<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Security Management</title>
	<atom:link href="http://elamb.org/category/security-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SAP security audit programs</title>
		<link>http://elamb.org/sap-security-auditprograms/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=sap-security-auditprograms</link>
		<comments>http://elamb.org/sap-security-auditprograms/#comments</comments>
		<pubDate>Sat, 16 Oct 2010 04:03:18 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Access Control]]></category>
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2681</guid>
		<description><![CDATA[SAP- Increasing Demand by Increasing Efficiency Systems, applications, Products (SAP) is a security auditing program that checks a computer systems data integrity and overall security. This application is accompanied by a user interface that is highly flexible. SAP security audit &#8230; <a href="http://elamb.org/sap-security-auditprograms/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>SAP- Increasing Demand by Increasing Efficiency</strong></p>
<p>Systems, applications, Products (SAP) is a security auditing program that checks a computer systems data integrity and overall security. This application is accompanied by a user interface that is highly flexible. SAP security audit programs were introduced in the 1980s and provides the best audit resources for major companies and industry leaders.</p>
<p>In SAP, audit security is the foremost requirement enabling access control and separation of duties. These two areas are very important for the integration of control mechanisms.  A company must plan prior to implementing SAP to obtain better access and a clear understanding of the system. This includes proper design of profile and removal of surplus IDs.   Security audit programs includes many audit procedures that are designed to efficiently access a variety of transactions.</p>
<p>The main administrative function of SAP security Audit Programs includes automatic scheduling of jobs according to different user IDs, monitoring errors, administering backdrop session and access to proper management functionality. As far as security settings are concerned, SAP system audit program helps to execute online programs using different procedures and maintenance of different tables. This allows access to maintain different profile parameters including password and security of default user IDs. SAP system audit programs also allow locking of sensitive codes of transactions and execution of OS commands externally.</p>
<p>The SAP system audit program contains different audit procedures showing steps to extract useful information from a system. Some system audit program resources are highly beneficial and include audit programs for financial accounting, audit programs for basic security, audit programs for Fixed Asset, audit programs for expenditures, audit programs for treasury, audit programs for inventory management, audit programs for HR &#038; payroll and audit programs for revenue.  Companies using SAP applications can create different software packages to meet their key objectives. This application is assembled in such a way that allows each department of an organization to get integrated.  </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/sap-security-auditprograms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GFI LANGuard &#8211; Review</title>
		<link>http://elamb.org/gfi-languard-review/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=gfi-languard-review</link>
		<comments>http://elamb.org/gfi-languard-review/#comments</comments>
		<pubDate>Sat, 08 Aug 2009 03:47:38 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Network Management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[gfi languard]]></category>
		<category><![CDATA[network vulnerability]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security scan]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1833</guid>
		<description><![CDATA[I was given the honor of reviewing GFI LANguard network and security scanner. Right off the bat I notice that the interface is very intuitive &#038; easy to use, which is important to a busy security professional that have better &#8230; <a href="http://elamb.org/gfi-languard-review/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://elamb.org/wp-content/uploads/2009/08/gfi-langaurd.jpg" alt="GFI Languard Network and Security Scanner" />
<p>
I was given the honor of reviewing GFI LANguard network and security scanner.  Right off the bat I notice that the interface  is very intuitive &#038; easy to use, which is important to a busy security professional that have better things to do with their time than fight with a messy<br />
security tool.  </p>
<p>The network scanning tool I normally use is called Retina.<br />
When lining the two up, I have to say Retina is much more powerful, with many more options built in.  It can drill way down and do intrusive scans where GFI LANguard v.9 is pretty vanilla.  It gives you what you need and that is it.  </p>
<p>The simplicity could be an advantage to a system admin doing a security job, because it really is straight to the point.  The cost is definitely and advantage.  GFI LANguard is about Â½ the cost of the Retina Scan tool. </p>
<p>Retina Professional Edition 16 IP Pack &#8211; $995.00</p>
<p>GFI LAN Guard goes for about 300+ for 10 licences. </p>
<p><a href="http://www.mckeay.net/2008/05/14/changes-to-the-nessus-license/">Nessus</a> is considered one of the best network scan tools but its more expensive then both.</p>
<p>What I really like about Retina is that it allows you to scan in accordance with Department of Defense standards, SAN, and others.  Languard does look at the  <a href="http://www.sans.org/top20/">SANS Top 20 report vulnerabilities</a>.  </p>
<p>If your looking for basic, down to Earth network &#038; security scanner for your small to medium business needs, than GFI Languard is definitely the way to go because you will not beat the cost for the quality and support you get.  Its going to give you a thorough assessment of the your systems and even tell you how to fix them.  Buy this product!</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/gfi-languard-review/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>You Hack US, We Nuke You!</title>
		<link>http://elamb.org/you-hack-us-we-nuke-you/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=you-hack-us-we-nuke-you</link>
		<comments>http://elamb.org/you-hack-us-we-nuke-you/#comments</comments>
		<pubDate>Fri, 29 May 2009 01:51:46 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[I got hacked]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Super GEEK]]></category>
		<category><![CDATA[System security engineering]]></category>
		<category><![CDATA[vulnerabilities]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1716</guid>
		<description><![CDATA[The United States&#8217; top commanding officer for the space and cyber domains told reporters last week that a cyber attack could merit a more conventional military response. During a press briefing on Thursday, U.S. Air Force General Kevin Chilton, who &#8230; <a href="http://elamb.org/you-hack-us-we-nuke-you/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<blockquote><p>The United States&#8217; top commanding officer for the space and cyber domains told reporters last week that a cyber attack could merit a more conventional military response.</p>
<p>During a press briefing on Thursday, U.S. Air Force General Kevin Chilton, who heads the U.S. Strategic Command, told reporters that top Pentagon advisors would not rule out a physical attack on any force that attacks the United States through the Internet. Currently, the military&#8217;s networks are probed thousands of times a day, but the goal of attackers seems to be espionage, not to take down critical networks, he told reporters â€“</p></blockquote>
<p>&#8211; <a href="http://www.securityfocus.com/brief/961?ref=rss">Security Focus</a></p>
<p>I donâ€™t believe that military force is the equivalent action for a cyber attack.  Arrest and/or apprehension is the physical response necessary for criminal hackers attacking from other countries.  Cyber counter-attacks are the correct response for government funded &#038; coordinated attacks.  </p>
<p>I think if the U.S. reciprocates a cyber attack x10 when other countries are playing little games, weâ€™d get our message across effectively.  We should do so in a well funded and covert way in which the enemy has <strong>NO DOUBT</strong> that the face slap came from a U.S, hand, but no proof at all allowing <a href="http://en.wikipedia.org/wiki/Plausible_deniability">plausible deniability</a>.  It should be black Ops hacks, very well coordinated, very well funded and full time. </p>
<p>I donâ€™t think the US can be complacent or wrecklessly meek in matters of cyber warfare.  Instead, it must be fair, quiet and heavy handed when it comes to one of its most valuable asset, information.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/you-hack-us-we-nuke-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical Infrastructure Infiltrated</title>
		<link>http://elamb.org/critical-infrastructure-infiltrated/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-infrastructure-infiltrated</link>
		<comments>http://elamb.org/critical-infrastructure-infiltrated/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 02:07:45 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[I got hacked]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Management]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1679</guid>
		<description><![CDATA[So apparently, part of the U.S. critical infrastructure has already been exploited. It doesn&#8217;t surprise me. Its all fun and games with developers, engineers and scientists until their ass is getting hacked. They resist. They say &#8220;who the hell would &#8230; <a href="http://elamb.org/critical-infrastructure-infiltrated/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>So apparently, part of the U.S. critical infrastructure has already been exploited.  It doesn&#8217;t surprise me.  Its all fun and games with developers, engineers and scientists until their ass is getting hacked.  They resist.  They say &#8220;who the hell would hack this system&#8221;  &#8220;HOW the hell would they hack it&#8221;.  They cut corners and make excuses.  Then, when the system is hacked, they blame it on the rain.  <a href="http://digg.com/d1nL2C">The good news is that they know its been infiltrated</a>.  </p>
<p>I wonder why they didn&#8217;t design it as a closed network.  Make all critical functions completely inaccessible to the outside world.  It&#8217;s got me wondering if they even used an Information Assurance standard.  </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/critical-infrastructure-infiltrated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More GMAIL Problems</title>
		<link>http://elamb.org/more-gmail-problems/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=more-gmail-problems</link>
		<comments>http://elamb.org/more-gmail-problems/#comments</comments>
		<pubDate>Sat, 22 Nov 2008 19:03:59 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[blogging/blog hack]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Domain Names]]></category>
		<category><![CDATA[Google Hacks]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[I got hacked]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[cracker]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[scam]]></category>

	<!-- AutoMeta Start -->
	<category>makeuseof</category>
	<category>gmail</category>
	<category>temporary</category>
	<category>domain</category>
	<category>managed</category>
	<category>domains</category>
	<category>makeusof</category>
	<category>flaw</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/more-gmail-problems/</guid>
		<description><![CDATA[This was news I could not ignore because I really, really like Gmail. These hacks are ridiculous. I hope that google is getting a handle on this. It looks like the accounts are getting hacked with some sort of script &#8230; <a href="http://elamb.org/more-gmail-problems/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This was news I could not ignore because I really, really like Gmail.  These hacks are ridiculous.  I hope that google is getting a handle on this.  It looks like the accounts are getting hacked with some sort of script that runs from a site or email while gmail is opened:  </p>
<p><strong>According to David Airey &#038; gnucitizen.org:</strong><br />
The victim visits a page while being logged into GMail. Upon execution, the page performs a multipart/form-data POST to one of the GMail interfaces and injects a filter into the victimâ€™s filter list. In the example above, the attacker writes a filter, which simply looks for emails with attachments and forward them to an email of their choice. This filter will automatically transfer all emails matching the rule. Keep in mind that future emails will be forwarded as well. The attack will remain present for as long as the victim has the filter within their filter list, even if the initial vulnerability, which was the cause of the injection, is fixed by Google.<br />
&#8211; <a href="http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/">gnucitizen</a></p>
<p>As many of you already know on November 2nd, MakeUseOf.comâ€™s domain was stolen from us. It took us about 36 hours to get the domain back. As we have pointed out earlier the hacker somehow managed to get access to my Gmail account and from there to our GoDaddy account, unlock the domain and move it to another registrar.</p>
<p>You can see the whole story on our temporary blog <a href="http://makeuseof-temporary.blogspot.com/">makeuseof-temporary.blogspot.com/</a></p>
<p>I wasnâ€™t planning to publish anything about the incident or cracker (person who steals domains) and how he managed to pull it off unless I was completely sure about it myself. I had a good feeling it was a Gmail security flaw but wanted to confirm it before posting anything about it on MakeUseOf. We love Gmail and giving them bad publicity is not something we would ever want to do.</p>
<p>Now the thing is the domain name domainsgames.org is protected by Moniker and they hide all the contact info for it.</p>
<p>    Domain ID:D154519952-LROR<br />
    Domain Name:DOMAINSGAME.ORG<br />
    Created On:22-Oct-2008 07:35:56 UTC<br />
    Last Updated On:08-Nov-2008 12:11:53 UTC<br />
    Expiration Date:22-Oct-2009 07:35:56 UTC<br />
    Sponsoring Registrar:Moniker Online Services Inc. (R145-LROR)<br />
    Status:CLIENT DELETE PROHIBITED<br />
    Status:CLIENT TRANSFER PROHIBITED<br />
    Status:CLIENT UPDATE PROHIBITED<br />
    Status:TRANSFER PROHIBITED<br />
    Registrant ID:MONIKER1571241<br />
    .<br />
    .<br />
    .<br />
    .<br />
    Name Server:NS3.DOMAINSERVICE.COM<br />
    Name Server:NS2.DOMAINSERVICE.COM<br />
    Name Server:NS1.DOMAINSERVICE.COM<br />
    Name Server:NS4.DOMAINSERVICE.COM</p>
<p>More at <a href="http://www.makeuseof.com/tag/breaking-gmail-security-flaw-more-domains-get-stollen/">Makeusof.com</a> </p>
<p><a href="http://www.gnucitizen.org/blog/csrf-demystified/?_method=POST&#038;_enctype=multipart/form-data&#038;_action=https%3A//mail.google.com/mail/h/ewt1jmuj4ddv/%3Fv%3Dprf&#038;cf2_emc=true&#038;cf2_email=evilinboxmailinator.com&#038;cf1_from&#038;cf1_to&#038;cf1_subj&#038;cf1_has&#038;cf1_hasnot&#038;cf1_attach=true&#038;tfi&#038;s=z&#038;irf=on&#038;nvp_bu_cftb=Create%20Filter">The Google Fix</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/more-gmail-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Team of Barack Obama</title>
		<link>http://elamb.org/security-team-of-barack-obama/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-team-of-barack-obama</link>
		<comments>http://elamb.org/security-team-of-barack-obama/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 07:34:55 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[freedom]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Other Stuff]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security experts]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[barack obama]]></category>
		<category><![CDATA[personnel security]]></category>
		<category><![CDATA[secret service]]></category>

	<!-- AutoMeta Start -->
	<category>obama</category>
	<category>techni</category>
	<category>president</category>
	<category>george</category>
	<category>fine</category>
	<category>proactive</category>
	<category>bush</category>
	<category>protecting</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/security-team-of-barack-obama/</guid>
		<description><![CDATA[Dear Secret Service, Thank you for the fine work of protecting President George W. Bush. Regardless of my personal disagreements with about 90% of his administrations actions I wish nothing beyond a very irritating groin rash on the man who &#8230; <a href="http://elamb.org/security-team-of-barack-obama/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Dear Secret Service,</p>
<p>Thank you for the fine work of protecting President George W. Bush.  Regardless of my personal disagreements with about 90% of his administrations actions I wish nothing beyond a very irritating groin rash on the man who has been my president from 2000 &#8211; 2008.  </p>
<p>I hope that you can do the same thing for President Obama.  I am certain you&#8217;ll be proactive in  your security techniques.  I am definitely not questioning whether or not you are good at your job.</p>
<p>As an American citizen I just ask that you go one step further by looking at potential insider threats.  I&#8217;m not trying to promote some sort of conspiracy theories or anything and I certainly don&#8217;t have any reason to believe that your current staff is stocked with traitors of the American Republic.  I&#8217;m just pointing out potential threats.</p>
<p>To let harm befall such a great American who has become a symbol of hope for people around the world would be a serious blemish on YOU.  </p>
<p>p.s. Congrats on the Win, President Obama</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/security-team-of-barack-obama/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to catch hackers on your wireless</title>
		<link>http://elamb.org/how-to-catch-hackers-on-your-wireless/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-catch-hackers-on-your-wireless</link>
		<comments>http://elamb.org/how-to-catch-hackers-on-your-wireless/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 04:40:32 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Wireless]]></category>

	<!-- AutoMeta Start -->
	<category>arp</category>
	<category>techdar</category>
	<category>catch</category>
	<category>defences</category>
	<category>antiarp</category>
	<category>promiscan</category>
	<category>capsa</category>
	<category>neighbour</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/how-to-catch-hackers-on-your-wireless/</guid>
		<description><![CDATA[Techdar talks about How to catch hackers on your wireless network and how to defend your Wi-Fi from future attacks There are lots of tools around to help people carry out ARP-related exploits and if a malicious, Wi-Fi enabled neighbour &#8230; <a href="http://elamb.org/how-to-catch-hackers-on-your-wireless/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Techdar talks about How to catch hackers on your wireless network and how to defend your Wi-Fi from future attacks</p>
<p>There are lots of tools around to help people carry out ARP-related exploits and if a malicious, Wi-Fi enabled neighbour decided to find out more about your network, this could be an effective way to do it.  The good news is that there are some defences out there. The bad? They can be costly and don&#8217;t always deliver the protection you might expect.</p>
<p>Tools of Choice:</p>
<p>Arp Defender</p>
<p>AntiARP</p>
<p>Capsa</p>
<p>PromiScan</p>
<p><a href="http://www.techradar.com/news/networking/how-to-catch-hackers-on-your-wireless-network-473445?artc_pg=1">TEchdar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/how-to-catch-hackers-on-your-wireless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why is Internet Safety Important</title>
		<link>http://elamb.org/why-is-internet-safety-important/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=why-is-internet-safety-important</link>
		<comments>http://elamb.org/why-is-internet-safety-important/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 02:15:57 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[Computer Security/Home Computer Security]]></category>
		<category><![CDATA[Computer Security/Home Computer Security/Home Computer ]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[personal computer security]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[safety]]></category>

	<!-- AutoMeta Start -->
	<category>julie</category>
	<category>impressionable</category>
	<category>psychologically</category>
	<category>amero</category>
	<category>accessing</category>
	<category>items</category>
	<category>enforced</category>
	<category>norwich</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/why-is-internet-safety-important/</guid>
		<description><![CDATA[The amazing freedom and availability of the Internet lends itself to a few major dangers: Pr0n, malware and how to perform illegal and/or dangerous activities. Whether it is a curious person seeking these things out or the child accidentally clinking &#8230; <a href="http://elamb.org/why-is-internet-safety-important/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href='http://elamb.org/wp-content/uploads/2008/09/danger-electrical1.jpg' title='Dangers on the Internet'><img src='http://elamb.org/wp-content/uploads/2008/09/danger-electrical1.jpg' alt='Dangers on the Internet' /></a><br />
The amazing freedom and availability of the Internet lends itself to a few major dangers:  Pr0n, malware and how to perform illegal and/or dangerous activities. </p>
<p>Whether it is a curious person seeking these things out or the child accidentally clinking the wrong link and getting bombard with explicit pop-ups, the items lists can be harmful to an impressionable mind.  Policies must be enforced.</p>
<p>There are a few groups that should have limited exposure to certain types of information on the Internet.  Children, mentally handicapped or psychologically damaged people in settings such as schools, homes, rehabilitation or correctional facilities and group homes should be blocked, tracked and monitored while accessing the Internet.  Certain information could destroy them if they donâ€™t yet have the capacity to understand or put certain information in the proper context. </p>
<p><strong><br />
Protection from Pornography &#038; Malware</strong></p>
<p>In a professional setting there should be a written policy against accessing and/or downloading unacceptable material such as pornography.  These items should be actively blocked whether in a working environment or at home among minors accessing the same system.  Allowing impressionable or fragile minds unlimited access to certain graphic material is irresponsible.  The law is also a good reason why Internet safety is important.  If you are the owner or charged with immediate control of the system being used for illegal activity, you could be partially or wholly liable for the activity.  An example is substitute teacher <a href="http://en.wikipedia.org/wiki/Julie_Amero">Julie Amero</a> </p>
<blockquote><p>On October 19, 2004, Julie Amero was substituting for a seventh-grade language class at Kelly Middle School in Norwich, Connecticut. The teacher&#8217;s computer was accessed by pupils while the regular teacher, Matthew Napp, was out of the room. When Julie took charge, the computer started showing pornographic images.</p>
<p>On January 5, 2007, Amero was convicted in Norwich Superior Court on four counts of risk of injury to a minor, or impairing the morals of a child. Her sentencing was delayed four times after her conviction, with both the prosecution and judge not satisfied that all aspects of the case had been assessed.[1] The felony charges for which she was originally convicted carry a maximum prison sentence of 40 years</p></blockquote>
<p> &#8211; wikipedia</p>
<p>The Kelly Middle School systems were actually infected with malware that allowed the explicit pictures to pop up.</p>
<p><strong>Access to Dangerous information</strong></p>
<p>From the Columbine shooters to the Virginia Tech massacre, most of the killers had a recorded history of mental illness and/or psychologically instability.  In many cases, they used public and/or home computers belonging to their parents to research bomb making or even purchase guns.</p>
<p>Controlling access is the best way to get on the Internet safely.  Maintaining privacy of users is another important step in Internet safety, however that is a matter of educating users particularly if the frequent Social networks such as facebook or myspace.  They need to be instructed about the dangers of stalkers, perverts and predators looking specifically for impressionable minds.  </p>
<p>We are the keepers of these impressionable and fragile minds.  That is the reason Internet safety is important and why we must be mindful of these subjects.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/why-is-internet-safety-important/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Certification &amp; Accreditation Change</title>
		<link>http://elamb.org/certification-accreditation-change/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=certification-accreditation-change</link>
		<comments>http://elamb.org/certification-accreditation-change/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 00:55:54 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[federal]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[System security engineering]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Committee on National Security Systems]]></category>
		<category><![CDATA[DIACAP]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[nist 800]]></category>

	<!-- AutoMeta Start -->
	<category>metafile</category>
	<category>picture</category>
	<category>intelligence</category>
	<category>accreditation</category>
	<category>cnss</category>
	<category>cnssâ ™</category>
	<category>ehlers</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/certification-accreditation-change/</guid>
		<description><![CDATA[Standard-issue security Certification and accreditation process for national security systems to extend to the rest of government. A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies. &#8230; <a href="http://elamb.org/certification-accreditation-change/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Standard-issue security</strong><br />
Certification and accreditation process for national security systems to extend to the rest of government.  A two-year-old effort to standardize processes for certifying and accrediting government IT systems could soon bear fruit, according to officials from several agencies.</p>
<p>The <strong>Committee on National Security Systems</strong> is preparing instructions for implementing a unified certification and accreditation (C&#038;A) process that could be used on all national security systems, including those in the Defense Department and intelligence community, said Tony Cornish, chairman of the CNSSâ€™ C&#038;A working group.</p>
<p>At the same time, the National Institute of Standards and Technology plans to update its C&#038;A guidance for systems covered by the <strong>Federal Information Security Management Act</strong>, said Ron Ross, a senior computer scientist and FISMA implementation lead at NIST.</p>
<p>â€œWe are very close to producing a unified C&#038;A process for the entire federal government,â€ Ross said in July at a government security symposium hosted by Symantec. â€œWithin the next six to eight months, you are going to see a plethora of new things coming outâ€ from CNSS and NIST.</p>
<p>CNSSâ€™ instructions will be incorporated into NIST guidelines in its 800 series of special publications. Ross said a major update of SP 800-53 Rev. 2, â€œRecommended Security Controls for Federal Information Systems,â€ is expected in December, and a draft of the first revision of SP 800-37, â€œGuide for the Security Certification and Accreditation of Federal Information Systems,â€ is expected to be released for comment soon.</p>
<p>A single, governmentwide approach would make it easier for agencies to share data and cooperate with one another and with states, foreign allies and the private sector.</p>
<p>It could enable reciprocity, or the acceptance of other agenciesâ€™ C&#038;A processes, without requiring recertification, and also could streamline acquisition processes by making it easier for vendors and developers to meet one set of standards.</p>
<p>C&#038;A is a process for ensuring that IT systems are operating with an appropriate level of security. In the certification phase, the security of the system is documented; for accreditation, a designated authority signs off on the systemâ€™s fitness to go into operation. The concept has been around for some time, but there has been little standardization.</p>
<p>â€œIn the past, we each had our own set of policies, and we didnâ€™t look at each otherâ€™s,â€ said Sherrill Nicely, deputy associate director of national intelligence at the Office of the Director of National Intelligence.</p>
<p>FISMA requires C&#038;A of information technology systems, but that does not apply to national security systems. And within the national security community, the military and intelligence sectors each have had their own way of doing things.</p>
<p>â€œSince about 1993, the Defense Department had its program, the Defense IT Security Certification and Accreditation Process,â€ said Eustace King, DOD chief of acquisition and technology oversight. â€œIt worked pretty wellâ€ in a time before DODâ€™s emphasis on network- centric systems and information sharing, but it lacked enterprise visibility.</p>
<p>That C&#038;A program was replaced with the Defense Information Assurance Certification and Accreditation Process. DOD was moving to the program in 2006 to harmonize military and intelligence processes when, a year later, it was expanded to include the rest of the national security community by bringing in the CNSS.</p>
<p>Through NIST, C&#038;A procedures eventually will be standardized across all of government. However, policies do not change mind-sets, and old habits still remain one of the primary challenges to a standardized process. At DOD, there is a reluctance to accept reciprocity â€” that is, to give full credit to another agencyâ€™s C&#038;A process without recertification, King said.</p>
<p>The intelligence community faces a similar hurdle, said Sharon Ehlers, an assistant deputy associate director of national intelligence.</p>
<p>â€œThe cultural change has been the biggest challenge,â€ Ehlers said. â€œWhen it is not invented here, people donâ€™t want to look at it.â€</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/certification-accreditation-change/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ed Skoudis lists the Top 5 Worst Attacks of 1998 &#8211; 2002</title>
		<link>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002</link>
		<comments>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 00:04:15 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware/Malware Removal]]></category>
		<category><![CDATA[Malware/Trojans]]></category>
		<category><![CDATA[Malware/Virus]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[code red]]></category>
		<category><![CDATA[ed skoudis]]></category>
		<category><![CDATA[i love you]]></category>
		<category><![CDATA[melissa]]></category>
		<category><![CDATA[nimda]]></category>
		<category><![CDATA[Worm]]></category>

	<!-- AutoMeta Start -->
	<category>skoudis</category>
	<category>nimda</category>
	<category>lessons</category>
	<category>1998</category>
	<category>iis</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/</guid>
		<description><![CDATA[That which does not kill us makes us stronger. -Friedrich Nietzsche In the November 2002, Information Security Magazine article, Infosecâ€™s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 â€“ 2002. Mr. Skoudis is the founders of &#8230; <a href="http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><em>That which does not kill us makes us stronger.</em><br />
-Friedrich Nietzsche </p>
<p>In the November 2002, Information Security Magazine article, Infosecâ€™s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 â€“ 2002.  Mr. Skoudis is the founders of Intelguardians Network Intelligence, LLC and is a handler of the very popular Internet Storm Center.</p>
<p>Mr. Skoudis mentions that the Top five major destructive attacks of 1998 â€“ 2002 made many industries â€œbattle-testedâ€ and more likely to be proactive rather than reactive.  The 5 year Worst Skoudis list is based on exploits that shook our very faith in the Internet and security of e-commerce. </p>
<p><strong>1.  <a href="http://en.wikipedia.org/wiki/Code_Red_worm">Code Red (2001)</a></strong>.  July 13 2001, the worm attacked Microsoft IIS systems.  By 19 July 2001, the worm had affected over 350,000 systems.  SANS and Honeynet Project set up honey pots to capture the worm.  But E-eye Digital Security Programmers did the most intense research on the worm and also named it.   The worm exploited a vulnerability in the indexing software distributed with IIS, described in Microsoftâ€™s MS01-033 patch.  It was a buffer overflow attack. Some of the lessons learned:  Keep systems patched, use of honey pots to capture malware, coordinated response helps to contain worms.  </p>
<p><strong>2.  Nimda (2001). </strong> Shortly after 9/11, the Nimda worm was unleashed.  It caused more damage financially than Code Red.  There were rumors that it was China that released it to hurt the US further, but this is unlikely due to the nature of Nimda. </p>
<blockquote><p>
While it was bad, it had the appearance of a being written by a determined amateur, not a nation-state that spends $1 Billion annually on cyberwarfare capabilities. â€“ Skoudis.  </p></blockquote>
<p>Nimda affected Windows 95, 98, Me, NT, or 2000 and servers running Windows NT and 2000.  It was so affective because it attacked IIS, e-mail, browsers and network shares.  This multi dimensional attack method could mark a trend in future cyberfare.</p>
<p><em>Lessons Learned: The importance of an incident response capability, disabling arbitrary scripts in e-mail and browsers.</em></p>
<p><strong>3.  Melissa (1999) &#038; LoveLetter (2000). </strong> Both of these exploited malware through e-mail propagation.  Melissa used Microsoft Word Macro virus and LoveLetter (I Love You Virus).   The worm harvested the victims address book to forward itself to more victims which killed a lot of email servers.  Lessons Learned:  Many companies got serious about implementing anti-virus applications throughout the network.<br />
<strong><br />
4.  Distributed Denial-of-Service (DdoS) attacks (2000)</strong>.  After all the panic of pre-Y2K, a completely new and unexpected storm hit major sites: Yahoo!, Amazon, CNN, E*Trade ZDNet and eBay.  All by a single child hacker nicked named Mafiaboy.  He had spread zombie flooding agents to hundreds of machines around the world and used them to attack sites with billions of useless packets.  <em>Lessons Learned: employ anti-spoofing filters.</em><br />
<strong><br />
5.  Remote Control Trojan Horse Backdoors (1998 â€“ 2000)</strong>.  In 1998, the Cult of the Dead Cow hackers group created the Trojan, Back Orifice which initially targeted Windows NT/9x.    The tool allowed unskilled attackers to attack any vulnerable system.  It also marked the rise of the â€œscript kiddiesâ€ and produced a bunch of spin offs such as Subseven, Netbus and Hack-a-Tack.  </p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ed-skoudis-lists-the-top-5-worst-attacks-of-1998-2002/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

