<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9928805</id><updated>2011-12-14T21:57:51.493-05:00</updated><title type='text'>Internet Security with Kirk</title><subtitle type='html'>Tips, tricks, etc. to make your internet experience safer.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>54</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9928805.post-114668485602916113</id><published>2006-05-03T15:33:00.000-04:00</published><updated>2006-05-03T15:45:13.320-04:00</updated><title type='text'>Blog Moving</title><content type='html'>This blog can be found in updated form at &lt;a href="http://www.cepheus.us"&gt;www.cepheus.us&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114668485602916113?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114668485602916113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114668485602916113' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114668485602916113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114668485602916113'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/05/blog-moving.html' title='Blog Moving'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114317673700268138</id><published>2006-03-23T23:51:00.000-05:00</published><updated>2006-03-24T00:05:37.230-05:00</updated><title type='text'>Internet Security Bad Day</title><content type='html'>The Internet Storm Center went to level yellow &lt;a href="http://isc.sans.org/diary.php?date=2006-03-24"&gt;today&lt;/a&gt; based on a number of fairly serious exploits, vulnerabilities, and worms roaming around the internet.  This includes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Internet Explorer exploit on the loose (what's new?) that allows for arbitrary code execution (not good).  Microsoft's original response was to disable active scripting and only surf to safe sites (to their defense, they have put out an &lt;a href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;advisory&lt;/a&gt;), which is not the easiest advice.&lt;/li&gt;&lt;li&gt;Sendmail has put out a patch and is strongly urging users to patch their mail systems.&lt;/li&gt;&lt;li&gt;Mambo/Joomla software has a worm out created to take advantages in the 1.0.7 version (the 1.0.8 patch resolves this and has been out for 3 weeks).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Windows users - keep a real eye on  this.  Today's proof  of concept is fairly benign, but can be morphed to a more vicious exploit.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114317673700268138?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114317673700268138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114317673700268138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114317673700268138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114317673700268138'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/03/internet-security-bad-day.html' title='Internet Security Bad Day'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114208962352310019</id><published>2006-03-11T10:07:00.000-05:00</published><updated>2006-03-11T10:07:03.666-05:00</updated><title type='text'>Citibank uncovers debit card fraud</title><content type='html'>&lt;a href="http://www.chicagotribune.com/technology/local/chi-0603090170mar09,1,1026651.story?coll=chi-technologylocal-hed&amp;amp;ctrack=1&amp;cset=true"&gt;Chicago Tribune | Citibank uncovers debit card fraud&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks like Citibank has had many fraudulent losses due to lax security at some PIN based retailer or processing company.  The fraudulent debit cards are being used in U.K., Canada, and Russia. &lt;br /&gt;&lt;br /&gt;This really is not an unusual location for the transactions to occur.  There is a great deal of fraud, stolen credit cards, and debit cards where either the cards get located in Eastern Europe or Central Asia.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114208962352310019?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114208962352310019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114208962352310019' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114208962352310019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114208962352310019'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/03/citibank-uncovers-debit-card-fraud.html' title='Citibank uncovers debit card fraud'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114073066878100309</id><published>2006-02-23T16:37:00.000-05:00</published><updated>2006-02-23T16:37:48.990-05:00</updated><title type='text'>Botnet Operator "Interview"</title><content type='html'>&lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/02/14/AR2006021401342_pf.html"&gt;Invasion of the Computer Snatchers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Brian Krebs from the Washington Post has posted a great interview with a hacker that operates a botnet and takes a look at the darker sides of the internet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114073066878100309?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114073066878100309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114073066878100309' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114073066878100309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114073066878100309'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/02/botnet-operator-interview.html' title='Botnet Operator &quot;Interview&quot;'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114072832917952507</id><published>2006-02-23T15:58:00.000-05:00</published><updated>2006-02-23T16:47:25.066-05:00</updated><title type='text'>Steal data, get prison time</title><content type='html'>&lt;a href="http://news.com.com/2102-7348_3-6042290.html?tag=st.util.print"&gt;Data thief gets eight years&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The price for stealing personal data from the Axciom Corp - 8 yrs.&lt;br /&gt;&lt;br /&gt;The scary part of the article is that this may not have been the first time it has happened to Axciom.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114072832917952507?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114072832917952507/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114072832917952507' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072832917952507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072832917952507'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/02/steal-data-get-prison-time.html' title='Steal data, get prison time'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114072779234126295</id><published>2006-02-23T15:49:00.000-05:00</published><updated>2006-02-23T16:45:54.013-05:00</updated><title type='text'>419 scammers caught</title><content type='html'>&lt;a href="http://news.yahoo.com/s/afp/20060222/tc_afp/netherlandsnigeriaus&amp;amp;printer=1;_ylt=AnGLv17avv6cAhKPZvN3amiOOrgF;_ylu=X3oDMTA3MXN1bHE0BHNlYwN0bWE-"&gt;12 Nigerians arrested in Holland for Internet scam&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Finally, 12 Nigerian 419 scammers have been arrested in Amsterdam.  Supposedly, they have scammed people for over $2.4 million dollars.&lt;br /&gt;&lt;br /&gt;What should be done with those dregs of society?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114072779234126295?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114072779234126295/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114072779234126295' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072779234126295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072779234126295'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/02/419-scammers-caught.html' title='419 scammers caught'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-114072639895250440</id><published>2006-02-23T15:26:00.000-05:00</published><updated>2006-02-23T16:42:58.433-05:00</updated><title type='text'>What is the liability of Financial institutions</title><content type='html'>&lt;a href="http://www.securityfocus.com/columnists/387"&gt;Strict liability for data breaches?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How much protection must be taken to protect personal data by different types of financial institutions?  This is an article about unencrypted data on a stolen laptop from a student loan firm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-114072639895250440?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/114072639895250440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=114072639895250440' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072639895250440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/114072639895250440'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/02/what-is-liability-of-financial.html' title='What is the liability of Financial institutions'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113910178090436057</id><published>2006-02-04T20:09:00.000-05:00</published><updated>2006-02-04T20:09:41.133-05:00</updated><title type='text'>Postage Is Due for Companies Sending E-Mail - New York Times</title><content type='html'>&lt;a href="http://www.nytimes.com/2006/02/05/technology/05AOL.html?ei=5089&amp;amp;en=6efa03d1cbfacf9e&amp;ex=1296795600&amp;amp;partner=rssyahoo&amp;emc=rss&amp;amp;pagewanted=all"&gt;Postage Is Due for Companies Sending E-Mail &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;AOL and Yahoo apparently are looking to send out their "heavys".  These two companies are proposing to have a preferred message system where the sender spends .25 to 1 cent per message to bypass the spam filters of their users.  Between this and phone companies like AT&amp;T (formerly SBC) and BellSouth which are looking for multitiered bandwidth solutions both from the end users, but also from the web providers.&lt;br /&gt;&lt;br /&gt;All of these models go against the initial concept of the internet and the freedom of information.  The internet was created to share information between universities, government entities, and other individuals.  Let's hope that people react and let these providers know that this tiering and preferential treatment for those that will pay the "protection" system that this will not be acceptable on the Internet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113910178090436057?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113910178090436057/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113910178090436057' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113910178090436057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113910178090436057'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/02/postage-is-due-for-companies-sending-e.html' title='Postage Is Due for Companies Sending E-Mail - New York Times'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113768712904916536</id><published>2006-01-19T11:12:00.000-05:00</published><updated>2006-01-20T21:53:16.960-05:00</updated><title type='text'>Illusions of Security</title><content type='html'>&lt;a href="http://isc.sans.org/diary.php?storyid=1052"&gt;SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In the January 18th diary entry, Swa Frantzen gives a great diatribe about the illusion (or disillusions) that some people in the industry have about security on the Internet.&lt;br /&gt;&lt;br /&gt;You never can be 100% assured of security.  The best you can do is layer your security posture so that if one level is breached, you have several layers of protection to protect your personal data.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113768712904916536?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113768712904916536/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113768712904916536' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113768712904916536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113768712904916536'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/illusions-of-security.html' title='Illusions of Security'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113717999833091635</id><published>2006-01-13T14:19:00.000-05:00</published><updated>2006-01-20T21:55:47.336-05:00</updated><title type='text'>WMF "flaw" intentional?</title><content type='html'>&lt;a href="http://www.grc.com/sn/SN-022.htm"&gt;Security Now! Transcript of Episode #22&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Steve Gibson, in his Security Now podcast with Leo Laporte, is explaining the WMF flaw and the possibility that this was an intentional backdoor put into the system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Update (1/20/2006) - In his &lt;a href="http://www.grc.com/sn/SN-023.htm"&gt;episode 23&lt;/a&gt;, Steve Gibson backs off some of the backdoor talk and further expands on the issues (or lack thereof) in the Windows 9X line of OS.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113717999833091635?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113717999833091635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113717999833091635' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113717999833091635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113717999833091635'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/wmf-flaw-intentional.html' title='WMF &quot;flaw&quot; intentional?'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113683315224252549</id><published>2006-01-09T13:59:00.000-05:00</published><updated>2006-01-09T13:59:14.566-05:00</updated><title type='text'>Is WMF Vulnerabilities dead yet?</title><content type='html'>&lt;a href="http://www.securityfocus.com/bid/16167/discuss"&gt;Microsoft Windows Graphics Rendering Engine Multiple Memory Corruption Vulnerabilities&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Announced over Bugtraq this weekend (published today), two more functions may be vulnerable to Metafile issues.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113683315224252549?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113683315224252549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113683315224252549' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113683315224252549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113683315224252549'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/is-wmf-vulnerabilities-dead-yet.html' title='Is WMF Vulnerabilities dead yet?'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113683214019849500</id><published>2006-01-09T13:42:00.000-05:00</published><updated>2006-01-09T13:42:20.406-05:00</updated><title type='text'>Internet Free Speech at Risk</title><content type='html'>&lt;a href="http://news.com.com/Create+an+e-annoyance%2C+go+to+jail/2010-1028_3-6022491.html"&gt;Create an e-annoyance, go to jail | Perspectives | CNET News.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Could your first amendment rights be at risk on the internet?  See this article about changes in federal law about "annoying" someone on the internet, you cannot do so anonymously.&lt;br /&gt;&lt;br /&gt;I wonder if what might be the first test case and the legality could be.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113683214019849500?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113683214019849500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113683214019849500' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113683214019849500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113683214019849500'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/internet-free-speech-at-risk.html' title='Internet Free Speech at Risk'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113649399184787849</id><published>2006-01-05T15:46:00.000-05:00</published><updated>2006-01-05T15:57:32.143-05:00</updated><title type='text'>Microsoft Out of Cycle Patch</title><content type='html'>&lt;a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx"&gt;Microsoft Security Bulletin Advance Notification&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Microsoft is releasing (GASP Out of Cycle) MS06-001, it's fix for the WMF file issues announced last week.  It is supposed to be available after 5pm ET.&lt;br /&gt;&lt;br /&gt;DOWNLOAD IT ASAP, even if you load Ilfak's patch.&lt;br /&gt;&lt;br /&gt;Thank you Microsoft for releasing it when testing was done, not in the regular cycle.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113649399184787849?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113649399184787849/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113649399184787849' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113649399184787849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113649399184787849'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/microsoft-out-of-cycle-patch.html' title='Microsoft Out of Cycle Patch'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113616124233759110</id><published>2006-01-01T19:06:00.000-05:00</published><updated>2006-01-03T13:20:41.876-05:00</updated><title type='text'>MetaFile Problems Continue..</title><content type='html'>The SANS Institute's Internet Storm Center (ISC) has raised the infocon level back to &lt;a href="http://isc.sans.org/diary.php?date=2006-01-01"&gt;yellow&lt;/a&gt;, based on the metafile issues that were announced December 28.  F-Secure has announced the &lt;a href="http://www.f-secure.com/weblog/"&gt;discovery&lt;/a&gt; of using .jpeg attachments in email to propogate this virus/vulnerability and the irresponsible disclosure by FRIST.&lt;br /&gt;&lt;br /&gt;There is a temporary patch that is being recommended by the ISC written by Ilfak Guilfanov that will mitigate the problem.  The patch can be downloaded at &lt;a href="http://handlers.sans.org/tliston/wmffix_hexblog14.exe"&gt;http://handlers.sans.org/tliston/wmffix_hexblog14.exe&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You are still &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;HIGHLY&lt;/span&gt; recommended to unregister the dll I listed on December 28th in addition to this patch.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 153);"&gt;&lt;span style="font-style: italic;"&gt;SECURE YOUR COMPUTER&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;.&lt;span style="color: rgb(255, 0, 0);"&gt;  &lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;I will be testing it at home and will let post if there are any problems noticed.&lt;br /&gt;&lt;br /&gt;Update - 1/3/06 - &lt;span style="color: rgb(0, 204, 204);"&gt;I have had no issue with the patch so far.  Microsoft is scheduled to release their patch on 1/10/06, depending on the results of their testing.  The patch put out by Ilfak can be easily uninstalled and should be when Microsoft releases their patch.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113616124233759110?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113616124233759110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113616124233759110' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113616124233759110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113616124233759110'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2006/01/metafile-problems-continue.html' title='MetaFile Problems Continue..'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113580865266565581</id><published>2005-12-28T17:23:00.000-05:00</published><updated>2005-12-28T22:01:27.276-05:00</updated><title type='text'>WMF File Exploits</title><content type='html'>The WMF file exploits are in the wild.  For those who don't know what they are, a &lt;i&gt;metafile&lt;/i&gt; is a collection of structures that store a picture in a device-independent format (according to &lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/gdi/metafile_7ulv.asp"&gt;Microsoft&lt;/a&gt;).   Security professionals have been hearing rumors of the vulnerabilities in these metafile for probably the next month, but now the vulnerability is in the wild.&lt;br /&gt;&lt;br /&gt;What can it do to your computer?  See this &lt;a href="http://www.websensesecuritylabs.com/images/alerts/wmf-movie.wmv"&gt;link&lt;/a&gt; to open a Windows Movie about what happens to your computer.  From what I understand, the only real way to irradicate this intrusion is to rebuild your machine.&lt;br /&gt;&lt;br /&gt;The SANS Institute has moved their infocon level to yellow, indicating an increased vulnerability level on the internet.  See the daily &lt;a href="http://isc.sans.org/diary.php?date=2005-12-28"&gt;diary&lt;/a&gt; for more information.&lt;br /&gt;&lt;br /&gt;One workaround being passed around the internet is as follows:&lt;br /&gt;---&lt;br /&gt;According to iDefense, Windows users can disable the rendering of WMF files using the following hack:&lt;br /&gt;&lt;br /&gt;1. Click on the Start button on the taskbar.&lt;br /&gt;2. Click on Run...&lt;br /&gt;3. Type "regsvr32&lt;div class="commentBody"&gt;&lt;nobr&gt; &lt;wbr&gt;&lt;/nobr&gt;/u shimgvw.dll" to disable.&lt;br /&gt;4. Click ok when the change dialog appears.&lt;br /&gt;&lt;br /&gt;iDefense notes that this workaround may interfere with certain thumbnail images loading correctly, though I have used the hack on my machine and haven't had any problems yet. The company notes that once Microsoft issues a patch, the WMF feature may be enabled again by entering the command "regsvr32 shimgvw.dll" in step three above.&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;There still may be metafiles not associated with this dll, so YMMV.&lt;br /&gt;&lt;br /&gt;Update - 2200 ET - Microsoft has confirmed much of this information with the following advisory:  &lt;a href="http://www.microsoft.com/technet/security/advisory/912840.mspx"&gt;http://www.microsoft.com/technet/security/advisory/912840.mspx&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113580865266565581?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113580865266565581/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113580865266565581' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113580865266565581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113580865266565581'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/12/wmf-file-exploits.html' title='WMF File Exploits'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113560751816165293</id><published>2005-12-26T09:31:00.000-05:00</published><updated>2005-12-26T09:31:58.190-05:00</updated><title type='text'>RED HERRING | The Business of Technology</title><content type='html'>&lt;a href="http://www.redherring.com/PrintArticle.aspx?a=15013&amp;amp;sector=Industries"&gt;RED HERRING | The Business of Technology&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Red Herring Magazine has their top security trends for 2006.  Highlights include phishing at lower levels, worms targeting businesses, and wireless security focus.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113560751816165293?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113560751816165293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113560751816165293' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113560751816165293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113560751816165293'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/12/red-herring-business-of-technology.html' title='RED HERRING | The Business of Technology'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113536418966677650</id><published>2005-12-23T13:56:00.000-05:00</published><updated>2005-12-23T13:57:30.056-05:00</updated><title type='text'>MSNBC - Let's see some ID, please</title><content type='html'>&lt;a href="http://www.msnbc.msn.com/id/10441443/page/2/print/1/displaymode/1098/"&gt;MSNBC - Let's see some ID, please&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is an article about the possible release to consumer PC that is called the Trusted Platform Module (that will be integrated with the chipset).  I have mixed feelings about this, as does the article.&lt;br /&gt;&lt;br /&gt;However, security expert Bruce Schneier has much concern in a recent &lt;a href="http://www.schneier.com/blog/archives/2005/12/idiotic_article.html"&gt;blog entry&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113536418966677650?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113536418966677650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113536418966677650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113536418966677650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113536418966677650'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/12/msnbc-lets-see-some-id-please.html' title='MSNBC - Let&apos;s see some ID, please'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113444922446933990</id><published>2005-12-12T23:47:00.000-05:00</published><updated>2005-12-12T23:47:04.470-05:00</updated><title type='text'>Tips for helping remove and or prevent spyware.</title><content type='html'>&lt;a href="http://forums.majorgeeks.com/showthread.php?t=35407"&gt;READ &amp; RUN ME FIRST Before Asking for Support - MajorGeeks Support Forums&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113444922446933990?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113444922446933990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113444922446933990' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113444922446933990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113444922446933990'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/12/tips-for-helping-remove-and-or-prevent.html' title='Tips for helping remove and or prevent spyware.'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113444905974273845</id><published>2005-12-12T23:44:00.000-05:00</published><updated>2005-12-13T00:12:51.536-05:00</updated><title type='text'>spyaxe removal</title><content type='html'>SpyAxe is a real pain when it comes to possible spyware/scumware.  Here are some sites that might help remove this PITA.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forums.techguy.org/showthread.php?t=421458"&gt;Spyaxe removal - Tech Support Guy&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.geekstogo.com/forum/index.php?showtopic=83853"&gt;Geeks to Go SpyAxe Removal&lt;/a&gt;&lt;br /&gt;&lt;a href="http://castlecops.com/postp676191.html#676191"&gt;&lt;br /&gt;CastleCops Spyaxe Removal&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113444905974273845?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113444905974273845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113444905974273845' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113444905974273845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113444905974273845'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/12/spyaxe-removal.html' title='spyaxe removal'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-113202466397023983</id><published>2005-11-14T22:17:00.000-05:00</published><updated>2005-11-14T22:17:44.003-05:00</updated><title type='text'>Pay up or lose out</title><content type='html'>&lt;a href="http://www.securityfocus.com/brief/46"&gt;Pay up or lose out&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Consumers are now beginning to be willing to pay extra for more security on important web sites, like home banking.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-113202466397023983?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/113202466397023983/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=113202466397023983' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113202466397023983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/113202466397023983'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/11/pay-up-or-lose-out.html' title='Pay up or lose out'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112916196666602301</id><published>2005-10-12T19:33:00.000-04:00</published><updated>2005-10-12T20:06:06.673-04:00</updated><title type='text'>Microsoft Patch Cycle</title><content type='html'>Time to remember to patch your Windows PC's.  Microsoft released its "Black Tuesday" &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms05-oct.mspx"&gt;Advisory&lt;/a&gt; for October, with 9 patches (8 for a client PC).  Don't forget to patch your machines.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112916196666602301?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112916196666602301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112916196666602301' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112916196666602301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112916196666602301'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/10/microsoft-patch-cycle.html' title='Microsoft Patch Cycle'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112852793999056703</id><published>2005-10-05T11:58:00.000-04:00</published><updated>2005-10-05T11:58:59.990-04:00</updated><title type='text'>National Cyber Security Awareness Month.</title><content type='html'>October is National Cyber Security Awarness month. In this digital age, it is great to have as much information to keep you safe. Check out the following site for more information on a joint site with a non-profit site and DHS (or at least the cyberwing).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.staysafeonline.info/"&gt;Stay Safe Online. National Cyber Security Alliance&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112852793999056703?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112852793999056703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112852793999056703' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112852793999056703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112852793999056703'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/10/national-cyber-security-awareness.html' title='National Cyber Security Awareness Month.'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112852788435383664</id><published>2005-10-05T11:57:00.000-04:00</published><updated>2005-10-05T12:00:33.400-04:00</updated><title type='text'>California phish fighting</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;b&gt;California Enacts Nation’s First Anti-Phishing Law&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;California Governor, &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;Arnold&lt;/st1:place&gt;&lt;/st1:City&gt; Schwarzenegger signed a bill last week making Internet phishing identity theft scams punishable by law.&lt;/p&gt;   &lt;p class="MsoNormal"&gt; &lt;/p&gt;   &lt;p class="MsoNormal"&gt;The bill is the first of its kind in the &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;United States&lt;/st1:place&gt;&lt;/st1:country-region&gt; and makes phishing a civil offense.&lt;/p&gt;   &lt;p class="MsoNormal"&gt; &lt;/p&gt;   &lt;p class="MsoNormal"&gt;Phishing is the practice of getting people to divulge personal information via email by representing oneself as a business without the approval or authority of the business. Phishing usually involves the use of legitimate banks, retailers, and financial institutions to convince recipients of bogus emails to respond.&lt;/p&gt;   &lt;p class="MsoNormal"&gt; &lt;/p&gt;   &lt;span style="font-size: 12pt; font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;Under the new law, victims may seek to recover actual damages or $500,000 for each violation, depending upon which is greater&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112852788435383664?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112852788435383664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112852788435383664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112852788435383664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112852788435383664'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/10/california-phish-fighting.html' title='California phish fighting'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112750741354563079</id><published>2005-09-26T16:30:00.000-04:00</published><updated>2005-09-26T09:04:00.563-04:00</updated><title type='text'>Consumers Insist Financial Institutions Remain Vigilant In Protecting Their Privacy | eds.com</title><content type='html'>&lt;a href="http://www.eds.com/news/news.aspx?news_id=2596"&gt;Consumers Insist Financial Institutions Remain Vigilant In Protecting Their Privacy | eds.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A recent study put out by EDS shows likely implications if financial institutions are cavalier with their security and safety of private information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112750741354563079?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112750741354563079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112750741354563079' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112750741354563079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112750741354563079'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/09/consumers-insist-financial.html' title='Consumers Insist Financial Institutions Remain Vigilant In Protecting Their Privacy | eds.com'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112775295561605946</id><published>2005-09-26T12:42:00.000-04:00</published><updated>2005-09-26T12:42:36.616-04:00</updated><title type='text'>GonzoBanker - Article</title><content type='html'>&lt;a href="http://www.gonzobanker.com/article.aspx?Article=250"&gt;GonzoBanker - Article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the Cornerstone Advisor, how one bank was able to fight and bring down a phishing site within 1 day.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112775295561605946?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112775295561605946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112775295561605946' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112775295561605946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112775295561605946'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/09/gonzobanker-article.html' title='GonzoBanker - Article'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112567018515114747</id><published>2005-09-02T10:09:00.000-04:00</published><updated>2005-09-02T10:09:45.156-04:00</updated><title type='text'>PhishFighting.com - Fight back and take down the Phishers.</title><content type='html'>&lt;a href="http://www.phishfighting.com/"&gt;PhishFighting.com - Fight back and take down the Phishers.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is an interesting site that is trying to feed as much false information to phishers.  I'm going to give it a try for the next phishing email I get.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112567018515114747?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112567018515114747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112567018515114747' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112567018515114747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112567018515114747'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/09/phishfightingcom-fight-back-and-take.html' title='PhishFighting.com - Fight back and take down the Phishers.'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112566753373764048</id><published>2005-09-02T09:25:00.000-04:00</published><updated>2005-09-02T09:25:33.770-04:00</updated><title type='text'>CastleCops - New Research Reveals Men More Likely to Fall Prey to Online Scams</title><content type='html'>Are men smarter online than women?  A recent &lt;a href="http://castlecops.com/modules.php?name=News&amp;file=print&amp;sid=6207"&gt;study&lt;/a&gt; says no, even though men were more aware of the issues.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112566753373764048?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112566753373764048/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112566753373764048' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112566753373764048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112566753373764048'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/09/castlecops-new-research-reveals-men.html' title='CastleCops - New Research Reveals Men More Likely to Fall Prey to Online Scams'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112558630118227500</id><published>2005-09-01T10:51:00.000-04:00</published><updated>2005-09-01T10:53:27.843-04:00</updated><title type='text'>TIME.com Print Page: TIME Magazine -- The Invasion of the Chinese Cyberspies (And the Man Who Tried to Stop Them)</title><content type='html'>The Chinese are coming!!!  Time had a very interesting &lt;a href="http://www.time.com/time/magazine/printout/0,8816,1098961,00.html"&gt;article&lt;/a&gt; about an investigation about the defense of some governement research facility.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112558630118227500?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112558630118227500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112558630118227500' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112558630118227500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112558630118227500'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/09/timecom-print-page-time-magazine.html' title='TIME.com Print Page: TIME Magazine -- The Invasion of the Chinese Cyberspies (And the Man Who Tried to Stop Them)'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112430066515864052</id><published>2005-08-17T13:44:00.000-04:00</published><updated>2005-08-17T13:44:25.176-04:00</updated><title type='text'>CNN.com - Worm strikes down Windows 2000 systems - Aug 16, 2005</title><content type='html'>&lt;a href="http://www.cnn.com/2005/TECH/internet/08/16/computer.worm/index.html"&gt;CNN.com - Worm strikes down Windows 2000 systems - Aug 16, 2005&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The sad part about this is that the patch to help prevent this had been out a week.  And a simple router change would prevent much of the traffic.&lt;br /&gt;&lt;br /&gt;One minor part - SANS is not based in Jacksonville, FL, just Johannes.  It would be nice to get most of the information right, but this is CNN.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112430066515864052?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112430066515864052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112430066515864052' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112430066515864052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112430066515864052'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/08/cnncom-worm-strikes-down-windows-2000.html' title='CNN.com - Worm strikes down Windows 2000 systems - Aug 16, 2005'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112389917469532517</id><published>2005-08-12T22:11:00.000-04:00</published><updated>2005-08-12T22:12:54.696-04:00</updated><title type='text'>User Education Sites</title><content type='html'>You have heard all your life that education is important, and that is especially  true online. You can learn about how to better protect yourself by learning what  the proverbial bad guys are trying to do to get your information. There are  several good sites out there that try to educate the normal user on what threats  to your information exist and how you can protect yourself. These newsletters  attempt to take possibly technical information and make it readable to the  normal internet user. Such sites (and their associated newsletters) are as  follows:&lt;br /&gt;&lt;br /&gt;US-CERT - The United States Computer Emergency Readiness Team  (US-CERT) is a partnership between the Department of Homeland Security and the  public and private sectors. This partnership has allowed a furthering of  computer security both within the federal government and with home users as they  publish threats, best practices, and other education materials. Two pages within  the site have great links for educating yourself about the internet in general  and the threats that have materialized. These sites are &lt;a title="http://www.us-cert.gov/cas/tips/index.html" href="http://www.us-cert.gov/cas/tips/index.html" target="_blank"&gt;http://www.us-cert.gov/cas/tips/index.html &lt;/a&gt;and &lt;a title="http://www.us-cert.gov/nav/nt01/" href="http://www.us-cert.gov/nav/nt01/" target="_blank"&gt;http://www.us-cert.gov/nav/nt01/. &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SANS Institute -  This computer security think tank has a philosophy of educating both the  technical and non-technical with securing the internet. The &lt;a title="http://www.sans.org/newsletters/ouch/index.php" href="http://www.sans.org/newsletters/ouch/index.php" target="blank"&gt;Ouch!  newsletter &lt;/a&gt;is a security awareness document that shows you how to avoid  phishing, viruses, and other malware (bad programs).&lt;br /&gt;&lt;br /&gt;Knowledge is power.  The more you educate yourself online, the better (and safer) your internet  experience will be.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112389917469532517?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112389917469532517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112389917469532517' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112389917469532517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112389917469532517'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/08/user-education-sites.html' title='User Education Sites'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112368607437575002</id><published>2005-08-10T11:01:00.000-04:00</published><updated>2005-08-12T22:11:55.073-04:00</updated><title type='text'>Security still underfunded</title><content type='html'>&lt;a href="http://www.securityfocus.com/print/columnists/345"&gt;Security still underfunded&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Why is computer security still a challenge in the world.  One of the leading reasons still happens to be user education (which is always a driving factor).  In addition, it is still a struggle for IT departments to convince the CXO's of companies of the real ROI of computer security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112368607437575002?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112368607437575002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112368607437575002' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112368607437575002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112368607437575002'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/08/security-still-underfunded.html' title='Security still underfunded'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112361531393188762</id><published>2005-08-09T15:21:00.000-04:00</published><updated>2005-08-12T22:09:46.333-04:00</updated><title type='text'>Antispyware firm warns of massive ID theft ring - Computerworld</title><content type='html'>&lt;a href="http://www.computerworld.com/securitytopics/security/story/0,10801,103737,00.html"&gt;Antispyware firm warns of massive ID theft ring - Computerworld&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sunbelt software happens to stumble on a site that had accounts for at least 50 financial institutions.  Spyware had been installed on various PC's around the world and reported back to this web site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112361531393188762?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112361531393188762/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112361531393188762' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112361531393188762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112361531393188762'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/08/antispyware-firm-warns-of-massive-id.html' title='Antispyware firm warns of massive ID theft ring - Computerworld'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112317428987292742</id><published>2005-08-04T12:51:00.000-04:00</published><updated>2005-08-04T12:51:29.890-04:00</updated><title type='text'>Worm hole found in Windows 2000 | CNET News.com</title><content type='html'>&lt;a href="http://news.com.com/2102-1002_3-5817400.html?tag=st.util.print"&gt;Worm hole found in Windows 2000 | CNET News.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Eeye has announced a second Microsoft Vulnerability this week (not much information), this one being "wormable" and at the core of the TCP/IP implementation (from what I understand).&lt;br /&gt;&lt;br /&gt;Worth keeping an eye on it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112317428987292742?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112317428987292742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112317428987292742' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112317428987292742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112317428987292742'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/08/worm-hole-found-in-windows-2000-cnet.html' title='Worm hole found in Windows 2000 | CNET News.com'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112269256225206551</id><published>2005-07-29T22:18:00.000-04:00</published><updated>2005-07-29T23:02:42.256-04:00</updated><title type='text'>Cisco Silencing former ISS employee about possible problems with internet routers</title><content type='html'>At the Black Hat 2005 conference, former ISS employee Michael Lynn was to discuss the possible exploits of Cisco routers.  The presentation was pulled by the Black Hat Organizers (particularly Jeff Moss) under threat of lawsuit by Cisco and ISS.  Furthermore, they are in the process of silencing all those that might have had a mirror of the presentation (see the following &lt;a href="http://www.infowarrior.org/users/rforno/lynn-cisco.pdf"&gt;infowarrior&lt;/a&gt; site), which basically they threatened the site operator to pull the information or face a suit himself.  As the Internet Storm Center so elequently put it -&lt;br /&gt;&lt;br /&gt;&lt;h2 style="color: rgb(255, 102, 0);"&gt; Lynn's Cat is Out of The Bag &lt;/h2&gt; &lt;span style="color: rgb(255, 102, 0);"&gt; While Black Hat may have torn out paper pages, the PDF of Michael Lynn's presentation, "The Holy Grail: Cisco IOS Shellcode and Exploitation Techniques," lives on. Given the amount of attention this thing has gotten, mirrors and links to it are now all over the place. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Shame on Cisco and ISS for their conduct to a security researcher that was discussing a possible issue that he had discovered in working for ISS that can affect much of the core of the internet.  There was to be nothing in there to tell the black hats that might be attending the conference before DEFCON 2005 how to exploit it (basically, they would have to do the same research that Lynn did).  Many top proponents of full disclosure (like &lt;a href="http://www.schneier.com/blog/"&gt;Bruce Schneier&lt;/a&gt;) have railed on these companies for the way they handled the situation.&lt;br /&gt;&lt;br /&gt;What is Cisco trying to hide...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112269256225206551?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112269256225206551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112269256225206551' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112269256225206551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112269256225206551'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/07/cisco-silencing-former-iss-employee.html' title='Cisco Silencing former ISS employee about possible problems with internet routers'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112195289805570078</id><published>2005-07-21T09:33:00.000-04:00</published><updated>2005-07-21T09:34:58.066-04:00</updated><title type='text'>What may happen if you don't keep up your server patches</title><content type='html'>This &lt;a href="http://eks0.free.fr/whax-demos/?f=Whoppix-ssh-dcom_config.xml"&gt;site&lt;/a&gt; has about a 10 minute "demo" on how someone may take control of your server (in this case IIS) and gain control to your internal network if you fail to keep up on your vulnerability management.&lt;br /&gt;&lt;br /&gt;Scary Stuff.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112195289805570078?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112195289805570078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112195289805570078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112195289805570078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112195289805570078'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/07/what-may-happen-if-you-dont-keep-up.html' title='What may happen if you don&apos;t keep up your server patches'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-112147025466758771</id><published>2005-07-15T19:30:00.000-04:00</published><updated>2005-07-15T19:30:54.680-04:00</updated><title type='text'>A Chronology of Data Breaches Since the ChoicePoint Incident</title><content type='html'>&lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;A Chronology of Data Breaches Since the ChoicePoint Incident&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a very interesting list of all the reported security breaches since the announcement of Choice Point's problems this Feburary.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-112147025466758771?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/112147025466758771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=112147025466758771' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112147025466758771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/112147025466758771'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/07/chronology-of-data-breaches-since.html' title='A Chronology of Data Breaches Since the ChoicePoint Incident'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111940194225686756</id><published>2005-06-21T20:59:00.000-04:00</published><updated>2005-07-21T09:35:36.976-04:00</updated><title type='text'>Security headache for CVS customers?</title><content type='html'>&lt;a href="http://news.com.com/2061-10789_3-5756469.html?part=rss&amp;amp;tag=feed&amp;amp;subj=news"&gt;Security headache for CVS customers?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;According to this blog, CVS is currently pulling access to their customer loyalty card (ExtraCare) via the internet because of a security hole. CVS has 50 million of these cards out all over.&lt;br /&gt;&lt;br /&gt;Not anything like credit cards, but still an issue none the less.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111940194225686756?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111940194225686756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111940194225686756' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111940194225686756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111940194225686756'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/06/security-headache-for-cvs-customers.html' title='Security headache for CVS customers?'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111932670024743012</id><published>2005-06-21T00:05:00.000-04:00</published><updated>2005-06-21T00:05:00.260-04:00</updated><title type='text'>Lost Credit Data Improperly Kept, Company Admits - New York Times</title><content type='html'>&lt;a href="http://www.nytimes.com/2005/06/20/technology/20credit.html?ei=5090&amp;amp;en=05e9ba47e5ac4543&amp;amp;ex=1276920000&amp;amp;adxnnl=0&amp;amp;partner=rssuserland&amp;amp;emc=rss&amp;amp;adxnnlx=1119304581-L6AR0bVV+ZIDE03EQJzx5g&amp;amp;pagewanted=print"&gt;Lost Credit Data Improperly Kept, Company Admits - New York Times&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently, there is more information about the CardSystems had not followed Visa and MasterCard Regulation in storing the data that was exposed.  This included names, account numbers, expiration dates, and security codes.  It also appears that a trojan program entered CardSystem's network.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111932670024743012?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111932670024743012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111932670024743012' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111932670024743012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111932670024743012'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/06/lost-credit-data-improperly-kept.html' title='Lost Credit Data Improperly Kept, Company Admits - New York Times'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111913687324593341</id><published>2005-06-18T19:21:00.000-04:00</published><updated>2005-06-18T19:21:13.253-04:00</updated><title type='text'>MasterCard: 68,000 Customers at High Risk - Yahoo! News</title><content type='html'>&lt;a href="http://news.yahoo.com/news?tmpl=story&amp;amp;cid=509&amp;amp;e=4&amp;amp;u=/ap/20050618/ap_on_bi_ge/credit_cards_breach"&gt;MasterCard: 68,000 Customers at High Risk - Yahoo! News&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;An update to the story...of the 40 million cards exposed by CardSystems Solutions, about 13.9 million accounts were MasterCard.  The rest are Visa, Discover, and Amex (even though Amex says this is to a lesser extent).  MasterCard says that of these 13.9 cards, about 68,000 are a higher risk.  A quick calculation (assuming the rate of the 1st third of the cards) yields about 200k cards being higher risk.  I wonder what they consider a higher level of risk. &lt;br /&gt;&lt;br /&gt;The card compromise affects both credit and debit cards, so I can forsee a great problem with people's checking accounts.&lt;br /&gt;&lt;br /&gt;From what I also understand, the compromise occured when a trojan was installed on the internal network.  For sensitive data, one would think they would be more diligent in preventing this situation from occurring.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111913687324593341?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111913687324593341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111913687324593341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111913687324593341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111913687324593341'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/06/mastercard-68000-customers-at-high.html' title='MasterCard: 68,000 Customers at High Risk - Yahoo! News'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111904268969065423</id><published>2005-06-17T17:11:00.000-04:00</published><updated>2005-06-20T14:20:28.646-04:00</updated><title type='text'>MasterCard Cites Security Breach</title><content type='html'>&lt;a href="http://www.thestreet.com/_googlen/stocks/banking/10228650.html?cm_ven=GOOGLEN&amp;cm_cat=FREE&amp;amp;cm_ite=NA"&gt;MasterCard Cites Security Breach&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently, one of MasterCard's processors had a security breach, exposing 40 million credit and debit cards. Many financial institutions will have a lot of effort replacing these cards. The need for data security is quite evident these days as various companys are playing a very bad game of can you top this.&lt;br /&gt;&lt;br /&gt;Another write up can be found at &lt;a href="http://tinyurl.com/chk3w"&gt;SecurityFocus.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111904268969065423?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111904268969065423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111904268969065423' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111904268969065423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111904268969065423'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/06/mastercard-cites-security-breach.html' title='MasterCard Cites Security Breach'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111852755858024207</id><published>2005-06-11T18:05:00.000-04:00</published><updated>2005-06-11T18:05:58.596-04:00</updated><title type='text'>Threatchaos.com Gartner presentation</title><content type='html'>Richard Stiennon had a very interesting presenation at the Gartner conference this week.  He is the VP of Threat Research at Webroot Software.  The presentation is in the blog of his below.  It basically looks at what he sees as the potential spyware threat for the coming year.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.threatchaos.com/"&gt;Threatchaos.com&lt;/a&gt;: "Latest ThreatChaos Presentation&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111852755858024207?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111852755858024207/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111852755858024207' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111852755858024207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111852755858024207'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/06/threatchaoscom-gartner-presentation.html' title='Threatchaos.com Gartner presentation'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111688744290687487</id><published>2005-05-23T18:30:00.000-04:00</published><updated>2005-05-23T18:30:42.920-04:00</updated><title type='text'>Data at Bank of America, Wachovia, others compromised - May. 23, 2005</title><content type='html'>&lt;a href="http://money.cnn.com/2005/05/23/news/fortune500/bank_info/index.htm"&gt;Data at Bank of America, Wachovia, others compromised - May. 23, 2005&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Apparently, 4 Banks sold information to a collection fraudster and at least 670,000 customer infomation was stolen.  Not good for the banks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111688744290687487?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111688744290687487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111688744290687487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111688744290687487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111688744290687487'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/05/data-at-bank-of-america-wachovia.html' title='Data at Bank of America, Wachovia, others compromised - May. 23, 2005'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111541070718350024</id><published>2005-05-06T16:18:00.000-04:00</published><updated>2005-05-20T20:18:45.386-04:00</updated><title type='text'>NewsFactor Network - Internet Life - Web Survey Examines 'Pharming' Trend</title><content type='html'>&lt;a href="http://www.newsfactor.com/story.xhtml?story_id=0120013P54S0"&gt;NewsFactor Network - Internet Life - Web Survey Examines 'Pharming' Trend&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111541070718350024?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111541070718350024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111541070718350024' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541070718350024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541070718350024'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/05/newsfactor-network-internet-life-web.html' title='NewsFactor Network - Internet Life - Web Survey Examines &apos;Pharming&apos; Trend'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111541052977157789</id><published>2005-05-06T16:15:00.000-04:00</published><updated>2005-05-20T20:19:56.740-04:00</updated><title type='text'>NewsFactor Network - Tech Trends - Blogs: The Next Hot CRM Strategy</title><content type='html'>&lt;a href="http://www.newsfactor.com/news/Blogs--The-Next-Hot-CRM-Strategy/story.xhtml?story_id=012000008T8C"&gt;NewsFactor Network - Tech Trends - Blogs: The Next Hot CRM Strategy&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This article discusses how people might be using blogs to help maintain better customer service.  Not necessarily a security issue, but an interesting trend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111541052977157789?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111541052977157789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111541052977157789' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541052977157789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541052977157789'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/05/newsfactor-network-tech-trends-blogs.html' title='NewsFactor Network - Tech Trends - Blogs: The Next Hot CRM Strategy'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111541035348009876</id><published>2005-05-06T16:12:00.000-04:00</published><updated>2005-05-20T20:18:26.486-04:00</updated><title type='text'>NewsFactor Network - Enterprise Security - Phishers Using New Methods To Steal User Information</title><content type='html'>&lt;a href="http://www.newsfactor.com/story.xhtml?story_id=012000008T6C"&gt;NewsFactor Network - Enterprise Security - Phishers Using New Methods To Steal User Information&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111541035348009876?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111541035348009876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111541035348009876' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541035348009876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111541035348009876'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/05/newsfactor-network-enterprise-security.html' title='NewsFactor Network - Enterprise Security - Phishers Using New Methods To Steal User Information'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111533981320392639</id><published>2005-05-05T20:36:00.000-04:00</published><updated>2005-05-05T20:36:53.210-04:00</updated><title type='text'>TSA</title><content type='html'>Two articles below on how the TSA will begin to have airlines transmit information from confirmed passengers to check against terrorist lists, etc. The second article mentions that the TSA would also be obtaining credit card information. With the woeful history of some departments and internet security, one might wonder if that is such a great idea. And...why would the government need my credit card number????? Inquiring minds would like to know.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.usatoday.com/travel/news/2005-05-03-travelers-screening_x.htm"&gt;USATODAY.com - U.S. asks for more data on travelers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://tinyurl.com/dt4gz"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;AP Report on TSA Request&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111533981320392639?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111533981320392639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111533981320392639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111533981320392639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111533981320392639'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/05/tsa.html' title='TSA'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-111111421884430920</id><published>2005-04-11T21:50:00.000-04:00</published><updated>2005-04-12T19:25:25.336-04:00</updated><title type='text'>InfoWorld: Holy Father on rootkit writing for fun, profit: March 16, 2005: By : APPLICATION_DEVELOPMENT : NETWORKING : SECURITY</title><content type='html'>Why do hackers do what they do?  See the following article from InfoWorld with an interview with the Hacker Defender Rootkit.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.infoworld.com/article/05/03/16/HNholyfather_1.html"&gt;InfoWorld: Holy Father on rootkit writing for fun, profit: March 16, 2005: By : APPLICATION_DEVELOPMENT : NETWORKING : SECURITY&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-111111421884430920?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/111111421884430920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=111111421884430920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111111421884430920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/111111421884430920'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/04/infoworld-holy-father-on-rootkit.html' title='InfoWorld: Holy Father on rootkit writing for fun, profit: March 16, 2005: By : APPLICATION_DEVELOPMENT : NETWORKING : SECURITY'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110877610920288815</id><published>2005-02-18T20:02:00.000-05:00</published><updated>2005-02-18T20:21:49.203-05:00</updated><title type='text'>Interesting Security Issues to watch</title><content type='html'>Two interesting stories dealing with companies and consumers reached the surface this week.  The first has to deal with Choicepoint PRG, which is a company that is generally used by companies to do background checks on prospective employees among other features.  Apparently, they opened business accounts to members of the criminal element, which allowed them to access a ton of information about people.  Choicepoint has notified by letter 35,000 customers in California (as required by California Statue) about the possible compromise of their data.  Some estimates say that as many as 110,000 people might be affected nationwide.  There has been over 700 cases of identity theft because of this data compromise.  The Reuters article can be found &lt;a href="http://www.reuters.com/printerFriendlyPopup.jhtml?type=topNews&amp;storyID=7640556"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The other article comes from the "&lt;a href="http://www.theregister.co.uk/2005/02/08/e-banking_trojan_lawsuit/print.html"&gt;You have to be kidding me file&lt;/a&gt;."  A man in South Florida is suing Bank of America for the $90,000 in losses he incurred because of a trojan program on his computer.  The trojan had a keystroke component, which allowed the program creator to gain passwords and to wire monies to Latvia.  The core of the case is that B of A did not inform customers about the possibilities that this trojan may affect them.  At what point is a company doing business with you responsible for disclosing the possibility that a security threat (worm, virus, or trojan) can put your data at risk, especially if the threat lives on your computer.  Businesses have plenty of threats to combat without making sure that you are running anti-spyware, anti-virus, and a firewall on your personal computer.   A loss by B of A in this matter might limit businesses interest in using the internet as a mode of commerce, as no one will want to accept the risk of some moron who can't keep malware off of his computer suing them for not telling him/her he should be running personal computer security software.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110877610920288815?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110877610920288815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110877610920288815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110877610920288815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110877610920288815'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/02/interesting-security-issues-to-watch.html' title='Interesting Security Issues to watch'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110851269184998224</id><published>2005-02-15T18:58:00.000-05:00</published><updated>2005-02-15T19:11:31.853-05:00</updated><title type='text'>Gates talking about the Security Future at RSA Conference</title><content type='html'>Bill Gates said some interesting things at his &lt;a href="http://tinyurl.com/4knyd"&gt;keynote address&lt;/a&gt; at this years RSA conference.&lt;br /&gt;&lt;br /&gt;Some of the interesting notes:&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;Microsoft will keep the personal edition of its Microsoft Antispyware free.&lt;/li&gt;   &lt;li&gt;Internet Explorer 7 will be in beta later this summer and will be available for XP SP2 and Longhorn (when it comes out) users with a valid Microsoft License.&lt;/li&gt;   &lt;li&gt;Windows Update will become much more (Microsoft Update), which will incorporate a wider group of Microsoft products&lt;/li&gt;   &lt;li&gt;More training programs.&lt;/li&gt; &lt;/ul&gt; We'll see how this helps internet security.  The first and the third initiatives will be the more important when they come out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110851269184998224?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110851269184998224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110851269184998224' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110851269184998224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110851269184998224'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/02/gates-talking-about-security-future-at.html' title='Gates talking about the Security Future at RSA Conference'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110808026528326332</id><published>2005-02-10T19:01:00.000-05:00</published><updated>2005-02-10T19:04:25.283-05:00</updated><title type='text'>Symantec joins Microsoft in Patching</title><content type='html'>Symantec announces a critical flaw in its security products that can lead to compromise.  The announcement is &lt;a href="http://tinyurl.com/4wbux"&gt;here&lt;/a&gt;.  Make sure you are patching this as you take care of your &lt;a href="http://windowsupdate.microsoft.com"&gt;Microsoft&lt;/a&gt; products.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110808026528326332?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110808026528326332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110808026528326332' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110808026528326332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110808026528326332'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/02/symantec-joins-microsoft-in-patching.html' title='Symantec joins Microsoft in Patching'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110754167185107532</id><published>2005-02-04T13:30:00.000-05:00</published><updated>2005-02-04T13:27:51.853-05:00</updated><title type='text'>Busy Microsoft Patching Month</title><content type='html'>Microsoft is releasing &lt;a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx"&gt;13 patches&lt;/a&gt; on Tuesday.  Make sure your automated updates are working.  You will also likely have to visit Microsoft Office's &lt;a href="http://www.microsoft.com/office"&gt;site&lt;/a&gt; as well for a patch.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110754167185107532?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110754167185107532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110754167185107532' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110754167185107532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110754167185107532'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/02/busy-microsoft-patching-month.html' title='Busy Microsoft Patching Month'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110570729571807124</id><published>2005-01-14T07:51:00.000-05:00</published><updated>2005-01-14T07:54:55.716-05:00</updated><title type='text'>A reason to be aggressive against computer security threats</title><content type='html'>The Internet culture may be beginning to change.  There is a story in the &lt;a href="http://tinyurl.com/53r8u"&gt;LA Times&lt;/a&gt; where some people are starting to "unplug" from the Internet because of spam, spyware, and virus concerns.  It is imperative that we continue to fight and win against malicious code in order to continue to grow the usefulness of this incredible medium.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110570729571807124?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110570729571807124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110570729571807124' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110570729571807124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110570729571807124'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/01/reason-to-be-aggressive-against.html' title='A reason to be aggressive against computer security threats'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110505681331967340</id><published>2005-01-06T19:13:00.000-05:00</published><updated>2005-01-12T14:52:21.603-05:00</updated><title type='text'>Microsoft Announces Beta for Anti-Spyware program</title><content type='html'>Microsoft is announcing their beta program for the "new" AntiSpyware program....which they obtained from buying Giant Software. I have set it up on my home PC and it seems to be pretty good so far. Quite customizable, and even found possible spyware that &lt;a href="http://tinyurl.com/5qh5b"&gt;Spybot S&amp;amp;D&lt;/a&gt; has not found over the years I have used it. I know that Microsoft is planning to offer a subscription service with it, but between the 2 programs mentioned, it might be a pretty good combo. We'll have to see how the beta goes. Download at:&lt;br /&gt;&lt;a href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Microsoft Windows AntiSpyware (Beta) Home&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110505681331967340?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110505681331967340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110505681331967340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110505681331967340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110505681331967340'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/01/microsoft-announces-beta-for-anti.html' title='Microsoft Announces Beta for Anti-Spyware program'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9928805.post-110479824932858604</id><published>2005-01-03T19:20:00.000-05:00</published><updated>2005-01-03T19:24:09.330-05:00</updated><title type='text'>Auditor Toolkit</title><content type='html'>I am testing a version of Linux that is called the &lt;a href="http://remote-exploit.org/?page=auditor"&gt;Auditor Toolkit&lt;/a&gt;.   There is an article on &lt;a href="http://tinyurl.com/3nzx5"&gt;Security Focus&lt;/a&gt; that refers to it dealing with WEP insecurities.  I am intrigued by this and will let you know what I think about the product.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9928805-110479824932858604?l=security-cepheus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://security-cepheus.blogspot.com/feeds/110479824932858604/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9928805&amp;postID=110479824932858604' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110479824932858604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9928805/posts/default/110479824932858604'/><link rel='alternate' type='text/html' href='http://security-cepheus.blogspot.com/2005/01/auditor-toolkit.html' title='Auditor Toolkit'/><author><name>Kirk</name><uri>http://www.blogger.com/profile/12970766135910834457</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://www.floridabeckers.us/a/Kirk.jpg'/></author><thr:total>0</thr:total></entry></feed>
