<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><!-- generator="wordpress/2.3.3" --><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>InfosecBlurb.com</title>
	<link>http://www.dbergert.com/infosecblurb</link>
	<description>Infosec News, Rants &amp; Raves</description>
	<pubDate>Fri, 28 Mar 2008 00:27:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<geo:lat>41.551883</geo:lat><geo:long>-90.489751</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Infosecblurb" type="application/rss+xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.rojo.com/add-subscription?resource=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://blog.rojo.com/RojoWideRed.gif">Subscribe with Rojo</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Infosecblurb" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FInfosecblurb" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:browserFriendly>Infosecblurb, "Just another Network Security IT/Risk Managment Blog" by David B</feedburner:browserFriendly><item>
		<title>www.paymentsystemsblog.com</title>
		<link>http://www.dbergert.com/infosecblurb/wwwpaymentsystemsblogcom/2008/03/27/</link>
		<comments>http://www.dbergert.com/infosecblurb/wwwpaymentsystemsblogcom/2008/03/27/#comments</comments>
		<pubDate>Fri, 28 Mar 2008 00:27:58 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/wwwpaymentsystemsblogcom/2008/03/27/</guid>
		<description>I ran into someone recently who said they found my blog, and that I haven&amp;#8217;t updated it it a year !!!, &amp;#8212; well I have a few days left, so here is a post right before the year gap of posting   I have another blog that is more active then this one.  [...]</description>
			<content:encoded><![CDATA[<p>I ran into someone recently who said they found my blog, and that I haven&#8217;t updated it it a year !!!, &#8212; well I have a few days left, so here is a post right before the year gap of posting <img src='http://www.dbergert.com/infosecblurb/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I have another blog that is more active then this one.  <a href="http://www.paymentsystemsblog.com">www.paymentsystemsblog.com</a> While I might make infrequent posts here, most of my blogging will be related to payment systems and payment systems security.  </p>
<p>Come on over.<br />
DB</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=Gqi7vr"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=Gqi7vr" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/wwwpaymentsystemsblogcom/2008/03/27/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Expired Cards Safe ? - Think again TJX</title>
		<link>http://www.dbergert.com/infosecblurb/expired-cards-safe-think-again-tjx/2007/04/02/</link>
		<comments>http://www.dbergert.com/infosecblurb/expired-cards-safe-think-again-tjx/2007/04/02/#comments</comments>
		<pubDate>Mon, 02 Apr 2007 12:48:02 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/expired-cards-safe-think-again-tjx/2007/04/02/</guid>
		<description>From the TJX Credit Card Theft Story: www.msnbc.msn.com/id/17853440/

TJX Cos., the owner of about 2,500 stores, said in a regulatory filing late Wednesday that about three-quarters of those cards had either expired at the time of the theft, or data from their magnetic strips had been masked — stored as asterisks rather than numbers.

The whole expired [...]</description>
			<content:encoded><![CDATA[<p><img height="86" alt="expired" src="http://www.dbergert.com/infosecblurb/wp-content/uploads/2007/04/expired.jpg" width="90" align="right" /></p>
<p>From the TJX Credit Card Theft Story: <a href="http://www.msnbc.msn.com/id/17853440/">www.msnbc.msn.com/id/17853440/</a></p>
<blockquote>
<p>TJX Cos., the owner of about 2,500 stores, said in a regulatory filing late Wednesday that about <strong><u><em><font color="red">three-quarters of those cards had either expired at the time of the theft</font></em></u></strong>, or data from their magnetic strips had been masked — stored as asterisks rather than numbers.</p>
</blockquote>
<p>The whole expired card thing is funny. It is spin. Just like stating a lost laptop was &#8220;password protected&#8221; and that the data was safe because its required a password.</p>
<p>TJX states - Hey don&#8217;t worry these were expired cards, 75% of them were !!! &#8212; Implying that these cards have no use to the attackers.</p>
<p>Have you ever noticed what happens when your card expires ?</p>
<p>Here is the answer, you don&#8217;t get a new account number, your expiration date is incremented by a few years. Further yet, most authorization hosts do not match the expiration date on the card, they check the provided expiration date to the current date, and if it occurred in the past you get an expired card response code.</p>
<p>Sigh&#8230;</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=mXCTcy"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=mXCTcy" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/expired-cards-safe-think-again-tjx/2007/04/02/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows zero-day flaw ‘very dangerous,’ experts say</title>
		<link>http://www.dbergert.com/infosecblurb/windows-zero-day-flaw-very-dangerous-experts-say/2007/03/31/</link>
		<comments>http://www.dbergert.com/infosecblurb/windows-zero-day-flaw-very-dangerous-experts-say/2007/03/31/#comments</comments>
		<pubDate>Sun, 01 Apr 2007 00:09:27 +0000</pubDate>
		<dc:creator>kketelsen</dc:creator>
		
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/windows-zero-day-flaw-very-dangerous-experts-say/2007/03/31/</guid>
		<description>http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;#038;articleId=9015138


The Windows zero-day bug now being used by attackers is extremely dangerous, security researchers said today, and ranks with the Windows Metafile vulnerability of more than a year ago on the potential damage meter
&amp;#8220;This is a good exploit,&amp;#8221; Roger Thompson, CTO of Exploit Prevention Labs, said in an instant message exchange. &amp;#8220;It&amp;#8217;s very dangerous. [...]</description>
			<content:encoded><![CDATA[<p><a> http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9015138</a></p>
</p>
<p></a></p>
<p>The Windows zero-day bug now being used by attackers is extremely dangerous, security researchers said today, and ranks with the Windows Metafile vulnerability of more than a year ago on the potential damage meter</p>
<p>&#8220;This is a good exploit,&#8221; Roger Thompson, CTO of Exploit Prevention Labs, said in an instant message exchange. &#8220;It&#8217;s very dangerous. One of the reasons is that there&#8217;s no crash involved&#8230;it&#8217;s instantaneous. And all it takes is visiting a site.&#8221;</p>
<p>and <a href="http://isc.sans.org/diary.html?storyid=2542">SANS InfoCon has been raised to Yellow</a> because of this.</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=Y0cBIw"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=Y0cBIw" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/windows-zero-day-flaw-very-dangerous-experts-say/2007/03/31/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Encryption to the MAXX and the false sense of “Security” of encryption</title>
		<link>http://www.dbergert.com/infosecblurb/encryption-to-the-maxx-and-the-false-sense-of-security-of-encryption/2007/03/29/</link>
		<comments>http://www.dbergert.com/infosecblurb/encryption-to-the-maxx-and-the-false-sense-of-security-of-encryption/2007/03/29/#comments</comments>
		<pubDate>Thu, 29 Mar 2007 18:25:23 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/encryption-to-the-maxx-and-the-false-sense-of-security-of-encryption/2007/03/29/</guid>
		<description>I&amp;#8217;m sure everyone is familiar with the T.J. Maxx and Credit Card loss.  MSNBC has an article here.  There was one paragraph that caught my eye :
&amp;#8220;But TJX acknowledged it still knows little about the full scope of the breach, in part because the hacker or hackers accessed TJX’s encryption software and could [...]</description>
			<content:encoded><![CDATA[<p><img height="64" alt="TJMAX" hspace="5" src="http://www.dbergert.com/images/tjmax.jpg" width="90" align="right" vspace="5" /></p>
<p>I&#8217;m sure everyone is familiar with the T.J. Maxx and Credit Card loss.  MSNBC has an article <a href="http://www.msnbc.msn.com/id/17853440/">here</a>.  There was one paragraph that caught my eye :</p>
<p><u><em>&#8220;But TJX acknowledged it still knows little about the full scope of the breach, in part because the hacker or hackers accessed TJX’s encryption software and could have known how to unscramble the information&#8221;</em></u></p>
<p>What you mean, encryption isn&#8217;t the end all solution !?! <img src='http://www.dbergert.com/infosecblurb/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>My biggest complaint against &#8220;encryption&#8221; is a number a factors, including key management, but here is the biggest:</p>
<p><strong>Encryption does not protection against application layer attacks.</strong> With encrypting databases you have two options:</p>
<ul dir="ltr">
<li>
<div>Column Level Encryption:</div>
</li>
<li>
<div>Transparent Encryption or Disk Encryption.</div>
</li>
</ul>
<p>If attacks <strong>impersonate</strong> the application, using column level encryption a SQL injection attack could call the decrypt function or stored procedure (a little harder to do, depending if you encryption logic is contained in the database or application itself), and if your using not using column level encryption, the information from the database is decrypted when it is read, File level encryption is great for lost hard drives and hardware.</p>
<p>Guess what is easier to implement ? and doesn&#8217;t require re-writing code? Guess what most people implement? Guess what will still happen in the future, - Injection attacks against &#8220;encrypted&#8221; databases and credit card breaches&#8230;</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=cHA9M5"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=cHA9M5" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/encryption-to-the-maxx-and-the-false-sense-of-security-of-encryption/2007/03/29/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wireless LAN security myths that won’t die</title>
		<link>http://www.dbergert.com/infosecblurb/wireless-lan-security-myths-that-won%e2%80%99t-die/2007/03/27/</link>
		<comments>http://www.dbergert.com/infosecblurb/wireless-lan-security-myths-that-won%e2%80%99t-die/2007/03/27/#comments</comments>
		<pubDate>Tue, 27 Mar 2007 22:54:19 +0000</pubDate>
		<dc:creator>kketelsen</dc:creator>
		
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/wireless-lan-security-myths-that-won%e2%80%99t-die/2007/03/27/</guid>
		<description>Some good comments on Wireless Security and those items that are security theatre:

It&amp;#8217;s been two years since I wrote &amp;#8220;The six dumbest ways to secure a wireless LAN,&amp;#8221; and it&amp;#8217;s probably been one of my more successful blog entries ever, with two flashes on Digg. Since that time, I&amp;#8217;ve written a free electronic book on [...]</description>
			<content:encoded><![CDATA[<p>Some good comments on Wireless Security and those items that are security theatre:</p>
<blockquote>
<p>It&#8217;s been two years since I wrote &#8220;<strong><a href="http://blogs.zdnet.com/Ou/index.php?p=43">The six dumbest ways to secure a wireless LAN</a></strong>,&#8221; and it&#8217;s probably been one of my more successful blog entries ever, with two flashes on Digg. Since that time, I&#8217;ve written a free electronic book on <strong><a href="http://blogs.zdnet.com/Ou/?p=404">enterprise wireless LAN security</a></strong> for anyone to use and download from TechRepublic. Since it has been two years, I&#8217;m going to update the information with more defined categories and better explain why they&#8217;re so bad from an ROI (return on investment) and security perspective.</p>
<p><a href="http://blogs.zdnet.com/Ou/?p=454" title="Wireless LAN security myths that won’t die">http://blogs.zdnet.com/Ou/?p=454 </a></p>
<p> Posted by George Ou at Zdnet</p>
</blockquote>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=GjO5fe"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=GjO5fe" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/wireless-lan-security-myths-that-won%e2%80%99t-die/2007/03/27/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MetaSploit 3 released !!!</title>
		<link>http://www.dbergert.com/infosecblurb/metasploit-3-released/2007/03/27/</link>
		<comments>http://www.dbergert.com/infosecblurb/metasploit-3-released/2007/03/27/#comments</comments>
		<pubDate>Tue, 27 Mar 2007 17:16:29 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/metasploit-3-released/2007/03/27/</guid>
		<description>MetaSploit 3 - is released: www.metasploit.com/

&amp;#8220;The Metasploit Framework (&amp;#8221;Metasploit&amp;#8221;) is a development platform for creating security tools and exploits. Version 3.0 contains 177 exploits 104 payloads 17 encoders and 3 nop modules. Additionally 30 auxiliary modules are included that perform a wide range of tasks including host discovery protocol fuzzing and denial of service testing.
Metasploit [...]</description>
			<content:encoded><![CDATA[<p>MetaSploit 3 - is released: <a href="http://www.metasploit.com/">www.metasploit.com/</a><img height="69" alt="meta" hspace="5" src="http://www.dbergert.com/images/meta.jpg" width="90" align="right" vspace="5" /></p>
<blockquote>
<p>&#8220;The Metasploit Framework (&#8221;Metasploit&#8221;) is a development platform for creating security tools and exploits. Version 3.0 contains 177 exploits 104 payloads 17 encoders and 3 nop modules. Additionally 30 auxiliary modules are included that perform a wide range of tasks including host discovery protocol fuzzing and denial of service testing.</p>
<p>Metasploit is used by network security professionals to perform penetration tests system administrators to verify patch installations product vendors to perform regression testing and security researchers world-wide. The framework is written in the Ruby programming language and includes components written in C and assembler. &#8220;</p>
</blockquote>
<p>I really like the new web interface.</p>
<p>Here are some links to some videos and screenshots of it in action:</p>
<p><a href="http://sugar.metasploit.com/msf/gallery.html">http://sugar.metasploit.com/msf/gallery.html</a></p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=N1aa6M"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=N1aa6M" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/metasploit-3-released/2007/03/27/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ten dangerous claims about smart phone security</title>
		<link>http://www.dbergert.com/infosecblurb/ten-dangerous-claims-about-smart-phone-security/2007/03/24/</link>
		<comments>http://www.dbergert.com/infosecblurb/ten-dangerous-claims-about-smart-phone-security/2007/03/24/#comments</comments>
		<pubDate>Sun, 25 Mar 2007 01:23:33 +0000</pubDate>
		<dc:creator>kketelsen</dc:creator>
		
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/ten-dangerous-claims-about-smart-phone-security/2007/03/24/</guid>
		<description>Ten dangerous claims about smart phone security 
I&amp;#8217;m looking into getting a smart phone to replace my normal cell.  I came across this article.  Beware that smart phones and have security risks too.</description>
			<content:encoded><![CDATA[<p>
<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9014118"><br />
Ten dangerous claims about smart phone security</a> </p>
<p>I&#8217;m looking into getting a smart phone to replace my normal cell.  I came across this article.  Beware that smart phones and have security risks too.</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=JG3CAg"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=JG3CAg" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/ten-dangerous-claims-about-smart-phone-security/2007/03/24/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Surprise, Microsoft Listed as Most Secure OS</title>
		<link>http://www.dbergert.com/infosecblurb/surprise-microsoft-listed-as-most-secure-os/2007/03/22/</link>
		<comments>http://www.dbergert.com/infosecblurb/surprise-microsoft-listed-as-most-secure-os/2007/03/22/#comments</comments>
		<pubDate>Thu, 22 Mar 2007 23:28:55 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/surprise-microsoft-listed-as-most-secure-os/2007/03/22/</guid>
		<description>Surprise, Microsoft Listed as Most Secure OS

From: www.internetnews.com/security/article.php/3667201

The report found that Microsoft Windows had the fewest number of patches and the shortest average patch development time of the five operating systems it monitored in the last six months of 2006.

While this is really based upon the # of vulnerabilities (12 of MS were severe, MAC [...]</description>
			<content:encoded><![CDATA[<p><img height="71" alt="ms" hspace="5" src="http://www.dbergert.com/images/ms-1.jpg" width="90" align="right" vspace="5" />Surprise, Microsoft Listed as Most Secure OS</p>
<p>
From: <a href="http://www.internetnews.com/security/article.php/3667201">www.internetnews.com/security/article.php/3667201</a></p>
<blockquote>
<p>The report found that Microsoft Windows had the fewest number of patches and the shortest average patch development time of the five operating systems it monitored in the last six months of 2006.</p>
</blockquote>
<p>While this is really based upon the # of vulnerabilities (12 of MS were severe, MAC 1, RHEL 2), and not their severity, it is good news that the the world most popular OS is improving a little.</p>
<p><strong>Bottom line Patch Management is O/S agnostic.</strong></p>
<p></p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=cQwI1E"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=cQwI1E" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/surprise-microsoft-listed-as-most-secure-os/2007/03/22/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PC Mag - Security Super Guide</title>
		<link>http://www.dbergert.com/infosecblurb/pc-mag-security-super-guide/2007/03/21/</link>
		<comments>http://www.dbergert.com/infosecblurb/pc-mag-security-super-guide/2007/03/21/#comments</comments>
		<pubDate>Wed, 21 Mar 2007 13:16:43 +0000</pubDate>
		<dc:creator>David Bergert</dc:creator>
		
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/pc-mag-security-super-guide/2007/03/21/</guid>
		<description>I received a copy of &amp;#8220;PC Magazine&amp;#8221; in the mail yesterday. What caught my eye was two different things.  First - in the top it states &amp;#8220;Special Double Issue&amp;#8221; - I guess I was thinking that this would make the issue thicker. Is is just me or wasn&amp;#8217;t PC Magazine normally like 1&amp;#8243; [...]</description>
			<content:encoded><![CDATA[<p> <a title="Security Super Guide" href="www.pcmag.com/print_article2/0,1217,a=202584,00.asp"><img height="130" alt="0,1425,i=168655,00" hspace="5" src="http://www.dbergert.com/images/0,1425,i=168655,00.gif" width="100" align="right" vspace="5" /></a>I received a copy of &#8220;PC Magazine&#8221; in the mail yesterday. What caught my eye was two different things.  First - in the top it states &#8220;Special Double Issue&#8221; - I guess I was thinking that this would make the issue thicker. Is is just me or wasn&#8217;t PC Magazine normally like 1&#8243; inch thick in the past?</p>
<p>The other item was the title, <strong>&#8220;The Complete Guide to Security.&#8221;</strong>  while this was a good basic overview I think that the title should of been called: <strong><em>&#8220;Spyware, AntiVirus, Firewall, Parental Control, and a Review of Security Suite Software.&#8221;</em></strong> It wasn&#8217;t really the &#8220;complete guide that I had hoped for.</p>
<p>You can read the article - there is a link below or on the image to the right.</p>
<p>Here is a list of the article&#8217;s Top 10 Security Threats &#8212; I&#8217;ll add some of my personal comments inline below:</p>
<p>For the PCMag.com article <a title="Security Super Guide" href="www.pcmag.com/print_article2/0,1217,a=202584,00.asp">click here</a>.</p>
<blockquote>
<p>10 Spam Mail<br />
While it&#8217;s annoying, it&#8217;s not a security threat unless it comes with a malicious payload. Your e-mail service may filter out spam automatically. If not, Outlook&#8217;s built-in &#8220;Junk E-Mail&#8221; filter is as effective as the spam protection in many suites.</p>
<p><em><font color="navy">Not everyone has there own domain or hosts their email server on linux in their basement, but I use</font></em> <a href="http://mailscanner.info/"><em><font color="navy">MailScanner</font></em></a><em><font color="navy"> that provides gateway level AV, Spam, other filtering on email.</font></em></p>
<p>9 Phishing Mail<br />
Phishing messages pretend to be from eBay, PayPal, your bank, or the like. If you log in to their fake sites, they steal your username and password and you&#8217;re sunk. However, both IE7 and Firefox 2 have phishing detection built in.</p>
<p><em><font color="navy">Again I use</font></em> <a href="http://mailscanner.info/"><em><font color="navy">MailScanner</font></em></a><em><font color="navy"> to detect links to fake web sites, and highlighting these in the messages you deliver to your users.</font></em></p>
<p><em><font color="navy">An example of the alert is here, where the thieves site &#8220;</font></em><a href="http://www.nasty.com"><em><font color="navy">www.nasty.com</font></em></a><em><font color="navy">&#8221; is pretending to be &#8220;</font></em><a href="http://www.bank.com"><em><font color="navy">www.bank.com</font></em></a><em><font color="navy">&#8220;: To access your account, click on</font> <font color="red"><strong>MailScanner has detected a possible fraud attempt by &#8220;</strong></font></em><a href="http://www.nasty.com"><font color="red"><strong><em>www.nasty.com</em></strong></font></a><font color="red"><strong><em>&#8221; claiming to be</em></strong></font> <a href="http://www.bank.com"><font color="red"><strong><em>www.bank.com</em></strong></font></a><font color="red"><em><strong>.</strong></em></font></p>
<p>8 Wireless Attack<br />
If you&#8217;re not careful, anybody in range can mooch bandwidth from your wireless network and can rummage through your files, because they&#8217;re inside your network. Your router&#8217;s WPA/WEP encryption can stop the mooching—but you have to use it.</p>
<p><em><font color="navy">Don&#8217;t use WEP it is broken, WPA-2/TKIP is better with a strong key, 802.1x is better yet, but not supported in many consumer WAP&#8217;s</font></em></p>
<p>7 Hacker Attack<br />
Hackers don&#8217;t care about your puny computer enough to attack it directly. They might broadcast a network virus or release a Trojan, but a personal attack is highly unlikely. Your security suite&#8217;s firewall and malware protection should keep you safe.</p>
<p><em><font color="navy">An automatic script attack from a bot doesn&#8217;t care and if it gets enough &#8220;puny&#8221; computers it creates a nice botnet. Don&#8217;t &#8220;hope&#8221; your firewall will keep you safe, test it. Perform an external port scan or use a &#8220;firewall tester&#8221; : </font><a title="http://www.google.com/search?hl=en&amp;q=firewall+test" href="http://www.google.com/search?hl=en&amp;q=firewall+test"><font color="navy">www.google.com/search?hl=en&amp;q=firewall+test</font></a><font color="navy"> do you have any ports open? do you understand why these ports are open ?</font></em></p>
<p>6 Web Exploits<br />
Some Web sites include malicious code to exploit vulnerabilities in your browser or operating system. Just visiting the site can infect or damage your system if the vulnerability hasn&#8217;t been patched, so keep Automatic Updates on.</p>
<p><em><a href="http://getfirefox.com"><font color="navy">Firefox</font></a> <font color="navy">?  Web content Filtering Software,</font> <a href="http://www.opendns.com"><font color="navy">Open DNS</font></a> <font color="navy">?</font></em></p>
<p>5 Adware<br />
Simple adware pops up ads that get in your face. More sinister adware shadows your online activity, phones home, and tailors ads for you. Up-to-date antispyware is the solution.</p>
<p><em><font color="navy">Pop-up blockers help a little here as well. Also keep the Anti-Spware up-to-date and run it periodically.</font></em></p>
<p>4 Viruses<br />
Viruses are insidious. They hide and use your computer to infect other computers. At some predefined point they strike. Modern antivirus programs are quite good, but add a non-signature anti-malware program to help with brand-new threats.</p>
<p><em><font color="navy"> Also keep the Anti-Virus up-to-date and run it periodically. AV filtering at the gateway has stopped a lot of this.  BTW, anyone remember the &#8220;monkey&#8221; virus from floppies <img src='http://www.dbergert.com/infosecblurb/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </font></em></p>
<p>3 Spyware/Trojans<br />
Spyware spies on everything you do and steals private information. Trojan horse programs pretend to be useful but can turn your computer into a spam-spewing zombie. Antispyware plus non-signature anti-malware should keep out these threats.</p>
<p>2 Identity Theft<br />
It&#8217;s not just about your computer when they use your credit cards, divert your paycheck, and change your vehicle registration. A full-powered security suite should block all computer-related avenues for identity theft.</p>
<p><em><font color="navy">Identity Theft is still more prevelant via non-eletronic means - also, a stolen CC number is not the same as Identity theft.  Shred your mail, use strong passwords, and don&#8217;t use the same password and username for all of your online accounts. Also do this</font> <a href="https://www.annualcreditreport.com/"><font color="navy">www.annualcreditreport.com/</font></a><font color="navy"> for free one a year as well to monitor you identiy and credit.</font></em></p>
<p>1 Social Engineering<br />
The number one threat to your computer&#8217;s security is—you! Use common sense. Don&#8217;t take programs from strangers, don&#8217;t go to &#8220;iffy&#8221; Web sites, and if your security software pops up a warning, READ IT before you click.</p>
<p><em><font color="navy">Two examples of how bad this is:</font></em></p>
<p><a href="http://www.theregister.co.uk/2003/04/18/office_workers_give_away_passwords/"><font color="navy">www.theregister.co.uk/2003/04/18/office_workers_give_away_passwords/</font></a></p>
<p><a href="http://www.darkreading.com/document.asp?doc_id=95556&amp;WT.svl=column1_1"><font color="navy">www.darkreading.com/document.asp?doc_id=95556&amp;WT.svl=column1_1</font></a></p>
<p><em><font color="navy">I guess all I can say is common sense, and training, training, training on Information Security Awareness.</font></em></p>
</p>
</blockquote>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=uDMsp4"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=uDMsp4" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/pc-mag-security-super-guide/2007/03/21/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Stolen Indentities on the Cheap</title>
		<link>http://www.dbergert.com/infosecblurb/stolen-indentities-on-the-cheap/2007/03/19/</link>
		<comments>http://www.dbergert.com/infosecblurb/stolen-indentities-on-the-cheap/2007/03/19/#comments</comments>
		<pubDate>Mon, 19 Mar 2007 17:16:46 +0000</pubDate>
		<dc:creator>kketelsen</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.dbergert.com/infosecblurb/stolen-indentities-on-the-cheap/2007/03/19/</guid>
		<description>I just saw this article and it didn&amp;#8217;t surprise me. Goes to show how important computer security is and how much pain you are saving just by keeping computers updated and having the right security policies in place:
Stolen Identities Sold Cheap on the Black Market

Hackers selling IDs for $14, Symantec says

Also: from the last link: [...]</description>
			<content:encoded><![CDATA[<p>I just saw this article and it didn&#8217;t surprise me. Goes to show how important computer security is and how much pain you are saving just by keeping computers updated and having the right security policies in place:</p>
<p><a href="http://blog.washingtonpost.com/securityfix/2007/03/stolen_identities_two_dollars.html?nav=rss_blog">Stolen Identities Sold Cheap on the Black Market</a><br />
<br />
<a href="http://www.infoworld.com/article/07/03/19/HNhackerssellids_1.html">Hackers selling IDs for $14, Symantec says</a><br />
<br />
Also: from the last link: <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/01/watch_the_exploit_a_targeted_a.html">Watch the Exploit: A Targeted Attack Video</a>  pretty scary stuff.</p>

<p><a href="http://feeds.feedburner.com/~a/Infosecblurb?a=aahZHd"><img src="http://feeds.feedburner.com/~a/Infosecblurb?i=aahZHd" border="0"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.dbergert.com/infosecblurb/stolen-indentities-on-the-cheap/2007/03/19/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
