<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="http://feedproxy.google.com/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feedproxy.google.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">

<channel>
	<title>The IT Security Blog Roundup</title>
	
	<link>http://roundup.scmagazineblogs.com</link>
	<description />
	<pubDate>Fri, 23 Nov 2007 01:36:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feedproxy.google.com/TheItSecurityBlogRoundup" type="application/rss+xml" /><item>
		<title>More on the e-jihad that never happened</title>
		<link>http://roundup.scmagazineblogs.com/2007/11/13/more-on-the-e-jihad-that-never-happened/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/11/13/more-on-the-e-jihad-that-never-happened/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 19:11:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Emerging Threats]]></category>

		<category><![CDATA[Government]]></category>

		<category><![CDATA[Groundbreakers and newsmakers]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/11/13/more-on-the-e-jihad-that-never-happened/</guid>
		<description><![CDATA[I had a feeling that some people stayed up all night on Sunday waiting for the planned, and announced, al Qaeda cyber-jihad to begin. 
Thankfully, like the Great Pumpkin, it might just be a figment of the imagination. 
We found some interesting points this week from Marcus Sachs, SANS Internet Storm Center director and a [...]]]></description>
			<content:encoded><![CDATA[<p>I had a feeling that some people stayed up all night on Sunday waiting for the planned, and announced, <a href="http://www.scmagazineus.com/Website-Al-Qaeda-cyber-jihad-to-begin-Nov-11/article/58336/">al Qaeda cyber-jihad</a> to begin. </p>
<p>Thankfully, like the Great Pumpkin, it might just be a figment of the imagination. </p>
<p>We found <a href="http://isc.sans.org/diary.html?storyid=3633">some interesting points</a> this week from Marcus Sachs, SANS Internet Storm Center director and a former White House cybersecurity advisor on whether or not cyber-terror is a reality. His point: Sunday’s threat was overblown in the press, but al Qaeda and other terrorist groups do use the internet to communicate and raise money. </p>
<p><em>“This whole cyber-terrorism thing has always bothered me, especially since every time some nut decides that the ‘next attack’ is going to be against an online target, the press goes into hyper alert mode. Folks, let&#8217;s get serious about this for a few minutes. I know that this is politically incorrect, but the odds of a terrorist group ‘terrorizing’ the internet with cyber-bullets and e-bombs are about as small as the odds of the Morse Code coming back as a primary means of communication.  It&#8217;s not zero, but it&#8217;s also not much more than zero…</p>
<p>The terrorists use the internet for the same thing everybody else does - communicating with each other. They also use it to raise money through criminal activity, then launder it via one of the many electronic payment systems. Ever look at the spam and phishing junk mail you receive? It&#8217;s not just the Russian Business Network operating in the shadows. With the internet providing near-perfect communications and a seemingly endless supply of money why would a terrorist group want to blow it up?”</em></p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/11/12/no-sign-of-e-jihad/" rel="bookmark" title="Permanent Link: No sign of e-jihad" >No sign of e-jihad</a></span><div class="aizattos_related_posts_excerpt">Maybe it’s time for a sigh of relief. The much rumored “cyber-jihad,” scheduled for Sunday, ne...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/" rel="bookmark" title="Permanent Link: Cyberjihad - for real?" >Cyberjihad - for real?</a></span><div class="aizattos_related_posts_excerpt">Johannes Ullrich, on the SANS Internet Storm Center diary, on reports (including ours) that al Qaeda...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/18/no-proof-yet-of-os-x-worm/" rel="bookmark" title="Permanent Link: No proof yet of OS X worm" >No proof yet of OS X worm</a></span><div class="aizattos_related_posts_excerpt">Security researchers at McAfee are hot on the trail of a recent post at the Infosecsellout blog that...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/07/whos-saying-what-about-tjx/" rel="bookmark" title="Permanent Link: Who&#8217;s saying what about TJX" >Who&#8217;s saying what about TJX</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/lolpyeVzlj6TJccTsSDx-wRnzAc/a"><img src="http://feedads.googleadservices.com/~a/lolpyeVzlj6TJccTsSDx-wRnzAc/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/11/13/more-on-the-e-jihad-that-never-happened/feed/</wfw:commentRss>
		</item>
		<item>
		<title>No sign of e-jihad</title>
		<link>http://roundup.scmagazineblogs.com/2007/11/12/no-sign-of-e-jihad/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/11/12/no-sign-of-e-jihad/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 20:06:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Emerging Threats]]></category>

		<category><![CDATA[Trojans]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/11/12/no-sign-of-e-jihad/</guid>
		<description><![CDATA[Maybe it’s time for a sigh of relief. The much rumored “cyber-jihad,” scheduled for Sunday, never took place. 
Most security researchers dismissed, or at leas downplayed, the threat in the days leading up to the scheduled Nov. 11 event, but I’d bet there was – and likely is – at least one person working for [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe it’s time for a sigh of relief. The much rumored “<a href="http://www.scmagazineus.com/Al-Qaeda-cyber-jihad-threat-dismissed-by-researchers/article/96294/">cyber-jihad</a>,” scheduled for Sunday, never took place. </p>
<p>Most <a href="http://www.scmagazineus.com/Al-Qaeda-cyber-jihad-threat-dismissed-by-researchers/article/96294/">security researchers dismissed</a>, or at leas downplayed, the threat in the days leading up to the scheduled Nov. 11 event, but I’d bet there was – and likely is – at least one person working for the federal government taking the threat seriously. </p>
<p>F-Secure’s Mikko Hypponnen has a write-up on the <a href="http://www.f-secure.com/weblog/archives/00001315.html">company blog</a>, stating, “Cyberterrorism is not a problem. But it does make for cool movie scripts.”</p>
<p>And Peter Coogan at Symantec Security Response filed <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/ejihad_vs_storm.html">this post</a>, listing the tale of the tape between e-Jihad vs. Storm Worm. Guess who won? </p>
<p>Here’s a hint, from Coogan’s <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/ejihad_vs_storm.html">post</a>: </p>
<p><em>“Comparing the e-jihad and Storm techniques mentioned above clearly shows that the &#8216;cyber terrorists&#8217; in this case are well behind the cyber criminals.”</em></p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/" rel="bookmark" title="Permanent Link: Cyberjihad - for real?" >Cyberjihad - for real?</a></span><div class="aizattos_related_posts_excerpt">Johannes Ullrich, on the SANS Internet Storm Center diary, on reports (including ours) that al Qaeda...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/06/sign-up-for-spam-here/" rel="bookmark" title="Permanent Link: Sign up for spam here!" >Sign up for spam here!</a></span><div class="aizattos_related_posts_excerpt">Ever sign up to be spammed? Probably not. But that’s effectively what happens if you open one unwa...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/11/13/more-on-the-e-jihad-that-never-happened/" rel="bookmark" title="Permanent Link: More on the e-jihad that never happened" >More on the e-jihad that never happened</a></span><div class="aizattos_related_posts_excerpt">I had a feeling that some people stayed up all night on Sunday waiting for the planned, and announce...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/02/post-launch-iphone-security-concerns/" rel="bookmark" title="Permanent Link: Post-launch iPhone security concerns" >Post-launch iPhone security concerns</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/zMwXSZI84hrO4IIhjTeiidrqtIs/a"><img src="http://feedads.googleadservices.com/~a/zMwXSZI84hrO4IIhjTeiidrqtIs/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/11/12/no-sign-of-e-jihad/feed/</wfw:commentRss>
		</item>
		<item>
		<title>More Mac trojan variants</title>
		<link>http://roundup.scmagazineblogs.com/2007/11/09/more-mac-trojan-variants/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/11/09/more-mac-trojan-variants/#comments</comments>
		<pubDate>Fri, 09 Nov 2007 20:25:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Trojans]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/11/09/more-mac-trojan-variants/</guid>
		<description><![CDATA[We’d be lying to you if we were to use the words “Mac trojan” and “epidemic” in the same sentence. 
While an in-the-wild trojan was found for OS X last month, and now it doesn’t appear to be alone, it’s also not fair to say Mac exploits are everywhere – at least not yet. 
Here’s [...]]]></description>
			<content:encoded><![CDATA[<p>We’d be lying to you if we were to use the words “Mac trojan” and “epidemic” in the same sentence. </p>
<p>While an <a href="http://www.scmagazineus.com/Trojan-targets-Mac-users/article/58290/">in-the-wild trojan was found for OS X last month</a>, and now <a href="http://www.f-secure.com/weblog/archives/00001312.html">it doesn’t appear to be alone</a>, it’s also not fair to say Mac exploits are everywhere – at least not yet. </p>
<p>Here’s a link to <a href="http://www.f-secure.com/weblog/archives/00001312.html">F-Secure’s blog</a>, where they detail a number of variants found in the wild recently. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/13/more-on-apples-safari-release-for-windows/" rel="bookmark" title="Permanent Link: More on Apple&#8217;s Safari release for Windows" >More on Apple&#8217;s Safari release for Windows</a></span><div class="aizattos_related_posts_excerpt">At the risk of turning The Roundup into “All Safari, all the time,” here’s another sampling fr...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/04/a-microsoft-look-alike/" rel="bookmark" title="Permanent Link: A Microsoft look-alike" >A Microsoft look-alike</a></span><div class="aizattos_related_posts_excerpt">Now, why would Microsoft need my credit card information when I paid for my PC with my debit card? N...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/09/13/an-international-hacking-story-that-doesnt-include-china/" rel="bookmark" title="Permanent Link: An international hacking story that doesn&#8217;t include China" >An international hacking story that doesn&#8217;t include China</a></span><div class="aizattos_related_posts_excerpt">I’m willing to bet that most people who read headlines today about the hacking of the U.S. Consula...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/25/harry-potter-and-last-weeks-other-it-security-news/" rel="bookmark" title="Permanent Link: Harry Potter, and last week&#8217;s other IT security news" >Harry Potter, and last week&#8217;s other IT security news</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/04/cybercriminals-crazy-for-still-using-britney-photos/" rel="bookmark" title="Permanent Link: Cybercriminals &#8216;Crazy&#8217; for still using Britney photos?" >Cybercriminals &#8216;Crazy&#8217; for still using Britney photos?</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/7Z2Qv97szgKpsXDTmYW9yVtKGv8/a"><img src="http://feedads.googleadservices.com/~a/7Z2Qv97szgKpsXDTmYW9yVtKGv8/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/11/09/more-mac-trojan-variants/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Cyberjihad - for real?</title>
		<link>http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 00:06:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Emerging Threats]]></category>

		<category><![CDATA[Groundbreakers and newsmakers]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/</guid>
		<description><![CDATA[Johannes Ullrich, on the SANS Internet Storm Center diary, on reports (including ours) that al Qaeda-trained cyberattackers are playing a e-jihad on Nov. 11:

“So in short: stay calm, focus on best practices and you don’t have to do anything special on Nov. 11. If your systems are secure, they will be fine. If they are [...]]]></description>
			<content:encoded><![CDATA[<p>Johannes Ullrich, on <a href="http://isc.sans.org/">the SANS Internet Storm Center diary</a>, on reports (<a href="http://www.scmagazineus.com/Website-Al-Qaeda-cyber-jihad-to-begin-Nov-11/article/58336/">including ours</a>) that al Qaeda-trained cyberattackers are playing a e-jihad on Nov. 11:<br />
<em><br />
“So in short: stay calm, focus on best practices and you don’t have to do anything special on Nov. 11. If your systems are secure, they will be fine. If they are not secure, they will get hacked no matter if it’s cyber jihad or the script kiddie from next door. </p>
<p>In the past, political attacks like this resulted in some more or less manual DoS attacks. Expect things like calls for supporters to reload particular ‘offensive’ websites, or use the ping command to flood them. In some cases, supporters may be asked to install trojans. But chances are that the usual criminals will just take advantage of this and use it as a trick to install the regular criminal bots.”</em></p>
<p>Johannes might be right. The site that reported the coming e-jihad, DEBKAfile, has been known to get things wrong. We’ll know one way or the other on Sunday. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/06/sign-up-for-spam-here/" rel="bookmark" title="Permanent Link: Sign up for spam here!" >Sign up for spam here!</a></span><div class="aizattos_related_posts_excerpt">Ever sign up to be spammed? Probably not. But that’s effectively what happens if you open one unwa...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/09/26/an-eye-on-redmond/" rel="bookmark" title="Permanent Link: An eye on Redmond" >An eye on Redmond</a></span><div class="aizattos_related_posts_excerpt">Something to keep an eye on later this week: Microsoft’s BlueHat v6 blog. 

Set to take place in R...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/22/hypponen-tries-another-bank-shot/" rel="bookmark" title="Permanent Link: Hypponen tries another .bank shot" >Hypponen tries another .bank shot</a></span><div class="aizattos_related_posts_excerpt">Security researchers may have to go another round over whether a .bank domain would cut down on the ...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/20/weekend-edition-members-of-the-military-targeted-id-theft-scare-at-los-alamos-and-oracle-turns-on-the-flashlight/" rel="bookmark" title="Permanent Link: Weekend edition: Members of the military targeted, ID theft scare at Los Alamos and Oracle turns on the flashlight" >Weekend edition: Members of the military targeted, ID theft scare at Los Alamos and Oracle turns on the flashlight</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/01/bloggers-takes-on-google-going-greenborder/" rel="bookmark" title="Permanent Link: Bloggers&#8217; takes on Google going GreenBorder" >Bloggers&#8217; takes on Google going GreenBorder</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/gcFbPolWYlO72DKgZ0faHdU4vBA/a"><img src="http://feedads.googleadservices.com/~a/gcFbPolWYlO72DKgZ0faHdU4vBA/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/11/06/cyberjihad-for-real/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Be careful of California wildfire scammers</title>
		<link>http://roundup.scmagazineblogs.com/2007/10/25/be-careful-of-california-wildfire-scammers/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/10/25/be-careful-of-california-wildfire-scammers/#comments</comments>
		<pubDate>Thu, 25 Oct 2007 20:17:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Consumer threats]]></category>

		<category><![CDATA[Groundbreakers and newsmakers]]></category>

		<category><![CDATA[Legal and Professional Services]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/10/25/be-careful-of-california-wildfire-scammers/</guid>
		<description><![CDATA[An important reminder from Randy Abrams, director of technical education at ESET: 
If you’re panning on giving to the Red Cross or other charities to help people dislocated by the California fires (and I hope you are), it’s important to note that scammers want to take advantage of your good intentions. 
Here’s a routine trick: [...]]]></description>
			<content:encoded><![CDATA[<p>An <a href="http://www.eset.com/threat-center/blog/?p=88">important reminder</a> from Randy Abrams, director of technical education at ESET: </p>
<p>If you’re panning on giving to the Red Cross or other charities to help people dislocated by the California fires (and I hope you are), it’s important to note that scammers want to take advantage of your good intentions. </p>
<p>Here’s a routine trick: </p>
<p><em>“First of all, do not respond to email messages soliciting donations, even from legitimate charities. These messages often are not sent by the charity itself. If you get an email from The American Red Cross and you wish to donate to this respected organization, do not use any information in the email as it may have been sent by a scammer that will redirect you to their fake Red Cross website. Instead, look up the phone number for the Red Cross, or open your browser yourself and type in <a href="http://american.redcross.org">http://american.redcross.org</a>.”</em></p>
<p>Or, for more information on what is, or what is not, a legit charity organization, visit <a href="http://www.charitynavigator.org/">http://www.charitynavigator.org/</a>. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/11/irs-better-business-bureau-phishing-scams-have-chinese-roots/" rel="bookmark" title="Permanent Link: IRS, Better Business Bureau phishing scams have Chinese roots" >IRS, Better Business Bureau phishing scams have Chinese roots</a></span><div class="aizattos_related_posts_excerpt">Recently we brought you stories about phishing scams claiming to be from the IRS or the Better Busin...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/23/a-fitting-description-for-virginia-tech-scammers/" rel="bookmark" title="Permanent Link: A fitting description for Virginia Tech scammers" >A fitting description for Virginia Tech scammers</a></span><div class="aizattos_related_posts_excerpt">It’s tough to believe that it’s been a week since the tragic deaths of 32 students and professor...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/10/12/sunbelt-marin-county-was-warned/" rel="bookmark" title="Permanent Link: Sunbelt: Marin County was warned" >Sunbelt: Marin County was warned</a></span><div class="aizattos_related_posts_excerpt">Some interesting stuff today on Sunbelt Security’s blog about the fed shutdown of the California �...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/10/speaking-of-blogger-debates/" rel="bookmark" title="Permanent Link: Speaking of blogger debates" >Speaking of blogger debates</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/05/another-angle-iphone-scams/" rel="bookmark" title="Permanent Link: Another angle: iPhone scams" >Another angle: iPhone scams</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/lLMFzOUZNqR1OeQAlY_YDj0xrGY/a"><img src="http://feedads.googleadservices.com/~a/lLMFzOUZNqR1OeQAlY_YDj0xrGY/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/10/25/be-careful-of-california-wildfire-scammers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hackers or scalpers?</title>
		<link>http://roundup.scmagazineblogs.com/2007/10/23/hackers-or-scalpers/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/10/23/hackers-or-scalpers/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 18:05:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Consumer threats]]></category>

		<category><![CDATA[Emerging Threats]]></category>

		<category><![CDATA[Groundbreakers and newsmakers]]></category>

		<category><![CDATA[High Tech]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/10/23/hackers-or-scalpers/</guid>
		<description><![CDATA[We have some instant reaction to the hacking of the Colorado Rockies’ online ticket system from Larry Seltzer at PC Magazine. 
I have to admit, one of the first thoughts that crossed my mind when I first heard of this incident was, “Hmmmmm, isn’t Boston a security researcher-rich city?”
Seltzer also raises the possibility that the [...]]]></description>
			<content:encoded><![CDATA[<p>We have some instant reaction to <a href="http://www.scmagazineus.com/Colorado-Rockies-blame-cyberattack-for-online-ticket-sales-outage/article/58167/">the hacking of the Colorado Rockies’ online ticket system</a> from <a href="http://blogs.pcmag.com/securitywatch/2007/10/hacking_the_world_series.php">Larry Seltzer at <em>PC Magazine</a></em>. </p>
<p>I have to admit, one of the first thoughts that crossed my mind when I first heard of this incident was, “Hmmmmm, isn’t Boston a security researcher-rich city?”</p>
<p>Seltzer also raises the possibility that the attack wasn’t an attack at all, but an attempt to hog tickets. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/08/28/microsoft-unleashes-hacker-blog/" rel="bookmark" title="Permanent Link: Microsoft unleashes hacker blog" >Microsoft unleashes hacker blog</a></span><div class="aizattos_related_posts_excerpt">News flash – Microsoft employs ethical hackers - researchers who test the company’s software for...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/09/13/an-international-hacking-story-that-doesnt-include-china/" rel="bookmark" title="Permanent Link: An international hacking story that doesn&#8217;t include China" >An international hacking story that doesn&#8217;t include China</a></span><div class="aizattos_related_posts_excerpt">I’m willing to bet that most people who read headlines today about the hacking of the U.S. Consula...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/10/17/moore-unleashes-iphone-exploits/" rel="bookmark" title="Permanent Link: Moore unleashes iPhone exploits" >Moore unleashes iPhone exploits</a></span><div class="aizattos_related_posts_excerpt">Mega-hype = increased attention from hackers. 

Researchers have proven that one since late July, si...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/02/post-launch-iphone-security-concerns/" rel="bookmark" title="Permanent Link: Post-launch iPhone security concerns" >Post-launch iPhone security concerns</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/04/cybercriminals-crazy-for-still-using-britney-photos/" rel="bookmark" title="Permanent Link: Cybercriminals &#8216;Crazy&#8217; for still using Britney photos?" >Cybercriminals &#8216;Crazy&#8217; for still using Britney photos?</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/sYkkjJjW2nCPS29M3Ju-oEqiej0/a"><img src="http://feedads.googleadservices.com/~a/sYkkjJjW2nCPS29M3Ju-oEqiej0/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/10/23/hackers-or-scalpers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Moore unleashes iPhone exploits</title>
		<link>http://roundup.scmagazineblogs.com/2007/10/17/moore-unleashes-iphone-exploits/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/10/17/moore-unleashes-iphone-exploits/#comments</comments>
		<pubDate>Wed, 17 Oct 2007 19:05:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Browser flaws]]></category>

		<category><![CDATA[Consumer threats]]></category>

		<category><![CDATA[Groundbreakers and newsmakers]]></category>

		<category><![CDATA[High Tech]]></category>

		<category><![CDATA[Mobile and Endpoint Security]]></category>

		<category><![CDATA[Product News]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/10/17/moore-unleashes-iphone-exploits/</guid>
		<description><![CDATA[Mega-hype = increased attention from hackers. 
Researchers have proven that one since late July, since when the iPhone has been pulled apart by what must be the largest number of researchers ever interested in a mobile device. 
And why not? The iPhone, after all, is a mini-computer – and one from a company known for [...]]]></description>
			<content:encoded><![CDATA[<p>Mega-hype = increased attention from hackers. </p>
<p>Researchers have proven that one since late July, since when the iPhone has been pulled apart by what must be the largest number of researchers ever interested in a mobile device. </p>
<p>And why not? The iPhone, after all, is a mini-computer – and one from a company known for not having the best relationship with the research community. </p>
<p>Renowned hacker H.D. Moore published some iPhone exploit code over the weekend. <a href="http://blog.metasploit.com/2007/10/cracking-iphone-part-2.html">Here it is</a>, if you want to take a look.</p>
<p>And please keep in mind, most experts have recommended fighting iPhone insecurity with policy, allowing the device only a very short leash within corporate environments. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/20/what-does-the-iphone-mean-for-security-pros/" rel="bookmark" title="Permanent Link: What does the iPhone mean for security pros?" >What does the iPhone mean for security pros?</a></span><div class="aizattos_related_posts_excerpt">Few people seem to know exactly what to make of the iPhone yet – other than to comment on how the ...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/05/another-angle-iphone-scams/" rel="bookmark" title="Permanent Link: Another angle: iPhone scams" >Another angle: iPhone scams</a></span><div class="aizattos_related_posts_excerpt">Who wouldn’t want a free iPhone – or an iPhone free of a binding agreement to one voice service ...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/02/post-launch-iphone-security-concerns/" rel="bookmark" title="Permanent Link: Post-launch iPhone security concerns" >Post-launch iPhone security concerns</a></span><div class="aizattos_related_posts_excerpt">It’s a little too early to start wondering if, a decade now, you’ll ask your friends, “Where w...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/12/a-bug-hunting-safari-begins-on-windows/" rel="bookmark" title="Permanent Link: A bug-hunting Safari begins on Windows" >A bug-hunting Safari begins on Windows</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/25/harry-potter-and-last-weeks-other-it-security-news/" rel="bookmark" title="Permanent Link: Harry Potter, and last week&#8217;s other IT security news" >Harry Potter, and last week&#8217;s other IT security news</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/5gphHtldufSTCPNZSsyn0-1DgG0/a"><img src="http://feedads.googleadservices.com/~a/5gphHtldufSTCPNZSsyn0-1DgG0/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/10/17/moore-unleashes-iphone-exploits/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Death of a spammer? Not likely</title>
		<link>http://roundup.scmagazineblogs.com/2007/10/12/death-of-a-spammer-not-likely/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/10/12/death-of-a-spammer-not-likely/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 19:11:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Email Security]]></category>

		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/10/12/death-of-a-spammer-not-likely/</guid>
		<description><![CDATA[Spamming, in most cases, is illegal. So it’s worth wondering what other bad deeds spammers are wrapped up in. 
That’s why recent reports describing a spammer’s death were so intriguing. 
However, according to McAfee researchers, the event was actually a hoax – and the website announcing the death was registered on Oct. 11, hours before [...]]]></description>
			<content:encoded><![CDATA[<p>Spamming, in most cases, is illegal. So it’s worth wondering what other bad deeds spammers are wrapped up in. </p>
<p>That’s why recent reports describing a spammer’s death were so intriguing. </p>
<p>However, according to McAfee researchers, the event was actually a hoax – and the website announcing the death was registered on Oct. 11, hours before the reports appeared on it. </p>
<p><em>“Plus, neither Russian sites nor Google have ever heard of this particular spammer (which would be impossible as he is depicted as one of the most prolific). And there is no trace of this murder case in the news, on TV or on the web. In a word – it is definitely a hoax.”</em><br />
- Igor Muttik, <a href="http://www.avertlabs.com/research/blog/index.php/2007/10/12/two-dead-spammers-again/">McAfee Avert Labs Blog</a>, Oct. 12, “Two dead spammers? Again.”</p>
<p>Alex Eckelberry, Sunbelt Software president and CEO, said on <a href="http://sunbeltblog.blogspot.com/">his company’s blog</a> that the hoax site may be a ploy to infect visitors with malware.<br />
<em><br />
“I wouldn&#8217;t encourage visits to this hoax site. There&#8217;s no malware on it and you&#8217;re not going to get infected. But given where this thing is hosted (and the fact that it is tracking visits), why bother? (If you&#8217;re seriously paranoid, you might even go so far as to use TOR to anonymize yourself.)&#8221;</em></p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/08/hitman-phishing-or-the-419-death-threat-scam/" rel="bookmark" title="Permanent Link: Hitman phishing, or the 419 death threat scam" >Hitman phishing, or the 419 death threat scam</a></span><div class="aizattos_related_posts_excerpt">Talk about putting the spear in spearphishing – or any other weapon for that matter.

The diligent...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/10/spammer-vs-spamhaus/" rel="bookmark" title="Permanent Link: Spammer vs. Spamhaus" >Spammer vs. Spamhaus</a></span><div class="aizattos_related_posts_excerpt">Spamhaus has enemies out there. 

Last year, e360 Insight objected to the U.K.-based non-profit list...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/06/sign-up-for-spam-here/" rel="bookmark" title="Permanent Link: Sign up for spam here!" >Sign up for spam here!</a></span><div class="aizattos_related_posts_excerpt">Ever sign up to be spammed? Probably not. But that’s effectively what happens if you open one unwa...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/29/what%e2%80%99s-up-with-image-spam/" rel="bookmark" title="Permanent Link: What’s up with image spam?" >What’s up with image spam?</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/G6jCSbjBpGZUKfqOv5pnV05-yWE/a"><img src="http://feedads.googleadservices.com/~a/G6jCSbjBpGZUKfqOv5pnV05-yWE/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/10/12/death-of-a-spammer-not-likely/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Sunbelt: Marin County was warned</title>
		<link>http://roundup.scmagazineblogs.com/2007/10/12/sunbelt-marin-county-was-warned/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/10/12/sunbelt-marin-county-was-warned/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 19:08:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Breaches]]></category>

		<category><![CDATA[Browser flaws]]></category>

		<category><![CDATA[Lawbreakers]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/10/12/sunbelt-marin-county-was-warned/</guid>
		<description><![CDATA[Some interesting stuff today on Sunbelt Security’s blog about the fed shutdown of the California “ca.gov” websites this week. 
For one, Sunbelt’s CEO and President Alex Eckelberry said today that the Marin County site is still not completely clean, and Madera County has experienced some hacks of its own. 
Scroll down a bit, and you’ll [...]]]></description>
			<content:encoded><![CDATA[<p>Some interesting stuff today on <a href="http://sunbeltblog.blogspot.com/">Sunbelt Security’s blog</a> about the fed shutdown of the California “ca.gov” websites this week. </p>
<p>For one, Sunbelt’s CEO and President Alex Eckelberry said today that the Marin County site is still not completely clean, and Madera County has experienced some hacks of its own. </p>
<p>Scroll down a bit, and you’ll see that Eckelberry highlighted a few emails sent to Marin County officials before the shutdown, warning them of the hackings. </p>
<p>On the fed shutdown itself:<br />
<em><br />
“So, was shutting down the entire system overkill? Of course. It was complete overkill. But, on the other hand, it’s a wake up call: Keep your site clean. And for Pete’s sake, please heed the warnings of security researchers when they send you email.”</em></p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/06/on-julie-ameros-big-day/" rel="bookmark" title="Permanent Link: On Julie Amero&#8217;s big day" >On Julie Amero&#8217;s big day</a></span><div class="aizattos_related_posts_excerpt">There’s one news story that everyone in the IT security world is talking about today: Julie Amero,...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/30/on-the-menu-spam-and-more-spam/" rel="bookmark" title="Permanent Link: On the menu: spam and more spam" >On the menu: spam and more spam</a></span><div class="aizattos_related_posts_excerpt">In case you didn’t already hate spam, here are two more reasons. 

McAfee Avert Labs has spotted �...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/08/30/a-new-bbb-phishing-scam/" rel="bookmark" title="Permanent Link: A new BBB phishing scam" >A new BBB phishing scam</a></span><div class="aizattos_related_posts_excerpt">Phishers target corporations and corporate executives for the same reason that bank robbers target b...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/31/beware-the-mario-worm/" rel="bookmark" title="Permanent Link: Beware the Mario worm" >Beware the Mario worm</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/04/19/first-image-spam-now-cartoon-spam/" rel="bookmark" title="Permanent Link: First image spam, now cartoon spam" >First image spam, now cartoon spam</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/aBcpNslIF3bjNDLrdm1v2uOMIlk/a"><img src="http://feedads.googleadservices.com/~a/aBcpNslIF3bjNDLrdm1v2uOMIlk/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/10/12/sunbelt-marin-county-was-warned/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google Documents bug disclosed, too</title>
		<link>http://roundup.scmagazineblogs.com/2007/09/27/google-documents-bug-disclosed-too/</link>
		<comments>http://roundup.scmagazineblogs.com/2007/09/27/google-documents-bug-disclosed-too/#comments</comments>
		<pubDate>Thu, 27 Sep 2007 16:19:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Email Security]]></category>

		<category><![CDATA[Google]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://roundup.scmagazineblogs.com/2007/09/27/google-documents-bug-disclosed-too/</guid>
		<description><![CDATA[Yesterday we brought you news that Gmail is open to a filter-insertion technique that can allow attackers to forward mail with attachments to other addresses. Google confirmed that flaw yesterday.
But it looks like Petko Petkov isn’t the only researcher out there looking into Google flaws. 
On Wednesday, Billy (BK) Rios posted on his blog that [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday we brought you <a href="http://www.scmagazineus.com/Google-working-to-patch-Gmail-message-forwarding-flaw/article/35854/">news that Gmail is open to a filter-insertion technique</a> that can allow attackers to forward mail with attachments to other addresses. Google confirmed that flaw yesterday.</p>
<p>But it looks like Petko Petkov isn’t the only researcher out there looking into Google flaws. </p>
<p>On Wednesday, Billy (BK) Rios posted on <a href="http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/">his blog</a> that Google may be putting its own servers at risk because of a cross-domain exposure flaw associated with Google Documents. </p>
<p>Here’s a snippet: </p>
<p><em>“Google Documents basically allows you to upload your documents (a.k.a. content) to a Google server. Once you’ve uploaded the document, Google has essentially “taken ownership” of the document (content). There are ways to minimize the risks associated with taking ownership of content, and it seems that Google has taken some measures to sanitize for XSS… but it seems that their focus on XSS may have caused them to miss a different type of cross domain exposure.”</em></p>
<p>Rios’ blog also features proof-of-concept code. </p>
<div class="aizattos_related_posts"><span class="aizattos_related_posts_header" >Related Posts</span><ul><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/07/09/postini-youve-been-googled/" rel="bookmark" title="Permanent Link: Postini, you&#8217;ve been Googled" >Postini, you&#8217;ve been Googled</a></span><div class="aizattos_related_posts_excerpt">Google announced another security acquisition today, picking up Postini for a reported $625 million....</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/23/one-more-blog-to-read/" rel="bookmark" title="Permanent Link: One more blog to read&#8230;" >One more blog to read&#8230;</a></span><div class="aizattos_related_posts_excerpt">Add another IT security blog to the list (after all of the SC Magazine Blogs, of course). Google lau...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/17/click-here-for-virus-google-adwords-experiment-gets-400-clicks-260000-views-in-six-months/" rel="bookmark" title="Permanent Link: &#8216;Click here for virus&#8217; Google Adwords experiment gets 400 clicks, 260,000 views in six months" >&#8216;Click here for virus&#8217; Google Adwords experiment gets 400 clicks, 260,000 views in six months</a></span><div class="aizattos_related_posts_excerpt">Late last month, we learned that sponsored advertising links on Google can yield malware, but we did...</div></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/05/24/google-and-dell-in-semi-spyware-cahoots/" rel="bookmark" title="Permanent Link: Google and Dell in semi-spyware cahoots?" >Google and Dell in semi-spyware cahoots?</a></span></li><li><span class="aizattos_related_posts_title"><a href="http://roundup.scmagazineblogs.com/2007/06/01/bloggers-takes-on-google-going-greenborder/" rel="bookmark" title="Permanent Link: Bloggers&#8217; takes on Google going GreenBorder" >Bloggers&#8217; takes on Google going GreenBorder</a></span></li></ul></div>
<p><a href="http://feedads.googleadservices.com/~a/dXhEepE25TziFb0jJIhFiCcQtks/a"><img src="http://feedads.googleadservices.com/~a/dXhEepE25TziFb0jJIhFiCcQtks/i" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://roundup.scmagazineblogs.com/2007/09/27/google-documents-bug-disclosed-too/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
