<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Zen One</title><link>http://blog.zenone.org/</link><description>Blog of Steve Zenone; Information Security Professional, Ubuntu Supporter, Mac User, MythTV Convert, Music Aficionado, Volunteer Firefighter, Trail Runner, Mountain Biker, ...</description><language>en</language><managingEditor>noreply@blogger.com (Steve Zenone)</managingEditor><lastBuildDate>Thu, 05 Nov 2009 16:48:03 PST</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">95</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><itunes:owner><itunes:email>noreply@blogger.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:subtitle>Blog of Steve Zenone; Information Security Professional, Ubuntu Supporter, Mac User, MythTV Convert, Music Aficionado, Volunteer Firefighter, Trail Runner, Mountain Biker, ...</itunes:subtitle><geo:lat>36.980556</geo:lat><geo:long>-122.046031</geo:long><creativeCommons:license>http://creativecommons.org/licenses/by/2.0/</creativeCommons:license><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/morphic" type="application/rss+xml" /><feedburner:emailServiceId>morphic</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Cyberspace Security Review</title><link>http://feedproxy.google.com/~r/morphic/~3/W6-oG6fYfuo/cyberspace-secuity-review.html</link><category>Strategy</category><category>Penetration Testing</category><category>attack</category><category>InfoSec</category><category>Government</category><category>Research and Development</category><category>hacker</category><category>Information Security</category><category>Risk</category><category>Process</category><category>White House</category><category>Investigation</category><category>Policy</category><category>Security</category><category>compliance</category><category>Cyberspace</category><category>Obama</category><category>Vulnerability</category><category>Incident Response</category><category>Network Security</category><category>Pentest</category><category>Intrusion Detection</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Sun, 31 May 2009 15:01:45 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7377562367280876067</guid><description>&lt;p&gt;On Friday (May 29, 2009) President Obama announced the nation’s plan to defend against attacks on the nation's computer networks; a “strategic national asset.” This plan includes appointing a Cyber-Security Chief, whom he has not yet chosen, in the White House. Obama will sign a classified order within the coming weeks that will create the military cybercommand.&lt;/p&gt;
&lt;p&gt;He stated that cyber-criminals have cost US citizens over $8 billion worth of stolen data and that the figure worldwide was up to $1 trillion.&lt;/p&gt;
&lt;p&gt;The announcement came with the release of the &lt;a href="http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf" target="_blank"&gt;Cyberspace Security Review&lt;/a&gt;, a 76 page document that had 60-days to be completed from the date of the initial request. The Cyberspace Security Review explains how the US intends to secure its critical network infrastructure. It was stated that the review was necessary because, “&lt;em&gt;America's failure to protect cyberspace is one of the most urgent national security problems facing the new administration”&lt;/em&gt;, and that, “&lt;em&gt;our digital infrastructure has already suffered intrusions that have allowed criminals to steal hundreds of millions of dollars and nation-states and other entities to steal intellectual property and sensitive military information&lt;/em&gt;.”&lt;/p&gt;
&lt;p&gt;The Cyberspace Security Review made the following 10 recommendations for near-term action:&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Appoint a cybersecurity policy official responsible for coordinating the Nation’s cybersecurity policies and activities; establish a strong NSC directorate, under the direction of the cybersecurity policy official dual-hatted to the NSC and the NEC, to coordinate interagency development of cybersecurity-related strategy and policy.&lt;/li&gt;

  &lt;li&gt;Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure. This strategy should include continued evaluation of CNCI activities and, where appropriate, build on its successes.&lt;/li&gt;

  &lt;li&gt;Designate cybersecurity as one of the President’s key management priorities and establish performance metrics.&lt;/li&gt;

  &lt;li&gt;Designate a privacy and civil liberties official to the NSC cybersecurity directorate.&lt;/li&gt;

  &lt;li&gt;Convene appropriate interagency mechanisms to conduct interagency-cleared legal analyses of priority cybersecurity-related issues identified during the policy-development process and formulate coherent unified policy guidance that clarifies roles, responsibilities, and the application of agency authorities for cybersecurity-related activities across the Federal government.&lt;/li&gt;

  &lt;li&gt;Initiate a national public awareness and education campaign to promote cybersecurity.&lt;/li&gt;

  &lt;li&gt;Develop U.S. Government positions for an international cybersecurity policy framework and strengthen our international partnerships to create initiatives that address the full range of activities, policies, and opportunities associated with cybersecurity.&lt;/li&gt;

  &lt;li&gt;Prepare a cybersecurity incident response plan; initiate a dialog to enhance public-private partnerships with an eye toward streamlining, aligning, and providing resources to optimize their contribution and engagement.&lt;/li&gt;

  &lt;li&gt;In collaboration with other EOP entities, develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience, and trustworthiness of digital infrastructure; provide the research community access to event data to facilitate developing tools, testing theories, and identifying workable solutions.&lt;/li&gt;

  &lt;li&gt;Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;What is promising about the Review is that there's repeated focus on &lt;em&gt;outcomes&lt;/em&gt; as opposed to the &lt;em&gt;inputs&lt;/em&gt;. Too often forward progress is hindered by the inefficient efforts of trying to define &lt;em&gt;process&lt;/em&gt; before goals and objectives are clearly defined and understood. Rather, the Review consistently attempts to make it clear what the strategic outcomes are, and from those objectives, the development of process will be guided.&lt;/p&gt;
&lt;p&gt;The Review also states, “&lt;em&gt;Other structures will be needed to help ensure that civil liberties and privacy rights are protected.”&lt;/em&gt; The inclusion to help protect our privacy and civil liberties is an indication of the balanced intention of the plan.&lt;/p&gt;
&lt;p&gt;Money will also be set aside for research and development of security technologies, from which there will be significant opportunity.&lt;/p&gt;
&lt;p&gt;What I'm not certain about is the overall effectiveness the Cyber-Security Chief will have. Specifically, the position will not have direct access to the president. As a result, this position may not be high-level enough to prevent the almost certain bureaucratic nonsense, internal bickering and games that could waste millions/billions of dollars.&lt;/p&gt;
&lt;p&gt;Though the Review solely focusses on defensive measures, I'm also curious what efforts are underway, if any, towards the development and potential use of cyberweapons.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Overall, the document doesn't suggest that there will be any major changes that will affect the private sector within the near term. The Review recommends specific changes to the direction of future US policies. Within the mid-term I imagine that lawmakers will develop regulations that will require the sharing of security incident data from the private sector with the government, presumably tempered with the commitment to ensure civil liberties. I anticipate that we will also see more emphasis put towards penetration testing and incident response.&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7377562367280876067?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=W6-oG6fYfuo:VthIh8ua25M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=W6-oG6fYfuo:VthIh8ua25M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=W6-oG6fYfuo:VthIh8ua25M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=W6-oG6fYfuo:VthIh8ua25M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=W6-oG6fYfuo:VthIh8ua25M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=W6-oG6fYfuo:VthIh8ua25M:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/W6-oG6fYfuo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-31T15:01:45.239-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><media:content url="http://feedproxy.google.com/~r/morphic/~5/sncgHjX2wz4/Cyberspace_Policy_Review_final.pdf" fileSize="727551" type="application/pdf" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> On Friday (May 29, 2009) President Obama announced the nation’s plan to defend against attacks on the nation's computer networks; a “strategic national asset.” This plan includes appointing a Cyber-Security Chief, whom he has not yet chosen, in the White</itunes:subtitle><itunes:author>noreply@blogger.com (Steve Zenone)</itunes:author><itunes:summary> On Friday (May 29, 2009) President Obama announced the nation’s plan to defend against attacks on the nation's computer networks; a “strategic national asset.” This plan includes appointing a Cyber-Security Chief, whom he has not yet chosen, in the White House. Obama will sign a classified order within the coming weeks that will create the military cybercommand. He stated that cyber-criminals have cost US citizens over $8 billion worth of stolen data and that the figure worldwide was up to $1 trillion. The announcement came with the release of the Cyberspace Security Review, a 76 page document that had 60-days to be completed from the date of the initial request. The Cyberspace Security Review explains how the US intends to secure its critical network infrastructure. It was stated that the review was necessary because, “America's failure to protect cyberspace is one of the most urgent national security problems facing the new administration”, and that, “our digital infrastructure has already suffered intrusions that have allowed criminals to steal hundreds of millions of dollars and nation-states and other entities to steal intellectual property and sensitive military information.” The Cyberspace Security Review made the following 10 recommendations for near-term action: Appoint a cybersecurity policy official responsible for coordinating the Nation’s cybersecurity policies and activities; establish a strong NSC directorate, under the direction of the cybersecurity policy official dual-hatted to the NSC and the NEC, to coordinate interagency development of cybersecurity-related strategy and policy. Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure. This strategy should include continued evaluation of CNCI activities and, where appropriate, build on its successes. Designate cybersecurity as one of the President’s key management priorities and establish performance metrics. Designate a privacy and civil liberties official to the NSC cybersecurity directorate. Convene appropriate interagency mechanisms to conduct interagency-cleared legal analyses of priority cybersecurity-related issues identified during the policy-development process and formulate coherent unified policy guidance that clarifies roles, responsibilities, and the application of agency authorities for cybersecurity-related activities across the Federal government. Initiate a national public awareness and education campaign to promote cybersecurity. Develop U.S. Government positions for an international cybersecurity policy framework and strengthen our international partnerships to create initiatives that address the full range of activities, policies, and opportunities associated with cybersecurity. Prepare a cybersecurity incident response plan; initiate a dialog to enhance public-private partnerships with an eye toward streamlining, aligning, and providing resources to optimize their contribution and engagement. In collaboration with other EOP entities, develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience, and trustworthiness of digital infrastructure; provide the research community access to event data to facilitate developing tools, testing theories, and identifying workable solutions. Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation. What is promising about the Review is that there's repeated focus on outcomes as opposed to the inputs. Too often forward progress is hindered by the inefficient efforts of trying to define process before goals and objectives are clearly defined and understood. Rather, the Review consistently attempts to make it clear what the strategic outcomes are, and from those objectives, the development of process will </itunes:summary><itunes:keywords>Strategy, Penetration Testing, attack, InfoSec, Government, Research and Development, hacker, Information Security, Risk, Process, White House, Investigation, Policy, Security, compliance, Cyberspace, Obama, Vulnerability, Incident Response, Network Security, Pentest, Intrusion Detection</itunes:keywords><feedburner:origLink>http://blog.zenone.org/2009/05/cyberspace-secuity-review.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/morphic/~5/sncgHjX2wz4/Cyberspace_Policy_Review_final.pdf" length="727551" type="application/pdf" /><feedburner:origEnclosureLink>http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf</feedburner:origEnclosureLink></item><item><title>How ITIL Can Improve Information Security</title><link>http://feedproxy.google.com/~r/morphic/~3/n2c2MY3yjjE/how-itil-can-improve-information.html</link><category>Financial Management</category><category>ITIL</category><category>Risk Analysis</category><category>Strategic</category><category>OLA</category><category>Tactical</category><category>Information Security</category><category>SLA</category><category>IT Services</category><category>Security</category><category>Policies</category><category>Problem Management</category><category>Procedures</category><category>IT Organization</category><category>Incident Management</category><category>Release Management</category><category>Service Level Management</category><category>Instructions</category><category>Processes</category><category>Availability Management</category><category>Configuration Management</category><category>Operational</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Wed, 27 May 2009 08:59:07 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7030134522800038580</guid><description>&lt;p&gt;By: Steven Weil&lt;/p&gt;
&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p class="text"&gt;ITIL - the Information Technology Infrastructure Library - is a set of best practices and guidelines that define an integrated, process-based approach for managing information technology services. ITIL can be applied across almost every type of IT environment.&lt;/p&gt;
&lt;p class="text"&gt;Interest in and adoption of ITIL has been steadily increasing throughout the world; the numerous public and private organizations that have adopted it include Proctor &amp;amp; Gamble, Washington Mutual, Southwest Airlines, Hershey Foods, and the Internal Revenue Service. In addition to the often touted benefits of ITIL - aligning IT with the needs of the business, improving service quality, decreasing the costs of IT service delivery and support - the framework can aid the information security professional both directly (there is a specific Security Management process) and indirectly.&lt;/p&gt;
&lt;p class="text"&gt;This article will provide a general overview of ITIL and discuss how ITIL can improve how organizations implement and manage information security.&lt;/p&gt;
&lt;h2&gt;ITIL overview&lt;/h2&gt;
&lt;p class="text"&gt;ITIL began in the 1980s as an attempt by the British government to develop an approach for efficient and cost-effective use of its many IT resources. Using the experiences and expertise of successful IT professionals, a British government agency developed and released a series of best-practice books, each focusing on a different IT process. Since then, ITIL has become an entire industry of organizations, tools, consulting services, related frameworks, and publications. Currently in the public domain and still evolving, the 44-volume set of ITIL guidelines has been consolidated into 8 core books.&lt;/p&gt;
&lt;p class="text"&gt;When most people discuss ITIL, they refer to the ITIL Service Support and Service Delivery books. These contain a set of structured best practices and standard methodologies for core IT operational processes such as Change, Release, and Configuration Management, as well as Incident, Problem, Capacity, and Availability Management.&lt;/p&gt;
&lt;p class="text"&gt;ITIL stresses service quality and focuses on how IT services can be efficiently and cost-effectively provided and supported. In the ITIL framework, the business units within an organization who commission and pay for IT services (e.g. Human Resources, Accounting), are considered to be "customers" of IT services. The IT organization is considered to be a service provider for the customers.&lt;/p&gt;
&lt;p class="text"&gt;ITIL defines the objectives, activities, inputs, and outputs of many of the processes found in an IT organization. It primarily focuses on what processes are needed to ensure high quality IT services; however, ITIL &lt;strong&gt;&lt;em&gt;does not&lt;/em&gt;&lt;/strong&gt; provide specific, detailed descriptions about how the processes should be implemented, as they will be different in each organization. In other words, ITIL tells an organization what to do, not how to do it.&lt;/p&gt;
&lt;p class="text"&gt;The ITIL framework is typically implemented in stages, with additional processes added in a continuous service improvement program.&lt;/p&gt;
&lt;p class="text"&gt;Organizations can benefit in several important ways from ITIL:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;IT services become more customer-focused&lt;/li&gt;

  &lt;li&gt;The quality and cost of IT services are better managed&lt;/li&gt;

  &lt;li&gt;The IT organization develops a clearer structure and becomes more efficient&lt;/li&gt;

  &lt;li&gt;IT changes are easier to manage&lt;/li&gt;

  &lt;li&gt;There is a uniform frame of reference for internal communication about IT&lt;/li&gt;

  &lt;li&gt;IT procedures are standardized and integrated&lt;/li&gt;

  &lt;li&gt;Demonstrable and auditable performance measurements are defined&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;ITIL details&lt;/h2&gt;
&lt;p class="text"&gt;ITIL takes a process-based approach to managing and providing IT services; IT activities are divided into processes, each of which has three levels:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Strategic&lt;/em&gt;: An organization's objectives are determined, along with an outline of methods to achieve the objectives.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Tactical&lt;/em&gt;: The strategy is translated into an appropriate organizational structure and specific plans that describe which processes have to be executed, what assets have to be deployed, and what the outcome(s) of the processes should be.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Operational&lt;/em&gt;: The tactical plans are executed. Strategic objectives are achieved within a specified time.&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="text"&gt;A description of each of the numerous IT processes covered by ITIL is beyond the scope of this article. What follows are brief, general descriptions of the ITIL processes that, along with the Security Management process, have a significant relationship with information security. Each of these areas is a set of best practices:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Configuration Management&lt;/em&gt;: Best practices for controlling production configurations (for example, standardization, status monitoring, asset identification). By identifying, controlling, maintaining and verifying the items that make up an organization's IT infrastructure, these practices ensure that there is a logical model of the infrastructure.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Incident Management&lt;/em&gt;: Best practices for resolving incidents (any event that causes an interruption to, or a reduction in, the quality of an IT service) and quickly restoring IT services. These practices ensure that normal service is restored as quickly as possible after an incident occurs.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Problem Management&lt;/em&gt;: Best practices for identifying the underlying cause(s) of IT incidents in order to prevent future recurrences. These practices seek to proactively prevent incidents and problems.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Change Management&lt;/em&gt;: Best practices for standardizing and authorizing the controlled implementation of IT changes. These practices ensure that changes are implemented with minimum adverse impact on IT services, and that they are traceable.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Release Management&lt;/em&gt;: Best practices for the release of hardware and software. These practices ensure that only tested and correct versions of authorized software and hardware are provided to IT customers.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Availability Management&lt;/em&gt;: Best practices for maintaining the availability of IT services guaranteed to a customer (for example, optimizing maintenance and design measures to minimize the number of incidents). These practices ensure that an IT infrastructure is reliable, resilient, and recoverable.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Financial Management&lt;/em&gt;: Best practices for understanding and managing the cost of providing IT services (for example, budgeting, IT accounting, charging). These practices ensure that IT services are provided efficiently, economically, and cost-effectively.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Service Level Management&lt;/em&gt;: Best practices for ensuring that agreements between IT and IT customers are specified and fulfilled. These practices ensure that IT services are maintained and improved through a cycle of agreeing, monitoring, reporting, and reviewing IT services.&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="text"&gt;There is also a Service Desk function that describes best practices for establishing and managing a central point of contact for users of IT services. Two of the Service Desk's most important responsibilities are monitoring incidents and communicating with users.&lt;/p&gt;
&lt;p class="text"&gt;Figure 1 depicts the above processes, showing how the Service Desk function serves as the single point of contact for the various service management processes.&lt;/p&gt;
&lt;p class="text"&gt;&lt;/p&gt;
&lt;div align="center"&gt;
  &lt;br /&gt;
  &lt;img src="http://farm3.static.flickr.com/2421/3569845519_a35c732459.jpg" width="400" alt="Figure 1" /&gt;
&lt;/div&gt;
&lt;div align="center"&gt;
  &lt;span style="font-size: 9px; font-weight: bold;"&gt;Figure 1. ITIL Service Management Processes&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;p class="text"&gt;More detailed information about the above processes and Service Desk function can be found in the references listed at the end of this article.&lt;/p&gt;
&lt;h2&gt;ITIL and information security&lt;/h2&gt;
&lt;p class="text"&gt;ITIL seeks to ensure that effective information security measures are taken at strategic, tactical, and operational levels. Information security is considered an iterative process that must be controlled, planned, implemented, evaluated, and maintained.&lt;/p&gt;
&lt;p class="text"&gt;ITIL breaks information security down into:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Policies - overall objectives an organization is attempting to achieve&lt;/li&gt;

  &lt;li&gt;Processes - what has to happen to achieve the objectives&lt;/li&gt;

  &lt;li&gt;Procedures - who does what and when to achieve the objectives&lt;/li&gt;

  &lt;li&gt;Work instructions - instructions for taking specific actions&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="text"&gt;It defines information security as a complete cyclical process with continuous review and improvement, as illustrated in Figure 2:&lt;/p&gt;
&lt;p class="text"&gt;&lt;/p&gt;
&lt;div align="center"&gt;
  &lt;br /&gt;
  &lt;img src="http://farm4.static.flickr.com/3395/3569865405_4f18ede607.jpg" width="400" alt="Figure 2" /&gt;
&lt;/div&gt;
&lt;div align="center"&gt;
  &lt;span style="font-size: 9px; font-weight: bold;"&gt;Figure 2. Information Security Process&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;p class="text"&gt;As some organizations look at Implementation and Monitoring as a single step, ITIL's Information Security Process can be described as a seven step process:&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Using risk analysis, IT customers identify their security requirements.&lt;/li&gt;

  &lt;li&gt;The IT department determines the feasibility of the requirements and compares them to the organization's minimum information security baseline.&lt;/li&gt;

  &lt;li&gt;The customer and IT organization negotiate and define a service level agreement (SLA) that includes definition of the information security requirements in measurable terms and specifies how they will be verifiably achieved.&lt;/li&gt;

  &lt;li&gt;Operational level agreements (OLAs), which provide detailed descriptions of how information security services will be provided, are negotiated and defined within the IT organization.&lt;/li&gt;

  &lt;li&gt;The SLA and OLAs are implemented and monitored.&lt;/li&gt;

  &lt;li&gt;Customers receive regular reports about the effectiveness and status of provided information security services.&lt;/li&gt;

  &lt;li&gt;The SLA and OLAs are modified as necessary.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Service level agreements&lt;/h2&gt;
&lt;p class="text"&gt;The SLA is a key part of the ITIL information security process. It is a formal, written agreement that documents the levels of service, including information security, that IT is responsible for providing. The SLA should include key performance indicators and performance criteria. Typical SLA information security statements should include:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Permitted methods of access&lt;/li&gt;

  &lt;li&gt;Agreements about auditing and logging&lt;/li&gt;

  &lt;li&gt;Physical security measures&lt;/li&gt;

  &lt;li&gt;Information security training and awareness for users&lt;/li&gt;

  &lt;li&gt;Authorization procedure for user access rights&lt;/li&gt;

  &lt;li&gt;Agreements on reporting and investigating security incidents&lt;/li&gt;

  &lt;li&gt;Expected reports and audits&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="text"&gt;In addition to SLAs and OLAs, ITIL defines three other types of information security documentation:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;em&gt;Information security policies&lt;/em&gt;: ITIL states that security policies should come from senior management and contain:&lt;/li&gt;

  &lt;li style="list-style: none"&gt;
    &lt;ol&gt;
      &lt;li&gt;Objectives and scope of information security for an organization&lt;/li&gt;

      &lt;li&gt;Goals and management principles for how information security is to be managed&lt;/li&gt;

      &lt;li&gt;Definition of roles and responsibilities for information security&lt;/li&gt;
    &lt;/ol&gt;
  &lt;/li&gt;

  &lt;li&gt;&lt;em&gt;Information security plans&lt;/em&gt;: describes how a policy is implemented for a specific information system and/or business unit.&lt;/li&gt;

  &lt;li&gt;&lt;em&gt;Information security handbooks&lt;/em&gt;: operational documents for day-to-day usage; they provide specific, detailed working instructions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Ten ways ITIL can improve information security&lt;/h2&gt;
&lt;p class="text"&gt;There are a number of important ways that ITIL can improve how organizations implement and manage information security.&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;ITIL keeps information security business and service focused. Too often, information security is perceived as a "cost center" or "hindrance" to business functions. With ITIL, business process owners and IT negotiate information security services; this ensures that the services are aligned with the business' needs.&lt;/li&gt;

  &lt;li&gt;ITIL can enable organizations to develop and implement information security in a structured, clear way based on best practices. Information security staff can move from "fire fighting" mode to a more structured and planned approach.&lt;/li&gt;

  &lt;li&gt;With its requirement for continuous review, ITIL can help ensure that information security measures maintain their effectiveness as requirements, environments, and threats change.&lt;/li&gt;

  &lt;li&gt;ITIL establishes documented processes and standards (such as SLAs and OLAs) that can be audited and monitored. This can help an organization understand the effectiveness of its information security program and comply with regulatory requirements (for example, HIPAA or Sarbanes Oxley).&lt;/li&gt;

  &lt;li&gt;ITIL provides a foundation upon which information security can build. It requires a number of best practices - such as Change Management, Configuration Management, and Incident Management - that can significantly improve information security. For example, a considerable number of information security issues are caused by inadequate change management, such as misconfigured servers.&lt;/li&gt;

  &lt;li&gt;ITIL enables information security staff to discuss information security in terms other groups can understand and appreciate. Many managers can't "relate" to low-level details about encryption or firewall rules, but they are likely to understand and appreciate ITIL concepts such as incorporating information security into defined processes for handling problems, improving service, and maintaining SLAs. ITIL can help managers understand that information security is a key part of having a successful, well-run organization.&lt;/li&gt;

  &lt;li&gt;The organized ITIL framework prevents the rushed, disorganized implementation of information security measures. ITIL requires designing and building consistent, measurable information security measures into IT services rather than after-the-fact or after an incident. This ultimately saves time, money, and effort.&lt;/li&gt;

  &lt;li&gt;The reporting required by ITIL keeps an organization's management well informed about the effectiveness of their organization's information security measures. The reporting also allows management to make informed decisions about the risks their organization has.&lt;/li&gt;

  &lt;li&gt;ITIL defines roles and responsibilities for information security. During an incident, it's clear who will respond and how they will do so.&lt;/li&gt;

  &lt;li&gt;ITIL establishes a common language for discussing information security. This can allow information security staff to communicate more effectively with internal and external business partners, such as an organization's outsourced security services.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Implementing ITIL&lt;/h2&gt;
&lt;p class="text"&gt;ITIL does not typically start with IT - it is usually initiated by senior management such as the CEO or CIO. As an information security professional, however, you can add value by bringing ITIL to the attention of senior management. With the framework's rapidly increasing adoption, your organization might already be talking about ITIL; letting your management know specifically about ITIL's information security benefits can help spur its adoption.&lt;/p&gt;
&lt;p class="text"&gt;Implementing ITIL does take time and effort. Depending on the size and complexity of an organization, implementing it can take &lt;em&gt;significant&lt;/em&gt; up front time and effort. For many organizations, successful implementation of ITIL will require changes in their organizational culture and the involvement and commitment of employees throughout the organization.&lt;/p&gt;
&lt;p class="text"&gt;Critical factors for successful ITIL implementation include:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Full management commitment and involvement with the ITIL implementation&lt;/li&gt;

  &lt;li&gt;A phased approach&lt;/li&gt;

  &lt;li&gt;Consistent and thorough training of staff and management&lt;/li&gt;

  &lt;li&gt;Making ITIL improvements in service provision and cost reduction sufficiently visible&lt;/li&gt;

  &lt;li&gt;Sufficient investment in ITIL support tools&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p class="text"&gt;Information security measures are steadily increasing in scope, complexity, and importance. It is risky, expensive, and inefficient for organizations to have their information security depend on cobbled-together, homegrown processes. ITIL can enable these processes to be replaced with standardized, integrated processes based on best practices. Though some time and effort are required, ITIL can improve how organizations implement and manage information security.&lt;/p&gt;
&lt;p class="text"&gt;&lt;br /&gt;&lt;/p&gt;&lt;strong&gt;Author Resource:&lt;/strong&gt; Steven Weil, CISSP, CISA, CBCP is senior security consultant with Seitel Leeds &amp;amp; Associates, a full service consulting firm based in Seattle, WA. Mr. Weil specializes in the areas of security policy development, HIPAA compliance, disaster recovery planning, security assessments, and information security management. He can be reached at sweil@sla.com.&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;Article From:&lt;/strong&gt; &lt;a href="http://www.securityfocus.com/infocus/1815" target="_blank"&gt;SecurityFocus&lt;/a&gt;&lt;br /&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7030134522800038580?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n2c2MY3yjjE:GOzrAC3A-ns:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n2c2MY3yjjE:GOzrAC3A-ns:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n2c2MY3yjjE:GOzrAC3A-ns:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=n2c2MY3yjjE:GOzrAC3A-ns:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n2c2MY3yjjE:GOzrAC3A-ns:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n2c2MY3yjjE:GOzrAC3A-ns:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/n2c2MY3yjjE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-27T08:59:07.431-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2009/05/how-itil-can-improve-information.html</feedburner:origLink></item><item><title>Some of the Best Ways to Lose Your System Data</title><link>http://feedproxy.google.com/~r/morphic/~3/aofxJmI8_Wg/some-of-best-ways-to-lose-your-system.html</link><category>Proactive</category><category>SANS</category><category>Viruses</category><category>Attacks</category><category>Outsource</category><category>hacker</category><category>Hackers</category><category>Passwords</category><category>Policy</category><category>Encryption</category><category>Firewall</category><category>email attachments</category><category>Hardening</category><category>Backups</category><category>Business Continuity</category><category>Credit Card</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Mon, 18 May 2009 07:44:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-731532815012453140</guid><description>By: Nick Pegley&lt;br /&gt;
&lt;p&gt;Have you ever thought about the best ways to be negatively affected by a disaster, get hacked, or otherwise part with data stored on your computers? Here are some of the best ways to lose system security, in no particular order:&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;&lt;img src="http://farm3.static.flickr.com/2105/3541037303_09dcda6f2d.jpg" width="200" height="281" alt="Security Guard" style="float:right; padding-top:1px; padding-right:1px; padding-bottom:1px; padding-left:1px;" /&gt;When an employee quits or is let go, leave his network log ins and e mail accounts enabled. You never know when he might want to check in on things.&lt;/li&gt;

  &lt;li&gt;Rely solely on technology. Firewalls, encryption and antivirus software are all you need to protect your information.&lt;/li&gt;

  &lt;li&gt;Completely outsource your information security initiatives. There's no need for anyone inside your organization to worry about such matters.&lt;/li&gt;

  &lt;li&gt;Leave your operating systems and software applications with the default settings. System hardening is for the birds.&lt;/li&gt;

  &lt;li&gt;Don't train your users on your security policies and what to look out for, such as unsolicited e mail attachments and common hacker activities. Your users can't be burdened with more training.&lt;/li&gt;

  &lt;li&gt;If you do happen to have a security policy, never refer to it, enforce it, update it or do what it says.&lt;/li&gt;

  &lt;li&gt;By all means, don't take an inventory of your information systems or document your network.&lt;/li&gt;

  &lt;li&gt;Don't pay attention to or even bother to understand what you're trying to protect.&lt;/li&gt;

  &lt;li&gt;Don't patch your software or update your virus signatures, and never, ever, run vulnerability assessments to detect newly discovered software flaws and system misconfigurations. It s just too time consuming.&lt;/li&gt;

  &lt;li&gt;Respond to hacker attacks, viruses and other intrusions as they happen don't be proactive in dealing with them.&lt;/li&gt;

  &lt;li&gt;Ignore all known best practices and international information security standards from the International Standards Organization, Internet Engineering Task Force, SANS Institute, and your local information security consultant, to name a few.&lt;/li&gt;

  &lt;li&gt;Leave your databases, especially those containing credit card or other confidential information, unencrypted. And be sure to store them on publicly accessible servers.&lt;/li&gt;

  &lt;li&gt;Run your business without disaster recovery and business continuity plans. After all, you can think clearly and make critical decisions under pressure, right?&lt;/li&gt;

  &lt;li&gt;Don't monitor your systems. They'll be fine running by themselves, and if anything major happens with the integrity or availability of your information, you'll be notified automatically, won't you?&lt;/li&gt;

  &lt;li&gt;Don't back up your data, but if you must, don't test your backups. Also, leave your backup media on site preferably sitting on top of an uninterruptible power supply.&lt;/li&gt;

  &lt;li&gt;Don't create any security policies that document how you re safeguarding your information to protect your organization and clients from information disasters and legal liabilities.&lt;/li&gt;

  &lt;li&gt;Apply the principle of greatest privilege. Give all users the greatest amount of access to your information systems. Everyone should have access to everything ... it's only fair, right?&lt;/li&gt;

  &lt;li&gt;Don't subscribe to security bulletins and mailing lists, and don't ever read information security trade magazines.&lt;/li&gt;

  &lt;li&gt;Don't, under any circumstances, get upper management involved in information security initiatives. They're business focused and shouldn't be bothered or even care about technology or the liabilities associated with their information, right?&lt;/li&gt;

  &lt;li&gt;Use passwords that consist of your pet's name, your name, your mom's maiden name, or your birthday. That way, you won t forget them. Better yet, just use "&lt;em&gt;password&lt;/em&gt;" for your passwords. Also, don t forget to write them down and post them on your monitor or keyboard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;And, last but not least:&lt;/p&gt;
&lt;ol start="21"&gt;
  &lt;li&gt;Leave your servers and network equipment in a room to which everyone, including outsiders off the street, has access.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;By following these practices you can be sure that your computers will be an easy target for viruses, disgruntled employees, hackers, and others. You can show up to work each day with the pride of knowing that there's an excellent chance that your business data will be missing when you arrive. It's just a matter of time, and it s all easily achieved.&lt;/p&gt;&lt;br /&gt;
&lt;b&gt;Author Resource:-&amp;gt;&lt;/b&gt; Nick Pegley is VP Marketing for All Covered: Technology Services Partner for Small Business, providing &lt;a href="http://www.allcovered.com/locations/denver/" target="_blank"&gt;http://www.allcovered.com/locations/denver/&lt;/a&gt; disaster recovery solutions and technology services in 20 major U.S. metro areas.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Article From&lt;/b&gt; &lt;a href="http://www.zingarticles.com/" target="_blank"&gt;Zing Articles - Best Free Articles on all topics&lt;/a&gt;&lt;br /&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-731532815012453140?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aofxJmI8_Wg:D1_FiVkOz8M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aofxJmI8_Wg:D1_FiVkOz8M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aofxJmI8_Wg:D1_FiVkOz8M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=aofxJmI8_Wg:D1_FiVkOz8M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aofxJmI8_Wg:D1_FiVkOz8M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aofxJmI8_Wg:D1_FiVkOz8M:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/aofxJmI8_Wg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-18T07:44:00.099-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2009/05/some-of-best-ways-to-lose-your-system.html</feedburner:origLink></item><item><title>Where The 'Bleep' Did My Identity Go?</title><link>http://feedproxy.google.com/~r/morphic/~3/XfRkjqLXvnw/where-did-my-identity-go.html</link><category>Security</category><category>SSN</category><category>Mac</category><category>PC</category><category>Privacy</category><category>Password</category><category>Confidential</category><category>Restricted Data</category><category>Identity Theft</category><category>Social Security Number</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 08 May 2009 17:15:32 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-4240140170118507437</guid><description>&lt;p&gt;By &lt;a href="http://www.articlesengine.com/Author/Judi-Lynn-Lake/4486/1"&gt;Judi Lynn Lake&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I am a die-hard Mac user. Have been for over twenty years and it only gets better. The PC certainly has its place but for creative projects well... the Mac is superior and the good news is is that Mac's do not get viruses.&lt;br /&gt;
&lt;br /&gt;
My partner is a die-hard PC user. If you ever viewed the recent Mac commercials then you can imagine our relationship. I have recently added creative video production to my advertising agency's services and my partner began to feel a bit competitive. I have always thrived on competition and believe it to be good... even if it is with your partner.&lt;br /&gt;
&lt;br /&gt;
My first video was a Creative Director's dream -- my client gave me complete creative carte blanche. My partner, who is a copywriter, had recently bought PC video software and... well, he was just dying to use it and prove that it would triumph over the Mac.&lt;br /&gt;
&lt;br /&gt;
Once I completed all the storyboards, I sent a crew out to shoot on location. As I passed my partners office, I peaked in his office and I could see sweat dripping from his forehead. He was struggling and I silently laughed, wishing we had made a bet. Two weeks later the video was completed; fully edited and designed on my Mac. The client approved the video and it was a 'go'. My partner, on the other hand, was still trying to learn the software and his final product was 'the homegrown version' clip. It is comical, but seriously our differences actually are our strengths.&lt;br /&gt;
&lt;br /&gt;
An experienced Mac user tends to be 'cocky' at times because there really are no limits to what our little machines can do, and I am no exception -- I rarely see any limits. There was, however, a disadvantage I experienced recently that unfortunately is nondiscriminating towards neither a Mac nor a PC: Identity Theft. This week I became victim to Identity Theft and therefore a statistic in the wonderland of technology.&lt;br /&gt;
&lt;br /&gt;
No longer holding the 'it could never happen to me' mentality because it did and it happens to millions of people a day without some consumers ever realizing it. Technology is incredible and we can do things today that were never imagined twenty years ago. But as technology juices up the creative sector, it also feeds the larcenists and opens up a world of crime unheard of years ago.&lt;br /&gt;
&lt;br /&gt;
Once considered a protection, our social security number has actually transformed into the very bait that perpetrators look for to steal identities. Who is walking around with my name? Who is walking around with my numbers and personal information? Is it someone reading this article? Is it someone I do business with? Is it my neighbor? This is a form of terrorism, which stalks our daily lives in the twenty-first century and ruins lives.&lt;br /&gt;
&lt;br /&gt;
I have been 'Judi Lynn' all of my life and 'Lake' for the past eleven years and am very happy to be me. How dare a stranger invade my life and steal it from me. I have heard nightmare stories of people haunted for years through Identity Theft and to quote the 1970s movie Network, "I am mad as hell and I am not going to take it anymore!"&lt;br /&gt;
&lt;br /&gt;
Unfortunately, in this day and age, high security precautions must be taken both personally and professionally. The best defense against this heinous crime is education and guidance but 'the damned if you do' fact is that skilled identity thieves will use a variety of methods to gain access to your data. There are many websites available on the Internet that educates people on steps to protect themselves before and after Identity Theft occurs. One such site I recommend is The Federal Trade Commission For The Consumer.&lt;br /&gt;
&lt;br /&gt;
Some Steps To Take Today Before You Fall Victim&lt;br /&gt;&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Place passwords on all of your credit card, bank, and phone accounts. Avoid using easily available information like your mother's maiden name, your birth date, the last four digits of your SSN or your phone number, or a series of consecutive numbers. When opening new accounts, you may find that many businesses still have a line on their applications for your mother's maiden name. Ask if you can use a password instead.&lt;/li&gt;

  &lt;li&gt;Secure personal information in your home, especially if you have roommates, employ outside help, or are having work done in your home.&lt;/li&gt;

  &lt;li&gt;Ask about information security procedures in your workplace or at businesses, doctor's offices or other institutions that collect your personally identifying information. Find out who has access to your personal information and verify that it is handled securely. Ask about the disposal procedures for those records as well. Find out if your information will be shared with anyone else. If so, ask how your information can be kept confidential.&lt;/li&gt;
&lt;/ol&gt;Don't think that identity theft can not happen to you, expect that it will so that it won't -- stay informed and stay educated so you do not become a statistic.&lt;br /&gt;
&lt;br /&gt;
Article Source: &lt;a href="http://www.articlesengine.com/Article/Where-The--Bleep--Did-My-Identity-Go-/54730/1"&gt;Articles Engine&lt;/a&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-4240140170118507437?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XfRkjqLXvnw:GAi4yHhoG9k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XfRkjqLXvnw:GAi4yHhoG9k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XfRkjqLXvnw:GAi4yHhoG9k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=XfRkjqLXvnw:GAi4yHhoG9k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XfRkjqLXvnw:GAi4yHhoG9k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XfRkjqLXvnw:GAi4yHhoG9k:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/XfRkjqLXvnw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-08T17:15:32.264-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2009/05/where-did-my-identity-go.html</feedburner:origLink></item><item><title>PCI Compliance - Disable SSLv2 and Weak Ciphers</title><link>http://feedproxy.google.com/~r/morphic/~3/3CYgzMOP-vQ/pci-compliance-disable-sslv2-and-weak.html</link><category>Cryptography</category><category>Risk Management</category><category>Payment Card Industry</category><category>Crypto</category><category>PCI DSS</category><category>Windows</category><category>Risk</category><category>OpenSSL</category><category>Secure Sockets Layer</category><category>PCI</category><category>SSL</category><category>Security</category><category>Data Security Standard</category><category>IIS</category><category>AVS</category><category>SSLv2</category><category>Apache</category><category>Registry</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Thu, 19 Mar 2009 07:57:06 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-9136266752224235795</guid><description>&lt;p&gt;According to section &lt;a href="http://www.pci-portal.com/lang-en/pci-knowledge/pcidss-detail/requirement-4/41-use-strong-cryptography-and-security-protocols" target="_blank"&gt;4.1&lt;/a&gt; of the the Payment Card Industry Data Security Standard (&lt;a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank"&gt;PCI-DSS&lt;/a&gt;) v1.2, merchants handling credit card data are required to “use strong cryptography and security protocols such as SSL/TLS or IPSEC to safeguard sensitive cardholder data during transmission over open, public networks.”&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;What does this mean? In order to validate your PCI DSS compliance in this area you will need to ensure that your relevant server(s) within your PCI environment are configured to disallow Secure Sockets Layer (&lt;a href="http://en.wikipedia.org/wiki/Transport_Layer_Security" target="_blank"&gt;SSL&lt;/a&gt;) version 2 as well as "weak" cryptography. You are also required to have quarterly PCI security vulnerability scans conducted against your externally facing PCI systems. Without disabling SSLv2 and weak ciphers you are almost guaranteed to fail the scans. In turn this will lead to falling out of compliance along with the associated risks and consequences.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;The SSLv2 Conundrum&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Does your server support SSLv2?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How to test:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You will need to have OpenSSL installed on the system that you will perform the tests from. Once installed, use the following command to test your web server, assuming port 443 is where you're providing http&lt;strong&gt;s&lt;/strong&gt; connections:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;# openssl s_client -ssl2 -connect SERVERNAME:443&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If the server does not support SSLv2 you should receive an error similar to the following:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;# openssl s_client -ssl2 -connect SERVERNAME:443&lt;/p&gt;

  &lt;p&gt;CONNECTED(00000003)&lt;/p&gt;

  &lt;p&gt;458:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:428:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;How to configure Apache v2 to not accept SSLv2 connections:&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;You will need to modify the SSLCipherSuite directive in the httpd.conf or ssl.conf file.&lt;/p&gt;
&lt;p&gt;An example would be editing the following lines to look similar to:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;SSLProtocol -ALL +SSLv3 +TLSv1&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Restart the Apache process and ensure that the server is functional. Also retest using OpenSSL to confirm that SSLv2 is no longer accepted.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How to configure Microsoft IIS to not accept SSLv2 connections:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You will need to modify the system’s registry.&lt;/p&gt;
&lt;p&gt;Merge the following keys to the Windows registry:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Restart the system and ensure that the server is functional. Also retest using OpenSSL to confirm that SSLv2 is no longer accepted.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;Those Pesky Weak SSL Ciphers&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Does your server support weak SSL ciphers?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How to test:&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;You will need to have OpenSSL installed on the system that you will perform the tests from. Once installed, use the following command to test your web server, assuming port 443 is where you're providing http&lt;strong&gt;s&lt;/strong&gt; connections:&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;# openssl s_client -connect SERVERNAME:443 -cipher LOW:EXP&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If the server does not support weak ciphers you should receive an error similar to the following:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;# openssl s_client -connect SERVERNAME:443 -cipher LOW:EXP&lt;/p&gt;

  &lt;p&gt;CONNECTED(00000003)&lt;/p&gt;

  &lt;p&gt;461:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:226:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;How to configure Apache v2 to not accept weak SSL ciphers:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You will need to modify the SSLCipherSuite directive in the httpd.conf or ssl.conf file.&lt;/p&gt;
&lt;p&gt;An example would be editing the following lines to look similar to:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Restart the Apache process and ensure that the server is functional. Also retest using OpenSSL to confirm that weak SSL ciphers are no longer accepted.&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How to configure Microsoft IIS to not accept weak SSL ciphers:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You will need to modify the system’s registry.&lt;/p&gt;
&lt;p&gt;Merge the following keys to the Windows registry:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:00000000&lt;/p&gt;

  &lt;p&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 64/128]&lt;/p&gt;

  &lt;p&gt;"Enabled"=dword:0000000&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Restart the system and ensure that the server is functional. Also retest using OpenSSL to confirm that weak SSL ciphers are no longer accepted..&lt;/p&gt;
&lt;p&gt;At this point have your Approved Scanning Vendor (ASV) scan your external facing PCI environment to validate. Making the above changes should cause the ASV scans to &lt;em&gt;not&lt;/em&gt; tag and fail you on the following vulnerabilities:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;SSL Server Supports Weak Encryption&lt;/li&gt;

  &lt;li&gt;SSL Server Allows Cleartext Encryption&lt;/li&gt;

  &lt;li&gt;SSL Server May Be Forced to Use Weak Encryption&lt;/li&gt;

  &lt;li&gt;SSL Server Allows Anonymous Authentication&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-9136266752224235795?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CYgzMOP-vQ:ks2vqEB3jrk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CYgzMOP-vQ:ks2vqEB3jrk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CYgzMOP-vQ:ks2vqEB3jrk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=3CYgzMOP-vQ:ks2vqEB3jrk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CYgzMOP-vQ:ks2vqEB3jrk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CYgzMOP-vQ:ks2vqEB3jrk:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/3CYgzMOP-vQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-19T07:57:06.894-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">16</thr:total><feedburner:origLink>http://blog.zenone.org/2009/03/pci-compliance-disable-sslv2-and-weak.html</feedburner:origLink></item><item><title>Sync Oracle Calendar to Google Calendar + iCal + iPhone</title><link>http://feedproxy.google.com/~r/morphic/~3/GoG9OAAGGH8/sync-oracle-calendar-to-google-calendar.html</link><category>Mac</category><category>Calendar</category><category>Calaboration</category><category>day events</category><category>SyncML2iCal</category><category>Apple</category><category>WiFi</category><category>WPA</category><category>Oracle Calendar</category><category>Synthesis AG</category><category>Policy</category><category>iPhone Calendar</category><category>syncml</category><category>Sync</category><category>day notes</category><category>CalDAV</category><category>CorporateTime</category><category>WEP</category><category>HTTPS</category><category>Google Calendar</category><category>itunes</category><category>read-only</category><category>Blackberry</category><category>Get Things Done</category><category>iTouch</category><category>Phone</category><category>Oracle</category><category>Password</category><category>iphone</category><category>Productivity</category><category>Security</category><category>iCal</category><category>Todo+Cal+Sync</category><category>Google</category><category>Privacy</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Mon, 02 Mar 2009 19:21:21 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-8015609008297655100</guid><description>&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;I've been searching for a reliable method to automate the synchronization of events from&lt;/span&gt; &lt;a href="http://www.oracle.com/technology/products/ocal/index.html" target="_blank"&gt;Oracle Calendar&lt;/a&gt; &lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;&lt;span style="line-height: 18px;"&gt;(formerly CorporateTime) &lt;span style="font-family: Helvetica; font-size: 12px; line-height: normal;"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;to my&lt;/span&gt; &lt;a href="http://www.google.com/calendar" target="_blank"&gt;Google Calendar&lt;/a&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;,&lt;/span&gt; &lt;a href="http://www.apple.com/support/ical/" target="_blank"&gt;iCal&lt;/a&gt; &lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;on my Mac, and&lt;/span&gt; &lt;a href="http://www.apple.com/iphone/features/calendar.html" target="_blank"&gt;internal iPhone calendar&lt;/a&gt; &lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;on my iPhone.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;center&gt;
  &lt;img src="http://farm4.static.flickr.com/3393/3316279569_898b0c742c_o.png" width="400" alt="Slide1.png" style="border:1px #ffffff solid;" /&gt;
&lt;/center&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;Recently I learned of a promising iPhone app available at iTunes called&lt;/span&gt; &lt;a href="http://www.synthesis.ch/todosync.php" target="_blank" style="background-color: rgba(0, 0, 0, 0); color: #BB3300; line-height: 18px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-align: left; text-decoration: underline; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto;"&gt;Todo+Cal+Sync&lt;/a&gt; &lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;that could do most of what I was looking for with synchronizing calendars. However, I didn't want to fork over $14.99 for an application that, instead of importing Oracle Calendar events into the native iPhone calendar, added an additional calendar application on my iPhone. Synthesis AG, the developer of the Todo+Cal+Sync application, is required to do this because of limitations imposed by&lt;/span&gt; &lt;span style="line-height: 18px;"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;Apple's iPhone software development kit (SDK). In other words, Apple does not allow 3rd part applications, such as Todo+Cal+Sync, to access the internal iPhone calendar, nor sync with iCal. This is a risk/benefit that Apple needs to manage; is the benefit of restricting access to the internal iPhone calendar worth the impact it has on the development of 3rd party applications and subsequent ripple effect? Until Apple's iPhone SDK allow such access,&lt;/span&gt; &lt;span style="line-height: normal;"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;I did not want two calendar applications and continued looking for &lt;em&gt;something&lt;/em&gt; that would better match my needs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;After digging around and tinkering with different solutions, I worked out a method that did exactly what I wanted. To make this solution even better, it cost $0 - in other words, FREE!&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica; min-height: 14.0px"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;Below are the steps that I came up with to make the calendar sync work for me. Steps 1-3 are also useful for those who do not necessarily have an iPhone or iTouch but want to sync their Oracle Calendar with other devices and/or calendar apps that support Google Calendar's&lt;/span&gt; &lt;a href="http://en.wikipedia.org/wiki/Caldav" target="_blank"&gt;CalDAV&lt;/a&gt; &lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;sync.&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;Begin by changing your password for your Oracle Calendar user account. Make it a unique password that you are &lt;span style="text-decoration: underline;"&gt;not&lt;/span&gt; using anywhere else. In other words, your new Oracle Calendar password should not be the same password as you're using for other email accounts, online banking, eBay, PayPal, etc. This new password should also comply to any password policies that may exist for users of the Oracle Calendar system.&lt;/li&gt;

  &lt;li&gt;Create a "&lt;em&gt;magic&lt;/em&gt;" URL using &lt;a href="http://www.syncml2iphone.com/pmwiki.php?n=TryItNow.TryItNow" target="_blank"&gt;SyncML2iCal.com&lt;/a&gt;. This URL will be used in step #3. You will want your &lt;em&gt;&lt;span style="font-style: normal;"&gt;magic&lt;/span&gt;&lt;/em&gt; URL to look something like the following:&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="line-height: 18px;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: black;"&gt;Example - Oracle Calendar supporting https on port 443&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;

  &lt;p&gt;&lt;span style="line-height: normal;"&gt;http://sync.syncml2ical.com/?serverurl=https://&lt;span style="color: #0000FF;"&gt;YOUR.ORACLE.CALENDAR.COM&lt;/span&gt;:443/ocas-bin/ocas.fcgi?sub=syncml&amp;amp;user=&lt;span style="color: #0000FF;"&gt;USERNAME&lt;/span&gt;&amp;amp;pass=&lt;span style="color: #0000FF;"&gt;PASSWORD&lt;/span&gt;&amp;amp;eventsdb=./Calendar/Events&lt;span style="font-family: Arial;"&gt;?/dr(-7,30)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: #FF0000;"&gt;SECURITY WARNING&lt;/span&gt; &lt;span style="color: black;"&gt;- There is an increased security risk with this method. It's up to you to determine if this is a risk you are willing to accept and that it doesn't violate any policies or restrictions imposed by the organization running the Oracle Calendar service that you are using. The risks include:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

  &lt;ul&gt;
    &lt;li&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: black;"&gt;Unauthorized interception of your password from the URL as it's being transmitted to SyncML2iCal.com or from SyncML2iCal.com.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;

    &lt;li&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: black;"&gt;SyncML2iCal.com itself becoming compromised and allowing an attacker to intercept your password.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
  &lt;/ul&gt;

  &lt;p style="font: 12.0px Helvetica"&gt;&lt;/p&gt;

  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: black;"&gt;In my opinion, the likelihood of the above risks happening are medium to low. You can keep this risk on the lower end by never connecting to untrusted networks or using insecure wireless, which includes wireless networks that use WEP encryption.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: black;"&gt;Additionally, you will need to determine if the impact of an unauthorized user obtaining your Oracle Calendar password would have a significant impact or not. In most instances, I would imagine the impact would be low.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;em&gt;&lt;span style="color: black;"&gt;This is why doing step #1 above is critical in helping minimize the impact&lt;/span&gt;&lt;/em&gt; &lt;em&gt;&lt;span style="color: black;"&gt;if&lt;/span&gt;&lt;/em&gt; &lt;em&gt;&lt;span style="color: black;"&gt;your password was comprom&lt;/span&gt;&lt;/em&gt;&lt;span style="color: black;"&gt;ised.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

  &lt;p&gt;&lt;span style="line-height: normal;"&gt;&lt;span style="color: black;"&gt;Anyone using an application that syncs using the SyncML functionality of Oracle Calendar should take the same precautions irregardless if he or she are using SyncML2iCal.com as a proxy to convert SynchML to iCal format.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
  &lt;li value="3"&gt;Go to Google Calendar and add a new calendar by selecting &lt;em&gt;&lt;a href="https://www.google.com/support/calendar/bin/answer.py?hl=en&amp;amp;answer=37100" target="_blank"&gt;Add by URL&lt;/a&gt;&lt;/em&gt; . You will use the URL you created from step #2. You may also want to change the display &lt;a href="https://www.google.com/support/calendar/bin/answer.py?hl=en&amp;amp;answer=45702" target="_blank"&gt;name&lt;/a&gt; and &lt;a href="https://www.google.com/support/calendar/bin/answer.py?hl=en&amp;amp;answer=37227" target="_blank"&gt;color&lt;/a&gt; of this new calendar on Google Calendar.&lt;br /&gt;
    &lt;br /&gt;

    &lt;center&gt;
      &lt;img src="http://farm4.static.flickr.com/3427/3318169582_ea25eabe47_o.png" width="194" height="113" alt="AddCal.png" style="border:1px #000000 solid;" /&gt;
    &lt;/center&gt;Do note that &lt;a href="http://www.google.com/support/calendar/bin/static.py?page=troubleshooter.cs&amp;amp;problem=techissue&amp;amp;selected=techissue_update_feed&amp;amp;sl=imp03&amp;amp;ctx=techissue_techissue_update_feed_38847" target="_blank"&gt;Google has stated&lt;/a&gt; that external feeds added via the "Add by URL" method should be refreshed every 24 hours.&lt;br /&gt;
  &lt;/li&gt;
&lt;/ol&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;/p&gt;
&lt;ol&gt;
  &lt;li value="4"&gt;Download and run &lt;a href="http://code.google.com/p/calaboration/" target="_blank"&gt;Calaboration&lt;/a&gt; from Google Code. This will allow you to add your Oracle calendar to your Mac's iCal application. Before you can add the new calendar, click on &lt;em&gt;preferences&lt;/em&gt; within Calaboration and enable allowing read only calendars to be added. Make sure your new calendar is selected and let Calaboration do the setup work for you. Your Oracle calendar will then sync with iCal.&lt;/li&gt;
&lt;/ol&gt;
&lt;center&gt;
  &lt;img src="http://farm4.static.flickr.com/3566/3318164536_59550ff137_o.png" width="400" alt="Calaboration.png" name="3318164536_59550ff137_o.png" style="border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-color: rgb(255, 255, 255); border-right-color: rgb(255, 255, 255); border-bottom-color: rgb(255, 255, 255); border-left-color: rgb(255, 255, 255); border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid;" /&gt;
&lt;/center&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;/p&gt;
&lt;ol&gt;
  &lt;li value="5"&gt;&lt;span style="line-height: normal;"&gt;Use iTunes to sync Oracle calendar from iCal to your iPhone.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;center&gt;
  &lt;img src="http://farm4.static.flickr.com/3539/3318054546_4ec5e2881d_o.png" width="277" height="141" alt="iTunes-Calendar.png" style="border:1px #000000 solid;" /&gt;
&lt;/center&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;One minor annoying issue I came across was with how &lt;em&gt;day events&lt;/em&gt; and &lt;em&gt;day notes&lt;/em&gt; from Oracle Calendar were handled by the time they showed up in iCal. Day events and notes from Oracle Calendar showed up in iCal as being a blocked all-day event from 0000-2359. As a quick temporary solution I simply denied day events and notes within Oracle Calendar and re-synced. This temporary approach was acceptable for me since I use Google Calendar to manage my daily notes and I can look at a user's Oracle calendar if I need to know if he or she is on vacation, on-call, etc.&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;As for effectively managing tasks using your iPhone, see my previous article titled, &lt;a href="http://blog.zenone.org/2009/01/tools-to-get-things-done.html"&gt;Tools To Get Things Done&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;Steve&lt;/span&gt;&lt;/p&gt;
&lt;p style="font: 12.0px Helvetica"&gt;&lt;span style="font-family: 'Trebuchet MS'; font-size: 13px;"&gt;###&lt;/span&gt;&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-8015609008297655100?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=GoG9OAAGGH8:MWMlSFSDoXo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=GoG9OAAGGH8:MWMlSFSDoXo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=GoG9OAAGGH8:MWMlSFSDoXo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=GoG9OAAGGH8:MWMlSFSDoXo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=GoG9OAAGGH8:MWMlSFSDoXo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=GoG9OAAGGH8:MWMlSFSDoXo:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/GoG9OAAGGH8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-02T19:21:21.188-08:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">34</thr:total><feedburner:origLink>http://blog.zenone.org/2009/02/sync-oracle-calendar-to-google-calendar.html</feedburner:origLink></item><item><title>Thoughts on IT Security Organizational Structure</title><link>http://feedproxy.google.com/~r/morphic/~3/XhtctQKQ3OY/thoughts-on-it-security-organizational.html</link><category>Risk Management</category><category>Strategy</category><category>Organisational Structure</category><category>Leadership</category><category>InfoSec</category><category>IT</category><category>Information Security</category><category>Host Security</category><category>Organisation</category><category>Policy</category><category>Legal</category><category>Security</category><category>compliance</category><category>Business</category><category>Audit</category><category>Architecture</category><category>Incident Management</category><category>IT Security</category><category>Conflict of Interest</category><category>Network Security</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Mon, 04 May 2009 15:45:12 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-4013497941114349352</guid><description>&lt;p&gt;I've recently been asking myself how to most effectively structure Information Security (InfoSec) within an organization. Here are some thoughts I've had while trying to answer this.&lt;/p&gt;
&lt;p&gt;As with any "structure" there needs to be some form of integral support, whether it's a frame for a house or honeycomb for a beehive. This is also true with organizational structures - there needs to be &lt;em&gt;support&lt;/em&gt;. In order for InfoSec to be successful it &lt;em&gt;must&lt;/em&gt; have the full support of senior or executive management. This support would be actualized as a sincere commitment by senior management to achieve the following:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Develop high standards of corporate governance&lt;/li&gt;

  &lt;li&gt;Treat InfoSec as a critical function that enables an organization to &lt;em&gt;do&lt;/em&gt; business&lt;/li&gt;

  &lt;li&gt;Create an environment that understands the importance of, and embraces, InfoSec&lt;/li&gt;

  &lt;li&gt;Consistently show 3rd parties that InfoSec is vital and will always be handled in a professional manner&lt;/li&gt;

  &lt;li&gt;Ensure that controls being implemented by InfoSec are appropriate and proportionate to risk being addressed&lt;/li&gt;

  &lt;li&gt;Stay informed and accept ultimate responsibility and accountability&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The first bulleted point in the above list, "&lt;em&gt;Develop high standards of corporate governance&lt;/em&gt;", is where the necessary framework is built from which InfoSec can flourish. At a minimum, an effective governance framework includes:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;An all-inclusive security strategy that links to clearly defined and documented business objectives&lt;/li&gt;

  &lt;li&gt;Security policies that address the multiple facets of security strategy, regulatory compliance and controls&lt;/li&gt;

  &lt;li&gt;Standards for each of the policies to make sure that procedures and guidelines comply with policy&lt;/li&gt;

  &lt;li&gt;An organizational structure &lt;em&gt;&lt;strong&gt;void of conflicts of interest&lt;/strong&gt;&lt;/em&gt; with sufficient resources and authority&lt;/li&gt;

  &lt;li&gt;Metrics and monitoring processes to ensure compliance and provide feedback&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;Again, I want to emphasize that It is imperative that an organization's top management sees InfoSec as a critical business function and is fully committed to stand behind InfoSec. Without the complete assurance from top management we will continue to see security functions getting moved around the organization while adequate resources are never obtained and conflicts of interest are progressively created.&lt;br /&gt;&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;To limit conflicts of interest and actualize the benefits from investing within InfoSec, the Chief Information Security Officer (CISO/ISO) or Information Security Manager (ISM) must report directly to the top of the organizational structure, or an independent branch such as Audit. The trend in the past was to embed central InfoSec within Information Technology (IT), that is, until organizations began realizing that this structure kept InfoSec's hands tied behind their back, significantly reducing InfoSec's overall effectiveness. In other words, organizations were self-limiting their return on investment (ROI) from InfoSec. To resolve this issue and improve the ROI from InfoSec, CISO's/ISO's/ISM's began reporting to the CEO's, CFO's, CTO's and CIO's.&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: justify;"&gt;&lt;/p&gt;
&lt;center&gt;
  &lt;a href="http://farm4.static.flickr.com/3362/3259881198_fd01a06ed7.jpg"&gt;&lt;img src="http://farm4.static.flickr.com/3362/3259881198_fd01a06ed7.jpg" width="400" alt="Slide11.png" name="3259881198_fd01a06ed7.jpg" style="border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-color: rgb(0, 0, 0); border-right-color: rgb(0, 0, 0); border-bottom-color: rgb(0, 0, 0); border-left-color: rgb(0, 0, 0); border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid;" height="356" /&gt;&lt;/a&gt;
&lt;/center&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;Ok, great, so the ISO should report to the CFO ... then what?&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;What we want to avoid is a structure with the fragmentation that is commonly seen today. Rather, create a tighter integration of the duties and activities performed by IT Security, Operations, Policy &amp;amp; Compliance, Risk Management and Audit. To anticipate the trends of the future, it’s very likely that individuals and departments taking on central InfoSec duties will also have various risk management responsibilities that extend beyond IT. This can include anything from physical security, business continuity and disaster recovery.&lt;/p&gt;&lt;img src="http://farm4.static.flickr.com/3350/3259943929_544c1ceedc.jpg" border="0" width="169" height="480" alt="Slide1.png" style="padding-left: 5px; float: right;" name="3259943929_544c1ceedc.jpg" /&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;Fact is, too often in industry the security discipline is (mis)directed by technology instead of using a risk analysis and proactive ‘intelligence’ approach. To add to the vicious cycle, when majority of the investment is being put into technology then most of the return comes from there too. This reinforcement perpetuates the destructive spiral.&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;So, how does a business avoid this technodazed shortsightedness? It comes down to strategy, making the conscious shift to &lt;em&gt;be more strategic&lt;/em&gt;. This means moving away from the predictable technology-centric and tactical security operation seen in the industry since the golden days of the dot-gone era. At a high level, for InfoSec to more closely align with and help business achieve its objectives, InfoSec will need to become more focussed on '&lt;strong&gt;intelligence&lt;/strong&gt;'; gathering information, ability to comprehend, ability to develop policy and plans at a &lt;em&gt;high&lt;/em&gt; level, using a methodology of risk analysis and risk mitigation, having the knowledge about an organization's business environment that has implications for its long-term viability and success, thinking long-term, and being both pragmatic and visionary.&lt;br /&gt;&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;Thinking strategically while taking into account anticipation of future trends and using proactive 'intelligence', I believe the wise CISO, or equivalent, who's in a healthy organizational environment needs to start planning for incorporating some of the non-IT specific risk management responsibilities before it's thrust upon them within the next three to five years. There &lt;em&gt;will&lt;/em&gt; need to be coordination between IT Security, Operations, Policy &amp;amp; Compliance, Risk Management, Audit and Physical Security.&lt;/p&gt;
&lt;p style="background-color: rgba(0, 0, 0, 0); color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 12px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto; text-align: left;"&gt;What this boils down to is that a very effective way to structure InfoSec within an organization involves having the CISO, or equivalent, reporting directly to the senior/executive level of the organization while having their full support, commitment and involvement. This top level commitment includes the development of high standards of corporate governance and actively limiting conflicts of interest so that InfoSec will be effective and provide a high ROI by enabling the organization to do business.&lt;br /&gt;&lt;/p&gt;
&lt;center&gt;
  &lt;a href="http://farm4.static.flickr.com/3365/3259877105_9a12b8f85b.jpg"&gt;&lt;img src="http://farm4.static.flickr.com/3365/3259877105_9a12b8f85b.jpg" width="400" alt="Slide2.png" border="0" /&gt;&lt;/a&gt;
&lt;/center&gt;
&lt;center style="text-align: left;"&gt;
  Steve
&lt;/center&gt;
&lt;center style="text-align: left;"&gt;
  ###
&lt;/center&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-4013497941114349352?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XhtctQKQ3OY:GIcYP7Oif9E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XhtctQKQ3OY:GIcYP7Oif9E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XhtctQKQ3OY:GIcYP7Oif9E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=XhtctQKQ3OY:GIcYP7Oif9E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XhtctQKQ3OY:GIcYP7Oif9E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=XhtctQKQ3OY:GIcYP7Oif9E:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/XhtctQKQ3OY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-04T15:45:12.550-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://blog.zenone.org/2009/02/thoughts-on-it-security-organizational.html</feedburner:origLink></item><item><title>Forensics: Blackberry Curve 8310 and Incorrect EXIF Time Stamp</title><link>http://feedproxy.google.com/~r/morphic/~3/nwr-2QnQugQ/forensics-blackberry-curve-8310-and.html</link><category>Preview</category><category>Blackberry</category><category>RIM</category><category>Forensics</category><category>8310</category><category>Mac</category><category>Photo</category><category>Windows</category><category>EXIF</category><category>Investigation</category><category>Untitled</category><category>Security</category><category>EXIF Viewer</category><category>Privacy</category><category>InfranView</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 23 Jan 2009 11:43:18 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-6317295845855370027</guid><description>&lt;p&gt;While working on a forensic investigation that involved a Blackberry 8310 I ran into an issue that just didn't settle right with me. I wanted to ensure that, beyond a reasonable doubt, the EXIF time stamp embedded within a photo taken by the Blackberry device was written accurately by the device. Before signing off on the validity of the EXIF time stamp, something just didn't seem right. After digging around and doing countless tests, I was surprised that I was able to consistently recreate a failure whereby the incorrect time stamp was written to the original date/time EXIF field. Here are additional details:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DEVICE&lt;/strong&gt;: Blackberry Curve 8310 smartphone (EDGE)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;VERSIONS&lt;/strong&gt;: v4.5.0.55 (Platform 2.7.0.68) &amp;amp; v4.5.0.110 (Platform 2.7.0.90)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PROVIDER&lt;/strong&gt;: AT&amp;amp;T&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DATE/TIME SOURCE&lt;/strong&gt;S: Blackberry &amp;amp; Network&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ADDITIONAL ENABLED SETTINGS WORTH NOTING&lt;/strong&gt;:&lt;br /&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;PASSWORD (&lt;em&gt;options | security options | general settings | password&lt;/em&gt;)&lt;/li&gt;

  &lt;li&gt;BACKLIGHT TIMEOUT value of 30 seconds (&lt;em&gt;options | screen/keyboard | backlight timeout)&lt;/em&gt;&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;SECURITY TIMEOUT value of 1 minute (&lt;em&gt;options | security options | general settings | security timeout&lt;/em&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;OBSERVED BEHAVIOR&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;The EXIF original date/time embedded within a photo taken by the Blackberry 8310 had the incorrect time stamp. Consistently and repeatedly I was able to have the Blackberry device write the incorrect time stamp to the EXIF field. The EXIF original date/time was inconsistent with the actual date/time that the photo was taken in addition to the “Last Modified” time displayed by the Blackberry device.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;SCENARIO REPRODUCING THE PROBLEM&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;I take a photo with the Blackberry at 0600 on 1/22/2009. The image name is IMG00001. Using the Blackberry and looking at the properties of photo IMG00001 I see the correct “Last Modified” date and time of “Jan 22, 2009 6:00AM”. Emailing the photo to my email address I then view the EXIF data of the photo on a separate forensics system and see the correct original date/time of “2009:01:22 06:00:00”.&lt;/li&gt;

  &lt;li&gt;An hour passes. I delete IMG00001 from the Blackberry and then take a photo at 0700 on 1/22/2009. The image name is IMG00002. Using the Blackberry and looking at the properties of photo IMG00002 I see the correct “Last Modified” date and time of “Jan 22, 2009 7:00AM”. Again, I email myself the photo and view the EXIF data of the photo on a separate forensics system. However, this time I see the incorrect original date/time. The EXIF field shows “2009:01:22 07:02:00”.&lt;/li&gt;

  &lt;li&gt;[update: 1/23/2009] - I can also reproduce this EXIF incorrect time stamp issue &lt;em&gt;without&lt;/em&gt; deleting photos. This issue presents itself &lt;em&gt;only&lt;/em&gt; with the first photo taken after the phone has automatically locked, requiring a password to unlock before the said photo with the incorrect EXIF time stamp can be taken by the device. Subsequent photos taken before the security timeout locks the device have the correct EXIF time stamps.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;IMPLICATIONS&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;An assumption is made that the Blackberry device is writing the correct date/time within the EXIF data when a photo is taken with the device. EXIF data within photos could potentially be used as evidence to support what an individuals recorded statement (e.g., whereabouts at a given time). From my tests there’s reasonable doubt that the EXIF time stamp of a photo taken by a Blackberry 8310 device (and perhaps others) may be incorrect. Therefore, EXIF time stamps from photos used as evidence becomes highly questionable and ultimately, and likely, could be rendered irrelevant.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;ADDITIONAL NOTES &amp;amp; QUESTIONS&lt;/span&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Blackberry and RIM have been contacted to investigate and confirm the issue.&lt;/li&gt;

  &lt;li&gt;I was able to reproduce this issue on a single Blackberry Curve 8310 which was initially running v4.5.0.55 (Platform 2.7.0.68). I was also able to reproduce the failure after upgrading the same Blackberry Curve 8310 to v4.5.0.110 (Platform 2.7.0.90).&lt;/li&gt;

  &lt;li&gt;I viewed the EXIF data on a Mac using both “EXIF Viewer” and “Preview”. I viewed the EXIF data on a Windows XP system using “InfranView” with the EXIF plugin installed.&lt;/li&gt;

  &lt;li&gt;Can others reproduce the same issue on 8310’s running similar and/or different firmwares?&lt;/li&gt;

  &lt;li&gt;Can others reproduce the same issue on non-8310 Blackberry devices?&lt;/li&gt;

  &lt;li&gt;[update: 1/23/2009] - Could this be a residual artifact of the security lockout feature? (will need to test after disabling the security timeout)&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: justify;"&gt;
  &lt;center&gt;
    &lt;img src="http://farm4.static.flickr.com/3411/3218066475_bc2f4f8277_o.jpg" width="300" height="343" alt="Blackberry8310_300x343.shkl.jpg" /&gt;
  &lt;/center&gt;
&lt;/div&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-6317295845855370027?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nwr-2QnQugQ:Bo4k68UEQik:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nwr-2QnQugQ:Bo4k68UEQik:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nwr-2QnQugQ:Bo4k68UEQik:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=nwr-2QnQugQ:Bo4k68UEQik:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nwr-2QnQugQ:Bo4k68UEQik:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nwr-2QnQugQ:Bo4k68UEQik:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/nwr-2QnQugQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-01-23T11:43:18.737-08:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.zenone.org/2009/01/forensics-blackberry-curve-8310-and.html</feedburner:origLink></item><item><title>Tools To Get Things Done</title><link>http://feedproxy.google.com/~r/morphic/~3/jgd1o-Dx7NE/tools-to-get-things-done.html</link><category>Productivity</category><category>Get Things Done</category><category>Jott</category><category>Remember The Milk</category><category>Journler</category><category>GTD</category><category>ReQall</category><category>RTM</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Sun, 11 Jan 2009 00:08:15 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7481940655366561401</guid><description>&lt;blockquote&gt;
  &lt;p style="text-align: left;"&gt;&lt;em&gt;“Give us the tools and we will finish the job.”&lt;/em&gt; &lt;em&gt;~&amp;nbsp;&amp;nbsp;Winston Churchill&lt;/em&gt;&lt;br /&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Managing tasks and keeping notes readily accessible and easily searchable has been an ongoing challenge for me. In 1997 I took a Franklin Time Management class and clearly understood the necessity to effectively manage my tasks and time. However, carrying an awkward organizer with me wherever I went wasn't convenient, and I often found it annoying to pull my organizer out when I needed review my schedule and often difficult to quickly locate notes that I had taken previously.&lt;/p&gt;
&lt;p&gt;Fortunately...through need, advances in technology and the synergy of creative minds, many electronic productivity tools have surfaced in the market over the years to help with staying organized and getting things done.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;Task Management&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Over the past several years I've used tools such as &lt;a href="http://jott.com/" target="_blank"&gt;Jott&lt;/a&gt; and Remember The Milk (&lt;a href="http://www.rememberthemilk.com/" target="_blank"&gt;RTM&lt;/a&gt;) to help me with managing my tasks. Over a period of time I found myself growing more and more frustrated with the two productivity tools. Jott started charging money for a service that did a mediocre job with converting speech-to-text. I tethered RTM with Jott for adding tasks through speech...in other words, I was using two productivity tools to do what one should have been able to do independently.&lt;/p&gt;
&lt;p&gt;I can't expect to meet the challenges of today with yesterday's tools and expect to be in business tomorrow. Fortunately, I found a very powerful yet easy to use productivity tool that has been working extremely well for me. Several months ago I started using &lt;a href="http://www.reqall.com/" target="_blank"&gt;ReQall&lt;/a&gt; as a replacement for both Jott and RTM. What exactly is ReQall? According to the marketing blurb on the ReQall website:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;"ReQall is the best memory tool you may ever have, connecting all the ways you communicate in one easy-to-use reminder system. Use it on the web (no software to install!) or download it into your iPhone or BlackBerry smartphone. ... By integrating voice input, speech-to-text transcription, automatic organization and multi-platform reminders, ReQall goes beyond typical to-do and reminder applications."&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I've been using ReQall to manage my tasks and shopping lists. From my experience ReQall does a much better job with speech-to-text conversions than with Jott. ReQall's web interface to manage tasks is simpler to use. I'm able to add tasks via the following; web (text), iphone app (text and voice), firefox plugin (text), phone (voice), and &lt;a href="http://blog.zenone.org/2008/07/security-instant-messaging-and-enabling.html" target="_blank"&gt;instant messaging&lt;/a&gt; (text). Plus, I appreciate now having a single solution (ReQall) to do what I had been doing with two (Jott and RTM).&lt;/p&gt;
&lt;p&gt;ReQall also allows me to add meetings and schedule tasks for specific dates and times. For example, on my iPhone I can launch the ReQall app and say the following note:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;"Meet with Mike on Friday at 3pm"&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The above voice note gets converted to text by ReQall. Adding my ReQall meeting feed to my Google Calendar I then see a meeting on Friday at 3pm with Mike! I also synch my iCal with Google Calendar so that my schedule stays current and easily accessible no matter where I'm accessing it.&lt;/p&gt;
&lt;p&gt;If I want to add an item to my shopping list, all I have to do is say "&lt;em&gt;buy&lt;/em&gt;" and whatever it is I need to pick up at the market. Whoala, the item gets converted to text and shows up in my shopping list. My shopping list can be accessed and individual items checked off from my iPhone while at the store.&lt;/p&gt;
&lt;p&gt;Though ReQall is currently a very useful productivity tool, there's room for improvement that will increase ReQall's value. Features I would like to see include:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;A ReQall desktop widget for Mac (RTM already has a &lt;a href="http://spedr.com/4yd1u" target="_blank"&gt;desktop widget&lt;/a&gt; for Mac OS X)&lt;/li&gt;

  &lt;li&gt;Ability to view all To-Do's and shopping list items via the Firefox extension&lt;/li&gt;

  &lt;li&gt;Ability to check items off as completed via Firefox extension&lt;/li&gt;

  &lt;li&gt;Ability to check items off as completed via the IM interface&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;iPhone app: Have shared shopping list entries show up in my shopping list AS WELL as my recipient's shopping list&lt;/li&gt;

  &lt;li&gt;iPhone app: Auto refresh when starting app, making changes to items, and at specified time intervals (e.g., every 15 mins)&lt;/li&gt;

  &lt;li&gt;iPhone app: Ability to change user/pass from the ReQall app instead of having to go through the standard iPhone settings app&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I look forward to seeing what ReQall will rollout throughout 2009!&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;em&gt;“Computers are magnificent tools for the realization of our dreams, but no machine can replace the human spark of spirit, compassion, love, and understanding.” ~ Louis Gerstner&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;Note Taking, Journaling and Retrieval&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: left;"&gt;Over the past six months I've been using &lt;a href="http://journler.com/" target="_blank" style="background-color: rgba(0, 0, 0, 0); color: #BB3300; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 18px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-align: left; text-decoration: underline; text-indent: 0px; clip-rule: nonzero; flood-color: #000000; flood-opacity: 1; lighting-color: #FFFFFF; stop-color: #000000; stop-opacity: 1; pointer-events: visiblepainted; color-interpolation: srgb; color-interpolation-filters: linearrgb; color-rendering: auto; fill: #000000; fill-opacity: 1; fill-rule: nonzero; image-rendering: auto; shape-rendering: auto; stroke-linecap: butt; stroke-linejoin: miter; stroke-miterlimit: 4; stroke-opacity: 1; text-rendering: auto; alignment-baseline: auto; baseline-shift: baseline; dominant-baseline: auto; text-anchor: start; writing-mode: lr-tb; glyph-orientation-horizontal: 0deg; glyph-orientation-vertical: auto;"&gt;Journler&lt;/a&gt; to record and search through my notes. Journler was great so long as I had my laptop next to me when I needed to retrieve notes. Ultimately, what I needed was a solution that would allow me to securely access my notes from my iPhone as well as from the web. I also wanted a productivity tool that would let me take photos with my iPhone, or other camera, of whiteboards at the conclusion of a work meeting and would place the photo into my notes and preferably convert the words on the whiteboard from the photo into searchable text (&lt;a href="http://en.wikipedia.org/wiki/Optical_character_recognition" target="_blank"&gt;OCR&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Last month a co-worker of mine asked about &lt;a href="http://evernote.com/" target="_blank"&gt;Evernote&lt;/a&gt;. Simply put, Evernote is incredibly useful! According to the Evernote website:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;"Evernote allows you to easily capture information in any environment using whatever device or platform you find most convenient, and makes this information accessible and searchable at any time, from anywhere."&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I've now migrated all of my Journler entries into Evernote. It goes without saying, I don't store anything sensitive in Evernote unless PGP'd. I can access my notes from the web browser on my laptop, the Evernote application, and from my iPhone. Imagine I was in a meeting this morning and I took a picture of the whiteboard where the word "Monkey" was written. Evernote will convert the writing into text and make it searchable. Therefore, I can search my Evernotes for the word "Monkey" and the picture of the whiteboard will be a returned result. That's awesome!&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;img src="http://farm4.static.flickr.com/3398/3181368980_e73f216459_o.png" width="200" height="300" alt="IMG_0001_200x300.shkl.PNG" style="padding-top: 2px; padding-bottom: 2px; padding-right: 2px; padding-left: 2px;" name="3181368980_e73f216459_o.png" /&gt;&lt;br /&gt;
&lt;em&gt;Screenshot: Evernote iPhone App&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Additional features I would like to see in Evernote include:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Strong crypto that can be applied to specific notes requiring a separate password to encrypt/decrypt for enhanced security and privacy - see next bullet point regarding two-factor authentication;&lt;/li&gt;

  &lt;li&gt;Two-factor authentication with support for one-time-passwords (see &lt;a href="http://spedr.com/4r4w6" target="_blank"&gt;PayPal Security Key&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Overall, I see productivity tools finally getting to a point where there's a noticeable benefit in my productivity in using them. ReQall and Evernote are two such productivity tools.&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;em&gt;“When you write down your ideas you automatically focus your full attention on them. Few if any of us can write one thought and think another at the same time. Thus a pencil and paper make excellent concentration tools.”&lt;/em&gt; ~ Michael Leboeuf&lt;br /&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7481940655366561401?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=jgd1o-Dx7NE:bx__Mm3663o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=jgd1o-Dx7NE:bx__Mm3663o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=jgd1o-Dx7NE:bx__Mm3663o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=jgd1o-Dx7NE:bx__Mm3663o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=jgd1o-Dx7NE:bx__Mm3663o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=jgd1o-Dx7NE:bx__Mm3663o:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/jgd1o-Dx7NE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-01-11T00:08:15.070-08:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2009/01/tools-to-get-things-done.html</feedburner:origLink></item><item><title>Microsoft out-of-band security bulletin for October 2008</title><link>http://feedproxy.google.com/~r/morphic/~3/2MAgeUWt_c4/microsoft-out-of-band-security-bulletin.html</link><category>Security</category><category>attack</category><category>Windows</category><category>Vulnerability</category><category>hacker</category><category>Exploit</category><category>Microsoft</category><category>Windows XP</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Thu, 23 Oct 2008 14:25:45 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-2670643939890547752</guid><description>&lt;p&gt;Microsoft recently issued an out-of-band security advisory for a vulnerability in the server service that could allow remote code execution (MS08-067). Due to the criticality of the vulnerability, Microsoft has released a fix out-of-band (i.e., not on the regular Patch Tuesday).&lt;/p&gt;
&lt;p&gt;It is strongly recommended that patches be tested and applied to all vulnerable systems you administrate as soon as possible. According to one source, targeted attacks using this vulnerability to compromise fully-patched Windows XP and Windows Server 2003 systems have been seen.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Advisories&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx" title="MS08-067" target="_blank"&gt;MS08-67&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/31874" title="Security Focus" target="_blank"&gt;SecurityFocus&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Additional Information&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx" title="Technet Blog" target="_blank"&gt;Technet Blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Steve&lt;br /&gt;
###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-2670643939890547752?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2MAgeUWt_c4:61A9u22-6XI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2MAgeUWt_c4:61A9u22-6XI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2MAgeUWt_c4:61A9u22-6XI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=2MAgeUWt_c4:61A9u22-6XI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2MAgeUWt_c4:61A9u22-6XI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2MAgeUWt_c4:61A9u22-6XI:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/2MAgeUWt_c4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-23T14:25:45.950-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/10/microsoft-out-of-band-security-bulletin.html</feedburner:origLink></item><item><title>Made the Switch to Mac</title><link>http://feedproxy.google.com/~r/morphic/~3/aJC9X7VfY-I/made-switch-to-mac.html</link><category>Productivity</category><category>OS X</category><category>Desktop</category><category>Mac</category><category>Operating System</category><category>Windows</category><category>Unix</category><category>RedHat</category><category>ecto</category><category>Ubuntu</category><category>Leopard</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 14:17:23 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-6847799506577181270</guid><description>&lt;p&gt;Years back I made the switch from Windows to RedHat as my desktop OS of choice. I wasn't too impressed with it as a Desktop OS and eventually migrated over to Ubuntu, which I immediately fell in love with. Last week I finally made the move to using a Mac as my preferred "desktop" operating system. After traveling from Singapore, to Alaska, and then to St. Louis, I finally have my PowerBook Pro. I didn't do the traveling - rather, my Mac was shipped from Singapore and made the journey halfway around the world.&lt;/p&gt;
&lt;p&gt;Every time I'm on my MacBook I find myself very impressed with how smooth and fully integrated the system is. Simply put, the system is awesome! I've also installed VMware Fusion so that I can virtually run Windows from my BootCamp partition, allowing me to still run the Windows dependent programs necessary for me to get my work done as efficiently as possible.&lt;/p&gt;
&lt;p&gt;This morning I installed a blogging client called "ecto", which I'm trying out for the first time with this posting.&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;
&lt;p&gt;###&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-6847799506577181270?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aJC9X7VfY-I:P6N8u8a_OdE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aJC9X7VfY-I:P6N8u8a_OdE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aJC9X7VfY-I:P6N8u8a_OdE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=aJC9X7VfY-I:P6N8u8a_OdE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aJC9X7VfY-I:P6N8u8a_OdE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=aJC9X7VfY-I:P6N8u8a_OdE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/aJC9X7VfY-I" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T14:17:23.096-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.zenone.org/2008/09/made-switch-to-mac.html</feedburner:origLink></item><item><title>Blackhat Briefings: The Talks I Plan on Attending</title><link>http://feedproxy.google.com/~r/morphic/~3/vuWEWZKDZSY/blackhat-briefings-talks-i-plan-on.html</link><category>BlackHat</category><category>Security</category><category>Fyodor</category><category>Las Vegas</category><category>Hacking</category><category>Kaminsky</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:47:25 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-6753123708235146647</guid><description>&lt;p&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_f5zPJR8dXDg/SJkCKDb2wLI/AAAAAAAADBo/PM5hNkb1JEo/s1600-h/blackhat.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://2.bp.blogspot.com/_f5zPJR8dXDg/SJkCKDb2wLI/AAAAAAAADBo/PM5hNkb1JEo/s200/blackhat.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5231214813911630002" /&gt;&lt;/a&gt;The &lt;em&gt;Blackhat Trainings&lt;/em&gt; just wrapped up and now everybody here is getting ready for the &lt;em&gt;Blackhat Briefings&lt;/em&gt;.&lt;br /&gt;
&lt;br /&gt;
After today's training I picked up my &lt;em&gt;official annual Blackhat swag bag&lt;/em&gt;. While picking up my bag there were slews of people wandering around the Caesar's Palace Convention Center for the briefings. The number of people seems to have doubled since the trainings, which is typical.&lt;br /&gt;
&lt;br /&gt;
Last week I had looked online at the list of presentations and had written down what I wanted to attend. This afternoon I reviewed my list against what was shown within the printed brochure. Assuming there's room, my plan is to attend the following presentations at the &lt;em&gt;Blackhat Briefings&lt;/em&gt; for the next two days:&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Day 1 - August 6&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;0900-0950 - &lt;em&gt;Keynote: Complexity in Computer Security&lt;/em&gt; - Ian Angell&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;1000-1100 - &lt;em&gt;Nmap: Scanning the Interne&lt;/em&gt;t - Fyodor Vaskovich&lt;/li&gt;

  &lt;li&gt;1115-1230 - &lt;em&gt;DNS Goodness&lt;/em&gt; - Dan Kaminsky&lt;/li&gt;

  &lt;li&gt;1345-1500 - &lt;em&gt;Client-Side Security&lt;/em&gt; - Petko D. Petkov&lt;/li&gt;

  &lt;li&gt;1515-1630 - &lt;em&gt;Xploiting Google Gadgets: Gmalware and Beyond&lt;/em&gt; - Tom Stracener&lt;/li&gt;

  &lt;li&gt;1645-1800 - &lt;em&gt;MetaPost Exploitation&lt;/em&gt; - Val Smith&lt;/li&gt;
&lt;/ul&gt;&lt;strong&gt;Day 2 - August 7&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;
  &lt;li&gt;0900-0950 - &lt;em&gt;Keynote: Natural Security&lt;/em&gt; - Rod Beckstrom&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;1000-1100 - &lt;em&gt;Satan is on My Friends List&lt;/em&gt; - Shawn Moyer &amp;amp; Nathan Hamiel&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;1115-1230 - &lt;em&gt;Visual Forensic Analysis and Reverse Engineering&lt;/em&gt; - Greg Conti &amp;amp; Erik Dean&lt;/li&gt;

  &lt;li&gt;1345-1500 - &lt;em&gt;Hacking and Injecting Federal Trojans&lt;/em&gt; - Lukas Grunwald&lt;/li&gt;

  &lt;li&gt;1515-1630 - The Internet is Broken - Nathan McFeters, Rob Carter &amp;amp; John Heasman&lt;/li&gt;

  &lt;li&gt;1645-1800 - &lt;em&gt;Pushing the Camel Through the Eye of a Needle&lt;/em&gt; - Haroon Meer &amp;amp; Marco Slaviero&lt;/li&gt;
&lt;/ul&gt;For those of you in Twitterland - tweet me if you're going to any of the same presentations and want to say &lt;em&gt;"hi"&lt;/em&gt; [&lt;a href="http://twitter.com/morphic" target="_blank"&gt;twitter&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Steve Zenone&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-6753123708235146647?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=vuWEWZKDZSY:iJ4tX3-b9Xc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=vuWEWZKDZSY:iJ4tX3-b9Xc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=vuWEWZKDZSY:iJ4tX3-b9Xc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=vuWEWZKDZSY:iJ4tX3-b9Xc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=vuWEWZKDZSY:iJ4tX3-b9Xc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=vuWEWZKDZSY:iJ4tX3-b9Xc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/vuWEWZKDZSY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:47:25.924-07:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/_f5zPJR8dXDg/SJkCKDb2wLI/AAAAAAAADBo/PM5hNkb1JEo/s72-c/blackhat.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.zenone.org/2008/08/blackhat-briefings-talks-i-plan-on.html</feedburner:origLink></item><item><title>Productivity: Useful Meetings</title><link>http://feedproxy.google.com/~r/morphic/~3/n1qdYWUyVzM/productivity-useful-meetings.html</link><category>Meetings</category><category>Productivity</category><category>Dilbert</category><category>Agenda</category><category>Dumb Little Man</category><category>Objectives</category><category>Personal Development</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:47:57 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-8655580058917019893</guid><description>&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_f5zPJR8dXDg/SHUJ_381DJI/AAAAAAAAC88/bpgch8fmOwE/s1600-h/conferenceroom.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://4.bp.blogspot.com/_f5zPJR8dXDg/SHUJ_381DJI/AAAAAAAAC88/bpgch8fmOwE/s200/conferenceroom.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5221090335961451666" /&gt;&lt;/a&gt;Aaron, of the &lt;a href="http://www.dumblittleman.com/2008/07/8-ways-to-avoid-unproductive-meetings.html" target="_blank"&gt;Dumb Little Man blog&lt;/a&gt;, just posted a helpful reminder that includes eight tips we all [should] intuitively know in order to keep meetings focussed and useful. I think we've all experienced "those" types of work meetings; whereby hours pass and very little progress, if any, has been made. The result is wasted time, wasted money, and often frustration and confusion.&lt;br /&gt;
&lt;br /&gt;
Aaron writes:&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
  The phenomenon of chronic, pointless meetings is also known as the Dilbert Meeting in some circles. Dilbert Meetings happen every day, wasting people's time and patience.&lt;br /&gt;
  &lt;br /&gt;
  Meetings can be quite productive, but most organizers simply don’t take the steps to guarantee that a meeting will be useful.
&lt;/blockquote&gt;Aaron then lists and expands upon the following eight points:&lt;br /&gt;
&lt;ul&gt;
  &lt;li&gt;Have a clear agenda&lt;/li&gt;

  &lt;li&gt;Make sure that only attendees are people who need to be present&lt;/li&gt;

  &lt;li&gt;Establish objectives for the meeting&lt;/li&gt;

  &lt;li&gt;Have the attendees prepare in advance (if necessary)&lt;/li&gt;

  &lt;li&gt;Keep it short&lt;/li&gt;

  &lt;li&gt;Record key points and decisions&lt;/li&gt;

  &lt;li&gt;Create action items and assign them&lt;/li&gt;

  &lt;li&gt;Report progress and follow-up&lt;/li&gt;
&lt;/ul&gt;I believe it's important for all of us who propose meetings to incorporate the above points into how we organize and run our meetings. The result will be better for the business, and better for the development and morale of those attending.&lt;br /&gt;
&lt;br /&gt;
Steve Zenone&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-8655580058917019893?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n1qdYWUyVzM:2uhI3UdvOi0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n1qdYWUyVzM:2uhI3UdvOi0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n1qdYWUyVzM:2uhI3UdvOi0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=n1qdYWUyVzM:2uhI3UdvOi0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n1qdYWUyVzM:2uhI3UdvOi0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=n1qdYWUyVzM:2uhI3UdvOi0:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/n1qdYWUyVzM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:47:57.649-07:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/_f5zPJR8dXDg/SHUJ_381DJI/AAAAAAAAC88/bpgch8fmOwE/s72-c/conferenceroom.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.zenone.org/2008/07/productivity-useful-meetings.html</feedburner:origLink></item><item><title>Security: Thoughts on Latest DNS Vulnerability</title><link>http://feedproxy.google.com/~r/morphic/~3/BhD16sEFmyQ/security-thoughts-on-latest-dns.html</link><category>Risk Rating</category><category>BlackHat</category><category>DNS</category><category>BIND</category><category>Security</category><category>VU#800113</category><category>Karminsky</category><category>Vulnerability</category><category>Twitter</category><category>Exploit</category><category>Doxpara.com</category><category>CERT</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:48:18 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-4850765824943857515</guid><description>&lt;p&gt;While on a quick trail run before work this morning, I was thinking about yesterday's announcement of a serious vulnerability in the DNS protocol. For those that don't know, yesterday &lt;a href="http://doxpara.com/" target="_blank"&gt;Dan Kaminsky&lt;/a&gt; announced that there's a fundamental flaw in the DNS protocol. Shortly thereafter the United States Computer Emergency Readiness Team (&lt;a href="http://www.kb.cert.org/vuls/id/800113" target="_blank"&gt;US-CERT&lt;/a&gt;) issued a security advisory titled, "Multiple DNS implementations vulnerable to cache poisoning".&lt;br /&gt;
&lt;br /&gt;
Since we're talking about a fundamental flaw within the DNS protocol itself, &lt;em&gt;many&lt;/em&gt; implementations of DNS are considered to be vulnerable. DNS, in a nutshell, is what translates human readable and memorizable names, such as www.blackhat.com, to IP addresses that can get routed through the Net, such as 66.240.206.90.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://media.blackhat.com/webinars/blackhat-kaminsky-dns-press-conference.mp3" target="_blank"&gt;BlackHat&lt;/a&gt; has made available a recording of the press conference at which Karminsky made the public announcement. Karminsky has also made available an &lt;a href="http://doxpara.com/" target="_blank"&gt;online tool&lt;/a&gt; to check whether or not the primary DNS server you're using is vulnerable. A recent &lt;a href="http://mailman.nanog.org/pipermail/nanog/2008-July/001966.html" target="_BLANK"&gt;post&lt;/a&gt; on NANOG has a link to a perl script that allows one to run Karminsky's DNS checker against &lt;em&gt;any&lt;/em&gt; nameserver.&lt;br /&gt;
&lt;br /&gt;
I've heard a few individuals state that this latest &lt;a href="http://twitter.com/tqbf/statuses/853104857" target="_blank"&gt;vulnerability isn't critical&lt;/a&gt; in nature. We do know that Karminsky will be releasing full details of the vulnerability at next month's BlackHat in Las Vegas. It &lt;em&gt;is&lt;/em&gt; also possible that exploit code could emerge prior since Karminsky did narrow down the area in which the DNS design flaw exists. Though Karminsky has stated, "This is not enough information to reverse engineer the flaw," I believe it's an extremely risky assumption for businesses to base delaying the patching of their vulnerable name servers upon.&lt;br /&gt;
&lt;br /&gt;
Looking at a risk matrix, I see the this DNS vulnerability as a &lt;em&gt;high&lt;/em&gt; risk:&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Likelihood of exploitation: LOW/MEDIUM [ within 30 days]&lt;br /&gt;&lt;/em&gt;Impact of exploitation: HIGH&lt;br /&gt;
&lt;em&gt;-----------------&lt;/em&gt;&lt;br /&gt;
&lt;em&gt;Risk Rating: HIGH&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
One individual I know had stated, "In terms of DNS, the world isn't any more dangerous today than it was yesterday." However, we're not just dealing with randomization of source ports which had been known publicly for several years (back in &lt;a href="http://isc.sans.org/diary.html?storyid=4693&amp;amp;rss" target="_BLANK"&gt;2005&lt;/a&gt;). We're also dealing with the weak entropy in the DNS transfer id (DNS XID). I believe that the risk, or danger, &lt;em&gt;has&lt;/em&gt; increased.&lt;br /&gt;
&lt;br /&gt;
&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_f5zPJR8dXDg/SHTm-4ENo-I/AAAAAAAAC80/c3itp5RkzD4/s1600-h/leveefail.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://3.bp.blogspot.com/_f5zPJR8dXDg/SHTm-4ENo-I/AAAAAAAAC80/c3itp5RkzD4/s200/leveefail.jpg" alt="" border="0" /&gt;&lt;/a&gt;In some uncomfortable way, this latest issue with DNS reminds me of the levees in New Orleans that were known to have severe vulnerabilities. Eventually the threat (heavy rain) exploited (broke) the vulnerability (failing levees) resulting in negative impact (flooding, financial loss and loss of life). Ignoring the vulnerability with the levees didn't remove the risk or make things any "safer".&lt;br /&gt;
&lt;br /&gt;
I'm interested to see what Karminsky produces at the upcoming BlackHat.&lt;br /&gt;
&lt;br /&gt;
Steve Zenone&lt;br /&gt;
###&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;[UPDATE - 7/10/2008&lt;/strong&gt;]: Yet another option to test your nameserver is to use the &lt;em&gt;dig&lt;/em&gt; hack from &lt;a href="http://lists.oarci.net/pipermail/dns-operations/2008-July/002932.html" target="_blank"&gt;Duane Wessels&lt;/a&gt;; from a unix shell type 'dig +short @&lt;em&gt;nameserver-to-be-tested&lt;/em&gt; porttest.dns-oarc.net TXT'.&lt;br /&gt;
&lt;br /&gt;
A vulnerable nameserver will display the following output:&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;z.y.x.w.v.u.t.s.r.q.p.o.n.m.l.k.j.i.h.g.f.e.d.c.b.a.pt.dns-oarc.net.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: courier new;"&gt;"&lt;/span&gt;&lt;span style="font-style: italic; font-family: courier new;"&gt;nameserver-you-tested&lt;/span&gt; &lt;span style="font-family: courier new;"&gt;is&lt;/span&gt; &lt;span style="font-weight: bold; font-family: courier new;"&gt;POOR&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;: 22 queries in 0.6 seconds from 1 ports with std dev 0.00"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
In turn, a better maintained nameserver will return the following:&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: courier new;font-size:85%;"&gt;z.y.x.w.v.u.t.s.r.q.p.o.n.m.l.k.j.i.h.g.f.e.d.c.b.a.pt.dns-oarc.net.&lt;br /&gt;
"&lt;em&gt;nameserver-you-tested&lt;/em&gt; is &lt;strong&gt;GOOD&lt;/strong&gt;: 22 queries in 0.6 seconds from 1 ports with std dev 0.00"&lt;/span&gt;&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-4850765824943857515?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=BhD16sEFmyQ:lkZlQwisaCU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=BhD16sEFmyQ:lkZlQwisaCU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=BhD16sEFmyQ:lkZlQwisaCU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=BhD16sEFmyQ:lkZlQwisaCU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=BhD16sEFmyQ:lkZlQwisaCU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=BhD16sEFmyQ:lkZlQwisaCU:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/BhD16sEFmyQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:48:18.562-07:00</app:edited><media:thumbnail url="http://3.bp.blogspot.com/_f5zPJR8dXDg/SHTm-4ENo-I/AAAAAAAAC80/c3itp5RkzD4/s72-c/leveefail.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><media:content url="http://feedproxy.google.com/~r/morphic/~5/tLhi7Cr79fY/blackhat-kaminsky-dns-press-conference.mp3" type="audio/mpeg" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> While on a quick trail run before work this morning, I was thinking about yesterday's announcement of a serious vulnerability in the DNS protocol. For those that don't know, yesterday Dan Kaminsky announced that there's a fundamental flaw in the DNS prot</itunes:subtitle><itunes:author>noreply@blogger.com (Steve Zenone)</itunes:author><itunes:summary> While on a quick trail run before work this morning, I was thinking about yesterday's announcement of a serious vulnerability in the DNS protocol. For those that don't know, yesterday Dan Kaminsky announced that there's a fundamental flaw in the DNS protocol. Shortly thereafter the United States Computer Emergency Readiness Team (US-CERT) issued a security advisory titled, "Multiple DNS implementations vulnerable to cache poisoning". Since we're talking about a fundamental flaw within the DNS protocol itself, many implementations of DNS are considered to be vulnerable. DNS, in a nutshell, is what translates human readable and memorizable names, such as www.blackhat.com, to IP addresses that can get routed through the Net, such as 66.240.206.90. BlackHat has made available a recording of the press conference at which Karminsky made the public announcement. Karminsky has also made available an online tool to check whether or not the primary DNS server you're using is vulnerable. A recent post on NANOG has a link to a perl script that allows one to run Karminsky's DNS checker against any nameserver. I've heard a few individuals state that this latest vulnerability isn't critical in nature. We do know that Karminsky will be releasing full details of the vulnerability at next month's BlackHat in Las Vegas. It is also possible that exploit code could emerge prior since Karminsky did narrow down the area in which the DNS design flaw exists. Though Karminsky has stated, "This is not enough information to reverse engineer the flaw," I believe it's an extremely risky assumption for businesses to base delaying the patching of their vulnerable name servers upon. Looking at a risk matrix, I see the this DNS vulnerability as a high risk: Likelihood of exploitation: LOW/MEDIUM [ within 30 days] Impact of exploitation: HIGH ----------------- Risk Rating: HIGH One individual I know had stated, "In terms of DNS, the world isn't any more dangerous today than it was yesterday." However, we're not just dealing with randomization of source ports which had been known publicly for several years (back in 2005). We're also dealing with the weak entropy in the DNS transfer id (DNS XID). I believe that the risk, or danger, has increased. In some uncomfortable way, this latest issue with DNS reminds me of the levees in New Orleans that were known to have severe vulnerabilities. Eventually the threat (heavy rain) exploited (broke) the vulnerability (failing levees) resulting in negative impact (flooding, financial loss and loss of life). Ignoring the vulnerability with the levees didn't remove the risk or make things any "safer". I'm interested to see what Karminsky produces at the upcoming BlackHat. Steve Zenone ### [UPDATE - 7/10/2008]: Yet another option to test your nameserver is to use the dig hack from Duane Wessels; from a unix shell type 'dig +short @nameserver-to-be-tested porttest.dns-oarc.net TXT'. A vulnerable nameserver will display the following output: z.y.x.w.v.u.t.s.r.q.p.o.n.m.l.k.j.i.h.g.f.e.d.c.b.a.pt.dns-oarc.net. "nameserver-you-tested is POOR: 22 queries in 0.6 seconds from 1 ports with std dev 0.00" In turn, a better maintained nameserver will return the following: z.y.x.w.v.u.t.s.r.q.p.o.n.m.l.k.j.i.h.g.f.e.d.c.b.a.pt.dns-oarc.net. "nameserver-you-tested is GOOD: 22 queries in 0.6 seconds from 1 ports with std dev 0.00" </itunes:summary><itunes:keywords>Risk Rating, BlackHat, DNS, BIND, Security, VU#800113, Karminsky, Vulnerability, Twitter, Exploit, Doxpara.com, CERT</itunes:keywords><feedburner:origLink>http://blog.zenone.org/2008/07/security-thoughts-on-latest-dns.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/morphic/~5/tLhi7Cr79fY/blackhat-kaminsky-dns-press-conference.mp3" length="-1" type="audio/mpeg" /><feedburner:origEnclosureLink>https://media.blackhat.com/webinars/blackhat-kaminsky-dns-press-conference.mp3</feedburner:origEnclosureLink></item><item><title>Security: Instant Messaging and Enabling Business</title><link>http://feedproxy.google.com/~r/morphic/~3/nNYQeWKAdTs/security-instant-messaging-and-enabling.html</link><category>Instant Messaging</category><category>Google Talk</category><category>Security</category><category>AIM</category><category>Yahoo IM</category><category>ICQ</category><category>Risk</category><category>IM</category><category>XMPP</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:24 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-210804325638730067</guid><description>&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_f5zPJR8dXDg/SG0fkEoZu7I/AAAAAAAACvQ/vNzt60POi60/s1600-h/im-clients.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://1.bp.blogspot.com/_f5zPJR8dXDg/SG0fkEoZu7I/AAAAAAAACvQ/vNzt60POi60/s200/im-clients.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5218862247771225010" /&gt;&lt;/a&gt;I recently had a colleague ask me about the inherent risks in using Instant Messaging (IM) for business. Certainly, IM is an extremely effective way to communicate with team members and customers who may not be in close physical proximity. However, if used incorrectly, negative impact to the business can be massive.&lt;br /&gt;
&lt;br /&gt;
There's consumer grade and business grade IM solutions. Services such as Yahoo IM are considered consumer grade. All text based IMs can either be routed through a core set of central servers and then on to the recipient, or through peer-to-peer connections. When you combine consumer grade IM services with traffic flowing in the clear (i.e., unencrypted) through central servers outside of the organization's control, you end up with a significantly elevated set of risks. Are these risks worth accepting?&lt;br /&gt;
&lt;br /&gt;
Here are &lt;em&gt;some&lt;/em&gt; of the more obvious risks that I see with using consumer grade IM for business:&lt;br /&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Vulnerable Clients -- advisories for vulnerabilities in chat clients are announced fairly often. Many of these vulnerabilities allow for the remote execution of code on the vulnerable client system&lt;/li&gt;

  &lt;li&gt;Traffic can be viewed ("sniffed") -- by default, consumer grade IM clients send all of their traffic in the clear. There are plugins to provide encryption for some clients, however, all parties involved in the chat will need the crypto plugin enabled and configured correctly&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;Data theft -- a &lt;em&gt;nefario&lt;/em&gt;&lt;em&gt;us&lt;/em&gt; employee could potentially move critical/restricted data to a location offsite&lt;br /&gt;&lt;/li&gt;

  &lt;li&gt;Identity Theft -- The mechanism for consumer grade IM user authentication is weak. Grab the weak authentication traffic and an attacker now has valid login credentials. The stolen credentials can then be used to impersonate the victim and be used as a launch pad to further identify theft&lt;/li&gt;

  &lt;li&gt;Provides IP info to attackers -- if an employee decides to go to an external chatroom with their IM client, their IP is now known to anyone else in the chatroom who may be interested...including a potential attacker. With the IP the attacker can focus their attack to a specific system&lt;/li&gt;

  &lt;li&gt;Privacy...or lack thereof -- see all points above&lt;/li&gt;

  &lt;li&gt;Social Engineering -- more likely to happen if an employee engages in conversations in non-business specific chatrooms&lt;/li&gt;
&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_f5zPJR8dXDg/SG0mysTlO4I/AAAAAAAACvY/DJXmlnioYkA/s1600-h/identity-theft.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_f5zPJR8dXDg/SG0mysTlO4I/AAAAAAAACvY/DJXmlnioYkA/s200/identity-theft.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5218870195520879490" /&gt;&lt;/a&gt;Another risk is in employees using IM for business on their home computers. Imagine, for just a moment, that an employee commits a crime against the business from their home and used IM to enable them to commit the crime. Your business won't have the authority or right to confiscate their home computer for investigation - your hands are tied behind your back. I'm sure you can start seeing where the dangers and risks start to go up.&lt;br /&gt;
&lt;br /&gt;
Additionally, many chat clients will log all conversations to disk. What if confidential or restricted data is logged and stored on an individuals home computer? Other family members, or friends, may have access to that system, or perhaps the home computer is already compromised and under someone else's control (think botnet). Now the attacker can pull the chat logs and have unauthorized access to confidential or restricted data. The impact could be titanic to the business! Of course, confidential or restricted data should &lt;em&gt;never&lt;/em&gt; be sent over IM in the first place.&lt;br /&gt;
&lt;br /&gt;
In addition to having policies, procedures, and perhaps even guidelines on the proper use of IM for business, I believe the return on investment by providing an internal and redundant IM service to enable business is compelling and certainly worth considering strategically.&lt;br /&gt;
&lt;br /&gt;
Steve Zenone&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-210804325638730067?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nNYQeWKAdTs:xVXglDmq_Eo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nNYQeWKAdTs:xVXglDmq_Eo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nNYQeWKAdTs:xVXglDmq_Eo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=nNYQeWKAdTs:xVXglDmq_Eo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nNYQeWKAdTs:xVXglDmq_Eo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=nNYQeWKAdTs:xVXglDmq_Eo:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/nNYQeWKAdTs" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:24.985-07:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/_f5zPJR8dXDg/SG0fkEoZu7I/AAAAAAAACvQ/vNzt60POi60/s72-c/im-clients.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/07/security-instant-messaging-and-enabling.html</feedburner:origLink></item><item><title>Security Toolbox: RatProxy</title><link>http://feedproxy.google.com/~r/morphic/~3/ouRTO_lnKJg/toolbox-ratproxy.html</link><category>Security</category><category>OWASP</category><category>Toolbox</category><category>Open Source</category><category>Google</category><category>RatProxy</category><category>Ubuntu</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:29 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-8082038838599397327</guid><description>&lt;p&gt;The good folks from Google have released a freely available open-source web application security assessment tool called &lt;em&gt;RatProxy&lt;/em&gt;. The tool, which is still in beta, is designed to identify security vulnerabilities within web based applications.&lt;br /&gt;
&lt;br /&gt;
Quoting from the RatProxy project documentation page:&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
  "Ratproxy is a semi-automated, largely passive web application security audit tool. It is meant to complement active crawlers and manual proxies more commonly used for this task, and is optimized specifically for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments."
&lt;/blockquote&gt;Earlier this afternoon I downloaded the source code and compiled it to run on Ubuntu 8.04. After posting this blog entry I'll begin experimenting with RatProxy.&lt;br /&gt;
&lt;br /&gt;
RatProxy Documentation Page [&lt;a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Steve Zenone&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-8082038838599397327?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ouRTO_lnKJg:0AKih12DyCk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ouRTO_lnKJg:0AKih12DyCk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ouRTO_lnKJg:0AKih12DyCk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=ouRTO_lnKJg:0AKih12DyCk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ouRTO_lnKJg:0AKih12DyCk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ouRTO_lnKJg:0AKih12DyCk:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/ouRTO_lnKJg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:29.283-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/07/toolbox-ratproxy.html</feedburner:origLink></item><item><title>The Coolness of Geek</title><link>http://feedproxy.google.com/~r/morphic/~3/i2t6C9baDFg/coolness-of-geek.html</link><category>TRS-80</category><category>BASIC</category><category>Apple II</category><category>Sexy</category><category>William Gibson</category><category>Geeks</category><category>Neuromancer</category><category>Cyber</category><category>Burning Chrome</category><category>BBS</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:35 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7750684526758690414</guid><description>&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_f5zPJR8dXDg/SFhGbsgnb1I/AAAAAAAACuw/YuHK75K_iWs/s1600-h/00046.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://4.bp.blogspot.com/_f5zPJR8dXDg/SFhGbsgnb1I/AAAAAAAACuw/YuHK75K_iWs/s200/00046.jpg" alt="Steve Zenone looking at Tondelayo - girls were always cool!" border="0" /&gt;&lt;/a&gt;Apparently, &lt;em&gt;geek&lt;/em&gt; is becoming sexy. We've all known that geek was chic [pronounced &lt;em&gt;sheek&lt;/em&gt; for those who think I'm saying &lt;em&gt;chick&lt;/em&gt;]....but sexy, that's just hot! I think I've been waiting for this since the late seventies:&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
  "&lt;em&gt;The Nerd Girls may not look like your stereotypical pocket-protector-loving misfits—their adviser, Karen Panetta, has a thing for pink heels-but they're part of a growing breed of young women who are claiming the nerd label for themselves. In doing so, they're challenging the notion of what a geek should look like, either by intentionally sexing up their tech personas, or by simply finding no disconnect between their geeky pursuits and more traditionally girly interests such as fashion, makeup and high heels."&lt;/em&gt;&lt;br /&gt;
  Newsweek, "Revenge of the Nerdette", 6/9/2008
&lt;/blockquote&gt;As I sit here I get mini flashbacks of typing away on my TRS-80 in elementary school, writing my first snippets of code in BASIC, knowing that in the eyes of the masses I wasn't being &lt;em&gt;cool&lt;/em&gt;. Then, in junior high, I graduated to the the Apple II, on which platform I launched my first BBS. Soon after I added multiple phone lines and had sister systems throughout the US. Ahh, the good 'ol days of the lawless wild west, shortly before William Gibson coined the term &lt;em&gt;cyber&lt;/em&gt; in his 1982 book, &lt;em&gt;Burning Chrome&lt;/em&gt;.&lt;br /&gt;
&lt;br /&gt;
Newsweek Article [&lt;a href="http://www.newsweek.com/id/140457" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
-Steve Zenone&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7750684526758690414?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=i2t6C9baDFg:Xgt_B8iiHuY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=i2t6C9baDFg:Xgt_B8iiHuY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=i2t6C9baDFg:Xgt_B8iiHuY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=i2t6C9baDFg:Xgt_B8iiHuY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=i2t6C9baDFg:Xgt_B8iiHuY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=i2t6C9baDFg:Xgt_B8iiHuY:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/i2t6C9baDFg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:35.003-07:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/_f5zPJR8dXDg/SFhGbsgnb1I/AAAAAAAACuw/YuHK75K_iWs/s72-c/00046.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/06/coolness-of-geek.html</feedburner:origLink></item><item><title>Equiped to Get the Job Done</title><link>http://feedproxy.google.com/~r/morphic/~3/3CJ3-B1Dx7k/equiped-to-get-job-done.html</link><category>Budget</category><category>Employee Retention</category><category>Buckingham and Coffman</category><category>USA Today</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:39 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-4623597008471845898</guid><description>&lt;p&gt;I came across an article in USA Today titled, &lt;em&gt;Some employees buy own laptops, phones for work&lt;/em&gt;. The article reports that more and more professionals are buying their own electronic equipment to get their work done. This includes equipment like cell phones and even laptops!&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
  Nearly 40% of professionals recently surveyed by researcher In-Stat paid for a laptop that they regularly carried. Cellphone users often picked up their bill. And company-provided personal digital assistants (PDAs), cameras and Global Positioning Systems (GPS) are relatively rare, says the survey, released Monday.
&lt;/blockquote&gt;As many organizations start to withdraw spending on materials and equipment, professionals are having to take matters into their own hands and purchase their own equipment. This reminds me of research done by Buckingham and Coffman. Their research paper summarized the twelve key factors in retaining star employees (there's a connection here - question #2 relates to employees having to purchase their own equipment).&lt;br /&gt;
&lt;br /&gt;
In a nutshell, if employees can answer the below questions in the affirmative, then the work environment is probably very strong and productive:&lt;br /&gt;
&lt;ol&gt;
  &lt;li&gt;Do I know what is expected of me at work?&lt;/li&gt;

  &lt;li&gt;Do I have the materials and equipment I need to do my work right?&lt;/li&gt;

  &lt;li&gt;At work, do I have the opportunity to do what I do best every day?&lt;/li&gt;

  &lt;li&gt;In the last seven days, have I received recognition or praise for good work?&lt;/li&gt;

  &lt;li&gt;Does my supervisor, or someone at work, seem to care about me as a person?&lt;/li&gt;

  &lt;li&gt;Is there someone at work who encourages my development?&lt;/li&gt;

  &lt;li&gt;At work, do my opinions seem to count?&lt;/li&gt;

  &lt;li&gt;Does the mission/purpose of my company make me feel like my work is important?&lt;/li&gt;

  &lt;li&gt;Are my co-workers committed to doing quality work?&lt;/li&gt;

  &lt;li&gt;Do I have a best friend at work?&lt;/li&gt;

  &lt;li&gt;In the last six months, have I talked with someone about my progress?&lt;/li&gt;

  &lt;li&gt;At work, have I had the opportunities to learn and grow?&lt;br /&gt;&lt;/li&gt;
&lt;/ol&gt;As a manager, the above points are worth reflecting upon.&lt;br /&gt;
&lt;br /&gt;
USA Today Article [&lt;a href="http://www.usatoday.com/tech/techinvestor/corporatenews/2008-06-15-electronic-devices-workplace_N.htm" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
###

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-4623597008471845898?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CJ3-B1Dx7k:61zRU4mvEng:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CJ3-B1Dx7k:61zRU4mvEng:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CJ3-B1Dx7k:61zRU4mvEng:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=3CJ3-B1Dx7k:61zRU4mvEng:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CJ3-B1Dx7k:61zRU4mvEng:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3CJ3-B1Dx7k:61zRU4mvEng:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/3CJ3-B1Dx7k" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:39.406-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/06/equiped-to-get-job-done.html</feedburner:origLink></item><item><title>On The Air: Manualism</title><link>http://feedproxy.google.com/~r/morphic/~3/ak7arcY5lm4/on-air-manualism.html</link><category>Podcast</category><category>Radio</category><category>KUSP</category><category>Manualism</category><category>Manualist</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:42 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7639706663807765335</guid><description>&lt;p&gt;Several weeks back, on May 12, I posted a blog entry about &lt;a href="http://blog.zenone.org/2008/05/off-topic-manualism.html" target="_blank"&gt;Manualism&lt;/a&gt;; the &lt;em&gt;art&lt;/em&gt; of making music with one's hands as the instrument. I've edited the piece down to half its original size and then edited it some more. This past Sunday I went down to the radio station to record the piece and had the producers do their magic. It will air on &lt;a href="http://kusp.org/" target="_blank"&gt;KUSP&lt;/a&gt; this Friday (6/13) at 7:33am and 5:33pm in the &lt;em&gt;First Person Singular&lt;/em&gt; segment.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE #1 [6/13/2008]&lt;/strong&gt;: I believe my piece on KUSP is being delayed a week. I listened to the station this morning and someone else's &lt;em&gt;First Person Singular&lt;/em&gt; was aired...and I would imagine the same piece will be aired this afternoon. I will update this post once I learn of the new air date.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE #2 [6/13/2008]:&lt;/strong&gt; I received confirmation from the radio station that the piece &lt;em&gt;will&lt;/em&gt; air this afternoon at 5:33pm.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE #3 [6/13/2008]:&lt;/strong&gt; My piece aired this afternoon. If you missed it, you can download the two minute segment here [&lt;a href="http://www.zenone.org-a.googlepages.com/20080613-steve-kusp.mp3"&gt;link to mp3&lt;/a&gt;]&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7639706663807765335?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ak7arcY5lm4:32dJ-nyQBc4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ak7arcY5lm4:32dJ-nyQBc4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ak7arcY5lm4:32dJ-nyQBc4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=ak7arcY5lm4:32dJ-nyQBc4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ak7arcY5lm4:32dJ-nyQBc4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=ak7arcY5lm4:32dJ-nyQBc4:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/ak7arcY5lm4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:42.637-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><media:content url="http://feedproxy.google.com/~r/morphic/~5/ZayOSaBXJ4g/20080613-steve-kusp.mp3" fileSize="2001187" type="application/octet-stream" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Several weeks back, on May 12, I posted a blog entry about Manualism; the art of making music with one's hands as the instrument. I've edited the piece down to half its original size and then edited it some more. This past Sunday I went down to the radio</itunes:subtitle><itunes:author>noreply@blogger.com (Steve Zenone)</itunes:author><itunes:summary> Several weeks back, on May 12, I posted a blog entry about Manualism; the art of making music with one's hands as the instrument. I've edited the piece down to half its original size and then edited it some more. This past Sunday I went down to the radio station to record the piece and had the producers do their magic. It will air on KUSP this Friday (6/13) at 7:33am and 5:33pm in the First Person Singular segment. UPDATE #1 [6/13/2008]: I believe my piece on KUSP is being delayed a week. I listened to the station this morning and someone else's First Person Singular was aired...and I would imagine the same piece will be aired this afternoon. I will update this post once I learn of the new air date. UPDATE #2 [6/13/2008]: I received confirmation from the radio station that the piece will air this afternoon at 5:33pm. UPDATE #3 [6/13/2008]: My piece aired this afternoon. If you missed it, you can download the two minute segment here [link to mp3] </itunes:summary><itunes:keywords>Podcast, Radio, KUSP, Manualism, Manualist</itunes:keywords><feedburner:origLink>http://blog.zenone.org/2008/06/on-air-manualism.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/morphic/~5/ZayOSaBXJ4g/20080613-steve-kusp.mp3" length="2001187" type="application/octet-stream" /><feedburner:origEnclosureLink>http://www.zenone.org-a.googlepages.com/20080613-steve-kusp.mp3</feedburner:origEnclosureLink></item><item><title>PCI Security Standards Council Mandates New Vulnerability Scoring</title><link>http://feedproxy.google.com/~r/morphic/~3/lmWOlwPMrbY/pci-security-standards-council-mandates.html</link><category>penetration test</category><category>ASV</category><category>compliance</category><category>PCI DSS</category><category>vlnerability scan</category><category>CVSS</category><category>PCI</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:47 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-5461745109556485330</guid><description>&lt;p&gt;I recently learned that all Approved Scanning Vendors (ASVs) are required to use version 2 of the Common Vulnerability Scoring System (CVSS). Starting July 1, 2008, version 2 will be the new industry standard and all scans will be scored using this system.&lt;br /&gt;
&lt;br /&gt;
Many of the ASVs that I have experience with continue to fail scans based upon false positives. Although PCI DSS requirement 11.3.1 necessitates a network-layer penetration test to be performed at least once a year and after any significant infrastructure upgrade or modification, the automated quarterly vulnerability scans will still show a compliance failure even if the flagged vulnerability is a false positive.&lt;br /&gt;
&lt;br /&gt;
It'll be interesting to see how many merchants will move from compliance status of &lt;em&gt;compliant&lt;/em&gt; to &lt;em&gt;non-compliant&lt;/em&gt; after July 1.&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-5461745109556485330?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=lmWOlwPMrbY:MQgymJSEVn8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=lmWOlwPMrbY:MQgymJSEVn8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=lmWOlwPMrbY:MQgymJSEVn8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=lmWOlwPMrbY:MQgymJSEVn8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=lmWOlwPMrbY:MQgymJSEVn8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=lmWOlwPMrbY:MQgymJSEVn8:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/lmWOlwPMrbY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:47.560-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/06/pci-security-standards-council-mandates.html</feedburner:origLink></item><item><title>Sunday Post #11 - Memorial Day</title><link>http://feedproxy.google.com/~r/morphic/~3/Ub9PQ0V0Sus/sunday-post-11-memorial-day.html</link><category>Sunday Post</category><category>Memorial Day</category><category>Abraham Lincoln</category><category>Gettysburg</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:49:56 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-435921499434240483</guid><description>&lt;p&gt;Where does one begin saying "Thank You" to all those who have given everything so that we may have our freedom?&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;
&lt;div style="text-align: center;"&gt;
  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_f5zPJR8dXDg/SDuB2cziRvI/AAAAAAAACtE/qZ1_rb-tjY8/s1600-h/goldengate.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_f5zPJR8dXDg/SDuB2cziRvI/AAAAAAAACtE/qZ1_rb-tjY8/s320/goldengate.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5204896566802007794" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;Photo: Steve Zenone (Golden Gate National Cemetery)&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;blockquote&gt;
  &lt;em&gt;"That from these honored dead we take increased devotion to that cause for which they gave the last full measure of devotion ... that we here highly resolve that these dead shall not have died in vain."&lt;br /&gt;
  -- Abraham Lincoln, spoken at Gettysburg in 1863&lt;/em&gt;
&lt;/blockquote&gt;Walking through the cemetery, contemplating, I was in awe. Each tombstone not only represents a single serviceman/servicewoman. Rather, every tombstone also represents the family and friends whose lives were interwoven so intimately...in addition to the lives the family and friends touched. Clearly, we're all affected and connected.

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-435921499434240483?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=Ub9PQ0V0Sus:mfbbk-06SAc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=Ub9PQ0V0Sus:mfbbk-06SAc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=Ub9PQ0V0Sus:mfbbk-06SAc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=Ub9PQ0V0Sus:mfbbk-06SAc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=Ub9PQ0V0Sus:mfbbk-06SAc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=Ub9PQ0V0Sus:mfbbk-06SAc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/Ub9PQ0V0Sus" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:49:56.076-07:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/_f5zPJR8dXDg/SDuB2cziRvI/AAAAAAAACtE/qZ1_rb-tjY8/s72-c/goldengate.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/05/sunday-post-11-memorial-day.html</feedburner:origLink></item><item><title>Opinion: Responses to OpenSSL Vulnerability</title><link>http://feedproxy.google.com/~r/morphic/~3/3rPhD0-bhVw/opinion-why-attack-debian-and-ubuntu.html</link><category>Security</category><category>Opinion OpenSSL</category><category>linux</category><category>Fedora</category><category>Unix</category><category>RedHat</category><category>Debian</category><category>Ubuntu</category><category>FreedBSD</category><category>SUSE</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:50:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-8361479410349653832</guid><description>&lt;p&gt;As those of you in the IT Security world know, last week there was a serious vulnerability in Debian's/Ubuntu's OpenSSL random number generator [&lt;a href="http://blog.zenone.org/2008/05/security-debian-and-ubuntu-openssl.html" target="_blank"&gt;link&lt;/a&gt;].&lt;br /&gt;
&lt;br /&gt;
The vulnerability in OpenSSL was announced by the Debian Project on Thursday, May 13th, 2008 [&lt;a href="http://www.debian.org/security/2008/dsa-1571" target="_blank"&gt;link&lt;/a&gt;]. That same day updated OpenSSL packages were released for Debian, Ubuntu and Debian-based distributions [e.g., &lt;a href="http://www.ubuntu.com/usn/usn-612-1"&gt;link&lt;/a&gt;]. Shortly thereafter code was being posted to Full Disclosure and other lists to exploit this vulnerability on unpatched systems.&lt;br /&gt;
&lt;br /&gt;
I was very surprised by people's reaction regarding this vulnerability. In particular, there was a noticeable amount of OS bashing; discrediting the affected operating systems. That irony is that majority of this negative publicity came from from other *NIX centric individuals who simply stood back while proudly saying, "look, &lt;em&gt;my&lt;/em&gt; superior OS wasn't affected." It's funny that the elitist OS wars of past still continue continue today. It's also entertaining - but that's besides the point. Unfortunately, &lt;em&gt;this&lt;/em&gt; type of negative publicity doesn't contribute to building and strengthening the communities that are working so hard to build incredible flavors of their OS of choice. In one way or another, some requiring more creativity than others, the family of *NIX operating systems share a common ancestry [see UNIX family tree image below].&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;
&lt;div style="text-align: center;"&gt;
  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_f5zPJR8dXDg/SDHyiadPFUI/AAAAAAAACsQ/-ivBqnd4d2Y/s1600-h/unixhistory.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_f5zPJR8dXDg/SDHyiadPFUI/AAAAAAAACsQ/-ivBqnd4d2Y/s320/unixhistory.jpg" alt="" border="0" name="BLOGGER_PHOTO_ID_5202205717621052738" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;Click on above image to enlarge [image: &lt;a href="http://www.zwahlendesign.ch/en/node/13"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="submitted"&gt;&lt;a href="http://www.zwahlendesign.ch/en/node/13" target="_blank"&gt;ZwahlenDesign&lt;/a&gt;]&lt;/span&gt;&lt;br /&gt;
  &lt;span style="font-size:85%;"&gt;For a more complete timeline, see Eric Levenez's UNIX History [&lt;a href="http://www.levenez.com/unix/history.html" target="_blank"&gt;link&lt;/a&gt;].&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;&lt;br /&gt;
I can imagine Rodney King, while waiving a black flag with a the Linux penguin mascot, now saying, "People, I just want to say, you know, can we all get along? Can we get along?"&lt;br /&gt;
&lt;br /&gt;
I agree, it's too bad that the code that made the latest OpenSSL vulnerability a reality existed. It also highlights the blind trust people &lt;em&gt;generally&lt;/em&gt; place into the operating systems that they use. However, what I also &lt;em&gt;clearly see&lt;/em&gt; is how &lt;strong&gt;the community quickly worked together and released fixes&lt;/strong&gt; &lt;span style="font-style: italic; font-weight: bold;"&gt;prior&lt;/span&gt; &lt;strong&gt;to exploit code being widely disseminated&lt;/strong&gt;. Now, &lt;em&gt;that's&lt;/em&gt; awesome! There was no Patch Tuesday to wait for. Rather, the fixes were created, tested, and distributed as soon as possible.&lt;br /&gt;
&lt;br /&gt;
Without a doubt I'm very glad to have moved my desktop OS of choice to Ubuntu two years ago. Sure, I'd be happy with SUSE, Fedora, RedHat, FreeBSD, OpenBSD. I've used them all. However, for reasons that work for me I've settled on Ubuntu ... for now.

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-8361479410349653832?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3rPhD0-bhVw:frh9QuR3a-Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3rPhD0-bhVw:frh9QuR3a-Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3rPhD0-bhVw:frh9QuR3a-Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=3rPhD0-bhVw:frh9QuR3a-Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3rPhD0-bhVw:frh9QuR3a-Y:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=3rPhD0-bhVw:frh9QuR3a-Y:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/3rPhD0-bhVw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:50:00.988-07:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/_f5zPJR8dXDg/SDHyiadPFUI/AAAAAAAACsQ/-ivBqnd4d2Y/s72-c/unixhistory.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/05/opinion-why-attack-debian-and-ubuntu.html</feedburner:origLink></item><item><title>Security: Debian and Ubuntu OpenSSL Vulnerability</title><link>http://feedproxy.google.com/~r/morphic/~3/0y-XYgIXxI8/security-debian-and-ubuntu-openssl.html</link><category>OpenVPN</category><category>Enterprise Security</category><category>Vulnerability</category><category>ssh</category><category>Metasploit</category><category>Debian</category><category>CERT</category><category>OpenSSL</category><category>Ubuntu</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:50:08 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-7827420599414369716</guid><description>&lt;p&gt;I won't go into all the details since majority of the security mailing lists and blogs are covering the issue -- however, I'm blogging this as a reminder. The recent Debian/Ubuntu OpenSSL random number generator vulnerability is very serious, especially if you had generated any keys on Debian or Ubuntu systems running vulnerable versions of OpenSSL (e.g., ssh keys, OpenVPN keys, etc).&lt;br /&gt;
&lt;br /&gt;
There's an excellent detailed summary regarding this issue on HD Moore's web site hosted on Metasploit (link below). To quote from the website:&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
  "All SSL and SSH keys generated on Debian-based systems (Ubuntu, Kubuntu, etc) between September 2006 and May 13th, 2008 may be affected. In the case of SSL keys, all generated certificates will be need to recreated and sent off to the Certificate Authority to sign. Any Certificate Authority keys generated on a Debian-based system will need be regenerated and revoked. All system administrators that allow users to access their servers with SSH and public key authentication need to audit those keys to see if any of them were created on a vulnerabile system. Any tools that relied on OpenSSL's PRNG to secure the data they transferred may be vulnerable to an offline attack. Any SSH server that uses a host key generated by a flawed system is subject to traffic decryption and a man-in-the-middle attack would be invisible to the users. This flaw is ugly because even systems that do not use the Debian software need to be audited in case any key is being used that was created on a Debian system."
&lt;/blockquote&gt;Per the standard recommendation, &lt;strong&gt;patch all vulnerable systems as soon as possible&lt;/strong&gt;. In addition you will need to generate any keys that were created previously using vulnerable versions of OpenSSL.&lt;br /&gt;
&lt;br /&gt;
HD Moore's Website [&lt;a href="http://metasploit.com/users/hdm/tools/debian-openssl/" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
Official CERT Advisory [&lt;a href="http://www.us-cert.gov/cas/techalerts/TA08-137A.html" target="_blank"&gt;link&lt;/a&gt;]

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-7827420599414369716?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=0y-XYgIXxI8:HzhAc1wYVFg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=0y-XYgIXxI8:HzhAc1wYVFg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=0y-XYgIXxI8:HzhAc1wYVFg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=0y-XYgIXxI8:HzhAc1wYVFg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=0y-XYgIXxI8:HzhAc1wYVFg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=0y-XYgIXxI8:HzhAc1wYVFg:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/0y-XYgIXxI8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:50:08.026-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/05/security-debian-and-ubuntu-openssl.html</feedburner:origLink></item><item><title>HowTo: Uncomplicated Firewall (ufw) in Ubuntu 8.04</title><link>http://feedproxy.google.com/~r/morphic/~3/2We-l8_jzvw/howto-uncomplicated-firewall-ifw-in.html</link><category>HowTo</category><category>Security</category><category>Firewall</category><category>Uncomplicated Firewall</category><category>Hardy Heron</category><category>ifw</category><category>Ubuntu</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:50:12 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-663305902462932518</guid><description>&lt;p&gt;I've recently upgraded several of my systems to Ubuntu 8.04 (Hardy Heron). While poking around, figuring out what has changed since 7.10 (Gutsy Gibbon), I came across the 'ufw' command, which is an acronym for &lt;strong&gt;U&lt;/strong&gt;ncomplicated &lt;strong&gt;F&lt;/strong&gt;ire&lt;strong&gt;w&lt;/strong&gt;all.&lt;br /&gt;
&lt;br /&gt;
Personally, on my linux systems I've preferred working with iptables directly. Several years ago I started using 'fwbuilder' to manage my iptables. Nonetheless, I'm still interested in playing around with ufw to see what value it has.&lt;br /&gt;
&lt;br /&gt;
Here's an ifw example using OpenBSD's PF syntax:&lt;br /&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Let's assume I want to allow all ssh traffic (22/tcp) from the 10.10.1.0/24 subnet to my host at IP 10.10.2.10:&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
  sudo ufw allow from 10.10.1.0/24 to 10.10.2.10 port 22
&lt;/blockquote&gt;
&lt;ul&gt;
  &lt;li&gt;Is there a single host that's bothering you and you want to block it?&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
  sudo ufw deny from {IP address}
&lt;/blockquote&gt;If you're interested in testing ufw, the Ubuntu Unleashed Blog [&lt;a href="http://www.ubuntu-unleashed.com/2008/05/howto-take-use-setup-and-advantage-of.html" target="_blank"&gt;link&lt;/a&gt;] has a useful guide on using the tool. Of course, you can always use the man pages as well [`man ufw`].

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-663305902462932518?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2We-l8_jzvw:xH8Q4_mb6pE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2We-l8_jzvw:xH8Q4_mb6pE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2We-l8_jzvw:xH8Q4_mb6pE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=2We-l8_jzvw:xH8Q4_mb6pE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2We-l8_jzvw:xH8Q4_mb6pE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=2We-l8_jzvw:xH8Q4_mb6pE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/2We-l8_jzvw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:50:12.830-07:00</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.zenone.org/2008/05/howto-uncomplicated-firewall-ifw-in.html</feedburner:origLink></item><item><title>Off Topic: Manualism</title><link>http://feedproxy.google.com/~r/morphic/~3/cD8PQy2kzSw/off-topic-manualism.html</link><category>Music</category><category>High School</category><category>Hand Music</category><category>Yankee Doodle</category><category>Cantina Band</category><category>Cecil Dill</category><category>Star Wars</category><category>Manualism</category><category>Off Topic</category><category>Manualist</category><author>noreply@blogger.com (Steve Zenone)</author><pubDate>Fri, 12 Sep 2008 13:50:15 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-7267320703085764135.post-3544634850198937186</guid><description>&lt;p&gt;Recently I learned about the entertaining subculture of manualism. It happened by complete chance, I swear! You believe me, don't you?&lt;br /&gt;
&lt;br /&gt;
&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_f5zPJR8dXDg/SCiyDqdPFLI/AAAAAAAACqA/vPVI5fibLf8/s1600-h/Manualism.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://4.bp.blogspot.com/_f5zPJR8dXDg/SCiyDqdPFLI/AAAAAAAACqA/vPVI5fibLf8/s200/Manualism.jpg" alt="" border="0" /&gt;&lt;/a&gt;While searching YouTube for "Cantina Band", there was a video that I couldn't resist watching. Without skipping a beat I moved my mouse over the video and clicked play. As I began watching the video of a manualist playing the Star Wars “Cantina Band” song with his hands, distant memories from my past started to emerge. It had nothing to do with rice and beans. Please!&lt;br /&gt;
&lt;br /&gt;
As I was saying, we were just about to take a stroll down memory lane...&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: #666666;"&gt;[dream sequence]&lt;/span&gt;&lt;br /&gt;
I remembered my sophomore year in high school; I was sitting in my desk during Spanish class. I should have been conjugating verbs, but instead I was attempting to squeeze air through my hands while pressing them together, firmly. Minutes passed and I kept trying to make sound with my hands. Suddenly, and quite unexpectedly, there was a hush in class, and it was during that silence that my hands made “the sound”. If I recall correctly, the moment my hands made the sound of bodily relief, my face grew bright red. I had no idea if my classmates thought I had uncontrolled flatulence or if my hands made the sound.&lt;br /&gt;
&lt;span style="color: #666666;"&gt;[/dream sequence]&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Fast forward twenty years, and there I was watching a guy play “The Cantina Band” using his hands! I wondered how much the musician must have practiced to be able to play the song as well as he did? Interestingly, according to Wikipedia, “&lt;em&gt;Some manualists practice for as much as 30 years before finally reaching a presentable level of proficiency&lt;/em&gt;.” Apparently the first individual that was documented to have made musical parody with his hands was Cecil Dill. He claims to have learned how to play “Yankee Doodle” using his hands back in 1914.&lt;br /&gt;
&lt;br /&gt;
Now, isn't that a gas!&lt;br /&gt;
&lt;br /&gt;
Video of manualist playing "The Cantina Band" [&lt;a href="http://youtube.com/watch?v=pBiLAy7mDbw" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
Video of Cecil Dill and his Musical Hands [&lt;a href="http://youtube.com/watch?v=gcZynEsdGnQ" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
Wikipedia article on Manualism [&lt;a href="http://en.wikipedia.org/wiki/Manualism_%28hand_music%29" target="_blank"&gt;link&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE [6/13/2008]:&lt;/strong&gt; My piece aired this afternoon. If you missed it, you can download the two minute segment here [&lt;a href="http://www.zenone.org-a.googlepages.com/20080613-steve-kusp.mp3"&gt;link to mp3&lt;/a&gt;]&lt;/p&gt;

&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7267320703085764135-3544634850198937186?l=blog.zenone.org'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/morphic?a=cD8PQy2kzSw:Fd7xuzD9Nz8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=cD8PQy2kzSw:Fd7xuzD9Nz8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=cD8PQy2kzSw:Fd7xuzD9Nz8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?i=cD8PQy2kzSw:Fd7xuzD9Nz8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=cD8PQy2kzSw:Fd7xuzD9Nz8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/morphic?a=cD8PQy2kzSw:Fd7xuzD9Nz8:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/morphic?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/morphic/~4/cD8PQy2kzSw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-12T13:50:15.751-07:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/_f5zPJR8dXDg/SCiyDqdPFLI/AAAAAAAACqA/vPVI5fibLf8/s72-c/Manualism.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><media:content url="http://feedproxy.google.com/~r/morphic/~5/ZayOSaBXJ4g/20080613-steve-kusp.mp3" fileSize="2001187" type="application/octet-stream" /><itunes:explicit>no</itunes:explicit><itunes:subtitle> Recently I learned about the entertaining subculture of manualism. It happened by complete chance, I swear! You believe me, don't you? While searching YouTube for "Cantina Band", there was a video that I couldn't resist watching. Without skipping a beat </itunes:subtitle><itunes:author>noreply@blogger.com (Steve Zenone)</itunes:author><itunes:summary> Recently I learned about the entertaining subculture of manualism. It happened by complete chance, I swear! You believe me, don't you? While searching YouTube for "Cantina Band", there was a video that I couldn't resist watching. Without skipping a beat I moved my mouse over the video and clicked play. As I began watching the video of a manualist playing the Star Wars “Cantina Band” song with his hands, distant memories from my past started to emerge. It had nothing to do with rice and beans. Please! As I was saying, we were just about to take a stroll down memory lane... [dream sequence] I remembered my sophomore year in high school; I was sitting in my desk during Spanish class. I should have been conjugating verbs, but instead I was attempting to squeeze air through my hands while pressing them together, firmly. Minutes passed and I kept trying to make sound with my hands. Suddenly, and quite unexpectedly, there was a hush in class, and it was during that silence that my hands made “the sound”. If I recall correctly, the moment my hands made the sound of bodily relief, my face grew bright red. I had no idea if my classmates thought I had uncontrolled flatulence or if my hands made the sound. [/dream sequence] Fast forward twenty years, and there I was watching a guy play “The Cantina Band” using his hands! I wondered how much the musician must have practiced to be able to play the song as well as he did? Interestingly, according to Wikipedia, “Some manualists practice for as much as 30 years before finally reaching a presentable level of proficiency.” Apparently the first individual that was documented to have made musical parody with his hands was Cecil Dill. He claims to have learned how to play “Yankee Doodle” using his hands back in 1914. Now, isn't that a gas! Video of manualist playing "The Cantina Band" [link] Video of Cecil Dill and his Musical Hands [link] Wikipedia article on Manualism [link] UPDATE [6/13/2008]: My piece aired this afternoon. If you missed it, you can download the two minute segment here [link to mp3] </itunes:summary><itunes:keywords>Music, High School, Hand Music, Yankee Doodle, Cantina Band, Cecil Dill, Star Wars, Manualism, Off Topic, Manualist</itunes:keywords><feedburner:origLink>http://blog.zenone.org/2008/05/off-topic-manualism.html</feedburner:origLink><enclosure url="http://feedproxy.google.com/~r/morphic/~5/ZayOSaBXJ4g/20080613-steve-kusp.mp3" length="2001187" type="application/octet-stream" /><feedburner:origEnclosureLink>http://www.zenone.org-a.googlepages.com/20080613-steve-kusp.mp3</feedburner:origEnclosureLink></item><media:rating>nonadult</media:rating></channel></rss>
