<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Fighting Back</title>
	<atom:link href="http://www.uncompiled.com/category/fighting-back/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>&#8216;World&#8217;s No. 1 hacker&#8217; tome rocks security world</title>
		<link>http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/</link>
		<comments>http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 11:06:05 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1335</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>A recently published e-book penned by the self-proclaimed “world&#8217;s No. 1 hacker” is rocking the security community with back-and-forth allegations of plagiarism, racism, and even threats against a security podcaster and his family.</p>
<p>How to Become the World&#8217;s No. 1 Hacker is purportedly written by Gregory D. Evans, an animated felon who went on to become CEO of Ligatt Security International, a publicly traded company worth about 0.0002 cent per share that bills itself as a full-service computer security firm. Released by the obscure Cyber Crime Media publishing house, the 342-page PDF is a comprehensive, step-by-step guide for consumers who want to learn how to harden their networks against attackers. Unix security, Wi-Fi cracking, and web service configuration are all covered.</p>
<p>But it turns out that huge chunks of the book weren&#8217;t written by Evans at all, even though no other authors are credited. For instance, virtually all of Chapter 12 – 5,894 words, to be exact – is identical to this tutorial on port scanning written by Armando Romeo and published on the hackerscenter.com website in early 2008. And 1,750 words found in Chapter 9 were lifted from this manual posted to ethicalhacker.net, including screenshots that make reference to Chris Gates, the original author.</p>
<p>In all, at least 13 of the e-book&#8217;s 26 chapters were lifted almost entirely word-for-word from other sources without attribution, according to this analysis from Ben Rothke, a senior security consultant for a professional services firm, who ran the portions through iThenticate, an online tool for spotting plagiarism. Other sources that were used without credit include Security Focus, Auditmypc.com, and Squidoo.com.</p>
<p>“Mr Evans has never asked any permission from me and I&#8217;m the only owner of the copyrights of my website,” said Armando Romeo, CEO of eLearnSecurity who says in all five Chapters in How to Become the World&#8217;s No. 1 Hacker “have been literally copied and pasted from my guides” on the Hacker Center website. He added that this is the second run-in he&#8217;s had with Evans, who regularly appears on local and national TV shows to talk about computer security.</p>
<p>Chris Gates and Donald Donzal, the author and editor respectively of the articles on the Ethical Hacker site, are also steadfast that Evans never had permission to use their content, which was first published published in 2007. Donzal said he&#8217;s in the process of filing a take-down demand under the US Digital Millennium Copyright Act.</p>
<p>Evans – who in 2002 was sentenced to 24 months in federal prison after pleading guilty to wire fraud – has vociferously defended his use of the previously published articles. In an interview with The Register, he said he began work on the book in 2008, and largely drew on ghost writers who by contract agreed to submit “original content.” He insisted the submissions were vetted for authenticity by a service he declined to name. But he nonetheless went on to challenge the authors who have stepped forward to complain their work has been misappropriated.</p>
<p>“What you&#8217;re doing is you&#8217;re saying Greg, you put other people&#8217;s stuff in your book, but if I go out on the internet, you cannot tell me who owns those other people&#8217;s stuff,” he said. “All you&#8217;re doing is you&#8217;re telling me that who owns a website where other people publish at that website, but they&#8217;re not the owners of the content.”</p>
<p>&#8216;Mitnick under my wing&#8217;<br />
Evans, who is African American, has pushed back equally hard against other people asking hard questions about the true origins of his book. In a reference to another company Evans leads, he published a this rebuttal headlined “National Cyber Security Uncovers Racism Within the Computer Security Industry,” and continued to refer to himself as the author of the book.</p>
<p>In an accompanying video blog that was posted late last week, Evans went on to defend his hacker credentials, noting the he was incarcerated on the same floor as Kevin Mitnick during the latter&#8217;s five-year prison stint for hacking and fraud crimes.</p>
<p>“When I get in there, I take Kevin Mitnick under my wing,” Evans said in the video. “We used to turn around and have contests like who can get free phone calls, who can get away with making a three-way call without getting caught.”</p>
<p>Evans went on to claim that he advised Mitnick on a plea bargain he was negotiating with federal prosecutors and was in the same room as Mitnick when he learned he was going to be interviewed on the CBS News show &#8220;60 Minutes.&#8221; Mitnick denies the account.</p>
<p>“He basically misrepresented our relationship, our meetings” Mitnick told The Register. “He certainly didn&#8217;t take me under his wing, whatever that means. I didn&#8217;t really discuss my case with him because you don&#8217;t discuss your case with other people in jail because they&#8217;ll become informants.”</p>
<p>According to Mitnick, by the time he was approached by &#8220;60 Minutes,&#8221; he had been transferred to the Lompoc Federal Correctional Complex and hadn&#8217;t seen Evans in months.</p>
<p>Evans “made that whole story up,” Mitnick said. “He was never there.”</p>
<p>Mitnick also challenged the hacking skills of Evans, whose previous books include Memoirs of A Hi-Tech Hustler and Hi-Tech Hustler Scrap Book 2004-2005.</p>
<p>“What I recall of him, he wasn&#8217;t too savvy with hacking, but he did understand phone phreaking,” Mitnick continued. Evans&#8217;s 1998 prosecution “was a typical fraud case. It wasn&#8217;t hacking or phone freaking, really. He seemed to be a nice guy, a very evangelist type personality. I kind of sized him up kind of like a hustler, a grifter.”</p>
<p>Indeed, in video blogs promoting Ligatt Security to potential shareholders, Evans comes across at some points as a high-pressure salesman and at others as a class clown. In this video from last year discussing a deal involving a property known as spoofem.com he shares this nugget:</p>
<p>“I got the news this morning on my way to work, got here late because I caused an accident when I was reading my email and I saw it and I started screaming and I swerved and then this tractor trailer fell over and hit this bus full nuns and it was just [a] mess, but I took off real quick because I got a fast car. They didn&#8217;t know it was me, so I&#8217;m here doing this video blog. Pray for me.&#8221;</p>
<p>Be like &#8216;Googles&#8217;<br />
In the same video a few minutes later, he compared Ligatt shares to those of Google – which he mistakenly refers to as “Googles” – before the stock hit sky-high prices: “It&#8217;s just like buying Googles,” he said. “You could have bought Googles years ago. Just imagine if you bought Googles at a penny or less than a penny how trillionaire you&#8217;d be today. I&#8217;m trying to give you that same vision.&#8221;</p>
<p>But it&#8217;s fair to say Evans, who says he&#8217;s 41 years old, has a temper as well. About a half hour into his interview with The Register, after growing increasingly agitated with the questions, he abruptly stopped the conversation and, through a spokeswoman, refused to continue.</p>
<p>And according to this account from security blogger and podcaster Chris John Riley, someone left a post threatening “to go after you family [sic]” less than 15 minutes after he spoke with Evans on the phone to arrange a taped interview regarding the allegations of plagiarism.</p>
<p>“I will have my friend in your country tracked down [sic] everyone you are friends with and your family and see what you are all about,” the posting stated. The person didn&#8217;t sign the message, but the IP address used to leave the message belongs to a Bell South customer in the Atlanta area, where Ligatt Security is headquartered.</p>
<p>Evans – who often refers to himself as the &#8220;world&#8217;s No. 1 hacker&#8221; and is regularly interviewed by various Fox News anchors and affiliates – has yet to say whether he played any role in posting the comments. He terminated his interview with The Register before the issue could be addressed.</p>
<p>Riley said that nothing during his brief conversation with Evans on Wednesday gave any indication there were any hard feelings. But when the time they had arranged to conduct the podcast came, Evans was a no-show.</p>
<p>Said Riley: “I did log onto Skype and I did wait and nothing ever came around. I thought it was funny. To be honest, I think Greg is more bark than bite.” </p>
<p><a href="http://www.theregister.co.uk/2010/06/22/worlds_no_1_hacker/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;n=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;t=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;srcUrl=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;srcTitle=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22%27World%27s%20No.%201%20hacker%27%20tome%20rocks%20security%20world%22&amp;body=Link: http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;t=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;title=%27World%27s+No.+1+hacker%27+tome+rocks+security+world" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=%27World%27s+No.+1+hacker%27+tome+rocks+security+world+-+http://b2l.me/5ztad&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/&amp;submitHeadline=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=%27World%27s+No.+1+hacker%27+tome+rocks+security+world&amp;body=Link: http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/worlds-no-1-hacker-tome-rocks-security-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud security: The basics</title>
		<link>http://www.uncompiled.com/2010/06/cloud-security-the-basics/</link>
		<comments>http://www.uncompiled.com/2010/06/cloud-security-the-basics/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 13:46:59 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1310</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Cloud computing is one of the most-discussed topics among IT professionals today. And not too long into any conversation about the most highly touted cloud models—software as a service (SaaS), infrastructure as a service (IaaS) or platform as a service (PaaS)—the talk often turns to cloud security.</p>
<p>According to Milind Govekar, an analyst at Gartner, cloud has rocketed up the list from number 16 to number two in Gartner&#8217;s annual CIO survey of key technology investments. &#8220;Like with anything new, the primary concern is security,&#8221; he says. In fact, the vast majority of clients who inquire about cloud, he says, would rather create a virtualized data center on their own premises—what some call a private cloud—because they&#8217;re uncomfortable with the security issues raised by cloud computing and the industry&#8217;s ability to address them.</p>
<p>&#8220;We are in the early stages of a fascinating journey into a new computing model that, for all its purported advantages, from a security and risk point of view, is a difficult thing to deal with,&#8221; agrees Jay Heiser, an analyst at Gartner. &#8220;The things that make it easy and appealing—like the immediate plug-and-play productivity—also make it impossible to conclusively assess your relative risks.&#8221; Current certifications, such as SAS 70 and ISO 27001 and 27002, are not sufficient, he says, leading to frustration for both buyers and sellers.</p>
<p>For this reason, securing cloud computing environments will be a major focus of vendor efforts over the next year, says Jonathan Penn, an analyst at Forrester Research. In the short term, he sees users having to do a lot of the legwork, but over time, &#8220;cloud providers themselves will see the opportunity to differentiate themselves by integrating security,&#8221; he says. Security vendors accustomed to selling directly to the enterprise will find that they need these cloud providers as a way to reach the market, Penn says, and as the market matures, customers will want this stuff baked into the services they&#8217;re buying. &#8220;That will be quite a radical change and a disruption,&#8221; he adds.</p>
<p>In the meantime, organizations such as the Cloud Security Alliance (CSA) are working to put some shape around the security issues and the ways to address them. The CSA recently released a summary of the strategic and tactical security pain points within a cloud environment, along with recommendations on how to address them. The organization divided the domains into two broad areas: governance and operations.</p>
<p>Domains grouped under governance include:</p>
<p>governance and ERM<br />
legal and electronic discovery<br />
compliance and audit<br />
information lifecycle management<br />
portability and interoperability<br />
Domains grouped under operations include:</p>
<p>traditional security, business continuity and disaster recovery<br />
data center operations<br />
incident response, notification and remediation<br />
application security<br />
encryption and key management<br />
identity and access management<br />
virtualization<br />
The CSA also summarized the top threats of cloud computing, along with the cloud models each threat most pertains to and guidance for remediation.</p>
<p>The categories of tools that can help address these threats include XML, SOA and application security; encryption tools for data in transit and at rest; smart key management; log management; identity and access management; virtual firewalls and other virtualization-management tools; data-loss prevention; and more. &#8220;You&#8217;re translating the existing security architecture into the cloud, so there are a lot of different tools you&#8217;ll need, some of which already exist and other cases where you need new technology,&#8221; Reiser says.</p>
<p>For instance, malware scanning tools will need to look specifically for emerging malware that targets virtual platforms; identity management systems will need to authenticate not just users but also devices and applications; and security information management (SIM) systems will need to log billions of events and analytics.</p>
<p>Forrester also released a list of questions that enterprises should ask to secure their cloud implementation, covering the areas of security and privacy, compliance, and other legal and contractual issues.</p>
<p>Cloud layers</p>
<p>Experts also emphasize that the level of exposure and risk for the three cloud models are very different, and the way of addressing security also differs, depending on which layer you&#8217;re engaging with. &#8220;The security requirements are really the same, but as you go from SaaS to PaaS and IaaS, the level of control you have over security changes,&#8221; says Mike Kavis, founder of Kavis Technology Consulting and CTO at a startup company. &#8220;From a logical view, nothing has really changed, but how you physically do it changes dramatically.&#8221;</p>
<p>SaaS.</p>
<p>As the CSA explains, with SaaS, the provider&#8217;s applications run on a cloud infrastructure and are accessible through a Web browser. The consumer does not manage or control the network, servers, operating systems, storage or even individual application capabilities.<br />
For this reason, the SaaS model integrates the most functionality directly into the offering, with the least consumer extensibility, and &#8220;security responsibilities are almost entirely up to the vendor,&#8221; Reiser says. &#8220;If the vendor doesn&#8217;t encrypt data, it&#8217;s not encrypted. If there isn&#8217;t activity monitoring, you won&#8217;t get any.&#8221;</p>
<p>PaaS.</p>
<p>With PaaS, consumers create applications using programming languages and tools supported by the vendor and then deploy these onto the cloud infrastructure, the CSA explains. As with SaaS, the consumer does not manage or control the infrastructure—the network, servers, operating systems or storage—but does have control over the deployed applications and possibly the application-hosting environment configurations.<br />
There are fewer customer-ready or built-in security features with PaaS than with SaaS, the CSA says, and those that do exist are less complete, but there is more flexibility to layer on additional security. This means users need to pay attention to application security, as well as security issues surrounding the management APIs, such as authentication, authorization and auditing.</p>
<p>IaaS.</p>
<p>Here, consumers can provision processing, storage, networks and other fundamental computing resources, as well as deploy and run operating systems and applications, according to the CSA. While they don&#8217;t manage or control the underlying cloud infrastructure, they do have control over operating systems, storage and deployed applications, and possibly limited control of select networking components, such as host firewalls, the CSA says.<br />
With IaaS, there are few integrated security capabilities beyond protecting the infrastructure itself, but there&#8217;s enormous extensibility, according to the CSA. This means users need to manage and secure operating systems, applications and content, typically through an API.</p>
<p>&#8220;A lot of the perimeter security is handled by the vendor, but they&#8217;re giving you access to virtual machines, so you still have to build the application and provide the infrastructure control,&#8221; Kavis says.</p>
<p>With IaaS, virtualization management is a big concern, says Heiser, particularly when it comes to intrusion detection and the integrity of partitioning virtual machines. &#8220;You need to mediate separation and make sure they don&#8217;t interact with each other,&#8221; he says.</p>
<p>Chris Barber, CIO at Wescorp, says he is concerned about multitenancy and hypervisor vulnerabilities. &#8220;Since you have multiple users on a single physical box, there may be a security vulnerability that one user could somehow access another user&#8217;s virtual machine,&#8221; he says.</p>
<p><a href="http://www.csoonline.com/article/596819/cloud-security-the-basics">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;n=Cloud+security%3A+The+basics&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/cloud-security-the-basics/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;t=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics&amp;srcUrl=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;srcTitle=Cloud+security%3A+The+basics&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cloud%20security%3A%20The%20basics%22&amp;body=Link: http://www.uncompiled.com/2010/06/cloud-security-the-basics/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;t=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;title=Cloud+security%3A+The+basics" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/cloud-security-the-basics/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cloud+security%3A+The+basics+-+http://b2l.me/3w364&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/cloud-security-the-basics/&amp;submitHeadline=Cloud+security%3A+The+basics&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Cloud+security%3A+The+basics&amp;body=Link: http://www.uncompiled.com/2010/06/cloud-security-the-basics/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/cloud-security-the-basics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentagon probed 6 million times daily</title>
		<link>http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/</link>
		<comments>http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 13:39:31 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cyber Warfare]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Military]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1285</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Unauthorized users penetrate Pentagon networks over six million times a day, says the head of the US Cyber Command, urging US military to guard against cyber attacks. </p>
<p>General Keith Alexander cautioned that Pentagon systems are &#8220;probed by unauthorized users approximately 250,000 times an hour, over six million times a day.&#8221; The remarks by Alexander, who is also at the helm of the main US spy organizations, the National Security Agency, was made in a Thursday address to a major Washington policy think tank, the Center for Strategic and International Studies. </p>
<p>&#8220;Our nation&#8217;s interests are in jeopardy,&#8221; he said citing &#8220;tremendous vulnerabilities&#8221; and threats from a &#8220;growing array of foreign actors, terrorists, criminal groups and individual hackers.&#8221; </p>
<p>Alexander emphasized that his main priority was to develop a real time picture of threats to US military networks and devising rules to fight back by conducting cyber attacks against enemies. </p>
<p>Alexander said that US military &#8220;depends on its networks for command and control, communications, intelligence, operations and logistics.&#8221; </p>
<p>&#8220;We at the Department of Defense have more than seven million machines to protect linked-in 15,000 networks,&#8221; he noted.</p>
<p><a href="http://www.presstv.ir/detail.aspx?id=129399&#038;sectionid=3510203">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;n=Pentagon+probed+6+million+times+daily&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;t=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily&amp;srcUrl=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;srcTitle=Pentagon+probed+6+million+times+daily&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Pentagon%20probed%206%20million%20times%20daily%22&amp;body=Link: http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;t=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;title=Pentagon+probed+6+million+times+daily" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Pentagon+probed+6+million+times+daily+-+http://b2l.me/z6be9&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/&amp;submitHeadline=Pentagon+probed+6+million+times+daily&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Pentagon+probed+6+million+times+daily&amp;body=Link: http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/pentagon-probed-6-million-times-daily/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT pros are hacking their own enterprises to keep intruders out</title>
		<link>http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/</link>
		<comments>http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 13:45:57 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1234</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>A survey of IT security professionals has discovered that 83% consider commercial applications, the ones you buy off the shelf, to be riddled with code flaws and vulnerabilities.</p>
<p>Fortify Software found that 56% believe these flaws could allow hackers to exploit these software vulnerabilities. As a result, security professionals are making heavy investments in penetration and code testing, combined with application scanning, to try and build security into the software.</p>
<p>Half of the IT security professionals also admitted to hacking, with 73% of these respondents doing so to test the strength of their own network’s defenses, 13% for fun or out of curiosity, and 3% targeting their efforts at the competition.</p>
<p>Compiled at Infosecurity Europe, the survey also unearthed that, amongst the 300 IT security professionals interviewed (with the majority taken from companies employing 1,000 plus employees), 31% admitted to being victims of hacking. More interestingly, with 29% replying ‘don’t know’, this figure could be substantially higher! The majority of respondents cited the application layer to be the hackers’ main target.</p>
<p>57% of the IT security profession also confer that the best way to check that their software applications are free of vulnerabilities and secure is to combine all available techniques and solutions, including code and static analysis, web application firewalls, application scanners and pen testing. Only 5% of the survey respondents we spoke to said their organizations didn’t employ technology for software security.</p>
<p>Of those in this survey that admitted to previous hacking knowledge and experience, 42% learnt in their twenties and 14% in their teens. Most people learnt to hack at work &#8212; 29%; on the Internet, 26%; at University, 13%; and 8% gained their hacking skills whilst still at school and 8% used friends to help them hone their talent.</p>
<p><a href="http://www.net-security.org/secworld.php?id=9358">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;n=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;t=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;srcUrl=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;srcTitle=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22IT%20pros%20are%20hacking%20their%20own%20enterprises%20to%20keep%20intruders%20out%22&amp;body=Link: http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;t=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;title=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out+-+http://b2l.me/ymeb7&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/&amp;submitHeadline=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=IT+pros+are+hacking+their+own+enterprises+to+keep+intruders+out&amp;body=Link: http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/it-pros-are-hacking-their-own-enterprises-to-keep-intruders-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fraud Bazaar Carders.cc Hacked</title>
		<link>http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/</link>
		<comments>http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/#comments</comments>
		<pubDate>Wed, 19 May 2010 14:15:42 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Financial]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1191</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Carders.cc, a German online forum dedicated to helping criminals trade and sell financial data stolen through hacking, has itself been hacked. The once-guarded contents of its servers are now being traded on public file-sharing networks, leading to the exposure of potentially identifying information on the forum’s users as well as countless passwords and credit card accounts swiped from unsuspecting victims.</p>
<p>The breach involves at least three separate files being traded on Rapidshare.com: The largest is a database file containing what appear to be all of the communications among nearly 5,000 Carders.cc forum members, including the contents of private, one-to-one messages that subscribers to these forums typically use to negotiate the sale of stolen goods. Another file includes the user names, e-mail addresses and in many cases the passwords of Carder.cc forum users.</p>
<p>A third file — which includes what appear to be Internet addresses assigned to the various Carders.cc users when those users first signed up as members — also features a breezy explanation of how the forum was compromised. The top portion of this file — which is accompanied by an ASCII art picture of a cat — includes an oblique reference to the party apparently responsible for the Carders.cc site compromise, noting that the file is the inaugural issue of Owned and Exposed, no doubt the first of many such “e-zines” to come from this group.</p>
<p>Ironically, the anonymous authors of the e-zine said they were able to compromise the criminal forum because its operators had been sloppy with security. Specifically, they claimed, the curators of Carders.cc had set insecure filesystem permissions on the Web server, which essentially turned what might have been a minor site break-in into a total database compromise. </p>
<p><a href="http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;n=Fraud+Bazaar+Carders.cc+Hacked&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;t=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked&amp;srcUrl=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;srcTitle=Fraud+Bazaar+Carders.cc+Hacked&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Fraud%20Bazaar%20Carders.cc%20Hacked%22&amp;body=Link: http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;t=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;title=Fraud+Bazaar+Carders.cc+Hacked" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Fraud+Bazaar+Carders.cc+Hacked+-+http://b2l.me/vg56f&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/&amp;submitHeadline=Fraud+Bazaar+Carders.cc+Hacked&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Fraud+Bazaar+Carders.cc+Hacked&amp;body=Link: http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/05/fraud-bazaar-carders-cc-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cops add image-matching to anti-paedophile arsenal</title>
		<link>http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/</link>
		<comments>http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/#comments</comments>
		<pubDate>Wed, 12 May 2010 14:04:55 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1154</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Police across Australia will crack down on child pornography with an image matching platform in development in Queensland that is set to go national at the end of the year.</p>
<p>The system will identify and match hundreds of thousands of child abuse images located on suspects&#8217; hard drives and stored in the Australian National Victim Image Library (ANVIL), and tie them to solved and cold cases.</p>
<p>Government technology agency Crimtrac estimates 20,000 new child exploitation images appear on the Internet each week through some 100,000 websites, paid portals and peer-to-peer sites. About 100,000 of the 500,000 images estimated to be in circulation are original.</p>
<p>State police agencies have no way of knowing if a seized image is original, or is part of a solved, open or cold case in another state.</p>
<p>Queensland Detective Senior Sergeant, Wayne Steinhart, said the system will image-match to determine if a suspect has duplicate images, or is involved in new acts of child abuse.</p>
<p>&#8220;Detectives spend hundreds of hours sifting through child abuse images to discover child exploitation on an offenders&#8217; computer &#8212; it could be 100,000 images which is overwhelming, but our role is to identify victims,&#8221; Stienhart said.</p>
<p>&#8220;We won&#8217;t know if suspects have committed new offences unless we have eyeballed each image.&#8221;</p>
<p>The Child Exploitation System (CETS) is under trial by the Queensland Police and the Australian Federal Police. It uses image recognition and hash functions to identify groups of images that involve the same victim in order to gather evidence for investigation.</p>
<p>&#8220;It&#8217;s not nice work&#8230; the system saves the operator from that work,&#8221; Steinhart said, adding the CETS and ANVIL will provide a complete system from &#8220;seizure to storage&#8221;.</p>
<p>The system was built in 2005 by Canadian police services and regional Microsoft developers for more than $11 million, and is used by 25 of the nation&#8217;s police forces. The United Kingdom, the US and Italy are some of the countries that use and share data from the CETS, and according to CrimTrac national manager of law enforcement systems, Stewart Cross, has led to the dismantling of &#8220;at least&#8221; three international paedophile rings.</p>
<p>Steinhart said online child exploitation material is distributed evenly between websites and peer-to-peer networks and said the government&#8217;s Internet content filter will help restrict access to child porn websites.</p>
<p>It is expected to go live in Queensland after the trial business case is presented to Australia&#8217;s police ministers at the Ministerial Council for Police and Emergency Management Police in July.</p>
<p>Steinhart said there is no substance to rumours that Microsoft had planned to pull support for CETS.</p>
<p><a href="http://www.networkworld.com/news/2010/051010-cops-add-image-matching-to-anti-paedophile.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;n=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;t=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;srcUrl=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;srcTitle=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cops%20add%20image-matching%20to%20anti-paedophile%20arsenal%22&amp;body=Link: http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;t=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;title=Cops+add+image-matching+to+anti-paedophile+arsenal" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cops+add+image-matching+to+anti-paedophile+arsenal+-+http://b2l.me/t4ngk&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/&amp;submitHeadline=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Cops+add+image-matching+to+anti-paedophile+arsenal&amp;body=Link: http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/05/cops-add-image-matching-to-anti-paedophile-arsenal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automated penetration testing tools</title>
		<link>http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/</link>
		<comments>http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 14:23:14 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1102</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Codenomicon released a toolkit for automated penetration testing which eliminates unnecessary ad-hoc manual testing. The required expertise is built into the tools making efficient penetration testing available for all. The new solution makes fuzzing an affordable solution for consultants.</p>
<p>When conducted manually, penetration testing requires substantial knowledge of the systems that are tested. Thus, most penetration testers only feel comfortable testing web applications. Codenomicon&#8217;s penetration testing solution utilizes a unique fuzz testing technique, which learns the tested system automatically enabling penetration testers to enter new domains such as VoIP assessment or to start testing industrial automation solutions and wireless technologies. Test automation increases the test coverage of penetration tests.</p>
<p>One of the key components of the penetration testing solution is the Network Analyzer, which enables you to map real network traffic and to determine what really needs to be tested. It automates the work-flow for threat analysis and attack surface analysis. Thus, you can target your tests and reduce test run times without compromising test coverage.</p>
<p>The penetration kit is an adjustable package with flexible project-based licensing, answering your changing penetration testing needs. The test suite package contains a combination of systematic model-based fuzzers, which best suit your current testing needs. In addition, the Defensics Traffic Capture and XML Fuzzers enable you to test any protocol or XML application.</p>
<p>&#8220;You don&#8217;t need to be an expert to use Codenomicon solutions such as Defensics fuzzers or our Network Analyzer&#8221; says Ari Takanen, CTO of Codenomicon. &#8220;But professional security testers will also benefit from our new tools. The tools quickly find around 95% of easy flaws allowing specialists to focus on vulnerabilities that are harder to find.&#8221;</p>
<p><a href="http://www.net-security.org/secworld.php?id=9199">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;n=Automated+penetration+testing+tools&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;t=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools&amp;srcUrl=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;srcTitle=Automated+penetration+testing+tools&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Automated%20penetration%20testing%20tools%22&amp;body=Link: http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;t=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;title=Automated+penetration+testing+tools" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Automated+penetration+testing+tools+-+http://b2l.me/rjrm7&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/&amp;submitHeadline=Automated+penetration+testing+tools&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Automated+penetration+testing+tools&amp;body=Link: http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/automated-penetration-testing-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A New Law Could Change the Way You Build Database Applications</title>
		<link>http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/</link>
		<comments>http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/#comments</comments>
		<pubDate>Sun, 25 Apr 2010 19:07:57 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1089</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Massachusetts recently passed a sweeping new data security law that will have a profound impact on the way the United States, and perhaps the rest of the world, manages and develops data-centric applications. Oddly, most people in the business don’t seem to know about it.</p>
<p>Google “Massachusetts data security law, 201 CMR 17.00” and you’ll find plenty of facts about the new law. I also encourage you to read InformationWeek’s &#8220;States&#8217; Rights Come to Security Forefront: Massachusetts&#8217; new data protection law reaches beyond its borders. Are you ready?&#8221; It’s one of the best summaries I’ve seen. But even it falls short of helping you understand the profound impact of this law. </p>
<p>Here are the basics of the new law. If you have personally identifiable information (PII) about a Massachusetts resident, such as a first and last name, then you have to encrypt that data on the wire and as it’s persisted. Sending PII over HTTP instead of HTTPS? That’s a big no no. Storing the name of a customer in SQL Server without the data being encrypted?  No way, Jose. You’ll get a fine of $5,000 per breach or lost record. If you have a database that contains 1,000 names of Massachusetts residents and lose it without the data being encrypted that’s $5,000,000. Yikes.</p>
<p>Perhaps just as much fun is the fact that to be compliant with the law your company will also need to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts. The WISP must address and outline your business’s “technical, administrative, and physical safeguards” that are in place to protect the data. If you lost a laptop without a WISP being filed with Massachusetts, you’re potentially on the hook for a cool million even if the data was encrypted. Yikes again.</p>
<p>If I didn’t know better, I’d think the security czar of Massachusetts (or whatever the title is of the person who wrote this law) was a SQL Server sales executive because the law could sell a heck of a lot of SQL Server 2008 Enterprise Edition upgrades to get Transparent Data Encryption and other useful Enterprise Edition–only features in the OS and database stack. </p>
<p>By the way, this law doesn’t affect just businesses in MA. It also affects businesses that have PII for Massachusetts residents. Do you know if the application you’re building for a company in Virginia might ever store Massachusetts resident data? Unless you’re sure that it never, ever will, you better be compliant with Massachusetts data security law, 201 CMR 17.00. What if you’re sure and then one of your employees moves from Virginia to Massachusetts? Well, now you probably have PII for a MA resident. Yikes again. This law changes pretty much everything we need to do and think about with respect to building database applications. </p>
<p>I could wax eloquently on about the potential battle of states’ rights versus federal oversight and the potential for a Supreme Court challenge based on the Commerce Clause, but, this is an article for geeks, so I won’t go there. Instead, I’ll simply say once again: yikes. </p>
<p><a href="http://www.sqlmag.com/print/sql-server/A-New-Law-that-Will-Change-the-Way-You-Build-Database-Applications.aspx">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;n=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;t=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;srcUrl=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;srcTitle=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22A%20New%20Law%20Could%20Change%20the%20Way%20You%20Build%20Database%20Applications%22&amp;body=Link: http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;t=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;title=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications+-+http://b2l.me/q8txp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/&amp;submitHeadline=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=A+New+Law+Could+Change+the+Way+You+Build+Database+Applications&amp;body=Link: http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/a-new-law-could-change-the-way-you-build-database-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top U.S. domain name registrars lag on DNS security</title>
		<link>http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/</link>
		<comments>http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 17:52:57 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=927</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The leading domain name registrars in the United States appear to be dragging their feet on the deployment of DNS Security Extensions, an emerging standard that prevents an insidious type of hacking attack where network traffic is redirected from a legitimate Web site to a fake one without the Web site operator or user knowing.</p>
<p>DNSSEC prevents cache poisoning attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption. Cache poisoning attacks are possible because of a serious flaw in the DNS that was disclosed by security researcher Dan Kaminsky in 2008. </p>
<p>In order for Web site operators and end users to benefit from DNSSEC, the standard must be supported at every level of the DNS heirarchy. </p>
<p>At the top of this heirarchy, the DNS root servers will support DNSSEC on July 1.</p>
<p>Next are the registries that operate the back-end servers for the various top-level domains. The registries have announced rolling deadlines for their DNSSEC deployments: .org and .edu in June; .net in December; and .com by March 2011.<br />
However, none of the top 10 domain name registrars in the United States has committed to a deadline for deploying DNSSEC.</p>
<p>&#8220;It&#8217;s sad that the registrars are not keeping up with the registries in their deployment schedules for DNSSEC,&#8221; says Paul Hoffman, director of the VPN Consortium and an active participant in DNSSEC standards development at the Internet Engineering Task Force. &#8220;If my registrar can&#8217;t tell me when they will support DNSSEC, then I can&#8217;t do the planning I need to do to upgrade my DNS software.&#8221;</p>
<p>U.S. corporations &#8212; such as banks and e-retailers &#8212; won&#8217;t be able to deploy the extra layer of security provided by DNSSEC until their registrars offer it as a service.</p>
<p>&#8220;It is a roadblock,&#8221; Hoffman says. &#8220;If my registrar doesn&#8217;t know how do to DNSSEC, I have to change registrars…Whichever registrar announces first is going to see people switching to them.&#8221;</p>
<p>Of the 10 largest domain name registrars in the United States, only four responded to queries about the status of their DNSSEC deployments. None of these registrars would commit to a deadline for when they will support this new security mechanism.</p>
<p>Network Solutions and Dotster appear to be furthest along with DNSSEC.</p>
<p>&#8220;We are supportive of the DNSSEC initiative and recognize its technical importance and its efficiency in securing directory data,&#8221; sais Network Solutions spokeswoman Susan Wade. &#8220;We are working closely with the registries and are actively engaged in market research to determine the demand for DNS Security. At the present time, we do not have a launch date for our DNSSEC offering.&#8221;</p>
<p>&#8220;Dotster is working with a number of registries to implement DNSSEC,&#8221; said Dotster&#8217;s IT Director Aaron Bathum. &#8220;This is on our product road map, and availability is currently under review.&#8221;</p>
<p>Go Daddy, the largest domain name registrar in the United States, was vague about its DNSSEC plans. </p>
<p><a href="http://www.networkworld.com/news/2010/032310-domain-name-registars-lagging.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;n=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;t=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;srcUrl=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;srcTitle=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Top%20U.S.%20domain%20name%20registrars%20lag%20on%20DNS%20security%22&amp;body=Link: http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;t=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;title=Top+U.S.+domain+name+registrars+lag+on+DNS+security" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Top+U.S.+domain+name+registrars+lag+on+DNS+security+-+http://b2l.me/kykj9&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/&amp;submitHeadline=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Top+U.S.+domain+name+registrars+lag+on+DNS+security&amp;body=Link: http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/top-u-s-domain-name-registrars-lag-on-dns-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spain arrests three accused of running huge botnet</title>
		<link>http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/</link>
		<comments>http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 16:52:03 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Fighting Back]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=837</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Authorities in Spain have arrested three men accused of operating a massive botnet composed of 12.7 million PCs that stole credit card and bank log-in data and infected computers in half of the Fortune 1,000 companies and more than 40 banks, according to published reports.</p>
<p>The botnet &#8220;Mariposa,&#8221; which means butterfly in Spanish, first appeared in December 2008 and grew to be one of the largest botnets ever, The Associated Press reported. It spread the Butterfly worm via removable drives, MSN Messenger, and peer-to-peer programs and targets Windows XP and older systems.</p>
<p>Unlike many underground hackers, the alleged ringleaders of the operation were not skilled programmers, but had contacts who were, authorities said.</p>
<p>&#8220;They&#8217;re not like these people from the Russian mafia or Eastern European mafia who like to have sports cars and good watches and good suits&#8211;the most frightening thing is they are normal people who are earning a lot of money with cybercrime,&#8221; Cesar Lorenza, a captain with Spain&#8217;s Guardia Civil, which is investigating the case, told the news service.</p>
<p>In Spain, names and mug shots of arrested citizens are not released to protect their privacy, though they were identified by their Internet aliases: &#8220;netkairo,&#8221; 31; &#8220;jonyloleante,&#8221; 30; and &#8220;ostiator,&#8221; 25. They face up to six years in prison if convicted of the hacking charges.</p>
<p>More arrests are expected, authorities said. The botnet is no longer operating, according to the AP report.</p>
<p><a href="http://news.cnet.com/8301-27080_3-10462718-245.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;n=Spain+arrests+three+accused+of+running+huge+botnet&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;t=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet&amp;srcUrl=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;srcTitle=Spain+arrests+three+accused+of+running+huge+botnet&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Spain%20arrests%20three%20accused%20of%20running%20huge%20botnet%22&amp;body=Link: http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;t=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;title=Spain+arrests+three+accused+of+running+huge+botnet" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Spain+arrests+three+accused+of+running+huge+botnet+-+http://b2l.me/hxtg9&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/&amp;submitHeadline=Spain+arrests+three+accused+of+running+huge+botnet&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Spain+arrests+three+accused+of+running+huge+botnet&amp;body=Link: http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/spain-arrests-three-accused-of-running-huge-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
