<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Context Security &#187; Security</title>
	<atom:link href="http://www.contextsecurity.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.contextsecurity.com</link>
	<description>Bringing information security into context.</description>
	<lastBuildDate>Wed, 16 Jun 2010 18:18:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Maybe those DLP $$$/record breached stats aren&#8217;t so far off&#8230;</title>
		<link>http://www.contextsecurity.com/2010/06/16/maybe-those-dlp-record-breached-stats-arent-so-far-off/</link>
		<comments>http://www.contextsecurity.com/2010/06/16/maybe-those-dlp-record-breached-stats-arent-so-far-off/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 18:18:03 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[DLP]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=101</guid>
		<description><![CDATA[I have often scoffed at some of the numbers used to cost justify Data Leakage Prevention (DLP) purchases.  While I agree there is a pretty serious need for redoubled efforts at preventing (and moreover detecting) sensitive data leaving an organization&#8217;s control, I haven&#8217;t found myself persuaded by most of the &#8220;studies&#8221; that show crazy high [...]]]></description>
			<content:encoded><![CDATA[<p>I have often scoffed at some of the numbers used to cost justify Data Leakage Prevention (DLP) purchases.  While I agree there is a pretty serious need for redoubled efforts at preventing (and moreover detecting) sensitive data leaving an organization&#8217;s control, I haven&#8217;t found myself persuaded by most of the &#8220;studies&#8221; that show crazy high $$$/record costs.  Perhaps I am jaded, but often these reports feel as if they were  funded by those with a vested interest in the results pointing in a particular direction (that of &#8220;buying our product makes cents&#8221; [sic]).</p>
<p>Fast forward to the DarkReading <a href="http://www.darkreading.com/insiderthreat/security/government/showArticle.jhtml?articleID=225600466" target="_blank">article</a> that I first noticed this past weekend.  In 2008, California passed two laws <a href="http://info.sen.ca.gov/cgi-bin/postquery?bill_number=ab_211&amp;sess=CUR&amp;house=B&amp;site=sen" target="_blank">Assembly Bill 211</a> and <a href="http://info.sen.ca.gov/cgi-bin/postquery?bill_number=sb_541&amp;sess=CUR&amp;house=B&amp;site=sen">Senate Bill 541</a>, which were aimed at further incentivizing health care providers to ensure the privacy of medical records.  The laws went into effect 01/01/2009, but last week marks the first time that the California Department of Public Health (CDPH) has wielded its expanded power of  fining facilities up to $25,000/per record for allowing unauthorized access to a patient&#8217;s medical record.  CDPH has published the details <a href="http://www.cdph.ca.gov/Pages/NR10-039.aspx" target="_blank">here</a>.</p>
<p>Five separate facilities were fined a total of $675,000.  In total, the confidentiality of 245 medical records were breached.  Although the fines varied (sometimes based on the number of people that accessed the records), in aggregate, that puts the cost/record breached at $2,755. A far cry from the $25,000/record mark (though some instances did receive that level of penalty), but still a substantial cost.  Given the relative low volume (when compared to the numbers frequently seen in credit card breaches), it is hard to anticipate if thousands or tens of thousands of records were breached whether the penalties would remain this high.</p>
<p>While I welcome the increased penalties that might help persuade organizations to make further strides in ensuring the confidentiality of sensitive data, I am worried about the (un)anticipated side effects.  The CDPH has made the sanitized reports available on their website.  One phrase seems to be a fairly common theme, &#8220;the facility reported the breach&#8221;.  I applaud the facilities for reporting these breaches of medical privacy, but will every facility be so forthcoming given the potential for fines.  Would a private for-profit hospital be hesitant to report the breach of 1,000 records knowing that it could  result in $25,000,000 in fines?  I hope so, but something tells me that not every health care provider would reach the conclusion that self-reporting is in their best interest.  As a parting shot, know what the cost/day fine is if it is found that a facility didn&#8217;t report a breach? A hundred bucks&#8230;  Seriously?  Not sure a benjamin is a strong incentive for early reporting&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2010/06/16/maybe-those-dlp-record-breached-stats-arent-so-far-off/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Quick synopsis of Cybersecurity Act of 2009</title>
		<link>http://www.contextsecurity.com/2009/04/03/quick-synopsis-of-cybersecurity-act-of-2009/</link>
		<comments>http://www.contextsecurity.com/2009/04/03/quick-synopsis-of-cybersecurity-act-of-2009/#comments</comments>
		<pubDate>Fri, 03 Apr 2009 18:48:32 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cybersecurity Act of 2009]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[Rockefeller-Snowe Bill]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=96</guid>
		<description><![CDATA[Just wanted to let everyone know that Stephen Northcutt has a quick section by section 1-3 sentence review of the Cybersecurity Act of 2009 legislation (a.k.a Rockefeller-Snowe Bill) that was recently proposed.
http://www.sans.edu/resources/musings/1439.php
I just got my hands on a copy of the bill, and am gonna try to read through it while waiting at the doctor&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Just wanted to let everyone know that Stephen Northcutt has a quick section by section 1-3 sentence review of the Cybersecurity Act of 2009 legislation (a.k.a Rockefeller-Snowe Bill) that was recently proposed.</p>
<p><a title="Stephen Northcutt's review of Cybersecurity Act of 2009" href="http://www.sans.edu/resources/musings/1439.php" target="_blank">http://www.sans.edu/resources/musings/1439.php</a></p>
<p>I just got my hands on a copy of the bill, and am gonna try to read through it while waiting at the doctor&#8217;s office this afternoon&#8230;  Hopefully can cobble some thoughts together this weekend.</p>
<p>Even if it doesn&#8217;t pass or gets completely rewritten, I expect this bill will be important for our field.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/04/03/quick-synopsis-of-cybersecurity-act-of-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>20% Off All SANS OnDemand Classes</title>
		<link>http://www.contextsecurity.com/2009/03/13/20-off-all-sans-ondemand-classes/</link>
		<comments>http://www.contextsecurity.com/2009/03/13/20-off-all-sans-ondemand-classes/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 14:36:49 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[discount]]></category>
		<category><![CDATA[OnDemand]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[seth misenar]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=92</guid>
		<description><![CDATA[Received an email this morning notifying me that SANS OnDemand is running a special for the month of March.  20% off of any SANS OnDemand class.  As an added bonus, you could have me as your OnDemand Virtual Mentor (ODVM)  
Please feel free to leave a comment or email me at seth combined with [...]]]></description>
			<content:encoded><![CDATA[<p>Received an email this morning notifying me that SANS OnDemand is running a special for the month of March.  20% off of any SANS OnDemand class.  As an added bonus, you could have me as your OnDemand Virtual Mentor (ODVM) <img src='http://www.contextsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Please feel free to leave a comment or email me at seth combined with this domain name.</p>
<p>Seth Misenar</p>
<p>Here is the text of the email, which includes the discount code of  STS_OD</p>
<blockquote>
<pre>To help you with your training needs, SANS is offering a Spring Training
Special on ALL courses in our extensive SANS OnDemand online course
library. Register and pay now through Thursday March 26th, 2009 and
receive a 20% discount on ANY SANS OnDemand course! Register at
<a class="moz-txt-link-freetext" href="http://www.sans.org/info/40138">http://www.sans.org/info/40138</a> and use the discount code "STS_OD".

For group or multi-course training needs, save an additional 10% on our
already discounted SANS OnDemand Flex Passes through March 26, 2009.
Check it out at <a class="moz-txt-link-freetext" href="http://www.sans.org/info/40133">http://www.sans.org/info/40133</a>.

Not sure online training is for you?  Try any of our OnDemand course
demos at <a class="moz-txt-link-freetext" href="http://www.sans.org/info/40123">http://www.sans.org/info/40123</a>.

With SANS OnDemand, students receive:
 * 4-months access to our 24/7 online training and assessment system
 * Full set of course books and hands-on CDs
 * Synchronized online courseware and lectures
 * Integrated assessment quizzes throughout the course
 * Access to OnDemand Virtual Mentors
 * Labs &amp; hands-on exercises
 * Progress Reports

In today's economy, travel budgets are very tight and even justifying
money for critical training can be difficult.  Many students have found
SANS OnDemand online training and assessment as a great alternative.  It
allows you to receive the same high quality SANS training while saving
100% of your travel costs.  Furthermore, it allows you to learn without
leaving home or the office. You can train anytime, anywhere!

Check out what a few of our students say about SANS OnDemand...

 "I got more out of this course than I had with any of the other SANS
 classes that I participated in. The quizzes at the end of each
 presentation helped reinforce the information presented.  I couldn't
 fake it.  I had to know it and retain it." - Richard Gancze, OCI

 "It was like having the teacher right there. Having each piece of the
 lecture broken up into little pieces helped me retain the information.
 You guys did an outstanding job creating this program." - Robert
 Urbanowicz, Parkway Insurance Company

 "I have several GIAC certs. My highest exam scores are from when I use
 OnDemand training." - Brad Fulton, SMS Data Products

If you have any questions about SANS OnDemand, write to
<a class="moz-txt-link-abbreviated" href="mailto:ondemand@sans.org">ondemand@sans.org</a> or call us at (301)654-7267.

And remember that every SANS OnDemand purchase earns you points towards
future OnDemand training! <a class="moz-txt-link-freetext" href="http://www.sans.org/info/40128">http://www.sans.org/info/40128</a>

Be sure to tell your friends and colleagues about this great opportunity!

Kind Regards,

Kimie Cabreira
Director
SANS OnDemand</pre>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/03/13/20-off-all-sans-ondemand-classes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS 542 Webcast: Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit</title>
		<link>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/</link>
		<comments>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 21:54:50 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS Teaching]]></category>
		<category><![CDATA[542]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=82</guid>
		<description><![CDATA[Below is information regarding a webcast I will be leading for SANS on 03/18/2009 at 10 AM EST.  Should be fun.
Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit
Featuring: Seth Misenar
In this preview to the newly updated SEC542 Web Application Penetration Testing course being offered in Amsterdam, you will learn how build [...]]]></description>
			<content:encoded><![CDATA[<p>Below is information regarding a webcast I will be leading for SANS on 03/18/2009 at 10 AM EST.  Should be fun.</p>
<h5>Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit</h5>
<h6>Featuring: Seth Misenar</h6>
<p>In this preview to the newly updated SEC542 Web Application Penetration Testing course being offered in Amsterdam, you will learn how build and control your very own zombie battalion/Army of Darkness.  The discussion will start with a whizz|bang overview of the new 6 day version of SEC542, and quickly move to XSS Frameworks and, of course, zombies galore. Whether you are excited or petrified by the prospect of zombies, join Seth Misenar for this hour long webcast.  As Bruce Campbell/Ash of Evil Dead fame would say, &#8220;Groovy&#8221;.</p>
<h5>Speaker Bios:</h5>
<p><strong>Seth Misenar:</strong></p>
<p>When not watching zombie films, Seth Misenar serves as Founder/Lead Consultant for Context Security, which provides information security though leadership, independent research, security training, and security consulting services. His background includes network and web application penetration testing, vulnerability assessment, regulatory compliance efforts, security architecture design, as well as general security consulting. He has previously served as both a physical and network security consultant for Fortune 100 companies as well as the HIPAA and Information Security Officer for a state government agency.</p>
<p>In his former life, Seth received a B.S. in Philosophy from Millsaps College where he was twice selected for a Ford Teaching Fellowship. Also, Seth is no stranger to certifications and thus far has achieved credentials which include, but are not limited to, the following: CISSP, GSEC, GCIA, GCIH, GCWN, GCFA, GHTQ, GWAS, and MCSE credentials. He has previously taught numerous SANS classes including SEC401: Security Essentials, SEC504: Hacker Techniques, and SEC542: Web Application Penetration Testing. In addition to serving SANS in an teaching capacity, Seth also serves as both Virtual Mentor and Technical Director for SANS OnDemand.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS/Ed Skoudis Releases 3 Pen Testing Cheat Sheets</title>
		<link>http://www.contextsecurity.com/2009/02/17/sansed-skoudis-releases-3-pen-testing-cheat-sheets/</link>
		<comments>http://www.contextsecurity.com/2009/02/17/sansed-skoudis-releases-3-pen-testing-cheat-sheets/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 12:31:54 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cheat Sheets]]></category>
		<category><![CDATA[Ed Skoudis]]></category>
		<category><![CDATA[Fgdump]]></category>
		<category><![CDATA[Hping]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Netcat]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=80</guid>
		<description><![CDATA[Thought some of you might be interested&#8230;
Ed Skoudis (of InGuardians and SANS 504/517/560 fame) twitted about the release of 3 new cheat sheets this morning.  The sheets are hosted on SANS website and links to them can be found on InGuardians (http://www.inguardians.com/pubs/articles.html).
Here is the description from InGuardians:
&#8220;Ed Skoudis releases 3 new cheat sheets for the [...]]]></description>
			<content:encoded><![CDATA[<p>Thought some of you might be interested&#8230;</p>
<p>Ed Skoudis (of InGuardians and SANS 504/517/560 fame) twitted about the release of 3 new cheat sheets this morning.  The sheets are hosted on SANS website and links to them can be found on InGuardians (http://www.inguardians.com/pubs/articles.html).</p>
<p>Here is the description from InGuardians:</p>
<blockquote><p>&#8220;Ed Skoudis releases 3 new cheat sheets for the most useful Windows command-line tools, Netcat, and other useful attack tools (Metasploit, Fgdump, and Hping). Get &#8216;em while their hot!&#8221;</p></blockquote>
<p>Links:<br />
Netcat: http://www.sans.org/resources/sec560/netcat_cheat_sheet_v1.pdf</p>
<p>Windows command line: http://www.sans.org/resources/sec560/windows_command_line_sheet_v1.pdf</p>
<p>Metasploit, Fgdump, Hping, etc.: http://www.sans.org/resources/sec560/misc_tools_sheet_v1.pdf</p>
<p>Seth Misenar</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/02/17/sansed-skoudis-releases-3-pen-testing-cheat-sheets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS Log Management Survey</title>
		<link>http://www.contextsecurity.com/2009/01/09/sans-log-management-survey/</link>
		<comments>http://www.contextsecurity.com/2009/01/09/sans-log-management-survey/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 10:59:51 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Summit]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=69</guid>
		<description><![CDATA[SANS posted their log management survey the other day.  If you/your company deals with enterprise log management, then please participate in the survey.  Results will be detailed in April at SANS Log Management and Analysis Summit in DC (http://www.sans.org/logmgtsummit09/).
Here is the link to the survey:
https://www.surveymonkey.com/s.aspx?sm=FCwjvfHzkGml4stgnYQ7rg_3d_3d
]]></description>
			<content:encoded><![CDATA[<p>SANS posted their log management survey the other day.  If you/your company deals with enterprise log management, then please participate in the survey.  Results will be detailed in April at SANS Log Management and Analysis Summit in DC (<a title="SANS Log Managment Summit" href="http://www.sans.org/logmgtsummit09/" target="_blank">http://www.sans.org/logmgtsummit09/</a>).</p>
<p>Here is the link to the survey:</p>
<p><a href="https://www.surveymonkey.com/s.aspx?sm=FCwjvfHzkGml4stgnYQ7rg_3d_3d" target="_blank">https://www.surveymonkey.com/s.aspx?sm=FCwjvfHzkGml4stgnYQ7rg_3d_3d</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/01/09/sans-log-management-survey/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>CeWL for Pen Testers</title>
		<link>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/</link>
		<comments>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 01:50:07 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Ed Skoudis]]></category>
		<category><![CDATA[pauldotcom]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Robin Wood]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=63</guid>
		<description><![CDATA[Shortly after flipping through Ed&#8217;s slide deck for Secrets of America&#8217;s Top Pen Testers yesterday, I noticed a fortuitous tool annoucement come across the SANS GIAC Alumni mailing list.  Robin Wood emailed to announce the release of a tool called CeWL: Custom Wordlist Generator (which is of course pronounced &#8216;cool&#8217;).
http://www.digininja.org/cewl.php
CeWL &#8220;spiders a given url to [...]]]></description>
			<content:encoded><![CDATA[<p>Shortly after flipping through Ed&#8217;s slide deck for <em>Secrets of America&#8217;s Top Pen Testers</em> yesterday, I noticed a fortuitous tool annoucement come across the SANS GIAC Alumni mailing list.  Robin Wood emailed to announce the release of a tool called CeWL: Custom Wordlist Generator (which is of course pronounced &#8216;cool&#8217;).</p>
<p>http://www.digininja.org/cewl.php</p>
<blockquote><p>CeWL &#8220;spiders a given url to a specified depth, optionally following external links, and returns a list of words which can then be used for password crackers such as <a href="http://www.openwall.com/john/">John the Ripper</a>&#8221; (from the website).</p></blockquote>
<p>Very nice. This tool dovetails nicely with Ed&#8217;s first tip from <em>SATPT</em>, &#8220;Build Password Guessing and Cracking Dictionaries&#8221;.  In fact, it turns out that the tool was based on a PaulDotCom discussion, <a href="http://pauldotcom.com/2008/11/creating-custom-wordlists-for.html" target="_blank">http://pauldotcom.com/2008/11/creating-custom-wordlists-for.html</a>, which was in turn based upon content provided in Ed&#8217;s SEC560: Network Penetration Testing, which I will be teaching in Atlanta in February, <a href="https://www.sans.org/atlanta09_cs/description.php?tid=1717" target="_blank">https://www.sans.org/atlanta09_cs/description.php?tid=1717</a>.</p>
<p>Wshew&#8230;did you follow all that.  Regardless of its origins, CeWL definitely looks like something I will be adding to my tool arsenal.  Check it out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Sponsored&#8230;Malware</title>
		<link>http://www.contextsecurity.com/2008/12/16/google-sponsoredmalware/</link>
		<comments>http://www.contextsecurity.com/2008/12/16/google-sponsoredmalware/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 20:22:54 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=55</guid>
		<description><![CDATA[The folks at Websense Security Labs have found some malware that is leveraging users&#8217; trust in Google to undermine them.  Specifically, Google&#8217;s &#8220;Sponsored Links&#8221;, where folks pay Google for advertising there link at the top for specific search terms.  In Google We Trust&#8230;?
A thorough walkthrough can be found at the link below:
http://securitylabs.websense.com/content/Blogs/3264.aspx
]]></description>
			<content:encoded><![CDATA[<p>The folks at Websense Security Labs have found some malware that is leveraging users&#8217; trust in Google to undermine them.  Specifically, Google&#8217;s &#8220;Sponsored Links&#8221;, where folks pay Google for advertising there link at the top for specific search terms.  In Google We Trust&#8230;?</p>
<p>A thorough walkthrough can be found at the link below:</p>
<p><a href="http://securitylabs.websense.com/content/Blogs/3264.aspx">http://securitylabs.websense.com/content/Blogs/3264.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2008/12/16/google-sponsoredmalware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS OnDemand Newsletter Volume 1, Number 1</title>
		<link>http://www.contextsecurity.com/2008/12/15/sans-ondemand-newsletter-volume-1-number-1/</link>
		<comments>http://www.contextsecurity.com/2008/12/15/sans-ondemand-newsletter-volume-1-number-1/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 03:43:24 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[discount]]></category>
		<category><![CDATA[newsletter]]></category>
		<category><![CDATA[OnDemand]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=23</guid>
		<description><![CDATA[In my role as Technical Director for SANS OnDemand, I will now be providing a monthly &#8220;article&#8221; (or at least some security oriented content) to the new SANS OnDemand Newsletters&#8230;  The first Newsletter is below:
************************************************************************
SECURITY TIMES SPECIAL
As a thank you for receiving our SANS OnDemand Security Times
Newsletter, you may take an additional 5% off our [...]]]></description>
			<content:encoded><![CDATA[<p>In my role as Technical Director for SANS OnDemand, I will now be providing a monthly &#8220;article&#8221; (or at least some security oriented content) to the new SANS OnDemand Newsletters&#8230;  The first Newsletter is below:</p>
<p>************************************************************************<br />
SECURITY TIMES SPECIAL</p>
<p>As a thank you for receiving our SANS OnDemand Security Times<br />
Newsletter, you <span id="OBJ_PREFIX_DWT1860" class="Object"><span id="OBJ_PREFIX_DWT1861" class="Object">may</span></span> take an additional 5% off our listed current<br />
specials through December 26.</p>
<p>For single courses, see <span id="OBJ_PREFIX_DWT1862" class="Object"><span id="OBJ_PREFIX_DWT1863" class="Object"><a href="http://www.sans.org/info/35939" target="_blank">http://www.sans.org/info/35939</a></span></span> for our current<br />
offer. Use discount code &#8220;T1_add5&#8243; for a total of 30% off any OnDemand<br />
course.</p>
<p>For groups or multiple courses, take an additional 5% off our lowest<br />
listed pricing at <span id="OBJ_PREFIX_DWT1864" class="Object"><span id="OBJ_PREFIX_DWT1865" class="Object"><a href="http://www.sans.org/info/35944" target="_blank">http://www.sans.org/info/35944</a></span></span>.</p>
<p>Check out our Free OnDemand Demos at <span id="OBJ_PREFIX_DWT1866" class="Object"><span id="OBJ_PREFIX_DWT1867" class="Object"><a href="http://www.sans.org/info/35949" target="_blank">http://www.sans.org/info/35949</a></span></span><br />
************************************************************************<br />
WHAT&#8217;S UPCOMING?</p>
<p>For courses currently being developed in OnDemand, take advantage of our<br />
30% Development Discount.  For a full list of upcoming courses, go to<br />
<span id="OBJ_PREFIX_DWT1868" class="Object"><a href="http://www.sans.org/info/35954" target="_blank">http://www.sans.org/info/35954</a></span><br />
************************************************************************<br />
EARN REWARDS POINTS</p>
<p>Receive one OnDemand Reward Point for every dollar that you spend for<br />
SANS OnDemand training, including the OnDemand Bundle.  To begin<br />
receiving reward points, visit <span id="OBJ_PREFIX_DWT1869" class="Object"><span id="OBJ_PREFIX_DWT1870" class="Object"><a href="http://www.sans.org/info/35959" target="_blank">http://www.sans.org/info/35959</a></span></span><br />
************************************************************************<br />
SECURITY TIP</p>
<p>Whether you are a small Mom &amp; Pop shop or a multinational corporation,<br />
your employees are almost certainly leveraging sites with user generated<br />
content.  User generated content sites <span id="OBJ_PREFIX_DWT1871" class="Object"><span id="OBJ_PREFIX_DWT1872" class="Object">(e.g.</span></span> Myspace, Youtube, Facebook,<br />
Craigslist, Blogger, and Flickr) are routinely in the top 20 most<br />
visited websites.</p>
<p>From a numbers perspective, it goes without saying that your<br />
employees/colleagues/superiors, and likely you, are users of these<br />
popular sites.  Although the most obvious risk posed by employee usage<br />
of these sites is productivity loss [1], perhaps the more serious risk<br />
is posed by the break-neck speed with which these sites are allowing<br />
active user generated content and applications to flourish [2][3].<br />
Therein lies part of the appeal, but so too, some of the risks. In order<br />
for these sites to be useful, users configure their browsers to allow<br />
this content to run virtually unfettered.  However, the risk posed by<br />
active content isn&#8217;t the point of this article either <span id="OBJ_PREFIX_DWT1873" class="Object"><span id="OBJ_PREFIX_DWT1874" class="Object">[4]&#8230;</span></span></p>
<p>A somewhat less discussed &#8220;feature&#8221; of sites containing user generated<br />
content is the significant information disclosure posed by users from<br />
your organization.  Imagine, if you will, that you were being targeted<br />
by an attacker.  Of course, _you_ aren&#8217;t being targeted, but just bear<br />
with <span id="OBJ_PREFIX_DWT1875" class="Object"><span id="OBJ_PREFIX_DWT1876" class="Object">me&#8230;</span></span> Perhaps you have really done a bang up job hardening your<br />
perimeter, patching systems, <span id="OBJ_PREFIX_DWT1877" class="Object"><span id="OBJ_PREFIX_DWT1878" class="Object">etc.,</span></span> such that you feel relatively secure<br />
in your overall security program and architecture.  If an attacker could<br />
find a trusted insider that was willing to disclose details regarding<br />
the products, programming languages, patch levels, <span id="OBJ_PREFIX_DWT1879" class="Object"><span id="OBJ_PREFIX_DWT1880" class="Object">etc.,</span></span> in use at your<br />
organization, could it subvert some of those feelings of security?  In<br />
effect, social networking sites are a veritable treasure trove for<br />
attackers wishing to gain this type of intelligence.  What&#8217;s more,<br />
sometimes they are able to gain this information without engaging in<br />
even the most rudimentary of social engineering attacks.  For instance,<br />
users with profiles on LinkedIn frequently list their resume, including<br />
both specialties and employers, for the world to see.  This and other<br />
information is like gold to an attacker. This type of information,<br />
coupled with attackers armed with information mining tools like Maltego<br />
<span id="OBJ_PREFIX_DWT1881" class="Object">(i.e.,</span> Rapleaf and Spock transforms) can really lower the bar for a<br />
successful targeted attack [5].</p>
<p>Now that the little thought experiment is over, let&#8217;s think about the<br />
primary assumption &#8211; you are being targeted by an attacker.  Some of you<br />
fully accept this as a given, but most of you likely dismiss this<br />
without much thought (we are too small, no one has heard of us, why<br />
would anyone come after us).  Well, consider that restaurants in West<br />
Monroe, LA (pop. 12,951)[6] were part of a group of restaurants in<br />
Mississippi and Louisiana targeted by a ring of thieves harvesting<br />
credit card numbers [7].  If something as innocuous as a family owned<br />
diner can be targeted for an attack, then certainly any organization can<br />
become a likely target.</p>
<p>The risks associated with websites, in general, and social networking<br />
sites, in particular, are discussed in several SANS courses available<br />
via OnDemand (AUD507, MGT512, SEC401 and SEC502).  The social<br />
engineering and reconnaissance exposure made possible by these sites is<br />
explored in SEC560.</p>
<p>For more info on these courses, visit:<br />
AUD507: Auditing Networks, Perimeters &amp; Systems<br />
<span id="OBJ_PREFIX_DWT1882" class="Object">(<a href="http://www.sans.org/link.php?id=1032&amp;mid=6">http://www.sans.org/l</a></span><span id="OBJ_PREFIX_DWT1883" class="Object"><span id="OBJ_PREFIX_DWT1884" class="Object"><a href="http://www.sans.org/link.php?id=1032&amp;mid=6">ink.php?id=1032&amp;mid=6</a>)</span></span><br />
MGT512: SANS Security Leadership Essentials For Managers<br />
<span id="OBJ_PREFIX_DWT1885" class="Object">(<a href="http://www.sans.org/link.php?id=1032&amp;mid=62">http://www.sans.org/l</a></span><span id="OBJ_PREFIX_DWT1886" class="Object"><span id="OBJ_PREFIX_DWT1887" class="Object"><a href="http://www.sans.org/link.php?id=1032&amp;mid=62">ink.php?id=1032&amp;mid=62</a>)</span></span><br />
SEC401: SANS Security Essentials<br />
<span id="OBJ_PREFIX_DWT1888" class="Object">(<a href="http://www.sans.org/link.php?id=1032&amp;mid=61">http://www.sans.org/l</a></span><span id="OBJ_PREFIX_DWT1889" class="Object"><span id="OBJ_PREFIX_DWT1890" class="Object"><a href="http://www.sans.org/link.php?id=1032&amp;mid=61">ink.php?id=1032&amp;mid=61</a>)</span></span><br />
SEC502: Perimeter Protection In-Depth<br />
<span id="OBJ_PREFIX_DWT1891" class="Object">(<a href="http://www.sans.org/link.php?id=1032&amp;mid=17">http://www.sans.org/l</a></span><span id="OBJ_PREFIX_DWT1892" class="Object"><span id="OBJ_PREFIX_DWT1893" class="Object"><a href="http://www.sans.org/link.php?id=1032&amp;mid=17">ink.php?id=1032&amp;mid=17</a>)</span></span><br />
SEC560: Network Penetration Testing and Ethical Hacking<br />
<span id="OBJ_PREFIX_DWT1894" class="Object">(<a href="http://www.sans.org/link.php?id=1032&amp;mid=937">http://www.sans.org/l</a></span><span id="OBJ_PREFIX_DWT1895" class="Object"><span id="OBJ_PREFIX_DWT1896" class="Object"><a href="http://www.sans.org/link.php?id=1032&amp;mid=937">ink.php?id=1032&amp;mid=937</a>)</span></span></p>
<p>Seth Misenar<br />
SANS OnDemand Virtual Mentor</p>
<p>1: &#8220;Facebook &#8216;costs businesses dear&#8217; &#8221; -<br />
<span id="OBJ_PREFIX_DWT1897" class="Object"><a href="http://news.bbc.co.uk/2/hi/technology/6989100.stm" target="_blank">http://news.bbc.co.uk/2/hi/technology/6989100.stm</a></span><br />
2:  More than 33,000 Facebook applications -<br />
<a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/23/BU7C11TAES.DTL"><span id="OBJ_PREFIX_DWT1898" class="Object">http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/23/BU7C11TAES.D</span>TL</a><br />
3:  More than 400,000 registered Facebook developers -<br />
<span id="OBJ_PREFIX_DWT1899" class="Object"><a href="http://www.facebook.com/press/releases.php?p=48242" target="_blank">http://www.facebook.com/press/releases.php?p=48242</a></span><br />
4: &#8220;Elaborate Facebook Worm Spreading&#8221; -<br />
<a href="http://www.techcrunch.com/2008/08/07/elaborate--facebook-worm-virus-spreading/"><span id="OBJ_PREFIX_DWT1900" class="Object">http://www.techcrunch.com/2008/08/07/elaborate&#8211;facebook-worm-virus-spre</span>ading/</a><br />
5: &#8220;Maltego Part I &#8211; Intro and Personal Recon&#8221; -<br />
<span id="OBJ_PREFIX_DWT1901" class="Object"><a href="http://www.ethicalhacker.net/content/view/202/24/" target="_blank">http://www.ethicalhacker.net/content/view/202/24/</a></span><br />
6: <span id="OBJ_PREFIX_DWT1902" class="Object"><span id="OBJ_PREFIX_DWT1903" class="Object">U.S.</span></span> Census Bureau, 2007 Population Estimates -<br />
<span id="OBJ_PREFIX_DWT1904" class="Object"><a href="http://factfinder.census.gov/" target="_blank">http://factfinder.census.gov</a></span><br />
7: &#8220;Attacks Continue on Retail Stores, Restaurants&#8221; -<br />
<a href="************************************************************************ SECURITY TIMES SPECIAL  As a thank you for receiving our SANS OnDemand Security Times Newsletter, you may take an additional 5% off our listed current specials through December 26.  For single courses, see http://www.sans.org/info/35939 for our current offer. Use discount code &quot;T1_add5&quot; for a total of 30% off any OnDemand course.  For groups or multiple courses, take an additional 5% off our lowest listed pricing at http://www.sans.org/info/35944.  Check out our Free OnDemand Demos at http://www.sans.org/info/35949 ************************************************************************ WHAT'S UPCOMING?  For courses currently being developed in OnDemand, take advantage of our 30% Development Discount.  For a full list of upcoming courses, go to http://www.sans.org/info/35954 ************************************************************************ EARN REWARDS POINTS  Receive one OnDemand Reward Point for every dollar that you spend for SANS OnDemand training, including the OnDemand Bundle.  To begin receiving reward points, visit http://www.sans.org/info/35959 ************************************************************************ SECURITY TIP  Whether you are a small Mom &amp; Pop shop or a multinational corporation, your employees are almost certainly leveraging sites with user generated content.  User generated content sites (e.g. Myspace, Youtube, Facebook, Craigslist, Blogger, and Flickr) are routinely in the top 20 most visited websites.  From a numbers perspective, it goes without saying that your employees/colleagues/superiors, and likely you, are users of these popular sites.  Although the most obvious risk posed by employee usage of these sites is productivity loss [1], perhaps the more serious risk is posed by the break-neck speed with which these sites are allowing active user generated content and applications to flourish [2][3]. Therein lies part of the appeal, but so too, some of the risks. In order for these sites to be useful, users configure their browsers to allow this content to run virtually unfettered.  However, the risk posed by active content isn't the point of this article either [4]...  A somewhat less discussed &quot;feature&quot; of sites containing user generated content is the significant information disclosure posed by users from your organization.  Imagine, if you will, that you were being targeted by an attacker.  Of course, _you_ aren't being targeted, but just bear with me...  Perhaps you have really done a bang up job hardening your perimeter, patching systems, etc., such that you feel relatively secure in your overall security program and architecture.  If an attacker could find a trusted insider that was willing to disclose details regarding the products, programming languages, patch levels, etc., in use at your organization, could it subvert some of those feelings of security?  In effect, social networking sites are a veritable treasure trove for attackers wishing to gain this type of intelligence.  What's more, sometimes they are able to gain this information without engaging in even the most rudimentary of social engineering attacks.  For instance, users with profiles on LinkedIn frequently list their resume, including both specialties and employers, for the world to see.  This and other information is like gold to an attacker. This type of information, coupled with attackers armed with information mining tools like Maltego (i.e., Rapleaf and Spock transforms) can really lower the bar for a successful targeted attack [5].  Now that the little thought experiment is over, let's think about the primary assumption - you are being targeted by an attacker.  Some of you fully accept this as a given, but most of you likely dismiss this without much thought (we are too small, no one has heard of us, why would anyone come after us).  Well, consider that restaurants in West Monroe, LA (pop. 12,951)[6] were part of a group of restaurants in Mississippi and Louisiana targeted by a ring of thieves harvesting credit card numbers [7].  I"><span id="OBJ_PREFIX_DWT1905" class="Object">http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleI</span>D=211201193</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2008/12/15/sans-ondemand-newsletter-volume-1-number-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Layoffs==Data Leakage</title>
		<link>http://www.contextsecurity.com/2008/12/06/layoffsdata-leakage/</link>
		<comments>http://www.contextsecurity.com/2008/12/06/layoffsdata-leakage/#comments</comments>
		<pubDate>Sat, 06 Dec 2008 21:43:43 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[insider]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=14</guid>
		<description><![CDATA[Recently read some interesting results of a survey/study carried out by Cyber-Ark&#8230;  The associated press release can be found here: http://www.cyber-ark.com/news-events/pr_20081201.asp.
Though the headline is _somewhat_ surprising, &#8220;&#8230;Nervous workers offer to double their hours and reduce their salaries to secure employment&#8221;, it is largely innocuous when compared to data that comes to light in the [...]]]></description>
			<content:encoded><![CDATA[<p>Recently read some interesting results of a survey/study carried out by Cyber-Ark&#8230;  The associated press release can be found here: <a title="http://www.cyber-ark.com/news-events/pr_20081201.asp" href="http://http://www.cyber-ark.com/news-events/pr_20081201.asp" target="_blank">http://www.cyber-ark.com/news-events/pr_20081201.asp.</a></p>
<p>Though the headline is _somewhat_ surprising, &#8220;&#8230;Nervous workers offer to double their hours and reduce their salaries to secure employment&#8221;, it is largely innocuous when compared to data that comes to light in the second paragraph.</p>
<p>&#8220;When confronted with the prospect of being fired tomorrow ethics go out the door (so to speak), 71% surveyed declared they would definitely <strong>take company data </strong>with them to their next employer.&#8221; (emphasis mine)</p>
<p>Ouch.  71% of seemingly loyal employees would walk away with data, including: &#8220;customer and contact databases, with plans and proposals, product information, and access / password codes&#8221;</p>
<p>Of course almost every company I have every worked with has had at least some measure of the &#8220;that would never happen to me&#8221; syndrome.  Some companies would sit back smugly and think that their termination procedures, exit interviews, and general &#8220;tight ship&#8221; would prevent this potentiality.  Then we read again&#8230;</p>
<p>&#8220;&#8230;more than half have <strong>already downloaded competitive corporate data</strong> and plan to use the information as a negotiating tool to secure their next post&#8221; (emphasis mine)</p>
<p>Rather a scary proposition if you ask me.  We should of course keep in mind that these statistics come from a vendor who has a widget to help with the problem&#8230;  Regardless of the numbers, however, in the current economic climate employees have reason to be a bit scared.  When scared, some will have a tendency to act a bit more impetuously than than their reason would otherwise dictate.</p>
<p>I don&#8217;t intend for this to be yet another article bemoaning the virtue of DLP solutions.  Honestly, these employees are insiders with access, who are motivated by fear of losing their ability to provide for themselves and/or their families.  I think most of the technical controls attempting to prevent this leakage would be left wanting in the face of a thusly motivated insider.</p>
<p>I honestly think awareness training/reminders are likely the only thing that could be very effective in this situation&#8230;  Sadly, the best solution is likely to have a unabashedly solvent company in the first place&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2008/12/06/layoffsdata-leakage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
