<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Stallions Blog &#187; OpenDNS</title>
	<atom:link href="http://www.securitystallions.com/index.php/tag/opendns/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitystallions.com</link>
	<description>&#34;Musings of all things infosec...&#34;</description>
	<lastBuildDate>Tue, 02 Feb 2010 17:59:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/><cloud domain='www.securitystallions.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Daily Digs &#8211; 09.15.2009</title>
		<link>http://www.securitystallions.com/index.php/2009/09/15/daily-digs-09-15-2009/</link>
		<comments>http://www.securitystallions.com/index.php/2009/09/15/daily-digs-09-15-2009/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 03:32:00 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[Daily Digs]]></category>
		<category><![CDATA[Attitude]]></category>
		<category><![CDATA[BToD]]></category>
		<category><![CDATA[COTS]]></category>
		<category><![CDATA[Craigslist]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Eyefinity]]></category>
		<category><![CDATA[funny]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[OpenDNS]]></category>
		<category><![CDATA[Pwnage Tool]]></category>
		<category><![CDATA[Schneier]]></category>
		<category><![CDATA[Soc]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[TCP/IP]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=250</guid>
		<description><![CDATA[Amazing, I actually started tonight's digs before 10pm.  Then I realized that I hadn't read most of what I marked for tonight so it'll take me just as long by the time I actually get this one posted.  I just can't beat time these days! The 'ctricky and Web Application Security' blog had a post [...]]]></description>
			<content:encoded><![CDATA[<p>Amazing, I actually started tonight's digs before 10pm.  Then I realized that I hadn't read most of what I marked for tonight so it'll take me just as long by the time I actually get this one posted.  I just can't beat time these days!</p>
<p>The 'ctricky and Web Application Security' blog had a post on some great insight of things to ask during an app sec test.  I've never actually run across this particular scenario before but the point is that JS pop-up warnings mean nothing to your proxy and may present warnings that the tester will never see (like "If you do this you'll break all of prod").  Anyway, read the post for the full rundown.<br />
[<a href="http://cktricky.blogspot.com/2009/09/btod-target-scope-precautions.html">BToD Target Scope and Precautions</a>]</p>
<p>VeriSign's new DDoS attack protection service is an interesting topic for me.  I've dealt with countless large enterprise carrier services along with the architecture around load balancing and multi-homed environments.  So offloading all of your traffic in an event (i.e. throwing the BGP switch) to VeriSign seems a tad bit scary, oh - but no worries they'll route the good traffic back.  The other thing is all of the Netflow data VeriSign collects (to do this) is an interesting concept.  To me, architecturally, this looks like a bad idea and maybe I'll just have to dig into this one a little more.  For now you can start your own opinions by starting to read about it at the link.<br />
[<a href="http://itknowledgeexchange.techtarget.com/security-bytes/verisign-extends-ddos-attack-protection-service/">VeriSign Extends DDoS Attack Protection</a>]</p>
<p>Work in defense?  Then COTS is something you probably deal with on a daily basis.  The funny thing is that when I started my career in the defense industry a lot of proprietary hard and software were being gutted for COTS.  Even I knew (as I started out as a System Engineering Associate), that the square peg they were jamming in the round hole didn't fit.  Apparently the cyclical monster is coming around in the DOD on this one.<br />
[<a href="http://gcn.com/blogs/tech-blog/2009/09/dod-rethinks-build-vs-buy-software.aspx?s=gcndaily_150909">DoD Rethinking Build Versus Buy</a>]</p>
<p>West side what?  Go figure - China modeling how to take down the US power grid for fun.  Reminds me of a conference I was at a few years ago in which a consultant disclosed some interesting facts about the substation and grid connections the Mall of America has in it's substructure.  We then learned how to shut the lights off in all of the neighboring communities that particular day.<br />
[<a href="http://www.computerworld.com/s/article/9138017/DHS_to_review_report_on_vulnerability_in_West_Coast_power_grid?taxonomyId=17">DHS to Review Report on Vulnerability in West Coast Power Grid</a>]</p>
<p>This was one of the best / most disturbing banking related articles I've read in a while.  It's also why you shouldn't do most any online business with HSBC.  I hope HSBC just had a PCI audit done by a large firm so that particular QSA can head to the chopping block.  This one's just downright "special" (and not really from today, but I ran across it in my feeds).<br />
[<a href="http://eternallyoptimistic.com/2009/08/24/so-funny-i-forgot-to-laugh/">So Funny I Forgot To Laugh</a>]</p>
<p>This one came across the OSF data loss incidents list and it made me think.  Do you really think Jones General Store has any idea of PCI?  It's so focused today in big business and infrastructure security yet these types of processes still exist in hundreds of thousands of small businesses day in and day out.  In fact, this past weekend, I saw more carbon copies of card data at a local art fair than I'd care to pretend were still around.<br />
[<a href="http://www.coloradodaily.com/ci_13334305?source=most_emailed">University Hill Shops Burglarized; Credit Cards Stolen</a>]</p>
<p>As of this posting less than 19 hours until the Social Engineering Framework is released.  Mark it on your smartphone yo.<br />
[<a href="http://social-engineer.org/">Social Engineering: Exploiting Human Vulnerabilities</a>]</p>
<p>All you need to know about this one: "Operation Hot Date", Dumb Sheriff in Florida, and Craigslist for your evening entertainment.<br />
[<a href="http://news.cnet.com/8301-17852_3-10353855-71.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Another Sheriff Goes After CL</a>]</p>
<p>That's all he wrote for tonight boys and girls.  We'll leave you with some links to peruse, but without the colorful commentary.  Take care and keep your stick on the ice!  Also, first person to tweet "I won the easter egg hunt at www.securitystallions.com" and @s me in the message wins a $20 Starbucks gift card (first person = one winner).  Figuring out where to find me on Twitter should be trivial.  Get your tweet in before 10:30pm on Wednesday, September 16th 2009 Central.</p>
<p>[<a href="http://news.cnet.com/8301-13846_3-10353826-62.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Does IBM Have a Fix for Banking Infrastructure?</a>]<br />
[<a href="http://maltainfosec.org/archives/187-Security-Attitudes.html">Security Attitudes</a>]<br />
[<a href="http://lukenotricks.blogspot.com/2009/09/thoughts-on-cult-of-schneier.html">Thoughts on the Cult of Schneier</a>]<br />
[<a href="http://blog.iphone-dev.org/post/188779017/3-o-fun">Pwnage Tool and iPhone 3.1</a>]<br />
[<a href="http://www.extremetech.com/article2/0,2845,2352762,00.asp?kc=ETRSS02129TX1K0000532">AMD 'Eyefinity' Powers 24 Monitors</a>]<br />
[<a href="http://www.symantec.com/connect/blogs/bsod-and-possibly-more">A BSoD and Possibly More</a>]<br />
[<a href="http://tech.slashdot.org/story/09/09/15/0131209/Microsoft-Says-No-TCPIP-Patches-For-XP">No TCP/IP Patches for XP</a>]<br />
[<a href="http://www.net-security.org/secworld.php?id=8093">OpenDNS Announces Premium Cloud Services</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2009/09/15/daily-digs-09-15-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
