<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; News</title>
	<atom:link href="http://infosec3t.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>No National &#8216;Stand Your Cyberground&#8217; Law Please</title>
		<link>http://infosec3t.com/2012/05/10/no-national-stand-your-cyberground-law-please/</link>
		<comments>http://infosec3t.com/2012/05/10/no-national-stand-your-cyberground-law-please/#comments</comments>
		<pubDate>Thu, 10 May 2012 15:06:09 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[Defence]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2522</guid>
		<description><![CDATA[Patrick Lin, who is Assistant Professor and Director of Ethics and Emerging Science Group at California Polytechnic State University, penned  a thought provoking piece titled &#8216;Stand Your Cybergound&#8217; Law: A Novel Proposal for Digital Security in The Atlantic magazine in which he offers up a proposal allowing private industry to conduct cyber retaliation against foreign attackers. He rightly points [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2012/05/attack.jpeg"><img class="alignright size-full wp-image-2538" title="attack" src="http://infosec3t.com/wp-content/uploads/2012/05/attack.jpeg" alt="" width="272" height="185" /></a>Patrick Lin, who is Assistant Professor and Director of Ethics and Emerging Science Group at California Polytechnic State University, penned  a thought provoking piece titled <a title="'Stand Your Cybergound' Law: A Novel Proposal for Digital Security" href="http://www.theatlantic.com/technology/print/2012/04/stand-your-cyberground-law-a-novel-proposal-for-digital-security/256532/" target="_blank">&#8216;Stand Your Cybergound&#8217; Law: A Novel Proposal for Digital Security</a> in <em>The Atlantic</em> magazine in which he offers up a proposal allowing private industry to conduct cyber retaliation against foreign attackers. He rightly points out that a majority of cyber attacks against the United States or its interests are against private companies. It was reported just this week that the Department of Homeland Security  has sent out several alerts warning of a &#8220;gas pipeline sector cyber intrusion campaign&#8221; against multiple companies, which began earlier this year and is still under way. The face that companies are expected to fend for themselves is huge vulnerability in our national cyber defense. The Department of Defense protects military networks. The Department of Homeland Security defends other federal government networks. And everyone else is basically left to stand or fall on its own. It is the case  that there have been increased collaboration  between the public and private sectors in recent years. And the policy makers are looking at additional means for increased information sharing and collaboration. The  proposed Cyber Intelligence Sharing and Protection Act (CISPA) is one such effort. But if private company  is under attack, there is no calvary coming. Couple this with the fact that approximately 85% of the US critical infrastructure is owned and operated by private industry. It would take more that information sharing to adequately implement an effective national cyber defense. Our current cyber defense  is  mostly dependent on private for-profit companies making business decisions about how much to spend on their security overhead. That is certainly a recipe for disaster. It is imperative that government, business and academia join forces and develop better options for addressing this issue.</p>
<p>In the article, Lin writes, &#8220; <em>we may not be ready yet for the government to lead cyberdefense against foreign adversaries. To do so would trigger serious and unresolved [International humanitarian law] issues, including Geneva and Hague Conventions [which] requires that we take care in distinguishing combatants from noncombatants.</em>&#8221;</p>
<p>I would first draw a distinction between passive defense ( i.e. blocking attacker access, removing a vulnerability being exploited, etc ) and active defense ( i.e. launching a counter attack to disable the attackers capabilities).</p>
<p>All entities, government and private sector, are engaged in the former. Some more successfully than others. Some with greater effort than others. There are no legal or ethical questions there except a much broader sense . If gas pipelines are considered critical national infrastructure and these pipelines are owned and operated by private companies, should/can the government do more to defend them from attack? More than information sharing and increased collaboration, that is.</p>
<p>As to active defense, I have heard have seen proposals or discussions in security circles of the government launching counter cyber attacks against foreign adversaries on behalf of private companies. Lin&#8217;s proposal would create a legal framework that would allow the companies themselves to retaliate. He seems to find inspiration in the much talked about &#8221; stand your ground&#8221; laws such as the one in Florida that came to national attention as a it is reportedly invoked in the defense of the <a href="http://en.wikipedia.org/wiki/Shooting_of_Trayvon_Martin" target="_blank">fatal shooting an unarmed teenager by an armed neighborhood watch volunteer</a>.</p>
<p>Notwithstanding his references to armed citizens taming the wild, wild west. I find this proposal problematic on three fronts. From the purely cyber security perpective ,from a business perspective, and as a matter of national security policy. I&#8217;ll reiterate, in fairness, that Lin is not necessarily endorsing this as a solution, but contributing to a much needed discussion on nation cyber defense policy.</p>
<ul>
<li><strong>Security</strong>: In most cases, it is difficult to nearly impossible to ascertain the real identity of the attacker. Attackers use other compromised systems (victims) to launch attacks. Lin makes the point that &#8221; <em>There is a reasonable argument in claiming that a <a href="http://infosec3t.com/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> is not fully innocent and therefore not immune to harm.Most, if not all, botnets are made possible by negligence in applying security patches to <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a>, installing anti-<a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>, and using legally purchased and not pirated, vulberable copies of software</em>&#8220;. In other words, you allowed your systems to by hacked, so you deserve it if caught in a counter attack. I certainly agree that most reported successful attacks or breaches are a result of some degree of negligence. Most security professionals would agree that no system is immune to attack. We are trained to practice due diligence in making reasonable attempts to identify vulnerabilities and risk. You can never eliminate all risks all the time nor can you afford to mitigate all identified ones.</li>
</ul>
<ul>
<li><strong>Business</strong>: Typical business security incidence response practice includes: Detecting the attack, containing the damage, remediating effects of attack and gathering evidence, returning systems to normal and some follow-up. Lin&#8217;s proposal would require additional steps to gather sufficient forensic evidence to identify an actual perpetrator. He proposes allowing companies to present this evidence to some governmental body to review and sanction retaliation. Companies will then have to plan and execute the counter attack. Few companies have in-house expertise to do this. Few business managers will be willing to fund such activities. Whats the return? You get hacked from a $500 laptop and you spend $50,000 to do what exactly?</li>
</ul>
<ul>
<li><strong>National Security</strong>: We know for a fact some of the attacks on our private owned critical infrastructure have been attributed to foreign government affiliated networks. Would it really be wise to license private companies to attack these networks? I would think not. Most of these folks can&#8217;t even patch their servers or encrypt their sensitive data. The last think we need is an international incident started by some system administrator at some SMB. I mean a government allowing private entities to conduct cyber attacks against a foreign nation with a wink and a nod is not exactly a novel concept. Google &#8216;Russia Georgia <a href="http://infosec3t.com/tag/cyberwar/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cyberwar">Cyberwar</a>&#8221;.</li>
</ul>
<p>I commend Dr. Lin for his contribution to this very important discussion. I don&#8217;t necessarily agree with the proposed approach but as a nation, we really need to come to terms with how best to improve our national cyber defense as we are in dire straits.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
<li><a href='http://infosec3t.com/2010/02/18/we-really-need-to-start-taking-information-security-more-seriously/' rel='bookmark' title='We really need to start taking information security more seriously'>We really need to start taking information security more seriously</a> <small>From the Wall Street Journal: Hackers in Europe and China...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2012/05/10/no-national-stand-your-cyberground-law-please/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</title>
		<link>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/</link>
		<comments>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/#comments</comments>
		<pubDate>Sun, 23 Jan 2011 18:33:15 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Users]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2397</guid>
		<description><![CDATA[Across all industries, small businesses are increasingly facing new threats related to cyber security. Whereas some have taken minimum steps to address these threats but most have not. New security threats and incidents are reported every day in news reports and a many remain unreported. This underscores the need for cyber security education of small [...]]]></description>
			<content:encoded><![CDATA[<p>Across all industries, small businesses are increasingly facing new threats related to cyber <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>. Whereas some have taken minimum steps to address these threats but most have not. New <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> threats and incidents are reported every day in news reports and a many remain unreported. This underscores the need for cyber <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> education of small business owners and managers. These threats have potentially serious consequences and could lead to unrecoverable damage to small businesses.</p>
<p><strong>What are some consequences of the lack of basic cyber security controls?</strong></p>
<ul>
<li>Loss or stolen customer data<a href="http://infosec3t.com/wp-content/uploads/2011/01/logolarge.jpg"><img class="alignright size-medium wp-image-2398" title="SMB Cyber Security Alliance" src="http://infosec3t.com/wp-content/uploads/2011/01/logolarge-300x108.jpg" alt="" width="270" height="97" /></a></li>
<li>Loss of intellectual property</li>
<li>Decreased productivity</li>
<li>Legal liability</li>
<li>Regulatory sanctions and fines</li>
<li>Computer systems downtime</li>
<li>Loss of reputation and customer confidence</li>
<li>Loss of revenue</li>
<li>Banking Fraud</li>
</ul>
<p><strong>Could this happen to you?</strong></p>
<p>It is very important to understand that neither size nor industry guarantees protection from an attack. The use of computer systems and the Internet makes you vulnerable to attacks and other threats.</p>
<p>A 2010 survey conducted by the Ponemon Institute and Guardian Analytics of over 500 SMBs surfaced these alarming statistics:</p>
<ul>
<li><strong>55%</strong> experienced a fraud attack in the last year</li>
<li><strong>58%</strong> of the incidents involved <a href="http://infosec3t.com/tag/online-banking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with online banking">online banking</a></li>
<li>Over <strong>50%</strong> experienced multiple incidents</li>
<li><strong>87%</strong> failed to fully recover lost funds</li>
</ul>
<p><strong>You are not a big, well known business. Why would anyone attack you?</strong></p>
<p>While it might be the case that well trained hackers are not very interested in your small company, most online attacks aren&#8217;t carried out by expert hackers. Attacks are perpetrated by low-skilled, common criminals with access to pre-packaged hacking tools, thereby casting a wide net in hopes of finding an unprotected computer system or network. These tools are easy to use and readily available on the Internet, often times free of charge. The anonymity of a cyber attack makes it even more attractive to criminals. Many attackers use safe havens in foreign countries which do not have strong cyber crime laws.</p>
<p>Malicious software like viruses, worms, trojan horses, spam, bots are all vectors of cyber attacks that are indiscriminately spreading across the Internet. These attacks don&#8217;t only target your small business computer systems but also seek to use your unprotected systems to launch attack on others.</p>
<p><strong>Hasn&#8217;t IT guy(s) already dealt with this issue?</strong></p>
<p>Although cyber security includes traditional &#8220;IT&#8221;related issues, it primarily focuses on protecting your valuable information from all threats including physical attacks, data corruption, equipment failure, <a href="http://infosec3t.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">social engineering</a>, and bad security choices due to insufficient security awareness education. Effective cyber security management requires specific training related to threats, vulnerabilities, and risks affecting computer systems, business operational processes, and most importantly you and your employees. One&#8217;s security problems cannot be addressed solely by off the shelf products. Security must be addressed in the boardroom before it is addressed in the computer room.</p>
<p><strong>What are the benefits and cost of cyber security?</strong></p>
<p>Besides avoiding some of the devastating consequences mentioned earlier, good security is simply good business. It does far more than increase customer confidence and protects the integrity of your businesses brand. A secure business increases customer confidence, loyalty and adds to the businesses bottom line.</p>
<p>Responsible businesses understand that risk management mandates that all threats, including cyber threats, be assessed and managed to protect the business, employees and customers.</p>
<p>The potential cost of inaction far outweighs the cost of action. Analyzing your businesses risks allows you to weigh the costs and benefits and make informed decisions.</p>
<p><strong>Where do you start? Where can you get help?</strong></p>
<p>Although improving your security may seem a daunting task, it doesn&#8217;t have to be. Increasing cyber security awareness helps small and medium sized businesses proactively implement simple best practices to protect their businesses. Security should be built into your business processes, information technology (IT), and most importantly your employees and contractors. Each business is unique and faces challenges particular to their operations. There is no magic pill that guarantees 100% security. The SMB Cyber Security Alliance have security experts available to help you understand your unique risks and implement solutions that work your your particular business environment.</p>
<p><strong>Visit us today and sign up for your free membership at http://www.smbcybersecurity.org</strong></p>
<p>The SMB Cyber Security Alliance is volunteer-run organization seeking to increase cyber security awareness in small business communities through education, awareness training, free resources and consultations, and active engagements between small business owners and local security professionals.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/08/defend-your-small-business-against-online-bank-fraud/' rel='bookmark' title='Defend your Small Business against Online Bank Fraud'>Defend your Small Business against Online Bank Fraud</a> <small>Is your banking practices putting your business at risk? Protect...</small></li>
<li><a href='http://infosec3t.com/2010/07/08/security-on-a-shoestring-smb-budget/' rel='bookmark' title='Security On A Shoestring SMB Budget'>Security On A Shoestring SMB Budget</a> <small>The e-mail appeared to be an invitation from an old,...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/facebook-poses-biggest-security-threat-to-businesses/' rel='bookmark' title='Facebook poses biggest security threat to businesses'>Facebook poses biggest security threat to businesses</a> <small>According to it&#8217;s  Security Threats 2010 report published today, security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government Involvement in Cyber war in the last year</title>
		<link>http://infosec3t.com/2010/08/10/government-involvement-in-cyber-war-in-the-last-year/</link>
		<comments>http://infosec3t.com/2010/08/10/government-involvement-in-cyber-war-in-the-last-year/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 22:07:12 +0000</pubDate>
		<dc:creator>securnetworks</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2312</guid>
		<description><![CDATA[Related posts: Facebook poses biggest security threat to businesses According to it&#8217;s  Security Threats 2010 report published today, security... Twitter users hit hard by &#34;LOL&#34; phishing attack IT security and data protection firm Sophos is warning that... Top ten malware-hosting countries revealed US and UK among the top 10 countries hosting the...]]></description>
			<content:encoded><![CDATA[<div id="attachment_2311" class="wp-caption aligncenter" style="width: 576px"><img class="size-full wp-image-2311       " title="Governments and Cyber Crime" src="http://infosec3t.com/wp-content/uploads/2010/08/ScreenHunter_01-Aug.-10-16.35.gif" alt="" width="566" height="371" /><p class="wp-caption-text">sophos-<a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>-<a href="http://infosec3t.com/tag/threat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threat">threat</a>-report-midyear-2010-wpna.pdf</p></div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/01/facebook-poses-biggest-security-threat-to-businesses/' rel='bookmark' title='Facebook poses biggest security threat to businesses'>Facebook poses biggest security threat to businesses</a> <small>According to it&#8217;s  Security Threats 2010 report published today, security...</small></li>
<li><a href='http://infosec3t.com/2010/02/22/1572/' rel='bookmark' title='Twitter users hit hard by &quot;LOL&quot; phishing attack'>Twitter users hit hard by &quot;LOL&quot; phishing attack</a> <small>IT security and data protection firm Sophos is warning that...</small></li>
<li><a href='http://infosec3t.com/2010/02/03/top-ten-malware-hosting-countries-revealed/' rel='bookmark' title='Top ten malware-hosting countries revealed'>Top ten malware-hosting countries revealed</a> <small>US and UK among the top 10 countries hosting the...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/08/10/government-involvement-in-cyber-war-in-the-last-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google pulls out of China</title>
		<link>http://infosec3t.com/2010/03/23/google-pulls-out-of-china/</link>
		<comments>http://infosec3t.com/2010/03/23/google-pulls-out-of-china/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 16:18:49 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1984</guid>
		<description><![CDATA[Is this a divorce or separation?  I chronicled Google&#8217;s dysfunctional marriage to China last month. This week Google shut down its search service on the Chinese mainland last night after a two-month standoff with Beijing over censorship and the much talked about hacking incident. Google.cn now redirects visitors to google.com.hk – where they are greeted [...]]]></description>
			<content:encoded><![CDATA[<p>Is this a divorce or separation?  I chronicled <a href="http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/"><strong>Google&#8217;s dysfunctional marriage to China</strong></a> last month. This week <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> shut down its search service on the Chinese mainland last night after a two-month standoff with Beijing over censorship and the much talked about <a href="http://infosec3t.com/tag/hacking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hacking">hacking</a> incident.</p>
<p><img class="alignright size-full wp-image-710" title="google" src="http://infosec3t.com/wp-content/uploads/2010/01/google.jpg" alt="" width="106" height="40" />Google.cn now redirects visitors to google.com.hk – where they are greeted by a message reading: &#8220;Welcome to Google search in China&#8217;s new home.&#8221;</p>
<p>The move allowed Google to stop self-censoring the service, although the government&#8217;s filtering system would still prevent mainland users from seeing the results of many &#8220;politically sensitive&#8221; searches.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
<li><a href='http://infosec3t.com/2010/03/24/hacker-updates-woman-facebook-status/' rel='bookmark' title='Hacker Updates Woman Facebook Status'>Hacker Updates Woman Facebook Status</a> <small>Here&#8217;s an interesting story. Who didn&#8217;t see this coming? &#8220;Police...</small></li>
<li><a href='http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/' rel='bookmark' title='Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;'>Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;</a> <small>Talk about throwing out the baby with the bath water....</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/23/google-pulls-out-of-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer 9 &quot;Preview&quot; Now Available</title>
		<link>http://infosec3t.com/2010/03/17/internet-explorer-9-preview-now-available/</link>
		<comments>http://infosec3t.com/2010/03/17/internet-explorer-9-preview-now-available/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 22:31:47 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1927</guid>
		<description><![CDATA[Microsoft has released a preview of the new version of Internet Explorer, IE 9.It can be downloaded  from http://ie.microsoft.com/testdrive/Default.html. I&#8217;m sure we will soon start seeing phishing emails and malicious sites being set up around this so if you are interested, be sure to download it from the REAL Microsoft, huh. Not impressed? Here&#8217;s Microsoft&#8217;s response, [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-757" title="IE" src="http://infosec3t.com/wp-content/uploads/2010/01/IE1.jpg" alt="" width="111" height="111" />Microsoft has released a preview of the new version of <a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a>, IE 9.It can be downloaded  from <a href="http://ie.microsoft.com/testdrive/Default.html" target="_blank">http://ie.microsoft.com/testdrive/Default.html</a>.</p>
<p>I&#8217;m sure we will soon start seeing <a href="http://infosec3t.com/tag/phishing-users/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Phishing">phishing</a> emails and malicious sites being set up around this so if you are interested, be sure to download it from the REAL Microsoft, huh.</p>
<p>Not impressed? Here&#8217;s Microsoft&#8217;s response, or should I call it a <em>presponse</em>.</p>
<p>&#8220;The Platform Preview is an early look at the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> Explorer 9 platform so some features are incomplete, some may change, and some may be added&#8230;..We ask that you refrain from providing feedback on features where noted that they are either partially implemented or not available. We are aware of their condition and will provide updates in future releases. Similarly, for known issues, we are aware of their existence and are actively working on them. Thank you for your interest in the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> Explorer Platform Preview!&#8221;</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/19/france-germany-warn-users-against-internet-explorer/' rel='bookmark' title='France, Germany warn users against Internet Explorer'>France, Germany warn users against Internet Explorer</a> <small>France and Germany have warned web users against using ALL...</small></li>
<li><a href='http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/' rel='bookmark' title='Microsoft warns of new IE bug being exploited by hackers'>Microsoft warns of new IE bug being exploited by hackers</a> <small>Microsoft Corp. today warned of a critical vulnerability in Internet...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/' rel='bookmark' title='Microsoft offering choice of browser to users in Europe'>Microsoft offering choice of browser to users in Europe</a> <small>Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221;...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/17/internet-explorer-9-preview-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft warns of new IE bug being exploited by hackers</title>
		<link>http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/</link>
		<comments>http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 01:11:14 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1826</guid>
		<description><![CDATA[Microsoft Corp. today warned of a critical vulnerability in Internet Explorer that is already being exploited by hackers; it was the company&#8217;s second such admission in the past two months. Internet Explorer 6 and its 2006 successor, IE7, contain a vulnerability that can be used by attackers to inject malicious code into a Windows PC. [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-757" title="IE" src="http://infosec3t.com/wp-content/uploads/2010/01/IE1.jpg" alt="" width="111" height="111" />Microsoft Corp. today warned of a critical vulnerability in <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> Explorer that is already being exploited by hackers; it was the company&#8217;s second such admission in the past two months.</p>
<p><a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a> 6 and its 2006 successor, IE7, contain a vulnerability that can be used by attackers to inject malicious code into a Windows PC. The oldest and newest of Microsoft&#8217;s supported browsers, IE 5.01 and IE8, respectively, are not vulnerable to such attacks.</p>
<p>&#8220;At this time, we are aware of targeted attacks attempting to use this vulnerability,&#8221; Microsoft acknowledged in an <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx" target="_blank">advisory</a> posted simultaneously with two <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> <a href="http://infosec3t.com/tag/updates/" class="st_tag internal_tag" rel="tag" title="Posts tagged with updates">updates</a> that patched eight bugs in Windows and Office. Elsewhere, Microsoft said that the vulnerability had been publicly disclosed.</p>
<p>Source: http://www.computerworld.com/s/article/9168138/Microsoft_warns_of_new_IE_bug_attacks_under_way</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/' rel='bookmark' title='Many companies caught in the lurch as Microsoft ends support for Windows XP 2'>Many companies caught in the lurch as Microsoft ends support for Windows XP 2</a> <small>On July 13, Microsoft will officially retire Windows XP Service...</small></li>
<li><a href='http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/' rel='bookmark' title='Aaaah The Infamous Blue Screen of Death'>Aaaah The Infamous Blue Screen of Death</a> <small>On Tuesday, Microsoft issued a patch, MS10-015,  to fix a...</small></li>
<li><a href='http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/' rel='bookmark' title='Microsoft resumes pushing Blue Screen Update'>Microsoft resumes pushing Blue Screen Update</a> <small>Microsoft has resumed pushing out the patch connected to the...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter makes security enhancements to help users</title>
		<link>http://infosec3t.com/2010/03/11/twitter-makes-security-enhancements-to-help-users/</link>
		<comments>http://infosec3t.com/2010/03/11/twitter-makes-security-enhancements-to-help-users/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 23:09:06 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1821</guid>
		<description><![CDATA[Twitter has added a new service that detects malicious URLs in an effort to quell the rise in spam and phishing on the microblogging social network. I previously did a post about the risk posed by url shorteners. The new security feature ultimately will scan all URLs before they hit the Twitter feed, but initially [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-969" title="twitter" src="http://infosec3t.com/wp-content/uploads/2010/01/twitter.jpg" alt="" width="122" height="122" /><a href="http://infosec3t.com/tag/twitter/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Twitter">Twitter</a> has added a new service that detects malicious URLs in an effort to quell the rise in <a href="http://infosec3t.com/tag/spam/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spam">spam</a> and phishing on the microblogging social network. I previously did a <strong><a href="http://infosec3t.com/2010/01/09/brevity-is-the-soul-of-getting-yourself-infected-with-all-kinds-of-nasties/">post</a></strong> about the <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> posed by url shorteners.</p>
<p>The new <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> feature ultimately will scan all URLs before they hit the Twitter feed, but initially is only doing so for URLs sent via Twitter direct messages [DMs] and email notifications about DMs. Twitter is using its own URL shortener for these links: &#8220;For the most part, you will not notice this feature because it works behind the scenes but you may notice links shortened to twt.tl in Direct Messages and email notifications,&#8221; said Del Harvey, Twitter&#8217;s director of trust and safety, in a blog post last night.</p>
<p>Twitter&#8217;s security feature comes amid new data revealing the level of abuse on the social network: One in eight Twitter accounts last year was malicious, suspicious, or suspended, according to a report issued today by Barracuda Networks. The surge in celebrities joining Twitter in 2009 resulted in a major jump in spam, phishing, and other abuse on the site, according to the report.</p>
<p>Read more: <a href="http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=223400097&amp;cid=RSSfeed" target="_blank">http://www.darkreading.com/securityservices/security/attacks</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/04/how-to-limit-twitter-risks/' rel='bookmark' title='How to limit Twitter risks'>How to limit Twitter risks</a> <small>Twitter is now used by over 350 million people worldwide....</small></li>
<li><a href='http://infosec3t.com/2010/02/22/1572/' rel='bookmark' title='Twitter users hit hard by &quot;LOL&quot; phishing attack'>Twitter users hit hard by &quot;LOL&quot; phishing attack</a> <small>IT security and data protection firm Sophos is warning that...</small></li>
<li><a href='http://infosec3t.com/2009/12/07/facebook-and-twitter/' rel='bookmark' title='Facebook and Twitter'>Facebook and Twitter</a> <small>I have never found much use for social networking sites...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/11/twitter-makes-security-enhancements-to-help-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft resumes pushing Blue Screen Update</title>
		<link>http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/</link>
		<comments>http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 15:08:18 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1714</guid>
		<description><![CDATA[Microsoft has resumed pushing out the patch connected to the recent Windows blue screens. Microsoft concluded that the system crashes with due to a rootkit [named Alureon] infecting the users computers. The company  issued a scanning tool users can run to determine whether their PCs are infected  before they attempt to download and install MS10-015. The [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1528" title="BILL-GATES-bsod" src="http://infosec3t.com/wp-content/uploads/2010/02/BILL-GATES-bsod-300x206.jpg" alt="" width="218" height="150" /><a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> has resumed pushing out the patch connected to the recent <strong><a title="Recent Microsoft Update BSOD may be caused by Rootkit" href="http://infosec3t.com/2010/02/15/recent-microsoft-update-bsod-may-be-caused-by-rootkit/">Windows blue screens</a></strong>. Microsoft concluded that the system crashes with due to a rootkit [named Alureon] infecting the users computers. The company  issued a <a href="http://support.microsoft.com/kb/980966" target="_blank">scanning tool</a> users can run to determine whether their PCs are infected  before they attempt to download and install MS10-015. The <a href="http://infosec3t.com/tag/tool/" class="st_tag internal_tag" rel="tag" title="Posts tagged with tool">tool</a> doesn&#8217;t scrub Alureon from a compromised computer, but only determines whether the system is compatible with the patch.</p>
<p>Microsoft has not yet delivered a promised detect-and-destroy tool that will clean infected PCs. In the past, Microsoft has used its Malicious <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">Software</a> Removal Tool (MSRT), a free program updated each Patch Tuesday, to seek out and destroy rootkits. The next scheduled refresh of the MSRT is March 9.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/' rel='bookmark' title='Aaaah The Infamous Blue Screen of Death'>Aaaah The Infamous Blue Screen of Death</a> <small>On Tuesday, Microsoft issued a patch, MS10-015,  to fix a...</small></li>
<li><a href='http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/' rel='bookmark' title='Trojan Pretends to Be Microsoft Security Suite'>Trojan Pretends to Be Microsoft Security Suite</a> <small>Microsoft is warning users that a Trojan is masquerading as...</small></li>
<li><a href='http://infosec3t.com/2010/02/15/recent-microsoft-update-bsod-may-be-caused-by-rootkit/' rel='bookmark' title='Recent Microsoft Update BSOD may be caused by Rootkit'>Recent Microsoft Update BSOD may be caused by Rootkit</a> <small>Last week, I posted here about the recent pandemic of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft says Do Not Call for Help!</title>
		<link>http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/</link>
		<comments>http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 19:22:05 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1707</guid>
		<description><![CDATA[If it sounds like a horror movie&#8230;.well, that&#8217;s because is really is. Microsoft is reporting yet another Internet Explorer bug. In the latest episode of this never-ending saga, there is an unpatched bug in VBScript that hackers can use to drop malware on 32-bit Windows XP machines running IE 7 and 8. I know what [...]]]></description>
			<content:encoded><![CDATA[<p>If it sounds like a horror movie&#8230;.well, that&#8217;s because is really is. <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> is reporting yet another <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> Explorer bug.</p>
<p><img class="size-full wp-image-1708 alignright" title="the-f1-key-represents-help-or-assistance-thumb12300398" src="http://infosec3t.com/wp-content/uploads/2010/03/the-f1-key-represents-help-or-assistance-thumb12300398.jpg" alt="" width="218" height="147" />In the latest episode of this never-ending saga, there is an unpatched bug in VBScript that hackers can use to drop <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a> on 32-bit Windows XP machines running IE 7 and 8. I know what you are saying: &#8221; But we told them to upgrade from the nine year old IE6! &#8221;</p>
<p>According to <a href="http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx" target="_blank">Microsoft&#8217;s Senior Security Communications Manager Lead Jerry Bryant</a>, an exploit &#8220;was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 [or help] key in response to a pop up dialog box.&#8221;</p>
<p>Is it time to change your browser? <strong><a title="Microsoft offering choice of browser to users in Europe" href="http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/">Maybe the EU has it right. </a></strong></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/' rel='bookmark' title='If Microsoft can do it, why not McAfee?'>If Microsoft can do it, why not McAfee?</a> <small>Yesterday, a faulty McAfee anti-virus update labeled a critical Microsoft...</small></li>
<li><a href='http://infosec3t.com/2010/04/11/ikea-facebook-scam-cons-40000-users-2/' rel='bookmark' title='IKEA Facebook scam cons 40,000 users'>IKEA Facebook scam cons 40,000 users</a> <small>These types of attacks have become the norm on Facebook. ...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>United States Department of Defense Embraces Hacker Certification</title>
		<link>http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/</link>
		<comments>http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 22:45:09 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1698</guid>
		<description><![CDATA[Mar 01, 2010 – The U.S. Department of Defense (DoD) announces the official approval of the  EC-Council Certified Ethical Hacker (CEH) certification program as a new baseline skills requirement for U.S.cyber defenders. Specifically, the new Certified Ethical Hacker program is required for the DoD&#8217;s computer network defenders (CND&#8217;s), a specialized personnel classification within the DoD&#8217;s information [...]]]></description>
			<content:encoded><![CDATA[<p><em>Mar 01, 2010</em> – The U.S. Department of Defense (DoD) announces the official approval of the  EC-Council <strong><a title="CEH Prep" href="http://infosec3t.com/certifications/buy-ceh-prep/">Certified Ethical Hacker </a></strong><a title="CEH Prep" href="http://infosec3t.com/certifications/buy-ceh-prep/">(CEH)</a> certification program as a new baseline skills requirement for U.S.cyber defenders. Specifically, the new Certified Ethical Hacker program is required for the DoD&#8217;s computer network defenders (CND&#8217;s), a specialized personnel classification within the DoD&#8217;s information assurance workforce.</p>
<p>The Certified Ethical Hacker requirement falls under the auspices of DoD Directive 8570 Information Assurance Workforce Improvement Program. The current version (incorporating Change 2) was signed by Assistant Secretary of Defense, John G. Grimes and was officially instated on February 25, 2010. Directive 8570 provides clear guidance to information assurance training, certification and workforce management across all components of the DoD.</p>
<p>The CND groups protect, monitor, analyze, detect, and respond to unauthorized activity within DoD information systems and computer networks.</p>
<p>With this directive, military service, contractors, and foreign employees across all job descriptions must show 100-percent compliance with the new Certified Ethical Hacker training requirement by 2011. This shows the DoD&#8217;s focus on better training and preparation of the U.S. military workforce in this area.</p>
<p>The Certified Ethical Hacker qualification tests the certification holder&#8217;s knowledge in the mindset, tools and techniques of a hacker, fortifying it&#8217;s certification tag line: &#8220;To beat a hacker, you must think like one.&#8221;</p>
<p>&#8220;CEH has been selected due to the immense technical and tactical nature of the certification,&#8221;</p>
<div id="bd">
<p>said Jay Bavisi, co-founder and president of EC-Council. &#8220;It is one of the most technically advanced certifications on the directive for CND professionals. In fact, it is the only certification approved across four out of the five categories to prepare the CND teams. While other policy-based programs add value, CEH prepares the U.S. CNDs to combat hackers in real time, defending U.S. interests globally.&#8221;</p>
<p>Bavisi added: &#8220;We have been researching this space for quite some time and with this mandate from the DoD, there has never been a better time for us to beat the hackers at their own game. We are racing to research complex hacker techniques and in the next release of our CEH program, we hope to showcase in over 150 modules, detailed and extremely complex attack and countermeasures that will help raise the level of knowledge of the CND teams.&#8221;</p>
<p>KEY FACTS:<br />
·   CEH is now formally integrated into the certification requirements for U.S. DoD IA Workforce<br />
·   CEH is now required for CND Analyst, CND Infrastructure Support, CND Incident Responder, and CND Auditor as defined by<br />
Directive 8570<br />
·   Newly revised DoD 8570 is available at <a href="http://www.dtic.mil/whs/directives/corres/pdf/857001m.pdf" target="_blank">http://www.dtic.mil/whs/directives/corres/pdf/857001m.pdf</a><br />
·   More information about EC-Council and Directive 8570 can be found at https://www.eccouncil.org/about_us/dod_8570.aspx</p>
</div>
<p><!-- google_ad_section_end --># # #</p>
<p>The International Council of E-Commerce Consultants (EC-Council) is a member-based organization that certifies individuals in various e-business and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> skills. It is the owner and developer of the world famous Certified Ethical Hacker course, Computer <a href="http://infosec3t.com/tag/hacking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hacking">Hacking</a> Forensics Investigator program, License Penetration Tester program and various other programs offered in over 60 countries around the globe. These certifications are recognized worldwide and have received endorsements from various government agencies including the US Federal Government via the Montgomery GI Bill, and the US Government National Security Agency (NSA) and the Committee on National Security Systems (CNSS). For more information about EC-Council, please visit the website: <a href="http://www.eccouncil.org/" target="_blank">http://www.eccouncil.org</a></p>
<p>Source: http://www.prlog.org/10553483-united-states-department-of-defense-embraces-hacker-certification-to-protect-us-interests.html</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/25/botnets-give-the-hacker-espionage-tools-formerly-reserved-for-nation-states/' rel='bookmark' title='Botnets give the hacker espionage tools formerly reserved for nation states'>Botnets give the hacker espionage tools formerly reserved for nation states</a> <small>The cyber attacks against Google, Adobe and a raft of...</small></li>
<li><a href='http://infosec3t.com/2010/01/28/hacker-cracks-49-house-sites-insults-obama/' rel='bookmark' title='Hacker cracks 49 House sites, insults Obama'>Hacker cracks 49 House sites, insults Obama</a> <small>It must be the season. A hacker broke into 49...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/hacker-who-unlocked-iphone-breaks-into-playstation-3/' rel='bookmark' title='Hacker who unlocked iPhone breaks into PlayStation 3'>Hacker who unlocked iPhone breaks into PlayStation 3</a> <small>The hacker who managed to break into the iPhone has...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft offering choice of browser to users in Europe</title>
		<link>http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/</link>
		<comments>http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 16:44:55 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1692</guid>
		<description><![CDATA[Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221; following a ruling by the European Commission that Microsoft&#8217;s practice of pre-installing Internet Explorer on every new computer was anti-competitive. The Commission accepted Microsoft’s offer of rolling out the ballot box across its range of Windows machines, which it believes will make it easier for [...]]]></description>
			<content:encoded><![CDATA[<p><strong> </strong>Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221; following a    ruling by the European Commission that Microsoft&#8217;s practice of    pre-installing Internet Explorer on every new computer was anti-competitive.    The Commission accepted Microsoft’s offer of rolling out the ballot box    across its range of <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> machines, which it believes will make it easier    for computer users to choose an alternative browser to Internet Explorer. See ballot below:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1693" title="Browser-Ballot-Scr_1539038c" src="http://infosec3t.com/wp-content/uploads/2010/03/Browser-Ballot-Scr_1539038c.jpg" alt="" width="460" height="288" /></p>
<p>The ballot box will be pushed to Windows users running XP, Vista and Windows    7, via an automatic <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> update, and will only be shown to computer    users who are not already running a different default browser. The list of offered browsers are:</p>
<p>* <strong><a href="http://www.avantbrowser.com/" target="_blank">Avant</a></strong><br />
* <strong><a href="http://www.google.co.uk/chrome" target="_blank">Google Chrome</a></strong><br />
* <strong><a href="http://www.mozilla.com/firefox/" target="_blank">Mozilla Firefox</a></strong><br />
* <strong><a href="http://www.flock.com/" target="_blank">Flock</a></strong><br />
* <strong>GreenBrowser</strong><br />
* <strong><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx" target="_blank">Internet    Explorer</a></strong><br />
* <strong><a href="http://kmeleon.sourceforge.net/" target="_blank">K-meleon</a></strong><br />
* <strong><a href="http://www.maxthon.com/" target="_blank">Maxthon</a></strong><br />
* <strong><a href="http://www.opera.com/" target="_blank">Opera</a></strong><br />
* <strong><a href="http://www.apple.com/safari/" target="_blank">Apple Safari</a></strong><br />
* <strong><a href="http://www.fenrir-inc.com/global/" target="_blank">Sleipnir</a></strong><br />
* <strong><a href="http://www.flashpeak.com/sbrowser/" target="_blank">SlimBrowser</a></strong></p>
<p>I&#8217;m not sure how I feel about this. Competition is always good however users savvy enough to care already know they can download and run any of these browsers. I agree with Microsoft on the point that this will just add to the confusion of many users.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/' rel='bookmark' title='Microsoft warns of new IE bug being exploited by hackers'>Microsoft warns of new IE bug being exploited by hackers</a> <small>Microsoft Corp. today warned of a critical vulnerability in Internet...</small></li>
<li><a href='http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/' rel='bookmark' title='Microsoft says Do Not Call for Help!'>Microsoft says Do Not Call for Help!</a> <small>If it sounds like a horror movie&#8230;.well, that&#8217;s because is...</small></li>
<li><a href='http://infosec3t.com/2010/01/19/france-germany-warn-users-against-internet-explorer/' rel='bookmark' title='France, Germany warn users against Internet Explorer'>France, Germany warn users against Internet Explorer</a> <small>France and Germany have warned web users against using ALL...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft to drop support for Vista and XP SP2</title>
		<link>http://infosec3t.com/2010/03/01/microsoft-to-drop-support-for-vista-and-xp-sp2/</link>
		<comments>http://infosec3t.com/2010/03/01/microsoft-to-drop-support-for-vista-and-xp-sp2/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 16:07:52 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1688</guid>
		<description><![CDATA[Microsoft will drop support for Vista (without any Service Packs) on April 13 and support for XP SP2 ends July 13. (i.e. no more security updates). If you are still running these, it it time to update. Related posts: CISSP All In One Book FIFTH EDITION has been released The fifth edition of this best-selling [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> will drop support for Vista (without any Service Packs) on April 13 and support for XP SP2 ends July 13. (i.e. no more <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> <a href="http://infosec3t.com/tag/updates/" class="st_tag internal_tag" rel="tag" title="Posts tagged with updates">updates</a>). If you are still running these, it it time to update.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/01/microsoft-to-drop-support-for-vista-and-xp-sp2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of Chile Earthquake Scams</title>
		<link>http://infosec3t.com/2010/02/28/beware-of-chile-earthquake-scams/</link>
		<comments>http://infosec3t.com/2010/02/28/beware-of-chile-earthquake-scams/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 02:18:43 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Users]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1674</guid>
		<description><![CDATA[An 8.8 magnitude earthquake struck Santiago, Chile in the early hours of February 27th. Tsunami warnings, encompassing most of the Pacific Ocean, soon followed. These types of breaking news events often spur a surge in social engineering scams which exploit interest in the events. Commonly, scam artists might seed search engine results (particularly sponsored ads) [...]]]></description>
			<content:encoded><![CDATA[<div id="abw">
<div id="abm">
<div id="abc">
<div id="articlebody">
<div>
<p>An 8.8 magnitude earthquake struck Santiago, Chile in the early hours of February 27th. Tsunami warnings, encompassing most of the Pacific Ocean, soon followed. These types of breaking news events often spur a surge in <a href="http://infosec3t.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">social engineering</a> <a href="http://infosec3t.com/tag/scams/" class="st_tag internal_tag" rel="tag" title="Posts tagged with scams">scams</a> which exploit interest in the events.</p>
<p>Commonly, scam artists might seed search engine results (particularly sponsored ads) with bogus links that point to scareware sites. These can appear for any search on keywords such as Chile earthquake, Tsunami, etc. The best way to avoid such scams is to avoid clicking on links that point to unfamiliar sites. In particular, avoid donating charitable funds via unfamiliar sites or as a result of a solicitation received via <a href="http://infosec3t.com/tag/email-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Email">email</a>, Twitter, instant message, Facebook, or other social networking medium.</p>
<p><a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> has prepared a fully vetted information site for the Chilean earthquake, including relief efforts and reputable disaster relief funds:<a href="http://www.google.com/relief/chileearthquake/" target="_blank">http://www.google.com/relief/chileearthquake/</a>.</p>
<p>Source: <a href="http://antivirus.about.com/b/2010/02/27/be-on-alert-for-chile-earthquake-scams.htm" target="_blank">http://antivirus.about.com/b/2010/02/27/be-on-alert-for-chile-earthquake-scams.htm</a></p>
</div>
</div>
</div>
</div>
</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/' rel='bookmark' title='Beware of Haiti-Themed Scams and Attacks!'>Beware of Haiti-Themed Scams and Attacks!</a> <small>Our thoughts and prayers go out to all those affected...</small></li>
<li><a href='http://infosec3t.com/2010/02/10/irs-reminds-you-not-to-go-phishing-this-tax-season/' rel='bookmark' title='IRS reminds you not to go Phishing this tax season'>IRS reminds you not to go Phishing this tax season</a> <small>It&#8217;s tax time again and IRS phishing scams are alive...</small></li>
<li><a href='http://infosec3t.com/2009/12/17/show-me-the-malware-says-google/' rel='bookmark' title='&quot;Show me the malware&quot;- says Google'>&quot;Show me the malware&quot;- says Google</a> <small>A fews weeks ago, I had a discussion with a...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/28/beware-of-chile-earthquake-scams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan Pretends to Be Microsoft Security Suite</title>
		<link>http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/</link>
		<comments>http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 01:30:38 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1628</guid>
		<description><![CDATA[Microsoft is warning users that a Trojan is masquerading as the company&#8217;s popular free Microsoft Security Essentials package. &#8220;One of the oldest tricks used by rogue antivirus products is to use a similar name as, or have a similar look and feel to, legitimate security software,&#8221; Microsoft said in a post on the MMPC&#8217;s Threat [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1629" title="microsoft-security-essential" src="http://infosec3t.com/wp-content/uploads/2010/02/windowslivewriterdownloadandtestmicrosoftsecurityessentia-acacmicrosoft-security-essential-morro1-300x235.png" alt="" width="273" height="214" /><a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> is warning users that a Trojan is masquerading as the company&#8217;s popular free <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> Security Essentials package.</p>
<p>&#8220;One of the oldest tricks used by rogue <a href="http://infosec3t.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Antivirus">antivirus</a> products is to use a similar name as, or have a similar look and feel to, legitimate security software,&#8221; Microsoft said in a post on the MMPC&#8217;s Threat Research &amp; Response Blog. &#8220;So it was inevitable that the day would arrive when a rogue would masquerade as something similar to Microsoft Security Essentials.&#8221;<!--googleoff: all--><!--googleon: all--></p>
<p>The masquerading rogue security tool goes by the name Security Essentials 2010, which is very similar to the actual name of Microsoft&#8217;s suite, though the real suite does not have a date in its name.</p>
<p>Read full story: <a href="http://www.esecurityplanet.com/features/article.php/3867556/Trojan-Pretends-to-Be-Microsoft-Security-Suite.htm" target="_blank">http://www.esecurityplanet.com/features/article.php/3867556/Trojan-Pretends-to-Be-Microsoft-Security-Suite.htm</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/08/5-open-source-alternatives-to-microsoft-office/' rel='bookmark' title='5 Open Source Alternatives to Microsoft Office'>5 Open Source Alternatives to Microsoft Office</a> <small>The Microsoft Office productivity suite has risen to become the...</small></li>
<li><a href='http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/' rel='bookmark' title='Microsoft resumes pushing Blue Screen Update'>Microsoft resumes pushing Blue Screen Update</a> <small>Microsoft has resumed pushing out the patch connected to the...</small></li>
<li><a href='http://infosec3t.com/2010/03/17/another-fake-security-software-alert/' rel='bookmark' title='Another fake security software alert'>Another fake security software alert</a> <small>I&#8221;ve previously warned of fake security software or scareware. Here&#8217;s...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on Secure Online Banking</title>
		<link>http://infosec3t.com/2010/02/26/more-on-secure-online-banking/</link>
		<comments>http://infosec3t.com/2010/02/26/more-on-secure-online-banking/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 19:00:13 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1620</guid>
		<description><![CDATA[As a follow up to my previous post on online banking security products, a UK company, Network Intercept,is now selling a product called Secure-Me, which could be distributed on a USB key and  fires up a &#8220;secure&#8221; web browser which encrypts all traffic traveling to and from a user&#8217;s device. The product also features malware [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1598" title="online banking" src="http://infosec3t.com/wp-content/uploads/2010/02/online-banking-300x225.jpg" alt="" width="169" height="127" />As a follow up to my previous <strong><a title="Company develops Virtualized USB key for Online Banking Safety" href="http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/">post</a></strong> on <a href="http://infosec3t.com/tag/online-banking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with online banking">online banking</a> security products, a UK company, Network Intercept,is now selling a product called <a href="http://networkintercept.com/securemepc.html" target="_blank">Secure-Me</a>, which could be distributed on a USB key and  fires up a &#8220;secure&#8221; web browser which encrypts all traffic traveling to and from a user&#8217;s device. The product also features <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a> scanning, file encryption capabilities, virtual keyboard, and keystroke interference software to thwart hardware and software key-loggers. It currently supports <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> XP, Vista, <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> 7 and <a href="http://infosec3t.com/tag/mac/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MAC">Mac</a> OS X operating systems and  Android, iPhone, Symbian and Windows Mobile platforms.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/' rel='bookmark' title='Company develops Virtualized USB key for Online Banking Safety'>Company develops Virtualized USB key for Online Banking Safety</a> <small>IronKey has come up with a USB drive that can...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/14/addressing-software-vulnerabilities-before-you-buy/' rel='bookmark' title='Addressing Software Vulnerabilities BEFORE you buy'>Addressing Software Vulnerabilities BEFORE you buy</a> <small>Most organizations are constantly in the software purchase/create -deploy-patch cycle....</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/26/more-on-secure-online-banking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Company develops Virtualized USB key for Online Banking Safety</title>
		<link>http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/</link>
		<comments>http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 22:55:29 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1597</guid>
		<description><![CDATA[IronKey has come up with a USB drive that can be used to access accounts virtually without involving the operating system or applications that cause so many of today&#8217;s security problems. The drive runs a walled or &#8216;hardened&#8217; Linux virtual environment inside the PC&#8217;s OS. It comes complete with its own browser hardwired to access [...]]]></description>
			<content:encoded><![CDATA[<p><a href="https://www.ironkey.com/" target="_blank"><img class="alignright size-medium wp-image-1598" title="online banking" src="http://infosec3t.com/wp-content/uploads/2010/02/online-banking-300x225.jpg" alt="" width="237" height="178" />IronKey</a> has come up with a USB drive that can be used to access accounts virtually without involving the operating system or applications that cause so many of today&#8217;s <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> problems. The drive runs a walled or &#8216;hardened&#8217; Linux virtual environment inside the PC&#8217;s OS. It comes complete with its own browser hardwired    to access only a particular bank service, and incorporates RSA Secure ID tokens for authentication.</p>
<p>This allows users  simply plug the drive into any PC, and without the need for any additional drivers    or software, after which the host PC was given a precautionary scan for <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>, including specialised banking <a href="http://infosec3t.com/tag/trojans/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojans">Trojans</a> such    as <a title="Botnet vs. Botnet" href="http://infosec3t.com/2010/02/17/botnet-vs-botnet/">Zeus</a>. The virtualised environment run from the drive could resist browser based  attacks, session hijacking, and accessed    the bank via a hosted service network run either by IronKey or from a dedicated server. This solution is currently mainly targeted for companies that want increased protection in access their accounts but it could very well be the future.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/22/free-blocking-tool-to-stop-drive-by-malware-downloads/' rel='bookmark' title='Free Blocking Tool to Stop Drive-By Malware Downloads'>Free Blocking Tool to Stop Drive-By Malware Downloads</a> <small>The threat of drive-by downloads is very significant as users...</small></li>
<li><a href='http://infosec3t.com/2010/02/26/more-on-secure-online-banking/' rel='bookmark' title='More on Secure Online Banking'>More on Secure Online Banking</a> <small>As a follow up to my previous post on online...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Blocking Tool to Stop Drive-By Malware Downloads</title>
		<link>http://infosec3t.com/2010/02/22/free-blocking-tool-to-stop-drive-by-malware-downloads/</link>
		<comments>http://infosec3t.com/2010/02/22/free-blocking-tool-to-stop-drive-by-malware-downloads/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 02:41:43 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[malicious Web site]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[tool]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1584</guid>
		<description><![CDATA[The threat of drive-by downloads is very significant as users can get infected just by visiting a compromised or malicious web site. Often, hackers would compromise a web server which would allow them access to all viewers of the web sites hosted on that server. This download of malicious code happens in the background and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/02/blade.jpg"><img class="alignright size-full wp-image-1583" title="blade" src="http://infosec3t.com/wp-content/uploads/2010/02/blade.jpg" alt="" width="100" height="100" /></a>The <a href="http://infosec3t.com/tag/threat/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threat">threat</a> of drive-by downloads is very significant as users can get infected just by visiting a compromised or <a href="http://infosec3t.com/tag/malicious-web-site/" class="st_tag internal_tag" rel="tag" title="Posts tagged with malicious Web site">malicious web site</a>. Often, hackers would compromise a <a href="http://infosec3t.com/tag/web-server/" class="st_tag internal_tag" rel="tag" title="Posts tagged with web server">web server</a> which would allow them access to all viewers of the web sites hosted on that server. This download of malicious code happens in the background and aren&#8217;t to unsuspecting users.</p>
<p>Researchers are preparing to release a free <a href="http://infosec3t.com/tag/tool/" class="st_tag internal_tag" rel="tag" title="Posts tagged with tool">tool</a> to stop &#8220;drive-by&#8221; downloads. The new <a href="http://infosec3t.com/tag/tool/" class="st_tag internal_tag" rel="tag" title="Posts tagged with tool">tool</a>, called BLADE (Block All Drive-By Download Exploits), stops downloads that are initiated without the user&#8217;s consent.</p>
<p>Read Full Article: <a href="http://www.technologyreview.com/computing/24632/?a=f" target="_blank">http://www.technologyreview.com/computing/24632/?a=f</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2010/01/29/lynis-security-and-system-auditing-tool/' rel='bookmark' title='Lynis &#8211; Security and System Auditing Tool'>Lynis &#8211; Security and System Auditing Tool</a> <small>Lynis is an auditing tool for Unix (specialists). It scans...</small></li>
<li><a href='http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/' rel='bookmark' title='Company develops Virtualized USB key for Online Banking Safety'>Company develops Virtualized USB key for Online Banking Safety</a> <small>IronKey has come up with a USB drive that can...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/22/free-blocking-tool-to-stop-drive-by-malware-downloads/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter users hit hard by &quot;LOL&quot; phishing attack</title>
		<link>http://infosec3t.com/2010/02/22/1572/</link>
		<comments>http://infosec3t.com/2010/02/22/1572/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 20:12:22 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1572</guid>
		<description><![CDATA[IT security and data protection firm Sophos is warning that a major attack against Twitter users this weekend was designed to steal passwords and use hijacked accounts to spread money-making spam campaigns. The attack, which is ongoing, began on Saturday, as Twitter users found that fellow members of the micro-blogging network had posted messages disguised [...]]]></description>
			<content:encoded><![CDATA[<p>IT <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> and data protection firm<a title="Facebook poses biggest security threat to businesses" href="http://infosec3t.com/2010/02/01/facebook-poses-biggest-security-threat-to-businesses/"> Sophos</a> is warning that a major attack against <a href="http://infosec3t.com/tag/twitter/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Twitter">Twitter</a> users this weekend was designed to steal passwords and use hijacked accounts to spread money-making <a href="http://infosec3t.com/tag/spam/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spam">spam</a> campaigns.</p>
<p>The attack, which is ongoing, began on Saturday, as Twitter users found that fellow members of the micro-blogging network had posted messages disguised as humorous inks, but actually aimed to phish passwords credentials from unsuspecting users.</p>
<p>Messages, which began with phrases such as &#8220;Lol. this is me??&#8221;, &#8220;lol , this is funny.&#8221;,&#8221;Lol. this you??&#8221; and &#8220;ha ha, u look funny on here&#8221;, were accompanied with clickable links which redirected users to a fake Twitter login page hosted on a website based in China called BZPharma.net.</p>
<p>Unless the hacked Twitter users change their passwords, the intruders can continue to spread spam and other attacks from their hijacked accounts</p>
<p><iframe title="YouTube video player" class="youtube-player" type="text/html" width="425" height="344" src="http://www.youtube.com/embed/cDSskvrUw_g" frameborder="0" allowFullScreen="true"> </iframe></p>
<p>Source: www.sophos.com/pressoffice/news/articles/2010/02/twitter-phishing-attack.html</p>
<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/22/1572/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We really need to start taking information security more seriously</title>
		<link>http://infosec3t.com/2010/02/18/we-really-need-to-start-taking-information-security-more-seriously/</link>
		<comments>http://infosec3t.com/2010/02/18/we-really-need-to-start-taking-information-security-more-seriously/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 02:30:51 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1549</guid>
		<description><![CDATA[From the Wall Street Journal: Hackers in Europe and China successfully broke into computers at nearly 2,500 companies and government agencies over the last 18 months in a coordinated global attack that exposed vast amounts of personal and corporate secrets to theft, according to a computer-security company that discovered the breach. … But data compiled [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>From the <a href="http://online.wsj.com/article/SB10001424052748704398804575071103834150536.html?mod=e2tw" target="_blank">Wall Street Journal</a>:</p>
<blockquote><p>Hackers in Europe and China successfully broke into computers at nearly 2,500 companies and government agencies over the last 18 months in a coordinated global attack that exposed vast amounts of personal and corporate secrets to theft, according to a computer-<a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> company that discovered the breach. … But data compiled by NetWitness, the closely held firm that discovered the breaches, showed that hackers gained access to a wide array of data at 2,411 companies, from credit-card transactions to intellectual property.</p></blockquote>
</div>
</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/01/united-states-department-of-defense-embraces-hacker-certification/' rel='bookmark' title='United States Department of Defense Embraces Hacker Certification'>United States Department of Defense Embraces Hacker Certification</a> <small>Mar 01, 2010 – The U.S. Department of Defense (DoD)...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/18/we-really-need-to-start-taking-information-security-more-seriously/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010 CWE/SANS Top 25 Most Dangerous Programming Errors</title>
		<link>http://infosec3t.com/2010/02/17/2010-cwesans-top-25-most-dangerous-programming-errors/</link>
		<comments>http://infosec3t.com/2010/02/17/2010-cwesans-top-25-most-dangerous-programming-errors/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 18:52:56 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1544</guid>
		<description><![CDATA[The 2010 CWE/SANS Top 25 Most Dangerous Programming Errors is a list of the most widespread and critical programming errors that can lead to serious software vulnerabilities. They are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1545" title="bug" src="http://infosec3t.com/wp-content/uploads/2010/02/bug-300x141.jpg" alt="" width="300" height="141" />The 2010 CWE/SANS Top 25 Most Dangerous Programming Errors is a list of the most widespread and critical programming errors that can lead to serious <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> vulnerabilities.  They are often easy to find, and easy to exploit.  They are dangerous because they will frequently allow attackers to completely take over the <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a>, steal data, or prevent the <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> from working at all.</p>
<p>The Top 25 list is a <a href="http://infosec3t.com/tag/tool/" class="st_tag internal_tag" rel="tag" title="Posts tagged with tool">tool</a> for education and <a href="http://infosec3t.com/tag/awareness/" class="st_tag internal_tag" rel="tag" title="Posts tagged with awareness">awareness</a> to help  programmers to prevent the kinds of vulnerabilities that plague the software industry, by identifying and avoiding all-too-common mistakes that occur before software is even shipped.  Software customers can use the same list to help them to ask for more secure software. Researchers in software <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> can use the Top 25 to focus on a narrow but important subset of all known <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> weaknesses. Finally, software managers and CIOs can use the Top 25 list as a measuring stick of progress in their efforts to secure their software.</p>
<p><a href="http://cwe.mitre.org/top25/" target="_blank">Find the full list and guidance on using it here.</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/' rel='bookmark' title='Top 10 Web Application Security Risks for 2010'>Top 10 Web Application Security Risks for 2010</a> <small>Yesterday, OWASP released its list of top ten web application...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/17/2010-cwesans-top-25-most-dangerous-programming-errors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnet vs. Botnet</title>
		<link>http://infosec3t.com/2010/02/17/botnet-vs-botnet/</link>
		<comments>http://infosec3t.com/2010/02/17/botnet-vs-botnet/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 17:58:43 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[online banking]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1539</guid>
		<description><![CDATA[Did you hear the one about the bot that attacked the other bot and killed it? O but not before stealing your online banking credentials, that is. Security researchers say that the relatively unknown [Spy Eye toolkit] added this functionality just a few days ago in a bid to displace its larger rival, known as [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1540" title="hacker-virus-hand-1196269-l" src="http://infosec3t.com/wp-content/uploads/2010/02/hacker-virus-hand-1196269-l-300x236.jpg" alt="" width="300" height="236" />Did you hear the one about the bot that attacked the other bot and killed it? O but not before stealing your online banking credentials, that is.</p>
<p><a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> researchers say that the relatively unknown [<a href="http://www.symantec.com/connect/blogs/spyeye-bot-versus-zeus-bot" target="_blank">Spy Eye toolkit</a>] added this functionality just a few days ago in a bid to displace its larger rival, known as Zeus.</p>
<p>The feature, called &#8220;Kill Zeus,&#8221; apparently removes the Zeus software from the victim&#8217;s PC, giving Spy Eye exclusive access to usernames and passwords.</p>
<p>Zeus and Spy Eye are both Trojan-making toolkits, designed to give criminals an easy way to set up their own &#8220;<a href="http://infosec3t.com/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a>&#8221; networks of password-stealing programs. These programs emerged as a major problem in 2009, with the U.S. Federal Bureau of Investigation estimating last October that they have caused $100 million in losses.</p>
<p><a href="http://infosec3t.com/tag/trojans/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojans">Trojans</a> such as Zeus and Spy Eye steal online banking credentials. This information is then used to empty bank accounts by transferring funds to so-called money mules &#8212; U.S. residents with bank accounts &#8212; who then move the cash out of the country.</p>
<p><a href="http://www.computerworld.com/s/article/9154618/New_Russian_botnet_tries_to_kill_rival" target="_blank">Read the full article</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/' rel='bookmark' title='Company develops Virtualized USB key for Online Banking Safety'>Company develops Virtualized USB key for Online Banking Safety</a> <small>IronKey has come up with a USB drive that can...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/17/botnet-vs-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enter the Dragon browser, the more secure Google Chrome</title>
		<link>http://infosec3t.com/2010/02/16/1533/</link>
		<comments>http://infosec3t.com/2010/02/16/1533/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 22:22:38 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1533</guid>
		<description><![CDATA[The open source engine that forms the basis for Google&#8217;s Chrome has spawned an ostensibly new browser, Comodo&#8217;s cleverly named ‘Dragon&#8217;. Internet Explorer might be the most used, Firefox the most fashionable and Google allegedly the fastest, but firewall and tools outfit Comodo says that its new browser has enough tweaks to make it marginally [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1534" title="google-chrome-logo-711569" src="http://infosec3t.com/wp-content/uploads/2010/02/google-chrome-logo-711569.jpg" alt="" width="189" height="189" />The open source engine that forms the basis for <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a>&#8217;s Chrome has spawned an ostensibly new browser, Comodo&#8217;s cleverly named ‘Dragon&#8217;. <a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a> might be the most used, Firefox the most fashionable and Google allegedly the fastest, but firewall and tools outfit Comodo says that its new browser has enough tweaks to make it marginally the most secure. Based on Chromium project code, Dragon can give warnings regarding the type of SSL digital site certificate and whether any present provide enough security. In the case of domain SSL certificates, which can be bought through a wide range of agencies around the globe, the answer is almost certainly not.</p>
<p>The browser is also configured to transfer as little data to websites as possible, in particular on software errors the company says would normally be transmitted for troubleshooting purposes. This could betray a user&#8217;s browsing history.</p>
<p>Although identical to Google&#8217;s Chrome in terms of look and feel, delving into the options tab reveals this subtly different outlook. The crash report checkbox found in Chrome is missing, although it has to be said that the latter can be unchecked on the former and is not mandatory. The other security features such as control over cookies are all from Chrome.</p>
<p><a href="http://news.techworld.com/security/3212841/new-browser-tweaks-chrome-security/?olo=rss" target="_blank"> Read the full article</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/03/google-informs-users-of-terminination-of-support-frr-ie6/' rel='bookmark' title='Google Informs users of terminination of support for IE6'>Google Informs users of terminination of support for IE6</a> <small>I received this email from the good offices of Google...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/' rel='bookmark' title='Microsoft offering choice of browser to users in Europe'>Microsoft offering choice of browser to users in Europe</a> <small>Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221;...</small></li>
<li><a href='http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/' rel='bookmark' title='Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;'>Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;</a> <small>Talk about throwing out the baby with the bath water....</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/16/1533/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent Microsoft Update BSOD may be caused by Rootkit</title>
		<link>http://infosec3t.com/2010/02/15/recent-microsoft-update-bsod-may-be-caused-by-rootkit/</link>
		<comments>http://infosec3t.com/2010/02/15/recent-microsoft-update-bsod-may-be-caused-by-rootkit/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 16:39:59 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1527</guid>
		<description><![CDATA[Last week, I posted here about the recent pandemic of blue screens of death experienced that many XP users after installing the patch MS10-015 . Microsoft has since stopped shipping the patch and claims in a blog post that preliminary investigations lead them to believe that the system crashes were caused by a rootkit. Blogger [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1528" title="BILL-GATES-bsod" src="http://infosec3t.com/wp-content/uploads/2010/02/BILL-GATES-bsod-300x206.jpg" alt="" width="300" height="206" />Last week, I posted here about the recent pandemic of blue screens of death experienced that many XP users after installing the patch <strong><a title="Aaaah The Infamous Blue Screen of Death" href="http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/">MS10-015</a> </strong>. <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> has since stopped shipping the patch and claims in a <a href="http://redirectingat.com/?id=803X112721&amp;url=http%3A%2F%2Fblogs.technet.com%2Fmsrc%2Farchive%2F2010%2F02%2F12%2Fupdate-restart-issues-after-installing-ms10-015.aspx" target="_blank">blog post</a> that preliminary investigations lead them to believe that the system crashes were caused by a rootkit.</p>
<p>Blogger <a href="https://patrickwbarnes.com/blog/2010/02/microsoft-update-kb977165-triggering-widespread-bsod/" target="_blank">Pat Barnes</a> posted the following repair instructions :</p>
<h4>Using the Windows XP Recovery Console</h4>
<p>1. Boot from your Windows installation CD</p>
<p>Insert your Windows installation CD and boot your computer. If your computer is not set to boot from CD first, you may need to reconfigure your BIOS or press a boot menu key (often F12, F8 or Esc). If you are unsure of how to do this, consult your favorite geek. As soon as the boot starts, you should see a message like “Press any key to boot from CD…” – press a key.</p>
<p>2. Start the Recovery Console</p>
<p>After the CD loads (it may take a minute), you will be presented with a few choices. One of these options is to start a recovery by pressing “R”. Press “R” to launch the Recovery Console.</p>
<p>* You may be asked to choose a Windows installation.  If so, choose the damaged installation (probably “1″).<br />
* You may be prompted for the Administrator password.  If you do not have one, press “Enter”.</p>
<p>3. Identify your CD drive letter</p>
<p>You should now be at the command prompt.  Enter the following command:</p>
<p><code> map</code></p>
<p>Look for the drive letter for your CD drive.  It may look something like this:</p>
<p><code> D:	\Device\CdRom0</code></p>
<p>In this case, your CD drive is “D:”.</p>
<p>4. Replace ATAPI.SYS</p>
<p>Enter the following, replacing “D:” with your CD drive:</p>
<p><code> cd system32\drivers<br />
ren atapi.sys atapi.old<br />
expand D:\i386\atapi.sy_</code></p>
<p>You should see the message “1 file(s) expanded.” – this indicates you have succeeded.</p>
<p>5. Reboot and scan for malware</p>
<p>Reboot your computer. With a little luck, your computer will now boot normally. Because this problem is caused by malware, you should immediately scan your computer with up-to-date <a href="http://infosec3t.com/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Antivirus">antivirus</a> <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/' rel='bookmark' title='Aaaah The Infamous Blue Screen of Death'>Aaaah The Infamous Blue Screen of Death</a> <small>On Tuesday, Microsoft issued a patch, MS10-015,  to fix a...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/interested-in-computer-forensics/' rel='bookmark' title='Interested in Computer Forensics?'>Interested in Computer Forensics?</a> <small>I recently went through an EC Council Computer Hacking Forensic...</small></li>
<li><a href='http://infosec3t.com/2010/02/23/company-develops-virtualized-usb-key-for-online-banking-safety/' rel='bookmark' title='Company develops Virtualized USB key for Online Banking Safety'>Company develops Virtualized USB key for Online Banking Safety</a> <small>IronKey has come up with a USB drive that can...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/15/recent-microsoft-update-bsod-may-be-caused-by-rootkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aaaah The Infamous Blue Screen of Death</title>
		<link>http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/</link>
		<comments>http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 22:17:03 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1491</guid>
		<description><![CDATA[On Tuesday, Microsoft issued a patch, MS10-015,  to fix a 17-year-old kernel bug in all 32-bit versions of Windows. Since then, Microsoft&#8217;s support forum has been flooded with complaints by angry users whose Windows XP machines have experienced blue screens after performing the update.  The support thread was first noticed by security blogger Brian Krebs [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1492" title="microsoft-sign" src="http://infosec3t.com/wp-content/uploads/2010/02/microsoft-sign-300x269.jpg" alt="" width="300" height="269" />On Tuesday, <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> issued a patch, MS10-015,  to fix a 17-year-old kernel bug in all 32-bit versions of <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a>. Since then, Microsoft&#8217;s support forum has been flooded with complaints by angry users whose <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> XP machines have experienced blue screens after performing the update.  The support thread was first noticed by security blogger <a href="http://www.krebsonsecurity.com/2010/02/new-patches-cause-bsod-for-some-windows-xp-users/" target="_blank">Brian Krebs</a> . It contained more than 120 messages as of this morning, making it the third-longest on the Windows Update  support forum. The thread had been viewed more than 2,800 times since  its inception.</p>
<p>Users are advised to boot from their  Windows XP installation disc and launch the Recovery Console in order to regain control of their PC.  This solution,  however, leaves out netbook users as the  lightweight, inexpensive laptops do not have optical (cd/dvd) drives and so  can&#8217;t boot from an XP installation disc.</p>
<p>This isn&#8217;t the first time that a Microsoft update has crashed Windows PCs. Two years ago, a set of <a href="http://infosec3t.com/tag/updates/" class="st_tag internal_tag" rel="tag" title="Posts tagged with updates">updates</a> for Vista sent an unknown  number of machines into an endless series of reboots. Similar problems affected users who tried to upgrade to Windows XP  Service Pack 3  in May 2008, and others attempting to upgrade from  Vista to Windows 7  last October.</p>
<p>Large enterprises with numerous managed desktop computers should always test patches before rolling them out. Unfortunately, home users just have to hold their noses and wish for the best. Good Ole Microsoft.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/' rel='bookmark' title='Microsoft resumes pushing Blue Screen Update'>Microsoft resumes pushing Blue Screen Update</a> <small>Microsoft has resumed pushing out the patch connected to the...</small></li>
<li><a href='http://infosec3t.com/2010/03/01/microsoft-offering-choice-of-browser-to-users-in-europe/' rel='bookmark' title='Microsoft offering choice of browser to users in Europe'>Microsoft offering choice of browser to users in Europe</a> <small>Microsoft has been ordered to introduce the browser &#8220;ballot box&#8221;...</small></li>
<li><a href='http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/' rel='bookmark' title='Many companies caught in the lurch as Microsoft ends support for Windows XP 2'>Many companies caught in the lurch as Microsoft ends support for Windows XP 2</a> <small>On July 13, Microsoft will officially retire Windows XP Service...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Retracts Malware Accusation Against Firefox Extension</title>
		<link>http://infosec3t.com/2010/02/11/mozilla-retracts-malware-accusation-against-firefox-extension/</link>
		<comments>http://infosec3t.com/2010/02/11/mozilla-retracts-malware-accusation-against-firefox-extension/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 21:31:09 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1487</guid>
		<description><![CDATA[Six days ago, I posted that Mozilla had reported in a security notice that two experimental add-ons for its Firefox browser contain trojans that affect Windows machines. Mozilla has since retracted that accusation against one of the extensions. In a statement posted to its blog last night, Mozilla said: &#8220;We&#8217;ve worked with security experts and [...]]]></description>
			<content:encoded><![CDATA[<p>Six days ago, I posted that Mozilla had reported in a <a title="Mozilla confirms Trojan-infected Firefox add-ons" href="http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/">security notice</a> that two experimental add-ons for  its Firefox browser contain <a href="http://infosec3t.com/tag/trojans/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojans">trojans</a> that affect Windows  machines. Mozilla has since retracted that accusation against one of the extensions. In a statement posted to its blog last night, Mozilla said: &#8220;We&#8217;ve  worked with <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> experts and add-on developers to determine that the  suspected trojan in Version 4.0 of  Sothink Video Downloader was a false  positive and the extension does not include <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>.&#8221;</p>
<p>Good Grief! One would think that work would have been done BEFORE defaming a company.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/' rel='bookmark' title='Mozilla confirms Trojan-infected Firefox add-ons'>Mozilla confirms Trojan-infected Firefox add-ons</a> <small>If you are a Firefox user, as I am, you...</small></li>
<li><a href='http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/' rel='bookmark' title='Does the musical browser approach work?'>Does the musical browser approach work?</a> <small>German&#8217;s official cyber-security response team is advising surfers not to...</small></li>
<li><a href='http://infosec3t.com/2010/03/24/hacker-updates-woman-facebook-status/' rel='bookmark' title='Hacker Updates Woman Facebook Status'>Hacker Updates Woman Facebook Status</a> <small>Here&#8217;s an interesting story. Who didn&#8217;t see this coming? &#8220;Police...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/11/mozilla-retracts-malware-accusation-against-firefox-extension/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When it comes to cyber security, trust no one</title>
		<link>http://infosec3t.com/2010/02/07/when-it-comes-to-cyber-security-trust-no-one/</link>
		<comments>http://infosec3t.com/2010/02/07/when-it-comes-to-cyber-security-trust-no-one/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 23:32:30 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1397</guid>
		<description><![CDATA[I came across this little tidbit today. Pretty funny but so true. How well do you know your 500 best friends on Facebook? How much do you trust the 1000 pals you follow on Twitter? Never mind the fact that if any of those accounts are compromised, you&#8217;re toast. Robert Rivard over at MySANews writes: [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/02/be-afraid-be-very-afraid-297x300.jpg"><img class="alignright size-full wp-image-1398" title="be-afraid-be-very-afraid-297x300" src="http://infosec3t.com/wp-content/uploads/2010/02/be-afraid-be-very-afraid-297x300.jpg" alt="" width="201" height="204" /></a>I came across this little tidbit today. Pretty funny but so true.</p>
<p>How well do you know your 500 best friends on Facebook? How much do you trust the 1000 pals you follow on <a href="http://infosec3t.com/tag/twitter/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Twitter">Twitter</a>? Never mind the fact that if any of those accounts are compromised, you&#8217;re toast.</p>
<p>Robert Rivard over at MySANews writes:</p>
<p>Effective immediately, I&#8217;ve got cyber <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> religion. It&#8217;s scary out there, and I&#8217;m going on the defensive. You should, too.</p>
<p>Everybody else is kicking back on a Friday night, sipping a margarita, hanging with friends, planning Super Bowl Sunday. Me?</p>
<p>I&#8217;m changing passwords, downloading patches for outdated programs, running redundant anti-virus programs, sniffing for <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>.</p>
<p>Read the rest of the great piece at http://www.mysanantonio.com/<a href="http://infosec3t.com/tag/news/" class="st_tag internal_tag" rel="tag" title="Posts tagged with News">news</a>/local_<a href="http://infosec3t.com/tag/news/" class="st_tag internal_tag" rel="tag" title="Posts tagged with News">news</a>/When_it_comes_to_cyber_security_trust_no_one.html</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2011/01/23/smb-cyber-security-alliance-helps-small-businesses-address-cyber-security-risks/' rel='bookmark' title='SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks'>SMB Cyber Security Alliance helps Small Businesses address Cyber Security Risks</a> <small>Across all industries, small businesses are increasingly facing new threats...</small></li>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2010/01/09/brevity-is-the-soul-of-getting-yourself-infected-with-all-kinds-of-nasties/' rel='bookmark' title='Brevity is the soul of&#8230;..getting yourself infected with all kinds of nasties!'>Brevity is the soul of&#8230;..getting yourself infected with all kinds of nasties!</a> <small>Would you click on the link : http://www.click-here-to-give-me-access-to-all-your-computer-files.com? No? How...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/07/when-it-comes-to-cyber-security-trust-no-one/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Death of [the illusion of] Privacy on the Internet</title>
		<link>http://infosec3t.com/2010/02/05/the-death-of-the-illusion-of-privacy-on-the-internet/</link>
		<comments>http://infosec3t.com/2010/02/05/the-death-of-the-illusion-of-privacy-on-the-internet/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 19:23:23 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1371</guid>
		<description><![CDATA[If this doesn&#8217;t scare you, it should. The Washington Post, quoting unnamed sources, reported yesterday that the NSA and Google are in the process of finalizing an agreement under which the NSA will help Google better defend itself against future attacks. Under the deal, the NSA would not get access to users&#8217; search information or [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1090" title="big-brother-is-watching-you4" src="http://infosec3t.com/wp-content/uploads/2010/02/big-brother-is-watching-you4-235x300.jpg" alt="" width="235" height="300" />If this doesn&#8217;t scare you, it should.</p>
<p>The <a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html?hpid=topnews" target="_self"><em>Washington Post</em></a>, quoting unnamed sources, reported yesterday that the NSA and Google are in the process of finalizing an agreement under which the NSA will help Google better defend itself against future attacks. Under the deal, the NSA would not get access to users&#8217; search information or e-mail accounts and Google would not share any proprietary data, the source claimed.</p>
<p>Google isn&#8217;t the only company to get hacked. Will the NSA be extending this helping hand to all other multi-national corporations or just the one with access to all our personal data in some form or another.</p>
<p>The report states that Google approached the NSA shortly after the recent <a title="Google and China: A Dysfunctional Marriage" href="http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/">cyberattacks</a>, which it said were launched from China. However, the deal will take time to hammer out because of the sensitive <a href="http://infosec3t.com/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privacy">privacy</a> issues involved. If the deal goes through, it will be the first time that Google has entered into a formal information-sharing relationship with the NSA, the <em>Post</em> quoted its source as saying.</p>
<p>The prospect world&#8217;s largest search engine company teaming up with the country&#8217;s largest spy agency   should clear up any illusion of the concept of <a title="Google Toolbar caught tracking users when ‘disabled’" href="http://infosec3t.com/2010/01/27/google-toolbar-caught-tracking-users-when-disabled/">privacy</a> in the <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">internet</a>.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/23/google-acknowledges-privacy-issues-with-buzz-amid-ftc-complaint/' rel='bookmark' title='Google Acknowledges Privacy Issues With Buzz amid FTC complaint'>Google Acknowledges Privacy Issues With Buzz amid FTC complaint</a> <small>Although Google has acknowledged some of the privacy concerns with...</small></li>
<li><a href='http://infosec3t.com/2010/04/05/google-rolls-out-privacy-reset-for-buzz/' rel='bookmark' title='Google rolls out privacy reset for Buzz'>Google rolls out privacy reset for Buzz</a> <small>Google will ask users of its social network Buzz to...</small></li>
<li><a href='http://infosec3t.com/2010/03/23/google-pulls-out-of-china/' rel='bookmark' title='Google pulls out of China'>Google pulls out of China</a> <small>Is this a divorce or separation?  I chronicled Google&#8217;s dysfunctional...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/05/the-death-of-the-illusion-of-privacy-on-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla confirms Trojan-infected Firefox add-ons</title>
		<link>http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/</link>
		<comments>http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 19:00:07 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1365</guid>
		<description><![CDATA[If you are a Firefox user, as I am, you probably have one or more &#8220;add-ons&#8221; installed to enhance your browser capabilities. For example, I have add-ons installed to show the ip address and country location of the web servers I connect to. I also have another to block all scripts from running in my [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1366" title="mozilla" src="http://infosec3t.com/wp-content/uploads/2010/02/mozilla.jpg" alt="" width="185" height="110" />If you are a Firefox user, as I am, you probably have one or more &#8220;add-ons&#8221; installed to enhance your browser capabilities. For example, I have add-ons installed to show the ip address and country location of the web servers I connect to. I also have another to block all scripts from running in my browser by web servers unless i explicitly allow it. These add-ons help protect my computer while browsing the web.</p>
<div id="post">
<div>
<p>However, Mozilla has admitted in a <a title="Security Issue on AMO" href="http://blog.mozilla.com/addons/2010/02/04/please-read-security-issue-on-amo/" target="_blank">security notice</a> that two experimental add-ons for its Firefox browser contain <a href="http://infosec3t.com/tag/trojans/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojans">Trojans</a> that affect <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> machines.</p>
<p>The firm has since removed the add-ons from its official pages, but estimates that around 5,000 instances have already been downloaded.</p>
</div>
<div>
<p>&#8220;Two experimental add-ons, Version 4.0 of Sothink Web Video Downloader and all versions of Master Filer, were found to contain Trojan code aimed at Windows users,&#8221; said the company in a statement.</p>
<p>&#8220;Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen, and Master Filer contained Win32.Bifrose.32.Bifrose Trojan. Both add-ons have been disabled on Add-Ons for Firefox.&#8221;</p>
<p>Mozilla warned that users who have already downloaded the add-ons will become infected.</p>
<p>Simply installing the add-ons will execute the Trojan the next time Firefox starts, while uninstalling them will not eradicate the problem. The company advised the use of an anti-<a href="http://infosec3t.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> program to remove the malware.</p>
</div>
<div>
<p>Mac and <a href="http://infosec3t.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Linux">Linux</a> users are not affected.</p>
</div>
</div>
<p> </p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/11/mozilla-retracts-malware-accusation-against-firefox-extension/' rel='bookmark' title='Mozilla Retracts Malware Accusation Against Firefox Extension'>Mozilla Retracts Malware Accusation Against Firefox Extension</a> <small>Six days ago, I posted that Mozilla had reported in...</small></li>
<li><a href='http://infosec3t.com/2010/02/27/trojan-pretends-to-be-microsoft-security-suite/' rel='bookmark' title='Trojan Pretends to Be Microsoft Security Suite'>Trojan Pretends to Be Microsoft Security Suite</a> <small>Microsoft is warning users that a Trojan is masquerading as...</small></li>
<li><a href='http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/' rel='bookmark' title='Does the musical browser approach work?'>Does the musical browser approach work?</a> <small>German&#8217;s official cyber-security response team is advising surfers not to...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scaring the Senate Intelligence Committee</title>
		<link>http://infosec3t.com/2010/02/05/scaring-the-senate-intelligence-committee/</link>
		<comments>http://infosec3t.com/2010/02/05/scaring-the-senate-intelligence-committee/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 18:35:43 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1361</guid>
		<description><![CDATA[From Schneier on Security by Bruce Schneier This is unconscionable: At Tuesday&#8217;s hearing, Senator Dianne Feinstein, Democrat of California and chairwoman of the Senate Intelligence Committee, asked Mr. Blair [the Director of National Intelligence] to assess the possibility of an attempted attack in the United States in the next three to six months. He replied, [...]]]></description>
			<content:encoded><![CDATA[<h2></h2>
<p>From <a href="http://www.schneier.com/" target="_blank">Schneier on Security </a>by Bruce Schneier</p>
<p><a href="http://www.nytimes.com/2010/02/03/us/politics/03intel.html?em" target="_blank">This is unconscionable</a>:</p>
<blockquote><p>At Tuesday&#8217;s hearing, Senator Dianne Feinstein, Democrat of California and chairwoman of the Senate Intelligence Committee, asked Mr. Blair [the Director of National Intelligence] to assess the possibility of an attempted attack in the United States in the next three to six months.
<p>He replied, &#8220;The priority is certain, I would say&#8221; &#8212; a response that was reaffirmed by the top officials of the C.I.A. and the F.B.I.</p>
</blockquote>
<p>I don&#8217;t know what &#8220;the priority is certain&#8221; actually means, but now everyone is reporting that these agencies claim there <em>will</em> be a terrorist attack in the U.S. during the next six months.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/cissp-all-in-one-book-fifth-edition-has-been-released/' rel='bookmark' title='CISSP All In One Book FIFTH EDITION has been released'>CISSP All In One Book FIFTH EDITION has been released</a> <small>The fifth edition of this best-selling comprehensive CISSP training resources...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/05/scaring-the-senate-intelligence-committee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your guilty conscience could get you pwned</title>
		<link>http://infosec3t.com/2010/02/04/your-guilty-conscience-could-get-you-pwned/</link>
		<comments>http://infosec3t.com/2010/02/04/your-guilty-conscience-could-get-you-pwned/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 16:18:14 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1349</guid>
		<description><![CDATA[From Trend Micro Countermeasures Blog: I just received an email from some guy called Willie Hickey. Aside form having an extremely amusing name, Mr. Hickey was offering me some very urgent advice[..] The message reads&#8230; &#8220;Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of [...]]]></description>
			<content:encoded><![CDATA[<p>From Trend Micro Countermeasures Blog:</p>
<p>I just received an <a href="http://infosec3t.com/tag/email-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Email">email</a> from some guy called Willie Hickey. Aside form having an extremely amusing name, Mr. Hickey was offering me some very urgent advice[..]</p>
<p>The message reads&#8230;</p>
<p>&#8220;Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:&#8221;.</p>
<p>This little piece of <a href="http://infosec3t.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">social engineering</a> is obviously designed to arouse fear and doubt in the recipient; &#8220;Oh no, not those photos, the zookeeper promised he would destroy the negatives.<br /> Don&#8217;t be tempted though to click the link. There are no photos, there is no Willie Hickey.<br /> The link leads to a malicious JavaScript which redirects the browser to a Russian IP address where multiple PDF <a href="http://infosec3t.com/tag/exploits/" class="st_tag internal_tag" rel="tag" title="Posts tagged with exploits">exploits</a> and an ActiveX exploit are used to push out a variant of the ZeuS crimeware. The sample itself has very low detection rates with only 9 out of 40 detections on VirusTotal.</p>
<p><a href="From Trend Micro Countermeasures Blog:      I just received an email from some guy called Willie Hickey. Aside form having an extremely amusing name, Mr. Hickey was offering me some very urgent advice[..]      The message reads...      &quot;Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:&quot;.      This little piece of social engineering is obviously designed to arouse fear and doubt in the recipient; &quot;Oh no, not those photos, the zookeeper promised he would destroy the negatives.     Don't be tempted though to click the link. There are no photos, there is no Willie Hickey.     The link leads to a malicious JavaScript which redirects the browser to a Russian IP address where multiple PDF exploits and an ActiveX exploit are used to push out a variant of the ZeuS crimeware. The sample itself has very low detection rates with only 9 out of 40 detections on VirusTotal.  http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/" target="_blank">http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/29/dont-install-fake-facebook-antivirus/' rel='bookmark' title='Don&#039;t install fake Facebook Antivirus'>Don&#039;t install fake Facebook Antivirus</a> <small>Alas, another day, another Facebook security alert. As soon as...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/01/09/brevity-is-the-soul-of-getting-yourself-infected-with-all-kinds-of-nasties/' rel='bookmark' title='Brevity is the soul of&#8230;..getting yourself infected with all kinds of nasties!'>Brevity is the soul of&#8230;..getting yourself infected with all kinds of nasties!</a> <small>Would you click on the link : http://www.click-here-to-give-me-access-to-all-your-computer-files.com? No? How...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/04/your-guilty-conscience-could-get-you-pwned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

