<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Steve on Security</title>
	<atom:link href="http://security.goldsby.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://security.goldsby.com</link>
	<description>Information security developments. A high signal, low noise blog.</description>
	<lastBuildDate>Wed, 10 Mar 2010 13:23:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='security.goldsby.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/0cc231b5ea679bf32c482abde62578a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Steve on Security</title>
		<link>http://security.goldsby.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://security.goldsby.com/osd.xml" title="Steve on Security" />
	<atom:link rel='hub' href='http://security.goldsby.com/?pushpress=hub'/>
		<item>
		<title>List of Web application scanners</title>
		<link>http://security.goldsby.com/2010/03/10/list-of-web-application-scanners/</link>
		<comments>http://security.goldsby.com/2010/03/10/list-of-web-application-scanners/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 13:23:31 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=174</guid>
		<description><![CDATA[Well rounded list of commercial and free scanners over at http://projects.webappsec.org/Web-Application-Security-Scanner-List﻿
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=174&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Well rounded list of commercial and free scanners over at <a href="http://projects.webappsec.org/Web-Application-Security-Scanner-List">http://projects.webappsec.org/Web-Application-Security-Scanner-List</a>﻿</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/174/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/174/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/174/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=174&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/03/10/list-of-web-application-scanners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Do a full background check on yourself &#8211; for FREE.</title>
		<link>http://security.goldsby.com/2010/03/04/do-a-full-background-check-on-yourself-for-free/</link>
		<comments>http://security.goldsby.com/2010/03/04/do-a-full-background-check-on-yourself-for-free/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 16:34:22 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=171</guid>
		<description><![CDATA[Check out the consolidated list of sources that &#8220;the man&#8221; uses to gather your personal information.  Get your reports, go over them with a fine toothed comb, and get errors corrected.  Oh, and be awed by how much of your life is available to anyone willing to pay to get it.  Very Scary.  http://consumerist.com/2010/02/get-all-your-reports.html
  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=171&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Check out the consolidated list of sources that &#8220;the man&#8221; uses to gather your personal information.  Get your reports, go over them with a fine toothed comb, and get errors corrected.  Oh, and be awed by how much of your life is available to anyone willing to pay to get it.  Very Scary.  <a href="http://consumerist.com/2010/02/get-all-your-reports.html">http://consumerist.com/2010/02/get-all-your-reports.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/171/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/171/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/171/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=171&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/03/04/do-a-full-background-check-on-yourself-for-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Google &#8211; China &#8211; Aurora attacks dissected.</title>
		<link>http://security.goldsby.com/2010/03/02/google-china-aurora-attacks-dissected/</link>
		<comments>http://security.goldsby.com/2010/03/02/google-china-aurora-attacks-dissected/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 13:51:26 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=168</guid>
		<description><![CDATA[http://www.theregister.co.uk/2010/03/01/aurora_resistence_futile/
 Full paper here .  iSecPartner&#8217;s recommendations are good.  However, while comprehensive and technically accurate, I think it would be beneficial to have an accompanying set of &#8220;triage&#8221; recommendations (Use GPOs to disable LANMAN hashes; perform egress filtering and alerting; never EVER EVER login with admin credentials &#8211; use sudo or runas; migrate to token [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=168&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.theregister.co.uk/2010/03/01/aurora_resistence_futile/">http://www.theregister.co.uk/2010/03/01/aurora_resistence_futile/</a></p>
<p><a href="http://www.theregister.co.uk/2010/03/01/aurora_resistence_futile/"></a> Full paper <a title="iSecPaper" href="https://www.isecpartners.com/files/iSEC_Aurora_Response_Recommendations.pdf" target="_blank">here </a>.  iSecPartner&#8217;s recommendations are good.  However, while comprehensive and technically accurate, I think it would be beneficial to have an accompanying set of &#8220;triage&#8221; recommendations (Use GPOs to disable LANMAN hashes; perform egress filtering and alerting; never EVER EVER login with admin credentials &#8211; use sudo or runas; migrate to token based authentication).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/168/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=168&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/03/02/google-china-aurora-attacks-dissected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>HITECH data breach analysis</title>
		<link>http://security.goldsby.com/2010/03/02/hitech-data-breach-analysis/</link>
		<comments>http://security.goldsby.com/2010/03/02/hitech-data-breach-analysis/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 13:38:18 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=165</guid>
		<description><![CDATA[Chris Merritt over at Lumension did a quick analysis of the HHS breaches of healthcare data for ~4Q09.  It pretty well repeats what most of us in the security industry have been harping on for years regarding healthcare information:

Theft (not accidental loss) is the biggest vector both in terms of # of incidents and total [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=165&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Chris Merritt over at Lumension did a quick analysis of the HHS breaches of healthcare data for ~<a title="HHS Data" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">4Q09</a>.  It pretty well repeats what most of us in the security industry have been harping on for years regarding healthcare information:</p>
<ol>
<li>Theft (not accidental loss) is the biggest vector both in terms of # of incidents and total records compromised</li>
<li>The endpoint, NOT the datacenter, is your weak link</li>
</ol>
<p>The picture is a bit different with respect to financial information and PII (application and endpoint security), but time after time we&#8217;ve shown that if I can pop your desktops, I can use them to pop your datacenter.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/165/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=165&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/03/02/hitech-data-breach-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>VMWare Guest Stealer</title>
		<link>http://security.goldsby.com/2010/02/19/vmware-guest-stealer/</link>
		<comments>http://security.goldsby.com/2010/02/19/vmware-guest-stealer/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:01:41 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=162</guid>
		<description><![CDATA[http://www.fyrmassociates.com/tools.html



GuestStealer v1.1 [ Download ]
GuestStealer allows for the stealing of VMware guests from vulnerable hosts based on the Directory Traversal Vulnerability detailed in CVE-2009-3373 and VMSA-2009-0015. GuestStealer was released at ShmooCon 2010 during Tony Flick&#8217;s &#8216;Stealing Guests&#8230;The VMware Way&#8216; presentation.
Requirements

Perl interpreter
LWP::Simple perl module
XML::Simple perl module
Data::Dumper perl module
Crypt::SSLeay perl module

Instructions

perl gueststealer-v1.1.pl -h &#60;Host&#62; -p &#60;Web Access UI Port&#62; -s &#60;SSL [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=162&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.fyrmassociates.com/tools.html">http://www.fyrmassociates.com/tools.html</a></p>
<table border="0" cellspacing="0" cellpadding="0" width="980">
<tbody>
<tr>
<td width="870" align="left" valign="top"><img src="http://www.fyrmassociates.com/images/blue_arrow.png" alt="" width="8" height="11" />GuestStealer v1.1 [ <a href="http://www.fyrmassociates.com/tools/gueststealer-v1.1.pl">Download</a> ]</p>
<blockquote><p>GuestStealer allows for the stealing of VMware guests from vulnerable hosts based on the Directory Traversal Vulnerability detailed in <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3733" target="_blank">CVE-2009-3373</a> and <a href="http://www.vmware.com/security/advisories/VMSA-2009-0015.html" target="_blank">VMSA-2009-0015</a>. GuestStealer was released at ShmooCon 2010 during Tony Flick&#8217;s &#8216;<a href="http://www.shmoocon.org/presentations-all.html#stealingguests" target="_blank">Stealing Guests&#8230;The VMware Way</a>&#8216; presentation.</p></blockquote>
<p>Requirements</p>
<ol>
<li>Perl interpreter</li>
<li>LWP::Simple perl module</li>
<li>XML::Simple perl module</li>
<li>Data::Dumper perl module</li>
<li>Crypt::SSLeay perl module</li>
</ol>
<p>Instructions</p>
<ol>
<li>perl gueststealer-v1.1.pl -h &lt;Host&gt; -p &lt;Web Access UI Port&gt; -s &lt;SSL Web Access UI&gt; -t &lt;Server Type&gt; -o &lt;Output Directory&gt;</li>
<li>-h = The target host (IP Address or Host Name)<br />
-p = Port for the Web Access UI (Defaults: ESX/ESXi = 80/443, Server = 8222/8333)<br />
-s = Is the Web Access UI utilizing SSL (yes/no)<br />
-t = Target type (server/esx/esxi)<br />
-o = Output directory</li>
<li>Example Usage:<br />
perl gueststealer-v1.1.pl -h 192.168.1.2 -p 8333 -s yes -t server -o /tmp</li>
</ol>
<p><img src="http://www.fyrmassociates.com/images/blue_arrow.png" alt="" width="8" height="11" />NessusPBE [ <a href="http://www.fyrmassociates.com/tools/NessusPBE.pl">Download</a> ]</p>
<blockquote><p>NessusPBE simplifies the process of understanding Nessus output by transforming the data into an actionable format. Specifically, NessusPBE reads in .nbe formatted Nessus reports and creates spreadsheets that can be opened by most office suites, including Microsoft Excel and OpenOffice Spreadsheet. NessusPBE creates three spreadsheets: a list of services identified by Nessus, a list of open ports whose service was not identified by Nessus, and a list of Nessus’ findings.</p></blockquote>
<p>Requirements</p>
<ol>
<li>Perl interpreter</li>
<li>Nessus output in the .nbe format</li>
</ol>
<p>Instructions</p>
<ol>
<li>From a command line: ./NessusPBE.pl -i &lt;input .nbe&gt; -o &lt;output prefix&gt;<br />
<em>Example:</em> ./NessusPBE.pl –i AcmeBank.nbe –o AcmeBankNessus</li>
<li>Open the resulting output files: &lt;output-prefix&gt;-OpenPorts.csv &lt;output-prefix&gt;-UnknownPorts.csv &lt;output-prefix&gt;-VulnList.tsv<br />
<em>Example:</em> AcmeBank-OpenPorts.csv AcmeBank-UnknownPorts.csv AcmeBank-VulnList.tsv</li>
</ol>
</td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/162/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=162&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/02/19/vmware-guest-stealer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://www.fyrmassociates.com/images/blue_arrow.png" medium="image" />

		<media:content url="http://www.fyrmassociates.com/images/blue_arrow.png" medium="image" />
	</item>
		<item>
		<title>New google adwords Phish</title>
		<link>http://security.goldsby.com/2010/01/04/new-google-adwords-phish/</link>
		<comments>http://security.goldsby.com/2010/01/04/new-google-adwords-phish/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 14:11:51 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=157</guid>
		<description><![CDATA[Just saw a new google adwords phish this morning.  Nothing earth shattering, but well done in the google minimalist style:
If you view the mail headers, you&#8217;ll see that the email was bounced off (yet another) open .edu relay, copeland.udel.edu.  Update your blacklists &#8211; in this case, MXLogic didn&#8217;t catch it.
      [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=157&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Just saw a new google adwords phish this morning.  Nothing earth shattering, but well done in the google minimalist style:</p>
<div id="attachment_158" class="wp-caption aligncenter" style="width: 507px"><a href="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish.jpg"><img class="size-full wp-image-158" title="google_adword_phish" src="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish.jpg?w=497&#038;h=206" alt="Screencap of the phish email" width="497" height="206" /></a><p class="wp-caption-text">Screencap of the phish email</p></div>
<p>If you view the mail headers, you&#8217;ll see that the email was bounced off (yet another) open .edu relay, copeland.udel.edu.  Update your blacklists &#8211; in this case, MXLogic didn&#8217;t catch it.</p>
<div id="attachment_159" class="wp-caption aligncenter" style="width: 507px"><a href="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish_headers.jpg"><img class="size-full wp-image-159" title="google_adword_phish_headers" src="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish_headers.jpg?w=497&#038;h=335" alt="" width="497" height="335" /></a><p class="wp-caption-text">eMail headers</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=157&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2010/01/04/new-google-adwords-phish/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish.jpg" medium="image">
			<media:title type="html">google_adword_phish</media:title>
		</media:content>

		<media:content url="http://stevegoldsby.files.wordpress.com/2010/01/google_adword_phish_headers.jpg" medium="image">
			<media:title type="html">google_adword_phish_headers</media:title>
		</media:content>
	</item>
		<item>
		<title>My list of Security RSS feeds</title>
		<link>http://security.goldsby.com/2009/12/30/my-list-of-security-rss-feeds/</link>
		<comments>http://security.goldsby.com/2009/12/30/my-list-of-security-rss-feeds/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 16:26:40 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=154</guid>
		<description><![CDATA[Thought others might like my list of  Security feeds that I scan daily.  Some are very  active, some less so, and some defunct.  I get between 250 and 1200 items a day in this cluster, and can scan through, select, and flag interesting content in about 30 minutes a day using google reader.   Provided [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=154&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Thought others might like my list of  <a href="http://www.google.com/reader/bundle/user/04698079501293705718/bundle/Steve%20Goldsby's%20Security%20Feeds">Security feeds</a> that I scan daily.  Some are very  active, some less so, and some defunct.  I get between 250 and 1200 items a day in this cluster, and can scan through, select, and flag interesting content in about 30 minutes a day using google reader.   Provided as a <a href="http://www.google.com/reader/bundle/user/04698079501293705718/bundle/Steve%20Goldsby's%20Security%20Feeds">shared bundle</a> from within google reader.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/154/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=154&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/12/30/my-list-of-security-rss-feeds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Migrated to my new Kingston 128G SSDNow-V</title>
		<link>http://security.goldsby.com/2009/12/22/migrated-to-my-new-kingston-128g-ssdnow-v/</link>
		<comments>http://security.goldsby.com/2009/12/22/migrated-to-my-new-kingston-128g-ssdnow-v/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 22:20:02 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=145</guid>
		<description><![CDATA[Man, this thing is sweet.  It took a bit of tinkering and resizing to get the migration from my old Maxtor 160G SATA-RAID setup to the new 128G SSDNow, but it was well worth it, and I added a lot to my toolkit along the way:

built a USB MultiPass (I call it my U3-SwissBlade) with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=145&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Man, this thing is sweet.  It took a bit of tinkering and resizing to get the migration from my old Maxtor 160G SATA-RAID setup to the new 128G SSDNow, but it was well worth it, and I added a lot to my toolkit along the way:</p>
<ul>
<li>built a <a href="http://revision3.com/hak5/usbmultipass">USB MultiPass</a> (I call it my U3-SwissBlade) with gParted, CloneZilla and several other nifty tools</li>
<li>broke the RAID on my Maxtors</li>
<li>Resized my partitions to fit on the 128G SSDNow using gParted</li>
<li>Installed my SSDNow as my primary SATA drive</li>
<li>used CloneZilla to do a disk-to-disk partition copy from the Maxtor to the SSDNow (this took a few tries since I had failed to move all partitions to the right after resizing and free up slack space &#8212; you really CAN&#8217;T get 160G onto a 128G drive!)</li>
<li>Went through a few boot sequences until I discovered that my fstab was referencing root by UUID and thus GRUBbooting from the SSDNow and immediately mounting the old Maxtor for the rest of the OS Load.  Grrrrrgggggggggggh.  (Note, get confortable with the <a href="http://coreythompson.com/2008/01/etcfstab-help-for-distro-hoppers/">vol_id</a> utility so you can find the unique UUIDs for all your drives and update your fstab to use UUIDs instead of device sequence numbers like sda, sdb, etc).</li>
<li>uuidgen<br />
tune2fs /dev/sdb1 -U &lt;numbergeneratedbyuuidgen&gt;<br />
verify with vol_id /dev/sdb1<br />
vol_id /dev/hdaX</li>
</ul>
<p>Performance is excellent.  My VMs load near instantly and no more disk thrashing.</p>
<p>I put one of the SSDNows in my old Dell D630 and it has made significant improvements in performance as well.  I may get another year or two out of this laptop after all.  Well worth the $230 I spent.</p>
<p>I&#8217;m interested in getting a SSDNow V+ to see if the write performance justifies the increased cost, but not until I do some benchmarking of my system to see if I am write-bound or not.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/145/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/145/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/145/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=145&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/12/22/migrated-to-my-new-kingston-128g-ssdnow-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Fixed: Unetbootin / Syslinux version issues</title>
		<link>http://security.goldsby.com/2009/12/16/fixed-unetbootin-syslinux-version-issues/</link>
		<comments>http://security.goldsby.com/2009/12/16/fixed-unetbootin-syslinux-version-issues/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 15:50:27 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=135</guid>
		<description><![CDATA[Having problems using unetbootin to install certain packages on your USB multipass?  Discovered recently that syslinux version differences between packages (like GParted) and unetbootin can cause nasty errors at boot:
SYSLINUX 3.72 2008-09-25 EBIOS copyright (cc) 1994-2008 H. Peter Anvin
Unknown keyword in configuration file: UI
Could not find kernel image:  linux
boot:
FIX:   Use a current syslinux or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=135&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Having problems using unetbootin to install certain packages on your USB multipass?  Discovered recently that syslinux version differences between packages (like GParted) and unetbootin can cause nasty errors at boot:</p>
<blockquote><p><span style="color:#666699;">SYSLINUX 3.72 2008-09-25 EBIOS copyright (cc) 1994-2008 H. Peter Anvin</span><br />
<span style="color:#666699;">Unknown keyword in configuration file: UI</span><br />
<span style="color:#666699;">Could not find kernel image:  linux</span><br />
<span style="color:#666699;">boot:</span></p></blockquote>
<p>FIX:   Use a current syslinux or syslinux.exe (version 3.82 at the time of this writing, download <a title="Syslinux Download Repository" href="http://www.kernel.org/pub/linux/utils/boot/syslinux/" target="_blank">here</a>) to re-prep the USB stick:</p>
<p>Where z: is the drive letter of the USB drive.  This will install the newer version of syslinux on the USB drive and resolve those keyword issues.</p>
<blockquote><p>syslinux z:</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/135/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=135&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/12/16/fixed-unetbootin-syslinux-version-issues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Best kitchen-sink pizza</title>
		<link>http://security.goldsby.com/2009/12/14/best-kitchen-sink-pizza/</link>
		<comments>http://security.goldsby.com/2009/12/14/best-kitchen-sink-pizza/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 02:43:45 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=132</guid>
		<description><![CDATA[Tonight I perfected it.  Adjust to suit your tastes (e.g. leave off the hot stuff if you like)
Ingredients:

12&#8243; thin crust
6 oz finely shredded mozarella
5 oz pizza sauce (or tomato sauce)
1 roma tomato, halved and sliced into 1/8&#8243; slices
1/4  red onion, sliced in 1/4&#8243; rings and quartered
1/4 cup pepper rings
1/3 green pepper, diced
2 TBsp Feta cheese
Sliced [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=132&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Tonight I perfected it.  Adjust to suit your tastes (e.g. leave off the hot stuff if you like)</p>
<p>Ingredients:</p>
<ul>
<li>12&#8243; thin crust</li>
<li>6 oz finely shredded mozarella</li>
<li>5 oz pizza sauce (or tomato sauce)</li>
<li>1 roma tomato, halved and sliced into 1/8&#8243; slices</li>
<li>1/4  red onion, sliced in 1/4&#8243; rings and quartered</li>
<li>1/4 cup pepper rings</li>
<li>1/3 green pepper, diced</li>
<li>2 TBsp Feta cheese</li>
<li>Sliced Pepperoni</li>
<li>8 oz Chorizo, cooked, crumbled</li>
<li>8 oz spicy Jimmy Dean sausage, cooked, crumbled</li>
<li>1/2 cup mushrooms, sliced</li>
<li>3 cloves garlic, minced</li>
<li>3 pieces thick cut bacon, crumbled</li>
<li>2 Tbsp  capers</li>
<li>1 jalapeno, seeded, halved and sliced</li>
</ul>
<ol>
<li>Preheat oven to 450</li>
<li>Spread sauce on crust to within 1/2&#8243; of outer edge</li>
<li>Evenly distribute mozarella</li>
<li>Evenly spread all other ingredients (meat first, then veggies, then feta cheese)</li>
<li>Cook in 450 degree oven for 9 minutes</li>
</ol>
<p>Remove pizza.  Let cool for 7 minutes.  Slice.  Serve.  Enjoy.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/132/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=132&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/12/14/best-kitchen-sink-pizza/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>General fix for &#8220;ERROR FOUND IN CUSTOM UI XML&#8221; issues in MSOffice Products</title>
		<link>http://security.goldsby.com/2009/10/29/general-fix-for-error-found-in-custom-ui-xml-issues-in-msoffice-products/</link>
		<comments>http://security.goldsby.com/2009/10/29/general-fix-for-error-found-in-custom-ui-xml-issues-in-msoffice-products/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:29:46 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=119</guid>
		<description><![CDATA[I have seen this error in various software and it&#8217;s terribly annoying.  It most often pops up in outlook every single time you create an email, appointment or other object.  I thought it was originally isolated to the LinkedIn toolbar, but then it started happening with various MapiLab add-ins and other objects.  I have tried [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=119&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I have seen this error in various software and it&#8217;s terribly annoying.  It most often pops up in outlook <em>every single time </em>you create an email, appointment or other object.  I thought it was originally isolated to the LinkedIn toolbar, but then it started happening with various MapiLab add-ins and other objects.  I have tried diagnosing binaries using reflector, analyzing the subject XML, etc. but the fix was ridiculously simple.   I must have wasted at least 10 hours of my life chasing &#8220;errors&#8221; that are nothing more than annoyances and don&#8217;t break any application functionality.  To turn these goofy errors OFF in MSOffice products:&gt;</p>
<ol>
<li>Go into the application&#8217;s Options (i.e. click the Office Button <a href="http://byfiles.storage.msn.com/y1ptds2JPuHqYvikghXC8kRdYkDjRTk7UfWDolrIsHemKIB8yJsjeuCpuFAYn8Y_ocX2qFZrYwBTTk?PARTNER=WRITER"><img src="http://byfiles.storage.msn.com/y1ptds2JPuHqYsQQ7jdkDe9HOb_Ne6l9CkAkaxYCzVULrmnXgP9c6GEpfca7c3DYO9OOy0gc74Foks?PARTNER=WRITER" border="0" alt="image" width="30" height="28" /></a> and select &#8220;Options&#8221;)</li>
<li>Select &#8220;Advanced&#8221; from the navigation pane on the left.</li>
<li>Find the &#8220;Show add-in user interface errors&#8221; checkbox and unselect it.<br />
<a href="http://byfiles.storage.msn.com/y1ptds2JPuHqYsCELVGOJspiK8djnXCv-JuVogSJOOF_bNYanWylSmMBeSiIj9e5l2IdQ6fd1Xk9hc?PARTNER=WRITER"><img src="http://byfiles.storage.msn.com/y1ptds2JPuHqYuDIJuXIEAek1UUX70MLBHBVawbqDJWc_EJJXuj1R9EtGSCN2Vq9nGbmcOVizo9KqE?PARTNER=WRITER" border="0" alt="clip_image001" width="238" height="31" /></a></li>
<li>Click the OK button.</li>
</ol>
<p><strong>Outlook operates a little differently:</strong></p>
<ol>
<li>Start Microsoft Office Outlook.</li>
<li>On the Tools menu, click Options.</li>
<li>In the Options dialog box, click the Other tab, and then click Advanced Options.</li>
<li>In the Advanced Options dialog box, select Show add-in user interface errors, and then click OK.</li>
<li>Click OK to close the Options dialog box.</li>
</ol>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=119&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/10/29/general-fix-for-error-found-in-custom-ui-xml-issues-in-msoffice-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://byfiles.storage.msn.com/y1ptds2JPuHqYsQQ7jdkDe9HOb_Ne6l9CkAkaxYCzVULrmnXgP9c6GEpfca7c3DYO9OOy0gc74Foks?PARTNER=WRITER" medium="image">
			<media:title type="html">image</media:title>
		</media:content>

		<media:content url="http://byfiles.storage.msn.com/y1ptds2JPuHqYuDIJuXIEAek1UUX70MLBHBVawbqDJWc_EJJXuj1R9EtGSCN2Vq9nGbmcOVizo9KqE?PARTNER=WRITER" medium="image">
			<media:title type="html">clip_image001</media:title>
		</media:content>
	</item>
		<item>
		<title>Don&#8217;t hate your customers</title>
		<link>http://security.goldsby.com/2009/10/21/dont-hate-your-customers/</link>
		<comments>http://security.goldsby.com/2009/10/21/dont-hate-your-customers/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 15:37:17 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=117</guid>
		<description><![CDATA[A recent exchange with Delta Airlines went something (actual, EXACTLY) like this:
Welcome!
Note: During your chat session, Delta agents may be able to view your delta.com transactions. Additionally, chat conversations are recorded and monitored by Delta Air Lines.
Please wait while we contact the next available agent&#8230;
You are now speaking with Morris!
Morris: Hi! My name is Morris. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=117&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A recent exchange with Delta Airlines went something (actual, EXACTLY) like this:</p>
<p>Welcome!<br />
Note: During your chat session, Delta agents may be able to view your delta.com transactions. Additionally, chat conversations are recorded and monitored by Delta Air Lines.<br />
Please wait while we contact the next available agent&#8230;<br />
You are now speaking with Morris!<br />
<strong>Morris:</strong> Hi! My name is Morris. How may I help you?<br />
<strong>Morris:</strong> Hi! How may I assist you today?<br />
<strong>Steve Goldsby : </strong>I just checked in online, and tried to print my boarding pass . When I do, I get a &#8220;page not found&#8221; error from the website. If I go back to my itinerary and try to &#8220;reprint&#8221; boarding pass, I get the same &#8220;page not found&#8221; error. Can you fix this or email me my boarding pass in PDF format so I can print it and avoid the lines at the airport? SkyMiles #: &lt;xxxxxxxxxxxxxx&gt;<br />
<strong>Morris:</strong> Steve, I apologize for the inconvenience you faced on Delta.com; please give me a moment while I look into the matter for you!<br />
<strong>Steve Goldsby : </strong>thanks.<br />
<strong>Steve Goldsby : </strong>i also notice the flight is oversold. if you have seats on an ealrier flight, I would be happy to consider an earlier flight.<br />
<strong>Morris:</strong> Let me check that for you. Just one moment.<br />
<strong>Morris:</strong> I see on your reservation that you have already checked in, be rest assured you will get a print of the boarding pass at the airport.<br />
<strong>Steve Goldsby : </strong>right. i don&#8217;t want to wait in line.<br />
<strong>Morris:</strong> I will not be able to send a print of the pass via chat.<br />
<strong>Morris:</strong> Did you receive my last response?<br />
<strong>Steve Goldsby : </strong>i did.<br />
<strong>Steve Goldsby : </strong>since the flight is oversold, is there an option to move to an earlier flight?<br />
<strong>Morris:</strong> On the seat map I see that two seats are available 33 B and 36 F.<br />
<strong>Steve Goldsby : </strong>okay. when i checked in the website said:<br />
<strong>Steve Goldsby : </strong><em>Your flight is oversold. Delta is seeking volunteers with flexible travel plans to exchange their seats for compensation. Go ahead and check in below. If interested in volunteering see your gate agent at the airport.</em><br />
<strong>Morris:</strong> To check in, print your boarding card and check your bags online, please go to our home page, click on the Itineraries and Check In under the tab Traveling and Check In, retrieve your reservation with your name and the confirmation number or ticket number, on the trip details page you will see the area at the top that says Check In, please click on that link and follow the instructions. You will also be able check in your bags online.<br />
<strong>Steve Goldsby : </strong>I<strong> </strong>did that. website returns this error page at the &#8220;print boarding pass&#8221; page<br />
<strong>Steve Goldsby : </strong><em>Requested Page Not Found The requested page could not be found on delta.com: * We may have removed the page or changed its web address. * Bookmark or link you clicked on might be incorrect. * Web address may have been mistyped. Recheck it to make sure it’s correct. How to Find Your Page: Use our Search tool to help you find what you’re looking for, or start again from our home page. If you still need assistance, try our Live Chat option with a customer service representative, or contact us for help. </em><br />
<strong>Steve Goldsby : </strong>so I contacted you  for help.<br />
<strong>Morris:</strong> please call our Online Customer Support Desk at 1-888-750-3284 and our Representatives will be glad to help.<br />
<strong>Steve Goldsby : </strong>What&#8217;s the vector victor? Roger roger.<br />
<strong>Steve Goldsby : </strong>i&#8217;ll call customer support.<br />
<strong>Morris:</strong> Is there anything else I may help you with?<br />
<strong>Morris:</strong> Thanks for choosing Delta have a nice day.<br />
Morris left the chat.<br />
Your chat has ended.  Thank you for speaking with us.<br />
Please help us improve our service by clicking on the following link to take a short survey: <a href="https://s-2503.estara.com/UI/guiframedisplay.php?unblockip=24.96.152.74&amp;calltype=talkbychat&amp;timestamp=1256137792&amp;timestamphash=E910FBC81557C40F2412EA01ED0711EF&amp;ftcallid=newgui_95386%3A24.96.152.74%3A80%3A1256137793.0248&amp;guiid=43f2de8a9637b&amp;referrer=https%3A%2F%2Fwww.delta.com%2Foci%2Fservlet%2Fociservlet%3Fcmd%3Dreprintcmd%26estara_fsguid%3DAEA7C0EDBD1BABDA36263AF20A8D57A4&amp;accountid=200106289346&amp;template=369081&amp;nocacheguid=24.96.152.74_56000_4adf244142782&amp;_get=YToxMTp7czoxMDoiZG9ub3RjYWNoZSI7czoxMzoiMTI1NjEzNzc4NzMyOCI7czo5OiJhY2NvdW50aWQiO3M6MTI6IjIwMDEwNjI4OTM0NiI7czo4OiJyZWZlcnJlciI7czo1OToiaHR0cHM6Ly93d3cuZGVsdGEuY29tL29jaS9zZXJ2bGV0L29jaXNlcnZsZXQ%2FY21kPXJlcHJpbnRjbWQiO3M6OToicGFnZXRpdGxlIjtzOjE0OiJQYWdlIE5vdCBGb3VuZCI7czo4OiJhbXA7aG9zdCI7czoxNToiYXMwMC5lc3RhcmEuY29tIjtzOjg6InRlbXBsYXRlIjtzOjY6IjM2OTA4MSI7czo0OiJ1cmlkIjtzOjU6IjI5NTc1IjtzOjg6ImNhbGx0eXBlIjtzOjEwOiJ3ZWJjaGF0cG9wIjtzOjEzOiJlc3RhcmFfZnNndWlkIjtzOjMyOiJBRUE3QzBFREJEMUJBQkRBMzYyNjNBRjIwQThENTdBNCI7czo1OiJndWlpZCI7czoxMzoiNDNmMmRlOGE5NjM3YiI7czo5OiJ0aW1lc3RhbXAiO3M6MTA6IjEyNTYxMzc3OTIiO30%3D&amp;surveyname=delta6666">CLICK HERE</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/117/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/117/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=117&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/10/21/dont-hate-your-customers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Gmail phishing redux</title>
		<link>http://security.goldsby.com/2009/09/23/gmail-phishing-redux/</link>
		<comments>http://security.goldsby.com/2009/09/23/gmail-phishing-redux/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 19:12:02 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=112</guid>
		<description><![CDATA[Just noticed over at Commtouch Cafe that the gmail trickery is ongoing . They did a good job of comparing the real gmail site with a forgery, pointing out the obvious differences.  Got me to thinking so I did a little search (using google!) and came up with several phonies.  (Search criteria:  intitle:&#8221;gmail: email from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=112&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Just noticed over at Commtouch Cafe that the gmail trickery is ongoing . They did a good job of comparing the real gmail site with a forgery, pointing out the obvious differences.  Got me to thinking so I did a little search (using google!) and came up with several phonies.  (Search criteria: <em> intitle:&#8221;gmail: email from google&#8221;  &#8220;lots of space&#8221; &#8220;mobile access&#8221; &#8220;less spam&#8221;) </em>I don&#8217;t have the time right now, but it would be an interesting exercise to find linked pages&#8230; you&#8217;d probably find some XSS on the originating site, or an evil web proxy at the other end.  Maybe a project for my next layover at the airport.</p>
<div class="wp-caption alignnone" style="width: 365px"><img title="real Gmail Page" src="http://blog.commtouch.com/cafe/wp-content/uploads/real.jpg" alt="real Gmail page" width="355" height="201" /><p class="wp-caption-text">real Gmail page</p></div>
<div class="wp-caption alignleft" style="width: 351px"><img title="Fake Gmail" src="http://blog.commtouch.com/cafe/wp-content/uploads/fake1.jpg" alt="Fake Gmail screencap" width="341" height="174" /><p class="wp-caption-text">Fake Gmail screencap</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/112/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=112&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/09/23/gmail-phishing-redux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://blog.commtouch.com/cafe/wp-content/uploads/real.jpg" medium="image">
			<media:title type="html">real Gmail Page</media:title>
		</media:content>

		<media:content url="http://blog.commtouch.com/cafe/wp-content/uploads/fake1.jpg" medium="image">
			<media:title type="html">Fake Gmail</media:title>
		</media:content>
	</item>
		<item>
		<title>StolenID Search:  Find out if your PII has been compromised</title>
		<link>http://security.goldsby.com/2009/09/23/stolenid-search-find-out-if-your-pii-has-been-compromised/</link>
		<comments>http://security.goldsby.com/2009/09/23/stolenid-search-find-out-if-your-pii-has-been-compromised/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 19:04:35 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=108</guid>
		<description><![CDATA[There&#8217;s a free (as in beer) search service over at Stolen ID Search that allows you to search their database of stolen identity information to There&#8217;s a free (as in beer) search service over at Stolen ID Search that allows you to search their database of stolen identity information to see if you&#8217;re a victim [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=108&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a free (as in beer) search service over at<a title="Stolen ID Search" href="http://stolenidsearch.com" target="_blank"> Stolen ID Search</a> that allows you to search their database of stolen identity information to There&#8217;s a free (as in beer) search service over at Stolen ID Search that allows you to search their database of stolen identity information to see if you&#8217;re a victim of identity theft.  These guys claim to have information on 120 million+ compromised accounts.  Doesn&#8217;t require you to give up the farm to find out if you&#8217;ve been popped.  If there&#8217;s a match, Stolen ID Search also offers a fee-based service to get additional information on how the data was compromised, where it was discovered and instructions on what to do next for $15.  see if you&#8217;re a victim of identity theft.  These guys claim to have information on 120 million+ compromised accounts.  Doesn&#8217;t require you to give up the farm to find out if you&#8217;ve been popped.  If there&#8217;s a match, Stolen ID Search also offers a fee-based service to get additional information on how the data was compromised, where it was discovered and instructions on what to do next for $15.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/108/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=108&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/09/23/stolenid-search-find-out-if-your-pii-has-been-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Disabling USB on various platforms</title>
		<link>http://security.goldsby.com/2009/08/28/disabling-usb-on-various-platforms/</link>
		<comments>http://security.goldsby.com/2009/08/28/disabling-usb-on-various-platforms/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 16:51:22 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=104</guid>
		<description><![CDATA[Nice little cheatsheet from the NSA that I leave behind with clients.  Gives them enough information to get the job done without overwhelming them with unnecessary information.  http://www.nsa.gov/ia/_files/factsheets/I731-002R-2007.pdf
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=104&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Nice little cheatsheet from the NSA that I leave behind with clients.  Gives them enough information to get the job done without overwhelming them with unnecessary information. <a title="NSA cheatsheet - disabling USB devices" href="http://www.nsa.gov/ia/_files/factsheets/I731-002R-2007.pdf" target="_blank"> http://www.nsa.gov/ia/_files/factsheets/I731-002R-2007.pdf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/104/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/104/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/104/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=104&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/28/disabling-usb-on-various-platforms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Fixing Goorecon.rb to handle new google responses</title>
		<link>http://security.goldsby.com/2009/08/22/finding-goorecon-rb-to-handle/</link>
		<comments>http://security.goldsby.com/2009/08/22/finding-goorecon-rb-to-handle/#comments</comments>
		<pubDate>Sat, 22 Aug 2009 15:23:54 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=97</guid>
		<description><![CDATA[Goorecon recently broken when querying for email addresses (e.g. ruby goorecon.rb -e icsinc.com).   Sometime between when goorecon was written and now, google changed their formatting of reposnses for email addresses from:
emailaddress@&#60;br&#62;icsinc.com  to   emailaddress@&#60;em&#62;icsinc.com
Easy fix is to change the following line in goorecon.rb
response.scan(/[\w.-]+@&#60;b&#62;#{target}/o) { &#124;t&#124;
to
response.scan(/[\w.-]+@&#60;[^&#62;]+&#62;#{target}/o) { &#124;t&#124;
This will keep the code flexible enough so [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=97&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Goorecon recently broken when querying for email addresses (e.g. <em>ruby goorecon.rb -e icsinc.com</em>).   Sometime between when goorecon was written and now, google changed their formatting of reposnses for email addresses from:</p>
<p>emailaddress@<strong><span style="color:#ffff00;">&lt;</span></strong><strong><span style="color:#ffff00;">br&gt;</span></strong>icsinc.com  to   emailaddress@<strong><span style="color:#ffff00;">&lt;em&gt;</span></strong>icsinc.com</p>
<p>Easy fix is to change the following line in goorecon.rb</p>
<p style="padding-left:30px;">response.scan(/[\w.-]+@<strong><span style="color:#ffff00;">&lt;b&gt;</span></strong>#{target}/o) { |t|</p>
<p>to</p>
<p style="padding-left:30px;">response.scan(/[\w.-]+@<strong><span style="color:#ffff00;">&lt;[^&gt;]+&gt;</span></strong>#{target}/o) { |t|</p>
<p>This will keep the code flexible enough so that if google ever changes the highlighting tag (formerly &lt;b&gt; but now &lt;em&gt;) to some other html tag, goorecon will still correctly draw out emaill addresses.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/97/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=97&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/22/finding-goorecon-rb-to-handle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Analyst Cheatsheets over at Packetlife</title>
		<link>http://security.goldsby.com/2009/08/13/analyst-cheatsheets-over-at-packetlife/</link>
		<comments>http://security.goldsby.com/2009/08/13/analyst-cheatsheets-over-at-packetlife/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 11:08:46 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=91</guid>
		<description><![CDATA[Great list of cheat sheets for by Jeremy Stretch over at Packetlife
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=91&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Great list of <a href="http://packetlife.net/cheatsheets/" target="_blank">cheat sheets </a>for by <a href="http://packetlife.net/about/" target="_blank">Jeremy Stretch</a> over at <a href="http://packetlife.net/" target="_blank">Packetlife</a></p>
<div class="wp-caption alignnone" style="width: 316px"><a href="http://packetlife.net/cheatsheets/"><img title="Wireshark Display Filters" src="http://packetlife.net/static/cheatsheets/preview/wireshark-display-filters_t.jpg" alt="Wireshark Display Filters" width="306" height="198" /></a><p class="wp-caption-text">Wireshark Display Filters</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/91/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=91&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/13/analyst-cheatsheets-over-at-packetlife/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://packetlife.net/static/cheatsheets/preview/wireshark-display-filters_t.jpg" medium="image">
			<media:title type="html">Wireshark Display Filters</media:title>
		</media:content>
	</item>
		<item>
		<title>Patenting the pen-test?!?!</title>
		<link>http://security.goldsby.com/2009/08/12/patenting-the-pen-test/</link>
		<comments>http://security.goldsby.com/2009/08/12/patenting-the-pen-test/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 21:30:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=88</guid>
		<description><![CDATA[Okay, process patents in this space have gone too far.  I&#8217;m googling for some information for a presentation today, and I come across a WIPO patent titled: &#8220;SYSTEM AND METHOD FOR PROVIDING NETWORK PENETRATION TESTING&#8221;. The &#8220;inventors&#8221; (and yes, I&#8217;m using that term loosely) are Fernando Federico Russ Alejandro David Weil  Matias Ernesto Eissler  Francisco [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=88&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Okay, process patents in this space have gone too far.  I&#8217;m googling for some information for a presentation today, and I come across a WIPO patent titled: &#8220;<a href="http://www.wipo.int/pctdb/en/wo.jsp?WO=2009038818&amp;IA=US2008060219&amp;DISPLAY=STATUS" target="_blank">SYSTEM AND METHOD FOR PROVIDING NETWORK PENETRATION TESTING&#8221;. </a>The &#8220;inventors&#8221; (and yes, I&#8217;m using that term loosely) are <a href="http://www.faqs.org/patents/inv/127586" target="_blank">Fernando Federico Russ</a> Alejandro David Weil  Matias Ernesto Eissler  Francisco Javier Dibar  Hector Adrian Manrique.  A quick search shows these guys in other patent activity.  What&#8217;s disturbing is that this patent appears to have been filed in 2008, but the process described doesn&#8217;t seem terribly innovative.  Client side pen testing with a bunch of legal and process fluff thrown in to make it look sexy.  Surely metasploit would be prior art, among other tools and frameworks.  How do these folks get away with this.  I need to go do my research on these inventors, and CORE SDI INC to get a complete picture.  If anyone out there has input, I&#8217;d sure like to hear it.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=88&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/12/patenting-the-pen-test/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Finally, understand your inner (or outer) Nerd</title>
		<link>http://security.goldsby.com/2009/08/12/finally-understand-your-inner-or-outer-nerd/</link>
		<comments>http://security.goldsby.com/2009/08/12/finally-understand-your-inner-or-outer-nerd/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 00:27:18 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=80</guid>
		<description><![CDATA[I thought I&#8217;d reached the end of the Internet, but apparently I missed this little gem of content.  It actually brought tears to my eyes.  Tears of joy, because finally someone understands me and my kind.  I&#8217;m willing to bet that at least one out of three readers of this blog can relate.  So look [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=80&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I thought I&#8217;d reached the end of the Internet, but apparently I missed<a href="http://www.randsinrepose.com/archives/2007/11/11/the_nerd_handbook.html" target="_blank"> this little gem</a><a href="http://security.goldsby.com/2009/08/12/finally-understand-your-inner-or-outer-nerd/" target="_blank"> </a>of content.  It actually brought tears to my eyes.  Tears of joy, because finally someone understands me and my kind.  I&#8217;m willing to bet that at least one out of three readers of this blog can relate.  So look to your right, and look to your left.  If it ain&#8217;t them&#8230; well, you&#8217;re the nerd. Definitely worth the 8 minute read (40 seconds if<a href="http://mubix.blogspot.com/2009/08/rules-to-reading-faster.html" target="_blank"> Mubix&#8217;s recommendation</a> works).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=80&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/12/finally-understand-your-inner-or-outer-nerd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Fixing the way Firefox renders under Backtrack/Ubuntu</title>
		<link>http://security.goldsby.com/2009/08/11/fixing-the-way-firefox-renders-under-backtrackubuntu/</link>
		<comments>http://security.goldsby.com/2009/08/11/fixing-the-way-firefox-renders-under-backtrackubuntu/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 03:12:23 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://security.goldsby.com/?p=77</guid>
		<description><![CDATA[I finally had enough retuning Firefox every time I loaded Backtrack4.  You see, some apps (like firefox) are built using GTK, but Ubuntu/Backtrack run use KDE.  The result is that no matter how you tune your X-theme, Firefox still looks like poo.  The fix is to do some trickery with KDE-&#62;GTK-&#62;Qt bindings, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=77&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I finally had enough retuning Firefox every time I loaded <a href="http://www.remote-exploit.org/backtrack.html" target="_blank">Backtrack4</a>.  You see, some apps (like firefox) are built using GTK, but Ubuntu/Backtrack run use KDE.  The result is that no matter how you tune your X-theme, Firefox still looks like poo.  The fix is to do some trickery with KDE-&gt;GTK-&gt;Qt bindings,  look at Bug #193538, or just load a Firefox theme that addresses this problem.    My preference is <a href="http://ramonantonio.net/kde-firefox/" target="_blank">KFirefox: Firefox Theme for KDE4</a>.  Pointy clicky, draggy droppy, and you have a svelte firefox under Ubuntu.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/77/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=77&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/08/11/fixing-the-way-firefox-renders-under-backtrackubuntu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Baby pictures in lost wallets increase the chance they will be returned</title>
		<link>http://security.goldsby.com/2009/07/12/baby-pictures-in-lost-wallets-increase-the-chance-they-will-be-returned/</link>
		<comments>http://security.goldsby.com/2009/07/12/baby-pictures-in-lost-wallets-increase-the-chance-they-will-be-returned/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 13:23:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/12/baby-pictures-in-lost-wallets-increase-the-chance-they-will-be-returned/</guid>
		<description><![CDATA[
Interesting Social component.  This and similar research may have implications with social engineering to increase likelihood of success.  Article is over at BoingBoing  http://www.boingboing.net/2009/07/12/baby-pictures-in-los.html
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=66&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-71" title="walletb" src="http://stevegoldsby.files.wordpress.com/2009/07/istock_000007724108xsmall2.jpg?w=285&#038;h=188" alt="walletb" width="285" height="188" /><br />
Interesting Social component.  This and similar research may have implications with social engineering to increase likelihood of success.  Article is over at BoingBoing  <a href="http://www.blogger.com/Baby%20pictures%20in%20lost%20wallets%20increase%20the%20chance%20they%20will%20be%20returned">http://www.boingboing.net/2009/07/12/baby-pictures-in-los.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=66&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/12/baby-pictures-in-lost-wallets-increase-the-chance-they-will-be-returned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://stevegoldsby.files.wordpress.com/2009/07/istock_000007724108xsmall2.jpg" medium="image">
			<media:title type="html">walletb</media:title>
		</media:content>
	</item>
		<item>
		<title>X-Rumer 5.0 Spam tool &#8211; pure evil &#8211; Busts captcha, registration, etc.</title>
		<link>http://security.goldsby.com/2009/07/11/x-rumer-5-0-spam-tool-pure-evil-busts-captcha-registration-etc/</link>
		<comments>http://security.goldsby.com/2009/07/11/x-rumer-5-0-spam-tool-pure-evil-busts-captcha-registration-etc/#comments</comments>
		<pubDate>Sat, 11 Jul 2009 15:35:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/11/x-rumer-5-0-spam-tool-pure-evil-busts-captcha-registration-etc/</guid>
		<description><![CDATA[Interesting read over at Digital Soapbox on the &#8220;X-Rumer&#8221; Russian Spam tool.  This nasty little tool handles CAPTCHA&#8217;s, sites requiring registration, etc.  I&#8217;d be interested in seeing who else has fallen prey to and verified this thing.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=65&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Interesting read over at <a href="http://preachsecurity.blogspot.com/2009/07/devastated-by-link-spam-tool.html">Digital Soapbox</a> on the &#8220;X-Rumer&#8221; Russian Spam tool.  This nasty little tool handles CAPTCHA&#8217;s, sites requiring registration, etc.  I&#8217;d be interested in seeing who else has fallen prey to and verified this thing.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=65&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/11/x-rumer-5-0-spam-tool-pure-evil-busts-captcha-registration-etc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Sometimes when you&#8217;re right, you&#8217;re wrong &#8211; Beating clients around the head and neck in an audit.</title>
		<link>http://security.goldsby.com/2009/07/09/sometimes-when-youre-right-youre-wrong-beating-clients-around-the-head-and-neck-in-an-audit/</link>
		<comments>http://security.goldsby.com/2009/07/09/sometimes-when-youre-right-youre-wrong-beating-clients-around-the-head-and-neck-in-an-audit/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 16:30:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/09/sometimes-when-youre-right-youre-wrong-beating-clients-around-the-head-and-neck-in-an-audit/</guid>
		<description><![CDATA[VERY well articulated and fast read at http://www.securitycatalyst.com/did-i-think-this-through/.  having been in the business for some time, I can tell you this is where most of our security ninja&#8217;s make their mistake &#8212; beating the client over the head with a club like a baby seal.
Sometimes when you&#8217;re right, you&#8217;re wrong.
     [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=64&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>VERY well articulated and fast read at <a href="http://www.securitycatalyst.com/did-i-think-this-through/">http://www.securitycatalyst.com/did-i-think-this-through/</a>.  having been in the business for some time, I can tell you this is where most of our security ninja&#8217;s make their mistake &#8212; beating the client over the head with a club like a baby seal.</p>
<p>Sometimes when you&#8217;re right, you&#8217;re wrong.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=64&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/09/sometimes-when-youre-right-youre-wrong-beating-clients-around-the-head-and-neck-in-an-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Al Qaeda: 0 USA: (infinity)</title>
		<link>http://security.goldsby.com/2009/07/09/al-qaeda-0-usa-infinity/</link>
		<comments>http://security.goldsby.com/2009/07/09/al-qaeda-0-usa-infinity/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 02:57:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/09/al-qaeda-0-usa-infinity/</guid>
		<description><![CDATA[Hey, if you want to live in a cave but use 21st century technology&#8230; well&#8230; as a wise man once told me:  &#8220;LIFE isn&#8217;t fair&#8221;. http://www.wired.com/dangerroom/2009/07/infrared-beacons-guiding-cia-drone-strikes-qaeda-claims/.  Can I get a BOOMya?!?!?!?!
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=63&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Hey, if you want to live in a cave but use 21st century technology&#8230; well&#8230; as a wise man once told me:  &#8220;LIFE isn&#8217;t fair&#8221;. <a href="http://www.wired.com/dangerroom/2009/07/infrared-beacons-guiding-cia-drone-strikes-qaeda-claims/">http://www.wired.com/dangerroom/2009/07/infrared-beacons-guiding-cia-drone-strikes-qaeda-claims/</a>.  Can I get a BOOMya?!?!?!?!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/63/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=63&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/09/al-qaeda-0-usa-infinity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Stupid stego tricks with PDFs.</title>
		<link>http://security.goldsby.com/2009/07/09/stupid-stego-tricks-with-pdfs/</link>
		<comments>http://security.goldsby.com/2009/07/09/stupid-stego-tricks-with-pdfs/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 02:48:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/09/stupid-stego-tricks-with-pdfs/</guid>
		<description><![CDATA[http://secforall.info/2009/07/08/abusing-pdfs/Joe Webster has a great writeup on easy and effective steganography tricks using PDFs as your host.  9/10.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=62&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://secforall.info/2009/07/08/abusing-pdfs/">http://secforall.info/2009/07/08/abusing-pdfs/</a><br />Joe Webster has a great writeup on easy and effective steganography tricks using PDFs as your host.  9/10.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/62/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=62&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/09/stupid-stego-tricks-with-pdfs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Insane? Genius? Or alt-root maintainer AND president of the Fifth World Order?</title>
		<link>http://security.goldsby.com/2009/07/08/insane-genius-or-alt-root-maintainer-and-president-of-the-fifth-world-order/</link>
		<comments>http://security.goldsby.com/2009/07/08/insane-genius-or-alt-root-maintainer-and-president-of-the-fifth-world-order/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 17:32:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/08/insane-genius-or-alt-root-maintainer-and-president-of-the-fifth-world-order/</guid>
		<description><![CDATA[
I recently became aware of the Cesidian alt-root run by the &#8220;Hon Most Rev Dr Cesidio Tallini&#8220;.  This guy is definitely out there.
Why am I posting this?  I can&#8217;t explain why, but I haven&#8217;t seen anything this bizarre in a long time, and I see some bizarre stuff.  Apparently he lives on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=61&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cesidianroot.net/tech/tech_files/hmctmicro.jpg"><img style="float:left;cursor:pointer;width:112px;height:84px;margin:0 10px 10px 0;" src="http://www.cesidianroot.net/tech/tech_files/hmctmicro.jpg" border="0" alt="" /></a><br />
I recently became aware of the <a href="http://www.cesidianroot.net/">Cesidian alt-root</a> run by the &#8220;<a href="http://cesidio.org/">Hon Most Rev Dr Cesidio Tallini</a>&#8220;.  This guy is definitely out there.</p>
<p>Why am I posting this?  I can&#8217;t explain why, but I haven&#8217;t seen anything this bizarre in a long time, and I see some bizarre stuff.  Apparently he lives on Long Island and has proclaimed himself the head of that nation.  He also has these “micronations,” which consist of a rock in the ocean with a pelican sitting on it.  This guy is comprehensive in his delusion &#8211; his Amazon Store has books on how to start your own nation, pirates (&#8220;arrggh matey&#8221; not &#8220;ihackstuff&#8221;), and a field guide to mushrooms.</p>
<p>If nothing else, I entertained myself for 30 minutes</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/61/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/61/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/61/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=61&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/08/insane-genius-or-alt-root-maintainer-and-president-of-the-fifth-world-order/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://www.cesidianroot.net/tech/tech_files/hmctmicro.jpg" medium="image" />
	</item>
		<item>
		<title>Audio release of &quot;Into the Breach (Recommended)</title>
		<link>http://security.goldsby.com/2009/07/08/audio-release-of-into-the-breach-recommended/</link>
		<comments>http://security.goldsby.com/2009/07/08/audio-release-of-into-the-breach-recommended/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 11:07:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/08/audio-release-of-into-the-breach-recommended/</guid>
		<description><![CDATA[The audio version of “Into the Breach: Protect your Business by Managing People, Information, and Risk” has just been released.  Great if you have a stack of books on the nightstand but some free time in the car/airport/etc. 
Check out a snippet of the audio version of the book at:  http://www.securitycatalyst.com/innovation/security-catalyst-podcast/
   [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=60&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The audio version of “Into the Breach: Protect your Business by Managing People, Information, and Risk” has just been released.  Great if you have a stack of books on the nightstand but some free time in the car/airport/etc. </p>
<p>Check out a <span style="font-weight:bold;">snippet</span> of the audio version of the book at:  <a href="http://www.securitycatalyst.com/innovation/security-catalyst-podcast/">http://www.securitycatalyst.com/innovation/security-catalyst-podcast/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=60&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/08/audio-release-of-into-the-breach-recommended/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Protect .NET assemblies against reverse-engineering and recompilation</title>
		<link>http://security.goldsby.com/2009/07/08/protect-net-assemblies-against-reverse-engineering-and-recompilation/</link>
		<comments>http://security.goldsby.com/2009/07/08/protect-net-assemblies-against-reverse-engineering-and-recompilation/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 10:41:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[.net]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/08/protect-net-assemblies-against-reverse-engineering-and-recompilation/</guid>
		<description><![CDATA[02.07.2009   Decompilation Injection &#8211; Maty Siman, CISSPPress Release (PR) Press Release (PR)
Checkmarx Research Labs present a novel way to protect .NET assemblies against reverse-engineering and recompilation. By injecting them with commands that are activated only at the recompilation stage, the application retroactively detects the reverse-engineering process and acts upon it.
http://checkmarx.com/NewsDetails.aspx?id=18&#38;cat=3
    [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=59&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>02.07.2009   Decompilation Injection &#8211; Maty Siman, CISSP<br />Press Release (PR) Press Release (PR)</p>
<p>Checkmarx Research Labs present a novel way to protect .NET assemblies against reverse-engineering and recompilation. By injecting them with commands that are activated only at the recompilation stage, the application retroactively detects the reverse-engineering process and acts upon it.</p>
<p><a href="http://checkmarx.com/NewsDetails.aspx?id=18&amp;cat=3">http://checkmarx.com/NewsDetails.aspx?id=18&amp;cat=3</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/59/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=59&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/08/protect-net-assemblies-against-reverse-engineering-and-recompilation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Using Kon-Boot from a USB Flash Drive: Bypass those pesky Windows and Linux login passwords completely</title>
		<link>http://security.goldsby.com/2009/07/08/using-kon-boot-from-a-usb-flash-drive-bypass-those-pesky-windows-and-linux-login-passwords-completely/</link>
		<comments>http://security.goldsby.com/2009/07/08/using-kon-boot-from-a-usb-flash-drive-bypass-those-pesky-windows-and-linux-login-passwords-completely/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 10:26:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/08/using-kon-boot-from-a-usb-flash-drive-bypass-those-pesky-windows-and-linux-login-passwords-completely/</guid>
		<description><![CDATA[Good visual aid for the recently updated kon-boot over at http://www.irongeek.com/i.php?page=security/kon-boot-from-usb
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=58&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Good visual aid for the recently updated kon-boot over at <a href="http://www.irongeek.com/i.php?page=security/kon-boot-from-usb">http://www.irongeek.com/i.php?page=security/kon-boot-from-usb</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=58&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/08/using-kon-boot-from-a-usb-flash-drive-bypass-those-pesky-windows-and-linux-login-passwords-completely/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>New attack vector: &quot;Man-in-the-phone&quot; attacks.</title>
		<link>http://security.goldsby.com/2009/07/07/new-attack-vector-man-in-the-phone-attacks/</link>
		<comments>http://security.goldsby.com/2009/07/07/new-attack-vector-man-in-the-phone-attacks/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 21:26:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/new-attack-vector-man-in-the-phone-attacks/</guid>
		<description><![CDATA[Okay, maybe not new, but what a sexy marketing term for it.  From the article:
The scam works like this: The criminal calls a target, claiming to be the fraud department of the target&#8217;s bank calling to alert the mark to potential unauthorized activity. The recipient of the call is then told to please hold [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=56&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Okay, maybe not new, but what a sexy marketing term for it.  From the article:</p>
<p><span style="font-style:italic;">The scam works like this: The criminal calls a target, claiming to be the fraud department of the target&#8217;s bank calling to alert the mark to potential unauthorized activity. The recipient of the call is then told to please hold while a fraud specialist is brought on the line. The perpetrator then calls the victim&#8217;s bank, and bridges the call, while placing his portion of the call on mute.</p>
<p>When the bank&#8217;s fraud department asks various questions in a bid to authenticate the victim, the criminal records the customer&#8217;s answers. Depending on the institution, the answers may include the victim&#8217;s Social Security number or national ID number, a PIN or password, and/or the amount of last deposit or location of the last transaction.</p>
<p>The criminal then calls the bank back (ostensibly reaching a different customer service representative), supplies the personal information needed to access the victim&#8217;s account, and begins to initiate a series of wire transfers out of that account into another that he controls. </span><br /><a href="http://voices.washingtonpost.com/securityfix/2009/07/high_crimes_using_low-tech_att.html">http://voices.washingtonpost.com/securityfix/2009/07/high_crimes_using_low-tech_att.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=56&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/new-attack-vector-man-in-the-phone-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>List of current IE 0day exploiting domains</title>
		<link>http://security.goldsby.com/2009/07/07/list-of-current-ie-0day-exploiting-domains/</link>
		<comments>http://security.goldsby.com/2009/07/07/list-of-current-ie-0day-exploiting-domains/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 12:54:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/list-of-current-ie-0day-exploiting-domains/</guid>
		<description><![CDATA[update your ACLS at http://isc.sans.org/diary.html?storyid=6739&#38;rss
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=55&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>update your ACLS at <a href="http://isc.sans.org/diary.html?storyid=6739&amp;rss">http://isc.sans.org/diary.html?storyid=6739&amp;rss</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/55/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=55&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/list-of-current-ie-0day-exploiting-domains/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Don&#8217;t copy that floppy sequel promises prison beatings</title>
		<link>http://security.goldsby.com/2009/07/07/dont-copy-that-floppy-sequel-promises-prison-beatings/</link>
		<comments>http://security.goldsby.com/2009/07/07/dont-copy-that-floppy-sequel-promises-prison-beatings/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 12:44:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/dont-copy-that-floppy-sequel-promises-prison-beatings/</guid>
		<description><![CDATA[http://www.boingboing.net/2009/07/06/dont-copy-that-flopp-1.html
H4&#215;0r humor
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=54&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.boingboing.net/2009/07/06/dont-copy-that-flopp-1.html">http://www.boingboing.net/2009/07/06/dont-copy-that-flopp-1.html</a></p>
<p>H4&#215;0r humor<br /><span style="text-align:center; display: block;"><a href="http://security.goldsby.com/2009/07/07/dont-copy-that-floppy-sequel-promises-prison-beatings/"><img src="http://img.youtube.com/vi/fHaAFqoVLtI/2.jpg" alt="" /></a></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=54&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/dont-copy-that-floppy-sequel-promises-prison-beatings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/fHaAFqoVLtI/2.jpg" medium="image" />
	</item>
		<item>
		<title>Tool Density Matters &#8211; MultiISO LiveDVD v1.0 – BackTrack, Knoppix &amp; Ophcrack</title>
		<link>http://security.goldsby.com/2009/07/07/tool-density-matters-multiiso-livedvd-v1-0-%e2%80%93-backtrack-knoppix-ophcrack/</link>
		<comments>http://security.goldsby.com/2009/07/07/tool-density-matters-multiiso-livedvd-v1-0-%e2%80%93-backtrack-knoppix-ophcrack/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 12:06:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/tool-density-matters-multiiso-livedvd-v1-0-%e2%80%93-backtrack-knoppix-ophcrack/</guid>
		<description><![CDATA[http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It’s a all-in-one multipurpose LiveDVD put together. There’s something in it for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=53&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/">http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/</a><br />MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It’s a all-in-one multipurpose LiveDVD put together. There’s something in it for everyone.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=53&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/tool-density-matters-multiiso-livedvd-v1-0-%e2%80%93-backtrack-knoppix-ophcrack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Predictable Social Security Numbers &#8211; peeling back the layers of the onion</title>
		<link>http://security.goldsby.com/2009/07/07/predictable-social-security-numbers-peeling-back-the-layers-of-the-onion/</link>
		<comments>http://security.goldsby.com/2009/07/07/predictable-social-security-numbers-peeling-back-the-layers-of-the-onion/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 03:02:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/predictable-social-security-numbers-peeling-back-the-layers-of-the-onion/</guid>
		<description><![CDATA[A few barriers to entry. 

First, read the research summary: http://www.cmu.edu/news/archive/2009/July/july6_ssnprediction.shtml
Then, discover that the &#8220;death master file&#8221; is $14k plus update costs: http://www.ntis.gov/products/ssa-quarterly.aspx

Likely copies of this running around the &#8220;blackhat&#8221; underground, and it would only take a few identity thefts to cover the cost of the database, but the script kiddie populace should effectively be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=52&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A few barriers to entry. </p>
<ul>
<li>First, read the research summary: <a href="http://www.cmu.edu/news/archive/2009/July/july6_ssnprediction.shtml">http://www.cmu.edu/news/archive/2009/July/july6_ssnprediction.shtml</a></li>
<li>Then, discover that the &#8220;death master file&#8221; is $14k plus update costs: <a href="http://www.ntis.gov/products/ssa-quarterly.aspx">http://www.ntis.gov/products/ssa-quarterly.aspx</a></li>
</ul>
<p>Likely copies of this running around the &#8220;blackhat&#8221; underground, and it would only take a few identity thefts to cover the cost of the database, but the script kiddie populace should effectively be excluded.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/52/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=52&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/predictable-social-security-numbers-peeling-back-the-layers-of-the-onion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Goldman Sachs: 1 Ruskies: 0</title>
		<link>http://security.goldsby.com/2009/07/07/goldman-sachs-1-ruskies-0/</link>
		<comments>http://security.goldsby.com/2009/07/07/goldman-sachs-1-ruskies-0/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 02:50:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/goldman-sachs-1-ruskies-0/</guid>
		<description><![CDATA[http://www.wired.com/threatlevel/2009/07/aleynikov/
Great article on one of the outcomes of a good logging and compliance program.  Moral of the story?  Blowfish, UUencode then tunnel everything through SSL! $400k a year wasn&#8217;t enough?  #fail
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=51&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>http://www.wired.com/threatlevel/2009/07/aleynikov/</p>
<p>Great article on one of the outcomes of a good logging and compliance program.  Moral of the story?  Blowfish, UUencode then tunnel everything through SSL! $400k a year wasn&#8217;t enough?  #fail</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=51&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/goldman-sachs-1-ruskies-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Nobody Is That Dumb &#8230; Oh, Wait XII</title>
		<link>http://security.goldsby.com/2009/07/07/nobody-is-that-dumb-oh-wait-xii/</link>
		<comments>http://security.goldsby.com/2009/07/07/nobody-is-that-dumb-oh-wait-xii/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 02:25:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/07/nobody-is-that-dumb-oh-wait-xii/</guid>
		<description><![CDATA[From Chuvakin&#8217;s blog, a little light humor, with a bit too much reality.. follow the link for more.
Nobody Is That Dumb &#8230; Oh, Wait XII 
Many, many moons ago I had this brilliant series &#8220;Nobody Is That Dumb &#8230; Oh, Wait&#8220; (the last one was back in March) where I made fun of people making [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=50&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<h3 class="post-title"><span style="font-size:85%;"><span style="font-weight:normal;">From Chuvakin&#8217;s blog, a little light humor, with a bit too much reality</span></span>.. <span style="font-weight:normal;font-size:85%;">follow the link for more.</span><br /></h3>
<h3 style="font-style:italic;" class="post-title"><a href="http://chuvakin.blogspot.com/2009/07/nobody-is-that-dumb-oh-wait-xii.html">Nobody Is That Dumb &#8230; Oh, Wait XII</a> </h3>
<h5 style="font-style:italic;">Many, many moons ago I had this brilliant <a href="http://chuvakin.blogspot.com/search/label/stupidity">series &#8220;Nobody Is That Dumb &#8230; Oh, Wait</a><a href="http://chuvakin.blogspot.com/search/label/stupidity">&#8220;</a> (<u><a href="http://chuvakin.blogspot.com/2009/03/nobody-is-that-dumb-oh-wait-xi.html">the last one</a></u> was back in March) where I made fun of people making dumb security claims with apparent &#8211; and often scary! &#8211; seriousness. Somehow I neglected this series, but a few days ago I was shown a super-shining example of sheer stupidity of immense proportions.</h5>
<p style="font-style:italic;">It all started in a remote country of Norway where one particular journalist discovered a horrible evil (mmm… Evil!) that threatens all life in the Universe (mmmm… Multiverse!): honeypots.  Specifically, the English translation of the printed original from their “Aftenposten” newspaper starts like this:</p>
<blockquote><p>“Unethical and unacceptable, says computer experts.”</p>
</blockquote>
<p style="font-style:italic;">Reeeeally? OMFG, thanks for enlightening me that an idiot in Norwegian is spelled “c-o-m-p-u-t-e-r e-x-p-e-r-t” <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p style="font-style:italic;"></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=50&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/07/nobody-is-that-dumb-oh-wait-xii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>The Curious Case of Asset Valuation</title>
		<link>http://security.goldsby.com/2009/07/06/the-curious-case-of-asset-valuation/</link>
		<comments>http://security.goldsby.com/2009/07/06/the-curious-case-of-asset-valuation/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 15:04:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/06/the-curious-case-of-asset-valuation/</guid>
		<description><![CDATA[Good analysis of current framework (ISO 27005) and gaps over at http://riskmanagementinsight.com/riskanalysis/?p=641
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=49&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Good analysis of current framework (ISO 27005) and gaps over at http://riskmanagementinsight.com/riskanalysis/?p=641</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=49&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/06/the-curious-case-of-asset-valuation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Cryptohaze multihash brute forcers for CUDA</title>
		<link>http://security.goldsby.com/2009/07/06/cryptohaze-multihash-brute-forcers-for-cuda/</link>
		<comments>http://security.goldsby.com/2009/07/06/cryptohaze-multihash-brute-forcers-for-cuda/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 12:42:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/06/cryptohaze-multihash-brute-forcers-for-cuda/</guid>
		<description><![CDATA[Sexy, and source forthcoming.  This could open up many new possibilities for tinkerers &#8211; http://www.cryptohaze.com/bruteforcers.php
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=48&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Sexy, and source forthcoming.  This could open up many new possibilities for tinkerers &#8211; http://www.cryptohaze.com/bruteforcers.php</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/48/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=48&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/06/cryptohaze-multihash-brute-forcers-for-cuda/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Paimei &#8211; reverse engineering framework</title>
		<link>http://security.goldsby.com/2009/07/06/paimei-reverse-engineering-framework/</link>
		<comments>http://security.goldsby.com/2009/07/06/paimei-reverse-engineering-framework/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 01:14:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/06/paimei-reverse-engineering-framework/</guid>
		<description><![CDATA[PaiMei, is a reverse engineering framework consisting of multiple extensible components. The framework can essentially be thought of as a reverse engineer&#8217;s swiss army knife and has already been proven effective for a wide range of both static and dynamic tasks such as fuzzer assistance, code coverage tracking, data flow tracking and more.   [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=47&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://paimei.googlecode.com/svn/trunk/logos/paimei-2.jpg"><img style="float:left;cursor:pointer;width:350px;height:190px;margin:0 10px 10px 0;" src="http://paimei.googlecode.com/svn/trunk/logos/paimei-2.jpg" alt="" border="0" /></a><br />PaiMei, is a reverse engineering framework consisting of multiple extensible components. The framework can essentially be thought of as a reverse engineer&#8217;s swiss army knife and has already been proven effective for a wide range of both static and dynamic tasks such as fuzzer assistance, code coverage tracking, data flow tracking and more.   <a href="http://code.google.com/p/paimei/">http://code.google.com/p/paimei/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/47/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=47&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/06/paimei-reverse-engineering-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://paimei.googlecode.com/svn/trunk/logos/paimei-2.jpg" medium="image" />
	</item>
		<item>
		<title>Twitter mass suspending accounts &#8211; SpamCloud?</title>
		<link>http://security.goldsby.com/2009/07/06/twitter-mass-suspending-accounts-spamcloud/</link>
		<comments>http://security.goldsby.com/2009/07/06/twitter-mass-suspending-accounts-spamcloud/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 01:00:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/06/twitter-mass-suspending-accounts-spamcloud/</guid>
		<description><![CDATA[
Looks like Twitter has been mass suspending accounts today.  From what I can piece together, it&#8217;s holiday-related spam barrage, probably nimrods out there tinkering with their new knowledge from Month of Twitter Bugs.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=45&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://stevegoldsby.files.wordpress.com/2009/07/twitter_account_suspended.jpg?w=1600"><img style="float:right;cursor:pointer;width:320px;height:62px;margin:0 0 10px 10px;" src="http://stevegoldsby.files.wordpress.com/2009/07/twitter_account_suspended.jpg?w=320" alt="" border="0" /></a></p>
<p>Looks like <a href="http://www.twitter.com/">Twitter</a> has been mass suspending accounts today.  From what I can piece together, it&#8217;s holiday-related spam barrage, probably nimrods out there tinkering with their new knowledge from <a href="http://www.twitpwn.com/">Month of Twitter Bugs</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/45/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=45&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/06/twitter-mass-suspending-accounts-spamcloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>

		<media:content url="http://stevegoldsby.files.wordpress.com/2009/07/twitter_account_suspended.jpg?w=320" medium="image" />
	</item>
		<item>
		<title>CERT Resiliency Management Model released</title>
		<link>http://security.goldsby.com/2009/07/02/cert-resiliency-management-model-released/</link>
		<comments>http://security.goldsby.com/2009/07/02/cert-resiliency-management-model-released/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 16:40:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/02/cert-resiliency-management-model-released/</guid>
		<description><![CDATA[This is actually a well done framework viable for implementation in the organization.  Jump to http://www.cert.org/resiliency/rmm.html
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=44&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>This is actually a well done framework viable for implementation in the organization.  Jump to http://www.cert.org/resiliency/rmm.html</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=44&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/02/cert-resiliency-management-model-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>You have no privacy: What you buy may affect your credit</title>
		<link>http://security.goldsby.com/2009/07/01/you-have-no-privacy-what-you-buy-may-affect-your-credit/</link>
		<comments>http://security.goldsby.com/2009/07/01/you-have-no-privacy-what-you-buy-may-affect-your-credit/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 10:58:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/01/you-have-no-privacy-what-you-buy-may-affect-your-credit/</guid>
		<description><![CDATA[Of note:
Have you used your credit card at merchants specializing in secondhand clothing, retread tires, bail bond services, massages, casino gambling or betting? Your credit card issuer may be taking note &#8212; and making decisions about your creditworthiness based on your purchasing behavior. The reason: Buying used clothing or retread tires may be an indication [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=43&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Of note:
<div style="font-style:italic;" class="articleTxt smallText" id="articleTxt4">Have you used your credit card at merchants specializing in secondhand clothing, retread tires, bail bond services, massages, casino gambling or betting? Your credit card issuer may be taking note &#8212; and making decisions about your creditworthiness based on your purchasing behavior. The reason: Buying used clothing or retread tires may be an indication of financial distress and a preamble to missed credit card payments or defaults.   <a href="http://www.walletpop.com/credit/credit-cards/article/what-you-buy-where-you-shop-may-affect/544639?icid=main%7cmain%7cdl3%7clink3%7chttp%253A%252F%252Fwww.walletpop.com%252Fcredit%252Fcredit-cards%252Farticle%252F_a%252Fbbdp%252Fwhat-you-buy-where-you-shop-may-affect%252F544639">Link here </a></p>
<p><span style="font-family:arial;">But when a cop does this it&#8217;s illegal?</span></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/43/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=43&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/01/you-have-no-privacy-what-you-buy-may-affect-your-credit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Seven Deadly sins of Social Networking</title>
		<link>http://security.goldsby.com/2009/07/01/seven-deadly-sins-of-social-networking/</link>
		<comments>http://security.goldsby.com/2009/07/01/seven-deadly-sins-of-social-networking/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 10:53:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/01/seven-deadly-sins-of-social-networking/</guid>
		<description><![CDATA[Great article at computer world - let the social engineering begin.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=42&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Great article at <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9134994">computer world </a>- let the social engineering begin.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=42&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/01/seven-deadly-sins-of-social-networking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Good start to quantifying data breach costs</title>
		<link>http://security.goldsby.com/2009/07/01/good-start-to-quantifying-data-breach-costs/</link>
		<comments>http://security.goldsby.com/2009/07/01/good-start-to-quantifying-data-breach-costs/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 01:58:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/07/01/good-start-to-quantifying-data-breach-costs/</guid>
		<description><![CDATA[Good start to a framework for quantifying databreach hard- and soft-costs over at Securosis.  Warrants further inputs from business units to catch any stragglers, but seems viable.  Hard to track the costs surrounding loss in equity value&#8230; like when do you consider the recovery from the incident as starting and finishing?  I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=41&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Good start to a framework for quantifying databreach hard- and soft-costs over at <a href="http://securosis.com/blog/creating-a-standard-for-data-breach-costs/">Securosis</a>.  Warrants further inputs from business units to catch any stragglers, but seems viable.  Hard to track the costs surrounding loss in equity value&#8230; like when do you consider the recovery from the incident as starting and finishing?  I wonder what ChoicePoint, TJX or Heartland might say.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/41/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/41/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/41/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=41&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/07/01/good-start-to-quantifying-data-breach-costs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Opt out of Behavioral Advertising networks</title>
		<link>http://security.goldsby.com/2009/06/30/opt-out-of-behavioral-advertising-networks/</link>
		<comments>http://security.goldsby.com/2009/06/30/opt-out-of-behavioral-advertising-networks/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 13:36:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[behavioral advertising]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[pii]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/06/30/opt-out-of-behavioral-advertising-networks/</guid>
		<description><![CDATA[Behavioral marketing involves serving up ads to a particular individual based on his or her previous online behavior, and many folks consider it evil in the manner of George Orwellian &#8220;1984&#8243; government.  Check out the Network Advertising Initiative  for information on which behavioral advertising sites have cookies on your machine and pointy-clicky feature [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=40&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Behavioral marketing involves serving up ads to a particular individual based on his or her previous online behavior, and many folks consider it evil in the manner of George Orwellian &#8220;1984&#8243; government.  Check out the <a href="http://www.networkadvertising.org/managing/opt_out.asp">Network Advertising Initiative</a>  for information on which behavioral advertising sites have cookies on your machine and pointy-clicky feature for for opting out.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=40&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/06/30/opt-out-of-behavioral-advertising-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Unique security twist due to Increased comfort / dependence on Internet</title>
		<link>http://security.goldsby.com/2009/06/29/unique-security-twist-due-to-increased-comfort-dependence-on-internet/</link>
		<comments>http://security.goldsby.com/2009/06/29/unique-security-twist-due-to-increased-comfort-dependence-on-internet/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 15:24:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/06/29/unique-security-twist-due-to-increased-comfort-dependence-on-internet/</guid>
		<description><![CDATA[An interesting read over at The Center for the Digital Future at the USC Annenberg School that indicates (to me) that the efficacy of social engineering, phishing and other attacks will increase  as society becomes less engaged personally with relationships and more comfortable / dependent upon the online connections they have formed.  Is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=38&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>An interesting read over at <a href="http://www.digitalcenter.org/pages/current_report.asp?intGlobalId=43">The Center for the Digital Future at the USC Annenberg School</a> that indicates (to me) that the efficacy of social engineering, phishing and other attacks will increase  as society becomes less engaged personally with relationships and more comfortable / dependent upon the online connections they have formed.  Is Facebook making society sheep to the slaughter?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/38/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=38&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/06/29/unique-security-twist-due-to-increased-comfort-dependence-on-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>The problem with CyberSecurity Mandates</title>
		<link>http://security.goldsby.com/2009/06/29/the-problem-with-cybersecurity-mandates/</link>
		<comments>http://security.goldsby.com/2009/06/29/the-problem-with-cybersecurity-mandates/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 15:09:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/06/29/the-problem-with-cybersecurity-mandates/</guid>
		<description><![CDATA[Just got back from my 20-year high school reunion and had time to catch up on my reading.  After getting through CyberSecurity training: the battle over mandates  over at Federal Computer Week, I felt compelled to jot a few notes.
The article references a measure sponsored by Sens. John “Jay” Rockefeller (D-W.Va.) and Olympia [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=37&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Just got back from my 20-year high school reunion and had time to catch up on my reading.  After getting through <a href="http://fcw.com/Articles/2009/06/22/feat-cybersecurity-training.aspx">CyberSecurity training: the battle over mandates </a> over at Federal Computer Week, I felt compelled to jot a few notes.</p>
<p>The article references a measure sponsored by Sens. John “Jay” Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine) that would direct the Commerce Department to “develop or coordinate and integrate a national licensing, certification and periodic recertification program for cybersecurity professionals.”   Notable quote:  <span style="font-style:italic;">“It would then become unlawful for a person lacking the proper license and certification to provide cybersecurity services to an agency or for an information system or network designated as critical infrastructure”</span> (emphasis mine). </p>
<p>I think we all see the problems with this.</p>
<p><span style="font-weight:bold;">Problem 0:  “Unlawful” is a land-mine.  </span>My COO has a catch-phrase that I like:  Don’t run FROM something, run TO something.  His point is that fear-based decisions are nearly always bad decisions.  By introducing terminology in a requirement such as “unlawful” you are creating a big red flag for anyone that might even be remotely interested in your problem.<br />Problem 1:  Certification doesn’t necessarily imply capability.  Certifications only prove that at a particular point in time you had the knowledge required to pass a test.  It is not an indicator that you retained the knowledge, that you understood the material you tested on, or that you are able to do the job currently on the table.  We all know “paper tigers”, those consultants that have multiple certifications but lack the applied and practical skills to return significant value.  I have personally been involved in follow-on engagements to clean up after a highly-credentialed vendor whose deliverables lacked actionable recommendations, parity with budget constraints, or a realistic implementation timeline.  It is important to be able to properly qualify vendors and team members before engaging them.</p>
<p><span style="font-weight:bold;">Problem 2:  Certifications provide a false sense of security if considered out of context.   </span>I have seen cases where HR was screening candidates based solely on a laundry list of Security and IT certifications.  The business unit couldn’t understand why they couldn’t get qualified candidates until we discovered that HR was filtering out highly qualified consultants who simply lacked the ‘appropriate’ number of certifications.  Too many organizations rely on certifications as exclusive evaluation criteria but provide little weighting to other items such as past performance, experience in their vertical, background checks, or depth of technical ability.  </p>
<p><span style="font-weight:bold;">Problem 3:  Certification requirements may introduce barriers that exclude highly qualified talent.   </span>I agree that certifications are a good differentiator when selecting a vendor or a solution.  That is, when all other factors are equal, certifications make good “tie breakers”.  However, they are poor discriminators – they are not unique to any vendor or solution.    We all know highly qualified consultants that cannot or will not spend money on a certification costing thousands of dollars when they know it provides on value to their clients.  For instance, the PCI Qualified Security Assessor certification costs over $25,000 to achieve and $10,000 per year to maintain.  My firm chose not to pursue this certification and focuses instead on pre-audit services such as control selection and risk mitigation to help our clients pass the audit.</p>
<p><span style="font-weight:bold;">Problem 4:  Certification Lifecycle is Short.  </span>I may be a little over-dramatic here, but the point is valid.  The pace and velocity of change in IT is dramatic.  Very few certifications provide foundational knowledge that survive over time.  The CISSP is one exception as it does a deep dive into many axiomatic areas (think role-based access controls, risk models, etc).</p>
<p><span style="font-weight:bold;">Problem 5:  Vendor Certifications are Problematic in Information Security.  </span>Many certifications are vendor centric.  While this is a good thing for network- and systems-administrators (i.e. the ‘wrench turners’), its value erodes in the information security disciplines.  Vendor-centric certifications often skew security theory to their product lines, and there is no independent oversight body.  You are better served by balancing a combination of a technical degree, certifications and real-world experience rather than having a checklist of certifications.  Consider that University degrees communicate that the candidate has a broad range of exposure to the discipline, has the ability to self-teach new material, and buckle down to achieve goals they really don’t want to (anyone remember Music Appreciation class?). </p>
<p><span style="font-weight:bold;">Problem 6:  These requirements will trickle down to and strangle industry.  </span>The federal government has the ability to get their fingers into just about everything.  In this case, the Commerce Department can pull levers like interstate trade to impose their will on business.  Also, as the largest single customer in the nation, the Federal government can, has, and will continue to impose these requirements on a large percentage of commercial enterprises through contract flow-down provisions   Having served the federal government for over 12 years, I continue to see such onerous requirements creep into solicitations and contract vehicles, making the cost of serving our customers untenable.  We are so handcuffed by ‘checklist’ requirements that there is little funding left over to return real value to our customer, squeezing our margins, and degrading our service delivery.</p>
<p>Every day I see clients make these kinds of mistakes and pay the consequences.  Clients who don’t understand their own needs and copy-and-paste someone else’s requirements into their solicitation.  Clients who think compliance equals security.  Clients who release requests-for-proposal (RFPs) where the “successful bidder must assign a  to this project”.  </p>
<p>I’d be interested in other’s thoughts on this one. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=37&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/06/29/the-problem-with-cybersecurity-mandates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>When you index the entire internet, you can do some really sexy things.</title>
		<link>http://security.goldsby.com/2009/06/20/when-you-index-the-entire-internet-you-can-do-some-really-sexy-things/</link>
		<comments>http://security.goldsby.com/2009/06/20/when-you-index-the-entire-internet-you-can-do-some-really-sexy-things/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 12:15:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/06/20/when-you-index-the-entire-internet-you-can-do-some-really-sexy-things/</guid>
		<description><![CDATA[Google relaunched its malware finding search engine, AntiMalvertising.com.  In classic google manner, you can pass it a target website or domain via the url (ala http://www.google.com/safebrowsing/diagnostic?site=google.com) and get some interesting results.  In this example, you&#8217;ll see that google has indeed been a vector, and its&#8217; nice to see that they&#8217;re not filtering out [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=36&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Google relaunched its malware finding search engine, AntiMalvertising.com.  In classic google manner, you can pass it a target website or domain via the url (ala http://www.google.com/safebrowsing/diagnostic?site=google.com) and get some interesting results.  In this example, you&#8217;ll see that google has indeed been a vector, and its&#8217; nice to see that they&#8217;re not filtering out their own results.  Honesty&#8217;s the best policy.</p>
<p>There&#8217;s also a nice <a href="http://code.google.com/apis/safebrowsing/">Google API interface</a>.  If you have a little spare time and want to see the size, scope and intensity of malware infected sites, you can use the <a href="http://www.anti-malvertising.com/engine">SafeBrowsing site</a> and search for patterns like </p>
<p><span style="font-style:italic;">    &#8220;Malicious software is hosted on&#8221; </span><br />    or <br /><span style="font-style:italic;">    &#8220;Yes, this site has hosted malicious software&#8221; </span></p>
<p>Because it&#8217;s all built on the google search engine, you can do nifty search modifiers too, like this query:</p>
<p><span style="font-style:italic;">&#8220;Yes, this site has hosted malicious software&#8221;     inurl:site=*.com</span></p>
<p>Of course, I find it suspicious that </p>
<p><span style="font-style:italic;">&#8220;Yes, this site has hosted malicious software&#8221;     inurl:site=*.gov</span></p>
<p>doesn&#8217;t return any .gov sites in the USA, especially considering that I know there are dozens of them.  Maybe this is a safety filter that google built in to protect our national critical infrastructure?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=36&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/06/20/when-you-index-the-entire-internet-you-can-do-some-really-sexy-things/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>Googledocs.com trolling for user credentials to google sites?</title>
		<link>http://security.goldsby.com/2009/05/04/googledocs-com-trolling-for-user-credentials-to-google-sites/</link>
		<comments>http://security.goldsby.com/2009/05/04/googledocs-com-trolling-for-user-credentials-to-google-sites/#comments</comments>
		<pubDate>Mon, 04 May 2009 11:24:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/05/04/googledocs-com-trolling-for-user-credentials-to-google-sites/</guid>
		<description><![CDATA[Today I went in to update my google docs site with some new information for my team.  For some reason (call it early morning fog), I went to googledocs.com instead of docs.google.com.  The site rendered nothing, but did throw up a browser authentication dialog.  I tried a few nonsense userid/password combinations with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=35&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Today I went in to update my google docs site with some new information for my team.  For some reason (call it early morning fog), I went to googledocs.com instead of docs.google.com.  The site rendered nothing, but did throw up a browser authentication dialog.  I tried a few nonsense userid/password combinations with no satisfaction.  Just for grins, I created a gmail account and tried those credentials to see if the site was proxying the information through in a credential-trolling exercise, but continued to be presented with an authentication dialog.</p>
<p>McAfee says <a href="http://www.siteadvisor.com/sites/googledocs.com">it&#8217;s not evil </a> but I&#8217;m not convinced.  I&#8217;ll continue to check this out this week.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=35&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/05/04/googledocs-com-trolling-for-user-credentials-to-google-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
		<item>
		<title>New AVR credit card attack?</title>
		<link>http://security.goldsby.com/2009/04/30/new-avr-credit-card-attack/</link>
		<comments>http://security.goldsby.com/2009/04/30/new-avr-credit-card-attack/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 18:56:00 +0000</pubDate>
		<dc:creator>stevegoldsby</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://stevegoldsby.wordpress.com/2009/04/30/new-avr-credit-card-attack/</guid>
		<description><![CDATA[I&#8217;ve experienced just about every email/phone/web fraud you can think of.  Nigerian email scams, phishing, XSS, and phone calls from folks pretending to want to &#8220;verify&#8221; my credit card information.  Today I experienced a new one that is more brute force than the others I&#8217;ve seen.
Warning sign #1 &#8211; unsolicited callI was driving [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=32&subd=stevegoldsby&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve experienced just about every email/phone/web fraud you can think of.  Nigerian email scams, phishing, XSS, and phone calls from folks pretending to want to &#8220;verify&#8221; my credit card information.  Today I experienced a new one that is more brute force than the others I&#8217;ve seen.</p>
<p><span style="font-weight:bold;">Warning sign #1 &#8211; unsolicited call</span><br />I was driving to an appointment and the OnStar line in my Tahoe rang.  This is is unusual because I only use that line for the occasional outbound call when I&#8217;m stuck in traffic, and only a couple of people have it, none of whom bother to call it.  I answered the call, and after a couple of seconds&#8230; </p>
<p><span style="font-weight:bold;">Warning Sign #2 &#8211; AVR</span><br />I got an automated voice response system (AVR), one that appeared to be very very old.  It sounded, in fact, like the old <a href="http://en.wikipedia.org/wiki/Software_Automatic_Mouth">Software Automatic Mouth</a>.  I didn&#8217;t have a recorder going, but the general message that came out of this was &#8220;Your credit card shows suspicious activity.  Press one to verify this activity or two to leave&#8221;.  Intrigued, I pressed one.</p>
<p><span style="font-weight:bold;">Warning Sign #3 &#8211; </span><br />After pressing 1, the AVR moved on.  The AVR never told me anything to help me identify which account it might be talking about (e.g. by giving me the last 4 of an account number).   What the AVR *did* do, however, was ask me to enter my credit card number.   Since I was in the Tahoe, I didn&#8217;t have a keypad.  Trying to use the OnStart AVR to enter a (bogus) credit card number was less than successful, so the call ultimately dropped. </p>
<p>I suspect that the system is driven by some public record data sources, or partially complete transaction data pilfered from a commercial database, and that the AVR is simply robo-dialing for the missing pieces.  For instance, if the AVR had my name and address, it would need to acquire the CC#, expiration date and verification number.  You can imagine other scenarios based on various data sources (an e-tailer transaction log with everything except the credit card number which was encrypted?) </p>
<p>This is an interesting attack model.  Mildly more expensive than e-mail, less obvious as an attack as it used AVR (albeit a crappy one), and the ability to automate. </p>
<p>If anyone out there has experienced this &#8216;retro-phishing&#8217;, I&#8217;d sure like to know.</p>
<p>phone</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stevegoldsby.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stevegoldsby.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stevegoldsby.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stevegoldsby.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stevegoldsby.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stevegoldsby.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stevegoldsby.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stevegoldsby.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stevegoldsby.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stevegoldsby.wordpress.com/32/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=security.goldsby.com&blog=8575418&post=32&subd=stevegoldsby&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://security.goldsby.com/2009/04/30/new-avr-credit-card-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bed2e317351964ae7620588fbd9e3042?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stevegoldsby</media:title>
		</media:content>
	</item>
	</channel>
</rss>