -&gt;  T H E   L E A D i N G   F O R C E   &amp;lt;-                 ßÜ<br />
ßÜ                                                                           Üß<br />
ßßßßßßßßßßßßßßßßßßß ßßßßß  ß proudly presents  ß  ßßßßß ßßßßßßßßßßßßßßßßßßß<br />
° ÛÛÛ²²²²±±°° Silent Hunter 5: Battle  of the Atlantic / Ubisoft °°±±²²²²ÛÛÛ °<br />
±ÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜ±<br />
²                                                                            ²<br />
²   RELEASE DATE : 03-03-2010               PROTECTION :  Ubisoft DRM        ²<br />
²   GAME TYPE    :  Submarine Simulation     DISKS      : 1 DVD               ²<br />
°                                                                            °<br />
ßÛ²ßßßßßßßßßßßßßßßßÛÛßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßß ßßß   ß<br />
ßÛÝ Release Notes: ßÛÜ                                                ° Û<br />
Üþ  Þ² ÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÛÛÜ                                              ± Û<br />
Û   ÜÛß Û                                                                 ² Û<br />
ßßß  ° Û The  Skid Rowdies are looking new blood to fill up the  ranks.   Û Û<br />
± Û We're a professional team of dedicated sceners with big mark   Û Û<br />
Û Û under sceners. We  believe on the ground idealism of the root    Û Û<br />
Û Û of the real old school scene. We do all this for fun and       Û Û<br />
Û Û nothing else.  We don't earn anything on our hobby, as we  do    Û Û<br />
Û Û this for the competition and the heart of what got the scene   Û Û<br />
Û Û started in the mid eighties.                                   Û Û<br />
Û  Û                                                                Û Û<br />
Û Û If you think you got something to offer, then don't hold back  Û Û<br />
Û Û on contacting us as soon as possible.                           Û Û<br />
Û Û                                                                 Û Û<br />
Û Û  _______  __     ___     _____   /__                           Û Û<br />
Û Û      / |/ /_/_|         _  / /_ /  /                    Û Û<br />
Û Û  / /| / / //| |     //_// / / / / / /                   Û  Û<br />
Û Û /   |   /  | |_   / / / /_/ / /// /                    Û Û<br />
Û Û ____/|_|___/|___/ / /_/_/__/_/____/                     Û Û<br />
Û Û      twice the fun   / double the trouble                       Û Û<br />
Û Û                                                                 Û Û<br />
Û Û  ÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ Û Û<br />
Û  Û                                                                Û Û<br />
Û Û On with the game release information:                           Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Silent Hunter 5 hails the return  of the number one submarine   Û Û<br />
Û Û  simulation. For the first time the player will be able to play Û Û<br />
Û Û &amp; feel as U-boat captain  leading his crew from a first person  Û Û<br />
Û Û view in a true dynamic campaign.                                Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Operate against Allied shipping on  a vast area all across the  Û Û<br />
Û Û  Atlantic Ocean and Mediterranean Sea and participate  in famous Û Û<br />
Û Û encounters with strong enemy warships. Can you do  better than  Û Û<br />
Û Û the best U-boat aces?                                           Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Silent Hunter 5 raises the levels of interactivity and         Û Û<br />
Û Û immersion inside the  U-boat and outside                        Û Û<br />
Û Û                                                                Û Û<br />
Û Û For the first time the player will walk through  highly         Û Û<br />
Û Û detailed submarines in FPS view and be able to access every    Û Û<br />
Û Û inside &amp;  outside part of the U-boot                             Û Û<br />
Û Û                                                                 Û Û<br />
Û Û With the help of an advanced order system the player will      Û Û<br />
Û Û interact with the  submarine crew, watch them doing their  daily Û Û<br />
Û Û jobs and experience the tension &amp; fear inside the  U-boot.      Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Player actions  will impact the outcome of battles and the       Û Û<br />
Û Û scenario evolution in campaign. Depending on his  approach the  Û Û<br />
Û Û player can open  new locations with upgrade and resupply         Û Û<br />
Û Û possibilities, while the Allied response adjusts dynamically   Û Û<br />
Û Û                                                                 Û Û<br />
Û °                                                                 Û °<br />
ßÛ²ßßßßßßßßßßßßßßßßÛÛßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßßß ßßß   ß<br />
ßÛÝ Install Notes: ßÛÜ                                                ° Û<br />
Üþ  Þ² ÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÜÛÛÜ                                              ± Û<br />
Û   ÜÛß Û                                                                 ² Û<br />
ßßß  ° Û 1.  Unpack release                                              Û Û<br />
± Û  2. Mount image or burn it                                       Û Û<br />
Û Û 3. Install                                                      Û Û<br />
Û Û 4. Copy the  content from the SKIDROW folder on the DVD to  your Û Û<br />
Û Û    installation directory and overwrite                        Û Û<br />
Û Û 5. Play the game                                                Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Additinal Notes:                                                Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Don't install/use  Ubisoft launcher, or simply block any         Û Û<br />
Û Û connection to internet.                                         Û Û<br />
Û Û                                                                 Û Û<br />
Û Û Install game and copy  crack, it's that simple!                 Û Û<br />
Û Û                                                                Û Û<br />
Û Û Support the companies, which <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> you actually  enjoy!      Û Û</tt></p></blockquote>
<p>Source: http://www.theregister.co.uk/2010/04/28/ubisoft_drm_cracked/</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/04/02/cloud-computing-security-an-insiders-view/' rel='bookmark' title='Cloud Computing Security: An Insider&#039;s View'>Cloud Computing Security: An Insider&#039;s View</a> <small>As CSO of Qualys, Randy Barr is responsible for security,...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/28/hackers-crack-ubisoft-always-online-drm-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Web Application Security Risks for 2010</title>
		<link>http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/</link>
		<comments>http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 15:45:29 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2107</guid>
		<description><![CDATA[Yesterday, OWASP released its list of top ten web application security risks for this year. The list, which was first unveiled in November at the OWASP conference, is a departure from OWASP&#8217;s previous lists, which ranked the most commonly found weaknesses and vulnerabilities in Web applications. OWASP&#8217;s new list features the most exploitable and likely [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-2108 alignright" title="Owasp_logo" src="http://infosec3t.com/wp-content/uploads/2010/04/Owasp_logo_normal.jpg" alt="" width="106" height="106" />Yesterday, <a href="http://infosec3t.com/tag/owasp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OWASP">OWASP</a> released its list of top ten web <a href="http://infosec3t.com/tag/application-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Application Security">application security</a> risks for this year. The list, which was first unveiled in November at the OWASP conference, is a departure from OWASP&#8217;s previous lists, which ranked the most commonly found weaknesses and vulnerabilities in Web applications. OWASP&#8217;s new list features the most exploitable and likely <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> risks found in these apps. The list includes:</p>
<ul>
<li>A1: Injection</li>
<li>A2: Cross-Site Scripting (XSS)</li>
<li>A3: Broken Authentication and Session Management</li>
<li>A4: Insecure Direct Object References</li>
<li>A5: Cross-Site Request Forgery (CSRF)</li>
<li>A6: Security Misconfiguration</li>
<li>A7: Insecure Cryptographic Storage</li>
<li>A8: Failure to Restrict URL Access</li>
<li>A9: Insufficient Transport Layer Protection</li>
<li>A10: Unvalidated Redirects and Forwards</li>
</ul>
<p>Download the full report <a href="http://owasptop10.googlecode.com/files/OWASP%20Top%2010%20-%202010.pdf">here</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/05/women-in-it-security/' rel='bookmark' title='Women in IT Security'>Women in IT Security</a> <small>I recently had a conversation with a former student of...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
<li><a href='http://infosec3t.com/2010/01/25/web-application-security-testing-white-paper/' rel='bookmark' title='Web Application Security Testing White Paper'>Web Application Security Testing White Paper</a> <small>The need to provide web security and defend web applications...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does the musical browser approach work?</title>
		<link>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/</link>
		<comments>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 18:42:50 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[warning]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1976</guid>
		<description><![CDATA[German&#8217;s official cyber-security response team is advising surfers not to use Firefox pending the release of a patch to defend against a critical unpatched vulnerability. This is the second time in two months that Germany has taken such a step. Earlier in January, the German government issued a similar warning to IE users. I did [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1979" title="firefox" src="http://infosec3t.com/wp-content/uploads/2010/03/firefoxpostvotbox17090_.jpg" alt="" width="170" height="90" />German&#8217;s official cyber-<a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> response team is advising surfers not to use Firefox pending the release of a patch to defend against a critical unpatched vulnerability. This is the second time in two months that Germany has taken such a step. Earlier in January, the German government issued a similar <a href="http://infosec3t.com/tag/warning/" class="st_tag internal_tag" rel="tag" title="Posts tagged with warning">warning</a> to IE users. I did a post about it titled <em><a rel="bookmark" href="../2010/01/19/france-germany-warn-users-against-internet-explorer/">Germany warn users against Internet Explorer.<br />
</a></em></p>
<p>The zero-day vulnerability in the latest full version 3.6 of Firefox was discovered by security researcher Evgeny Legerov last month.  Legerov controversially offered to sell exploit code he developed.  Mozilla <a href="http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608" target="_blank">acknowledged</a> the security vulnerability on Thursday and promised the the next version of 3.6.2, due at the end of the month, would plug the hole.</p>
<p>I have to applaud the German government for taking such a proactive approach to online security of it&#8217;s citizens. I have to wonder what would be the response to such an approach my the US government here. As to the advice given, I&#8217;m of two minds really. Whereas home users are at liberty to switch browsers as often as their underpants, corporate users may not have that luxury. Whole scale <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> migrations in a corporate setting is no small undertaking. Ig it were, I doubt Google would have gotten hacked for using IE6.</p>
<p>Vulnerabilities in all browsers are discovered over time. Corporate users, does the musical browser approach really work even if it were possible? I think not. My advice: Test and Upgrade as soon as is feasible.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upgrade your Safari browser now!</title>
		<link>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/</link>
		<comments>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 22:49:37 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1931</guid>
		<description><![CDATA[The newly released Safari 4.0.5 reportedly fixes a number of security issues on the Windows and Mac OSX platform versions of its browser, and includes remediations for a total of 16 security vulnerabilities. Some of these vulnerabilities allows your system to be compromised simply by browsing a page with an infected image file so upgrade [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1932" title="apple_safari" src="http://infosec3t.com/wp-content/uploads/2010/03/apple_safari.jpg" alt="" width="144" height="144" />The newly released <a href="http://www.apple.com/safari/" target="_blank">Safari 4.0.5 </a> reportedly fixes a number of security issues on the <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> and <a href="http://infosec3t.com/tag/mac/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MAC">Mac</a> OSX platform versions of its browser, and includes remediations for a total of 16 security vulnerabilities.</p>
<p>Some of these vulnerabilities allows your system to be compromised simply by browsing a page with an infected image file so upgrade without delay.</p>
<p>According to Brian Cluley of Sophos , &#8220;It doesn&#8217;t matter whether you own a Mac or PC, if you run <a href="http://infosec3t.com/tag/safari/" class="st_tag internal_tag" rel="tag" title="Posts tagged with safari">Safari</a> the message is clear: It&#8217;s time to update your browser and ensure that you are protected against hackers exploiting the <a href="http://infosec3t.com/tag/security-holes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security holes">security holes</a> detailed in the security advisory on Apple&#8217;s website&#8221;</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA 2010 Recap</title>
		<link>http://infosec3t.com/2010/03/05/rsa-2010-recap/</link>
		<comments>http://infosec3t.com/2010/03/05/rsa-2010-recap/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 17:44:20 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Users]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[rsa]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1735</guid>
		<description><![CDATA[Today is the last day of RSA Conference 2010. If you didn’t make it,  CSOonline.com has provided a recap of the highlights here.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1736" title="RSA2010" src="http://infosec3t.com/wp-content/uploads/2010/03/RSA2010.jpg" alt="" width="220" height="220" />Today is the last day of RSA Conference 2010. If you didn&#8217;t make it,  CSOonline.com has provided a recap of the highlights:</p>
<p><strong>RSA COVERAGE</strong></p>
<p><a href="http://www.csoonline.com/article/563513" target="_blank">RSA 2010: Infosec Pros Get Raises Despite Recession </a>An (ISC)2 survey suggests salary increases and hiring went up for many security practitioners in the last year despite the    Great Recession. Ironically, the recession may be WHY it&#8217;s happening.</p>
<p><a href="http://www.csoonline.com/article/559863">RSA 2010: Why 41 Percent of You Would Fail a PCI Audit </a>Miscellaneous <a href="http://infosec3t.com/tag/news/" class="st_tag internal_tag" rel="tag" title="Posts tagged with News">news</a> bytes from the RSA 2010 press room: QSAs tell Ponemon Institute that 41 percent of companies would bomb    their PCI security audit; hackers industrialize their sinister revolution and VeriSign opens a new compatibility lab.</p>
<p><a href="http://www.csoonline.com/article/558913" target="_blank">RSA 2010: Can Adobe Stop the Hate? </a>Security pros are unhappy with Adobe Systems over recent flaws and attacks. Adobe Security Chief Brad Arkin on what the company    is doing about it.</p>
<p><a href="http://www.csoonline.com/article/556713" target="_blank">RSA Conference 2010: 4 Survival Tips</a>For the newcomer, the RSA security conference can be overwhelming. Follow these four strategies to get the most from it.</p>
<p><a href="http://www.csoonline.com/article/564387" target="_blank">Social Networking is Risky Business</a> From Computerworld: A panel discusses the risks associated with social networking sites.</p>
<p><a href="http://www.csoonline.com/article/564375" target="_blank">Chertoff: Tracking Attacks to the Source is Key for Cybersecurity</a> From Computerworld: An exclusive interview with former DHS leader Michael Chertoff.</p>
<p><strong>RSA PODCASTS</strong></p>
<p>RSA 2010: <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a>&#8217;s Plan for Cloud Security Audio: <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> VP Jim Jones explains his company&#8217;s approach for securing its services in the cloud.</p>
<p><a href="http://www.csoonline.com/podcast/559463" target="_blank">RSA 2010: Verizon Releases Its Threat Report Recipe</a> Verizon Business will share the research framework used for its Data Breach Investigations Reports so companies can create    reports tailored to their specific environments.</p>
<p><strong>SECURITY B-SIDES COVERAGE</strong></p>
<p><a href="http://www.csoonline.com/article/561913" target="_blank">Security B-Sides: Perfect Authentication Remains Elusive </a>Everyone realizes passwords have their shortcomings. But alternatives like two-factor authentication are not as powerful as    one would expect. The problem? As always &#8212; human behavior.</p>
<p><a href="http://www.csoonline.com/article/561663" target="_blank">One Man&#8217;s Life on the Security D-List</a> At Security B-Sides, infosec author Andrew Hay explains the four pillars for moving from the bottom of the IT security shop    to a place of respect, and why getting to the A-list isn&#8217;t all it&#8217;s cracked up to be.</p>
<p><a href="http://www.csoonline.com/article/554613" target="_blank">Security B-Sides: Rise of the &#8216;Anti-conference&#8217; </a>The RSA 2010 conference had some nearby competition. Here&#8217;s the story of Security B-Sides as the conference alternative.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/' rel='bookmark' title='Shmoocon 2010 Videos Online'>Shmoocon 2010 Videos Online</a> <small>Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this...</small></li>
<li><a href='http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/' rel='bookmark' title='Top 10 Web Application Security Risks for 2010'>Top 10 Web Application Security Risks for 2010</a> <small>Yesterday, OWASP released its list of top ten web application...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/05/rsa-2010-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How much more would be pay for less bugs?</title>
		<link>http://infosec3t.com/2010/02/19/how-much-more-would-be-pay-for-less-bugs/</link>
		<comments>http://infosec3t.com/2010/02/19/how-much-more-would-be-pay-for-less-bugs/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 15:22:45 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1553</guid>
		<description><![CDATA[[poll id="2"] No related posts.]]></description>
			<content:encoded><![CDATA[<p>[poll id="2"]</p>
<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/19/how-much-more-would-be-pay-for-less-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Open Source Alternatives to Microsoft Office</title>
		<link>http://infosec3t.com/2010/02/08/5-open-source-alternatives-to-microsoft-office/</link>
		<comments>http://infosec3t.com/2010/02/08/5-open-source-alternatives-to-microsoft-office/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 17:55:43 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Office suite]]></category>
		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1409</guid>
		<description><![CDATA[The Microsoft Office productivity suite has risen to become the dominant application of its type for business IT management. But there are open source office productivity suites available that may provide a suitable alternative to Office, depending on your requirements. 1. OpenOffice.org Ever since Sun Microsystems release the code to StarOffice back in 2000, OpenOffice.org [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> Office productivity suite has risen to become the dominant application of its type for business IT management. But there are open source office productivity suites available that may provide a suitable alternative to Office, depending on your requirements.</p>
<h2>1. <strong>OpenOffice.org</strong></h2>
<p>Ever since Sun Microsystems release the code to StarOffice back in 2000, OpenOffice.org has been a popular “free alternative” to Microsoft Office.</p>
<p>OpenOffice.org offers a complete suite of office apps, including a word processor, spreadsheet and presentation manager. In terms of user experience, it is the closest thing the open source world has to rival Microsoft Office and is thus popular with many home users as well.</p>
<p>Good file compatibility with Office is also a compelling feature of OpenOffice.org. Late last year the project announced 100 million downloads since version 3.0 was announced a year earlier. The next release will be 3.2,which is due in the coming weeks.</p>
<p>URL: http://www.openoffice.org<br />
Licence: LGPL</p>
<h2>2. <strong>KOffice</strong></h2>
<p>Not as popular as OpenOffice, but providing a similar level of functionality is KOffice. KOffice began life as an <a href="http://infosec3t.com/tag/office-suite/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Office suite">office suite</a> for the KDE open source project on <a href="http://infosec3t.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Linux">Linux</a>, but has since been ported <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> and Mac OS X.</p>
<p>In addition to the standard office applications, KOffice also features apps for project management, flowcharting and graphic design. Also part of the KOffice suite is Kexi &#8212; an open source database alternative to Microsoft Access.</p>
<p>KOffice is in rapid development after a major release upgrade from the 1.x to 2.x series. The developers will release the 2.2 stable version this year, which is meant to be a “production” release suitable for everyday use.</p>
<p>Last year Nokia announced it will use KOffice as the basis of its mobile office suite for the N900 smartphone.</p>
<p>URL: <a href="http://www.koffice.org/" target="_blank">http://www.koffice.org</a><br />
Licence: LGPL &amp; GPL</p>
<h2>3.<strong> GNOME Office</strong></h2>
<p>While not as tightly integrated as OpenOffice.org or KOffice, the GNOME office suite is a collection of productivity applications typically shipped with the GNOME desktop environment on Linux, but it can also run on Windows.</p>
<p>The word processor, AbiWord, reached version 2.8 last year and now supports annotations, smart quotes and scalable vector graphics. A collaboration tool also allows multiple people to work on one document at the same time. This can also be used with the AbiCollab.net online storage service.</p>
<p>Gnumeric, the spreadsheet, has support for Microsoft Excel documents and claims more calculation functions.</p>
<p>GNOME office also includes the Evolution e-mail and groupware client. Evolution has a number of enterprise features and has an extensive repository of plug-ins available to enhance its functionality.</p>
<p>URL: <a href="http://live.gnome.org/GnomeOffice" target="_blank">http://live.gnome.org/GnomeOffice</a><br />
Licence: GPL</p>
<h2>4. <strong>Feng Office</strong></h2>
<p>Formerly known as OpenGoo, Feng Office is not your typical open source office suite in that it is Web-based, like many of today&#8217;s SaaS offerings.</p>
<p>Feng Office allows users to upload and share any type of document and certain files can be edited online as well. A spreadsheet component is under development.</p>
<p>In addition to document management, Feng Office has applications for notes, e-mail, contact management, calendaring, task management and time keeping.</p>
<p>A commercially supported version is available which can be hosted on-site or provided as SaaS.</p>
<p>URL: <a href="http://www.fengoffice.com/" target="_blank">http://www.fengoffice.com</a><br />
Licence: AGPL</p>
<h2>5. <strong>Simple Groupware</strong></h2>
<p>As the name indicates, Simple Groupware was developed as an open source groupware suite, but we&#8217;ve included it here because of the increasing amount of office suite-like applications it contains, including an online spreadsheet.</p>
<p>Simple Groupware&#8217;s Simple Spreadsheet features support for formulas, functions, JavaScript macros, charts, cell manipulation and integration of images from the Web. Open Office and Microsoft Office documents can be previewed in a Web-browser.</p>
<p>With modules for HTML and wiki documents, Simple Groupware is starting to look a lot like a basic online office productivity suite. What&#8217;s more, the files module makes it possible to share files, track versions and manage folders.</p>
<p>URL: <a href="http://www.simple-groupware.de/" target="_blank">http://www.simple-groupware.de</a><br />
Licence: GPL</p>
<p>Source: http://www.cio.com.au/</p>
</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/25/keimpx-%e2%80%93-new-open-source-smb-credential-scanner/' rel='bookmark' title='keimpx – New Open Source SMB Credential Scanner'>keimpx – New Open Source SMB Credential Scanner</a> <small>keimpx is an open source tool, released under a modified...</small></li>
<li><a href='http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/' rel='bookmark' title='Trojan Pretends to Be Microsoft Security Suite'>Trojan Pretends to Be Microsoft Security Suite</a> <small>Microsoft is warning users that a Trojan is masquerading as...</small></li>
<li><a href='http://infosec3t.com/2010/01/30/100-open-source-security-tools/' rel='bookmark' title='100+ Open Source Security Tools'>100+ Open Source Security Tools</a> <small>Security testing  or assessment is a process to determine that...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/08/5-open-source-alternatives-to-microsoft-office/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Application Security Testing White Paper</title>
		<link>http://infosec3t.com/2010/01/25/web-application-security-testing-white-paper/</link>
		<comments>http://infosec3t.com/2010/01/25/web-application-security-testing-white-paper/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 16:27:06 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Application Security]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=983</guid>
		<description><![CDATA[The need to provide web security and defend web applications from hackers due to software and hardware vulnerabilities requires remote an online web vulnerability-assessment service to combat maximum vulnerabilities. The risks must be continually updated and the tests tailor-made to provide optimal solutions.]]></description>
			<content:encoded><![CDATA[<p>1.	Web Applications: An attractive target for hackers</p>
<p>How do you cost effectively defend web applications from hackers? Your organization relies on mission critical business applications that contain sensitive information about customers, business processes and corporate data. Moving away from proprietary client/server applications to web applications gives you a simpler, cost-effective, highly extensible delivery platform. These applications are more than a valuable tool to power your business operations; they are also a valuable and vulnerable target for attackers.</p>
<p>Web applications are increasingly the preferred targets of cyber-criminals looking to profit from identity theft, fraud, corporate espionage, and other illegal activities. The impact of an attack can be significant, and include:</p>
<p>Costly and embarrassing service disruptions</p>
<p>Down-time</p>
<p>Lost productivity</p>
<p>Stolen datav <br /> Regulatory fines</p>
<p>Angry users</p>
<p>Irate customers</p>
<p>In addition to protecting the corporate brand, federal and state legislation and industry regulations are now requiring web applications to be better protected.</p>
<p>As you take action to protect web applications in a timely and effective manner, you must balance the need for security with availability, performance and cost-effectiveness. Protecting web applications requires both zero-day protection and rapid response with minimal impact to operations without impacting performance or changing system architectures.</p>
<p>2.	Web applications are increasingly vulnerable.</p>
<p>Rapid growth leads to emerging problems</p>
<p>The number of corporate web applications has grown exponentially and most organizations are continuing to add new applications to their operations. With this rapid growth come common security challenges driven by complexity and inconsistency. New <a href="http://infosec3t.com/tag/awareness/" class="st_tag internal_tag" rel="tag" title="Posts tagged with awareness">awareness</a> into web application vulnerabilities, thanks to organizations such as the Open Web <a href="http://infosec3t.com/tag/application-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Application Security">Application Security</a> Project (<a href="http://infosec3t.com/tag/owasp/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OWASP">OWASP</a>), has helped organizations identify <a href="http://infosec3t.com/tag/application-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Application Security">application security</a> as a priority. But according to a June, 2006 survey (www.symantec.com/ about/<a href="http://infosec3t.com/tag/news/" class="st_tag internal_tag" rel="tag" title="Posts tagged with News">news</a>/release/article.jsp?prid=20060919_01), while 70 percent of software developers indicated that their employers emphasize the importance of application security, only 29 percent stated that security was always part of the development process.</p>
<p>Overlooked online application vulnerabilities</p>
<p>Unfortunately, it is not just application flaws that are leaving systems vulnerable. In addition to application issues, every web application relies on a large stack of commercial and custom software components. The operating system, web server, database and all the other critical components of this application stack, have vulnerabilities that are regularly being discovered and communicated to friend and foe alike. It is these vulnerabilities that most organizations overlook when they&#8217;re considering web application security.</p>
<p>As new vulnerabilities are found, patches become a critical part of managing application security. The process of patch management is complex and difficult to do successfully. Even the most proactive IT team must often reassign critical resources to deploy urgent patches, disrupting normal operations. The time required to patch responsibly lengthens the window of time a hacker has to exploit a specific vulnerability. With thousands of vulnerabilities and patches being announced each year the problem continues to grow. Even organizations with the most efficient patching processes in place can&#8217;t rely on this alone to protect them from attacks targeting web application vulnerabilities.</p>
<p>Hackers look for the path of least resistance</p>
<p>Today&#8217;s sophisticated attackers target corporate data for financial and political gain. They know they can more easily exploit vulnerabilities in web application stacks versus trying to defeat well built network and perimeter security. Hackers have a myriad number of vulnerabilities techniques to use including:</p>
<p>SQL Injection</p>
<p>Cross Site Scripting</p>
<p>Buffer Overflow,</p>
<p>Denial of Service</p>
<p>The number of application vulnerabilities in commercial applications and open source applications is growing at an alarming pace; anywhere from 200 to 400 new vulnerabilities are identified every month.</p>
<p>According to zone-h.org, 45% of attacks make use of vulnerabilities rather than configuration issues or use brute force. Attackers are working hard to find and exploit new vulnerabilities in web applications faster then they can be patched. The window of time, from when a hacker identifies a vulnerability to when it is communicated and eventually patched, makes a fast response defence- strategy critical to prevent a potentially damaging intrusion.</p>
<p>3.	Required: A remote online web application security-testing service</p>
<p>Web applications are increasingly vulnerable and protecting them requires a system that can:</p>
<p>Ensure compliance today</p>
<p>meet the evolving needs of an organization for tomorrow</p>
<p>Respond quickly</p>
<p>To meet this challenge, by the optimal solution should locate these vulnerabilities as they are seen from the hacker&#8217;s point of view. Therefore a remote online Web application security testing service will best address those needs.</p>
<p>A web application security scan should reveal vulnerability for these attacks:</p>
<p>SQL Injection</p>
<p>Blind SQL Injection</p>
<p>Installation Path Disclosure</p>
<p>.Net Exception</p>
<p>Command Execution</p>
<p>PHP Code Injection</p>
<p>Xpath Injection</p>
<p>CRLF Injection</p>
<p>Directory Traversal</p>
<p>Script Language Error</p>
<p>URL Redirection</p>
<p>Remote File Inclusion</p>
<p>LDAP Injection</p>
<p>Cookie Manipulation</p>
<p>Source Code Disclosure</p>
<p>Cross-Site Scriptingv <br /> Cross-Frame Scripting</p>
<p>The security scan must test vulnerabilities for a wide variety of website components:</p>
<p>Web Servers</p>
<p>Web Server Technologies</p>
<p>HTTP Methods</p>
<p>Backup Files</p>
<p>Directory Enumeration</p>
<p>Directory Indexing</p>
<p>Directory Access</p>
<p>Directory Permissions</p>
<p>Sensitive/Common Files</p>
<p>Third Party Application</p>
<p>The online web application security service must:</p>
<p>Remotely crawl the entire website.</p>
<p>Analyse each file.</p>
<p>List the vulnerabilities found along with the severity levels of each vulnerability.</p>
<p>Launch a series of web attacks to discover security.</p>
<p>Include option to make a tailor made attack</p>
<p>Be able to adapt to any web site configuration.</p>
<p>Produce dynamic tests, which will create relevant reports of online scan findings.</p>
<p>Provide a constantly updated vulnerability assessment</p>
<p>Include an automatic False Positive Prevention Engine.</p>
<p>Provide Enhanced Report Generation for Scanning Comparison. &#8211; Must include the ability to create comparison and trend analysis of your web applications vulnerabilities based on scan results generated over a selected time periods.</p>
<p>Recommend solutions in order to fix, or provide a viable workaround to the identified vulnerabilities</p>
<p>Author: Avi Bartov<br />Article Source: EzineArticles.com<br />Provided by: <a href="http://instantpot.com/">Programmable pressure cooker</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/18/effectively-scoping-application-security-penetration-testing-and-ethical-hacking/' rel='bookmark' title='Effectively Scoping Application Security Penetration Testing and Ethical Hacking'>Effectively Scoping Application Security Penetration Testing and Ethical Hacking</a> <small>When seeking to test if your web based application or...</small></li>
<li><a href='http://infosec3t.com/2010/03/08/sahi-%e2%80%93-web-automation-application-security-testing-tool/' rel='bookmark' title='SAHI – Web Automation &amp; Application Security Testing Tool'>SAHI – Web Automation &amp; Application Security Testing Tool</a> <small>Sahi is an automation tool to test web applications. Sahi...</small></li>
<li><a href='http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/' rel='bookmark' title='Top 10 Web Application Security Risks for 2010'>Top 10 Web Application Security Risks for 2010</a> <small>Yesterday, OWASP released its list of top ten web application...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/25/web-application-security-testing-white-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Security Software pose great risk</title>
		<link>http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/</link>
		<comments>http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 19:03:43 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=946</guid>
		<description><![CDATA[Desktop Security 2010 is the proverbial wolf in sheep&#8217;s clothing. It is a fake anti-spyware application that is promoted and installed through the use of malware , usually Trojan viruses. It is often spread through drive-by attacks. These are malware that gets downloaded to your computer just by browsing a malicious or infected website.  Google [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/DesktopDefender2010-500x399.jpg"><img class="size-thumbnail wp-image-947 alignleft" title="DesktopDefender2010 " src="http://infosec3t.com/wp-content/uploads/2010/01/DesktopDefender2010-500x399-150x150.jpg" alt="" width="150" height="150" /></a>Desktop <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> 2010 is the proverbial wolf in sheep&#8217;s clothing. It is a fake anti-spyware application that is promoted and installed through the use of malware , usually Trojan viruses. It is often spread through drive-by attacks. These are malware that gets downloaded to your computer just by browsing a malicious or infected website.  <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> is now making an effort to <a title="“Show me the malware”- says Google" href="http://infosec3t.com/2009/12/17/show-me-the-malware-says-google/">warn</a> users of these websites if these are present in search results. This particular software simulates a system scan and displays fake security alerts to make you think that your computer is infected with Trojans, worms,viruses and other forms of malware when in reality the only real <a href="http://infosec3t.com/tag/threat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threat">threat</a> is Desktop Security2010 itself. I too was once a victim of a previous version of this malware before I dumped my XP operating system for Ubuntu <a href="http://infosec3t.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Linux">linux</a>. Yes, it was the last straw. I don&#8217;t recommend that remedy for the light of heart however.</p>
<p>Desktop Security 2010 can also download additional malware to your computer which could complicate matters. It also uses quite effective self-defense methods. In some cases it blocks Task Manager so likely you won&#8217;t be able to end its processes. Then the rogue program blocks anti-virus software and block sany attempts to install a new one. The best remedy is to reboot your computer in safe mode with networking and run an anti-spyware program from there.</p>
<p>For more examples of fake security software, see Lavasoft&#8217;s <a title="Rogue's Gallery" href="http://www.lavasoft.com/mylavasoft/rogues/latest" target="_blank">Rogue&#8217;s Gallery</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/17/another-fake-security-software-alert/' rel='bookmark' title='Another fake security software alert'>Another fake security software alert</a> <small>I&#8221;ve previously warned of fake security software or scareware. Here&#8217;s...</small></li>
<li><a href='http://infosec3t.com/2010/02/21/a-guide-to-computer-security/' rel='bookmark' title='A Guide to Computer Security'>A Guide to Computer Security</a> <small>As the number of people connecting to the Internet continues...</small></li>
<li><a href='http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/' rel='bookmark' title='Beware of Haiti-Themed Scams and Attacks!'>Beware of Haiti-Themed Scams and Attacks!</a> <small>Our thoughts and prayers go out to all those affected...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Revealed &#8211; 5 Web Application Security Threats</title>
		<link>http://infosec3t.com/2010/01/08/revealed-5-web-application-security-threats/</link>
		<comments>http://infosec3t.com/2010/01/08/revealed-5-web-application-security-threats/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 00:00:55 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=586</guid>
		<description><![CDATA[How secure are your Web applications and your Web application server?  Why would you care?  The answer to that question coincides with the answer to the question, how important is your Web Server to your business?  If your Website is nothing more than a billboard on the 'information super highway', then the security of your Website may be inconsequential.]]></description>
			<content:encoded><![CDATA[<p>Consider the fallout if someone hacked your Website and altered the content of your site.</p>
<p>What would that do to your customer base?</p>
<p>Do you think their confidence in your ability to conduct business over the Internet would change?</p>
<p>What are the potential security <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> to your Web application server? The <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> are many. In fact, nearly every device that connects directly to the Internet on a broadband or dedicated (always on) connection is scanned multiple times.</p>
<p>Every device connected to the Internet receives an Internet Protocol (IP) address. That address has two components, a network component and a host component. A hacker can launch a program to &#8216;ping&#8217; every host address within a given network and log the results. Simple analysis of the results reveals which addresses are assigned to active devices by responding to the &#8216;ping&#8217;. Armed with a list of active devices, the hacker launches other scans to determine the operating system or application programs the active device runs. Many operating systems and applications have security vulnerabilities that the hacker exploits.</p>
<p><strong>So, what can the hacker do if he or she discovers vulnerabilities on your Web application server?</strong></p>
<p>Let&#8217;s examine 5 Web <a href="http://infosec3t.com/tag/application-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Application Security">application security</a> threats.</p>
<p>1. Defacement and Altered Content. Once a hacker gains access to your system, the content is at his mercy. As previously stated, what would be the fallout if someone altered the content of your Web Server? If you rely upon your Web Server or Website to generate revenue or drive customers to your business, defacement or altered content could irreparably damage your relationship with your customers and prospects.</p>
<p>2. Data Theft. Another potential <a href="http://infosec3t.com/tag/threat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threat">threat</a> is data theft. If your site has e-mail addresses, account numbers, or other sensitive data, a hacker may steal that data and exploit it to his or her own gain. Imagine having to explain to your customers that the information stolen from your server led to identity theft or the unauthorized use of their financial data.</p>
<p>3. Unauthorized Access to Applications and System Resources. Sometimes a hacker uses your system for his or her own purposes merely denying you the ability to efficiently and effectively use your system. The fallout ranges from a minor inconvenience to a major catastrophe.</p>
<p>4. Denial of Service Attacks. Some hackers launch denial of service attacks, which overwhelm the connection and deny you and your customers access to your Website. Again, the fallout ranges from a minor inconvenience to a major catastrophe.</p>
<p>5. Propagation of Viruses, Worms, and Other <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">Malware</a>. Sometimes a hacker may access your system to use it as a springboard to launch viruses, worms or other forms of <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>. This is done on your system to cover the hacker&#8217;s tracks.</p>
<p>The point is, take the security of your system seriously and employ all of the methods at your disposal to harden your site against attack.</p>
<p>Author: Tomer Shoha<br />
Article Source: EzineArticles.com<br />
Provided by: <a href="http://instantpot.com/">Pressure cooker</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/18/effectively-scoping-application-security-penetration-testing-and-ethical-hacking/' rel='bookmark' title='Effectively Scoping Application Security Penetration Testing and Ethical Hacking'>Effectively Scoping Application Security Penetration Testing and Ethical Hacking</a> <small>When seeking to test if your web based application or...</small></li>
<li><a href='http://infosec3t.com/2010/01/25/web-application-security-testing-white-paper/' rel='bookmark' title='Web Application Security Testing White Paper'>Web Application Security Testing White Paper</a> <small>The need to provide web security and defend web applications...</small></li>
<li><a href='http://infosec3t.com/2010/03/08/sahi-%e2%80%93-web-automation-application-security-testing-tool/' rel='bookmark' title='SAHI – Web Automation &amp; Application Security Testing Tool'>SAHI – Web Automation &amp; Application Security Testing Tool</a> <small>Sahi is an automation tool to test web applications. Sahi...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/08/revealed-5-web-application-security-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#039;t ignore this warning!</title>
		<link>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/</link>
		<comments>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 02:05:40 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=598</guid>
		<description><![CDATA[Following up on yesterday&#8217;s post, the advice was to ascertain the legitimacy of the web site by verifying the digital certificate. So what is a web site really? It&#8217;s just files located on a server somewhere. As you &#8220;browse the web&#8221;, your browser connects to the web server where those files are stored, downloads and [...]]]></description>
			<content:encoded><![CDATA[<p>Following up on yesterday&#8217;s <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/" target="_blank">post</a>, the advice was to ascertain the legitimacy of the web site by verifying the digital certificate. So what is a web site really? It&#8217;s just files located on a server somewhere. As you &#8220;browse the web&#8221;, your browser connects to the web server where those files are stored, downloads and displays them to you. The digital certificate resides on the web server and is transferred to your browser when you connect to a web site using https. The certificate contains two important items: the identification information of the web server and the encryption key that allows your browser to create an encrypted tunnel to the web server. The encrypted tunnel protects  your web traffic from attackers.</p>
<p>So https indicates your communications to the web site is encrypted. Clicking on the <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/" target="_blank">golden lock</a> displays the digital certificate and identity information. But what if your browsers decides it doesn&#8217;t like the certificate? Well it warns you. Ever seen these before:</p>
<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2.png"></a><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41.png"><img class="aligncenter size-medium wp-image-604" title="Internet Explorer Certificate Error" src="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41-300x168.png" alt="" width="300" height="168" /></a><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41.png"></a></p>
<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2.png"><img class="aligncenter size-medium wp-image-601" title="Firefox Certificate Error" src="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2-300x158.png" alt="Firefox Certificate Error" width="300" height="158" /></a></p>
<p>If you have spent any amount of time on the web, you will have eventually come across these warnings. What do you generally do? Flee for your life? Read the details? Continue on to the web site anyway? Well, don&#8217;t just ignore this <a href="http://infosec3t.com/tag/warning/" class="st_tag internal_tag" rel="tag" title="Posts tagged with warning">warning</a>! There are multiple reasons why your browser might balk at pproceeding to the requested web site.</p>
<p>Certificates are generally issued by companies like <a title="Verisign" href="http://www.verisign.com/" target="_blank">Verisign</a> and <a title="Thawte" href="http://www.thawte.com/" target="_blank">Thawte</a> after the entity requesting the certificate has verified its identity. The certificates are digitally connected to a root certificate located at the issuer. Browsers are pre-configured with a number of more popular root certificates. That is why, when you access your online bank account, your browsers automatically recognizes the certificate and allows you to proceed without issue. The certificates are valid for a specified period of time and require renewal. If the certificate has expired, your browser will detect it and you will see the warning displayed  above. If your browser does not recognize the source of the certificate ( i.e no connection to a known root certificate), you will see the error message as well. This is the case when web site owners decide not to purchase a certificate issued by one of the aforementioned third-parties and create their own certificate which still provides the same functions: claims an identify and enable encryption.</p>
<p>This last point is key. <strong>Anyone can create a certificate</strong>. I can create a certificate in seconds claiming my laptop to be <strong>https</strong>://www.your-online-bank.com. <a href="http://infosec3t.com/tag/tools/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Tools">Tools</a> that enable a man-in-the-middle attack mentioned in yesterday&#8217;s <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/">post</a> automatically do this.  Now, as your browser will recognize the lack of digital connection between my fake web site certificate and the real root certificate, it will warn you with one of the  errors displayed above. Beware that you don&#8217;t make it a habit of clicking to continue without giving it a second thought.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/16/1533/' rel='bookmark' title='Enter the Dragon browser, the more secure Google Chrome'>Enter the Dragon browser, the more secure Google Chrome</a> <small>The open source engine that forms the basis for Google&#8217;s...</small></li>
<li><a href='http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/' rel='bookmark' title='Beware of Free Internet Connections'>Beware of Free Internet Connections</a> <small>Many hotels,coffee shops and other such establishments  offer free wireless...</small></li>
<li><a href='http://infosec3t.com/2010/03/08/sahi-%e2%80%93-web-automation-application-security-testing-tool/' rel='bookmark' title='SAHI – Web Automation &amp; Application Security Testing Tool'>SAHI – Web Automation &amp; Application Security Testing Tool</a> <small>Sahi is an automation tool to test web applications. Sahi...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use Google Apps or Gmail? Avoid getting hacked!</title>
		<link>http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/</link>
		<comments>http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 03:23:09 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=121</guid>
		<description><![CDATA[It can happen to the best of us. Blogger and Techie Columnist, Amit Agarwal had his Google Apps account hacked this past week and wrote about it on his blog.  Amit has some good tips on how to avoid getting hacked , protect yourself  and improve the security of your online data. One can associate [...]]]></description>
			<content:encoded><![CDATA[<p>It can happen to the best of us. Blogger and Techie Columnist, Amit Agarwal had his <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> Apps account hacked this past week and wrote about it on his <a title="Google Apps Hacked" href="http://www.labnol.org/internet/gmail-and-google-apps-hacked/11799/" target="_blank"><strong>blog</strong></a>.  Amit has some good tips on how to avoid getting hacked , protect yourself  and improve the <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> of your online data. One can associate a Google account with a phone number and get an SMS when that password changes. If you aren&#8217;t already using this feature, you should.   He got his access restored in three hours but in many cases it takes much longer. It can be a terrifying experience to know that someone else has access to all your online data. One addition I would add to his list of tips is to install Google Gears which allows you to download all your emails to a local machine similar to an email client.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/23/google-pulls-out-of-china/' rel='bookmark' title='Google pulls out of China'>Google pulls out of China</a> <small>Is this a divorce or separation?  I chronicled Google&#8217;s dysfunctional...</small></li>
<li><a href='http://infosec3t.com/2010/01/25/botnets-give-the-hacker-espionage-tools-formerly-reserved-for-nation-states/' rel='bookmark' title='Botnets give the hacker espionage tools formerly reserved for nation states'>Botnets give the hacker espionage tools formerly reserved for nation states</a> <small>The cyber attacks against Google, Adobe and a raft of...</small></li>
<li><a href='http://infosec3t.com/2010/06/01/pause-your-google-history/' rel='bookmark' title='Pause your Google History'>Pause your Google History</a> <small>Have you ever used your Google search history? If you...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

