<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>MattJay Security</title>
	
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Wed, 02 Feb 2011 17:09:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/MattjaySecurity" /><feedburner:info uri="mattjaysecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Reveal Passwords Bookmarklet – What Could Go Wrong?</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/a5npkNdKqM8/</link>
		<comments>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 17:09:14 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[fundamentals]]></category>
		<category><![CDATA[Password]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=131</guid>
		<description><![CDATA[Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out. It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="whatcouldgowrong" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2011/02/whatcouldgowrong.jpg" alt="" width="350" height="230" />Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out.</p>
<p>It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them by heart.</p>
<p>I liken this to the fact that 10 years ago I had to dial everybody&#8217;s phone number on my home phone manually, and now I just pull up their contact in my cell and hit send. The funny thing is those friends and family I still call from the pre-cell phone era are the only people&#8217;s numbers I know by heart.</p>
<p>But even though this bookmarklet sounds like a good idea in theory, I have a problem with it. How many times have you been typing your login information in and started typing your password accidentally in the username field? For me it has happened a decent number of times and a handful of those were while people were behind me watching, which of course was followed by me changing my password. So now you are telling me there is a javascript bookmarklet being advertised to do such a thing *on purpose*?</p>
<p>What could go wrong here?</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;bodytext=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;notes=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;annotation=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;s=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/a5npkNdKqM8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Start Me Up</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/OINOENH8p9E/</link>
		<comments>http://www.mattjaysecurity.com/2011/01/start-me-up/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 04:47:19 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[career]]></category>
		<category><![CDATA[Entrepreneur]]></category>
		<category><![CDATA[Startup]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=124</guid>
		<description><![CDATA[Since joining WhiteHat Security late last spring, I’ve been living and working in the heart of Silicon Valley. It certainly is an exciting place to live except maybe the traffic and gas prices, which (un)fortunately for me is nothing to terribly new coming from New York. There is a certain vibe in the air during [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><a href="http://www.mattjaysecurity.com/wp-content/uploads/2011/01/clearboard.jpg#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img class="alignleft size-medium wp-image-128" title="clearboard" src="http://www.mattjaysecurity.com/wp-content/uploads/2011/01/clearboard-300x199.jpg" alt="" width="300" height="199" /></a>Since joining <a href="http://www.whitehatsec.com">WhiteHat Security</a> late last spring, I’ve been living and working in the heart of Silicon Valley. It certainly is an exciting place to live except maybe the traffic and gas prices, which (un)fortunately for me is nothing to terribly new coming from New York.</p>
<p>There is a certain vibe in the air during lunch breaks and happy hours when all sorts of people are meeting and talking about what they are passionate about, and since there are so many tech companies around these conversations can sometimes hit an 11 on the geek scale. Besides all the World of Warcraft talk there is an abundance of energy regarding new ideas, the next big thing, exciting opportunities, etc.</p>
<p>The startup community is certainly finding a way to boom in these tough economic times, and I’d venture so far as to say that they are booming because of the tough times. In a period of hard times the people who will thrive are those who choose to innovate and rise above the rest. Whether it be starting the next social networking phenomenon which awards you ribbons when you tag a body part with a landmark (Hey look its my finger at the Grand Canyon!) ™ or it’s paving the way for your company to receive huge bags of money from yet another tech giant on the prowl, smart people are rising up. We are in a unique age of acquisitions where the buy out is king.</p>
<p>I’ve only just begun paying attention to the startup community but it certainly is an interesting place to keep my eye. I’ve been fortunate enough to meet some of the brilliant people behind the curtains with their big ideas. The price of a beer is definitely worth its weight in gold if it buys me some conversation time. I’ve added a ton of reading to my morning RSS ritual which I thought I’d aggregate here for you to start keeping an eye along with me.</p>
<ul>
<li><a href="http://under30ceo.com/">Under30CEO</a></li>
<li><a href="http://youngentrepreneur.com/blog">Young Entrepreneur</a></li>
<li><a href="http://mixergy.com/">Mixergy</a></li>
<li><a href="http://www.businessinsider.com/sai">Silicon Alley Insider</a></li>
</ul>
<p>These are my most recent blog roll entries that I’ve been following the past few weeks and very much enjoying.</p>
<p>-Matt</p>
<p>P.S. &#8211; Don’t be surprised if more startup like posts start showing up here.</p>
</div>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up&amp;bodytext=%0D%0A%0D%0ASince%20joining%20WhiteHat%20Security%20late%20last%20spring%2C%20I%E2%80%99ve%20been%20living%20and%20working%20in%20the%20heart%20of%20Silicon%20Valley.%20It%20certainly%20is%20an%20exciting%20place%20to%20live%20except%20maybe%20the%20traffic%20and%20gas%20prices%2C%20which%20%28un%29fortunately%20for%20me%20is%20nothing%20to%20terribl" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up&amp;notes=%0D%0A%0D%0ASince%20joining%20WhiteHat%20Security%20late%20last%20spring%2C%20I%E2%80%99ve%20been%20living%20and%20working%20in%20the%20heart%20of%20Silicon%20Valley.%20It%20certainly%20is%20an%20exciting%20place%20to%20live%20except%20maybe%20the%20traffic%20and%20gas%20prices%2C%20which%20%28un%29fortunately%20for%20me%20is%20nothing%20to%20terribl" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;t=Start%20Me%20Up" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up&amp;annotation=%0D%0A%0D%0ASince%20joining%20WhiteHat%20Security%20late%20last%20spring%2C%20I%E2%80%99ve%20been%20living%20and%20working%20in%20the%20heart%20of%20Silicon%20Valley.%20It%20certainly%20is%20an%20exciting%20place%20to%20live%20except%20maybe%20the%20traffic%20and%20gas%20prices%2C%20which%20%28un%29fortunately%20for%20me%20is%20nothing%20to%20terribl" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=%0D%0A%0D%0ASince%20joining%20WhiteHat%20Security%20late%20last%20spring%2C%20I%E2%80%99ve%20been%20living%20and%20working%20in%20the%20heart%20of%20Silicon%20Valley.%20It%20certainly%20is%20an%20exciting%20place%20to%20live%20except%20maybe%20the%20traffic%20and%20gas%20prices%2C%20which%20%28un%29fortunately%20for%20me%20is%20nothing%20to%20terribl" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Start%20Me%20Up&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;title=Start%20Me%20Up" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F&amp;t=Start%20Me%20Up&amp;s=%0D%0A%0D%0ASince%20joining%20WhiteHat%20Security%20late%20last%20spring%2C%20I%E2%80%99ve%20been%20living%20and%20working%20in%20the%20heart%20of%20Silicon%20Valley.%20It%20certainly%20is%20an%20exciting%20place%20to%20live%20except%20maybe%20the%20traffic%20and%20gas%20prices%2C%20which%20%28un%29fortunately%20for%20me%20is%20nothing%20to%20terribl" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Start%20Me%20Up%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F01%2Fstart-me-up%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/OINOENH8p9E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2011/01/start-me-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2011/01/start-me-up/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Missing in Action -&gt; Return to Action</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/LOKy1cnXsVU/</link>
		<comments>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 23:56:35 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Random]]></category>
		<category><![CDATA[Web App]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=105</guid>
		<description><![CDATA[So it has been about 6 months since I wrote a blog post and I’ve promised to myself to get back into it for the new year. I miss you all. I guess I should start by explaining my absence from the blogosphere as I had some pretty damn good reasons: I got a new [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26.jpg#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img class="size-medium wp-image-110 aligncenter" title="2010-06-24 13.19.26" src="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26-e1293754164746-300x195.jpg" alt="" width="300" height="195" /></a>So  it has been about 6 months since I wrote a blog post and I’ve promised  to myself to get back into it for the new year. I miss you all. I guess I  should start by explaining my absence from the blogosphere as I had  some pretty damn good reasons:</p>
<ol>
<li>I got a new job</li>
<li>Said job was 3000 miles away</li>
<li><a href="http://www.google.com/maps?f=d&amp;source=s_d&amp;saddr=new+york,+ny&amp;daddr=San+Francisco,+CA&amp;hl=en&amp;geocode=FXFAbQIdK8KW-yk7CD_TpU_CiTFi_nfhBo8LyA%3BFVJmQAIdKAe0-CkhAGkAbZqFgDH_rXbwZxNQSg&amp;mra=ls&amp;sll=37.0625,-95.677068&amp;sspn=53.741627,95.009766&amp;ie=UTF8&amp;ll=39.774769,-98.173828&amp;spn=52.041139,95.009766&amp;t=h&amp;z=4">I drove the 3000 miles</a></li>
<li>First week in new location my house was broken into and my computers were among the more than $5k worth of stuff stolen.</li>
<li>I had just blown all my money moving 3000 miles =no way to replace computer (or go to BlackHat/Defcon/BSidesLV <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </li>
<li>New job has been keeping me supremely busy in a good way.</li>
</ol>
<p style="text-align: left;">This  whole extravaganza started in May so the summer was kind of a whirlwind  of craziness, the fall was work kicking into overdrive. I’ve kind of  hit my stride at the new job and gotten used to the giant piles of work  so I’m planning on setting aside time to blog again.</p>
<p>The job I started was at <a href="http://www.whitehatsec.com/">WhiteHat Security</a> as a resident appsec bug hunter. Drinking from a fire hose for 6 months  would be no exaggeration as we have a very unique playground of  websites to find/test vulnerabilities on. I’ve found some very high  profile vulnerabilities that I wish I could talk about but I’ll have to  settle for severely obfuscated posts in the future merely describing the  attack vector with all client information withheld.</p>
<p>Since I joined the team we have about doubled in size and gone from the “Operations” department to <a href="http://www.whitehatsec.com/home/services/threat_research.html">WhiteHat’s “Threat Research Center”</a> which just sounds so muchs spiffier and more official.</p>
<p>We also participated pretty avidly in the Google bug bounty program. Mighty successfully I might add: <a href="http://www.google.com/corporate/halloffame.html">Google Security Hall of Fame</a>.  5 people on our team found rewardable bugs in Google apps. I say  rewardable because a number of us found bugs that they didn’t qualify as  rewardable, mostly minor XSS or open redirects.</p>
<p>I might add that this is 5 <strong>so far</strong>, we have a few more emails sitting in their queue and I’ve had a bit of fun with their<a href="http://www.google.com/chromeos/pilot-program-cr48.html"> Cr-48 as a beta tester </a> <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  (more details to come after bug is reported and fixed but this one is a fun one).</p>
<p>So  there is a run down of my absence from the blog world, cliff notes of  course. I did a fair amount of weekend getaways enjoying the west coast  weather.</p>
<p style="text-align: left;">I  hope anybody reading this had a great Christmas and will have a safe  and happy new year. My better half put a grill / smoker under the tree  for me and I’ll be breaking that out to ring in 2011 with some smoked  meat.<br />
So  now that you know one of my resolutions is to start blogging again what  are some of yours? I miss you. You look great by the way.</p>
<p>Cheers,<br />
Matty Jay</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;bodytext=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;notes=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;annotation=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;s=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Missing%20in%20Action%20-%3E%20Return%20to%20Action%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/LOKy1cnXsVU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Horizon Bob Story [Reader Submitted]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/ISNDFsJoAJw/</link>
		<comments>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 04:01:29 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=101</guid>
		<description><![CDATA[This is the first of what I hope to be a continuing blog post topic of one of my readers, Bob, experiencing a security fail and sending me a letter. Feel free to mail me stories of your friend Bob and his epic adventures. Dear Matt Jay, I’m writing this email because as your friend, [...]]]></description>
			<content:encoded><![CDATA[<p>This is the first of what I hope to be a continuing blog post topic of one of my readers, Bob, experiencing a security fail and sending me a letter. Feel free to mail me stories of your friend Bob and his epic adventures.</p>
<blockquote><p>
Dear Matt Jay,</p>
<p>I’m writing this email because as your friend, I trust you will help me expose this nonsense.</p>
<p>My mom is spending a few days in North Carolina.   While there, she decided she needed a phone upgrade.  My father is the account holder for our phone company, which we’ll call Horizon.  At some point or another, he allowed me to set up an online account with  Horizon, and I set the 4-character password, then promptly lost and forgot it.</p>
<p>The phone of my dear mother’s desire requires an upgraded data plan, and such an upgrade requires the account holder’s permission.  The folks at the retailer asked for the password, which she did not have.  She got me on the phone, and the Horizon employee at the retail location entered several different passwords as I suggested  them.  Trial-and-error guessing for a security checkpoint… Fail #1.</p>
<p>I then called Horizon customer service in an  attempt to retrieve the password, since I couldn’t find it in any of my files and there is no way to reset it online.  I pretended to be my father, the account holder.  They asked for my name and –spoiler alert – my account password.  I told them I was calling to find out the password.  I offered my [father’s] last 4 digits of SSN.  I then gave the rep the wrong 4 digit number, but he told me it was  close.  He asked if I was sure, and I insisted there must be some mistake.  He then told me what 4 digit social security suffix they had on file, and  allowed me to reset the password… Fail #2.</p>
<p>The Horizon employee at the retail location was  apparently aware of most of this as it panned out.  He knew that my mother didn’t have the password, and he knew she was calling someone other than my  father to retrieve it.  Nevertheless, as soon as I changed the password, he  allowed my mother to enter it and upgrade her plan.  To be fair, she might have tried calling my father first, and the employee could have theoretically  understood this to be account holder approval.  Regardless… Fail #3.</p>
<p>It doesn’t take a genius to figure out what went  wrong here, and it really exposed the vulnerability of people’s information when it’s in the hands of improperly trained workers.  That being said, my dad’s full social securiy number is <strong>REDACTED</strong>.</p>
<p>Sincerely,</p>
<p>Bob</p>
<p>P.S. What are you doing later tonight?  I’m craving tacos.
</p></blockquote>
<p>Thanks Bob, I can go for some tacos too. This trip is on me for the good laugh.</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;bodytext=This%20is%20the%20first%20of%20what%20I%20hope%20to%20be%20a%20continuing%20blog%20post%20topic%20of%20one%20of%20my%20readers%2C%20Bob%2C%20experiencing%20a%20security%20fail%20and%20sending%20me%20a%20letter.%20Feel%20free%20to%20mail%20me%20stories%20of%20your%20friend%20Bob%20and%20his%20epic%20adventures.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ADear%20Matt%20Jay%2C%0D%0A%0D%0AI" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;notes=This%20is%20the%20first%20of%20what%20I%20hope%20to%20be%20a%20continuing%20blog%20post%20topic%20of%20one%20of%20my%20readers%2C%20Bob%2C%20experiencing%20a%20security%20fail%20and%20sending%20me%20a%20letter.%20Feel%20free%20to%20mail%20me%20stories%20of%20your%20friend%20Bob%20and%20his%20epic%20adventures.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ADear%20Matt%20Jay%2C%0D%0A%0D%0AI" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;t=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;annotation=This%20is%20the%20first%20of%20what%20I%20hope%20to%20be%20a%20continuing%20blog%20post%20topic%20of%20one%20of%20my%20readers%2C%20Bob%2C%20experiencing%20a%20security%20fail%20and%20sending%20me%20a%20letter.%20Feel%20free%20to%20mail%20me%20stories%20of%20your%20friend%20Bob%20and%20his%20epic%20adventures.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ADear%20Matt%20Jay%2C%0D%0A%0D%0AI" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=This%20is%20the%20first%20of%20what%20I%20hope%20to%20be%20a%20continuing%20blog%20post%20topic%20of%20one%20of%20my%20readers%2C%20Bob%2C%20experiencing%20a%20security%20fail%20and%20sending%20me%20a%20letter.%20Feel%20free%20to%20mail%20me%20stories%20of%20your%20friend%20Bob%20and%20his%20epic%20adventures.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ADear%20Matt%20Jay%2C%0D%0A%0D%0AI" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;title=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F&amp;t=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D&amp;s=This%20is%20the%20first%20of%20what%20I%20hope%20to%20be%20a%20continuing%20blog%20post%20topic%20of%20one%20of%20my%20readers%2C%20Bob%2C%20experiencing%20a%20security%20fail%20and%20sending%20me%20a%20letter.%20Feel%20free%20to%20mail%20me%20stories%20of%20your%20friend%20Bob%20and%20his%20epic%20adventures.%0D%0A%0D%0A%0D%0A%0D%0A%0D%0ADear%20Matt%20Jay%2C%0D%0A%0D%0AI" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Horizon%20Bob%20Story%20%5BReader%20Submitted%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F03%2Fhorizon-bob-story-reader-submitted%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/ISNDFsJoAJw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/03/horizon-bob-story-reader-submitted/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Secure Password Win [Random]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/gWCGnASIdYE/</link>
		<comments>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 22:29:30 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Password]]></category>
		<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=98</guid>
		<description><![CDATA[Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh: During a recent password audit at the Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin When Paddy was asked why he had such a [...]]]></description>
			<content:encoded><![CDATA[<p>Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh:</p>
<blockquote><p>
During a recent password audit at the  Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin</p>
<p>When Paddy was asked why he had such a  long password: he replied &#8221;Bejazus! are yez f*ckin&#8217; stupid? The bank told me password had to be at least 8 characters long and include  one capital&#8221;</p>
<p>Don&#8217;t ever  think you can outwit the Irish!
</p></blockquote>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;bodytext=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;notes=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;annotation=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Secure%20Password%20Win%20%5BRandom%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D&amp;s=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Secure%20Password%20Win%20%5BRandom%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/gWCGnASIdYE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Google Responds to China’s Actions [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/Zyv8HgjBsiE/</link>
		<comments>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 05:51:38 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[cyberdouchery]]></category>
		<category><![CDATA[LiquidMatrix]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=93</guid>
		<description><![CDATA[UFC 1337: Google vs. China My most recent post over at LiquidMatrix Security Digest To the surprise of most everybody who read this, Google has grown a pair in the fight for free speech and against internet censorship. Well.. at least they say they are.. &#8230;the attempts over the past year to further limit free [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/01/google-china.jpg"><img class="aligncenter size-medium wp-image-8147" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2010/01/google-china-300x166.jpg" alt="" width="300" height="166" /></a><br />
UFC 1337: Google vs. China</p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>To the surprise of most everybody who read this, Google has grown a pair in the fight for free speech and against internet censorship. Well.. at least they say they are..</p>
<blockquote><p>&#8230;the attempts over the past year to further limit free speech on the web&#8211;have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.</p></blockquote>
<p>This comes after the apparent attack upon Google and other American organizations originating from China.</p>
<blockquote><p>In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident&#8211;albeit a significant one&#8211;was something quite different.</p></blockquote>
<p>As of the time I wrote this post <a href="http://www.google.cn">Google.cn</a> is still up, so no preemptive praise just yet. I&#8217;m going to be interested to hear what else pops up about this story in the near future.</p>
<p><a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">Read on</a></p>
<p>Some other insight so far:</p>
<p><a href="http://ha.ckers.org/blog/20100112/wait-google-i-thought-you-were-evil/">RSnake</a><br />
<a href="http://eshoo.house.gov/index.php?option=com_content&amp;task=view&amp;id=704&amp;Itemid=79">Rep. Eshoo Responds to Attack on Google</a></p>
<p>Cheers,<br />
Matt</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;bodytext=%0D%0AUFC%201337%3A%20Google%20vs.%20China%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ATo%20the%20surprise%20of%20most%20everybody%20who%20read%20this%2C%20Google%20has%20grown%20a%20pair%20in%20the%20fight%20for%20free%20speech%20and%20against%20internet%20censorship.%20Well..%20at%20least%20they%20sa" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;notes=%0D%0AUFC%201337%3A%20Google%20vs.%20China%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ATo%20the%20surprise%20of%20most%20everybody%20who%20read%20this%2C%20Google%20has%20grown%20a%20pair%20in%20the%20fight%20for%20free%20speech%20and%20against%20internet%20censorship.%20Well..%20at%20least%20they%20sa" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;t=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;annotation=%0D%0AUFC%201337%3A%20Google%20vs.%20China%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ATo%20the%20surprise%20of%20most%20everybody%20who%20read%20this%2C%20Google%20has%20grown%20a%20pair%20in%20the%20fight%20for%20free%20speech%20and%20against%20internet%20censorship.%20Well..%20at%20least%20they%20sa" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=%0D%0AUFC%201337%3A%20Google%20vs.%20China%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ATo%20the%20surprise%20of%20most%20everybody%20who%20read%20this%2C%20Google%20has%20grown%20a%20pair%20in%20the%20fight%20for%20free%20speech%20and%20against%20internet%20censorship.%20Well..%20at%20least%20they%20sa" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;title=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F&amp;t=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D&amp;s=%0D%0AUFC%201337%3A%20Google%20vs.%20China%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ATo%20the%20surprise%20of%20most%20everybody%20who%20read%20this%2C%20Google%20has%20grown%20a%20pair%20in%20the%20fight%20for%20free%20speech%20and%20against%20internet%20censorship.%20Well..%20at%20least%20they%20sa" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Google%20Responds%20to%20China%27s%20Actions%20%5BLiquidMatrix%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fgoogle-responds-to-chinas-actions-liquidmatrix%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/Zyv8HgjBsiE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/01/google-responds-to-chinas-actions-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>IsleSec – January</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/bCxrNp1lymw/</link>
		<comments>http://www.mattjaysecurity.com/2010/01/islesec-january/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:33:12 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[IsleSec]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=88</guid>
		<description><![CDATA[Don&#8217;t have any original content to add just hoping to spread the word. A quick re-blog of Kees Leune&#8217;s post about this month&#8217;s IsleSec meetup. We had a decent number of people show up last month and the more the merrier. &#8220;After our (first) meeting last month, Matt Johansen and myself have decided to give [...]]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t have any original content to add just hoping to spread the word. A quick re-blog of <a href="http://www.leune.org/blog/">Kees Leune&#8217;s</a> post about this month&#8217;s <a href="http://www.leune.org/blog/kees/2010/01/islesec-every-third-wednesday.html">IsleSec meetup.</a> We had a decent number of people show up last month and the more the merrier.</p>
<p>&#8220;After our (first) meeting last month, <a href="../#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed">Matt Johansen</a> and myself have decided to give IsleSec a continuation.</p>
<p>IsleSec builds on the tradition of popular <a href="http://www.citysec.org/">CitySec</a> meetings, such as NYSEC, BeanSec, etc. and it provides an informal place for people to hang out, have a bite, drink beer (or something else), and chat about security-related issues.</p>
<p>We invite everyone with an interest in information security, ranging from techies to security executives to join us. Yes, even security auditors are welcome <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Vendors can come too, but please do not use the meet-up as a place to sell your wares. If you want to car pool, or take the train out to the meeting with company, please drop a note on our general access <a href="http://groups.google.com/group/li-infosec/about?pli=1">email group</a>.</p>
<p>IsleSec meetings will be held every third Wednesday of the month in <a href="http://www.yelp.com/biz/croxley-ale-house-farmingdale">Croxley</a>&#8216;s Ale House in Farmingdale, NY. Croxley&#8217;s is located next to the <a href="http://mta.info/lirr/html/ttn/farmingd.htm">train</a> station and is easily <a href="http://maps.google.com/maps?f=d&amp;source=s_d&amp;saddr=&amp;daddr=190+Main+Street,+Farmingdale,+NY+11735-2618&amp;hl=en&amp;geocode=&amp;mra=ls&amp;sll=40.694916,-73.714624&amp;sspn=0.675741,1.079407&amp;ie=UTF8&amp;t=h&amp;z=16">reachable</a> by car from Nassau and Suffolk.</p>
<p>This month&#8217;s meeting will be on January 20, 2010. The meetings typically start when the first person shows up (somewhere between 6pm and 7pm) and continue until the last person leaves (somewhere between 10pm and 11pm). Sponsors are more than welcome to <a href="mailto:kees@leune.org#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed">contact me</a> to arrange how to give us free beer.&#8221;</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January&amp;bodytext=Don%27t%20have%20any%20original%20content%20to%20add%20just%20hoping%20to%20spread%20the%20word.%20A%20quick%20re-blog%20of%20Kees%20Leune%27s%20post%20about%20this%20month%27s%20IsleSec%20meetup.%20We%20had%20a%20decent%20number%20of%20people%20show%20up%20last%20month%20and%20the%20more%20the%20merrier.%0D%0A%0D%0A%22After%20our%20%28first%29%20meeting" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January&amp;notes=Don%27t%20have%20any%20original%20content%20to%20add%20just%20hoping%20to%20spread%20the%20word.%20A%20quick%20re-blog%20of%20Kees%20Leune%27s%20post%20about%20this%20month%27s%20IsleSec%20meetup.%20We%20had%20a%20decent%20number%20of%20people%20show%20up%20last%20month%20and%20the%20more%20the%20merrier.%0D%0A%0D%0A%22After%20our%20%28first%29%20meeting" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;t=IsleSec%20-%20January" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January&amp;annotation=Don%27t%20have%20any%20original%20content%20to%20add%20just%20hoping%20to%20spread%20the%20word.%20A%20quick%20re-blog%20of%20Kees%20Leune%27s%20post%20about%20this%20month%27s%20IsleSec%20meetup.%20We%20had%20a%20decent%20number%20of%20people%20show%20up%20last%20month%20and%20the%20more%20the%20merrier.%0D%0A%0D%0A%22After%20our%20%28first%29%20meeting" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Don%27t%20have%20any%20original%20content%20to%20add%20just%20hoping%20to%20spread%20the%20word.%20A%20quick%20re-blog%20of%20Kees%20Leune%27s%20post%20about%20this%20month%27s%20IsleSec%20meetup.%20We%20had%20a%20decent%20number%20of%20people%20show%20up%20last%20month%20and%20the%20more%20the%20merrier.%0D%0A%0D%0A%22After%20our%20%28first%29%20meeting" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=IsleSec%20-%20January&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;title=IsleSec%20-%20January" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F&amp;t=IsleSec%20-%20January&amp;s=Don%27t%20have%20any%20original%20content%20to%20add%20just%20hoping%20to%20spread%20the%20word.%20A%20quick%20re-blog%20of%20Kees%20Leune%27s%20post%20about%20this%20month%27s%20IsleSec%20meetup.%20We%20had%20a%20decent%20number%20of%20people%20show%20up%20last%20month%20and%20the%20more%20the%20merrier.%0D%0A%0D%0A%22After%20our%20%28first%29%20meeting" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=IsleSec%20-%20January%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F01%2Fislesec-january%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/bCxrNp1lymw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/01/islesec-january/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2010/01/islesec-january/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Introducting IsleSec</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/oUxYfYzzS4s/</link>
		<comments>http://www.mattjaysecurity.com/2009/10/introducting-islesec/#comments</comments>
		<pubDate>Sun, 25 Oct 2009 22:38:34 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[IsleSec]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=84</guid>
		<description><![CDATA[For those of you who are familiar with CitySec meetups, I&#8217;ve been pondering starting up IsleSec here on Long Island. I know there is NYSec in the city but it is a hike for us islanders. For those of you unfamilar with CitySec meetups, they are informal meetups of local security professionals at whatever bar [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.mattjaysecurity.com/wp-content/uploads/2009/10/Croxley_Ale_House_NY.png" alt="Croxley_Ale_House_NY" title="Croxley_Ale_House_NY" width="200" height="170" class="alignleft size-full wp-image-83" />For those of you who are familiar with <a href="http://www.citysec.org/">CitySec</a> meetups, I&#8217;ve been pondering starting up IsleSec here on Long Island. I know there is NYSec in the city but it is a hike for us islanders.</p>
<p>For those of you unfamilar with CitySec meetups, they are informal meetups of local security professionals at whatever bar will tolearate us. It is a great way to meet others in the community and grow your professional network. To quote Chris Hoff while talking about <a href="http://rationalsecurity.typepad.com/blog/beansec/">BeanSec</a> up in Boston: &#8220;Unlike other meetings, you will not be expected to pay dues, “join up”, present a zero-day exploit, or defend your dissertation to attend.&#8221; Show up, get some wings, drink some beer and add to your business card collection.</p>
<p>I wanted to write a quick post to see if there is any interest around to meet up to make sure I&#8217;m not sitting at a bar drinking alone.  Feel free to post comments here or hop on the <a href="http://groups.google.com/group/li-infosec/about?pli=1">Google Group</a> to express interest.</p>
<p>Judging by people&#8217;s location who are interested we can adjust the bar location as necessary. I vote we start at <a href="http://www.bbqincrvc.com/Croxley/Home.html">Croxley&#8217;s Ale House</a> in Farmingdale. Following the model of other CitySec meetings we will start by meeting the third Wednesday of every month which works out perfectly because Croxley&#8217;s has a 10 cent wing special on Wednesdays.</p>
<p>So what this all comes down to is that the first IsleSec meetup will be at 6:00 PM on Novermber 18th at Croxley&#8217;s Ale House 190 Main St Farmingdale, NY 11735 (516) 293-7700. (<a href="http://maps.google.com/maps?oe=utf-8&#038;um=1&#038;ie=UTF-8&#038;cid=0,0,11661600445623871080&#038;fb=1&#038;hq=croxleys+ale+house&#038;hnear=farmingdale&#038;gl=us&#038;daddr=190+Main+St,+Farmingdale,+NY+11735&#038;geocode=5183260312671746112,40.733370,-73.445948&#038;ei=J8TkSovGJJaMtgfqkeGzAQ&#038;sa=X&#038;oi=local_result&#038;ct=directions-to&#038;resnum=1&#038;ved=0CA8QngIwAA">Get Directions</a>).</p>
<p>If you plan on coming please leave a comment or send out a message in the Google Group so that I know I should show up. (I&#8217;ll probably show up anyway just in case but it would be nice to know ahead of time.)</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec&amp;bodytext=For%20those%20of%20you%20who%20are%20familiar%20with%20CitySec%20meetups%2C%20I%27ve%20been%20pondering%20starting%20up%20IsleSec%20here%20on%20Long%20Island.%20I%20know%20there%20is%20NYSec%20in%20the%20city%20but%20it%20is%20a%20hike%20for%20us%20islanders.%0D%0A%0D%0AFor%20those%20of%20you%20unfamilar%20with%20CitySec%20meetups%2C%20they%20are%20inf" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec&amp;notes=For%20those%20of%20you%20who%20are%20familiar%20with%20CitySec%20meetups%2C%20I%27ve%20been%20pondering%20starting%20up%20IsleSec%20here%20on%20Long%20Island.%20I%20know%20there%20is%20NYSec%20in%20the%20city%20but%20it%20is%20a%20hike%20for%20us%20islanders.%0D%0A%0D%0AFor%20those%20of%20you%20unfamilar%20with%20CitySec%20meetups%2C%20they%20are%20inf" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;t=Introducting%20IsleSec" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec&amp;annotation=For%20those%20of%20you%20who%20are%20familiar%20with%20CitySec%20meetups%2C%20I%27ve%20been%20pondering%20starting%20up%20IsleSec%20here%20on%20Long%20Island.%20I%20know%20there%20is%20NYSec%20in%20the%20city%20but%20it%20is%20a%20hike%20for%20us%20islanders.%0D%0A%0D%0AFor%20those%20of%20you%20unfamilar%20with%20CitySec%20meetups%2C%20they%20are%20inf" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=For%20those%20of%20you%20who%20are%20familiar%20with%20CitySec%20meetups%2C%20I%27ve%20been%20pondering%20starting%20up%20IsleSec%20here%20on%20Long%20Island.%20I%20know%20there%20is%20NYSec%20in%20the%20city%20but%20it%20is%20a%20hike%20for%20us%20islanders.%0D%0A%0D%0AFor%20those%20of%20you%20unfamilar%20with%20CitySec%20meetups%2C%20they%20are%20inf" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Introducting%20IsleSec&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;title=Introducting%20IsleSec" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F&amp;t=Introducting%20IsleSec&amp;s=For%20those%20of%20you%20who%20are%20familiar%20with%20CitySec%20meetups%2C%20I%27ve%20been%20pondering%20starting%20up%20IsleSec%20here%20on%20Long%20Island.%20I%20know%20there%20is%20NYSec%20in%20the%20city%20but%20it%20is%20a%20hike%20for%20us%20islanders.%0D%0A%0D%0AFor%20those%20of%20you%20unfamilar%20with%20CitySec%20meetups%2C%20they%20are%20inf" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Introducting%20IsleSec%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F10%2Fintroducting-islesec%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/oUxYfYzzS4s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/10/introducting-islesec/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/10/introducting-islesec/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>Metasploit Unleashed – Mastering the Framework [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/Mcgpdf9Cvvg/</link>
		<comments>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 14:42:45 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Educational]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=79</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest As of earlier tonight a project a few months in the making has finally been unleashed (pun intended). Thanks to the great guys over at Offensive Security and whoever&#8217;s awesome idea it was to team them up with the Metasploit guys, a new resource called Metasploit [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/metasploit-unleashed.png"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/metasploit-unleashed-300x148.png" alt="metasploit-unleashed" width="300" height="148" class="aligncenter size-medium wp-image-7478" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>As of earlier tonight a project a few months in the making has finally been unleashed (pun intended).  Thanks to the great guys over at Offensive Security and whoever&#8217;s awesome idea it was to team them up with the Metasploit guys, a new resource called <a href="http://www.offensive-security.com/metasploit-unleashed/">Metasploit Unleashed &#8211; Mastering the Framework</a> is now online. </p>
<p>For those of you who don&#8217;t know, <a href="http://www.offensive-security.com/">Offensive-Security</a> are the people behind the <a href="http://www.offensive-security.com/information-security-training.php">Penetration Testing with Backtrack Trainings</a>.  Now they have teamed up with HD Moore and the <a href="http://metasploit.com/framework/">Metasploit</a> folks and put together the most comprehensive Metasploit training out there.</p>
<p>Best of all, it is free and for a good cause.</p>
<blockquote><p>
&#8220;This free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework.&#8221;
</p></blockquote>
<p>To really drive the point home, they decided 2 all stars weren&#8217;t enough and threw in a 3rd team mate with Johnny Long and <a href="http://www.hackersforcharity.org/">Hackers For Charity.</a></p>
<blockquote><p>
If you enjoy it and find it useful, we ask that you make a donation to the HFC (Hackers For Charity), $4.00 will feed a child for a month, so any contribution is welcome. We hope you enjoy this course as much as we enjoyed making it.</p>
<p>The &#8220;full&#8221; version of this course includes a PDF guide (it has the same material as the wiki) and a set of flash videos which walk you though the modules. You may purchase these materials from the Offensive Security Training page. All proceeds from this course go to HFC.
</p></blockquote>
<p>I highly recommend if you are interested in learning more about the Metasploit Framework that you float over this way and even if you&#8217;re not interested you should absolutely make a donation to HFC none the less.</p>
<p>Get it while its hot!</p>
<p>Matt</p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;bodytext=%0D%0A%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0A%0D%0AAs%20of%20earlier%20tonight%20a%20project%20a%20few%20months%20in%20the%20making%20has%20finally%20been%20unleashed%20%28pun%20intended%29.%20%20Thanks%20to%20the%20great%20guys%20over%20at%20Offensive%20Security%20and%20whoever%27s%20awesome%20idea%20" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;notes=%0D%0A%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0A%0D%0AAs%20of%20earlier%20tonight%20a%20project%20a%20few%20months%20in%20the%20making%20has%20finally%20been%20unleashed%20%28pun%20intended%29.%20%20Thanks%20to%20the%20great%20guys%20over%20at%20Offensive%20Security%20and%20whoever%27s%20awesome%20idea%20" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;t=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;annotation=%0D%0A%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0A%0D%0AAs%20of%20earlier%20tonight%20a%20project%20a%20few%20months%20in%20the%20making%20has%20finally%20been%20unleashed%20%28pun%20intended%29.%20%20Thanks%20to%20the%20great%20guys%20over%20at%20Offensive%20Security%20and%20whoever%27s%20awesome%20idea%20" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=%0D%0A%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0A%0D%0AAs%20of%20earlier%20tonight%20a%20project%20a%20few%20months%20in%20the%20making%20has%20finally%20been%20unleashed%20%28pun%20intended%29.%20%20Thanks%20to%20the%20great%20guys%20over%20at%20Offensive%20Security%20and%20whoever%27s%20awesome%20idea%20" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;title=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F&amp;t=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D&amp;s=%0D%0A%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0A%0D%0AAs%20of%20earlier%20tonight%20a%20project%20a%20few%20months%20in%20the%20making%20has%20finally%20been%20unleashed%20%28pun%20intended%29.%20%20Thanks%20to%20the%20great%20guys%20over%20at%20Offensive%20Security%20and%20whoever%27s%20awesome%20idea%20" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=Metasploit%20Unleashed%20-%20Mastering%20the%20Framework%20%5BLiquidMatrix%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Fmetasploit-unleashed-mastering-the-framework-liquidmatrix%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/Mcgpdf9Cvvg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/09/metasploit-unleashed-mastering-the-framework-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
		<item>
		<title>RBS WordPay SQL Injection [LiquidMatrix]</title>
		<link>http://feedproxy.google.com/~r/MattjaySecurity/~3/wklPCm1GqOo/</link>
		<comments>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:06:24 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=73</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230; RBS WordPay, a system that processes millions of payments daily has been compromised. It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1-298x300.jpg" alt="Kilts" title="Kilts" width="298" height="300" class="aligncenter size-medium wp-image-7326" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230;</p>
<p>RBS WordPay, a system that processes millions of payments daily has been compromised.  It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts of juicy information to whoever asks for it. Unu has a great write up of the vulnerability with plenty of juicy screenshots on his <a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-acces/">blog</a>.</p>
<p>Here is a real kicker for you:</p>
<blockquote><p>
The next picture is awesome, but really what we see. In the picture appear user, host and password in mysql database, user table. But look well to the first user webphp, surrounded me. We have % to host and NOTHING in the password !!! I mean we have a user password NULL and % to host, that means that we can log on his account, the MySQL server without password, from any IP.
</p></blockquote>
<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi-300x217.jpg" alt="RBS_SQLi" title="RBS_SQLi" width="300" height="217" class="aligncenter size-medium wp-image-7324" /></a></p>
<p>There is also some fun poked at Bill Gates which never hurts.</p>
<p><a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-access/">Article Link</a></p>



Share and Enjoy:


	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;bodytext=%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ARoyal%20Bank%20of%20Scottland%20Group%20might%20be%20feeling%20a%20bit%20exposed%20this%20afternoon...%0D%0A%0D%0ARBS%20WordPay%2C%20a%20system%20that%20processes%20millions%20of%20payments%20daily%20has%20been%20compromised.%20%20It%20looks%20like%20the" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;notes=%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ARoyal%20Bank%20of%20Scottland%20Group%20might%20be%20feeling%20a%20bit%20exposed%20this%20afternoon...%0D%0A%0D%0ARBS%20WordPay%2C%20a%20system%20that%20processes%20millions%20of%20payments%20daily%20has%20been%20compromised.%20%20It%20looks%20like%20the" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;t=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;annotation=%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ARoyal%20Bank%20of%20Scottland%20Group%20might%20be%20feeling%20a%20bit%20exposed%20this%20afternoon...%0D%0A%0D%0ARBS%20WordPay%2C%20a%20system%20that%20processes%20millions%20of%20payments%20daily%20has%20been%20compromised.%20%20It%20looks%20like%20the" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ARoyal%20Bank%20of%20Scottland%20Group%20might%20be%20feeling%20a%20bit%20exposed%20this%20afternoon...%0D%0A%0D%0ARBS%20WordPay%2C%20a%20system%20that%20processes%20millions%20of%20payments%20daily%20has%20been%20compromised.%20%20It%20looks%20like%20the" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;title=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F&amp;t=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D&amp;s=%0D%0A%0D%0AMy%20most%20recent%20post%20over%20at%20LiquidMatrix%20Security%20Digest%0D%0A%0D%0ARoyal%20Bank%20of%20Scottland%20Group%20might%20be%20feeling%20a%20bit%20exposed%20this%20afternoon...%0D%0A%0D%0ARBS%20WordPay%2C%20a%20system%20that%20processes%20millions%20of%20payments%20daily%20has%20been%20compromised.%20%20It%20looks%20like%20the" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=RBS%20WordPay%20SQL%20Injection%20%5BLiquidMatrix%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F09%2Frbs-wordpay-sql-injection-liquidmatrix%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/><img src="http://feeds.feedburner.com/~r/MattjaySecurity/~4/wklPCm1GqOo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</feedburner:origLink></item>
	</channel>
</rss>

