<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1796525214913699148</id><updated>2011-04-21T12:53:39.027-05:00</updated><category term='Me'/><category term='Quote'/><category term='Introduction'/><category term='Cup of Cocoa'/><category term='Best Practice'/><category term='Vista'/><category term='VoIP'/><category term='Malware'/><category term='Sun'/><category term='Microsoft'/><category term='SPAM'/><category term='Travel'/><category term='Patching'/><category term='Quicktime'/><category term='Exploits'/><category term='Passwords'/><category term='Culture'/><category term='Update'/><category term='Liberty'/><category term='WIndows'/><category term='Risk'/><category term='Security'/><category term='Java'/><title type='text'>Security Soapbox</title><subtitle type='html'>Leonard's Soapbox for security, privacy and more.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>47</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-4142079068477723398</id><published>2007-06-05T07:20:00.000-05:00</published><updated>2007-06-05T07:58:36.709-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk'/><category scheme='http://www.blogger.com/atom/ns#' term='Best Practice'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Responsibility is Everyone's Job</title><summary type='text'>The software developers constantly talk about responsible disclosure.Responsible disclosure is basically defined as informing the software developer of a vulnerability so that the vulnerability can be researched and fixed.  This is compared to full disclosure where the vulnerability is announced to everyone without giving the software developer a chance to fix the vulnerability.  Contrast this </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/4142079068477723398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=4142079068477723398' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4142079068477723398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4142079068477723398'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/06/responsibility-is-everyones-job.html' title='Responsibility is Everyone&apos;s Job'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6946750380776042327</id><published>2007-05-31T06:31:00.000-05:00</published><updated>2007-05-31T06:55:12.380-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Best Practice'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>When Google isn't Google: Google-analytics Compromised</title><summary type='text'>It has been reported the the popular Google Analytics has been compromised.  The details are in the ISC Diary Entry titled Google Counter ... isn't.What this means to the average user is that any web site that uses Google Analytics, and there are more than a few that use this free service, will attempt to infect your computer.Wat is the average user to do?  Disable javascript and break most web </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6946750380776042327/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6946750380776042327' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6946750380776042327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6946750380776042327'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/when-google-isnt-google-google.html' title='When Google isn&apos;t Google: Google-analytics Compromised'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-5786419180105274626</id><published>2007-05-30T16:03:00.001-05:00</published><updated>2007-05-30T16:24:19.613-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Windows Please Phone Home!</title><summary type='text'>I have talked about patching a few times.I have also discussed how I have found Microsoft Windows systems that where configured for automatic downloading of security patches, but where not patched in Cup of Hot Cocoa: Patch Warfare II.Now it appears that Microsoft has taken notice and has released patches to fix the problems with the automatic updates, and manually using Microsoft and Windows </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/5786419180105274626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=5786419180105274626' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5786419180105274626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5786419180105274626'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/windows-please-phone-home.html' title='Windows Please Phone Home!'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-4933715759938930467</id><published>2007-05-25T00:00:00.000-05:00</published><updated>2007-05-25T00:38:49.023-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Drive by What?</title><summary type='text'>It used to be that that you could avoid certain types of sites and avoid most malware.  Add a good antivirus software are you where pretty safe.  Not any more just about any site can be used for drive-by-downloads.Now even major sites can participate in spread infections just by displaying advertising.  The dark side submits an ad that downloads malware by just viewing the ad on a site.This has </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/4933715759938930467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=4933715759938930467' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4933715759938930467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4933715759938930467'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/drive-by-what.html' title='Drive by What?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-967521020587115589</id><published>2007-05-20T05:40:00.000-05:00</published><updated>2007-05-20T08:14:11.688-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Best Practice'/><category scheme='http://www.blogger.com/atom/ns#' term='Culture'/><title type='text'>Videos</title><summary type='text'>Who knows you better than your peers?It seems that there was a contest for university students to create videos to increase awareness of computer security among university students.The contest was conducted by the EDUCAUSE/Internet2 Computer and Network Security Task Force, the National Cyber Security Alliance, and ResearchChannel.Even though the intended audience is college and university </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/967521020587115589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=967521020587115589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/967521020587115589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/967521020587115589'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/videos.html' title='Videos'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1028379120397583831</id><published>2007-05-09T21:59:00.000-05:00</published><updated>2007-05-09T20:57:20.037-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Liberty'/><category scheme='http://www.blogger.com/atom/ns#' term='Culture'/><title type='text'>Enemy of the State RFID Style?</title><summary type='text'>The PlotBack in November of 1998 the movie Enemy of the State was released starring Will Smith as the harassed citizen that was tracked with every asset the government had including satellites.  While I do not claim to have access to any details of what the theses satellites can do I can make a few statements safely.No one casually moves satellites between orbits.  Simply put they have a limited </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1028379120397583831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1028379120397583831' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1028379120397583831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1028379120397583831'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/enemy-of-state-rfid-style.html' title='Enemy of the State RFID Style?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-5589900038906497097</id><published>2007-05-06T06:27:00.000-05:00</published><updated>2007-05-06T07:16:05.728-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk'/><title type='text'>AOL Password Warning: Time to Change Your Password?</title><summary type='text'>I try to avoid posting what everyone else is posting, but this case is special.  Due to the number of AOL users I'm going to post this brief message and link to the original post.Brian Krebs posted AOL's Password Puzzler on his Security Fix Blog yesterday May 5th.  In short even though AOL allows passwords up to 16 characters it *only* uses the first 8 characters.  I'll be the first to admit that</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/5589900038906497097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=5589900038906497097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5589900038906497097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5589900038906497097'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/aol-password-warning-time-to-change.html' title='AOL Password Warning: Time to Change Your Password?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1730897386543989942</id><published>2007-05-02T04:12:00.000-05:00</published><updated>2007-05-02T04:29:43.326-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Olympic Sized Ego</title><summary type='text'>Picture this:Security Bozos are happy to welcome you to the 2012 Olympics.  Please excuse us while we limit the size of your drinks, run you through bomb detection equipment, search your belongings and in general disrupt your ability t0 enjoy the games.  Please note that there will be a number of winners that will receive full body cavity searches.Or this:The 2012 Olympics are brought to you by [</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1730897386543989942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1730897386543989942' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1730897386543989942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1730897386543989942'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/05/olympic-sized-ego.html' title='Olympic Sized Ego'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-2558893323126877823</id><published>2007-04-17T22:13:00.001-05:00</published><updated>2007-04-21T22:22:44.428-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Culture'/><title type='text'>The Dark Side</title><summary type='text'>Now that I talked about the Internet culture in general in Out of the Mists of Antiquity... I will discuss the inevitable dark side,In the beginning there trust and sharing, but alas this was not paradise, just another place for humans to interact.One of the earliest, and well know, examples of the dark side is the flame war.  This is the term given when two or more parties disagree on a topic </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/2558893323126877823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=2558893323126877823' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2558893323126877823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2558893323126877823'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/out-of-mists-of-antiquity_17.html' title='The Dark Side'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-5704234056170815727</id><published>2007-04-17T22:13:00.000-05:00</published><updated>2007-04-17T22:55:41.962-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Culture'/><title type='text'>Out of the Mists of Antiquity...</title><summary type='text'>The only way to really understand something is to go back to the beginning, and the dark side of the Internet is no different.  Without light there can be no dark so that is where I'll start.In the beginning there was ARPANET (Advanced Research Projects Agency Network) which begat the Internet.First understand that in sharp contrast to the standard mainframe centric standard of the day (1960s)  </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/5704234056170815727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=5704234056170815727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5704234056170815727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5704234056170815727'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/out-of-mists-of-antiquity.html' title='Out of the Mists of Antiquity...'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6164535946507252247</id><published>2007-04-11T23:09:00.000-05:00</published><updated>2007-04-11T23:09:33.681-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='SPAM'/><title type='text'>Licensed to SPAM by Uncle Sam</title><summary type='text'>Shame on me after complaining about MS and their marketing hype, on the other had you can start sending SPAM to one of the lesser know TLA governmental agencies.Now getting serious the Securities and Exchange Comission (SEC) wants  pump and dump SPAM forwarded to them.The Internet Storm Center (ISC) has a  diary entry here that contains additional information and information about other non-US </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6164535946507252247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6164535946507252247' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6164535946507252247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6164535946507252247'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/licensed-to-spam-by-uncle-sam.html' title='Licensed to SPAM by Uncle Sam'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-9072359738435503257</id><published>2007-04-11T00:07:00.001-05:00</published><updated>2007-04-11T00:08:05.694-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>The One, The Only, The Vulnerable Vista</title><summary type='text'>Lets start this out by saying that Vista was designed to be more secure, and it appears to be headed in the right direction there.  Just don't get me started on DRM.Once again Vista, the impenetrable, that is according to the marketing hype has been proven vulnerable.  There was the ANI vulnerability that MS rushed a patch out for last week, and now during the regular update there is a second </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/9072359738435503257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=9072359738435503257' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/9072359738435503257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/9072359738435503257'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/one-only-vulnerable-vista.html' title='The One, The Only, The Vulnerable Vista'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3002067817029132172</id><published>2007-04-10T14:39:00.000-05:00</published><updated>2007-04-10T15:17:45.170-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><title type='text'>Vista Smista &amp; ANI Exploit</title><summary type='text'>OK, I've gotten it out of my system.  I'm not a fan of Vista  I have two main issues in regards to Vista:The fact that Digital Rights Management (DRM) has some control over my system, and can degrade or disable viewing "premium content" when someone else feels that there is a potential for me to steal premium content.  I'd call that guilty unless proven innocent.Then there is the marketing, I </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3002067817029132172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3002067817029132172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3002067817029132172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3002067817029132172'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/vista-smista-ani-exploit.html' title='Vista Smista &amp; ANI Exploit'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-2058254896108909645</id><published>2007-04-02T21:53:00.001-05:00</published><updated>2007-04-02T21:53:59.087-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Malware the New Common Cold</title><summary type='text'>Everyone has had a cold and everyone will continue to get colds.  Science, and your doctor, have tried to eradicate the common cold, but to no avail.Why are we still saddled with the common cold.  Lets go to the root cause, which is, excuse me, are viruses, and by viruses I mean uncountable millions.  Common cold viruses are so numerous  that no one has attempted to even count them, common cold </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/2058254896108909645/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=2058254896108909645' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2058254896108909645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2058254896108909645'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/malware-new-common-cold.html' title='Malware the New Common Cold'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1884679245472663407</id><published>2007-04-02T00:24:00.000-05:00</published><updated>2007-04-02T01:16:29.811-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><title type='text'>Its a Cold Day on the Internet</title><summary type='text'>No this is not an April fools joke.Once again the dark side has come out with a nasty, and this one is so bad that the Internet Storm Center (ISC)  has raised the threat level to Yellow which ISC describes as:We are currently tracking a significant new threat. The impact is either unknown or expected to be minor to the infrastructure. However, local impact could be significant. Users are advised </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1884679245472663407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1884679245472663407' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1884679245472663407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1884679245472663407'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/04/its-cold-day-on-internet.html' title='Its a Cold Day on the Internet'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-9221615644118636330</id><published>2007-03-28T00:25:00.000-05:00</published><updated>2007-03-27T23:25:38.390-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>Another Cup of Cocoa: Responsibility</title><summary type='text'>MySpace, YouTube, Web 2.0 there is so much happening and available out there. It is all exciting and there are so many possibilities opening up.The freedom of the Internet and web works both ways. The same technology lets you explore web sites on the other side of the world allows anyone in the world to attack your system and steal from you.In the real world people choose where to go and can </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/9221615644118636330/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=9221615644118636330' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/9221615644118636330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/9221615644118636330'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/another-cup-of-cocoa-responsibility.html' title='Another Cup of Cocoa: Responsibility'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-141259964698504288</id><published>2007-03-27T00:00:00.000-05:00</published><updated>2007-03-26T23:12:00.610-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>A Travel Cup of Hot Cocoa: Defense in depth</title><summary type='text'>Everyone likes to keep their hot Cocoa hot.  So travel mugs are insulated, and have a lid to help keep it hot.  Yes it keeps it in the mug as well, but you can argue that keeping more in the mug helps keep the heat in ;-)Which brings me to the topic at hand defense-in-depth for the PC.If it was made by man, it can be hacked and cracked by man.- AnonymousAbsolutely nothing is foolproof!  On the </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/141259964698504288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=141259964698504288' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/141259964698504288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/141259964698504288'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/travel-cup-of-hot-cocoa-defense-in.html' title='A Travel Cup of Hot Cocoa: Defense in depth'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8022825049047748702</id><published>2007-03-26T21:49:00.000-05:00</published><updated>2007-03-26T22:08:49.173-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Best Practice'/><title type='text'>Credit vs. Debit</title><summary type='text'>Is a credit card better than a debit card, or vise-versa.In the US the credit card wins hands down, by federal law the credit card is responsible for fraudulent charges to your account.  No such protection for debit cards exist, even if they are used as a "credit card."A short, and unfortunately true, story to illustrate the issues with a debit card.A man goes through a fast-food drive through </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8022825049047748702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8022825049047748702' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8022825049047748702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8022825049047748702'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/credit-vs-debit.html' title='Credit vs. Debit'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-783511857641231636</id><published>2007-03-26T00:00:00.000-05:00</published><updated>2007-03-25T22:08:18.783-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>The Band-aid Approach</title><summary type='text'>There was a comment posted asking why I was against the approach of shuffling buffers around in my post entitled Exploit Longevity (http://sec-soapbox.blogspot.com/2007/03/exploit-longevity.html).Before I can answer I need to make sure that we have a common understanding of buffers and buffer overflows.What is a Buffer?A buffer is a portion of memory where a program stores information that </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/783511857641231636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=783511857641231636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/783511857641231636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/783511857641231636'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/band-aid-approach.html' title='The Band-aid Approach'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1511537505455846122</id><published>2007-03-20T21:10:00.000-05:00</published><updated>2007-03-20T21:36:20.666-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Exploit Longevity</title><summary type='text'>Ever notice how some exploits just seem to stay around forever?There is actually a simple, but in my opinion ugly, explanation for this. As usual an example can be worth a thousand words, and I’m going to use rpc18.c as an example:////////////////////////////////////////////////////////// Windows RPC DCOM Remote Exploit with 18 Targets// by pHrail and smurfy + some offsets by teos//// Targets:// </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1511537505455846122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1511537505455846122' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1511537505455846122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1511537505455846122'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/exploit-longevity.html' title='Exploit Longevity'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8748966290027820331</id><published>2007-03-17T23:00:00.000-05:00</published><updated>2007-05-30T16:02:02.814-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>Cup of Hot Cocoa: Patch Warfare II</title><summary type='text'>What to do?FirstEither update you machines religiously on every Black Tuesday (the second Tuesday of the month when Microsoft releases security patches).  I don't trust Microsoft update.  I have seen too many machines that have it running and are still unpatched days after new patches are released.  I know many of these machines where left running over night to update.  So my conclusion is the </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8748966290027820331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8748966290027820331' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8748966290027820331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8748966290027820331'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/cup-of-hot-cocoa-patch-warfare-ii.html' title='Cup of Hot Cocoa: Patch Warfare II'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6698705574372715651</id><published>2007-03-16T00:01:00.000-05:00</published><updated>2007-03-26T23:12:56.818-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>Cup of Hot Cocoa: Patch Warfare</title><summary type='text'>Back in the day...In the PC world patches where a rare thing.  You purchased a program and then when the next version came out you either upgraded or didn't end of story.As programs became more complex and we actually began to use more of the growing set of features.  We found bugs and software companies began to supply patches.  If I recall correctly (IIRC) most patches where actually a whole </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6698705574372715651/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6698705574372715651' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6698705574372715651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6698705574372715651'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/cup-of-hot-cocoa-patch-warfare.html' title='Cup of Hot Cocoa: Patch Warfare'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3664856025361961169</id><published>2007-03-15T21:31:00.000-05:00</published><updated>2007-03-15T21:53:53.488-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><title type='text'>Why is Windows Insecure?</title><summary type='text'>Consider the following quote for a minute:Securing an environment of Windows platforms from abuse - external or internal - is akin to trying to install sprinklers in a fireworks factory where smoking on the job is permitted.— Gene Spafford (in e-mail to organizers of a workshop on insider misuse)I' say reactions for this statement cove the whole range.  From "Them's fight'in words" to laughter to</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3664856025361961169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3664856025361961169' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3664856025361961169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3664856025361961169'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/why-is-windows-insecure.html' title='Why is Windows Insecure?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8504525465462717630</id><published>2007-03-12T20:39:00.000-05:00</published><updated>2007-03-26T23:12:56.819-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Java'/><category scheme='http://www.blogger.com/atom/ns#' term='Sun'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>A Small Cup of Hot Cocoa</title><summary type='text'>Less is More!Less running or installed on your computer is more secure.  With less running on your computer there are fewer attack vectors (http://searchsecurity.techtarget.com/sDefinition/0,290660,sid14_gci1005812,00.html).To make sure we are all on the same page consider that everything that us running on a computer is a potential weak point where the system can be compromised.  Unnecessary or </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8504525465462717630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8504525465462717630' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8504525465462717630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8504525465462717630'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/small-cup-of-hot-cocoa.html' title='A Small Cup of Hot Cocoa'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8617386600716550468</id><published>2007-03-09T10:05:00.001-05:00</published><updated>2007-03-09T10:34:37.645-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Light at the End of the Tunnel?</title><summary type='text'>...or do I hear a train coming?Microsoft has announced (http://www.microsoft.com/technet/security/bulletin/advance.mspx) that there will be no Black Tuesday (no security patches) this month.  Have we finally turned the tide?  I think not.SANS Internet Storm Center keeps a list of knows security vulnerabilities that are not patched "The missing Microsoft patches." (http://isc.sans.org/diary.html?</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8617386600716550468/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8617386600716550468' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8617386600716550468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8617386600716550468'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/light-at-end-of-tunnel.html' title='Light at the End of the Tunnel?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3727468914885061085</id><published>2007-03-08T07:34:00.000-05:00</published><updated>2007-03-26T23:12:56.821-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Cup of Cocoa'/><title type='text'>Hot Cocoa</title><summary type='text'>Based on my recent blog entry  on insecure endpoints "https is all I need, right?" (http://sec-soapbox.blogspot.com/2007/03/https-is-all-i-need-right.html)Joe of 2 Guys Named Joe  (http://www.2gnj.com) wants to know how to determine if he is secure and if his information is already out there.First my warning the Cocoa is very hot be careful that you do not burn your tongue.  In other words there </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3727468914885061085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3727468914885061085' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3727468914885061085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3727468914885061085'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/hot-cocoa.html' title='Hot Cocoa'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8464955365808625236</id><published>2007-03-07T23:07:00.000-05:00</published><updated>2007-03-08T07:26:01.690-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Patching'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><title type='text'>Black Tuesday, Wednesday, Thursday, etc.</title><summary type='text'>MS PatchingOfficially called Patch Tuesday is the second Tuesday of the month, and is the date that Microsoft released their patches for the month.Many users, and small companies, have set their computer to automatically update.  These computers will daily check for updates, and apply them as they are releases.  Or not...It appears that the shear volume of computers attempting to check for </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8464955365808625236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8464955365808625236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8464955365808625236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8464955365808625236'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/black-tuesday-wednesday-thursday-etc.html' title='Black Tuesday, Wednesday, Thursday, etc.'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3298586303035401444</id><published>2007-03-06T09:05:00.000-05:00</published><updated>2007-03-06T09:05:19.747-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk'/><title type='text'>Risk Options</title><summary type='text'>Old, but still relevant.Wisdom consists in being able to distinguish among dangers and make a choice of the least harmful.— Niccolo Machiavelli, The PrinceValue vs. CostThis is still one of the hardest aspects of security today.  What are your different assets worth and how much will you spend on protecting them? The difficulty raises when  intangible assets are involved.  How much is a customer </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3298586303035401444/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3298586303035401444' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3298586303035401444'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3298586303035401444'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/risk-options.html' title='Risk Options'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-4999196344543142531</id><published>2007-03-05T01:00:00.000-05:00</published><updated>2007-03-05T04:10:13.906-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>https is all I need, right?</title><summary type='text'>Everyone talks about only sending you information over a secured connection when ordering or sending personal information over the internet, but is that all you should be concerned about?Using encryption on the Internet is the equivalent of arranging an armored car to deliver credit card information from someone living in a cardboard box to someone living on a park bench.— Gene SpafforIn other </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/4999196344543142531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=4999196344543142531' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4999196344543142531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/4999196344543142531'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/https-is-all-i-need-right.html' title='https is all I need, right?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-2783720193599262391</id><published>2007-03-04T21:00:00.000-05:00</published><updated>2007-03-04T20:55:58.746-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>Evolution: Fun, Bragging Rights and Profit</title><summary type='text'>In the BeginningBack in the old days it was the curious looking to expand their understanding of systems. They could hack together a program in fact the best hack was the most concise and elegant code.Organic EvolutionSome of these hackers turned their focus deep into the bowels or the computers and their operating systems.  Of course this required a higher privilege level so cracking into </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/2783720193599262391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=2783720193599262391' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2783720193599262391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2783720193599262391'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/evolution-fun-bragging-rights-and.html' title='Evolution: Fun, Bragging Rights and Profit'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-7582915655341008608</id><published>2007-03-03T01:00:00.000-05:00</published><updated>2007-03-03T09:28:29.702-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>One</title><summary type='text'>One simply one.  One crack one unguarded entry point of entry or one moment of opportunity. So true, and so deadly at the same time:We only need to be lucky once. You need to be lucky every time.— The IRA to Margaret Thatcher, after a failed assassination attempt.Probably the most famous example of  one point of weakness is Achilles heel (http://en.wikipedia.org/wiki/Achilles%27_heel).   In short</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/7582915655341008608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=7582915655341008608' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7582915655341008608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7582915655341008608'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/one.html' title='One'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-5700333087764964104</id><published>2007-03-02T01:00:00.000-05:00</published><updated>2007-03-02T12:17:06.073-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>Why is Defense so Hard?</title><summary type='text'>The basic premises is that you defend every attack vector. While the attacker probes for the one weak point where your defenses can be bypassed or breached.Securing a computer system has traditionally been a battle of wits: the penetrator tries to find the holes, and the designer tries to close them.— M. GosserWhen possible in the physical world fortifications are used to limit the attack vectors</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/5700333087764964104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=5700333087764964104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5700333087764964104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/5700333087764964104'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/03/why-is-defense-so-hard.html' title='Why is Defense so Hard?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6364000035758229272</id><published>2007-03-01T05:30:00.000-05:00</published><updated>2007-03-01T05:31:32.352-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='VoIP'/><title type='text'>This isn't Your Fathers Phone</title><summary type='text'>As I mentioned previously I started blogging after being a guest on the "2 Guys Named Joe" podcast (http://twoguysnamedjoe.libsyn.com/).Recently I was invited back to discuss VoIP AKA Voice over IP (http://www.answers.com/main/ntquery?s=voip&amp;gwp=13) for their current podcast 2gnj Episode 30: Ed Wants VOIP (http://twoguysnamedjoe.libsyn.com/index.php?post_id=185540).I really enjoy doing the </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6364000035758229272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6364000035758229272' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6364000035758229272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6364000035758229272'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/this-isnt-your-fathers-phone.html' title='This isn&apos;t Your Fathers Phone'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-7228965260419921554</id><published>2007-02-25T08:08:00.000-05:00</published><updated>2007-02-25T15:49:23.498-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>Isn't that so cute...</title><summary type='text'>The user's going to pick dancing pigs over security every time.— Bruce SchneierThis in one sentence summarizes how the bad guys penetrate defenses time after time.  how can that cute little game be harmful.This is also why Vista's UAC giving administrator rights to every setup program that is run.</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/7228965260419921554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=7228965260419921554' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7228965260419921554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7228965260419921554'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/isnt-that-so-cute.html' title='Isn&apos;t that so cute...'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3327765356945777417</id><published>2007-02-23T07:46:00.000-05:00</published><updated>2007-02-23T23:07:14.734-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>Ultimate Security</title><summary type='text'>Now this is getting to be truly secure:"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards - and even then I have my doubts."- Gene Spafford, Ph.D., Purdue CERIASI like to expand on this by having the concrete cover computer sealed in a lead box that is dropped off at a random location in the ocean... then of </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3327765356945777417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3327765356945777417' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3327765356945777417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3327765356945777417'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/ultimate-security.html' title='Ultimate Security'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6209045768750633908</id><published>2007-02-22T07:44:00.000-05:00</published><updated>2007-02-22T07:45:46.349-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Liberty'/><category scheme='http://www.blogger.com/atom/ns#' term='Quote'/><title type='text'>Liberty Boxes</title><summary type='text'>Everyone runs across quotes in their digital life, and some are worth sharing."There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order."-Ed Howdershelt (Author)</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6209045768750633908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6209045768750633908' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6209045768750633908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6209045768750633908'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/liberty-boxes.html' title='Liberty Boxes'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-7847814790157114130</id><published>2007-02-21T10:27:00.000-05:00</published><updated>2007-02-21T11:08:33.120-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><title type='text'>The Register on Vista Security</title><summary type='text'>The Register has a good blow-by-blow article on Vista Security (http://www.theregister.co.uk/2007/02/20/vista_security_oversold/).  As you would hope for it covers the good, the bad and the ugly.  This is true despite an inflammatory remark, especial if taken out of context as it is here:In a nutshell, Windows is single-handedly responsible for turning the internet into the toxic shithole of </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/7847814790157114130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=7847814790157114130' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7847814790157114130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/7847814790157114130'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/register-on-vista-security.html' title='The Register on Vista Security'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-21130026428199832</id><published>2007-02-20T12:32:00.000-05:00</published><updated>2007-03-08T07:33:18.910-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><category scheme='http://www.blogger.com/atom/ns#' term='Travel'/><title type='text'>TSA Hacked, Incompetent or Both</title><summary type='text'>The story begins like this:Has the Transportation Security Administration's website been hacked? All indications are yes, and that a malicious phishing attack has been launched against travelers...-http://blog.wired.com/27bstroke6/2007/02/homeland_securi.htmlThen it gets worse.Read the article and it this is any indication of the professionalismbe afraid be very afraidUpdate 3/8/2007: Congress </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/21130026428199832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=21130026428199832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/21130026428199832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/21130026428199832'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/tsa-hacked-incompetent-or-both.html' title='TSA Hacked, Incompetent or Both'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6661891623293848454</id><published>2007-02-20T12:19:00.000-05:00</published><updated>2007-02-21T10:27:50.524-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='WIndows'/><title type='text'>How to Find Bad Apps</title><summary type='text'>Every month Windows or Microsoft Update will download patches and fixed to your computer, but what about all the other non-Microsoft software?To check on upgrades for popular and multimedia software simply use the Secunia Software Inspector(http://secunia.com/software_inspector/).</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6661891623293848454/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6661891623293848454' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6661891623293848454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6661891623293848454'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/how-to-find-bad-apps.html' title='How to Find Bad Apps'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-6105793899925410109</id><published>2007-02-14T17:50:00.000-05:00</published><updated>2007-02-22T01:45:08.710-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><title type='text'>The 6 Million Dollar OS: Or A New Prey in Town</title><summary type='text'>I can just hear it "We can re-build it better, faster, more secure... the 6 million dollar OS"Is it really better or just a new meal for the predators of the InternetMicrosoft Vista is a rewrite of the desktop version of Microsoft's flagship Windows OS.  It is touted as the most secure, stable, advanced OS yet. What is the reality behind the hype?Anecdotally:No major company is even interested in</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/6105793899925410109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=6105793899925410109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6105793899925410109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/6105793899925410109'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/02/6-million-dollar-os-or-new-prey-in-town.html' title='The 6 Million Dollar OS: Or A New Prey in Town'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1043515341591403300</id><published>2007-01-30T06:47:00.000-05:00</published><updated>2007-01-30T06:56:29.726-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Predators and their Prey</title><summary type='text'>An old joke in the security community is:Two people are walking on the Serengeti and they notice a lion is stalking them.The first person stops , pulls out running shoes and puts them on.The second person states "You can't out run a lion."The first person states "I don't I have to out run the lion.  I have to out run you." The moral is that the easiest "kill" is the one most often taken by the </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1043515341591403300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1043515341591403300' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1043515341591403300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1043515341591403300'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/predators-and-their-prey.html' title='Predators and their Prey'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8500188550852146039</id><published>2007-01-25T05:12:00.000-05:00</published><updated>2007-02-21T13:30:26.656-05:00</updated><title type='text'>acroBat out of 'ell</title><summary type='text'>I now know why Acrobat 7 doesn't have Acrobat 8 as an upgrade.  So far it seems to be a downgrade in ease of use and quite slow.Now I upgraded because lately there have been several issues with Acrobat 7 that were notpresent in Acrobat 8.  Additional details on the vulnerabilities at the end for those that wish more information.Anyway I decided to update to Acrobat 8 only to losefunctionality and</summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8500188550852146039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8500188550852146039' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8500188550852146039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8500188550852146039'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/acrobat-out-of-ell.html' title='acroBat out of &apos;ell'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-2398548888872204323</id><published>2007-01-23T21:40:00.000-05:00</published><updated>2007-03-08T08:30:34.550-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Anatomy of a Password</title><summary type='text'>With my recent post concerning password tools it seemed like a good idea to discuss passwords and what makes a reasonable password.  I wont get overly technical or as in depth as Perfect Passwords (http://www.syngress.com/catalog/?pid=3420) which is full of good advice for the average user and administrator.The Good, Bad and UglyGood:  Secure passwords are long and complex making it difficult </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/2398548888872204323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=2398548888872204323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2398548888872204323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2398548888872204323'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/anatomy-of-password.html' title='Anatomy of a Password'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-3447358530450776604</id><published>2007-01-23T21:26:00.000-05:00</published><updated>2007-01-23T21:39:29.414-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><category scheme='http://www.blogger.com/atom/ns#' term='Quicktime'/><title type='text'>Not so Quick Quicktime Fix</title><summary type='text'>Apple has released a fix (http://docs.info.apple.com/article.html?artnum=304989) for the Quicktime vulnerability first announced July 2nd, 2007 (http://www.kb.cert.org/vuls/id/442497).Per the Apple site, URL above:"Impact: Visiting malicious websites may lead to arbitrary code execution" </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/3447358530450776604/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=3447358530450776604' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3447358530450776604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/3447358530450776604'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/not-so-quick-quicktime-fix.html' title='Not so Quick Quicktime Fix'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-8491125834749770964</id><published>2007-01-23T09:59:00.000-05:00</published><updated>2007-03-08T08:54:42.863-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><title type='text'>Password Tools</title><summary type='text'>Passwords are the bane of security.  Users hate them. Technical support spends too much time with password problems.  Other options cost too much up front imagine spending thousands of dollars to setup a solution that costs an additional  $100 or more for each user.Different systems have different requirements for user IDs and passwords.  Password expire at different times.Some site use </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/8491125834749770964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=8491125834749770964' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8491125834749770964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/8491125834749770964'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/password-tools.html' title='Password Tools'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-1107726253476946099</id><published>2007-01-22T22:52:00.000-05:00</published><updated>2007-03-08T07:33:38.001-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Java'/><category scheme='http://www.blogger.com/atom/ns#' term='Sun'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><title type='text'>Do you Java?</title><summary type='text'>Sun Java has this nice "feature." Every time you update it the old version is left behind.Which is great if you have some Java program that needs that version. For the rest of us it leave old, hopefully unused, vulnerable code laying around.oh by the way it's not just a few megabytes. Per the MS "Add/Remove Programs" each version takes up between 60+ MB to over 100MB. Not that I've verified that </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/1107726253476946099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=1107726253476946099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1107726253476946099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/1107726253476946099'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/do-you-java.html' title='Do you Java?'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1796525214913699148.post-2509903153471330279</id><published>2007-01-22T07:43:00.000-05:00</published><updated>2007-01-22T08:05:39.088-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Me'/><category scheme='http://www.blogger.com/atom/ns#' term='Introduction'/><title type='text'>Hello World</title><summary type='text'>Every, or nearly every, programming course/tutorial starts with a "hello world" program.  so in my initial post I pay my respects to this tradition.I have been in the IT field for over 20 years and have worked, contracted and consulted to and for many companies in many capacities.  Currently as I have my CISSP I am concentrating on security.I plan using this blog to discuss security related </summary><link rel='replies' type='application/atom+xml' href='http://sec-soapbox.blogspot.com/feeds/2509903153471330279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1796525214913699148&amp;postID=2509903153471330279' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2509903153471330279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1796525214913699148/posts/default/2509903153471330279'/><link rel='alternate' type='text/html' href='http://sec-soapbox.blogspot.com/2007/01/hello-world.html' title='Hello World'/><author><name>Leonard</name><uri>http://www.blogger.com/profile/13692766164366215532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
