<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-14300086</id><updated>2011-12-14T18:44:10.154-08:00</updated><title type='text'>Network Security World Updates</title><subtitle type='html'>Network security defined from basics to latest update news of the market.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>45</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-14300086.post-113263300132999867</id><published>2005-11-21T20:14:00.000-08:00</published><updated>2005-11-21T20:16:41.343-08:00</updated><title type='text'>Final post</title><content type='html'>This blog will have no more posts, any security/tech stuff I will be posting on my other blog (namely &lt;a href="http://aggarwalnakul.blogspot.com"&gt;http://aggarwalnakul.blogspot.com&lt;/a&gt;) itself.&lt;br /&gt;&lt;br /&gt;Thanks for visiting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-113263300132999867?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/113263300132999867/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=113263300132999867' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/113263300132999867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/113263300132999867'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/11/final-post.html' title='Final post'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112797999647561012</id><published>2005-09-29T00:41:00.000-07:00</published><updated>2005-09-29T00:46:36.480-07:00</updated><title type='text'>Scholarships Offered For IT Security</title><content type='html'>&lt;blockquote&gt;&lt;p&gt;Post-graduate students working on information-security research projects can&lt;br /&gt;qualify for a scholarship of up to $12,500.&lt;/p&gt;&lt;p&gt;The &lt;a href="https://www.isc2.org/cgi-bin/index.cgi"&gt;International Information Systems Security Certification Consortium Inc.&lt;/a&gt; (Palm Harbor, Fla.) said Tuesday (Sept. 27) it will offer one-year scholarships of up to $12,500 each to four qualifying full-time post-graduate students. Qualified candidates must be pursuing an advanced degree in information security at any&lt;br /&gt;accredited university worldwide. &lt;/p&gt;&lt;p&gt;&lt;a href="https://www.isc2.org/cgi-bin/content.cgi?page=311"&gt;Applications&lt;/a&gt; must be submitted by Nov. 30, 2005. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;from EE times via &lt;a href="http://www.securitypipeline.com/171201217"&gt;http://www.securitypipeline.com/171201217&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112797999647561012?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112797999647561012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112797999647561012' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112797999647561012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112797999647561012'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/09/scholarships-offered-for-it-security.html' title='Scholarships Offered For IT Security'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112595444302948873</id><published>2005-09-05T13:46:00.000-07:00</published><updated>2005-09-06T09:44:28.223-07:00</updated><title type='text'>Phishing Updates...</title><content type='html'>There has been an interesting discussion going on at google groups ... &lt;a href="http://groups.google.com/group/n3td3v/browse_thread/thread/d425eb8be1718084/e369b35f05358795?q=Phishing&amp;rnum=9#e369b35f05358795"&gt;Yahoo - a "Phisher-friendly" domain&lt;/a&gt;. The discussion is quite interesting since according to SpamHaus Project details, there has been large number of phishing attacks are going on using yahoo registered servers. Till now, they have found &lt;a href="http://www.spamhaus.org/sbl/listings.lasso?isp=yahoo.com"&gt;18 SBL listings under the domain name of yahoo.com&lt;/a&gt;&lt;br /&gt;[SBL: &lt;span class="body"&gt; The SBL is a realtime database of IP addresses of verified spam sources (including spammers, spam gangs and spam support services), maintained by the Spamhaus Project team and supplied as a free service to help email administrators better manage incoming email streams]&lt;br /&gt;&lt;hr /&gt;&lt;span style="font-weight: bold;"&gt;ADDED on 6th Sep...&lt;/span&gt;&lt;br /&gt;Richard Cox, chief information officer of Spamhaus, told an audience of politicians, security experts and law enforcement officials that Yahoo has just under 5,000 domains hosted and registered with the words 'bank', 'eBay' and 'PayPal' within the domain names.Most of those are used as phishing sites.&lt;br /&gt;&lt;a href="http://news.com.com/Spamhaus+Yahoo+major+phishing+site+host/2100-1029_3-5850773.html?part=rss&amp;tag=5850773&amp;amp;subj=news"&gt;Read Complete Article&lt;/a&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;/span&gt;"According to security outfit Postini, there was a 90 per cent reduction in the number of phishing emails in August and the number of viruses dropped by 30 percent from July."&lt;br /&gt;-- &lt;a href="http://www.theinquirer.net/?article=25857"&gt;INQUIRER&lt;/a&gt;&lt;br /&gt;But this doesnt seems the same for September. Why? read below.&lt;br /&gt;&lt;br /&gt;While US is suffering from Katrina Hurricane, the scammers/phishers are seeing an oppurtunity for money theft and effecting the PC's via malware installation or viruses. C&lt;span id="intelliTxt"&gt;omputer security firm &lt;a href="http://www.sophos.com/" onclick="window.open('http://www.sophos.com'); return false;"&gt;Sophos&lt;/a&gt; also warned of an e-mail circulating with news stories inside about the disaster. Clicking on the links in the e-mail takes users to a site that attempts to load virus code onto a user's computer. Articles by &lt;a href="http://www.securitypipeline.com/170700049?CID=RSSfeed"&gt;Security Pipeline&lt;/a&gt; and &lt;a href="http://www.ecommercetimes.com/story/KUfvyd0mMYwwJ5/Phishing-Malware-Scams-Rise-in-Katrinas-Wake.xhtml"&gt;E-commerce news&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112595444302948873?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112595444302948873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112595444302948873' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112595444302948873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112595444302948873'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/09/phishing-updates.html' title='Phishing Updates...'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112508482110911733</id><published>2005-08-26T12:29:00.000-07:00</published><updated>2005-08-27T17:43:27.640-07:00</updated><title type='text'>Phishing part2..</title><content type='html'>I got a new link from Bjorn borg (a researcher from sweden working in this field), a complete tutorial on Phishing.&lt;br /&gt;&lt;a href="http://www.pisa.org.hk/event/phishing_exposed.pdf"&gt;http://www.pisa.org.hk/event/phishing_exposed.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More news:&lt;br /&gt;1) August 26, 2005 -- &lt;a href="http://www.securitypipeline.com/170100818?CID=RSSfeed"&gt;Brazil Pinches 85 Phishers&lt;/a&gt;&lt;br /&gt;2) August 25, 2005 -- &lt;a href="http://www.securitypipeline.com/170100116?CID=RSSfeed"&gt;Microsoft to Expand Anti-Phishing Tool &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112508482110911733?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112508482110911733/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112508482110911733' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112508482110911733'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112508482110911733'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/phishing-part2.html' title='Phishing part2..'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112501397583000295</id><published>2005-08-25T16:39:00.000-07:00</published><updated>2005-08-25T17:29:02.473-07:00</updated><title type='text'>Phishing Survey</title><content type='html'>&lt;center&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Phishing&lt;/span&gt;&lt;/strong&gt;&lt;/center&gt;&lt;p align="left"&gt;&lt;strong&gt;Definition:&lt;br /&gt;&lt;/strong&gt;Phishing is the "art" of fooling people using social engineering and technical subterfuge by sending fake emails, or spam which seems as send by some known organization redirecting them to fake pages; hence getting unauthorized access to people's username, passwords, credit card account information etc.&lt;br /&gt;“Phishing attacks use 'spoofed' e-mails and fraudulent websites designed to fool recipients into divulging personal financial data such as credit card numbers, account usernames and passwords, social security numbers, etc.” This is a social engineering attack that targets vulnerable online consumers and, depending on the particular scam, uses weaknesses and exploits in email and web browsers.”&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Term origin:&lt;/strong&gt; It’s derived from fishing where a fisherman uses a lure to attract fish in the same way that the attackers use an email to attract online consumers. Finally the ‘f’’ from fishing has been substituted for with ‘ph’ to form “phishing”. This is in recognition of the original hacking method phreaking. (Dictionary meaning - “phreaking” is where a hacker would take over someone else’s phone line and use it for their own use, including hacking into other computers.)&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/5148/1149/1600/clip_image0014.gif"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://photos1.blogger.com/blogger/5148/1149/400/clip_image001.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;First incident of Phishing was reported as early as 1998. An example&lt;br /&gt;==&lt;br /&gt;Sector 4G9E of our data base has lost all I/O functions. When your account logged onto our system, we were temporarily able to verify it as a registered user. Approximately 94 seconds ago, your verification was made void by loss of data in the Sector 4G9E. Now, due to AOL verification protocol, it is mandatory for us to re-verify you. Please click 'Respond' and re-state your password. Failure to comply will result in immediate account deletion.&lt;br /&gt;====&lt;br /&gt;&lt;br /&gt;A number of examples of &lt;a href="http://www.informatics.indiana.edu/markus/papers/phishing_jakobsson.pdf"&gt;phishing with ebay and paypal &lt;/a&gt;especially can be seen here.&lt;br /&gt;From individuals or small groups in the starting stage, Phishing has now reached to very advanced stage. Large amount of bulk emails are send everyday, and hacking is going at large scale. Latest being hack of eBay login page, ATM card numbers etc.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Statistics:&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;The main targets are financial institutions and e-commerce companies, particularly online banks. The top four targets according to the Anti-Phishing Work Group in April 2004 were Citibank, eBay, PayPal and US Bank. The Anti-phishing Workgroup states that 5% of attacks result in identity theft26. A Gartner survey of 5000 estimated the damage from Phishing in 2003 cost US Banks and credit card companies $1.2 billion in 20033. Actual losses are much lower, monetary values of losses are difficult to obtain but Paypals loss rate from fraud is 0.33%. Australian banks have recently put aside $2 million to cover losses from phishing¹. British banks estimated they lost ₤1 million through phishing scams².&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Technology:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;A web server, a bulk mailing tool, a form e-mail and a database of e-mails would be enough to mount a phishing scam.&lt;br /&gt;The email is branded to look like it’s from the particular financial institution or e-commerce&lt;br /&gt;site and the ‘from’ address is spoofed to appear from that domain. It usually includes an URL, which appears to be linking back to the appropriate site, however the actual link points to the ghosted website.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Techniques:&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;1) Email&lt;br /&gt;2) Ghost Website (eg. &lt;a href="http://www.paypa1.com/"&gt;http://www.paypa1.com/&lt;/a&gt;)&lt;br /&gt;3) Hiding/spoofing the address bar&lt;br /&gt;a) No SSL padlock&lt;br /&gt;b) javascript&lt;br /&gt;4) Adding Subdomain to the main site&lt;br /&gt;5) PopUp Windows&lt;br /&gt;6) Use of Malware – Trojans, Viruses and Botnets&lt;br /&gt;7) Phishing through Compromised web servers&lt;br /&gt;8) Port redirection -- removing the possibility of backtrack by web server also by redirecting the web server to another web-server.&lt;br /&gt;9) Using botnets&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;In geek terms,&lt;/strong&gt;&lt;/span&gt; these are done via&lt;br /&gt;1) DNS poisoning&lt;br /&gt;2) Pharming (&lt;a href="http://www.ngssoftware.com/papers/ThePharmingGuide.pdf"&gt;a guide from NGS softwares&lt;/a&gt; )&lt;br /&gt;3) All the antiviruses has inbuilt capabilities to filter spams and some of the phishing attacks.&lt;br /&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;span style="font-family:trebuchet ms;"&gt;A white paper from McAfee(PDF:5) gives a detailed graphical and detailed explanation about the current phishing attacks methods. IT even comments&lt;br /&gt;existing counter measures and tells what McAfee has to provide.&lt;/span&gt;&lt;/blockquote&gt;&lt;p align="left"&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;COUNTER-MEASURES&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;1) Phishing scams can be reported through consumer alerts or real-time detection and then companies updates their respective customers about the same and even post about them on their websites.&lt;br /&gt;2) Toolbars – There exist a lot of toolbars and plugins for all the major browsers. A graph with their properties can be seen here:&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://photos1.blogger.com/blogger/5148/1149/400/snap11.JPG"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://photos1.blogger.com/blogger/5148/1149/400/snap11.JPG" border="0" /&gt;&lt;/a&gt; Source: Phish and HIPs: Human Interactive Proofs to Detect Phishing Attacks&lt;br /&gt;3) All the antiviruses has inbuilt capabilities to filter spams and some of the phishing attacks. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;RESEARCH:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;A lot of research has been encouraged bcoz of the stats as we have seen above. These are briefings of some of them:&lt;br /&gt;&lt;br /&gt;1) this paper has introduced a new scheme namely, Dynamic Security Skins, that allows a remote web server to prove its identity in a way that is easy for a human user to verify and hard for an attacker to spoof. We use a photographic image to create a trusted path between the user and this window to prevent spoofing of the window and of the text entry fields. [PDF:2]&lt;br /&gt;&lt;br /&gt;2) A contribution of this paper is the description of what we term a context aware phishing attack. [PDF:3]&lt;br /&gt;&lt;br /&gt;3) They define five properties of an ideal HIP (Human Interactive Proofs) to detect phishing attacks. The challenge must:&lt;br /&gt;1) be easy for a particular class of computers to pass,&lt;br /&gt;2) be hard for other computers to pass, even after observing a number of successful authentications,&lt;br /&gt;3) produce results that are easy for a human to verify,&lt;br /&gt;4) use a protocol that is publicly available, and&lt;br /&gt;5) not require the user to have specialized tools.&lt;br /&gt;[PDF:4]&lt;br /&gt;&lt;br /&gt;4) Complete technical and detailed specs of how phishing is done [PDF:5]&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;A brief intro about Microsoft Phishing Filter&lt;/strong&gt; (from Microsoft site)&lt;br /&gt;• Phishing Filter is a feature in Internet Explorer 7.0 that helps determine whether a Web site is legitimate or a so-called phishing Web site.&lt;br /&gt;&lt;br /&gt;• Phishing Filter uses three checks to help protect users from phishing scams:&lt;br /&gt;1. It compares the addresses of Web sites that a user attempts to visit to the addresses of sites that have been reported as legitimate. This list is stored on the user's computer.&lt;br /&gt;2. It analyzes sites that a user attempts to visit by checking those sites for characteristics common to phishing sites.&lt;br /&gt;3. If the user chooses, Phishing Filter sends the addresses of Web sites that a user attempts to visit to Microsoft to be checked against a frequently updated list of reported phishing sites.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Future Solutions:&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;1) Tumbleweed Communications already have a digital signing solution ready to go to market.&lt;br /&gt;2) Microsoft's Caller-ID,&lt;br /&gt;3) the Sender Policy Framework (SPF), and&lt;br /&gt;4) Yahoo! Domain Keys proposals.&lt;br /&gt;5) The Internet engineering Task Force (IETF) has also published an IETF draft to stop source address spoofing.&lt;br /&gt;6) Another area that will become more prominent is the near real-time detection of phishing scams using email scanning and filtering, trademark searches, monitoring of DNS registrations, scanning of front pages.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;SOME LINKS:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;Detailed explanation of Existing methods and tools&lt;br /&gt;&lt;a href="https://antiphishing.kavi.com/events/Conference_Notes/phishing-sfectf-report.pdf"&gt;https://antiphishing.kavi.com/events/Conference_Notes/phishing-sfectf-report.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=265"&gt;Latest Alert(25/08/2005) --WSLabs, Phishing Alert: Bank of Montreal&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.honeynet.org/papers/phishing/"&gt;http://www.honeynet.org/papers/phishing/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://antiphishing.org/"&gt;http://antiphishing.org/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.phishreport.net/"&gt;http://www.phishreport.net/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.honeynet.org/papers/phishing/details/phishing-background.html"&gt;http://www.honeynet.org/papers/phishing/details/phishing-background.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/mscorp/safety/technologies/antiphishing/default.mspx"&gt;Microsoft Antiphishing Technology&lt;/a&gt;&lt;br /&gt;&lt;a href="http://crypto.stanford.edu/SpoofGuard/"&gt;http://crypto.stanford.edu/SpoofGuard/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.lifehacker.com/software/security/identity-theft-via-online-resumes-118742.php"&gt;Identity Theft Via Online Resumes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.eweek.com/article2/0,1759,1851792,00.asp?kc=EWRSS03119TX1K0000594"&gt;Identity Theft From servers&lt;/a&gt;&lt;/p&gt;&lt;p align="left"&gt;Pdfs used:&lt;br /&gt;(1) An analysis of Phishing and possible mitigation strategies&lt;br /&gt;(2) The Battle Against Phishing: Dynamic Security Skins&lt;br /&gt;(3) Modeling and Preventing Phishing Attacks&lt;br /&gt;(4) Phish and HIPs: Human Interactive Proofs to Detect Phishing Attacks&lt;br /&gt;(5) Anti-Phishing: Best Practices for Institutions and Consumers&lt;br /&gt;&lt;br /&gt;All of these pdf’s can be searched from &lt;a href="http://scholar.google.com/"&gt;http://scholar.google.com/&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112501397583000295?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112501397583000295/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112501397583000295' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112501397583000295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112501397583000295'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/phishing-survey.html' title='Phishing Survey'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112426396686575717</id><published>2005-08-16T23:32:00.000-07:00</published><updated>2005-08-17T00:32:46.900-07:00</updated><title type='text'>Cyber security</title><content type='html'>A lots lots of research is going on in this field.  A lot of approaches and technology exists. Most people use one of multiples of them while some of them are research oriented.&lt;br /&gt;&lt;br /&gt;1) Firstly most people do use IDS/IPS's and Firewalls at their gateways and web-servers to protect from "bad" people.&lt;br /&gt;&lt;br /&gt;2) Many tools exist which tells to which exploits your web server is vunerable to (eg. Cenzic Hailstorm, &lt;a href="http://www.secguru.com/nikto_web_vulnerability_scanner"&gt;Nikto - Web Vulnerability Scanner&lt;/a&gt;, )&lt;br /&gt;&lt;br /&gt;3) Many tools exists which checks the web-applications you have built, and tells the exploits and weaknesses in them. (a &lt;a href="http://www.secguru.com/web_services_next_generation_vulnerable_enterprise_apps"&gt;tutorial&lt;/a&gt; for the same)&lt;br /&gt;&lt;br /&gt;4) Then browser based insecurity like exploitation of browser bugs for malware and spyware installation (including phishing attacks, botnets formation, hacking of secret user information etc.). Most of these bugs are fixed/updated regularly by the respective vendors. So, one needs to patch them regularly.&lt;br /&gt;&lt;br /&gt;5) Use of honeypots to diverge the focus of hackers is another method used in cyber secure methods.&lt;br /&gt;While &lt;strong&gt;research&lt;/strong&gt; use of honeypots is in the field of generating "hackers" information, the style and way of hacking and the getting info about attacks people have to face in near future.&lt;br /&gt;&lt;br /&gt;6) &lt;a href="http://research.microsoft.com/honeymonkey/"&gt;Honeymonkey&lt;/a&gt; is new field in this field of security(by M$).Honeypots are looking for server-based vulnerabilities, where the bad guys act like the client. Honeymonkeys are the other way around, where the client is the vulnerable one.&lt;br /&gt;Honeymonkeys are the chain of computer systems with different patch levels which "patrol" the web to get list of servers which actually exploit the browser vunerabilities and do spyware installtion.&lt;br /&gt;&lt;br /&gt;7) New kind of attacks in web include phishing attacks (new in the sense no proper secure approach exists as yet). While much research is going on in this field most of counter attack measures are incorporated in browsers itself.&lt;br /&gt;Even the Latest &lt;a href="http://blogs.msdn.com/ie/archive/2005/08/15/452006.aspx#comments"&gt;IE version7&lt;/a&gt;, they have implemented the object oriented approach known as CURI. While a lot of &lt;a href="http://networksecurityupdates.blogspot.com/2005/07/firefox-and-phishing.html"&gt;plugins for firefox against fishing &lt;/a&gt;already exists.&lt;br /&gt;&lt;br /&gt;MORE tools and links:&lt;br /&gt;&lt;a href="http://www.owasp.org/software/webgoat.html"&gt;WebGoat&lt;/a&gt; is a full J2EE web application designed to teach web application security lessons.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112426396686575717?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112426396686575717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112426396686575717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112426396686575717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112426396686575717'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/cyber-security.html' title='Cyber security'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112369702352050800</id><published>2005-08-10T10:55:00.000-07:00</published><updated>2005-08-10T16:07:59.883-07:00</updated><title type='text'>Sygate and ZoneLabs also offering HIP</title><content type='html'>Sygate Technologies has unveiled its own form of double-agent on Monday introducing Sygate Enterprise Protection (SEP) 5.0, software with device agents that do double duty by delivering both host intrusion prevention (HIP) and network access control (NAC) to millions of networked devices.&lt;br /&gt;SEP 5.0 now offers&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Sygate can block the transfer of data to unauthorized removable media devices including USB keys, iPods, CD/DVD Burners, PCMCIA hard drives, etc&lt;/li&gt;&lt;li&gt;Sygate blocks exploits that target known operating system vulnerabilities such as the RPC DCOM buffer overflow&lt;/li&gt;&lt;li&gt;Sygate’s protection includes the ability to block the exploit of known vulnerabilities in applications such as email, web browsers, and word processors, ensure that only authorized executables and .DLLs&lt;/li&gt;&lt;li&gt;Sygate’s intrusion prevention capabilities include the ability to block known network-based worm and web server attacks&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Read more at &lt;a href="http://www.sygate.com/news/sygate-enterprise-protection_rls.htm"&gt;http://www.sygate.com/news/sygate-enterprise-protection_rls.htm&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;On the contrary, zoneLabs has also launched their new version of firewall i.e. ZoneLabs 6.0 which features&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Updates, scans and removes spyware from your PC; integrated with our award-winning antivirus so you can easily manage both in a single, powerful operation.&lt;/li&gt;&lt;li&gt;Goes beyond traditional PC firewalls to protect your entire computer – including your operating system and programs – from hackers, spyware, and other Internet threats&lt;/li&gt;&lt;li&gt;Keeps your computer updated with the latest intelligence on Internet threats gathered from Zone Labs experts and the ZoneAlarm user community.&lt;/li&gt;&lt;li&gt;Protects you from identity theft and online profiling.&lt;/li&gt;&lt;li&gt;Quarantines suspicious attachments to help defend against unknown viruses; automatically halts outbound messages to keep you from accidentally infecting others.&lt;/li&gt;&lt;li&gt;Automatically blocks phishing and junk emails from entering your inbox, protecting you from dangerous scams and annoying spam.&lt;/li&gt;&lt;li&gt;Automatically detects wireless networks and secures your PC from hackers and other Internet threats wherever you're connected—at home or on the road.&lt;/li&gt;&lt;/ol&gt;Read more from&lt;br /&gt;&lt;a href="http://www.securitypipeline.com/168600444?CID=RSSfeed"&gt;http://www.securitypipeline.com/168600444?CID=RSSfeed&lt;/a&gt; &amp;&amp;amp;&lt;br /&gt;&lt;a href="http://www.zonelabs.com/store/application?namespace=zls_catalog&amp;origin=global.jsp&amp;amp;event=link1.skuList&amp;&amp;amp;zl_catalog_view_id=201"&gt;Zone labs on site&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Lets see who wins .. while I had tried both and liked both. But in terms of security I prefer sygate but it slows comp like hell while doing some networking stuff. In that way, ZoneLabs is not a bad option.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112369702352050800?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112369702352050800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112369702352050800' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112369702352050800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112369702352050800'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/sygate-and-zonelabs-also-offering-hip.html' title='Sygate and ZoneLabs also offering HIP'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112369645996919820</id><published>2005-08-10T10:49:00.000-07:00</published><updated>2005-08-10T10:54:19.976-07:00</updated><title type='text'>Signature matching</title><content type='html'>In the month of June, I got a project on "signature matching" in network intrusion detection. I know much work has been done already in this field and work is still going on. It forms an important and versatile part of most IDS tools like snort, bro etc.&lt;br /&gt;My main work was to study exisiting methods and implement the best one. What I did first was googling via &lt;a href="http://www.google.com"&gt;google&lt;/a&gt; and &lt;a href="http://scholar.google.com"&gt;scholar&lt;/a&gt;, &lt;a href="http://citeseer.psu.edu"&gt;citeseer&lt;/a&gt; etc. and find few papers to begin with.While I got to know two techniques for matching patterns&lt;br /&gt;&lt;ol&gt;&lt;li&gt;simple string matching&lt;/li&gt;&lt;li&gt;matching via DFA transitions &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Simple string matching is just not the simple iterative i.e. n^2 process to be followed but much research has been done into it already. Their are many efficient ways of doing this in software. ( you can get a lot of papers from scholar)&lt;br /&gt;While much more efficient ways exist in hardware which makes it widely applicable when it comes to inline matching in real time.&lt;br /&gt;&lt;br /&gt;While signature matching via DFA is much more interesting since it assumes good knowledge of automata theory, definite finite automata and regular expressions. The problem with this approach is in formation of DFA itself which explodes with the current number of signatures which needs to be incorporated into IDS. The solution to this problem is "Incremental generation of DFA's" which involves the DFA formation just at the stage of mathcing and not once hardcoded and making trasnsitions over it.&lt;br /&gt;&lt;br /&gt;The comparsion of the two approaches has been shown in the technical paper of "BRO" which uses the 2nd approach and compares the results with snort which uses the 1st approach. The results shows both the tools are at par with each other but snort havign a upper hand at some points.&lt;br /&gt;But am inclined towards the 2nd approach, and working on it currently lets see if this can give better results. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112369645996919820?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112369645996919820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112369645996919820' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112369645996919820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112369645996919820'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/signature-matching.html' title='Signature matching'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112335510794388541</id><published>2005-08-06T11:53:00.000-07:00</published><updated>2005-08-06T12:14:35.620-07:00</updated><title type='text'>HAcking with Google vs. Google Hack HoneyPot</title><content type='html'>&lt;strong&gt;&lt;em&gt;Part1 : Dangerous google&lt;br /&gt;&lt;/em&gt;&lt;/strong&gt;"Dangerous Google – Searching for Secrets", this is the name of the tutorial pdf i got from &lt;a href="http://www.hacking.pl"&gt;www.hacking.pl&lt;/a&gt; dont remember the exact link now.&lt;br /&gt;I have (may be you too) must have read a lot of articles on tweaks in google. But a lot more has been explained in this tutorial by the author, Michał Piotrowski.&lt;br /&gt;&lt;br /&gt;Some of the google operators are:&lt;br /&gt;site:&lt;br /&gt;intitle:&lt;br /&gt;allintitle:&lt;br /&gt;inurl:&lt;br /&gt;allinurl:&lt;br /&gt;filetype:&lt;br /&gt;numrange:&lt;br /&gt;link:&lt;br /&gt;inanchor:&lt;br /&gt;allintext:&lt;br /&gt;+ "search"-- ordering the results in order of no. of occurences of search string&lt;br /&gt;- "search"&lt;br /&gt;* and . -- wildcards for words and a character respectively&lt;br /&gt;-- or&lt;br /&gt;""&lt;br /&gt;=======&lt;br /&gt;A lot of query tables to get access to know about vunerable servers have been disclosed too like:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Google queries for locating various Web servers&lt;/li&gt;&lt;li&gt;Queries for discovering standard post-installation Web server pages&lt;/li&gt;&lt;li&gt;Querying for application-generated system reports&lt;/li&gt;&lt;li&gt;Error message queries&lt;/li&gt;&lt;li&gt;Google queries for locating passwords&lt;/li&gt;&lt;li&gt;Searching for personal data and confidential documents&lt;/li&gt;&lt;li&gt;Queries for locating network devices&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;And most important of all is the link at the end. Which is the &lt;a href="http://johnny.ihackstuff.com/index.php?module=prodreviews"&gt;&lt;strong&gt;&lt;em&gt;"Google Hacking Database (GHDB)!"&lt;/em&gt;&lt;/strong&gt;&lt;/a&gt; , which is called 'googledorks' (gOO gÃ´l'DÃ´rk, noun, slang) : An inept or foolish person as revealed by Google. Whatever you call these fools, you've found the center of the Google Hacking Universe! Stop by our forums to see where the magic happens!&lt;/p&gt;&lt;p&gt;Ya I got the link in the history...&lt;br /&gt;&lt;a href="http://www.haking.pl/en/attachments/google_en.pdf"&gt;http://www.haking.pl/en/attachments/google_en.pdf&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Part2: Google Hack HoneyPot&lt;br /&gt;&lt;/strong&gt;&lt;/em&gt;The reply to hackers, who use google to get information which they are not supposed to do, is Google Hack Honeypot(GHH).&lt;br /&gt;GHH is the reaction to a new type of malicious web traffic: search engine hackers. GHH is a “Google Hack” honeypot. It is designed to provide reconaissance against attackers that use search engines as a hacking tool against your resources. GHH implements honeypot theory to provide additional security to your web presence.&lt;br /&gt;&lt;br /&gt;The project also uses the above defined GHDB for getting signatures. The project is active project and keeps updating the signature database.&lt;/p&gt;&lt;br /&gt;Lets see who web developers react to this project?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112335510794388541?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112335510794388541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112335510794388541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112335510794388541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112335510794388541'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/hacking-with-google-vs-google-hack.html' title='HAcking with Google vs. Google Hack HoneyPot'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112327322226391117</id><published>2005-08-05T13:08:00.000-07:00</published><updated>2005-08-05T13:20:22.270-07:00</updated><title type='text'>Secure Software Development by Example</title><content type='html'>Below is the epitome of the article on &lt;strong&gt;Secure Software Development by Example &lt;/strong&gt;to be Published in Ju;y/August 2005 edition of "Security &amp; Privacy" Magazine.&lt;br /&gt;&lt;strong&gt;Authors:&lt;/strong&gt;&lt;br /&gt;Axelle Apvrille and Makan Pourzandi&lt;br /&gt;Ericsson Research Canada&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Summary:&lt;/strong&gt;&lt;br /&gt;"When trying to incorporate security into a program, software developers face either too much theoretical information that they can’t apply or exhaustive and discouraging recommendation lists. This article gives an overview of security concerns at each step of a project’s life cycle."&lt;br /&gt;&lt;br /&gt;The tutorial is very basic and describes the implementations of all the secure techniques you have learnt (or you can learn now too) in all stages of you software development. Authors not only discusses the "buffer overflow" handling but also others like environment security issues, misunderstanding of Algo's, misjudging the worst case scenario for implemented algorithms, choice of langauge for particular project etc. which most of other tutorials donot do. Tutorial provides an methodical, step-by-step procedure to be followed using an real-world example.&lt;br /&gt;&lt;br /&gt;There are five stages of project namely analysis, design, implementation, testing, and maintenance. hence security must be applied in every stage.&lt;br /&gt;&lt;strong&gt;Applying Security:&lt;/strong&gt;&lt;br /&gt;First step is the analysis and understanding of security model i.e. defining the environment and typical threats possible to your software and all sort of other inputs and threats to it.Hence defining a "security policy" and corresponding "risk evaluation" factor incases of trading-off between multiple tweaks to the same threat.&lt;br /&gt;After implementation of the security policies comes the step of "testing". While a lot of tools exists but none of them provides the "complete testing". What they can do is "code review" or just trying different (random) inputs etc. One should try every kind of random and arbit cases which are possible, try execution in different environments and even with different surrounding security. Also,authors final conclusion regarding security is, "code review is the best tool for security testing."&lt;br /&gt;A must READ article for project/software developers.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computer.org/portal/site/security/menuitem.6f7b2414551cb84651286b108bcd45f3/index.jsp?&amp;pName=security_level1_article&amp;amp;TheCat=1015&amp;path=security/v3n4&amp;amp;file=apvrille.xml&amp;amp;"&gt;Link to the Complete Article&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112327322226391117?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112327322226391117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112327322226391117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112327322226391117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112327322226391117'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/secure-software-development-by-example.html' title='Secure Software Development by Example'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112326245491454985</id><published>2005-08-05T10:17:00.000-07:00</published><updated>2005-08-05T10:20:54.923-07:00</updated><title type='text'>Phishing phishing everywhere..</title><content type='html'>"If you are in the business of phishing, you obviously are looking for money. Scam, business, money. So it comes as no surprise that &lt;a title="Blog This: 80% of phishing is targeted at financial institutions  IT Facts %u2014 Your Daily Research Synopsis  ZDNet.com" href="http://blogs.zdnet.com/ITFacts/index.php?blogthis=1&amp;p=8566"&gt;80% of phishing is targeted at financial institutions&lt;/a&gt;. That is where a lot of money is, eh?"&lt;br /&gt;--- &lt;a href="http://www.spamroll.com/"&gt;http://www.spamroll.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;At the same page, author has given link for &lt;a title="The latest and most prevalent hoaxes" href="http://www.sophos.com/virusinfo/hoaxes/recent/"&gt;latest and greatest email hoaxes&lt;/a&gt; as given by sophos.&lt;br /&gt;&lt;br /&gt;A good link for updating and getting fundaes for people interested in spam and phishing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112326245491454985?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112326245491454985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112326245491454985' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112326245491454985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112326245491454985'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/phishing-phishing-everywhere.html' title='Phishing phishing everywhere..'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112326079302385263</id><published>2005-08-05T09:42:00.000-07:00</published><updated>2005-08-05T09:53:13.036-07:00</updated><title type='text'>Future worms could evade a network of early-warning sensors</title><content type='html'>The 04 Aug dated article &lt;a href="http://news.com.com/Worms+could+dodge+Net+traps/2100-7349_3-5819293.html?part=rss&amp;tag=5819293&amp;amp;subj=news"&gt;"Worms could dodge Net traps"&lt;/a&gt; states "Future worms could evade a network of early-warning sensors hidden across the Internet unless countermeasures are taken, according to new research."&lt;br /&gt;&lt;br /&gt;This is the epitome of the papers[1,2,3] presented at &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.usenix.org%2Fevents%2Fsec05&amp;siteId=3&amp;amp;amp;oId=2100-7349-5819293&amp;ontId=1009&amp;amp;lop=nl.ex"&gt;Usenix Security Symposium&lt;/a&gt;  this thursday.&lt;br /&gt;&lt;br /&gt;1) But the Wisconsin researchers discovered that the sensor maps furnish just enough information for someone to create an algorithm that can map the location of the sensors "even with reasonable constraint on bandwidth and resources," John Bethencourt, one of the paper's authors, said in his presentation.&lt;br /&gt;&lt;br /&gt;2) "If the set of sensors is known, a malicious attacker could avoid the sensors entirely or could overwhelm the sensors with errant data," a team of computer scientists from the University of Wisconsin wrote in its &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.usenix.org%2Fevents%2Fsec05%2Ftech%2Fbethencourt.html&amp;siteId=3&amp;amp;amp;oId=2100-7349-5819293&amp;ontId=1009&amp;amp;lop=nl.ex" target="_blank"&gt;award-winning paper&lt;/a&gt; titled "Mapping Internet Sensors with Probe Response Attacks."&lt;br /&gt;&lt;br /&gt;3) Researchers from Japan came to a similar conclusion in a &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.usenix.org%2Fevents%2Fsec05%2Ftech%2Fshinoda.html&amp;siteId=3&amp;amp;oId=2100-7349-5819293&amp;ontId=1009&amp;amp;lop=nl.ex" target="_blank"&gt;paper&lt;/a&gt; titled "Vulnerabilities of Passive Internet Threat Monitors." They noted that sensor attackers can identify the location of sensors without the aid of a "complete list of sensor addresses." They also devised several algorithms that managed to pinpoint the sensors "in surprisingly short time."&lt;br /&gt;&lt;br /&gt;Be ready for more servere attacks and future. :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112326079302385263?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112326079302385263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112326079302385263' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112326079302385263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112326079302385263'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/future-worms-could-evade-network-of.html' title='Future worms could evade a network of early-warning sensors'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112318665039488420</id><published>2005-08-04T13:15:00.000-07:00</published><updated>2005-08-04T13:17:30.396-07:00</updated><title type='text'>First "Windows Vista Virus" found</title><content type='html'>Checkout &lt;a href="http://www.f-secure.com/weblog/"&gt;F-secure Weblog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"An Austrian virus writer has published five simple viruses targeting Microsoft MSH in a virus writing magazine.&lt;br /&gt;&lt;br /&gt;MSH, or Microsoft Command Shell, is a command line interface and scripting language. It's basically a replacement for shells such as CMD.EXE, COMMAND.COM or 4NT.EXE and will ship in 2006. As a command-line front end, MSH resembles many Unix shells quite a bit."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112318665039488420?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112318665039488420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112318665039488420' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318665039488420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318665039488420'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/first-windows-vista-virus-found.html' title='First &quot;Windows Vista Virus&quot; found'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112318610500293335</id><published>2005-08-04T12:57:00.000-07:00</published><updated>2005-08-04T13:08:25.006-07:00</updated><title type='text'>Google - The hacker's new tool.</title><content type='html'>Yes, u heard it right, google search results can provide you valuable information regarding the network topology of some of the large networks, sql and other databases passwords, cracks/serial numbers of any programs, even you can find ways and tools of hacking the major softwares such as microsoft products, maya (one of the best 3d softwares), all games etc.&lt;br /&gt;&lt;br /&gt;The source article is &lt;a href="http://www.infoworld.com/article/05/08/02/HNgooglehackertool_1.html"&gt;Google now a hacker's tool&lt;/a&gt; which describes the briefings of the &lt;a href=""&gt;Google Hacking for Penetration Testers&lt;/a&gt; presentation by &lt;a href="http://www.blackhat.com/html/bh-usa-05/bh-usa-05-speakers.html#long"&gt;Johnny Long&lt;/a&gt; at Black Hat Conference, USA 2005.&lt;br /&gt;&lt;br /&gt;They have given explained it using example of "NASA", in which &lt;a href="http://www.google.com/search?sourceid=navclient&amp;ie=UTF-8&amp;rls=GGLG,GGLG:2005-21,GGLG:en&amp;q=site%3Anasa"&gt;googling&lt;/a&gt; offers an insight into the structure of Nasa's (the U.S. National Aeronautics and Space Administration's) internal network.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112318610500293335?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112318610500293335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112318610500293335' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318610500293335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318610500293335'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/google-hackers-new-tool_04.html' title='Google - The hacker&apos;s new tool.'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112318475033578960</id><published>2005-08-04T12:35:00.000-07:00</published><updated>2005-08-04T12:45:50.340-07:00</updated><title type='text'>Phishers on rocking spree after ATMs its eBay</title><content type='html'>A flaw has been discovered on eBay's Web site that would have allowed fraudsters to successfully redirect the sign-on process to a phishing site.&lt;br /&gt;In recent article &lt;a href="http://www.pcworld.com/news/article/0,aid,122065,00.asp"&gt;Phishers hack Ebay&lt;/a&gt; at PCWorld.com, the end result has been told that users will be giving away information and allowing phishers to hijack their accounts, either as a way of laundering money or for launching fake auctions.&lt;br /&gt;&lt;br /&gt;In another article &lt;a href="http://news.com.com/Phishers+cash+in+on+ATM+cards/2100-7349_3-5815141.html?tag=nl"&gt;Phishers cash in on ATM cards&lt;/a&gt;, Phishing attacks have led to an estimated $2.75 billion in losses related to ATM and debit cards over the past 12 months, according to a new Gartner report.&lt;br /&gt;Phishing is on a steep rise and hot buzzword in security world. While the worms/viruses attack has gone down, this is going up.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112318475033578960?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112318475033578960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112318475033578960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318475033578960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112318475033578960'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/phishers-on-rocking-spree-after-atms.html' title='Phishers on rocking spree after ATMs its eBay'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112309960003237885</id><published>2005-08-03T12:49:00.000-07:00</published><updated>2005-08-03T13:06:40.036-07:00</updated><title type='text'>"How to Break Web Security" - Upcoming WebCast</title><content type='html'>&lt;p&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Date/Time:&lt;/strong&gt;&lt;/span&gt; August 9th, 1:00 p.m. EST&lt;br /&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Requirements:&lt;/strong&gt;&lt;/span&gt; Web browser, phone connection and Internet connection (high-speed preferred)&lt;br /&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Presenter:&lt;/strong&gt;&lt;/span&gt; Dr. James A. Whittaker, Ph. D - Chief Scientist and Founder of Security Innovation (bio)&lt;br /&gt;&lt;span style="color:#cc0000;"&gt;&lt;strong&gt;Audience:&lt;/strong&gt;&lt;/span&gt; IT Security Managers, CSO's, Security Architects, IT Directors, IT and Security Professionals, Security Experts, Chief Security Architects, CIO&lt;br /&gt;&lt;br /&gt;Topics covered will be : &lt;/p&gt;&lt;ol&gt;&lt;li&gt;Why the web is different and what this means to testing &lt;/li&gt;&lt;li&gt;How to think about security vulnerabilities in web apps &lt;/li&gt;&lt;li&gt;Techniques for information gathering, client-side attacks, state attacks, data attacks, language attacks, server attacks, authentication attacks &lt;/li&gt;&lt;li&gt;Some thoughts on web services, privacy on the web and tool support &lt;/li&gt;&lt;/ol&gt;&lt;p&gt; &lt;a href="http://www.securityinnovation.com/webcasts/htbws/index.shtml"&gt;Register here&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112309960003237885?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112309960003237885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112309960003237885' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112309960003237885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112309960003237885'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/how-to-break-web-security-upcoming.html' title='&quot;How to Break Web Security&quot; - Upcoming WebCast'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112308065871588409</id><published>2005-08-03T07:45:00.000-07:00</published><updated>2005-08-03T07:50:58.716-07:00</updated><title type='text'>Find vunerability Get Paid</title><content type='html'>Yes!! its true..&lt;br /&gt;checkout &lt;a href="http://www.zerodayinitiative.com/"&gt;Zero Day Initiative&lt;/a&gt;, a new kind of partnership between 3com and TippingPoint to support research in security area.&lt;br /&gt;Homepage says&lt;br /&gt;"The Zero Day Initiative (ZDI), founded by 3Com and TippingPoint, a division of 3Com, represents a best-of-breed model for rewarding security researchers for responsibly disclosing discovered vulnerabilities. The program's goal is threefold: &lt;br /&gt;1. reward independent security research&lt;br /&gt;2. promote and ensure the responsible disclosure of vulnerabilities&lt;br /&gt;3. provide 3Com's TippingPoint division customers with the world's best security protection"&lt;br /&gt;&lt;br /&gt;Process is properly defined in this image&lt;br /&gt;&lt;a href="http://www.zerodayinitiative.com/img/process.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://www.zerodayinitiative.com/img/process.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112308065871588409?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112308065871588409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112308065871588409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112308065871588409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112308065871588409'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/find-vunerability-get-paid.html' title='Find vunerability Get Paid'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112308028831966458</id><published>2005-08-03T07:39:00.000-07:00</published><updated>2005-08-03T07:44:48.323-07:00</updated><title type='text'>Hacking "hacking tools"</title><content type='html'>&lt;a href="http://news.com.com/2061-10789_3-5811705.html?part=rss&amp;tag=feed&amp;subj=news"&gt;Defcon: Poking holes in hacking tools&lt;/a&gt;, article at news.com.com security blog states that The Shmoo Group has found loopholes and bugs worth exploitation even in hacking tools such as Metasploit, Kismet etc.&lt;br /&gt;&lt;br /&gt;Since long I too have been thinking of the same. That if bugs exist in all softwares then why not in tools such as network scanners and hacking tools. And this read just made me happy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112308028831966458?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112308028831966458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112308028831966458' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112308028831966458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112308028831966458'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/hacking-hacking-tools.html' title='Hacking &quot;hacking tools&quot;'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112307942543728521</id><published>2005-08-03T01:17:00.000-07:00</published><updated>2005-08-03T07:30:25.450-07:00</updated><title type='text'>After "Blue Hat" its Regular Hacker Conferences</title><content type='html'>In March 2005, Microsoft invited several hackers to its headquarters for the first time. The meeting was dubbed "Blue Hat" as a nod toward the Black Hat security  conference where researchers annually discuss security issues. and now Microsoft  is mulling over plans to create a regular hacker  conference with the aim of discussing flaws in the company's software products. &lt;br /&gt;checkout &lt;a href="http://www.cio-today.com/news/Microsoft-Considers-Hosting-Hackers/story.xhtml?story_id=0020002HCMRG"&gt;article&lt;/a&gt;&lt;br /&gt;Another proof to support the fact &lt;a href="http://networksecurityupdates.blogspot.com/2005/07/windows-security.html"&gt;"Microsoft too serious about security issues in its products"&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112307942543728521?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112307942543728521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112307942543728521' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112307942543728521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112307942543728521'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/after-blue-hat-its-regular-hacker.html' title='After &quot;Blue Hat&quot; its Regular Hacker Conferences'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112301024486008188</id><published>2005-08-02T12:12:00.000-07:00</published><updated>2005-08-02T12:17:24.876-07:00</updated><title type='text'>Bluetooth eavesdropping</title><content type='html'>Martin Herfurt, in his article &lt;a href="http://trifinite.org/blog/archives/2005/07/introducing_the.html"&gt;Introducing the Car Whisperer at What The Hack&lt;/a&gt; about the tool &lt;a href="http://trifinite.org/trifinite_stuff_carwhisperer.html"&gt;The Car Whisperer&lt;/a&gt; exposed one more Bluetooth security flaw.&lt;br /&gt;&lt;br /&gt;What this tool does is it allows people equipped with a Linux Laptop and a directional antenna to inject audio to, and record audio from bypassing cars that have an unconnected Bluetooth handsfree unit running. Since many manufacturers use a standard passkey which often is the only authentication that is needed to connect.&lt;br /&gt;&lt;br /&gt;Its time to tell people how poorly they are driving :-?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112301024486008188?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112301024486008188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112301024486008188' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112301024486008188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112301024486008188'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/bluetooth-eavesdropping.html' title='Bluetooth eavesdropping'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112297670199671409</id><published>2005-08-02T02:51:00.000-07:00</published><updated>2005-08-02T06:49:27.150-07:00</updated><title type='text'>Windows Vista and IE7</title><content type='html'>As the date of launch of Windows new Version, &lt;b&gt;Windows Vista&lt;/b&gt; (originally codenamed "Longhorn") approaches, people are getting excited. Daily a lot of articles on its security, features, compatibility issues are being written.&lt;br /&gt;&lt;br /&gt;Some of the links&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;&lt;a href="http://blogs.msdn.com/fabricem/archive/2005/08/02/446495.aspx"&gt;Hands of Vista and  some of its features&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.eweek.com/slideshow/0,1206,a=156926,00.asp"&gt;Slideshow on IE7 and its features.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;    &lt;a name="112294135676190545" href="http://123suds.blogspot.com/2005/08/vista-changing-landscape.html" title="permanent link"&gt;Vista &amp;amp; The Changing Landscape&lt;/a&gt;   &lt;/li&gt;   &lt;/ol&gt;&lt;br /&gt;Me too getting excited for the new Vista.&lt;br /&gt;New news. &lt;A href="http://channel9.msdn.com/ShowPost.aspx?PostID=95051"&gt;IE7 wont pe passing the Acid2 test.&lt;/a&gt;. &lt;br /&gt;(P.S. : &lt;a href="http://webstandards.org/act/acid2/"&gt;Acid test&lt;/a&gt;)&lt;br /&gt;"We fully recognize that IE is behind the game today in CSS support. We've dug through the Acid2 test and analyzed IE's problems with the test in some great detail, and we've made sure the bugs and features are on our list--however, there are some fairly large and difficult features to implement, and they will not all sort to the top of the stack in IE7." says Chris Wilson, lead program manager for the web platform in IE.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112297670199671409?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112297670199671409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112297670199671409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112297670199671409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112297670199671409'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/windows-vista-and-ie7.html' title='Windows Vista and IE7'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112288059058618991</id><published>2005-08-01T00:11:00.000-07:00</published><updated>2005-08-01T00:17:47.996-07:00</updated><title type='text'>linux magazine podcast</title><content type='html'>The latest buzzword in the market is &lt;a href="http://ipod-apple.blogspot.com"&gt;iPod and the Podcasting&lt;/a&gt;. and many new podcasting technology has been released  lately including &lt;A href="http://odeo.com/"&gt;Odeo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Even the everything about linux, the &lt;a href="http://www.linuxmagazine.com/"&gt;Linux Magazine&lt;/a&gt; has released the &lt;a href="http://www.linuxmagazine.com/2002-09/harden_list.htm"&gt;"FIrst Linux Magazine Podcast"&lt;/a&gt;. Sounds cool.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112288059058618991?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112288059058618991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112288059058618991' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112288059058618991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112288059058618991'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/08/linux-magazine-podcast.html' title='linux magazine podcast'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112280821021171716</id><published>2005-07-31T04:03:00.000-07:00</published><updated>2005-08-01T07:52:44.866-07:00</updated><title type='text'>Black hat conference</title><content type='html'>&lt;a href="http://www.blackhat.com"&gt;Black Hat&lt;/a&gt; conference, USA 2005 was great one especially after the Michael Lynn presentation on "Cisco IOS Security Architecture" which exposed the CISCO IOS flaw which can lead to DDOs attacks and can give router complete access. The bug is not as serius as CISCO keeps saying and has filed suit against the researcher. Checkout my &lt;A href="http://networksecurityupdates.blogspot.com/2005/07/cisco-flaws-and-disclosure-issues.html"&gt;earlier post&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Other one was the highlighting of &lt;a href="http://www.networkworld.com/news/2005/080105-blackhat-side.html"&gt;RFID and VoIP security threats&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A lot of other security issues, bugs and holes has been discussed and presented too.&lt;br /&gt;&lt;a href="http://news.com.com/Black+Hat+Hunting+bugs%2C+finding+holes/2009-7348_3-5808386.html?tag=nefd.top"&gt;http://news.com.com/Black+Hat+Hunting+bugs%2C+finding+holes/2009-7348_3-5808386.html?tag=nefd.top&lt;/a&gt;&lt;br /&gt;&lt;A href="http://www.blackhat.com/html/bh-media-archives/bh-multi-media-archives.html#USA-2005"&gt;http://www.blackhat.com/html/bh-media-archives/bh-multi-media-archives.html#USA-2005&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112280821021171716?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112280821021171716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112280821021171716' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112280821021171716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112280821021171716'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/black-hat-conference.html' title='Black hat conference'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112272805702173178</id><published>2005-07-30T05:35:00.000-07:00</published><updated>2005-07-30T05:54:17.026-07:00</updated><title type='text'>Malicious Bot attacks and Botnets</title><content type='html'>After virus, worms and trojans, the other malwares affecting most of the people and networks are Bots. Bots when they form a network among themselves by spreading on a range or network or comps are known as Botnets.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;They are responsible for:&lt;/span&gt;&lt;br /&gt;1) Heavy DDos attacks&lt;br /&gt;2) Mass spamming mails&lt;br /&gt;3) Installing key logging software for getting secret user information&lt;br /&gt;4) Infecting computers to viruses and other malware.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;How they spread&lt;/span&gt;&lt;br /&gt;1) As email attachments&lt;br /&gt;2) via IRC file transfer mechanisms&lt;br /&gt;3) Attacking vunerable web servers and changing the scripts to execute "bot" scripts on client machines&lt;br /&gt;4) using P2P connections and file sharing mechanisms&lt;br /&gt;5) don’t replicate or spread on their own, but they can use the worms’ functionality to do so.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Statistics:&lt;/span&gt;&lt;br /&gt;1) We see as many as 60,000 come on in a day,” said Alfred Huger, Symantec Security Response’s senior director of engineering.&lt;br /&gt;2) “Security investigators have even found one botnet of 100,000 computers,” Ullrich chief technology officer for the Internet Storm Center, which detects, analyzes, and disseminates information about Internet-related security problems notified.&lt;br /&gt;3) “In 2003, there were only 750 [malicious] bots reported. In 2004, there have already been over 2,300. There is a potential for a 400 percent increase in 2004 and 2005 over what we have seen. If that’s the case, we could see up to 12,000 variants of bots appear in 2005,” said iDefense's Dunham.&lt;br /&gt;&lt;br /&gt;A detailed &lt;A href="http://portal.acm.org/citation.cfm?id=1042191.1042231"&gt;report&lt;/a&gt; about the future and their current existence has been published in IEEE magzine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112272805702173178?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112272805702173178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112272805702173178' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112272805702173178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112272805702173178'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/malicious-bot-attacks-and-botnets.html' title='Malicious Bot attacks and Botnets'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112272508176217329</id><published>2005-07-30T04:56:00.000-07:00</published><updated>2005-07-30T05:04:41.763-07:00</updated><title type='text'>Windows Security</title><content type='html'>2 recent articles on Eweek talks about promising efforts from Microsoft and of course new Windows version namely Windows Vista in security field. &lt;br /&gt;In the newer version, one will be able to work in Limited account and do administrative works by enterting password whenever will be asked for. (similar to putting root password in linux for security reasons) This feature has been named "User Account Protection".&lt;br /&gt;A lot of advanced secure features in IE7, windows firewall and antispyware products will be available too. Checkout some of them &lt;a href="http://www.eweek.com/article2/0,1895,1841242,00.asp"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"Microsoft has tools that will be in Visual Studio 2005 to do static code analysis," says Ozzie whose Groove Networks is now part of Microsoft. Even Microsoft is offering tools such as PreFast, Prefix and FXCop to weed out code vulnerabilities, and Microsoft developers cannot check in their code into the corporate code tree without running it through these tools, Gates said. Gates even said that Microsoft Research, which turned out the Microsoft code security tools, is "the best investment the company ever made,".&lt;br /&gt;Checkout &lt;A href="http://www.eweek.com/article2/0,1895,1841426,00.asp"&gt;Gates and Microsoft steps against hackers and exploits.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112272508176217329?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112272508176217329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112272508176217329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112272508176217329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112272508176217329'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/windows-security.html' title='Windows Security'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112270003229987271</id><published>2005-07-29T22:05:00.000-07:00</published><updated>2005-07-30T04:48:33.866-07:00</updated><title type='text'>Network companies Q2 revenues</title><content type='html'>A lot of companies Quater 2 financial results (the one ended June 30, 2005) has been declared recently, most of them listed on &lt;a href="http://www.lightreading.com/"&gt;LightReading&lt;/a&gt;.&lt;br /&gt;Most of companies reported growth and promising results with good profits.&lt;br /&gt;&lt;br /&gt;While for &lt;a href="http://www.lightreading.com/document.asp?doc_id=78118"&gt;NetLogic&lt;/a&gt;, greater demand for knowledge-based processors and growth in the company's total addressable market led to the stronger-than-expected second quarter revenue.&lt;br /&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78074"&gt;Sprint&lt;/a&gt; driven by solid execution across each of its business units, reported record quarterly earnings from continuing operations which are reflected in second quarter 2005.&lt;br /&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78119"&gt;Covad&lt;/a&gt; while hasnt shown much growth though ended the second quarter of 2005 with approximately 554,400 broadband lines in service, an increase of 7,000 lines from the first quarter of 2005. More than one-third of the line growth was from sales of business T1 services.&lt;br /&gt;Many other has been listed too.&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78109"&gt;Centillium&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78108"&gt;MRV COMMUNICATIONS, INC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78089"&gt;Valor&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78078"&gt;iBasis&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78032"&gt;Corning&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78031"&gt;Aastra&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78030"&gt;Brooktrout&lt;/a&gt;&lt;br /&gt; &lt;/li&gt;   &lt;/ol&gt;Many others can be checkout too at Lightreading.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112270003229987271?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112270003229987271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112270003229987271' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112270003229987271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112270003229987271'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/network-companies-q2-revenues.html' title='Network companies Q2 revenues'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112255236470794456</id><published>2005-07-28T05:01:00.000-07:00</published><updated>2005-07-29T22:54:20.810-07:00</updated><title type='text'>Cisco Flaws and Disclosure Issues</title><content type='html'>&lt;a href="http://dmiessler.com/archives/409"&gt;Gr8 post and article..&lt;/a&gt;&lt;br /&gt;Must readme for cisco IOS vendors and customers :x&lt;br /&gt;&lt;br /&gt;New Info (Edited: 30th july)&lt;br /&gt;&lt;a href="http://www.lightreading.com/document.asp?doc_id=78236"&gt;Cisco Reveals 'Black Hat' Flaw&lt;/a&gt; i.e. another DOS vunerability found in the Cisco's IOS in which the code execution can provide the router access to the hacker :) but will work only if router has been configured for IPv6.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112255236470794456?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112255236470794456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112255236470794456' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112255236470794456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112255236470794456'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/cisco-flaws-and-disclosure-issues.html' title='Cisco Flaws and Disclosure Issues'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112161412070516963</id><published>2005-07-17T08:27:00.000-07:00</published><updated>2005-07-17T08:32:54.090-07:00</updated><title type='text'>Firefox and Phishing..</title><content type='html'>Much work is going on for fighting with phishing the latest buzzword in internet fraud. Even some firefox extensions has been developed.&lt;br /&gt;Checkout :&lt;br /&gt;Outfoxed - http://getoutfoxed.com/&lt;br /&gt;TrustBar - http://trustbar.mozdev.org/&lt;br /&gt;Spoofstick - http://www.corestreet.com/spoofstick/&lt;br /&gt;Netcraft Toolbar - http://toolbar.netcraft.com/ (This one is the BEST)&lt;br /&gt;[ source : SecurityFocus mailing list ]&lt;br /&gt;&lt;br /&gt;Some &lt;a href="http://www.cyota.com/product_1_3.asp"&gt;stats about phishing market&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112161412070516963?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112161412070516963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112161412070516963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112161412070516963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112161412070516963'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/firefox-and-phishing.html' title='Firefox and Phishing..'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112161400326629717</id><published>2005-07-17T08:17:00.000-07:00</published><updated>2005-07-17T08:26:43.270-07:00</updated><title type='text'>Zlib Buffer Overflows..</title><content type='html'>Recently, A lot has been discussed on the Zlib[1] buffer overflow vunerability.&lt;br /&gt;Florian Weimer (from his recent post[3] at buqtraq@securityfocus[2] mailing list) have created Clamav signatures which can be used to detect copies of vulnerable zlib versions. (Giving credit to Mark Adler for providing data)&lt;br /&gt;&lt;br /&gt;"This is useful mainly for discovering statically linked zlib copies in program binaries, which must be patched separately.&lt;br /&gt;&lt;br /&gt;The Clamav signature database is available form:&lt;br /&gt; http://www.enyo.de/fw/security/zlib-fingerprint/&lt;br /&gt;" -- Florian&lt;br /&gt;He claims Clamav should be significantly faster.  Furthermore, clamscan can look inside certain archive formats used for software distribution (mainly .tar.gz and Debian packages, RPM packages aren't supported at the moment, AFAICS).&lt;br /&gt;&lt;br /&gt;This buffer overflow error when processing a malformed data stream, which could be exploited by attackers to execute arbitrary code via a specially crafted compressed stream embedded within network communication or an application file format. (CAN-2005-2096[4])&lt;br /&gt;This can further be used for Denial of Service (DoS) attack&lt;br /&gt;&lt;br /&gt;Links:&lt;br /&gt;[1] http://www.zlib.net/&lt;br /&gt;[2] http://www.securityfocus.com/archive/1&lt;br /&gt;[3] http://www.securityfocus.com/archive/1/404971/30/60/threaded&lt;br /&gt;[4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2096&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112161400326629717?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112161400326629717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112161400326629717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112161400326629717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112161400326629717'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/zlib-buffer-overflows.html' title='Zlib Buffer Overflows..'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112152483467393708</id><published>2005-07-16T07:37:00.000-07:00</published><updated>2005-07-16T07:43:06.363-07:00</updated><title type='text'>Netflow for IDS</title><content type='html'>Just read this mail on securityfocus mailing lists...&lt;br /&gt;NEtflow data also provides valuable information of IDS information. A lot of tools has been listed on &lt;a href="http://securitywizardry.com/protNetFlowA.htm"&gt;SecurityWizardry.com&lt;/a&gt;.&lt;br /&gt;Surely worth checkout for NEtflow users...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112152483467393708?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112152483467393708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112152483467393708' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112152483467393708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112152483467393708'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/netflow-for-ids.html' title='Netflow for IDS'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112152452639316342</id><published>2005-07-16T07:30:00.000-07:00</published><updated>2005-07-16T07:35:26.396-07:00</updated><title type='text'>Holidays!!</title><content type='html'>these days at home enjoying holidays...:)&lt;br /&gt;will be posting some new stuff soon (may be arnd 26th)&lt;br /&gt;&lt;br /&gt;till then cya. njoi&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112152452639316342?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112152452639316342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112152452639316342' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112152452639316342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112152452639316342'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/holidays.html' title='Holidays!!'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112127892217420425</id><published>2005-07-13T11:10:00.000-07:00</published><updated>2005-07-13T13:27:11.366-07:00</updated><title type='text'>Network Traffic Analysis through Images</title><content type='html'>In a recent 2005 &lt;a href="http://dropzone.tamu.edu/%7Eskim/infocom_v14.pdf"&gt;paper&lt;/a&gt;, Seong Soo Kim and A. L. Narasimha Reddy from Texas A&amp;amp;M University has harnessed the image and video processing technology for simultaneous detection, identification and visualization of attacks and anomalous traffic in real-time by passively monitoring packet headers.&lt;br /&gt;&lt;br /&gt;In their novice approach, they emphazied on "scene change analysis" and "motion prediction".&lt;br /&gt;Their representation allows simple visualization of traffic data as each sample is seen as a frame in a video sequence.Traffic data can then be efficiently stored through such techniques as video compression.&lt;br /&gt;&lt;br /&gt;They have even provided comparison statistics with other IDS, here &lt;a href="http://www.blogger.com/www.snort.org"&gt;Snort&lt;/a&gt;. Netviewer, the name of their tool performs quantative analysis and reports the suspicious IP addresses and the pattern of abnormality in an aggregated fashion.&lt;br /&gt;&lt;br /&gt;An interesting work. I really liked it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112127892217420425?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112127892217420425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112127892217420425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112127892217420425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112127892217420425'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/network-traffic-analysis-through.html' title='Network Traffic Analysis through Images'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112116892103562103</id><published>2005-07-12T04:26:00.000-07:00</published><updated>2005-07-12T04:48:59.326-07:00</updated><title type='text'>Spyware effecting the way people use Internet</title><content type='html'>In the latest &lt;a href="http://www.pewinternet.org/pdfs/PIP_Spyware_Report_July_05.pdf"&gt; report&lt;/a&gt; released by PEW INTERNET &amp;amp; AMERICAN LIFE PROJECT about "Spyware: The threat of unwanted software programs is changing the way people use the internet." starts off with statistics like:&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;Nine out of ten internet users say they have adjusted their online behavior&lt;br /&gt;out of fear of falling victim to software intrusions.&lt;/li&gt;   &lt;li&gt;Overall, 91% of internet users say they have made at least one change in their online behavior to avoid unwanted software programs.&lt;/li&gt;   &lt;li&gt;The definitions of spyware and adware may not be clear to many internet users, but many believe that surveillance and unwanted software are serious threats to users’ security and privacy.&lt;/li&gt;   &lt;li&gt;Four in ten internet users have had spyware, adware, or both.&lt;br /&gt; &lt;/li&gt; &lt;/ol&gt; the major changes has been summerized as :&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;81% of internet users say they have stopped opening email attachments unless they are sure these documents are safe.&lt;/li&gt;   &lt;li&gt;48% of internet users say they have stopped visiting particular Web sites that they fear might deposit unwanted programs on their computers.&lt;/li&gt;   &lt;li&gt;25% of internet users say they have stopped downloading music or video files from peer-to-peer networks to avoid getting unwanted software programs on their computers.&lt;/li&gt;   &lt;li&gt;18% of internet users say they have started using a different Web browser to avoid software intrusions.&lt;/li&gt; &lt;/ol&gt; Some statistics about the knowledge of internet users are:&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;88% of internet users say they have a good idea what “spam” means.&lt;/li&gt;   &lt;li&gt;78% of internet users say they have a good idea what “firewall” means.&lt;/li&gt;   &lt;li&gt;78% of internet users say they have a good idea what “spyware” means.&lt;/li&gt;   &lt;li&gt;68% of internet users say they have a good idea what “internet cookies” means (by comparison, 43% of internet users said they knew what an “internet cookie” was in 2000).&lt;/li&gt;   &lt;li&gt;52% of internet users say they have a good idea what “adware” means.&lt;/li&gt;   &lt;li&gt;29% of internet users say they have a good idea what “phishing” means (described as “internet phishing, spelled with a P-H at the beginning”). Fully 15% of internet usersvolunteered that they had never heard the term before. &lt;/li&gt; &lt;/ol&gt; You can better understand the basics with statistical analysis on &lt;a href="http://psi.bth.se/mbo/exploring_spyware_effects-nordsec2004.pdf"&gt;"spyware and their effect in day to day work and user privacy". &lt;/a&gt; This is a P2P perspective i.e. spyware considered are from P2P applications and their effect on network.&lt;br /&gt;&lt;br /&gt;A lot of tools are available for spyware removal. a Long list is available &lt;a href="http://www.pcworld.com/downloads/browse/0,cat,1727,sortIdx,1,pg,1,00.asp"&gt;here&lt;/a&gt;.&lt;br /&gt;Also, the list of their features, feature comparison and price listing at &lt;a href="http://anti-spyware-review.toptenreviews.com/"&gt;TopTenReviews&lt;/a&gt; shows Spyware Eliminator is the best one currently. But this site hasn't compared &lt;a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Microsoft Windows AntiSpyware&lt;/a&gt;. I have tried this one and Ad Aware professional trial version. I found both good but Microsoft product is seriously worth a try.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112116892103562103?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112116892103562103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112116892103562103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116892103562103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116892103562103'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/spyware-effecting-way-people-use.html' title='Spyware effecting the way people use Internet'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112116748213802842</id><published>2005-07-12T04:16:00.000-07:00</published><updated>2005-07-12T04:24:42.143-07:00</updated><title type='text'>Buffer Overflow or Stack Smashing</title><content type='html'>Buffer Overflows are one of the most common vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Problem&lt;/span&gt;: C++ and other programming languages (those derived from C++), do not automatically perform bounds-checking when passing data. When variables are passed, extra characters could be written past the variable's end.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Occurence&lt;/span&gt;:when the attacker intentionally enters more data than a program was written to handle.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Consequence&lt;/span&gt;: result in the program crashing or allowing the attacker to execute their own code on the target system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Pre-requisites&lt;/span&gt;: Basic knowledge of assembly is required. An understanding of virtual memory concepts, and experience with gdb are very helpful but not necessary.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Tutorial Links:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;http://www.linuxsecurity.com/content/view/119087/49/&lt;/li&gt;   &lt;li&gt;http://www.linuxsecurity.com/content/view/118881/49/&lt;/li&gt;   &lt;li&gt;http://www.insecure.org/stf/smashstack.txt&lt;/li&gt;   &lt;li&gt;http://www.watchguard.com/infocenter/editorial/135136.asp&lt;/li&gt; &lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112116748213802842?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112116748213802842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112116748213802842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116748213802842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116748213802842'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/buffer-overflow-or-stack-smashing.html' title='Buffer Overflow or Stack Smashing'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112116183228454465</id><published>2005-07-12T02:44:00.000-07:00</published><updated>2005-07-12T03:20:11.780-07:00</updated><title type='text'>Semantec + Veritas</title><content type='html'>&lt;a href="http://www.baselinemag.com/article2/0,1540,1831999,00.asp"&gt;Symantec merged with Veritas on 24rth June, 2005.&lt;/a&gt;&lt;br /&gt;Symantec had revenues last year of $1.9 billion, while Veritas saw revenues of $2.0 billion.&lt;br /&gt;&lt;br /&gt;With little public explanation of the underlying reasoning, investors' confidence in the deal sank along with its value, which dropped from $13.5 billion to as little as $9 billion before finally closing at about $11 billion on June 24. That made it, by a hair, the &lt;a href="http://www.eweek.com/article2/0,1895,1742005,00.asp"&gt;largest software merger&lt;/a&gt; to date, barely eclipsing the $10.6 billion acquisition of PeopleSoft completed at the end of last year by Oracle.&lt;br /&gt;&lt;br /&gt;Thompson, Symantec CEO said that this merge leads to birth of "purple" elephant and it aims at providing better and more secure information systems with constant data backups&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112116183228454465?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112116183228454465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112116183228454465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116183228454465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112116183228454465'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/semantec-veritas.html' title='Semantec + Veritas'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112114796586838777</id><published>2005-07-11T22:51:00.000-07:00</published><updated>2005-08-10T16:09:45.126-07:00</updated><title type='text'>Phrack Ends....</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;par&gt;&lt;br /&gt;&lt;/par&gt;&lt;/span&gt; &lt;div style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;[-]=====================================================================[-]&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                     +++++++++++++++++++++++++++&lt;br /&gt;&lt;/span&gt;&lt;/par&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                   =: P H R A C K - F I N A L :=&lt;br /&gt;&lt;/span&gt;&lt;/par&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                     +++++++++++++++++++++++++++&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;            ...a glorious era comes to an end. #63 will&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;              be _our_ last PHRACK RELEASE -- EVER...&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;   FINAL CALL FOR PAPERS * FINAL CALL FOR PAPERS * FINAL CALL FOR PAPERS&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                 -----------------------------------&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                  Deadline: 10 July 2005 at 11:59pm&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                 http://www.phrack.org/cfp_final.txt&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;                 -----------------------------------&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;   &lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;   Phrackstaff is pleased to bring you _our_ LAST EVER CALL FOR PAPERS for&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;   the FINAL RELEASE of PHRACK.&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;   We are preparing for a hardcover and ezine release at a major hacker&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;span style="font-family:arial;"&gt;   convention near you!&lt;/span&gt;&lt;/par&gt;&lt;br /&gt;&lt;par&gt;&lt;/par&gt;&lt;/span&gt;  &lt;/div&gt; &lt;div style="text-align: center; font-family: arial;"&gt; &lt;pre&gt;&lt;span style="font-size:85%;color:#000000;"&gt;[-]========================================================[-]&lt;/span&gt;&lt;/pre&gt; &lt;/div&gt; This is at the homepage of famous hacking magzine, &lt;a href="http://www.phrack.org/"&gt;PHRACK&lt;/a&gt;. This is their last edition but the site will be up for 2 more years after this last edition.&lt;br /&gt;=(( :((&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112114796586838777?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112114796586838777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112114796586838777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112114796586838777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112114796586838777'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/phrack-ends.html' title='Phrack Ends....'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112114551550660524</id><published>2005-07-11T22:14:00.000-07:00</published><updated>2005-07-11T22:18:35.510-07:00</updated><title type='text'>new WLAN security tools</title><content type='html'>In the past 2 weeks, &lt;A href="http://www.eweek.com/article2/0,1759,1834899,00.asp?kc=EWRSS03119TX1K0000594"&gt;2 new tools&lt;/a&gt; have been launched gives administrators new ways to inventory authorized wireless devices; spot attacks; and even spot rogue devices lurking in unsuspected places, a process known as wardriving.&lt;br /&gt;&lt;br /&gt;1) AirDefense, of Atlanta, unveiled AirDefense Mobile, a WLAN (wireless LAN) which retails for $995&lt;br /&gt;2) WiFi Watchdog 5.0 from Newbury Networks, will be out in an early release at the end of the summer and commercially available in September. Pricing starts at $14,995.&lt;br /&gt;&lt;br /&gt;While former using 802.11a,b and g protocol while latter uses location technology and behavior patterns for intrusion prevention and detection, client protection, and containment of rogue access points.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112114551550660524?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112114551550660524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112114551550660524' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112114551550660524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112114551550660524'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/new-wlan-security-tools.html' title='new WLAN security tools'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112110456971575235</id><published>2005-07-11T10:48:00.000-07:00</published><updated>2005-07-11T10:56:09.720-07:00</updated><title type='text'>Future of C++</title><content type='html'>While this post doesnot belongs to this blog but being a C++ fan couldn't stop myself from writing it here :)&lt;br /&gt;&lt;br /&gt;&lt;A href="http://www.research.att.com/~bs/homepage.html"&gt;Bjarne Stroustrup&lt;/a&gt;, the father of C++, has written an essay &lt;a href="http://www.informit.com/content/images/art_stroustrup_2005/elementLinks/rules.pdf"&gt;[PDF]&lt;/a&gt; on the features in the new C++ version named as C++0x standard (also available at &lt;a href="www.cuj.com"&gt;C/C++ Users Journal&lt;/a&gt;. In his essay, he argues that new features should make C++0x significantly better than current C++ version making it more compatible and easier for beginners.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112110456971575235?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112110456971575235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112110456971575235' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112110456971575235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112110456971575235'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/future-of-c.html' title='Future of C++'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112094489810751655</id><published>2005-07-09T14:30:00.000-07:00</published><updated>2005-07-09T21:15:38.446-07:00</updated><title type='text'>Strengthening Digital Signaures</title><content type='html'>via &lt;a href="https://www.threatsandcountermeasures.com/blogs/michaels/archive/2005/05/31/418.aspx"&gt;randomized hashing&lt;/a&gt;.. sounds interesting!!!!. &lt;br /&gt;The original draft seemed to me as sort of extention to &lt;a href="http://portal.acm.org/ft_gateway.cfm?id=803400&amp;type=pdf"&gt;univeral class of hash functions&lt;/a&gt; which defines the hash functions and key generation is random depending upon on some random parameters. But there is paper which says 100% perfect hashing is possible thru those functions depending upon ur choice of random parameter.&lt;br /&gt;&lt;br /&gt;Lets see where this one leads?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112094489810751655?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112094489810751655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112094489810751655' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112094489810751655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112094489810751655'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/strengthening-digital-signaures.html' title='Strengthening Digital Signaures'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112094066315722749</id><published>2005-07-09T13:17:00.000-07:00</published><updated>2005-07-09T14:42:41.856-07:00</updated><title type='text'>Web Application Firewalls</title><content type='html'>Just went through the article &lt;a href="https://www.threatsandcountermeasures.com/blogs/marksblog/archive/2005/05/26/408.aspx"&gt;Why  Don't You Like Web Application Firewalls?"&lt;/a&gt;.&lt;br /&gt;Really good points dicussed by Mark Curphy and especially about the "Imperva" product  and foundstone technologies.&lt;br /&gt;Checkout the demo of Validator .NET &lt;a href="http://msevents.microsoft.com/cui/r.aspx?t=4&amp;c=en-us&amp;r=6467330"&gt;Here&lt;/a&gt;&lt;br /&gt;Hey!! some more interesting stuff .. Vaidator.NET even handles Layer 7 (Application) DDoS attacks. (very helpful in cases of valid DDOS attack traffic)&lt;br /&gt; &lt;br /&gt;In the mean time, found another interesting article on IE bug exploitation. I was ROFL after reading it :)&lt;br /&gt;checkout &lt;a href="http://news.com.com/Online+miscreants+encrypt+files%2C+hold+for+ransom/2100-7349_3-5718678.html?part=rss&amp;tag=5718678&amp;amp;subj=news"&gt;Miscreants encrypt files, hold them for ransom&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112094066315722749?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112094066315722749/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112094066315722749' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112094066315722749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112094066315722749'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/web-application-firewalls.html' title='Web Application Firewalls'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112081579248420009</id><published>2005-07-08T02:36:00.000-07:00</published><updated>2005-07-08T02:43:12.486-07:00</updated><title type='text'>Network World's test of endpoint security products</title><content type='html'>Vernier Networks/PatchLink combination topped the list which included&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;&lt;a href="http://www.checkpoint.com/"&gt;Check Point&lt;/a&gt;,&lt;br /&gt; &lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.cisco.com/"&gt;Cisco&lt;/a&gt; ,&lt;br /&gt; &lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.citadel.com/"&gt;Citadel&lt;/a&gt;, &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.infoexpress.com/"&gt;InfoExpress&lt;/a&gt;,&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.senforce.com"&gt;Senforce&lt;/a&gt;,&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.trendmicro.com"&gt;Trend Micro &lt;/a&gt;and&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.verniernetworks.com"&gt;Vernier Networks&lt;/a&gt; (in cooperation with PatchLink)&lt;/li&gt;  &lt;/ol&gt;Checkout Article at &lt;a href="http://www.networkworld.com/reviews/2005/062705-endpoint-test.html"&gt;network world.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112081579248420009?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112081579248420009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112081579248420009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081579248420009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081579248420009'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/network-worlds-test-of-endpoint.html' title='Network World&apos;s test of endpoint security products'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112081521310588951</id><published>2005-07-08T02:27:00.000-07:00</published><updated>2005-07-08T02:33:33.110-07:00</updated><title type='text'>De-perimeterisation.</title><content type='html'>thats the term coined by &lt;a href="http://www.opengroup.org/jericho/"&gt; Jericho Forums&lt;/a&gt;. Accordign to them the increasing demand and use of B2B applications and e-commerce needs no firewalls at perimeters at boundaries since they effect the performance of these applications. Checkout what they are upto and how they provide the alternate solution since perimeter security is the indespensible need in security terms in current situation.&lt;br /&gt;&lt;br /&gt;On the other hand leading market analysts and firewalls vendors says its nearly impossible that perimeter firewall is not there in near future.checkout their views &lt;a href="http://www.networkworld.com/news/2005/070405perimeter.html"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So, what are your views?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112081521310588951?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112081521310588951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112081521310588951' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081521310588951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081521310588951'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/de-perimeterisation.html' title='De-perimeterisation.'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112081375619892725</id><published>2005-07-08T02:04:00.000-07:00</published><updated>2005-07-08T02:10:22.890-07:00</updated><title type='text'>Today's Hackers</title><content type='html'>"Code for Cash, Not Chaos" -- Marc Sachs, volunteer director of the SANS Institute's Internet Storm Center.&lt;br /&gt;&lt;br /&gt;A quite good article about the change in thinking of hackers. They now no more go more attaining fame by creating chaos (effecting millions/billions of people all over the world) rather aiming to get money for their work (:D). &lt;br /&gt;Article also discusses on seriousness in microsoft camp over security issues since they  have been recieving constant banging from people in this regard since long.&lt;br /&gt;checkout article &lt;a href="http://www.eweek.com/article2/0,1759,1833650,00.asp?kc=EWRSS03119TX1K0000594"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112081375619892725?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112081375619892725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112081375619892725' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081375619892725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081375619892725'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/todays-hackers.html' title='Today&apos;s Hackers'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112081341564924368</id><published>2005-07-08T02:00:00.000-07:00</published><updated>2005-07-08T02:03:35.650-07:00</updated><title type='text'>RPC/DCOM vunerabilities</title><content type='html'>I know this quite an old link(2003) but still its good for beginners..&lt;br /&gt;&lt;a href="http://www.stanford.edu/services/securecomputing/rpc-vulns.html"&gt;Vulnerabilities, Patches and Exploits for Windows RPC/DCOM&lt;/a&gt; explaining about the RPC and DCOM. Also explains the exploits and some pactches links has also been provided.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112081341564924368?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112081341564924368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112081341564924368' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081341564924368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112081341564924368'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/rpcdcom-vunerabilities.html' title='RPC/DCOM vunerabilities'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-14300086.post-112080968931668331</id><published>2005-07-08T00:39:00.000-07:00</published><updated>2005-07-08T02:12:01.093-07:00</updated><title type='text'>More ICMP flaws</title><content type='html'>Just gone thru the Kernal Trap Article on &lt;A href="http://kerneltrap.org/node/5382"&gt;More ICMP flaws&lt;/A&gt;. Some of the things were really great to know like most of companies are interested in gaining name/fame for dicovering the flaw rather solving the problem for their customers.&lt;br /&gt;Especially this line was gr8...&lt;br&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;Theo explains, "here we have a 20 year old protocol, a part of the Internet infrastructure that hasn't been touched in 10 years and we were all sure was right, and now is cast in doubt." He went on to add, "these things have to be done carefully. We can't ignore the problem, which is what the IETF and the other vendors are telling us to do."&lt;br /&gt;&lt;/i&gt;&lt;br&gt;&lt;br /&gt;These flaws(written in a draft by Fernando gont) has been summerized as:&lt;br /&gt;&lt;br /&gt;   1. Blind connection reset attack: an attacker can generate a "hard" ICMP error to remotely tear down an existing connection.&lt;br /&gt;   2. Blind throughput reduction: an attacker can generate ICMP errors that repeatedly trigger source quenching, thereby reducing the throughput of the connection.&lt;br /&gt;   3. Blind performance degrading attack: an attacker can use ICMP packets to trick Path MTU discovery into reducing the size of each sent packet down to only 68 bytes.&lt;br /&gt;&lt;br /&gt;He has given some solutions also. Must a checkout article.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/14300086-112080968931668331?l=networksecurityupdates.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurityupdates.blogspot.com/feeds/112080968931668331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=14300086&amp;postID=112080968931668331' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112080968931668331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/14300086/posts/default/112080968931668331'/><link rel='alternate' type='text/html' href='http://networksecurityupdates.blogspot.com/2005/07/more-icmp-flaws.html' title='More ICMP flaws'/><author><name>Nakul</name><uri>http://www.blogger.com/profile/10057752443930564492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
