<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Systems</title>
	<atom:link href="http://infosec3t.com/category/systems/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>Will your Cloud Provider be around in two years?</title>
		<link>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/</link>
		<comments>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/#comments</comments>
		<pubDate>Sun, 12 Sep 2010 15:45:33 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2361</guid>
		<description><![CDATA[I just read that my hosting company, GoDaddy, is on the auction block to be sold to the highest bidder. Naturally, I&#8217;m thinking of how this change of ownership could adversely affect the service of my web sites, blogs, and virtual servers.  One never really knows until the new owners take over. Maybe they clean [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/09/Cloud.jpg"><img class="alignright size-full wp-image-2365" title="Cloud" src="http://infosec3t.com/wp-content/uploads/2010/09/Cloud.jpg" alt="" width="175" height="175" /></a>I just read that my hosting company, GoDaddy, is on the auction block to be sold to the highest bidder. Naturally, I&#8217;m thinking of how this change of ownership could adversely affect the service of my web sites, blogs, and virtual servers.  One never really knows until the new owners take over. Maybe they clean house and things change for the better. Or they may look to cut costs and things could take a downward turn. Migrating to a another service would a pain but I could do it if needed.</p>
<p>This brings to mind the current state of the <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> market. The mad gold rush of cloud services providers continues. Everyone wants a piece of the action.  These companies offer a variety of hosting services for IT infrastructure, platforms and applications.  The lure of moving to the cloud is obvious. Let someone else do it better, cheaper, more reliably and worry about the  details. More organizations are taking advantage. Companies, large and small, are moving their data, applications, and systems to one or more of the legion of providers out there.  This means more dependence on these providers for accessing business critical resources.  Although there are some obvious leaders in the cloud market today ( <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a>, Amazon, Salesforce), there are also a many smaller boutique providers that compete mostly on price.</p>
<p>In coming years, I expect the market to settle. Some providers will flourish, others will go down in flames or be acquired by one of the larger shops. These changes could have real consequences to customers. What happens if your provider is using proprietary technology and goes out of business?  Migrating to a new provider might be difficult. Doing your due diligence before selecting a provider is very important. Verifying the financial stability of the company and developing a strong service level agreement are key requirements.  Your SLA must address uptime, performance and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>. The ability to audit your provider is also very important.</p>
<p>Many small businesses would not exist without the cloud. Building, hosting, and managing an IT infrastructure can be cost prohibitive. Choosing the right provider, however, may be the difference between success and failure.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/' rel='bookmark' title='The real arguments for Cloud Computing'>The real arguments for Cloud Computing</a> <small>As more vendors dive into the cloud computing market, every...</small></li>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IBM X-Force handicaps future trends in security</title>
		<link>http://infosec3t.com/2010/08/29/ibm-x-force-handicaps-future-trends-in-security/</link>
		<comments>http://infosec3t.com/2010/08/29/ibm-x-force-handicaps-future-trends-in-security/#comments</comments>
		<pubDate>Sun, 29 Aug 2010 23:26:56 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2342</guid>
		<description><![CDATA[Looking ahead, the X-Force Research and Development team has identified some key trends to watch for in the future, including: Cloud Computing &#8212; As an emerging technology, security concerns remain a hurdle for organizations looking to adopt cloud computing. As organizations transition to the cloud, IBM recommends that they start by examining the security requirements [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2343" title="XForce" src="http://infosec3t.com/wp-content/uploads/2010/08/XForce1-300x182.jpg" alt="" width="300" height="182" />Looking ahead, the X-Force Research and Development team has identified some key trends to watch for in the future, including:</p>
<p><strong><a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">Cloud Computing</a></strong> &#8212; As an emerging technology, <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> concerns remain a hurdle for organizations looking to adopt cloud computing. As organizations transition to the cloud, IBM recommends that they start by examining the <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> requirements of the workloads they intend to host in the cloud, rather than starting with an examination of different potential service providers. Gaining a good understanding of the needs and requirements first will help organizations take a more strategic approach to adopting cloud services.</p>
<p><strong><a href="http://infosec3t.com/tag/virtualization/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virtualization">Virtualization</a> </strong>&#8211; As organizations push workloads into virtual server infrastructures to take advantage of ever increasing CPU performance, questions have been raised about the wisdom of sharing workloads with different security requirements on the same physical hardware. X-Force&#8217;s vulnerability data shows that 35 percent of vulnerabilities impacting server class virtualization systems affect the hypervisor, which means that an attacker with control of one virtual system may be able to manipulate other systems on the same machine. This is a significant data point when architecting virtualization projects.</p>
<p>Read more: <a href="http://www.prnewswire.com/news-releases/ibm-x-force-report-reveals-global-security-threats-have-reached-record-levels-101460029.html" target="_blank">http://www.prnewswire.com/news-releases/ibm-x-force-report-reveals-global-security-threats-have-reached-record-levels-101460029.html</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/' rel='bookmark' title='Exploring Cloud Computing Information Leakage'>Exploring Cloud Computing Information Leakage</a> <small>If you are in cloud computing security (or part of...</small></li>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
<li><a href='http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/' rel='bookmark' title='Will your Cloud Provider be around in two years?'>Will your Cloud Provider be around in two years?</a> <small>I just read that my hosting company, GoDaddy, is on...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/08/29/ibm-x-force-handicaps-future-trends-in-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security On A Shoestring SMB Budget</title>
		<link>http://infosec3t.com/2010/07/08/security-on-a-shoestring-smb-budget/</link>
		<comments>http://infosec3t.com/2010/07/08/security-on-a-shoestring-smb-budget/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 15:03:49 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2266</guid>
		<description><![CDATA[The e-mail appeared to be an invitation from an old, junior high school friend. Yet when the hospital employee clicked on the link, it instead led her to a malicious site that installed a Trojan horse on her computer. In a little over a week, international cybercriminals used that beachhead to steal more than $600,000 [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2267" title="6a00e5539a104188340120a8b0302c970b-800wi" src="http://infosec3t.com/wp-content/uploads/2010/07/6a00e5539a104188340120a8b0302c970b-800wi-300x251.jpg" alt="" width="300" height="251" />The e-mail appeared to be an invitation from  an old, junior high school friend. Yet when the hospital employee  clicked on the link, it instead led her to a malicious site that  installed a Trojan horse on her computer. In a little over a week,  international cybercriminals used that beachhead to steal more than  $600,000 from the woman&#8217;s employer, according to a terse description of  the incident on the Information Systems <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">Security</a> Association’s Web site.</p>
<p>A number of similar incidents to this one highlight the <a href="http://infosec3t.com/tag/threats/" class="st_tag internal_tag" rel="tag" title="Posts tagged with threats">threats</a> of online crime facing small and midsize  businesses (SMBs), says Stan Stahl, president of Citadel Information  Group and president of the Los Angeles chapter of the ISSA.</p>
<p>&#8220;Typically, they say, &#8216;We have firewalls in place and have AV on all the  desktops, so I guess we are secure,&#8217;&#8221; Stahl says. &#8220;But today cybercrime  is so sophisticated that is not enough anymore.&#8221;</p>
<p>Read full article at <a href="http://www.darkreading.com/smb-security/security/attacks/showArticle.jhtml?articleID=225702557&amp;cid=RSSfeed" target="_blank">http://www.darkreading.com/smb-security/security/attacks/showArticle.jhtml?articleID=225702557&amp;cid=RSSfeed</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/06/thoughts-on-skype-security/' rel='bookmark' title='Thoughts on Skype security'>Thoughts on Skype security</a> <small>Michael Gough, an information security specialist and president of the...</small></li>
<li><a href='http://infosec3t.com/2010/03/08/did-you-facebook-ceo-play-fast-and-loose-with-user-login-data/' rel='bookmark' title='Did Facebook CEO play fast and loose with user login data?'>Did Facebook CEO play fast and loose with user login data?</a> <small>Did you Facebook CEO play fast and loose with user...</small></li>
<li><a href='http://infosec3t.com/2010/02/10/irs-reminds-you-not-to-go-phishing-this-tax-season/' rel='bookmark' title='IRS reminds you not to go Phishing this tax season'>IRS reminds you not to go Phishing this tax season</a> <small>It&#8217;s tax time again and IRS phishing scams are alive...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/07/08/security-on-a-shoestring-smb-budget/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving data storage to the cloud? What&#8217;s your business continuity plan?</title>
		<link>http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/</link>
		<comments>http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 18:59:41 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[availability]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2259</guid>
		<description><![CDATA[Many trumpet increased availability as a reason to move to the cloud but what happens when your cloud provider is no longer available? Some companies are faced with this very question this week as storage provider, EMC  announced its plan to shut down its Atmos Online cloud storage service immediately, according to a posting on [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2261" title="ptr_emc-sm" src="http://infosec3t.com/wp-content/uploads/2010/07/ptr_emc-sm.jpg" alt="" width="169" height="98" />Many trumpet increased <a href="http://infosec3t.com/tag/availability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with availability">availability</a> as a reason to move to the cloud but what happens when your cloud provider is no longer available?</p>
<p>Some companies are faced with this very question this week as storage provider, EMC  announced its plan to shut down its Atmos Online cloud storage service immediately, according to <a href="http://www.atmosonline.com/" target="new">a posting on its  website</a>.</p>
<p>EMC launched Atmos Online in May 2009, calling it &#8220;Cloud Optimized Storage [with] capabilities that can scale effectively,  coupled with <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> and management tools.&#8221;  This placed EMC in direct competition with some of its service provider partners who used EMC&#8217;s Atmos technology to provide cloud storage to its customers.</p>
<p>EMC has now  downgraded Atmos Online to a development platform and is offering no guarantee as to the availability of user data moving forward. EMC used its web posting to &#8220;strongly encourage [companies to] migrate any critical data or production  workloads currently served via Atmos Online to one of our partners  offering Atmos based services,&#8221;</p>
<p>The provider going out of business is one of the many risks companies have to address when considering moving their critical data into the cloud. In this case, companies now have to spend resources doing the necessary due diligence in selecting an alternative cloud storage provider.</p>
<p>According to Morris Cody, CIO at Washington D.C. based Information Security Services Firm, Secure Intervention, companies moving to the cloud better consider the following:</p>
<div>1) Disaster Recover Plan &#8211;  The bottom line is that no cloud provider can guarantee 100% up time all the time. Even a cloud provider as large as <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> has experienced an outage in it&#8217;s cloud environment.  In that case, a solid disaster recover plan will help mitigate loses from several different perspectives (i.e., monetary, branding, current clients, new clients)</p>
<p>2) BCP &#8211; Having a business continuity plan in place that will work in conjunction with you cloud provide capabilities will mitigate the <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> of an outage do to an scheduled / unscheduled event (not necessarily a disaster) in you cloud provider environment.</p>
<p>3) SLA &#8211; a strong SLA should be established with your cloud provider that will hold them accountable for losses or damages (define losses and damages) do to changes in their environment that effect your business.  For example, if your cloud provider decides to shutdown the cloud hosting services, then they should be responsible for the cost to migrate your apps/data to the new hosting provider&#8221;</p></div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/' rel='bookmark' title='The real arguments for Cloud Computing'>The real arguments for Cloud Computing</a> <small>As more vendors dive into the cloud computing market, every...</small></li>
<li><a href='http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/' rel='bookmark' title='Will your Cloud Provider be around in two years?'>Will your Cloud Provider be around in two years?</a> <small>I just read that my hosting company, GoDaddy, is on...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Many companies caught in the lurch as Microsoft ends support for Windows XP 2</title>
		<link>http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/</link>
		<comments>http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 22:57:06 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2238</guid>
		<description><![CDATA[On July 13, Microsoft will officially retire Windows XP Service Pack 2 . Although it will continue to provide security updates for XP Service Pack 3, it will stop providing patches for the older SP2. Microsoft offers support for its products for five years and extended support for another five years. For XP SP2, that [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><img class="alignright size-full wp-image-2241" title="windows-xp-box" src="http://infosec3t.com/wp-content/uploads/2010/06/windows-xp-box.jpg" alt="" width="180" height="180" />On July 13, <a href="http://support.microsoft.com/gp/lifean31" target="_blank">Microsoft</a> will officially retire <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> XP Service Pack 2 . Although it will continue to provide <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> <a href="http://infosec3t.com/tag/updates/" class="st_tag internal_tag" rel="tag" title="Posts tagged with updates">updates</a> for XP Service Pack 3, it will stop providing patches for the older SP2. Microsoft offers support for its products for five years and extended support for another five years. For XP SP2, that journey comes to an end on July 13. Windows XP 3 will be supported until April 2014.</p>
<p>Microsoft issues security updates and other core operating system patches every second Tuesday of the month, known as Patch Tuesday. Whereas most home users typically install these patches automatically, corporate users usually install service packs and security updates manually and only after extensive testing. For large corporate environments,  operating system upgrades are often a very perilous and expensive exercise.</p>
<p>According to security <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> and compliance management provider Qualys, 50 percent of the several hundred thousand PCs it monitors for its clients are still running Windows XP SP2.  Most of these are probably user desktops, but some may also be applications and appliances that use Windows XP 2 as the base platform. Upgrading such systems may make them inoperable.</p>
<p>According to Sajed Naseem, principal at Washington DC based security firm, <a title="Secure Intervention" href="http://www.secureintervention.com" target="_blank">Secure Intervention</a>,</p>
<p>&#8221; The longer these systems  linger after the July 13 deadline, the more vulnerable they become. There will undoubtedly be many Windows XP 2 systems still out there and hackers know that. Only there will no longer be security patches coming from Microsoft as new holes are discovered and publicized.&#8221;</p>
</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/11/aaaah-the-infamous-blue-screen-of-death/' rel='bookmark' title='Aaaah The Infamous Blue Screen of Death'>Aaaah The Infamous Blue Screen of Death</a> <small>On Tuesday, Microsoft issued a patch, MS10-015,  to fix a...</small></li>
<li><a href='http://infosec3t.com/2010/03/11/microsoft-warns-of-new-ie-bug-being-exploited-by-hackers/' rel='bookmark' title='Microsoft warns of new IE bug being exploited by hackers'>Microsoft warns of new IE bug being exploited by hackers</a> <small>Microsoft Corp. today warned of a critical vulnerability in Internet...</small></li>
<li><a href='http://infosec3t.com/2010/03/03/microsoft-resumes-pushing-blue-screen-update/' rel='bookmark' title='Microsoft resumes pushing Blue Screen Update'>Microsoft resumes pushing Blue Screen Update</a> <small>Microsoft has resumed pushing out the patch connected to the...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;</title>
		<link>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/</link>
		<comments>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 17:13:22 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2231</guid>
		<description><![CDATA[Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun telling new employees that they are no longer able to request Windows PCs, giving them the choice of Mac or Linux systems. Google has long offered its employees their choice of work operating system but [...]]]></description>
			<content:encoded><![CDATA[<p><em> </em><img class="alignright size-full wp-image-2230" title="microsoft_piss" src="http://infosec3t.com/wp-content/uploads/2010/06/microsoft_piss.jpeg" alt="" width="127" height="114" />Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun  telling new employees that they are no longer able to request <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a>  PCs, giving them the choice of Mac or <a href="http://infosec3t.com/tag/linux/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Linux">Linux</a> systems. Google has long  offered its employees their choice of work operating system but will no  longer do so. According to a Google employee, any exceptions will require will require CIO approval. [ <em>I find that assertion questionable though</em> ].</p>
<p>Google is apparently making this decision in response to the hacking attacks on late last year in China. The attackers  used vulnerabilities  in <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a>&#8217;s <a href="http://infosec3t.com/tag/internet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet">Internet</a> Explorer 6 to go after Google&#8217;s intellectual property, believed to be source code.  One could argue that if they had updated their browsers, the attacker would have had to find other vectors for attacks.</p>
<p>Could this be a strategic move by Google to prove that an Enterprise can survive WITHOUT Microsoft? With Google&#8217;s Chrome OS on the horizon, this may just be the warm-up act.</p>
<p>Source: <a href="http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html" target="_blank">http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
<li><a href='http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/' rel='bookmark' title='Microsoft says Do Not Call for Help!'>Microsoft says Do Not Call for Help!</a> <small>If it sounds like a horror movie&#8230;.well, that&#8217;s because is...</small></li>
<li><a href='http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/' rel='bookmark' title='Use Google Apps or Gmail? Avoid getting hacked!'>Use Google Apps or Gmail? Avoid getting hacked!</a> <small>It can happen to the best of us. Blogger and...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The real arguments for Cloud Computing</title>
		<link>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/</link>
		<comments>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/#comments</comments>
		<pubDate>Thu, 20 May 2010 19:07:11 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[open source]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2209</guid>
		<description><![CDATA[As more vendors dive into the cloud computing market, every possible claim regarding the supposed benefits of moving to a cloud-based service is being made.  I ran across an article titled &#8221; Why Cloud-based Monitoring is more reliable and secure than Nagios. &#8221; The auth0r, who represented a cloud-based network monitoring company, contended that the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2211" title="cloud-computing" src="http://infosec3t.com/wp-content/uploads/2010/05/zenith-infotech-virtualized-cloud-computing-300x200.jpg" alt="" width="189" height="127" />As more vendors dive into the <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> market, every possible claim regarding the supposed benefits of moving to a cloud-based service is being made.  I ran across an article titled &#8221; Why Cloud-based Monitoring is more reliable and secure than Nagios. &#8221; The auth0r, who represented a cloud-based network monitoring company, contended that the Software-as-a-Service (SaaS) model offered by his company was better for companies than Nagios and other <a href="http://infosec3t.com/tag/open-source/" class="st_tag internal_tag" rel="tag" title="Posts tagged with open source">open source</a> products.</p>
<p>The question is not  Cloud Computing vs. Open Source.  In fact, there are open source SaaS providers like MindTouch out there.  If considering a product like Nagios, a better comparison would be open source vs. commercial.  In many cases, cost is the determining factor for companies to look  to open source technologies. Other considerations include flexibility and <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>.</p>
<p>The more relevant  comparison would be hosting and managing a network monitoring system on site vs. moving to a SaaS provider. For many organizations,  IT is considered overhead and not the primary function of the organization. Companies move to the cloud for most of the same reasons companies out-source.  Can someone else do it better for less?  Cost is ually the easier consideration. Companies have to grapple with the &#8216;better&#8217;. Does it mean more security, <a href="http://infosec3t.com/tag/availability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with availability">availability</a>, capacity? Many cloud providers would say &#8216;yes&#8217; to all and then some.  Organizations have to really consider and make that determination themselves. Make a real comparision between their options and not just follow the typical vendor hype.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/' rel='bookmark' title='Exploring Cloud Computing Information Leakage'>Exploring Cloud Computing Information Leakage</a> <small>If you are in cloud computing security (or part of...</small></li>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploring Cloud Computing Information Leakage</title>
		<link>http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/</link>
		<comments>http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/#comments</comments>
		<pubDate>Mon, 17 May 2010 19:23:15 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2198</guid>
		<description><![CDATA[If you are in cloud computing security (or part of an organization with infrastructure in a public cloud), this paper is a must read. As more organizations seek to realizes the benefits of the cloud, it&#8217;s important that we continue to investigate the risks as well. Granted this research only applies to virtual machines on [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2199" title="cloud-question-mark-cloud-computing" src="http://infosec3t.com/wp-content/uploads/2010/05/cloud-question-mark-cloud-computing-190x300.jpg" alt="" width="148" height="234" />If you are in <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> (or part of an organization with infrastructure in a public cloud), this paper is a must read. As more organizations seek to realizes the benefits of the cloud, it&#8217;s important that we continue to investigate the risks as well. Granted this research only applies to virtual machines on a shared host. Cloud Computing service provider usually provide &#8220;private&#8221; cloud offerings with only one client&#8217;s virtual machines  per physical server.</p>
<p>Does the remote chance of your virtual server being attacked by another virtual server on the same host server justify the added cost of a private cloud deployment? That&#8217;s for each client to decide. Ensure you are doing your due diligence before making a decision one way or the other.</p>
<p>Abstract:</p>
<p><em>Amazon’s EC2, allow users to instantiate virtual machines (VMs) on demand and thus purchase precisely the capacity they require when they require it.In turn, the use of <a href="http://infosec3t.com/tag/virtualization/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virtualization">virtualization</a> allows third-party cloud providers to maximize the utilization of their sunk capital costs by multiplexing many customer VMs across a shared physical infrastructure. However, in this paper, we show that this approach can also introduce new vulnerabilities.Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine.<br />
</em></p>
<p>Download paper: <a title="New window will open" href="http://people.csail.mit.edu/tromer/papers/cloudsec.pdf" target="_blank">http://people.csail.mit.edu/tromer/papers/cloudsec.pdf</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/04/cloud-computing-loss-of-confidentiality/' rel='bookmark' title='Cloud Computing = Loss of Confidentiality?'>Cloud Computing = Loss of Confidentiality?</a> <small>Interesting excerpt from article in ITWorldCanada: &#8220;Adi Shamir, a computer...</small></li>
<li><a href='http://infosec3t.com/2010/08/29/ibm-x-force-handicaps-future-trends-in-security/' rel='bookmark' title='IBM X-Force handicaps future trends in security'>IBM X-Force handicaps future trends in security</a> <small>Looking ahead, the X-Force Research and Development team has identified...</small></li>
<li><a href='http://infosec3t.com/2010/09/12/will-your-cloud-provider-be-around-in-two-years/' rel='bookmark' title='Will your Cloud Provider be around in two years?'>Will your Cloud Provider be around in two years?</a> <small>I just read that my hosting company, GoDaddy, is on...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec warns that port 25 could be the problem. I disagree.</title>
		<link>http://infosec3t.com/2010/05/11/symantec-warns-that-port-25-could-be-the-problem-i-disagree/</link>
		<comments>http://infosec3t.com/2010/05/11/symantec-warns-that-port-25-could-be-the-problem-i-disagree/#comments</comments>
		<pubDate>Tue, 11 May 2010 23:42:28 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2137</guid>
		<description><![CDATA[I recently overheard a comment by a co-worker ( shoutout Ben A.) that we read and listen to news reports and assumed the report knows what they are  talking about until they turn to a topic we are familiar with in some depth and realize that report spouting off to potentially millions of people don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-2138" title="duh-duh1233387823" src="http://infosec3t.com/wp-content/uploads/2010/05/duh-duh1233387823-300x158.jpg" alt="" width="300" height="158" />I recently overheard a comment by a co-worker ( shoutout Ben A.) that we read and listen to news reports and assumed the report knows what they are  talking about until they turn to a topic we are familiar with in some depth and realize that report spouting off to potentially millions of people don&#8217;t have a clue what they are talking about.  How true!</p>
<p>I ran into this article today  titled &#8221; <em><a href="http://www.v3.co.uk/v3/news/2262681/botnets-exploit-linux-owners" target="_blank">Botnet exploits Linux users&#8217; ignorance</a>&#8220;. </em>The writer makes the point that &#8221; a lack of knowledge and <a href="http://infosec3t.com/tag/awareness/" class="st_tag internal_tag" rel="tag" title="Posts tagged with awareness">awareness</a> about how to use Linux mail servers  could be contributing to the disproportionately large number of Linux machines  being exploited to send <a href="http://infosec3t.com/tag/spam/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spam">spam</a>&#8221;.</p>
<p>I wholeheartedly agree with this. Companies see open source technologies as a means of saving money but do not have staff adequately trained to secure these systems.</p>
<p>The second point I noticed was that the report from Symantec&#8217;s Hosted Services referenced in the article pointed out that &#8221; Linux based machines are 5 times more likely to send out spam than <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> based computers&#8221;.</p>
<p>The writer quotes a Symantec Malware Analyst as saying:</p>
<p>&#8220;&#8230;..one reason there is so much spam from Linux could be  that many companies that have implemented their own mail servers, and are  using open-source software to keep costs down, have not realised that leaving  port 25 open to the Internet also leaves them open to abuse.&#8221;</p>
<div>That is just misleading. It&#8217;s like saying shut down port 80 on your web server to prevent your web site from being defaced or hacked. Port 25 is not the problem, mis-configured web services are the problem.</div>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/08/5-open-source-alternatives-to-microsoft-office/' rel='bookmark' title='5 Open Source Alternatives to Microsoft Office'>5 Open Source Alternatives to Microsoft Office</a> <small>The Microsoft Office productivity suite has risen to become the...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/01/25/botnets-give-the-hacker-espionage-tools-formerly-reserved-for-nation-states/' rel='bookmark' title='Botnets give the hacker espionage tools formerly reserved for nation states'>Botnets give the hacker espionage tools formerly reserved for nation states</a> <small>The cyber attacks against Google, Adobe and a raft of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/05/11/symantec-warns-that-port-25-could-be-the-problem-i-disagree/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If Microsoft can do it, why not McAfee?</title>
		<link>http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/</link>
		<comments>http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 18:54:06 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2111</guid>
		<description><![CDATA[Yesterday, a faulty McAfee anti-virus update labeled a critical Microsoft system file as a &#8220;virus&#8221; causing hundreds of thousands of computers around the world with Windows XP Service Pack 3 running  to go into a continuous reboot cycle [duh!]. Today, however, Sophos is reporting hackers are compounding the problem by using blackhat SEO (search engine [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, a faulty McAfee anti-virus update labeled a critical <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> system file as a &#8220;virus&#8221; causing hundreds of thousands of computers around the world with <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> XP Service Pack 3 running  to go into a continuous reboot cycle [duh!].</p>
<p>Today, however, Sophos is reporting hackers are compounding the problem by using <a href="http://www.sophos.com/blogs/gc/g/2010/03/31/automated-seo-poisoning-attacks-explained/" target="_blank">blackhat SEO (search engine optimisation)</a> techniques to create webpages stuffed with content which appears to be related to McAfee&#8217;s false alarm problem &#8211; but are really designed to infect visiting computers.</p>
<p>Sophos has identified malicious webpages which appear on the first page of <a href="http://infosec3t.com/tag/google/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Google">Google</a> results if users search for phrases associated with McAfee&#8217;s false positive.</p>
<p><img class="aligncenter size-full wp-image-2112" title="mcafee-false-positive-attack" src="http://infosec3t.com/wp-content/uploads/2010/04/mcafee-false-positive-attack.jpg" alt="" width="548" height="411" />&#8220;It&#8217;s bad enough if many of the computers in your company are out of action because of a faulty <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> update, but it&#8217;s even worse if you infect your network by Googling for a fix,&#8221; explained <a href="http://www.sophos.com/pressoffice/contacts/grahamc.html" target="_blank">Graham Cluley</a>, senior technology consultant for Sophos. &#8220;These poisoned pages are appearing on the very first page of search engine results, making it likely that many will click on them. If you visit the links you may see pop-up warnings telling you about security issues with your computer. The warnings are fake and designed to trick you into downloading dangerous software, which could result in hackers gaining control of your corporate computers or the theft of your credit card details.&#8221;</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/03/top-ten-malware-hosting-countries-revealed/' rel='bookmark' title='Top ten malware-hosting countries revealed'>Top ten malware-hosting countries revealed</a> <small>US and UK among the top 10 countries hosting the...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
<li><a href='http://infosec3t.com/2010/01/14/beware-of-haiti-theme-scams-and-attacks/' rel='bookmark' title='Beware of Haiti-Themed Scams and Attacks!'>Beware of Haiti-Themed Scams and Attacks!</a> <small>Our thoughts and prayers go out to all those affected...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/22/if-microsoft-can-do-it-why-not-mcafee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nessus 4.2.2 now released</title>
		<link>http://infosec3t.com/2010/04/15/nessus-4-2-2-now-released/</link>
		<comments>http://infosec3t.com/2010/04/15/nessus-4-2-2-now-released/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 17:05:53 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2094</guid>
		<description><![CDATA[Version version 4.2.2 released today brings the following fixes: Nessus-fetch: Proxy issues have been resolved. NASL: Fixed a memory leak in the NASL xmlparse() function. Networking: Fixed IPv6 routing when talking to a remote host (FreeBSD, Mac OS X). Packet forgery was not always working on ES5 64 bits. Packaging: Fixed the Debian /etc/rc init [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2095" title="nessus-logo" src="http://infosec3t.com/wp-content/uploads/2010/04/nessus-logo.jpg" alt="" width="105" height="105" />Version version 4.2.2 released today brings the following fixes:</p>
<ul>
<li>Nessus-fetch: Proxy issues have been resolved.</li>
<li>NASL: Fixed a memory leak in the NASL xmlparse() function.</li>
<li>Networking: Fixed IPv6 routing when talking to a remote host (FreeBSD, <a href="http://infosec3t.com/tag/mac/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MAC">Mac</a> OS X). Packet forgery was not always working on ES5 64 bits.</li>
<li>Packaging: Fixed the Debian /etc/rc init script. Upgraded OpenSSL to version 0.9.8n (<a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a>, Solaris)</li>
<li>Stability: Fixed a possible crash when using a badly written custom plugin. Fixed a possible crash when running out of BPFs on Windows.</li>
</ul>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/05/mozilla-confirms-trojan-infected-firefox-add-ons/' rel='bookmark' title='Mozilla confirms Trojan-infected Firefox add-ons'>Mozilla confirms Trojan-infected Firefox add-ons</a> <small>If you are a Firefox user, as I am, you...</small></li>
<li><a href='http://infosec3t.com/2010/02/11/mozilla-retracts-malware-accusation-against-firefox-extension/' rel='bookmark' title='Mozilla Retracts Malware Accusation Against Firefox Extension'>Mozilla Retracts Malware Accusation Against Firefox Extension</a> <small>Six days ago, I posted that Mozilla had reported in...</small></li>
<li><a href='http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/' rel='bookmark' title='Many companies caught in the lurch as Microsoft ends support for Windows XP 2'>Many companies caught in the lurch as Microsoft ends support for Windows XP 2</a> <small>On July 13, Microsoft will officially retire Windows XP Service...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/15/nessus-4-2-2-now-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing Security: An Insider&#039;s View</title>
		<link>http://infosec3t.com/2010/04/02/cloud-computing-security-an-insiders-view/</link>
		<comments>http://infosec3t.com/2010/04/02/cloud-computing-security-an-insiders-view/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 22:40:33 +0000</pubDate>
		<dc:creator>Guest Blogger</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2062</guid>
		<description><![CDATA[As CSO of Qualys, Randy Barr is responsible for security, risk management and business continuity planning of the QualysGuard platform. In this video Randy talks about cloud computing security from an insider&#8217;s point of view. He illustrates what a security professional has to go through when building a security program for a cloud environment. For [...]]]></description>
			<content:encoded><![CDATA[<!-- ProPlayer by Isa Goksu --><div name="mediaspace" id="mediaspace"><div class="pro-player-container" width="575px" height="350px"><div id="pro-player-2062pp-single-4fb96ef94faa8"></div></div></div><script type="text/javascript" charset="utf-8">var flashvars = {width: "575",height: "350",autostart: "false",repeat: "false",backcolor: "111111",frontcolor: "cccccc",lightcolor: "66cc00",stretching: "fill",enablejs: "true",mute: "false",skin: "http://infosec3t.com/wp-content/plugins/proplayer/players/skins/default.swf",image: "http://infosec3t.com/wp-content/plugins/proplayer/players/preview.png",plugins: "",javascriptid: "2062pp-single-4fb96ef94faa8",image: "http://infosec3t.com/wp-content/plugins/proplayer/players/preview.png",file: 'http://infosec3t.com/wp-content/plugins/proplayer/playlist-controller.php?pp_playlist_id=2062pp-single-4fb96ef94faa8&sid=1337552633'};var params = {wmode: "transparent",allowfullscreen: "true",allowscriptaccess: "always",allownetworking: "all"};var attributes = {id: "obj-pro-player-2062pp-single-4fb96ef94faa8",name: "obj-pro-player-2062pp-single-4fb96ef94faa8"};swfobject.embedSWF("http://infosec3t.com/wp-content/plugins/proplayer/players/player.swf", "pro-player-2062pp-single-4fb96ef94faa8", "575", "350", "9.0.0", false, flashvars, params, attributes);</script>
<p>As CSO of Qualys, Randy Barr is responsible for <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a>, <a href="http://infosec3t.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> management and business continuity planning of the QualysGuard platform. In this video Randy talks about <a href="http://infosec3t.com/tag/cloud-computing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with cloud computing">cloud computing</a> security from an insider&#8217;s point of view. He illustrates what a security professional has to go through when building a security program for a cloud environment.</p>
<p>For more security-related material visit Help Net Security: <a title="http://www.net-security.org" dir="ltr" rel="nofollow" href="http://www.youtube.com/redirect?username=helpnetsecurity&amp;q=http%3A%2F%2Fwww.net-security.org&amp;video_id=B2FMMcyYbt4&amp;event=url_redirect&amp;url_redirect=True&amp;usg=suzeyLKuY4EHJkc0rTGEIAE5EAs=" target="_blank">http://www.net-security.org</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/05/20/the-real-arguments-for-cloud-computing/' rel='bookmark' title='The real arguments for Cloud Computing'>The real arguments for Cloud Computing</a> <small>As more vendors dive into the cloud computing market, every...</small></li>
<li><a href='http://infosec3t.com/2009/12/10/cloud-security-alliance/' rel='bookmark' title='Cloud Security Alliance'>Cloud Security Alliance</a> <small>For more information on Cloud Computing Security, a good resource...</small></li>
<li><a href='http://infosec3t.com/2010/05/17/exploring-cloud-computing-information-leakage/' rel='bookmark' title='Exploring Cloud Computing Information Leakage'>Exploring Cloud Computing Information Leakage</a> <small>If you are in cloud computing security (or part of...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/04/02/cloud-computing-security-an-insiders-view/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another fake security software alert</title>
		<link>http://infosec3t.com/2010/03/17/another-fake-security-software-alert/</link>
		<comments>http://infosec3t.com/2010/03/17/another-fake-security-software-alert/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 23:26:56 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[desktop security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1942</guid>
		<description><![CDATA[I&#8221;ve previously warned of fake security software or scareware. Here&#8217;s a second helping. Beware of the following: XP Security Tool 2010 is a rogue virus protection program. It reports false scan results and fake security alerts to scare you into purchasing this rogue program. XPSecurityTool2010 claims that your computer is infected with worms, trojans, adware [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-947 alignright" title="DesktopDefender2010-500x399" src="http://infosec3t.com/wp-content/uploads/2010/01/DesktopDefender2010-500x399-300x239.jpg" alt="" width="234" height="186" />I&#8221;ve previously <a href="http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/"><strong>warned</strong></a> of fake security software or scareware. Here&#8217;s a second helping. Beware of the following:</p>
<p><strong>XP Security Tool 2010</strong> is a rogue <a href="http://infosec3t.com/tag/virus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with virus">virus</a> protection program. It reports false scan results and fake security alerts to scare you into purchasing this rogue program. XPSecurityTool2010 claims that your computer is infected with worms, <a href="http://infosec3t.com/tag/trojans/" class="st_tag internal_tag" rel="tag" title="Posts tagged with trojans">trojans</a>, adware or other malware and that you should purchase XP Security Tool 2010 to remove the infections that actually don&#8217;t even exist. Most of the time, this fake program comes from fake or infected video sites or fake online scanners. But may be also promoted on such popular sites as <a href="http://infosec3t.com/tag/facebook/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Facebook">Facebook</a> or MySpace.</p>
<p><strong>Vista Security Tool 2010</strong> is a rogue anti-malware program that usually comes from fake online scanners and fake video websites. While running, this fake program will run a fake system scan and report numerous spyware infections to make you think that your computer is infected with various malware. Then it will ask you to pay for a full version of the program to remove the infections which as well already know don&#8217;t even exist.</p>
<p><strong>Total Win 7 Security</strong> is a fake anti-spyware program that is promoted through the use of trojans and other malicious software. Most of the time, TotalWin7Security comes from fake online scanners, fake video websites or bundled with other malware. Once installed,Total Win 7 Security will imitate a system scan and display numerous infections that can&#8217;t be removed unless you first purchase the program.</p>
<p>For more information on how to rid your systems of these and others of their elk, check out <a href="http://www.2-spyware.com/" target="_blank">http://www.2-spyware.com/</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/22/fake-security-software-pose-great-risk/' rel='bookmark' title='Fake Security Software pose great risk'>Fake Security Software pose great risk</a> <small>Desktop Security 2010 is the proverbial wolf in sheep&#8217;s clothing....</small></li>
<li><a href='http://infosec3t.com/2010/01/28/fake-virus-alert-spreads-massively-across-facebook/' rel='bookmark' title='Fake virus alert spreads massively across Facebook'>Fake virus alert spreads massively across Facebook</a> <small>Panda Security has released the following advisory: In the last...</small></li>
<li><a href='http://infosec3t.com/2010/01/27/2010-year-of-the-zombie-cloud/' rel='bookmark' title='2010 Year of the Zombie Cloud'>2010 Year of the Zombie Cloud</a> <small>As more organizations consider moving into the cloud to benefit...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/17/another-fake-security-software-alert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA 2010 Recap</title>
		<link>http://infosec3t.com/2010/03/05/rsa-2010-recap/</link>
		<comments>http://infosec3t.com/2010/03/05/rsa-2010-recap/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 17:44:20 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Users]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[rsa]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1735</guid>
		<description><![CDATA[Today is the last day of RSA Conference 2010. If you didn’t make it,  CSOonline.com has provided a recap of the highlights here.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1736" title="RSA2010" src="http://infosec3t.com/wp-content/uploads/2010/03/RSA2010.jpg" alt="" width="220" height="220" />Today is the last day of <a href="http://infosec3t.com/tag/rsa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with rsa">RSA</a> Conference 2010. If you didn&#8217;t make it,  CSOonline.com has provided a recap of the highlights:</p>
<p><strong>RSA COVERAGE</strong></p>
<p><a href="http://www.csoonline.com/article/563513" target="_blank">RSA 2010: Infosec Pros Get Raises Despite Recession </a>An (ISC)2 survey suggests salary increases and hiring went up for many <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> practitioners in the last year despite the    Great Recession. Ironically, the recession may be WHY it&#8217;s happening.</p>
<p><a href="http://www.csoonline.com/article/559863">RSA 2010: Why 41 Percent of You Would Fail a PCI Audit </a>Miscellaneous news bytes from the RSA 2010 press room: QSAs tell Ponemon Institute that 41 percent of companies would bomb    their PCI security audit; hackers industrialize their sinister revolution and VeriSign opens a new compatibility lab.</p>
<p><a href="http://www.csoonline.com/article/558913" target="_blank">RSA 2010: Can Adobe Stop the Hate? </a>Security pros are unhappy with Adobe Systems over recent flaws and attacks. Adobe Security Chief Brad Arkin on what the company    is doing about it.</p>
<p><a href="http://www.csoonline.com/article/556713" target="_blank">RSA Conference 2010: 4 Survival Tips</a>For the newcomer, the RSA security conference can be overwhelming. Follow these four strategies to get the most from it.</p>
<p><a href="http://www.csoonline.com/article/564387" target="_blank">Social Networking is Risky Business</a> From Computerworld: A panel discusses the risks associated with social networking sites.</p>
<p><a href="http://www.csoonline.com/article/564375" target="_blank">Chertoff: Tracking Attacks to the Source is Key for Cybersecurity</a> From Computerworld: An exclusive interview with former DHS leader Michael Chertoff.</p>
<p><strong>RSA PODCASTS</strong></p>
<p>RSA 2010: <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a>&#8217;s Plan for Cloud Security Audio: <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a> VP Jim Jones explains his company&#8217;s approach for securing its services in the cloud.</p>
<p><a href="http://www.csoonline.com/podcast/559463" target="_blank">RSA 2010: Verizon Releases Its Threat Report Recipe</a> Verizon Business will share the research framework used for its Data Breach Investigations Reports so companies can create    reports tailored to their specific environments.</p>
<p><strong>SECURITY B-SIDES COVERAGE</strong></p>
<p><a href="http://www.csoonline.com/article/561913" target="_blank">Security B-Sides: Perfect Authentication Remains Elusive </a>Everyone realizes passwords have their shortcomings. But alternatives like two-factor authentication are not as powerful as    one would expect. The problem? As always &#8212; human behavior.</p>
<p><a href="http://www.csoonline.com/article/561663" target="_blank">One Man&#8217;s Life on the Security D-List</a> At Security B-Sides, infosec author Andrew Hay explains the four pillars for moving from the bottom of the IT security shop    to a place of respect, and why getting to the A-list isn&#8217;t all it&#8217;s cracked up to be.</p>
<p><a href="http://www.csoonline.com/article/554613" target="_blank">Security B-Sides: Rise of the &#8216;Anti-conference&#8217; </a>The RSA 2010 conference had some nearby competition. Here&#8217;s the story of Security B-Sides as the conference alternative.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/07/shmoocom-2010-videos-online/' rel='bookmark' title='Shmoocon 2010 Videos Online'>Shmoocon 2010 Videos Online</a> <small>Shmoocon was this weekend. Unfortunately,I couldn&#8217;t get a ticket this...</small></li>
<li><a href='http://infosec3t.com/2010/04/20/top-10-web-application-security-risks-for-2010/' rel='bookmark' title='Top 10 Web Application Security Risks for 2010'>Top 10 Web Application Security Risks for 2010</a> <small>Yesterday, OWASP released its list of top ten web application...</small></li>
<li><a href='http://infosec3t.com/2010/01/02/black-hat-dc-2010-is-here/' rel='bookmark' title='Black Hat DC -2010 is here!'>Black Hat DC -2010 is here!</a> <small>Black Hat, one of the biggest and most popular security...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/05/rsa-2010-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to back up and restore your digital media</title>
		<link>http://infosec3t.com/2010/02/22/how-to-back-up-your-digital-media/</link>
		<comments>http://infosec3t.com/2010/02/22/how-to-back-up-your-digital-media/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 16:07:06 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[availability]]></category>
		<category><![CDATA[backups]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1565</guid>
		<description><![CDATA[Many organizations realize that backing up critical data is an essential part of business operations. Sadly, it is often the case that home computer users don&#8217;t take the same precautions, even with built-in functionality at their finger tips. One of the three principals of security is availability. Backing up your files are a necessary step [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1566" title="backup" src="http://infosec3t.com/wp-content/uploads/2010/02/backup.jpg" alt="" width="136" height="132" />Many organizations realize that backing up critical data is an essential part of business operations. Sadly, it is often the case that home computer users don&#8217;t take the same precautions, even with built-in functionality at their finger tips. One of the three principals of <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> is <a href="http://infosec3t.com/tag/availability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with availability">availability</a>. Backing up your files are a necessary step in ensuring <a href="http://infosec3t.com/tag/availability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with availability">availability</a> i.e. being able to access your data when needed.</p>
<p>This article walks you through scheduling <a href="http://infosec3t.com/tag/backups/" class="st_tag internal_tag" rel="tag" title="Posts tagged with backups">backups</a> and restoring your data in <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> XP and <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> 7.</p>
<p>PC Advisor: <a href="http://www.pcadvisor.co.uk/news/index.cfm?RSS&amp;NewsID=3213247" target="_blank">How to back up your digital media</a></p>
<p>PC Advisor: <a href="http://www.pcadvisor.co.uk/news/index.cfm?RSS&amp;NewsID=3213253" target="_blank">How to restore data from a backup</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/07/05/moving-data-storage-to-the-cloud-whats-your-business-continuity-plan/' rel='bookmark' title='Moving data storage to the cloud? What&#8217;s your business continuity plan?'>Moving data storage to the cloud? What&#8217;s your business continuity plan?</a> <small>Many trumpet increased availability as a reason to move to...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/06/02/many-companies-caught-in-the-lurch-as-microsoft-ends-support-for-windows-xp-2/' rel='bookmark' title='Many companies caught in the lurch as Microsoft ends support for Windows XP 2'>Many companies caught in the lurch as Microsoft ends support for Windows XP 2</a> <small>On July 13, Microsoft will officially retire Windows XP Service...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/02/22/how-to-back-up-your-digital-media/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010 Year of the Zombie Cloud</title>
		<link>http://infosec3t.com/2010/01/27/2010-year-of-the-zombie-cloud/</link>
		<comments>http://infosec3t.com/2010/01/27/2010-year-of-the-zombie-cloud/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 17:27:20 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[illegal website]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1072</guid>
		<description><![CDATA[As more organizations consider moving into the cloud to benefit from the evident cost savings  and focus more on their core business functions, the bad guys are also looking for the benefits. 2009 has been a notable year for malware and malicious online activity for a number of reasons and several of them relate to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/zombie-gnaws-on-imac_270x405.jpg"><img class="size-medium wp-image-1073 alignleft" title="zombie-gnaws-on-imac_270x405" src="http://infosec3t.com/wp-content/uploads/2010/01/zombie-gnaws-on-imac_270x405-200x300.jpg" alt="" width="200" height="300" /></a></p>
<p>As more organizations consider moving into the cloud to benefit from the evident cost savings  and focus more on their core business functions, the bad guys are also looking for the benefits.</p>
<p>2009 has been a notable year for <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a> and malicious online activity for a number of reasons and several of them relate to what is known as botnets. A zombie, or a bot, is a PC infected by <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a> that brings it under the remote control of a criminal. Criminals run networks that can range from thousands to millions of infected machines and they use them to power most of the cybercrime we see today including <a href="http://infosec3t.com/tag/spam/" class="st_tag internal_tag" rel="tag" title="Posts tagged with spam">spam</a>, DDoS, scareware, phishing, and malicious or illegal website hosting. They have a finger in every cybercriminal pie.</p>
<p>In the first half of the year, the Conficker worm (also known as Downadup or Kido) stole all the headlines in the malware world. Eventually the Conficker <a href="http://infosec3t.com/tag/botnet/" class="st_tag internal_tag" rel="tag" title="Posts tagged with botnet">botnet</a> was seen to deliver standard cybercriminal payloads, such as spambots and Fake AV (or scareware), much to the disappointment of some of the more hysterical commentators. Just because the outbreak received so much coverage that died away just as rapidly, don’t be fooled into thinking this threat has gone away. The Conficker Working Group, an alliance of security vendors, researchers and other commercial organisations is currently showing around 6 million unique IP addresses as appearing to be infected with this malware.</p>
<p>An unrelated, but important trend in 2009 was the exponential increase in the abuse of social networking providers for malicious purposes. The enormous active user populations on sites like Facebook, Twitter and MySpace prove a very attractive lure to organised online crime and its attendant money-making, bot recruitment and Fake AV pushing <a href="http://infosec3t.com/tag/scams/" class="st_tag internal_tag" rel="tag" title="Posts tagged with scams">scams</a>. Facebook has been abused by rogue Apps, designed to fool users into clicking links that reward the creator through pay-per-click affiliate advertising networks. It has also been used to spread malware through many means; malicious links in wall posts and messages, malware designed specifically to hijack accounts and by external compromise of legitimate Facebook Apps. The Koobface family of malware (also a botnet) has evolved over the course of 2009; it was initially spread through malicious messages and wall posts with links to fake YouTube sites punting a supposed codec in order to view the video. The codec of course was nothing of the sort and led to infection and account hijacking. Koobface now though has evolved to the point where it is fully capable of creating its own fake Facebook profile pages, complete with confirmed Gmail address, photo and biographical data. These fake accounts then set about joining networks and sending friend requests again all in a completely automated fashion.</p>
<p>Read more at <a href="http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/" target="_blank">http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/17/another-fake-security-software-alert/' rel='bookmark' title='Another fake security software alert'>Another fake security software alert</a> <small>I&#8221;ve previously warned of fake security software or scareware. Here&#8217;s...</small></li>
<li><a href='http://infosec3t.com/2010/01/28/fake-virus-alert-spreads-massively-across-facebook/' rel='bookmark' title='Fake virus alert spreads massively across Facebook'>Fake virus alert spreads massively across Facebook</a> <small>Panda Security has released the following advisory: In the last...</small></li>
<li><a href='http://infosec3t.com/2010/08/14/sweet-yourr-bootyy-look-awseome-on-thiss-ivdeo/' rel='bookmark' title='Sweet!! Yourr bootyy look awseome on thiss ivdeo!'>Sweet!! Yourr bootyy look awseome on thiss ivdeo!</a> <small>Gee Thanks! I&#8217;ve been working out! &#8230;..oh wait a minute!...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/27/2010-year-of-the-zombie-cloud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

