<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Stallions Blog &#187; encryption</title>
	<atom:link href="http://www.securitystallions.com/index.php/tag/encryption/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitystallions.com</link>
	<description>&#34;Musings of all things infosec...&#34;</description>
	<lastBuildDate>Tue, 02 Feb 2010 17:59:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/><cloud domain='www.securitystallions.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Doing it Wrong &#8211; Uncryption of the Enterprise</title>
		<link>http://www.securitystallions.com/index.php/2010/02/02/doing-it-wrong-uncryption-of-the-enterprise/</link>
		<comments>http://www.securitystallions.com/index.php/2010/02/02/doing-it-wrong-uncryption-of-the-enterprise/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 17:59:45 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[DiW]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[KMIP]]></category>
		<category><![CDATA[WTF]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=263</guid>
		<description><![CDATA[Doing it Wrong (DiW) Jay Jacobs and David Meier Dave: First I'd like to take this opportunity to say "Hi!" to all three SecurityStallion readers out there. I know things have been a bit sparse since September last year but that's changing in 2010. The Digs are back and there's also some new article formats [...]]]></description>
			<content:encoded><![CDATA[<h4>Doing it Wrong (DiW)<br />
Jay Jacobs and David Meier</h4>
<p><em><strong>Dave:</strong></em> First I'd like to take  this opportunity to say "Hi!" to all three SecurityStallion readers out  there.  I know things have been a bit sparse since September last year  but that's changing in 2010.  The Digs are back and there's also some  new article formats we're going to be throwing around.  So with that  lead in I'd like to welcome the infamous Jay Jacobs.  Jay is one of the  more realistic security practitioners I've had the chance to work with  (albeit indirectly) and I'm pleased that we can do this type of spot  together respectably titled: "Doing it Wrong".  But what is this and why should you care?   Over to Jay for the explanation...</p>
<p><em><strong>Jay:</strong></em> Dave and I have had many  discussions on various topics and "doing it wrong" stuck out as a title  because that's what I kept thinking about Dave and I think Dave kept  thinking about me.  These posts should reflect that mutual respect.  I  also like the title, not just the initial Ha-Ha-ness, but also because  it reminds me that we learn best from mistakes. If I would have gotten  Sendmail working right away, I might not be able to spoof email with  telnet.  Realizing I'm doing it wrong means that I may be able to fix  it.  I look forward to challenging my way of thinking here.</p>
<p><em><strong>Dave:</strong></em> Seriously Jay, you're still  using Sendmail?  That's a whole other DiW  I guess!  But, back to the meat: Uncryption  of the Enterprise.  So what does that really  mean?  Well, I've been around the track a few times (from a consulting  perspective - it's really just like NASCAR, left turn, left turn, left  turn...) and I tend to get riled up when things in the enterprise, that  should be encrypted, are being tossed around the network, well,  unencrypted.  In fact often times when I bring up the fact that maybe  those NTP updates should be encrypted or that OSPF adjacency is left  ripe for the picking, or even FTP still  being used as a primary transport facility in very, very, very large  enterprises!  WTF people?  W-T-F?  The best (and oft heard) excuse by  far has to be from a monitoring perspective: "well then we can't see  what's going on".  The simple answer to that: if it's important enough  to encrypt (PII, authentication data, sensitive information, etc...) and  you don't have access to a point where you can extract, or view that  data in flight - then maybe, just maybe, you shouldn't be privy to said  data in the first place.  I know, this might be a real shocker, but just  because you're sitting in the SOC  or NOC doesn't mean that because  you can control the data flow that it's implied you should be able to  read it.  Encrypt if you have it, right?  Jay?  I mean, really, why not?</p>
<p><em><strong>Jay:</strong></em> Yeah, I was still using  Sendmail on my 286, but decided to upgrade for Y2K.  Encrypt if you have  it?  There's a saying around cryptography, encrypting data is easy,  it's the decryption that gets you.  It's really easy to sit on a high  horse (or Stallion, Dave) and say that everything should be encrypted,  it's a whole different ball game to actually do it.  As soon as data  gets encrypted, a key is created, and then two things happen:</p>
<ol>
<li>Auditors flip to a new tab in their spreadsheet because a whole  new set of controls around cryptography and key management must be  understood, or at least implemented.  Most IT folks, rather than view  this as a development opportunity, see this as just more ways to screw  up, which leads to...</li>
<li>The typical IT admin gets a glazed look  on their face and a mad rush ensues to find someone else to dump this  crazy "encryption" on.  Normally intelligent people all of a sudden look  like their being asked to captain the Titanic on her maiden voyage.</li>
</ol>
<p>These  two things are exasperated by overly-protective frameworks and  compliance controls that treat all the keys like they are dipped in gold  then encrusted with diamonds.  Generally speaking, a key is just a long  password (with a few caveats). So, while encrypting NTP is a no-brainer  in theory, in reality the key management in the products stink and  nobody wants to sign a form saying that they understand and accept their  key custodian responsibilities (thanks for that one PCI).</p>
<h4>Where  to Fix  (WTF)<em><strong><br />
</strong></em></h4>
<p><em><strong>Dave:</strong></em> I can see Jay's point (to a  degree).  To manage keying (as a process) and the keys themselves is a  complex undertaking in large organizations.  Fundamentally, however,  encryption is a component of the enterprise.  The task is simplifying it where it can be  simplified.  Use it as it was meant to be used: to keep things private.   And don't, I repeat, don't use it as an afterthought or add-on unless  there is no other option.  If encryption wasn't designed into your  system of systems from the beginning adding it after the fact usually  buys you as  much improved posture as the hunchback of Notre Dame.</p>
<p><em><strong>Jay:</strong></em> That's the rub, nobody is  capable of designing encryption in because everyone does it differently,  people should get together and make some type of open and interoperable  <a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=kmip" target="_blank">key  management protocol</a>.  Because rather than simply saying everyone  ought to turn on encryption everywhere, I think it's more appropriate to  say that we need to focus on the support structure to implement  encryption.  Something like meetings once a week, "Cryptos Anonymous"  I'd call it, where normally well-adjusted admins show up and say, "Hi,  I'm Jay and I'm a key custodian".  Either that, or a well defined key  management governance structure with tools to back it up.  Then we can  start talk about <em>encrypting the world</em>.</p>
<p><em><strong>Dave:</strong></em> "Encrypting the world" -  &lt;sinister laugh&gt;Mua ha ha ha hahhhhhh!&lt;/sinister laugh&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2010/02/02/doing-it-wrong-uncryption-of-the-enterprise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Digs &#8211; 09.14.2009</title>
		<link>http://www.securitystallions.com/index.php/2009/09/14/daily-digs-09-14-2009/</link>
		<comments>http://www.securitystallions.com/index.php/2009/09/14/daily-digs-09-14-2009/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 03:32:14 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[Daily Digs]]></category>
		<category><![CDATA[ARP]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[autoplay]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Fed]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[screencast]]></category>
		<category><![CDATA[SecurityTubeCon]]></category>
		<category><![CDATA[skimmer]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[unique]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=248</guid>
		<description><![CDATA[Well, "daily" has been more like "weekly" as of late, but the digs are back. I think this one is good on a few fronts, but mostly from a humorous perspective.  Joe Lieberman and Susan Collins should stick to whatever they do best - and that doesn't include addressing "cyber crime".  They're proposing a public [...]]]></description>
			<content:encoded><![CDATA[<p>Well, "daily" has been more like "weekly" as of late, but the digs are back.</p>
<p>I think this one is good on a few fronts, but mostly from a humorous perspective.  Joe Lieberman and Susan Collins should stick to whatever they do best - and that doesn't include addressing "cyber crime".  They're proposing a public / private relationship so that the government (really?) can help them defend against attacks.  OK, didn't the FBIs website just get defaced recently?  Unless the blunt plan is to put up some sort of subsidy (which I'm not at all endorsing) the government is just going to spin up more useless programs that are run by people who just-don't-get-it.<br />
[<a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Press.MajorityNews&amp;ContentRecord_id=b9feafd8-5056-8059-761d-36b82f8e272e&amp;Region_id=&amp;Issue_id=">Committee Examines Growing Cyber Threat to Businesses</a>]<br />
[<a href="http://security-sh3ll.blogspot.com/2009/09/fbi-jobs-site-gets-hacked.html">FBI Jobs Site Gets Hacked</a>]</p>
<p>Unique is not random is not secure.  I'm not sure that's a complete sentence, but it sums up the article on Newsoft's Tech Blog rightfully.  For a run down of examples on the differences in the three concepts hit up the link.<br />
[<a href="http://newsoft-tech.blogspot.com/2009/09/unique-is-not-random-is-not-secure.html">Unique is Not Random is Not Secure</a>]</p>
<p>The Consumerist ran a story this morning with video from LiveLeak on a man installing a skimmer.  I'd have to say that I'm definitely more cognizant when using ATMs that are non-bank affiliated and portable.  At one point in time I really didn't like ATMs that sucked the card into the machine, however today it makes sense as less risk to me.<br />
[<a href="http://consumerist.com/5358850/video-guy-installing-skimmer-on-atm">Guy Installing Skimmer on ATM</a>]</p>
<p>I can honestly say I really didn't know much about 'RNS' before I read this article today, but the Fed seems to have cracked down a few of the key members.  I'm not sure why the title references RNS as an '0Day' group however.<br />
[<a href="http://www.thetechherald.com/article.php/200937/4423/Fed-crackdown-on-RNS-signals-death-to-oldest-0Day-group-online">Fed Crackdown on 'RNS' Signals Death to Oldest 0Day Group Online</a>]</p>
<p>Don't have the cash or time to go to one of the big name cons?  ChrisJohnRiley posted an article about the first online hacker con entitled SecurityTubeCon.  There's a call for papers (&amp; vid) out until October 20th, so get your talk ready to go!<br />
[<a href="http://c22blog.wordpress.com/2009/09/13/first-online-hacker-conference/">First Online Hacker Conference</a>]</p>
<p>That's all the time we have for comments tonight, but we'll leave you with some other links to ponder.  Thanks for stopping by!</p>
<p>[<a href="http://isc.sans.org/diary.html?storyid=7126&amp;rss">Windows Autoplay Behavior Updated</a>]<br />
[<a href="http://www.h-i-r.net/2009/09/gustav-hackerspace-twitter-bot.html">Gustav, the Hackerspace Twitter Bot</a>]<br />
[<a href="http://www.databreaches.net/?p=7119">Loan Officer Indicted for Fraud and ID Theft</a>]<br />
[<a href="http://dradisframework.org/">Dradis 2.4 Released</a>]<br />
[<a href="http://www.net-security.org/secworld.php?id=8080">PhoneCrypt is Available for the iPhone (and entirely overpriced)</a>]<br />
[<a href="http://www.tips29.com/2007/02/20-best-temporary-and-disposable-email.html">20 Temporary / Disposable Email Services</a>]<br />
[<a href="http://38.119.187.38/hh/our_stuff.php#Hackers%20Hideaway%20ARP%20attack%20tool">Hacker's Hideaway ARP Attack Tool Released</a>]<br />
[<a href="http://vrt-sourcefire.blogspot.com/2009/09/vulnerability-report-september-2009.html">SourceFire's Vulnerability Report for September Screencast</a>]<br />
[<a href="http://www.roer.com/node/499">Practical Intrusion Analysis Book Review</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2009/09/14/daily-digs-09-14-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Digs &#8211; 08.10.2009</title>
		<link>http://www.securitystallions.com/index.php/2009/08/10/daily-digs-08-10-2009/</link>
		<comments>http://www.securitystallions.com/index.php/2009/08/10/daily-digs-08-10-2009/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 01:00:28 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[Daily Digs]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Gimp]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[IPO]]></category>
		<category><![CDATA[psnuffle]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Subversion]]></category>
		<category><![CDATA[UHG]]></category>
		<category><![CDATA[Verizon]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=197</guid>
		<description><![CDATA[Monday, bloody Monday.  At least we're in the clear!  Some interesting news as of today so with no further announcements let's dig right in. Our first link is for a tool distributed, for free, from Sophos: Anti-Rootkit software.  It's recently been updated to support 64-bit versions of Windows and the upcoming Windows 7 (which, let's [...]]]></description>
			<content:encoded><![CDATA[<p>Monday, bloody Monday.  At least we're in the clear!  Some interesting news as of today so with no further announcements let's dig right in.</p>
<p>Our first link is for a tool distributed, for free, from Sophos: Anti-Rootkit software.  It's recently been updated to support 64-bit versions of Windows and the upcoming Windows 7 (which, let's hope, brings the majority of Windows users into the 64-bit world).  No black-tie release event for this version, but at least Sophos is still putting it out there for "free".<br />
[<a href="http://www.sophos.com/blogs/gc/g/2009/08/10/sophos-antirootkit-updated-download-free/">Sophos Anti-Rootkit Updated</a>]</p>
<p>If you're in the Minneapolis / St. Paul area and you're in, well, pretty much any field you've probably heard <span style="text-decoration: line-through;">horror-stories</span> stories of United Health Group.  If we haven't had enough reasons to hate on UHG they're giving us a new one apparently!  Let's see here - they're not only selling the marketing data but also mapping risk ratings for health and life insurance purposes.  Way to go UHG!  You get my swift-kick-in-the-ass award for today.  If you can, do business elsewhere, UHG seems to treat their employees badly on top of the shady business practices.<br />
[<a href="http://www.phiprivacy.net/?p=1171">Your Prescription Data Has Been Sold For Profit</a>]</p>
<p>Next up is some new functionality that will probably find it's way into Metasploit.  Max's Remote-Exploit blog has all the details on 'psnuffle' including a screencast of the functionality.  Jam out to the techno beats while you watch the module in action!<br />
[<a href="http://remote-exploit.blogspot.com/2009/08/psnuffle-password-sniffer-for.html">Psnuffle Password Sniffer</a>]</p>
<p>I'm all about the Verizon Business Data-Breach Report.  That being said I think big vendors / carriers generally have over-hyped and under-performing security services in general.  Hopefully the security service doesn't share any of the service provisioning speeds that generally are, shall we say, not break-neck?  Anyway, if you're into hiring a big firm to do your due diligence for you Verizon can offer it on a silver-platter with a bill to match I'm sure.<br />
[<a href="http://www.networkworld.com/news/2009/081009-verizon-business-to-offer-risk-based.html">Verizon Business to Offer Risk-Based Security Service</a>]</p>
<p>I happened to post this one earlier in the day and it got quite a bit more attention than I had expected.  The RedTeam blog has some Gimp pwnage fun that shows you how to embed some sneaky PHP in a GIF.  That and <a href="http://twitter.com/hdmoore/status/3226575321">@hdmoore pointed out to me some extra fun to go along with the 'sploit.</a> Double whammy!<br />
[<a href="http://blogs.23.nu/RedTeam/2009/08/new-advisory-0wning-with-gimp/">0wning with Gimp</a>]</p>
<p>All your base are belong to...  Committers?  Sure.  Or just go patch Subversion if you haven't already!<br />
[<a href="http://www.h-online.com/security/Holes-closed-in-Subversion-version-control-system--/news/113967">Holes Closed in Subversion</a>]</p>
<p>One of the more prominent elite when it comes to OS X hacking: Dino Dai Zovi has posted to his blog a new article all about, you guessed it, rootkits!  This goes with his recent Black Hat talk and includes the preso, paper and code.<br />
[<a href="http://blog.trailofbits.com/2009/08/10/advanced-mac-os-x-rootkits/">Advanced OS X Rootkits</a>]</p>
<p>So you want to speak at RSA in 2010?  Well, you better get in gear because the call for proposals is quickly coming to a close.<br />
[<a href="http://www.rsaconference.com/2009/us/email/c4s/email2/rsa-conference-2010-cfp-v2.htm">RSA Call for Speaking Proposals Due August 14th</a>]</p>
<p>SANS has a rockstar intro up to memory forensics today.  The write up includes looking at Mantech MDD and Volatility (which we've linked previously).  If you're just getting your feet wet in forensics this quick run through definitely won't hurt!<br />
[<a href="https://blogs.sans.org/computer-forensics/2009/08/10/memory-forensics-a-practical-example/">Memory Forensics: A Practical Example</a>]</p>
<p>I asked myself a couple weeks ago this very question: "Why in the **** is the .NET Framework Extension installed in Firefox?" and now I have a fabulous answer.  Wladimir Palant, of Adblock Plus fame, has a very thorough write up with linkage to other articles in the press.  If you use Adblock, you'll want to read this.  Microsoft up to their shady shenanigans - again.<br />
[<a href="http://adblockplus.org/blog/the-return-of-net-framework-assistant">The Return of .NET Framework Assistant</a>]</p>
<p>Tsk tsk, reinventing the wheel is BAD.  Especially when dealing with crypto.  And doing crypto in JS!  Don't believe me?  Well, you don't have to take my word for it, but how about going back to the link to Nate Lawson's <a href="http://www.youtube.com/watch?v=ySQl0NhW1J0">"Crypto Strikes Back!"</a> Google Tech Talk and you'll understand why.  The devs themselves even say it's only a "base level of security" (uhhh, there's no auth), so why not just save yourself the trouble and avoid it?<br />
[<a href="http://www.h-online.com/security/jCryption-1-0-released--/news/113969">jCryption 1.0 Released</a>]</p>
<p>Fortinet is, apparently, going for the gold.  And in this case "gold" being public shares.  El Reg has a story up regarding the rare happening.<br />
[<a href="http://www.theregister.co.uk/2009/08/10/fortinet_ipo/">Fortinet IPO</a>]</p>
<p>Put this link out in mainstream C-Level inboxes and you'll have all kinds of heads rolling on Tuesday afternoon.  SANS has a post up about the consideration of renewing your A/V solution.  If you're not a complete security n00b you probably already knew that A/V is a waste of CPU cycles and whitelisting, not signature based blacklisting, is the only way to really go forward in today's shikata ga nai world.  Duh.<br />
[<a href="https://blogs.sans.org/security-leadership/2009/08/10/dont-renew-that-anti-virus-contract/">Don't Renew that Antivirus Contract</a>]</p>
<p>Looks like DHS is in the tubes these days.  Obama has another catastrophic fail on his hands with the latest being Mischel Kwon putting in her resignation to (shocker) go work in the, much higher paying, private sector.  Maybe if I tweet The Prez he'll mention me on Facebook and we can talk about it over Skype later.  Or how about this: maybe stop trying so hard with the communications outlets and focus on doing and not talking for a few months.  Because, we all know, Cash for Clunkers is really helping out!<br />
[<a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=219100615">Mischel Kwon Resigns</a>]</p>
<p>We end todays string of ranty-posts with the exclusive in-depth that Tom's Hardware has posted of Charlie Miller on the iPhone SMS exploit.  Check it out, I was slightly tickled when I saw reference on the first page to AT commands.  GO GO GADGET MODEM!<br />
[<a href="http://www.tomshardware.com/reviews/hacking-iphone-security,2384.html">Exclusive Interview with Charlie Miller</a>]</p>
<p>We commented all the good articles today so, don't hold your breath, no grab bag for today!</p>
<p>-windexh8er</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2009/08/10/daily-digs-08-10-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Digs &#8211; 08.03.2009</title>
		<link>http://www.securitystallions.com/index.php/2009/08/03/daily-digs-08-03-2009/</link>
		<comments>http://www.securitystallions.com/index.php/2009/08/03/daily-digs-08-03-2009/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 23:51:36 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[Daily Digs]]></category>
		<category><![CDATA[automatic updates]]></category>
		<category><![CDATA[ceo]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[locks]]></category>
		<category><![CDATA[netgear]]></category>
		<category><![CDATA[patent]]></category>
		<category><![CDATA[skimmer]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[ucsniff]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=163</guid>
		<description><![CDATA[Welcome to the 3rd production of Daily Digs here at Security Stallions!  It's been a long weekend with a relatively active Monday.  We've got a slew of links for your enjoyment with almost-short-as-a-Twitter-update commentary to go along. First of all I'd like to say that knowledge sharing is the key to &#62;80% of what I've [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome to the 3rd production of Daily Digs here at Security Stallions!  It's been a long weekend with a relatively active Monday.  We've got a slew of links for your enjoyment with almost-short-as-a-Twitter-update commentary to go along.</p>
<p>First of all I'd like to say that knowledge sharing is the key to &gt;80% of what I've learned in the security industry.  From the simple cases where I'm tipped off via a quick blurb on Twitter or all out full-disclosure, you just can't beat community sources.  That being said Russ McRee has a great post over on HolisticInfoSe.org about his and Mike Bailey's talk around CSRF.  Although Russ mentions vids in the post he didn't link them, so I did a bit of quick digging and found them - just for you.  Hit up the links for more info.<br />
[<a href="http://holisticinfosec.blogspot.com/2009/08/defcon-17-presentation-and-videos-now.html">CSRF: Yeah, it Still Works</a>]<br />
[<a href="http://holisticinfosec.blogspot.com/2009/07/defcon-preview-netgear-rp614-csrf.html">Netgear CSRF Attack Video</a>]</p>
<p>UCSniff's authors Jason Ostrom and Arjun Sambamoorthy also presented at DEFCON 17 this year.  The tool, which was previously only available via BackTrack3, has been more recently released as a SourceForge project with some significant new featureset.  Another one for the toolbelt!<br />
[<a href="http://www.h-online.com/security/DEFCON-Attack-on-audio-and-video-conferencing-made-easy--/news/113913">UCSniff - UCS Attack Tool</a>]</p>
<p>There's an article up on Silicon about CEOs needing to be less negligent with regards to security.  Very true, so if you like to chase the rainbow the article can be had below.<br />
[<a href="http://management.silicon.com/itdirector/0,39024673,39475478,00.htm">Optimistic CEOs Must Not Neglect IT Security</a>]</p>
<p>Ryan Naraine is one of the first to break the story on ATM skimming at DEFCON this year.  He goes on to tell us how Chris Paget of Google got scammed for $200 when debiting his account.  Note to all: get your cash at a reputable banking institution (i.e. where ATMs are built into the wall of the bank), in a casino, or somewhere else security of money transactions would be extremely high.<br />
[<a href="http://blogs.zdnet.com/security/?p=3843">Fake ATM Skimmers Found in Las Vegas Hotels</a>]</p>
<p>Do you know what Ippon means in Japanese?  Well you better -- it's "game over", and it's the name of a new tool for exploiting automatic updates.  Yes, this isn't anything earth shattering in terms of the base exploit, however the methods the tool can "win" at the game of insecure updates are pretty kick ass.  Read more about it over at the following TechRepublic blog post.<br />
[<a href="http://blogs.techrepublic.com.com/security/?p=2056">Automated Updates: May Not Be Such a Good Idea</a>]</p>
<p>File this one under the category of "About Damn Time" and you have Mikko Hypponen dropping news of Twitter starting to inspect and reject malicious URLs.  Although the article doesn't mention it Twitter is actually using Google's Safe Browsing API.  It's a (slow) start, but at least it's a start!<br />
[<a href="http://www.f-secure.com/weblog/archives/00001745.html">Twitter Now Filtering Malicious URLs</a>]</p>
<p>There's an interesting post by Susan Brenner over at CYB3RCRIM3 about whether or not we should reconsider the notion that companies under attack are prohibited from investigating the attackers and trying to locate them.<br />
[<a href="http://cyb3rcrim3.blogspot.com/2009/08/private-cyber-investigators.html">Private Cyber Investigators</a>]</p>
<p>Addonics announced an inline hardware encryption solution for most any SATAI/II type drive system.  What's great about the design is that there's also a removable cipher key to unlock operation of the unit and it is also small enough to be mounted in a 3.5" drive bay.  The CCM35MK1 is also NIST and CES certified.<br />
[<a href="http://www.net-security.org/secworld.php?id=7822">Versatile Hardware Encryption for any Computer</a>]</p>
<p>Although not directly related to security, but big news none the less, VoloMedia has somehow received a patent for podcasting.  Really?  Who works in the patent offices?  Surprisingly, this hasn't been on many people's radar judging from Twitter activity today.  Slightly odd considering everyone and their brother seems to have a podcast these days!<br />
[<a href="http://www.readwriteweb.com/archives/company_receives_patent_for_podcasting.php">Company Receives Patent for Podcasting</a>]</p>
<p>And tonight we'll leave you with what will, from now on, be referenced as the grab bag.  News that's worthy of reading, but we just didn't have time to comment on.</p>
<p>The links for the grab bag tonight are as follows...<br />
[<a href="http://peterkleissner.com/?p=34">Hacking Surfpoint Terminals</a>]<br />
[<a href="http://deals.venturebeat.com/2009/08/01/defcon-hacker-excuse-me-while-i-change-your-aircrafts-flight-plan/">DEFCON Air Traffic Control Hack</a>]<br />
[<a href="http://www.wired.com/threatlevel/2009/08/electronic-locks-defeated/">High-Security Locks Defeated</a>]<br />
[<a href="http://www.opensourc3.org/">Opensourc3 Magazine Publishes First Issue</a>]<br />
[<a href="http://news.cnet.com/8301-1023_3-10302072-93.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">PayPal Suffers Outage</a>]<br />
[<a href="http://www.net-security.org/article.php?id=1273">5 Tips to Stop Staff Snooping</a>]</p>
<p>As always, thanks for stopping by and comments are always welcome!</p>
<p>--windexh8er</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2009/08/03/daily-digs-08-03-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
