<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Stallions Blog &#187; threat</title>
	<atom:link href="http://www.securitystallions.com/index.php/tag/threat/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitystallions.com</link>
	<description>&#34;Musings of all things infosec...&#34;</description>
	<lastBuildDate>Tue, 02 Feb 2010 17:59:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/><cloud domain='www.securitystallions.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Daily Digs &#8211; 08.11.2009</title>
		<link>http://www.securitystallions.com/index.php/2009/08/11/daily-digs-08-11-2009/</link>
		<comments>http://www.securitystallions.com/index.php/2009/08/11/daily-digs-08-11-2009/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 01:00:44 +0000</pubDate>
		<dc:creator>windexh8er</dc:creator>
				<category><![CDATA[Daily Digs]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Asterisk]]></category>
		<category><![CDATA[Forrester]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Pirate Bay]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[safe]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.securitystallions.com/?p=202</guid>
		<description><![CDATA[Well boys and girls it's only Tuesday.  Yes Twitter, once again, is under siege, the Pirate Bay is having issues and Microsoft dropped a bombshell full of updates.  Welcome to the daily digs... The first article isn't exactly security focused.  It is, in a way, because from my viewpoint network stability is a direct component [...]]]></description>
			<content:encoded><![CDATA[<p>Well boys and girls it's only Tuesday.  Yes Twitter, once again, is under siege, the Pirate Bay is having issues and Microsoft dropped a bombshell full of updates.  Welcome to the daily digs...</p>
<p style="text-align: left;">The first article isn't exactly security focused.  It is, in a way, because from my viewpoint network stability is a direct component to security.  If information isn't accessible then it's no good, right?  Sometimes.  Either way, Lawrence Roberts (of ARPANET fame) has stepped back from today's slow, expensive routing platforms and decided to fix the brokenness, not from a bandwidth perspective, but flow.  Now at first glance I thought his whole concept was CEF repackaged, but it's not.  Just goes to show how much of the same crap Cisco can feed customers and get away with it year over year.  Monolithic kernel: check, repackaged software that Cisco has no core competency in: check.  It's good to see outside-the-box-thinkers like Hoff go over to players like Cisco, but at the end of the day he'll just get washed, dried and pressed into Cisco's typical mold.  Anyway, on to the original story at hand:<br />
[<a href="http://www.spectrum.ieee.org/computing/networks/a-radical-new-router/0">A Radical New Router</a>]</p>
<p style="text-align: left;">Mu Dynamics today posted some vulnerabilities in Asterisk to their Labs site.  Looks to be a case of the parsing blues (as Asterisk has had problems with this in the past).  Glad to be running "PBX In A Flash - PIAF" these days as I can grab the latest Asterisk upgrades and compile with a few simple commands.<br />
[<a href="http://labs.mudynamics.com/advisories/MU-200908-01.txt">Asterisk Bug Disclosed by Mu Dynamics</a>]</p>
<p style="text-align: left;">In light of the fun WordPress bugs today eWeek was running an article about common PHP coding mistakes and what you can do about them.  Personally I think the OWASP ESAPI toolkits are a better reference (where's Rails OWASP?), but to each their own.  You can always learn something from another perspective, right?<br />
[<a href="http://www.eweek.com/c/a/Security/Common-PHP-Security-Mistakes-and-What-You-Can-Do-About-Them-427112/?kc=rss">Common PHP Security Mistakes and What You Can Do About Them</a>]<br />
[<a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API">OWASP ESAPI</a>]</p>
<p style="text-align: left;">Wired was one of the first outlets to be seen running the story about the sentencing of the hacker with Aspergers sentenced to 55 months.  The original sentence would have been only slightly longer, but because because of the disease it was said that Mr. Berkovich was more susceptible to recruitment.  The actual hack was relatively impressive because of it's simplicity and reliability.<br />
[<a href="http://www.wired.com/threatlevel/2009/08/truckers/">Hacker with Asperger's Gets 55 Months</a>]</p>
<p style="text-align: left;">The "insider threat", all too common right?  What about "insider risk"?  Dennis Kuntz over at the Security Catalyst ran a nice clip this afternoon talking about the separation of defining insider threat and risk.  Maybe it's time to start looking at it again (or for the first time).<br />
[<a href="http://www.securitycatalyst.com/insider-threat-or-risk/">Insider Threat or Risk?</a>]</p>
<p style="text-align: left;">Not a day goes by that we can't get around something new, clever, lame or exciting directly tied to PCI.  That's why I feel morally obligated to tell you that 1.2.1 is now official.  Yeah, sure, it's not really any real defining changes but more-so fixes.  Go check out Branden Williams rundown of what's new.<br />
[<a href="http://blogs.verisign.com/securityconvergence/2009/08/pci_dss_goes_v121.php">PCI DSS Goes 1.2.1</a>]</p>
<p style="text-align: left;">Gunnar Peterson sets up the story about why a simple DTD can DoS your XML parser.  Old security bugs never die, says Gunnar, until you kill them.<br />
[<a href="http://1raindrop.typepad.com/1_raindrop/2009/08/behold-the-power-of-fuzzing.html">Behold the Power of Fuzzing</a>]</p>
<p style="text-align: left;">Oh Forrester, you get paid to come up with this stuff?  Forrester says all sec pros should drop what they're doing and focus on ways to secure the cloud because everyone knows the cloud is everything.  I'd honestly have to say that Rob Whiteley isn't too in touch with the real world these days.  Try hitting up your neighborhood Fortune 50 and see, actually, how much of their infrastructure is tied to SaaS, PaaS or IaaS.<br />
[<a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1364294,00.html?track=sy160">Data Has Become Too Distributed to Secure Says <span style="text-decoration: line-through;">Magic 8-Ball</span> Forrester</a>]</p>
<p style="text-align: left;">That's all for the commentary we have today folks.  Check back tomorrow for more!  I'll leave you with today's grab bag...</p>
<p style="text-align: left;">-windexh8er</p>
<p style="text-align: left;">[<a href="http://superconductor.voltage.com/2009/08/are-you-secure-or-are-you-safe.html">Are you secure, or are you safe?</a>]<br />
[<a href="http://www.networkworld.com/news/2009/081109-study-adobe-flash-cookies-pose.html">Adobe Flash Cookies Pose Vexing Privacy Questions</a>]<br />
[<a href="http://www.securityfocus.com/brief/993?ref=rss">More Companies Monitoring E-Mail</a>]<br />
[<a href="http://blog.dasient.com/2009/08/dasient-launches-web-anti-malware-lite_11.html">Dasient Launches Web Anti-Malware Lite</a>]<br />
[<a href="http://www.theregister.co.uk/2009/08/11/pirate_bay_down/">Pirate Bay Sinks Under Electrical Storm</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitystallions.com/index.php/2009/08/11/daily-digs-08-11-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
