<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Andre Yee&apos;s Security Insider</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/" />
    <link rel="self" type="application/atom+xml" href="http://www.ebizq.net/blogs/security_insider/atom.xml" />
    <id>tag:www.ebizq.net,2008-11-06:/blogs/security_insider//16</id>
    <updated>2008-11-20T08:19:22Z</updated>
    <subtitle>An open dialogue about security and compliance for the enterprise.</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Pro 4.21-en</generator>

<entry>
    <title>Eleven Indicted in Biggest Identity Theft Case</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2008/08/eleven_indicted_in_biggest_ide.php" />
    <id>tag:www.ebizq.net,2008:/blogs/temp_security_insider//16.10816</id>

    <published>2008-08-06T03:33:23Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>The Department of Justice handed out 11 indictments in what is believed to be the biggest identity theft hacking case. Allegedly, this eclectic group of Americans, Ukrainians, Estonians and Chinese were involved in stealing more than 40 million credit card...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Privacy/Information Theft" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p><a href="http://www.networkworld.com/community/node/30741">The Department of Justice handed out 11 indictments i</a>n what is believed to be the biggest identity theft hacking case.   Allegedly, this eclectic group of Americans, Ukrainians, Estonians and Chinese were involved in stealing more than 40 million credit card numbers by hacking into wireless networks of retailers such as <a href="http://www.usatoday.com/money/2007-06-11-tjx-data-theft_N.htm">TJX</a>, <a href="http://www.usatoday.com/tech/news/computersecurity/2004-07-06-idtheft_x.htm">BJ's Warehouse</a>, OfficeMax, <a href="http://seclists.org/isn/2005/Apr/0082.html">DSW </a>and Forever21.   The credit info was then sold in Eastern European and US black markets.  The total loss is currently unknown - in fact, you might be a victim and not know it.</p>

<p>If you even wonder if <a href="http://en.wikipedia.org/wiki/Wardriving">wardriving</a> is something that you should be concerned about, this case should cure you of such misconception.    These guys did nothing more than drive around looking for an open wireless access point, attached and used a sniffer to capture account info, passwords and credit card numbers flowing unencrypted across the wireless network.    It was so easy, you could have done it!</p>

<p>My question is - what kind of culpability is incurred by the retailers?  Aren't they at least responsible to take reasonable steps to protect consumer privacy info?   Was the wireless network even encrypted?  Should the retailers be held legally liable?  </p>

<p>Somehow, saying we're sorry just doesn't seem enough.</p>]]>
        
    </content>
</entry>

<entry>
    <title>United States Overtakes China in Infected Websites</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2008/05/united_states_overtakes_china.php" />
    <id>tag:www.ebizq.net,2008:/blogs/temp_security_insider//16.10815</id>

    <published>2008-05-05T03:39:25Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>In a recent report from Sophos, it appears that the US has overtaken China as the country hosting the most infected websites. If you believe the report, the growth of US-based infected websites has been phenomenal - from approximately 25%...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Industry Trends" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>In a recent report from Sophos, it appears that the US has overtaken China as the country hosting the most infected websites.   If you believe the report, the growth of US-based infected websites has been phenomenal - from approximately 25% in 2007 to about 50% in the first 3 months of 2008.  Part of the reason for the dubious distinction of holding top spot is that China is making progress in cleaning up its infected sites.  </p>

<p>Another interesting trend in the report is the drop of infected emails - only one infected email in over 2500 compared to one in 909 in 2007.    This coincides with the increase in infected websites where one infected webpage is discovered and blocked every 5 sec in 2008 compared with 14 sec in 2007.</p>

<p><a href="http://www.sophos.com/sophos/docs/eng/marketing_material/sophos-threat-report-Q108.pdf">Download the report here</a> if you're interested.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Beware the Tax Scamming Emails</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2008/04/beware_the_tax_scamming_emails.php" />
    <id>tag:www.ebizq.net,2008:/blogs/temp_security_insider//16.10814</id>

    <published>2008-04-08T04:07:03Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>It&apos;s tax season and if that&apos;s not enough to get you down, here&apos;s something to get your attention. A slew of scam emails are circulating, purporting to be from the IRS. These emails are targeted to companies and seek additional...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Alerts/Warnings" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>It's tax season and if that's not enough to get you down, here's something to get your attention.  A slew of scam emails are circulating, purporting to be from the IRS.   These emails are targeted to companies and seek additional tax related information. </p>

<p>This warning comes to us from Sunbelt Software, whose CFO received one of the scam emails.  The emails are realistic, carrying a certain believability.  A screensaver file disguised as a tax refund PDF file (tax_refund_scr) is attached to the email.   When the user clicked, a PDF file seems to appear but unknown to the user, malware is also downloaded to steal financial and confidential data.</p>

<p>Check it out <a href="http://sunbeltblog.blogspot.com/2008/04/heads-up-dangerous-new-customized-irs.html">here at the Sunbelt Software Blog</a>.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Airport Security &amp; Macbook Air</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2008/03/airport_security_macbook_air.php" />
    <id>tag:www.ebizq.net,2008:/blogs/temp_security_insider//16.10813</id>

    <published>2008-03-31T03:54:35Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>Going through airport security? You might want to be prepared for a few extra questions and a little longer inspection if you own the ultra-thin MacBook Air. Apparently, it&apos;s unusual physical dimensions is something that TSA inspectors might be unaccustom...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Odds and Ends" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>Going through airport security?  You might want to be prepared for a few extra questions and a little longer inspection if you own the ultra-thin MacBook Air.  Apparently, it's unusual physical dimensions is something that TSA inspectors might be unaccustom to.  Further, when it's run through the scan, it doesn't look quite the same as many other laptops perhaps due to solid state drives and other cutting edge upgrades.</p>

<p>Bob, TSA employee since 2002, explains this on the <a href="http://www.tsa.gov/blog/2008/03/update-bob-screens-apple-macbook-air.html">Evolution of Security blog</a>.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Privacy Problems with Social Networks</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/12/privacy_problems_with_social_n.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10812</id>

    <published>2007-12-04T17:40:20Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>Social networks like Facebook and MySpace continue to face security and privacy related issues as functional capabilities expand amd social interactions within the community become more complex.. Here are a couple of examples. First up, Facebook. It recently acknowledge that...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Odds and Ends" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Privacy/Information Theft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="web 2.0" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>Social networks like Facebook and MySpace continue to face security and privacy related issues as functional capabilities expand amd social interactions within the community become more complex..   Here are a couple of examples.</p>

<p>First up, Facebook.  It recently acknowledge that a new functional capability called Beacon continues to track user activity long after users have logged off the site and even when users have elected to not display their activities to Facebook friends.  Beacon is part of the Facebook Ads platform that tracks user acitivities on Facebook partner sites like Blockbuster and reports those activities to the "friends" of the Facebook account.   Account holders may choose to not have those activities reported but it appears that even in that case, the activities are tracked and stored in some Facebook database.  As you can imagine, privacy advocates are up in arms.  You can read <a href="http://www.infoworld.com/article/07/12/03/Facebook-admits-Beacon-tracks-logged-off-users_1.html">more about this case</a>, if you're interested.</p>

<p>You can assume that these privacy issues will not go away and will continue to plaque Facebook and other social networks.  Sometimes, problems are less about guarding privacy but rather the abuse of trust within the social network.  Here's a <a href="http://www.nytimes.com/2007/11/28/us/28hoax.html?_r=1&em&ex=1196398800&en=b1408a7356b77eef&ei=5087%0A&oref=slogin">chilling story </a>about how a MySpace teen took her own life because of a cruel prank perpetrated by adult neighbors.  </p>

<p>Perhaps the issue is that both the guarding of privacy and the protection of social network subscribers may be at odds with each other.  To some extent, that's how it works in real life...we yield some privacy to trusted authorities - banks, hospitals, law enforcement, the state...to gain protective services of some kind or another.  </p>

<p>However, striking this balance works in the cyberworld may not be so easy.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Implications of Salesforce Phishing Incident</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/11/implications_of_salesforce_phi.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10811</id>

    <published>2007-11-20T23:59:33Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>The news about Salesforce.com&apos;s phishing incident broke almost 2 weeks ago on Slashdot...although there were rumors swirling about for a number of days prior to the report. A Salesforce employee fell victim to a phishing attack that captured his company...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Industry Trends" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Privacy/Information Theft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="web 2.0" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>The news about Salesforce.com's <a href="http://it.slashdot.org/article.pl?sid=07/11/06/216228&from=rss">phishing incident broke almost 2 weeks ago on Slashdot</a>...although there were rumors swirling about for a number of days prior to the report.    A Salesforce employee fell victim to a phishing attack that captured his company credentials.  The attackers used those credentials to harvest customer contact data and began to send phishing attacks to customers, in the form of fake Salesforce invoices.   As you might expect some number of customers fell for the scam and yielded their Salesforce account info.</p>

<p>There are a few interesting implications of this phishing attack, none of which pertain specifically to what Salesforce should or could have done.  </p>

<p>Implication #1 - this kind of targeted phishing or "spear phishing" is difficult to monitor and eliminate.   When a specific target is singled out, the attack tends to proceed undetected for a while before it becomes evident.  No specific remedies or signatures are available to address them.</p>

<p>Implication #2 - until now, most highly phishing attacks have been targeted at financial institutions and consumers.  Relatively recent examples include the <a href="http://www.antiphishing.org/phishing_archive/04-19-05_BOA/04-19-05_BOA.html">Bank of America "change of email" scam</a> and <a href="http://www.reuters.com/article/fundsFundsNews/idUSWNAS412220070914">ADP.</a>  <br />
Not surprisingly, SaaS providers may now be next on the list.  Although, the value of the information to scammers may not be apparent, it is likely that phishing attacks against SaaS applications that hold identity and proprietary info will be on the rise.  </p>

<p>Implication #3 - phishing is only the starting point for the attack.  In the Salesforce incident, it was uncovered that some of the customers who were effectively phished, also had keyloggers and other malware downloaded onto their machines.  From the Salesforce letter sent to customers -</p>

<p><em>"...As a result of this, a small number of our customers began receiving bogus emails that looked like salesforce.com invoices, but were not--they were also phishes. Unfortunately, a very small number of our customers who were contacted had end users that revealed their passwords to the phisher... However, a few days ago a new wave of phishing attempts that included attached malware--software that secretly installs viruses or key loggers--appeared and seemed to be targeted at a broader group of customers."</em></p>

<p>Not a lot of good news there.  The point is that in this new Web 2.0, Saas enabled world, there is a <a href="http://en.wikipedia.org/wiki/The_Long_Tail">Long Tail </a>to this phishing problem...targeted, sophisticated attacks cannot be tackled by simply preaching "security awareness".  Nor it is enough to use signature based phishing detection techniques.  We need a different approach.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Electronic Jihad?</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/11/electronic_jihad.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10810</id>

    <published>2007-11-10T03:20:03Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>Apparently, two weeks ago, the Al Qaeda summoned an &quot;Electronic Jihad&quot; to commence on Nov 11. In a special Internet announcement in Arabic, picked up DEBKAfileâ€™s counter-terror sources, Osama bin Ladenâ€™s followers announced Monday, Oct. 29, the launching of Electronic...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Alerts/Warnings" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>Apparently, two weeks ago, the Al Qaeda summoned an "Electronic Jihad" to commence on Nov 11.  </p>

<p><em> In a special Internet announcement in Arabic, picked up DEBKAfileâ€™s counter-terror sources, Osama bin Ladenâ€™s followers announced Monday, Oct. 29, the launching of Electronic Jihad. On Sunday, Nov. 11, al Qaedaâ€™s electronic experts will start attacking Western, Jewish, Israeli, Muslim apostate and Shiite Web sites. On Day One, they will test their skills against 15 targeted sites expand the operation from day to day thereafter until hundreds of thousands of Islamist hackers are in action against untold numbers of anti-Muslim sites.</em></p>

<p>Can you say - "bring it on"?  Nah...  I don't know if this is legit but either way, I don't anticipate it'll actually register with anyone.</p>

<p>If you're interested, read the entire <a href="http://www.debka.com/headline.php?hid=4723">Debka.com report here</a>.</p>

<p>(HT: <a href="http://www.schneier.com/blog/">Bruce Schneier</a>)</p>]]>
        
    </content>
</entry>

<entry>
    <title>Top 10 Most Vulnerable Apps for 2007</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/11/top_10_most_vulnerable_apps_fo.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10809</id>

    <published>2007-11-06T02:18:54Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>As a software vendor, it must be the software equivalent of finding yourself on Hollywood&apos;s &quot;worst dressed&quot; list. Here are the top 10 most vulnerable apps in 2007 published by Bit9, an endpoint security company. 1. Yahoo! Messenger 8.1.0.239 and...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>As a software vendor, it must be the software equivalent of finding yourself on Hollywood's "worst dressed" list.  Here are the <a href="http://web.bit9.com/home/tabid/15398/bid/2568/The-Top-10-Most-Vulnerable-Applications-for-2007.aspx">top 10 most vulnerable apps in 2007 </a>published by Bit9, an endpoint security company.  </p>

<p>   1. Yahoo! Messenger 8.1.0.239 and earlier<br />
   2. Apple QuickTime 7.2<br />
   3. Mozilla Firefox 2.0.0.6<br />
   4. Microsoft Windows Live (MSN) Messenger 7.0, 8.0<br />
   5. EMC VMware Player (and other products) 2.0, 1.0.4<br />
   6. Apple iTunes 7.3.2<br />
   7. Intuit QuickBooks Online Edition 9 and earlier<br />
   8. Sun Java Runtime 1.6.0_X<br />
   9. Yahoo! Widgets 4.0.5 and previous<br />
  10. Ask.com Toolbar 4.0.2.53 and previous</p>

<p>Among the qualifying criteria is that it must be able to run on Microsoft Windows platform and be a well known consumer application, downloaded by individuals.  </p>

<p>It's interesting to note that Yahoo (Messenger, Widgets) and Apple (Quicktime, iTunes) related software each appears twice while Microsoft, with its extensive scope and distribution of software is only represented by MSN Messenger. Go figure.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Adobe Fixes Vulnerability But Problems Persist in the Wild</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/10/adobe_fixes_vulnerability_but.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10808</id>

    <published>2007-10-25T01:32:54Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>On Monday, Adobe released a patch a vulnerability in its Adobe Reader software (v 8.1 or earlier, v. 7.0.9 or earlier) exposed by U.K.-based researcher Petko Petkov. The vulnerability makes it possible for the spread of malicious PDF files resulting...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Alerts/Warnings" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>On Monday, Adobe released a patch a vulnerability in its Adobe Reader software (v 8.1 or earlier, v. 7.0.9 or earlier) exposed by U.K.-based researcher Petko Petkov.   The vulnerability makes it possible for the spread of malicious PDF files resulting in Windows machines being taken over, security controls disabled and additional malware files downloaded.</p>

<p>Although the patch was issued on Monday, problems persist in the wild, since many users don't remember to update their Adobe reader software regularly (guilty as charged!).  Symantec has identified the threat as Trojan.Pidief.A. The rogue PDF document is attached to spammed e-mail, and arrives with a filename such as YOUR_BILL.pdf or INVOICE.pdf, said Symantec.</p>

<p>Here are few suggestions by Symantec to protect yourself</p>

<p>- Apply the Adobe issued patches<br />
- Block the delivery of PDF files in email.<br />
- Issue advisory to employees to avoid reading or executing PDF files from unknown or untrusted sources.<br />
- Block access to the network and IP address involved in this attack.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Ann Coulter Hacked</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/10/ann_coulter_hacked_1.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10807</id>

    <published>2007-10-17T12:29:25Z</published>
    <updated>2009-03-27T09:29:09Z</updated>

    <summary>First, it was Paris Hilton&apos;s cell phone. Then some mischievious hacker compromised Carrie Underwood&apos;s MySpace account. Now Ann Coulter, the controversial conservative talking head, joins a growing list of celebrities, including Madonna who have been &quot;victimized&quot; by hackers. Apparently, hackers...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Odds and Ends" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>First, it was <a href="http://www.news.com/Paris-Hiltons-cell-phone-hacked/2100-7349_3-5584691.html">Paris Hilton's cell phone</a>.  Then some mischievious hacker compromised <a href="http://www.tmz.com/2007/06/05/carrie-underwood-hacked/">Carrie Underwood's MySpace account</a>.  Now Ann Coulter, the controversial conservative talking head, joins a growing list of celebrities, including <a href="http://www.mtv.com/news/articles/1471471/04232003/madonna.jhtml">Madonna </a>who have been "victimized" by hackers.</p>

<p>Apparently, hackers have cracked Ann Coulter's website and posted a fake message offering apologies for her recent comments and announcing her retirement as media talking head.  Here's the fake message -</p>

<blockquote><em>An Open Letter to Readers
by Ann Coulter
October 15, 2007

<p>Dear Readers,</p>

<p>I've been participating in a charade for nearly eleven years, now. Quite frankly, I'm sick of it. You have all been a part of a sick joke that I began considering shortly after first getting on the air. At first, it was quite interesting to see how people would react when I would use twisted logic and poorly masked bigotry.</p>

<p>But eleven years is a long time to be living a fake life, and I can no longer tolerate this falsity. Even someone as fake as I tires out eventually.</p>

<p>Here's the truth, I don't care what people believe. Jews don't need to be "made perfect" as I so arrogantly proclaimed to Editor & Publisher not a half week ago. I don't even care if people are Muslim. Granted, I don't know much about the religion or the people, but they are people. This is something that we cannot forget, they are in an abhorrent situation. These people are in need of education. Perhaps if we did not participate in causing them misery, they would not hate us so.</p>

<p>In fact, does it really matter whether we are Christian, Jewish, Muslim, Atheist, or even Pagan? We are one nation. One. We should not let petty differences separate us, we are all American, and should act in that manner.</p>

<p>And with that, my precious viewers, I bid you adieu. My career as a media figurehead is over.</p>

<p>Signed,</p>

<p>Ann Coulter</p>

<p>P.S. - Oh, and Bill O'Reilly is also just acting.</p>

<p>[From the hackers:] Haha, did it again. Oh, those silly web admins...they just embarrass themselves.</p>

<p>(Admins, check for an e-mail address in the CMS. Find it. I know you will.)</em></blockquote></p>

<p>It's tough being a celebrity these days.  Never mind the paparazzi, now hackers are out to get you.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Social Networking Versus Corporate Security</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/10/social_networking_versus_corpo.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10806</id>

    <published>2007-10-12T02:56:08Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>On the hype scale, social networking is red hot! Facebook, MySpace, Linkedin are all examples of the force multiplying, networking effect of Web 2.0. Yet as Peter Schoof reported last week, there is healthy debate on whether these sites should...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="web 2.0" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>On the hype scale, social networking is red hot!  Facebook, MySpace, Linkedin are all examples of the force multiplying, networking effect of Web 2.0.  Yet as <a href="http://www.ebizq.net/blogs/news_security/2007/10/should_companies_ban_web_20_to.php">Peter Schoof reported last week</a>, there is healthy debate on whether these sites should be permitted in the corporate environment.  </p>

<p>Social networking sites pose yet another security issue for security managers today, courtesy of the Web 2.0 model. While some of these social networking sites like Linkedin have distinct business applicability and value, other sites clearly emphasize the purely â€œsocialâ€? part of the equation.</p>

<p>Should security or IT managers even be concerned about whether employees are accessing these sites?  Here are couple of things to consider -</p>

<p>1. Social networking sites are increasingly targets for new exploits, especially cross-site scripting attacks. Like many Web 2.0 sites, social networking apps are ripe for client side attacks.   For instance, in November,2006,  a MySpace targeted CSS exploit replaced the navigation menu, enabling an attacker to redirect the user to a spoofed web page.</p>

<p>2. Social networking sites can be a platform to launch attacks.  Because social networking sites drive traffic, it can be an effective launch point for various attacks targeting other platforms or components.  Over a year ago,  an online banner advertisement running on MySpace used a Windows security flaw to infect more than a million users with spyware related to Windows Meta Files.  </p>

<p>3. Social networking sites can lead to compromise of privacy or proprietary information. What you do on a site is information that social networking apps control and could expose.   Case in point - last year, Facebook added a feature called News Feeds that exposed privacy and behavioral information about account users...without their explicit  consent.   The outrage from its users were expected and the problem was addressed but it's a clear lesson to all users.</p>

<p>4. Social networking sites may be costing businesses millions of $$$ in employee productivity.   According to recent studies, due to the result of social networking's overwheming popularity, many of these sites are becoming a source of loss productivity as employees spend time visiting these sites during work hours.   As reported in <a href="http://www.switched.com/2007/09/12/facebook-costing-businesses-264-million-daily-in-lost-man-hours/">this article,</a> a study commissioned by a UK law firm noted that Facebook is costing British firms 130 million pounds ($264M) in lost productivity every single day.    </p>

<p>Should companies be blocking social networking sites as a matter of practice?  Perhaps not.  But there's certainly ample reason to be concerned from a security perspective.</p>]]>
        
    </content>
</entry>

<entry>
    <title>How Web 2.0 is Challenging Corporate Security</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/10/how_web_20_is_challenging_corp.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10805</id>

    <published>2007-10-04T01:56:28Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>The emergence of Web 2.0 is one of the greatest challenges for corporate security managers today. One primary reason it poses such difficulty for the traditional security model is the unregulated way Web 2.0 applications are deployed and used in...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="web 2.0" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>The emergence of <a href="http://www.oreilly.com/pub/a/oreilly/tim/news/2005/09/30/what-is-web-20.html">Web 2.0</a> is one of the greatest challenges for corporate security managers today. One primary reason it poses such difficulty for the traditional security model is the unregulated way Web 2.0 applications are deployed and used in the corporate environment.  Itâ€™s what some have termed the â€œconsumerization of ITâ€? â€“ the trend of end-users employing web 2.0 tools/applications at home and then bringing those same tools into the corporate environment.   </p>

<p>Examples?  Instant messaging, Skype are just two peer-to-peer (P2P) technologies that have found traction in the consumer world but are increasingly used in the corporate environment.  More apps/tools are being used everyday without the awareness, much less consent of security managers. The reality is that most security organizations have little to no ability to limit or monitor its use and sometimes the implications to security can be staggering.  For instance, P2P file sharing tools like <a href="http://www.consumeraffairs.com/news04/2006/10/limewire.html">LimeWire </a> and <a href="http://www.ebizq.net/blogs/security_insider/2007/09/identity_data_leaked_from_mort.php">BearShare</a> have been implicated in a number of highly publicized security breaches where proprietary and privacy data has been compromised.</p>

<p>Needless to say, ignoring this web 2.0 problem wonâ€™t make it go away.  If anything, the notion of unregulated, unmonitored deployment of web 2.0 apps will only increase and so will the security issues surrounding its use.</p>

<p>Next post, how corporations deal with social networking sites...</p>]]>
        
    </content>
</entry>

<entry>
    <title>Identity Data Leaked from Mortgage Company</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/09/identity_data_leaked_from_mort.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10804</id>

    <published>2007-09-27T23:47:26Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>If you&apos;re one of millions of Americans with a mortgage, consider this - your mortgage company holds much of your privacy/identity info. Yet, have you ever wondered if your information is safe with them? According to this article, three spreadsheets...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Privacy/Information Theft" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>If you're one of millions of Americans with a mortgage, consider this - your mortgage company holds much of your privacy/identity info.  Yet, have you ever wondered if your information is safe with them?  </p>

<p>According to <a href="http://www.msnbc.msn.com/id/20912098/">this article</a>, three spreadsheets with social security numbers of over 5000 customers have been iinadvertantly leaked by a former employee of the ABN AMRO Mortgage Group.   The problem was traced to the use of a peer to peer (P2P) file sharing tool called <a href="http://www.bearshare.com/">BearShare</a>.  Here's an excerpt from the article explaining what happened - </p>

<blockquote><em>Tiversa Inc., a Pittsburgh company that offers data-leakage protection services, traced the origins of the ABN data to a Florida computer with the BearShare software installed..With such peer-to-peer sharing systems, files are obtained directly from another user's hard drive rather than a central hub like traditional Web sites. As a result, once a file begins to circulate, copies can sit on computers all over the world, ready to be grabbed by other users</em>.</blockquote>

<p>Although this data compromise was unintentional, P2P tools are increasingly becoming the weapon of choice in the arsenal of identity thieves.  Most companies are clueless about this threat...and unfortunately, some of these companies hold our privacy data</p>]]>
        
    </content>
</entry>

<entry>
    <title>Is the iPhone Secure Enough For You?</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/07/is_the_iphone_secure.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10803</id>

    <published>2007-07-25T21:45:14Z</published>
    <updated>2009-03-27T09:31:43Z</updated>

    <summary>Peter Schooff beat me to this post but... hey, it&apos;s summer and I&apos;m moving slow. Independent Security Evaluators, a security consulting group headed up by security expert Avi Rubin, reported on a number of iPhone vulnerabilities. Among the more serious...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="Alerts/Warnings" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p><a href="http://www.ebizq.net/blogs/news_security/2007/07/iphone_hacked_what_now.php">Peter Schooff  beat me to this post</a> but... hey, it's summer and I'm moving slow.  </p>

<p><a href="http://www.securityevaluators.com/">Independent Security Evaluators</a>, a security consulting group headed up by security expert Avi Rubin, reported on a number of iPhone vulnerabilities.  Among the more serious vulnerabilities that can be exploited may result in the following - </p>

<p>- Exploit may redirect placed phone calls to phone numbers designated by attacker.<br />
- Continuous loop of call attempts.  Turning off the phone is the only recourse<br />
- Tracking of personal info including calls placed by user.<br />
- Preventing phone from dialing out.<br />
    <br />
 You can read the <a href="http://www.securityevaluators.com/iphone/exploitingiphone.pdf">full report here</a>.</p>

<p>The commercials say "it's not just a version of the Internet...it's the Internet".  Well, now we know it comes with vulnerabilities as well...just like the Internet experience we know and love.</p>]]>
        
    </content>
</entry>

<entry>
    <title>HP Acquires SPI Dynamics</title>
    <link rel="alternate" type="text/html" href="http://www.ebizq.net/blogs/security_insider/2007/06/hp_acquires_spi_dynamics.php" />
    <id>tag:www.ebizq.net,2007:/blogs/temp_security_insider//16.10802</id>

    <published>2007-06-25T17:40:39Z</published>
    <updated>2008-11-20T08:19:22Z</updated>

    <summary>I&apos;ve been on vacation so I missed this announcement when it came out. HP has not been particularly focused on security so this wasn&apos;t an acquisition that seemed obvious at first. However, according to HP, this acquisition is complementary to...</summary>
    <author>
        <name>Andre Yee</name>
        <uri>http://www.ebizq.net/MT4/mt-cp.cgi?__mode=view&amp;blog_id=16&amp;id=14</uri>
    </author>
    
        <category term="M&amp;A" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.ebizq.net/blogs/security_insider/">
        <![CDATA[<p>I've been on vacation so I missed this announcement when it came out.  HP has not been particularly focused on security so this wasn't an acquisition that seemed obvious at first.   However, according to HP, this acquisition is complementary to the business process optimization strateg since it adds "quality management services" to its technology portfolio.  This isn't exactly a leap in the dark for HP - they've been partners with SPI for the past 5 years and are very familiar with their products.</p>

<p>SPI Dynamics has been at the helm of web application security lifecycle tools for quite a while, carving out a leadership position in this niche.   Their products focus on detecting vulnerabilities and assessing security of web applications from development to deployment.  </p>

<p>This acquisition could signal an interest in market for application security assessment tools vendors .  Other smaller, less established players like Fortify are still out there to be had.</p>]]>
        
    </content>
</entry>

</feed>

