<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Infosec Ramblings</title>
	
	<link>http://www.infosecramblings.com</link>
	<description>ramblings on various information security topics</description>
	<lastBuildDate>Fri, 05 Feb 2010 14:18:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InfosecRamblings" /><feedburner:info uri="infosecramblings" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><feedburner:emailServiceId>InfosecRamblings</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>SchmooCon 2010 Streaming Live for Free</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/6GXckI6bnOc/</link>
		<comments>http://www.infosecramblings.com/2010/02/05/schmoocon-2-streaming-live-for-free/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 14:06:17 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1946</guid>
		<description><![CDATA[
I meant to mention this again earlier this week, but forgot to. ShmooCon will be live streaming the entire event this year. The conference starts today at 3:00 EDT.
If you are not familiar with ShmooCon, here is a tidbit from the conference website:
Different • ShmooCon is an annual East coast hacker  convention hell-bent on [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://www.infosecramblings.com/2010/02/05/schmoocon-2-streaming-live-for-free/" title="Permanent link to SchmooCon 2010 Streaming Live for Free"><img class="post_image aligncenter" src="http://www.infosecramblings.com/wp-content/uploads/2010/02/shmoocon-new.jpg" width="700" height="182" alt="Post image for SchmooCon 2010 Streaming Live for Free" /></a>
</p><p>I meant to mention this again earlier this week, but forgot to. ShmooCon will be <a class="zem_slink" title="Streaming media" rel="wikipedia" href="http://en.wikipedia.org/wiki/Streaming_media" mce_href="http://en.wikipedia.org/wiki/Streaming_media">live streaming</a> the entire event this year. The conference starts today at 3:00 EDT.</p>
<p>If you are not familiar with ShmooCon, here is a tidbit from the <a title="Shmoocon Website" href="https://www.shmoocon.org/index.html" mce_href="https://www.shmoocon.org/index.html" target="_blank">conference website</a>:</p>
<blockquote><p><b>Different</b> • ShmooCon is an annual East coast hacker  convention hell-bent on offering three days of an interesting atmosphere  for demonstrating technology exploitation, inventive software &amp;  hardware solutions, and open discussions of critical infosec issues. The  first day is a single track of speed talks, One Track Mind. The next  two days, there are three tracks: Break It!, Build It!, and Bring It  On!.</p>
<p><b>Affordable</b> • ShmooCon is about high-quality without the  high price. Space is limited! ShmooCon has sold out every year, so  unless taking a chance on an eBay auction to get your ticket sounds like  fun, register early!</p>
<p><b>Accessible</b> • ShmooCon is in <a class="zem_slink" title="Washington, D.C." rel="homepage" href="http://www.dc.gov/" mce_href="http://www.dc.gov/">Washington, D.C.</a>, at the  <a class="zem_slink" title="Marriott Wardman Park" rel="geolocation" href="http://maps.google.com/maps?ll=38.9245277778,-77.0551944444&amp;spn=1.0,1.0&amp;q=38.9245277778,-77.0551944444%20%28Marriott%20Wardman%20Park%29&amp;t=h" mce_href="http://maps.google.com/maps?ll=38.9245277778,-77.0551944444&amp;spn=1.0,1.0&amp;q=38.9245277778,-77.0551944444%20%28Marriott%20Wardman%20Park%29&amp;t=h">Marriott Wardman Park</a> Hotel, just a few steps from the D.C. Metro. Fly  into DCA, IAD, or BWI, or take a train to Union Station, and you are  just a quick cab ride away from the con</p>
<p><b>Entertaining</b> • Brain melting from all the cool tech you are  learning? Check out some of the contests running at ShmooCon, including  the Hacker Arcade and Hack-Or-Halo. In years past, we have also thrown massive parties at a local area hot-spot, so  expect that to happen again too!</p>
</blockquote>
<p>Here are the links to the different streams. The source page is <a title="Shmoocon Video Streams" href="https://www.shmoocon.org/video.html" mce_href="https://www.shmoocon.org/video.html" target="_blank">here</a>.</p>
<blockquote>
<h3>Friday Feb 5th, 2010</h3>
<p><a href="https://www.shmoocon.org/onetrack-vid.html" mce_href="https://www.shmoocon.org/onetrack-vid.html">One Track Mind</a><br mce_bogus="1"></p>
<h3>Saturday Feb 6th, 2010</h3>
<p><a href="https://www.shmoocon.org/buildit-vid.html" mce_href="https://www.shmoocon.org/buildit-vid.html">Build It</a><br />
<a href="https://www.shmoocon.org/breakit-vid.html" mce_href="https://www.shmoocon.org/breakit-vid.html">Break It</a><br />
<a href="https://www.shmoocon.org/bringiton-vid.html" mce_href="https://www.shmoocon.org/bringiton-vid.html">Bring It On</a><br mce_bogus="1"></p>
<h3>Sunday Feb 7th, 2010</h3>
<p><a href="https://www.shmoocon.org/buildit-vid.html" mce_href="https://www.shmoocon.org/buildit-vid.html">Build It</a><br />
<a href="https://www.shmoocon.org/breakit-vid.html" mce_href="https://www.shmoocon.org/breakit-vid.html">Break It</a><br />
<a href="https://www.shmoocon.org/bringiton-vid.html" mce_href="https://www.shmoocon.org/bringiton-vid.html">Bring It On</a><br mce_bogus="1"></p>
</blockquote>
<p>I&#8217;ll be watching as much as I can. You should too!</p>
<p>-Kevin</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/4c266037-76a8-43ef-970f-2158e576d204/" mce_href="http://reblog.zemanta.com/zemified/4c266037-76a8-43ef-970f-2158e576d204/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" mce_style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=4c266037-76a8-43ef-970f-2158e576d204" mce_src="http://img.zemanta.com/reblog_e.png?x-id=4c266037-76a8-43ef-970f-2158e576d204" alt="Reblog this post [with Zemanta]"></a><span class="zem-script more-related pretty-attribution"><mce:script mce_src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></mce:script></span></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=6GXckI6bnOc:7rhqy76uzws:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=6GXckI6bnOc:7rhqy76uzws:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=6GXckI6bnOc:7rhqy76uzws:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=6GXckI6bnOc:7rhqy76uzws:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/6GXckI6bnOc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/05/schmoocon-2-streaming-live-for-free/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/05/schmoocon-2-streaming-live-for-free/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 02/04/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/mmxBHp6F-rk/</link>
		<comments>http://www.infosecramblings.com/2010/02/04/interesting-information-security-bits-for-02042010/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 01:59:40 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[Awareness]]></category>
		<category><![CDATA[cpu]]></category>
		<category><![CDATA[lab]]></category>
		<category><![CDATA[surveys]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1939</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

Robert has a nice exploration of Intel&#8217;s new processor named Nehalem.
Errata Security: Nehalem vs. IDS
Tags: ( hardware intel cpu )
Andy speaks some truth about the user&#8217;s responsibility in the security equation.
Are we being irresponsible? &#62;&#62; Andy [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>Robert has a nice exploration of Intel&#8217;s new processor named Nehalem.<br />
<a href="http://erratasec.blogspot.com/2010/02/nehalem-vs-ids.html" target="_blank">Errata Security: Nehalem vs. IDS</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/hardware" target="_blank">hardware</a> <a href="http://delicious.com/rigginsk/intel" target="_blank">intel</a> <a href="http://delicious.com/rigginsk/cpu" target="_blank">cpu</a> )</li>
<li>Andy speaks some truth about the user&#8217;s responsibility in the security equation.<br />
<a href="http://www.andyitguy.com/blog/?p=859&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+AndyItguy+%28Andy%2C+ITGuy%29" target="_blank">Are we being irresponsible? &gt;&gt; Andy ITGuy</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/awareness" target="_blank">awareness</a> )</li>
<li>The start of what looks to be a neat series. lsof is an awesome tool.<br />
<a href="http://www.blackfistsecurity.com/2010/02/nix-command-of-day.html" target="_blank">Black Fist Security: *nix command of the day</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/tools" target="_blank">tools</a> <a href="http://delicious.com/rigginsk/unix" target="_blank">unix</a> )</li>
<li>Here is an interesting story about a different cyber-crime target. Still very lucrative.<br />
<a href="http://www.wired.com/threatlevel/2010/02/hackers-steal-carbon-credits/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired27b+%28Blog+-+27B+Stroke+6+%28Threat+Level%29%29" target="_blank">Hackers Steal Millions in Carbon Credits | Threat Level | Wired.com</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/crime" target="_blank">crime</a> )</li>
<li>This is a really good read.<br />
<a href="http://jeremiahgrossman.blogspot.com/2010/02/web-wont-be-safe-let-alone-secure.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+JeremiahGrossman+%28Jeremiah+Grossman%29" target="_blank">Jeremiah Grossman: The Web won&#8217;t be safe, let alone secure, unless we break it</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/wepabbsec" target="_blank">wepabbsec</a> )</li>
<li>Securosis is looking for participants for some closed surveys. Check this out if you want to help.<br />
<a href="http://securosis.com/blog/need-brains.-user-brains" target="_blank">Securosis Blog | Need Brains. User Brains</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/surveys" target="_blank">surveys</a> )</li>
<li>Want to setup and virtual network security testing lab? Check this out.<br />
<a href="http://laz3rnet.wordpress.com/2010/02/02/in-lieu-of/" target="_blank">In Lieu of&#8230; &lt;&lt; Laz3rNet</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/lab" target="_blank">lab</a> <a href="http://delicious.com/rigginsk/how-to" target="_blank">how-to</a> )</li>
<li>Windows 2008/7 offers new functionality that may help ease the pain of service accounts. (Hat tip: @grey_area)<br />
<a href="http://technet.microsoft.com/en-us/library/dd548356(WS.10).aspx" target="_blank">Service Accounts Step-by-Step Guide</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/windows" target="_blank">windows</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=mmxBHp6F-rk:EwpJKnv_NR4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=mmxBHp6F-rk:EwpJKnv_NR4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=mmxBHp6F-rk:EwpJKnv_NR4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=mmxBHp6F-rk:EwpJKnv_NR4:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/mmxBHp6F-rk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/04/interesting-information-security-bits-for-02042010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/04/interesting-information-security-bits-for-02042010/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 02/03/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/zn6GdBHl-8g/</link>
		<comments>http://www.infosecramblings.com/2010/02/03/interesting-information-security-bits-for-02032010/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 01:05:34 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[bsidessf]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1936</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

Andrew has a talk up for consideration for BSidesSF.
Andrew Hay &#62;&#62; Blog Archive &#62;&#62; Vote For My #BSidesSF Talk &#8220;My Life on the Infosec D-List&#8221;
Tags: ( bsidessf )
Apache hit end-of-life today. The last update has been [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>Andrew has a talk up for consideration for BSidesSF.<br />
<a href="http://www.andrewhay.ca/archives/1328" target="_blank">Andrew Hay &gt;&gt; Blog Archive &gt;&gt; Vote For My #BSidesSF Talk &#8220;My Life on the Infosec D-List&#8221;</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/bsidessf" target="_blank">bsidessf</a> )</li>
<li>Apache hit end-of-life today. The last update has been released.<br />
<a href="http://www.h-online.com/security/news/item/Apache-HTTP-Server-1-3-s-final-update-released-921133.html" target="_blank">Apache HTTP Server 1.3&#8217;s final update released &#8211; The H Security: News and Features</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/apache" target="_blank">apache</a> )</li>
<li>Ouch. That&#8217;s a lot of infected machines.<br />
<a href="https://infosecurity.us/?p=12551" target="_blank">48% of 22,000,000 Scanned Systems Malware Laden</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/malware" target="_blank">malware</a> )</li>
<li>Ben has tossed his hat into the BSidesSF ring too.<br />
<a href="http://www.secureconsulting.net/2010/02/bsides_or_be_square_san_franci.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+secureconsulting%2FujTc+%28The+Falcon%27s+View%29" target="_blank">BSides or Be Square: San Francisco and Austin (The Falcon&#8217;s View)</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/conferences" target="_blank">conferences</a> <a href="http://delicious.com/rigginsk/bsidessf" target="_blank">bsidessf</a> )</li>
<li>Andrew&#8217;s next interview is with Rob Fuller. I met Rob last year at RSA. Good guy.<br />
<a href="http://www.andrewhay.ca/archives/1342?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+andrewhayca+%28www.andrewhay.ca%29" target="_blank">Andrew Hay &gt;&gt; Blog Archive &gt;&gt; Information Security D-List Interview: Rob Fuller</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/interview" target="_blank">interview</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=zn6GdBHl-8g:CiVvKyF0lVs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=zn6GdBHl-8g:CiVvKyF0lVs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=zn6GdBHl-8g:CiVvKyF0lVs:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=zn6GdBHl-8g:CiVvKyF0lVs:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/zn6GdBHl-8g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/03/interesting-information-security-bits-for-02032010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/03/interesting-information-security-bits-for-02032010/</feedburner:origLink></item>
		<item>
		<title>(IN)Security Issue 24 is Now Available</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/gkC7kTTUso4/</link>
		<comments>http://www.infosecramblings.com/2010/02/02/insecurity-issue-24-is-now-available/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 02:08:27 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[insecure magazine]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1933</guid>
		<description><![CDATA[DOWNLOAD ISSUE 24 HERE (February 2010)

Writing a secure SOAP client with PHP: Field report  from a real-world project
How virtualized browsing shields against web-based  attacks
Review: 1Password 3
Preparing a strategy for application vulnerability  detection
Threats 2.0: A glimpse into the near future
Preventing malicious documents from compromising  Windows machines
Balancing productivity and security in a mixed [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-24.pdf"><img class="alignleft" style="margin-left: 5px; margin-right: 20px; border: 0pt none;" src="http://www.net-security.org/images/insecure/issue-main-24.jpg" border="0" alt="" width="200" height="283" /></a><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-24.pdf"><span style="text-decoration: underline;">DOWNLOAD ISSUE 24 HERE</span></a> (February 2010)</p>
<ul>
<li>Writing a secure SOAP client with PHP: Field report  from a real-world project</li>
<li>How virtualized browsing shields against web-based  attacks</li>
<li>Review: 1Password 3</li>
<li>Preparing a strategy for application vulnerability  detection</li>
<li>Threats 2.0: A glimpse into the near future</li>
<li>Preventing malicious documents from compromising  Windows machines</li>
<li>Balancing productivity and security in a mixed  environment</li>
<li>AES and 3DES comparison analysis</li>
<li>OSSEC: An introduction to open source log and event  management</li>
<li>Secure and differentiated access in enterprise  wireless networks</li>
<li><em><strong>AND MORE!</strong></em></li>
</ul>
<ul></ul>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=gkC7kTTUso4:YOjT36_MEuo:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=gkC7kTTUso4:YOjT36_MEuo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=gkC7kTTUso4:YOjT36_MEuo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=gkC7kTTUso4:YOjT36_MEuo:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/gkC7kTTUso4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/02/insecurity-issue-24-is-now-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/02/insecurity-issue-24-is-now-available/</feedburner:origLink></item>
		<item>
		<title>Pardon the Dust</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/cj-Lzvnl4cE/</link>
		<comments>http://www.infosecramblings.com/2010/02/01/pardon-the-dust/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 03:38:32 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[maintenance]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1930</guid>
		<description><![CDATA[I am installing a new theme over the next few days so I expect some hicups and snags around here. I apologize for any issues you may have, but things should be back to normal in a couple days.
-Kevin
]]></description>
			<content:encoded><![CDATA[<p></p><p>I am installing a new theme over the next few days so I expect some hicups and snags around here. I apologize for any issues you may have, but things should be back to normal in a couple days.</p>
<p>-Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=cj-Lzvnl4cE:e_MVUi3x1r4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=cj-Lzvnl4cE:e_MVUi3x1r4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=cj-Lzvnl4cE:e_MVUi3x1r4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=cj-Lzvnl4cE:e_MVUi3x1r4:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/cj-Lzvnl4cE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/01/pardon-the-dust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/01/pardon-the-dust/</feedburner:origLink></item>
		<item>
		<title>Vote For My #BSidesSF Talk</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/MCPLEpiv7Js/</link>
		<comments>http://www.infosecramblings.com/2010/02/01/vote-for-my-bsidessf-talk/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 03:33:04 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[bsides]]></category>
		<category><![CDATA[conferences]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1928</guid>
		<description><![CDATA[I have submitted a topic for consideration for Security BSides San Francisco 2010 which happens concurrently with RSA.
For those not familiar with Security BSides, the following is from the website:

What is BSides?
BSides is an ad-hoc gathering of information security types born from the  desire for people to share and learn in an open environment. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I have submitted a topic for consideration for Security BSides San Francisco 2010 which happens concurrently with RSA.</p>
<p>For those not familiar with Security BSides, the following is from the website:</p>
<blockquote>
<h2><strong>What is BSides?</strong></h2>
<p><a href="http://www.securitybsides.org/BSides">BSides</a> is an ad-hoc gathering of information security types born from the  desire for people to share and learn in an open environment. It is an  intense event with discussions, demos and interaction from participants.  It is entirely community driven.  It is where conversations for the  next-big-thing may be happening.  We&#8217;ve followed the <a href="http://www.barcamp.org/" target="_blank">BarCamp format</a>&#8230;  because it works.</p></blockquote>
<p>My topic:</p>
<ul>
<li><strong>Title:</strong> <em>Discussion: What Makes a Good Risk  Management Practice?</em></li>
<li><strong>Abstract:</strong> All of our organizations have to manage  risk, specifically information security risk. What does it mean to do  that well? What are the moving parts that make up a good risk management  practice? This discussion/panel/talk will not focus on assessment  methodologies or frameworks. It will also not focus on the &#8220;information  security program.&#8221; We will spend some time focusing on the other moving  parts of a risk management practice. Engagement with our business  partners, how we bring it all together, how we can manage the inputs and  outputs of the risk management process, etc. It will be an opportunity  for those interested to share and learn from each other.</li>
</ul>
<p>This topic is modeled after the RSA Peer-2-Peer sessions in that it is not a presentation. I anticipate a discussion where we can all contribute to the conversation and try to define what we it means to build a good risk management practice in our organizations.</p>
<p>Please vote for my topic by tweeting the following if this sounds like a conversation you&#8217;d like to be a part of:</p>
<blockquote><p>@SecurityBSides I vote for “<em>What Makes a Good Risk Management Practice?</em>” by @kriggins #BSidesSF http://bit.ly/BSidesSFtalks</p></blockquote>
<p>-Kevin</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"><a title="Permanent Link to Vote For My #BSidesSF Talk “My  Life on the Infosec D-List”" rel="bookmark" href="http://www.andrewhay.ca/archives/1328">Vote For My #BSidesSF Talk “My Life on the  Infosec D-List”</a></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=MCPLEpiv7Js:SGbP74bxaeY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=MCPLEpiv7Js:SGbP74bxaeY:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=MCPLEpiv7Js:SGbP74bxaeY:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=MCPLEpiv7Js:SGbP74bxaeY:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/MCPLEpiv7Js" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/01/vote-for-my-bsidessf-talk/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/01/vote-for-my-bsidessf-talk/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 02/01/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/1ytq_j0X8Fg/</link>
		<comments>http://www.infosecramblings.com/2010/02/01/interesting-information-security-bits-for-02012010/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 00:41:04 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[awards]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[interviews]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1926</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

Hoff points to an interesting project that addresses the distributed authentication issue in web based systems.
MashSSL &#8211; An Excellent Idea You&#8217;ve Probably Never Heard Of&#8230; &#124; Rational Survivability
Tags: ( authentication ssl web )
Get your Security Threat [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>Hoff points to an interesting project that addresses the distributed authentication issue in web based systems.<br />
<a href="http://www.rationalsurvivability.com/blog/?p=1704" target="_blank">MashSSL &#8211; An Excellent Idea You&#8217;ve Probably Never Heard Of&#8230; | Rational Survivability</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/authentication" target="_blank">authentication</a> <a href="http://delicious.com/rigginsk/ssl" target="_blank">ssl</a> <a href="http://delicious.com/rigginsk/web" target="_blank">web</a> )</li>
<li>Get your Security Threat Report 2010 while it&#8217;s hot!<br />
<a href="http://www.sophos.com/blogs/gc/g/2010/02/01/sophos-security-threat-report-2010/" target="_blank">Sophos Security Threat Report 2010 | Graham Cluley&#8217;s blog</a><br />
Tags: (<a href="http://delicious.com/rigginsk/iis" target="_blank"></a> <a href="http://delicious.com/rigginsk/threats" target="_blank">threats</a> <a href="http://delicious.com/rigginsk/reports" target="_blank">reports</a> )</li>
<li>Jennifer is involved in a few talks at Security BSides San Fran. Vote for her!<br />
<a href="http://securityuncorked.com/2010/02/the-skinny-on-security-bsides-san-francisco/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+SecurityUncorked+%28JJ%27s+Security+Uncorked%29" target="_blank">Security Uncorked &gt;&gt; The Skinny on Security BSides San Francisco</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/conferences" target="_blank">conferences</a> <a href="http://delicious.com/rigginsk/bsides" target="_blank">bsides</a> )</li>
<li>The finalists for the Social Security Blogger Awards 2010 have been selected.<br />
<a href="http://www.ashimmy.com/2010/01/envelope-please-and-the-winners-are.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+StillsecureAfterAllTheseYears+%28The+Ashimmy+Blog%29" target="_blank">The Ashimmy Blog: Envelope please, and the winners are . . .</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/awards" target="_blank">awards</a> )</li>
<li>Very cool. Encrypt your logs before sending them across the wire.<br />
<a href="http://www.immutablesecurity.com/index.php/2010/01/29/using-ossec-for-encrypted-log-transport/" target="_blank">Immutable Security &gt;&gt; Using OSSEC for Encrypted Log Transport</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/logging" target="_blank">logging</a> <a href="http://delicious.com/rigginsk/encryption" target="_blank">encryption</a> <a href="http://delicious.com/rigginsk/ossec" target="_blank">ossec</a> )</li>
<li>Similar to the Amazon EC2 experiment last year, this time it is done with Microsoft&#8217;s Azure.<br />
<a href="http://www.gdssecurity.com/l/b/2010/01/29/breaking-password-based-encryption-with-azure/" target="_blank">Breaking Password Based Encryption with Azure &#8211; Gotham Digital Science</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/passwords" target="_blank">passwords</a> <a href="http://delicious.com/rigginsk/cracking" target="_blank">cracking</a> <a href="http://delicious.com/rigginsk/cloud" target="_blank">cloud</a> )</li>
<li>Looks like status quo for the PCI DSS this year.<br />
<a href="http://www.securityexe.com/?p=104&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+securityexe+%28Security.exe+-+Powered+by+The+CISO+Group%29" target="_blank">Security.exe &#8211; Powered by The CISO Group &gt;&gt; Blog Archive &gt;&gt; No major changes to PCI DSS in 2010, but watch for chip and pin in the future</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/pci" target="_blank">pci</a> )</li>
<li>Graham points out something those who use twitter should be aware of. Lists as spamming tools.<br />
<a href="http://www.sophos.com/blogs/gc/g/2010/01/29/twitter-list-spam/" target="_blank">Twitter list spam</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/lists" target="_blank">lists</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1ytq_j0X8Fg:bDNjVCoCyas:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1ytq_j0X8Fg:bDNjVCoCyas:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1ytq_j0X8Fg:bDNjVCoCyas:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1ytq_j0X8Fg:bDNjVCoCyas:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/1ytq_j0X8Fg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/02/01/interesting-information-security-bits-for-02012010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/02/01/interesting-information-security-bits-for-02012010/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 01/28/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/u9eCY5SGucQ/</link>
		<comments>http://www.infosecramblings.com/2010/01/28/interesting-information-security-bits-for-01282010/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 23:36:02 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[Career]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1924</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

This is a good article to look at if you are thinking about the cloud and your business. (Hat Tip: @infosecstuff)
Cloud Security: Ten Questions to Ask Before You Jump In
Tags: ( cloud )
Another interesting tool today. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>This is a good article to look at if you are thinking about the cloud and your business. (Hat Tip: @infosecstuff)<br />
<a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/g/a/2010/01/26/urnidgns852573C400693880002576B7006E3A79.DTL" target="_blank">Cloud Security: Ten Questions to Ask Before You Jump In</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/cloud" target="_blank">cloud</a> )</li>
<li>Another interesting tool today. Use Bing to find associated IP address and DNS hostnames. (Hat Tip: @lbhuston)<br />
<a href="http://bingprobe.codeplex.com/" target="_blank">Bing Web Server Probe</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/tools" target="_blank">tools</a> <a href="http://delicious.com/rigginsk/webappsec" target="_blank">webappsec</a> )</li>
<li>This looks like an interesting tool to add to your web app sec Firefox toolkit.<br />
<a href="http://www.darknet.org.uk/2010/01/groundspeed-1-1-web-application-security-add-on-for-firefox/" target="_blank">Groundspeed 1.1 &#8211; Web Application Security Add-on For Firefox | Darknet &#8211; The Darkside</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/webappsec" target="_blank">webappsec</a> <a href="http://delicious.com/rigginsk/tools" target="_blank">tools</a> <a href="http://delicious.com/rigginsk/firefox" target="_blank">firefox</a> )</li>
<li>Jarrod shares how he got into information security and offers some thoughts on making your own move.<br />
<a href="http://jarrodloidl.blogspot.com/2010/01/how-to-get-start-in-information.html" target="_blank">/dev/null &#8211; ramblings of an infosec professional: How to Get A Start in Information Security</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/career" target="_blank">career</a> )</li>
<li>Ben is up next on the D-list interviews. I know Ben from Twitter and hope we can meet IRL someday.<br />
<a href="http://www.andrewhay.ca/archives/1324" target="_blank">Andrew Hay &gt;&gt; Blog Archive &gt;&gt; Information Security D-List Interview: Ben Jackson</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/interview" target="_blank">interview</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=u9eCY5SGucQ:G4-TcLjFI2k:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=u9eCY5SGucQ:G4-TcLjFI2k:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=u9eCY5SGucQ:G4-TcLjFI2k:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=u9eCY5SGucQ:G4-TcLjFI2k:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/u9eCY5SGucQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/01/28/interesting-information-security-bits-for-01282010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/01/28/interesting-information-security-bits-for-01282010/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 01/27/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/BzAPeE81P2k/</link>
		<comments>http://www.infosecramblings.com/2010/01/27/interesting-information-security-bits-for-01272010/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 23:50:06 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Career]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[session]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1922</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

Some thoughts about the security job market and how to get into it. (Thanks Ron)
E-Commerce News: Trends: Breaking Into the Security Job Market
Tags: ( career )
Anton has some comments about log context. Very important stuff.
Anton Chuvakin [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>Some thoughts about the security job market and how to get into it. (Thanks Ron)<br />
<a href="http://www.ecommercetimes.com/story/Breaking-Into-the-Security-Job-Market-69185.html?wlc=1264605028" target="_blank">E-Commerce News: Trends: Breaking Into the Security Job Market</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/career" target="_blank">career</a> )</li>
<li>Anton has some comments about log context. Very important stuff.<br />
<a href="http://chuvakin.blogspot.com/2010/01/on-log-context.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+AntonChuvakinPersonalBlog+%28Anton+Chuvakin+Personal+Blog%29" target="_blank">Anton Chuvakin Blog &#8211; &#8220;Security Warrior&#8221;: On Log Context</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/log-monitoring" target="_blank">log-monitoring</a> )</li>
<li>This paper (pdf) takes a look at replacing session cookies with digest authentication.<br />
<a href="http://www.vsecurity.com/download/papers/WeaningTheWebOffOfSessionCookies.pdf" target="_blank">WeaningTheWebOffOfSessionCookies.pdf (application/pdf Object)</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/session" target="_blank">session</a> <a href="http://delicious.com/rigginsk/webappsec" target="_blank">webappsec</a> )</li>
<li>Another really good reason for egress controls.<br />
<a href="http://sunbeltblog.blogspot.com/2010/01/botnet-c-switching-to-http-away-from.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+SunbeltBlog+%28Sunbelt+BLOG%29" target="_blank">Sunbelt Blog: Botnet C&amp;C switching to http; away from IRC</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/botnet" target="_blank">botnet</a> )</li>
<li>That&#8217;s a lot of malware.<br />
<a href="http://blogs.zdnet.com/security/?p=5365&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+zdnet%2Fsecurity+%28ZDNet+Zero+Day%29" target="_blank">Report: 48% of 22 million scanned computers infected with malware | Zero Day | ZDNet.com</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/malware" target="_blank">malware</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=BzAPeE81P2k:EJcC2beDWqA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=BzAPeE81P2k:EJcC2beDWqA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=BzAPeE81P2k:EJcC2beDWqA:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=BzAPeE81P2k:EJcC2beDWqA:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/BzAPeE81P2k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/01/27/interesting-information-security-bits-for-01272010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/01/27/interesting-information-security-bits-for-01272010/</feedburner:origLink></item>
		<item>
		<title>Interesting Information Security Bits for 01/26/2010</title>
		<link>http://feedproxy.google.com/~r/InfosecRamblings/~3/1wMll6XQhIw/</link>
		<comments>http://www.infosecramblings.com/2010/01/26/interesting-information-security-bits-for-01262010/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 00:53:16 +0000</pubDate>
		<dc:creator>kriggins</dc:creator>
				<category><![CDATA[Interesting Bits]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[fstab]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[multi-tenancy]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://www.infosecramblings.com/?p=1920</guid>
		<description><![CDATA[Good afternoon everybody! I hope your day is going well.
Here are today&#8217;s Interesting Information Security Bits from around the web.

Gunnar says what I have been thinking about the whole APT argument, only much better than I could.
1 Raindrop: I Can See APT From Here
Tags: ( apt )
Anyone who does forensics or needs to deal with [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Good afternoon everybody! I hope your day is going well.</p>
<p>Here are today&#8217;s Interesting Information Security Bits from around the web.</p>
<ol>
<li>Gunnar says what I have been thinking about the whole APT argument, only much better than I could.<br />
<a href="http://1raindrop.typepad.com/1_raindrop/2010/01/i-can-see-atp-from-here.html" target="_blank">1 Raindrop: I Can See APT From Here</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/apt" target="_blank">apt</a> )</li>
<li>Anyone who does forensics or needs to deal with Linux machines should be aware of how the /etc/fstab file works. Sometimes to can find interesting things by peaking in there.<br />
<a href="http://www.tuxfiles.org/linuxhelp/fstab.html" target="_blank">How to edit and understand /etc/fstab</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/linux" target="_blank">linux</a> <a href="http://delicious.com/rigginsk/filesystem" target="_blank">filesystem</a> <a href="http://delicious.com/rigginsk/fstab" target="_blank">fstab</a> )</li>
<li>This is just very cool. A very neat visualization of historical browser use statistics.<br />
<a href="http://www.michaelvandaniker.com/labs/browserVisualization/" target="_blank">http://www.michaelvandaniker.com/labs/browserVisualization/</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/visualization" target="_blank">visualization</a> )</li>
<li>This is an interesting treatment of what cloud computing is.<br />
<a href="http://www.elementalcloudcomputing.com/2009/11/04/elemental-cloud-o-gram-release1/" target="_blank">Elemental Cloud-o-gram : elemental cloud computing</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/cloud" target="_blank">cloud</a> )</li>
<li>This is the one of the big questions you have to answer when you consider moving your sensitive corporate and customer data to externally hosted cloud services.<br />
<a href="http://chucksblog.emc.com/chucks_blog/2010/01/thoughts-on-secure-multitenancy.html" target="_blank">Thoughts on Secure Multi-Tenancy &#8211; Chuck&#8217;s Blog</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/cloud" target="_blank">cloud</a> <a href="http://delicious.com/rigginsk/multi-tenancy" target="_blank">multi-tenancy</a> )</li>
<li>Hmm, doesn&#8217;t look like the basis for Google claiming the Chinese are behind the Aurora attacks is quite as cut and dried as presented.<br />
<a href="http://www.theregister.co.uk/2010/01/26/aurora_attack_origins/" target="_blank">&#8216;Aurora&#8217; code circulated for years on English sites * The Register</a><br />
Tags: ( <a href="http://delicious.com/rigginsk/google" target="_blank">google</a> <a href="http://delicious.com/rigginsk/aurora" target="_blank">aurora</a> )</li>
</ol>
<p>That&#8217;s it for today.  Have fun!</p>
<p>Subscribe to my <a href="http://feeds2.feedburner.com/InfosecRamblings" target="_blank">RSS Feed</a> if you enjoy these daily Interesting Bits posts.</p>
<p>Kevin</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1wMll6XQhIw:aDvGhXL9XaM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1wMll6XQhIw:aDvGhXL9XaM:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?i=1wMll6XQhIw:aDvGhXL9XaM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/InfosecRamblings?a=1wMll6XQhIw:aDvGhXL9XaM:l6gmwiTKsz0"><img src="http://feeds.feedburner.com/~ff/InfosecRamblings?d=l6gmwiTKsz0" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/InfosecRamblings/~4/1wMll6XQhIw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.infosecramblings.com/2010/01/26/interesting-information-security-bits-for-01262010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.infosecramblings.com/2010/01/26/interesting-information-security-bits-for-01262010/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 0.929 seconds. --><!-- Cached page generated by WP-Super-Cache on 2010-02-07 07:53:55 -->
