<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IT Security Attaché &#187; Online Articles for Discussion</title>
	<atom:link href="http://theitsecurityattache.com/blogs/category/online-articles-for-discussion/feed/" rel="self" type="application/rss+xml" />
	<link>http://theitsecurityattache.com/blogs</link>
	<description>His life, profiles, work, aspirations, agenda and schedule.</description>
	<lastBuildDate>Mon, 26 Jul 2010 22:05:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>World&#8217;s nastiest trojan fools AV software</title>
		<link>http://theitsecurityattache.com/blogs/2009/09/20/worlds-nastiest-trojan-fools-av-software/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/09/20/worlds-nastiest-trojan-fools-av-software/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 04:55:47 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT News Articles of Interest]]></category>
		<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=804</guid>
		<description><![CDATA[World&#8217;s nastiest trojan fools AV software
Pounces on banking passwords
By Dan Goodin in San Francisco &#124; http://www.theregister.co.uk/2009/09/18/zeus_evades_detection/
Posted in Anti-Virus, 18th September 2009 00:37 GMT
Watch the Application Security Regcast, right here
One of the world&#8217;s nastiest password-stealing trojans evades detection by the majority PCs running anti-virus programs, according to a study that examined 10,000 machines.
Zeus, a stealthy piece of [...]]]></description>
			<content:encoded><![CDATA[<p><strong>World&#8217;s nastiest trojan fools AV software</strong></p>
<p>Pounces on banking passwords</p>
<p>By <a title="Send email to the author" href="http://forms.theregister.co.uk/mail_author/?story_url=/2009/09/18/zeus_evades_detection/"><strong>Dan Goodin in San Francisco</strong></a> | <a href="http://www.theregister.co.uk/2009/09/18/zeus_evades_detection/">http://www.theregister.co.uk/2009/09/18/zeus_evades_detection/</a></p>
<p>Posted in <a href="http://www.theregister.co.uk/security/virus/">Anti-Virus</a>, 18th September 2009 00:37 GMT</p>
<p><a href="http://go.theregister.com/tl/204/-913/-?td=wptl204">Watch the Application Security Regcast, right here</a></p>
<p>One of the world&#8217;s nastiest password-stealing trojans evades detection by the majority PCs running anti-virus programs, according to a study that examined 10,000 machines.</p>
<p>Zeus, a stealthy piece of malware that sits on a PC and waits for users to log in to bank websites, is detected just 23 per cent of time by AV programs, according to the <a href="http://www.trusteer.com/files/Zeus_and_Antivirus.pdf" target="_blank">study (PDF)</a> (http://www.trusteer.com/files/Zeus_and_Antivirus.pdf) released by security firm Trusteer. Even AV programs with up-to-date malware signatures were unable to identify the infection a majority of the time, the authors said.</p>
<p><noscript></noscript>Zeus, which also goes by the name Zbot and PRG, escapes detection using sophisticated techniques such as root-kit technology, the Trusteer report said. The company is able to detect it by examining the fingerprint Zeus leaves when it penetrates an infected PC&#8217;s browser process.</p>
<p>A recent report estimated that Zeus is the No. 1 trojan, with 3.6 million infections in the US alone, or about 1 per cent of the installed base of PCs. Trusteer&#8217;s study, which found Zeus accounted for 44 per cent of the banking malware infections, was consistent with that finding. After sneaking onto a PC, it sits quietly in the background until a user logs on to a financial website. It then sends the login credentials to a remote server in real time, sometimes by <a href="http://www.theregister.co.uk/2009/08/27/zeus_adopts_instant_messaging/">use of instant messaging</a> (http://www.theregister.co.uk/2009/08/27/zeus_adopts_instant_messaging/) programs.</p>
<p>Of Zeus-infected machines, about 31 per cent don&#8217;t run AV at all and 14 percent run AV that&#8217;s out of date. The remaining 55 per cent had AV programs that were up to date. ®</p>
<p><strong>Related stories</strong></p>
<p><a title="Virus and scareware writer hunt" href="http://www.theregister.co.uk/2009/09/18/microsoft_legalaction_malvertising/">Malvertisers slapped by Microsoft lawsuits</a> (18 September 2009)</p>
<p><a href="http://www.theregister.co.uk/2009/09/18/microsoft_legalaction_malvertising/">http://www.theregister.co.uk/2009/09/18/microsoft_legalaction_malvertising/</a></p>
<p> </p>
<p><a title="Resident evil" href="http://www.theregister.co.uk/2009/09/15/malware_persistence/">Malware lingers months on infected PCs</a> (15 September 2009)</p>
<p><a href="http://www.theregister.co.uk/2009/09/15/malware_persistence/">http://www.theregister.co.uk/2009/09/15/malware_persistence/</a></p>
<p> </p>
<p><a title="Instant gratification" href="http://www.theregister.co.uk/2009/08/27/zeus_adopts_instant_messaging/">Trojan zaps banking credentials via IM</a> (27 August 2009)</p>
<p><a href="http://www.theregister.co.uk/2009/08/27/zeus_adopts_instant_messaging/">http://www.theregister.co.uk/2009/08/27/zeus_adopts_instant_messaging/</a></p>
<p> </p>
<p><a title="Ringo forgotten again" href="http://www.theregister.co.uk/2009/04/08/macca_malware_attack/">Hackers pwn Macca site with banking malware</a> (8 April 2009)</p>
<p><a href="http://www.theregister.co.uk/2009/04/08/macca_malware_attack/">http://www.theregister.co.uk/2009/04/08/macca_malware_attack/</a></p>
<p> </p>
<p><a title="Rock Phish's big, fat, fast-flux network" href="http://www.theregister.co.uk/2008/09/05/rock_phish_and_asprox_team_up/">Crimeware giants form botnet tag team</a> (5 September 2008)</p>
<p><a href="http://www.theregister.co.uk/2008/09/05/rock_phish_and_asprox_team_up/">http://www.theregister.co.uk/2008/09/05/rock_phish_and_asprox_team_up/</a></p>
<p> </p>
<p><a title="Dishonour among thieves" href="http://www.theregister.co.uk/2008/08/07/scammers_con_naive_phishermen/">Crimeware grifters scamming naive phishers</a> (7 August 2008)</p>
<p><a href="http://www.theregister.co.uk/2008/08/07/scammers_con_naive_phishermen/">http://www.theregister.co.uk/2008/08/07/scammers_con_naive_phishermen/</a></p>
<p> </p>
<p><a title="Wrapped app conceals its Penguin nature via Virtual Server" href="http://www.theregister.co.uk/2007/05/21/zxtm_4_windows/">Zeus virtually ports traffic manager to Windows</a> (21 May 2007)</p>
<p><a href="http://www.theregister.co.uk/2007/05/21/zxtm_4_windows/">http://www.theregister.co.uk/2007/05/21/zxtm_4_windows/</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/09/20/worlds-nastiest-trojan-fools-av-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Hacker&#8217; threatens to expose health data, demands $10M</title>
		<link>http://theitsecurityattache.com/blogs/2009/05/06/hacker-threatens-to-expose-health-data-demands-10m/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/05/06/hacker-threatens-to-expose-health-data-demands-10m/#comments</comments>
		<pubDate>Thu, 07 May 2009 00:43:46 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT News Articles of Interest]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Virginia Department of Health Professions]]></category>
		<category><![CDATA[Virginia DHP Prescription Monitoring Program (PMP)]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=641</guid>
		<description><![CDATA[&#8216;Hacker&#8217; threatens to expose health data, demands $10M
Hoax or the real thing? Virginia health agency Web site shut down but investigators mum
Jaikumar Vijayan &#124; http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9132625 
May 6, 2009 (Computerworld) Days after a hacker claimed to have broken into a database and encrypted millions of prescription records at the Virginia Department of Health Professions, it remains [...]]]></description>
			<content:encoded><![CDATA[<h1 style="margin: auto 0in;"><span style="font-size: x-large;"><span style="font-family: Times New Roman;">&#8216;Hacker&#8217; threatens to expose health data, demands $10M</span></span></h1>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; font-size: 14pt;">Hoax or the real thing? Virginia health agency Web site shut down but investigators mum</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; font-size: 12pt;">Jaikumar Vijayan | <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9132625">http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9132625</a> </span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;"><strong>May 6, 2009</strong> </span></span><a href="http://www.computerworld.com/" target="_blank"><span style="font-family: Times New Roman; font-size: small;">(Computerworld)</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> Days after a hacker claimed to have broken into a database and encrypted millions of prescription records at the Virginia Department of Health Professions, it remains unclear what happened.</span></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Whistleblower Web site Wikileaks.org last Sunday </span><a href="http://wikileaks.org/wiki/Over_8M_Virginian_patient_records_held_to_ransom%2C_30_Apr_2009" target="new"><span style="font-family: Times New Roman; font-size: small;">carried a report from an anonymous poster</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> who said that the secure site for the Virginia DHP Prescription Monitoring Program (PMP) had been broken into by a hacker who made a $10 million ransom demand. </span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">The alleged ransom note posted on the PMP site claimed that the hacker had backed up and encrypted more than 8 million patient records and 35 million prescriptions and then deleted the original data. </span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">&#8220;Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh,&#8221; the hacker is supposed to have said in his note, a copy of which was available on Wikileaks. &#8220;For $10 million, I will gladly send along the password,&#8221; for decrypting the data, the supposed hacker wrote.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">The expletive-laden note goes on to say that authorities have seven days to decide if they will &#8220;pony up&#8221; the money. If the ransom is not paid, &#8220;I&#8217;ll go ahead and put this baby out on the market and accept the highest bid,&#8221; the note says.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">The hacker admits that while he is unsure about the worth of the data or who would want it, &#8220;I&#8217;m bettin&#8217; someone will. Hell, if I can&#8217;t move the prescription data at the very least I can find a buyer for the personal data,&#8221; the hacker said pointing to the fact that the data included patients&#8217; names, ages, addresses, Social Security and driver&#8217;s license numbers.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">A call seeking comment on the incident from the Virginia PMP program office was not immediately returned. A call to the Virginia State Police department seeking confirmation on whether it is investigating the reported incident also was not immediately returned.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">As of today, the main PMP Web site and all links on the site were unavailable.</span></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">The </span><a href="http://www.governor.virginia.gov/MediaRelations/newsReleases/viewRelease.cfm?id=540" target="_blank"><span style="font-family: Times New Roman; font-size: small;">PMP was set up</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> in the wake of a spate of drug-abuse-related crimes and some deaths in the state involving the painkiller Oxycontin. It allows pharmacists and health care professionals to track prescription drug abuse, such as incidents of patients who go &#8220;doctor-shopping&#8221; to find more than one doctor to prescribe narcotics. According to a description of the program from a cached version of the site, there were more than 31.6 million records in the PMP database as of Jan. 1. Doctors, pharmacists and other authorized users make requests for data from the PMP database via a secure Web page, the description said.</span></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">The </span><a href="http://www.timesdispatch.com/rtd/news/local/article/HACKGAT06_20090505-213004/265893/" target="new"><em><span style="font-family: Times New Roman; font-size: small;">Richmond Times-Dispatch</span></em></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> reported Tuesday that the FBI and State Police had confirmed investigations of a hacking incident at the PMP. The story also quoted Virginia Gov. Timothy Kaine as saying the compromised data was not the same as patient files from doctors&#8217; offices. &#8220;These were not patient records, so it&#8217;s not compromise of health-care information about particular individuals,&#8221; the governor is quoted as saying in the <em>Times-Dispatch</em>.</span></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">The compromise comes at a time of heightened </span><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=325376"><span style="font-family: Times New Roman; font-size: small;">concerns about the privacy and security of medical data</span></a><span style="font-family: Times New Roman; font-size: small;">. President Barack Obama&#8217;s recently passed economic stimulus package includes a health care component that initially provides $20 billion for the creation of a </span><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=storage&amp;articleId=9126279"><span style="font-family: Times New Roman; font-size: small;">national health records system</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;">. The bill mandates new privacy and security controls for health care data that are seen as being long overdue.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">The controls go beyond those mandated under HIPAA (the Health Insurance Portability and Accountability Act) and are expected to be more strictly enforced than HIPAA rules have been.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">The breach at the Virginia health agency highlights the &#8220;overall lack of compliance&#8221; with HIPAA within the health care sector, said Peter MacKoul, president of HIPAA Solutions LC, a consulting firm in Sugar Land, Texas.</span></span></p>
<p><span style="font-size: small;"><span style="font-family: Times New Roman;">&#8220;HIPAA by and large has been ignored, not because it is unimportant, but because of a lack of will to really [enforce] it,&#8221; MacKoul said. &#8220;Much like all other regulations, if there is no real enforcement, this type of thing will continue to happen over and over again.&#8221;</span></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">The reported incident in Virginia is </span><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9119518"><span style="font-family: Times New Roman; font-size: small;">identical to one reported by Express Scripts</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;">, a St. Louis-based prescription drug management company in October. The company said it received an extortion letter from data thieves who threatened to release millions of patient records if the company did not pay up.</span></span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/05/06/hacker-threatens-to-expose-health-data-demands-10m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should there be an IT Security law for every connected PC/Internet user? What if there were, what would you do?</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/08/should-there-be-an-it-security-law-for-every-connected-pcinternet-user-what-if-there-were-what-would-you-do/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/08/should-there-be-an-it-security-law-for-every-connected-pcinternet-user-what-if-there-were-what-would-you-do/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 18:54:52 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Broadband]]></category>
		<category><![CDATA[DSL]]></category>
		<category><![CDATA[EV-DO]]></category>
		<category><![CDATA[Internet Services]]></category>
		<category><![CDATA[IT Security Law]]></category>
		<category><![CDATA[Mobility]]></category>
		<category><![CDATA[Netbooks]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=365</guid>
		<description><![CDATA[As I look across the IT Security Threats Landscape ~TITSTL~ today, I am very, very concerned at the recent increase in “sophisticated and re-architectured” threats that are popping up online today. Every day there are thousands of new threats, variants and exploits popping up out of the wood works but today we’re seeing an increase [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As I look across the IT Security Threats Landscape ~TITSTL~ today, I am very, very concerned at the recent increase in “sophisticated and re-architectured” threats that are popping up online today. Every day there are thousands of new threats, variants and exploits popping up out of the wood works but today we’re seeing an increase in the ones that are more structured, well architecture and positioned to circumvent many security settings and solutions on the market today. As I look at these I can’t help but to ponder how seriously people take these issues or is the lack of education and awareness getting worse as more technology is being introduced in our society without proper knowledge of what they are.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Anyone can get internet services today in various forms, broadband (cable, DSL, satellite), mobile (EV-DO, 3G) and wireless wherever available. The introduction of Netbooks is adding to this mobile threats issue as they are so small, slick and loveable that people will be losing them more easily than the bigger traditional laptops.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So here’s the thought process on this. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What if there was an internet security law in place that states, you must protect your PC against the threats of today by running this, that and then some (depending on the OS of course)?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If found guilty of running a PC without these basic steps in place you will be fined, system confiscated and possibly arrested depending on the violations of let’s say, data loss of a number of people (depending on if this is a business or end user).</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What if such a law was put in place, what do you think would happen and what would you do?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I can see it now, some car pulls up at your house and guys in black suits come out, walk in and take you and the system away because they have scanners roaming the internet looking for systems that are not running specified services/products/solutions. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">You’re under arrest for violation of code WT123-Basic-internet-security-policy revision 2009 in the state of Wassu which resulted in the loss of 5000 people’s personal/private information.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Sounds like a movie doesn’t it?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Wake up, it may very well happen.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Our thoughts as I ponder on this myself.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~Brett A. Scudder~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché </span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/08/should-there-be-an-it-security-law-for-every-connected-pcinternet-user-what-if-there-were-what-would-you-do/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Conficker Worm: What Happens Next? CBS 60 mins report</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-what-happens-next-cbs-60-mins-report/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-what-happens-next-cbs-60-mins-report/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 00:31:54 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[60 Minutes]]></category>
		<category><![CDATA[Confiker Worm]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=244</guid>
		<description><![CDATA[For those who missed it here it is. Please take a few minutes to watch it. It may not be all that but is still some good facts about the state of IT Security today.
http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053.shtml
]]></description>
			<content:encoded><![CDATA[<p>For those who missed it here it is. Please take a few minutes to watch it. It may not be all that but is still some good facts about the state of IT Security today.</p>
<p><a href="http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053.shtml">http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053.shtml</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-what-happens-next-cbs-60-mins-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Conficker Worm – my review</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-%e2%80%93-my-review/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-%e2%80%93-my-review/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 21:00:24 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Blended Threat]]></category>
		<category><![CDATA[Conficker Worm]]></category>
		<category><![CDATA[Content Filtering]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[IT Security Threats Landscape]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[Security Suite]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Web Browsing]]></category>
		<category><![CDATA[Web Filtering]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=228</guid>
		<description><![CDATA[The Conficker Worm – my review
 
There have been many articles, reviews, information and posting about the Conf*ker as many people have started calling it. Depending on who you talk with you can replace the * with anything that suits your feelings towards it. The most interesting thing about this threat isn’t the fact that it’s [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The Conficker Worm – my review</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">There have been many articles, reviews, information and posting about the Conf*ker as many people have started calling it. Depending on who you talk with you can replace the * with anything that suits your feelings towards it. The most interesting thing about this threat isn’t the fact that it’s neither a new one nor a new attack form, it’s the same old attackers doing the nefarious things they do but with a bit more sophistication. For me as an IT guy looking at all this, i’m getting the wow factor from some of the new developments and traits of the threat. So my take today will not be to overwhelm you with all the techno jargon and high level breakdown of the threat but just to speak on it in the most basic form so that even those who are non technical can grasp the severity of it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So here goes.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If you get infected with the Conficker worm you’re screwed. Bottom line.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If this is a system that is on a business network it must be removed, quarantined, disinfected by any means necessary. Take no chances with this threat.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Get my drift?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Is this basic enough to understand?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Ok, let’s take it from another angle.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">This worm is a blended (virus, worm, rootkit, botnet, adware, malware and the what else factor) threat in a blended threat with blended characteristics. It’s like catching a cold and getting a headache, ear ache, stomach ache, backache and chest pains all in one. It starts with a simple cold but quickly spreads to other critical areas of the body causing serious effects and harm. This threat is in a class by itself as it deploys various additional agents around the system that causes complete successful removal to be unclear.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If you have been infected with the worm you’re only real option is to completely wipe the system. Unplug, power down, power drain, complete power loss to all storage capacities of the system. This is a very serious threat.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As for those who have been asking about which anti-virus solution is best to protect against this, there isn’t one. Anti-Virus alone is not going to protect you from this threat and the blended effects. It will take a number of things to make this happen and here’s my list.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">1.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">System must be fully patched from all angles, the operating system, the applications, services, devices and drivers. When patching the Microsoft Windows operating system many people have auto update enabled but in different settings. Some have alert me of new updates but never apply the new updates. Some have it set to download and wait for my approval and they never approve the installation of the updates. Some have it set to download and install all updates. This is a good option to have. When patching the OS one must be prudent so as not to only apply critical patches but all software, severe and high updates as well. So I recommend if you’re doing the built in auto update please use the download and apply all. If doing it manually do a custom update which will reveal all the patches and updates needed.</span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">2.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Anti-Virus alone will not protect you from this worm and most of the new threats in the IT Security Threats Landscape today and tomorrow. The need for an anti-malware solution is critical to combine the protective layers of web/content filtering, IDS/IPS, anomaly/heuristics based detection, network and proactive threat protections. This is a backup to the patching already performed on the system. A fully patched system can still be compromised if a targeted malicious code is allowed to reach it.</span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">3.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Common sense if the name of the game and the winner of all security practices. Adding to the patching of the system and having the needed security solution comes the best practice of all, the user’s common sense in using the system effectively. As the person using the system one needs to pay very close attention to details in their messaging, web browsing and IM practices. Opening emails from known and unknown sources requires due diligence in thinking about the nature of the message, the contents and what is its relevance to you. A message from a known source may not have been sent by them but could have been the result of an infection on their system(s). This is the same for email and IMs. There are many IM worms that will hijack your IM client and send out messages to everyone in your contact list pointing them to a website for them to get a drive-by-download. Many people think very little of web based attacks while they are the fastest growing today because of the ease of infection and the delivery of the payload.</span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">4.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">User education and awareness. This is a very critical issue as many seem to think that these issues are a corporate or industry problem. When a threat like Conficker goes into the wild it is not targeting specific systems in specific industries only, it is doing a general attack across all systems within its path. IT Security is a people problem and we are all in its path whether we like it or not and no matter what OS vendor platform you’re on/running.</span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">5.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Enable your built in firewall or get a third party one to put up some form of perimeter defenses.</span></p>
<p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-fareast-font-family: Garamond; mso-bidi-font-family: Garamond;"><span style="mso-list: Ignore;">6.<span style="font: 7pt &quot;Times New Roman&quot;;">      </span></span></span><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">There are security suite solutions that bundles multiple security technologies and features in one suite. That may be a more viable option for you because of the integration and management options.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The fact of the matter is, we have these issues at the level they should have been years ago, in the media and across all industries as a people problem, not an industry one. I take the same approach to Conficker as I do to rogue Anti-Virus 2008/9 threat, if detected, wipe, clean, rebuild, reimage.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">This isn’t something to play around with what is or if it is cleaned. The only way to be sure is to wipe it all out.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Thank you and have a great day,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~<strong>Brett A. Scudder</strong>~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-%e2%80%93-my-review/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>State Security Breach Notification Laws as of December 16, 2008 and the Conficker worm</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 16:38:58 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Community Programs/Initiatives]]></category>
		<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Schedule]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Breach Notification Laws]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Conficker Worm]]></category>
		<category><![CDATA[Devices]]></category>
		<category><![CDATA[Drivers]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Rogue Anti-Virus 2008/9]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=220</guid>
		<description><![CDATA[This is from an email I sent out to my network distribution list today at 12 noon.
 
Good day to you,
 
This is a critical issue that has been highly overlooked and is a bigger problem than most people care to think. For those of us consultants who are responsible for our client’s infrastructure, please help them [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">This is from an email I sent out to my network distribution list today at 12 noon.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Good day to you,</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">This is a critical issue that has been highly overlooked and is a bigger problem than most people care to think. For those of us consultants who are responsible for our client’s infrastructure, please help them to understand where these laws apply and how it affects them. I’m bringing in someone from the attorney general’s office to do a presentation on this for us in the coming month. I’m trying to work with their schedule so stay tuned for the date of the meeting.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">There are some serious new threats on the loose and the more I look at them is the easier i’m seeing the rate of success in their deliverables. Our organization speaks to these issues and we must understand what they mean for those we’re helping to understand. This new variant of the Conficker worm has some nasty new tricks to it and while following its development and path, i’m more convinced that this is a new level of sophistication way above the rogue Anti-Virus/Anti-Spyware 2008/2009 threat we encountered last year that is still being a major pain point for IT today. Whether this is an April fools days joke or not, as you can see, the financial ramifications of negligence will be heavy.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Get those system (OS, applications, devices) patches updated and current. Most people tend to patch the OS and leave vulnerable applications running with system access to the OS that even fully patched is still vulnerable. Patching is an all round process that applies to the OS, applications running on it and the devices being connected to it. Even the device drivers are a point of entry to a system today so patch them if needed. Check on those security policies and rules and ensure they are up and running. We have a few days before April 1<sup>st</sup> so talk with your people about this and let them understand the need for being prudent about it.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Make no mistake people, this is a new age where technology rules and the threats are more real than ever before. This is not someone physically walking in and taking your data, this is someone sitting anywhere in the world and having access to it (if allowed).</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">I posted this on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950</a> for a broader visibility from the business professional’s community. More feedback and input will be found there as well. Spread the word.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Thank you and have a great day,</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">~Brett A. Scudder~</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><strong><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 18pt;">State Security Breach Notification Laws</span></strong></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><em><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;;">As of December 16, 2008</span></em><em><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"></span></em></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;;"><a href="http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm"><span style="color: #800080; font-size: small;">http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm</span></a></span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security/Privacy Awareness 03-09 #1 &#8211; Do you understand the breach notification law is in your country/state, do you know what it means, all are affected.</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/29/securityprivacy-awareness-03-09-1-do-you-understand-the-breach-notification-law-is-in-your-countrystate-do-you-know-what-it-means-all-are-affected/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/29/securityprivacy-awareness-03-09-1-do-you-understand-the-breach-notification-law-is-in-your-countrystate-do-you-know-what-it-means-all-are-affected/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 15:59:14 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Breach Notification Laws]]></category>
		<category><![CDATA[States]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=216</guid>
		<description><![CDATA[Good day to you,
 
I want us to take a look at this issue because I had conversations with a few business owners at a recent conference and they were not aware of the laws of their state nor the impact it has on them as a business. So once again here is one of my [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Good day to you,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I want us to take a look at this issue because I had conversations with a few business owners at a recent conference and they were not aware of the laws of their state nor the impact it has on them as a business. So once again here is one of my education and awareness questions here on LinkedIn and I hope we can get some good feedback and input on it. Please keep in mind that the purpose of these questions is to build education and awareness on the subject so any referencing materials, links and verification is always valuable.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">There are over 48 states in the US to date that have enacted a breach notification law and while I do believe that this is a flaw in the system for each to have its own, it’s a good start in the process. Maybe soon we’ll see this falling under one structure for effective governance. I believe we should have one national law that covers everyone because a data breach is the same no matter where it is done and the impacts can/will be the same across state lines. How it is handled in each state is another story which at most may not be enough for those who lost their data/privacy.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As a security professional, I am very much aware of the many ways in which our private data and information is very carelessly handled by many organizations but that is not the issue here, I want this to be about the laws and helping people to understand the need for knowing and protecting themselves, their customers and clients.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So, Do you have a breach notification law is in your country/state, do you know what it means and how are you affected by it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Are SMB omitted from these laws and how do they feel about the financial backlash of the issue.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do we know and understand of the recent laws of and around data security and the financial effects of it?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">US State Security Breach Notification Laws as of December 16, 2008</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a href="http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm"><span style="color: #800080;">http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm</span></a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Let us take this opportunity to build on these key issues as people need to understand what it really means for them. Know your technology/security/privacy laws.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Thank you and have a great day,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~<strong>Brett A. Scudder</strong>~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I posted this on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950</a> for a broader visibility from the business professional&#8217;s community. More feedback and input will be found there as well.</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/29/securityprivacy-awareness-03-09-1-do-you-understand-the-breach-notification-law-is-in-your-countrystate-do-you-know-what-it-means-all-are-affected/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New ransomware holds Windows files hostage, demands $50</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/26/new-ransomware-holds-windows-files-hostage-demands-50/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/26/new-ransomware-holds-windows-files-hostage-demands-50/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 21:17:09 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Anti FileFix]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Cybercrooks]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[FileFix Pro]]></category>
		<category><![CDATA[FireEye Inc.]]></category>
		<category><![CDATA[PDFs]]></category>
		<category><![CDATA[Ransomeware]]></category>
		<category><![CDATA[Scareware]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[Trojans]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=209</guid>
		<description><![CDATA[New ransomware holds Windows files hostage, demands $50
&#8216;Sobering&#8217; turn by crooks &#8216;doesn&#8217;t bode well,&#8217; says researcher
Gregg Keizer
http://www.computerworld.com/action/article.do?command=viewArticleBasic&#38;articleId=9130539&#38;source=NLT_AM
March 25, 2009 (Computerworld) Cybercrooks have hit on a new twist to their aggressive marketing of fake security software and are duping users into downloading a file utility that holds users&#8217; data for ransom, security researchers warned today.
While so-called [...]]]></description>
			<content:encoded><![CDATA[<p><strong>New ransomware holds Windows files hostage, demands $50<br />
</strong>&#8216;Sobering&#8217; turn by crooks &#8216;doesn&#8217;t bode well,&#8217; says researcher<br />
Gregg Keizer</p>
<p><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9130539&amp;source=NLT_AM">http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9130539&amp;source=NLT_AM</a></p>
<p>March 25, 2009 (Computerworld) Cybercrooks have hit on a new twist to their aggressive marketing of fake security software and are duping users into downloading a file utility that holds users&#8217; data for ransom, security researchers warned today.</p>
<p>While so-called scareware has plagued computer users for months, those campaigns have relied on phony antivirus products that pretend to trap malware but actually only exist to pester people into ponying up as much as $50 to stop the bogus warnings.</p>
<p>The new scam takes a different tack: It uses a Trojan horse that&#8217;s seeded by tricking users into running a file that poses as something legitimate like a software update. Once on the victim&#8217;s PC, the malware swings into action, encrypting a wide variety of document types &#8212; ranging from Microsoft Word .doc files to Adobe Reader PDFs &#8212; anytime one is opened. It also scrambles the files in Windows&#8217; &#8220;My Documents&#8221; folder.</p>
<p>When a user tries to open one of the encrypted files, an alert pops up saying that a utility called FileFix Pro 2009 will unscramble the data. The message poses as an semiofficial notice from the operating system. &#8220;Windows detected that some of your MS Office and media files are corrupted. Click here to download and install recommended file repair application,&#8221; the message reads.</p>
<p>Clicking on the alert downloads and installs FileFix Pro, but the utility is anything but legit. It will decrypt only one of the corrupted files for free, then demands the user purchase the software. Price? $50.</p>
<p>&#8220;This does look like a new tactic,&#8221; said David Perry, the global director of education at antivirus vendor Trend Micro Inc. &#8220;But all online fraud is just minor variations of classic con games. This is just the &#8216;Bank Examiner&#8217; played out on the Internet.&#8221;</p>
<p>That classic con, said Perry, typically involves a swindler posing as an official, a bank examiner or an FBI agent who asks for help in an investigation. The swindler convinces the mark to withdraw money from the bank &#8212; it&#8217;s needed to catch the nonexistent crook in the act &#8212; and promises to return the funds at the end of the case. Of course, the money vanishes, along with the grifter.</p>
<p>On the Web, data-hostage scams like this are called &#8220;ransomware&#8221; for obvious reasons. This isn&#8217;t the first time the tactic has been used, but it is remarkably polished, said Perry. &#8220;We&#8217;ve not seen ransomware with this level of sophistication,&#8221; he said.</p>
<p>Users who have fallen for the FileFix Pro 2009 con do not have to fork over cash to restore their files, according to other researchers, who have figured out how to decrypt the data. The Bleeping Computer site, for instance, has a free program called &#8220;Anti FileFix&#8221; available for download that unscrambles files corrupted by the Trojan horse. And security company FireEye Inc. has created a free online decrypter that also returns files to their original condition.</p>
<p>Alex Lanstein, a malware researcher at FireEye who blogged about FileFix Pro 2009 last week, called the turn from scareware to ransomware &#8220;sobering.&#8221;</p>
<p>&#8220;Although we broke the encryption, it&#8217;s a sobering realization of the state of malware that it is now actively extorting users by holding their data ransom,&#8221; Lanstein said. &#8220;Despite this version of FileFix being trivial to crack, it does not bode well for the future of Internet malware.&#8221;</p>
<p>If ransomware follows a similar path as scareware, criminals will be hustling to mimic FileFix Pro. According to some estimates, crooks make as much as $5 million a year pushing fake antivirus software.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/26/new-ransomware-holds-windows-files-hostage-demands-50/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/26/apple-mac-users-warned-of-web-based-malware-threats-rsplug-f-mac-trojan-horse-distributed-via-hdtv-website/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/26/apple-mac-users-warned-of-web-based-malware-threats-rsplug-f-mac-trojan-horse-distributed-via-hdtv-website/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 07:56:31 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[HDTV]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Malicious Codes]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[RSPlug]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Zlob]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/2009/03/26/apple-mac-users-warned-of-web-based-malware-threats-rsplug-f-mac-trojan-horse-distributed-via-hdtv-website/</guid>
		<description><![CDATA[25 March 2009
Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website

IT security and control firm Sophos is warning Apple Mac users to be on their guard against websites hosting malicious code designed to infect their systems. The advice follows the discovery of a new version of the OSX/RSPlug [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN-TOP: 10px">25 March 2009</p>
<p class="MsoNormal" style="MARGIN: 0in 0in 0pt"><span style="FONT-FAMILY: 'Georgia','serif'; COLOR: #000099; FONT-SIZE: 16pt">Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website</span></p>
<p><!-- Text starts --></p>
<p>IT security and control firm Sophos is warning Apple Mac users to be on their guard against websites hosting malicious code designed to infect their systems. The advice follows the discovery of a new version of the OSX/RSPlug Trojan horse that is being distributed via a legitimate-looking website offering HDTV software.</p>
<p><object width="550" height="316" data="http://vimeo.com/moogaloop.swf?clip_id=3838133&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=00ADEF&amp;fullscreen=1" type="application/x-shockwave-flash"><param name="src" value="http://vimeo.com/moogaloop.swf?clip_id=3838133&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=00ADEF&amp;fullscreen=1" /><param name="allowfullscreen" value="true" /></object><br />
<a href="http://vimeo.com/3838133">Apple Mac malware: Caught on camera</a> from <a href="http://vimeo.com/sophoslabs">Sophos Labs on Vimeo</a>.</p>
<p>&#8220;There is much less malware for the Apple Mac than there is for Windows, but that doesn&#8217;t mean that Apple fans can hide their head in the sand like ostriches,&#8221; said <a href="/pressoffice/contacts/grahamc.html">Graham Cluley</a>, senior technology consultant for Sophos. &#8220;Mac users are no different to Windows users when it comes to falling for social engineering tricks like this &#8211; they are just as likely to install and run this program on their computer if they believe it will help them watch high definition TV.&#8221;</p>
<p>Sophos notes that the criminal gang behind this malware attack is targeting Windows computers as well as Mac OS X.</p>
<p>&#8220;Windows users shouldn&#8217;t be feeling smug about this attack against Mac users. If you visit the website from a Windows computer, it will serve up a malicious Windows executable from the Zlob family of malware rather than the RSPlug-F Mac OS X Trojan horse. By targeting both platforms with their malicious website, the hackers can kill two birds with one stone,&#8221; explained Cluley. &#8220;Once a piece of malware like this is in place on your computer, it can do whatever the hacker wants it to do. Mac users are gambling with the security of their data if they believe they are somehow magically immune from threats that Windows users have lived with everyday for years.&#8221;</p>
<p>Sophos experts have determined that the RSPlug-F Trojan horse changes DNS Settings on Apple Mac computers, meaning users may find they are taken to bogus websites which may attempt to steal personal information, display revenue-generating adverts, or install further malware.</p>
<p>The article was posted here <a href="http://www.sophos.com/pressoffice/news/articles/2009/03/mac-malware.html?_log_from=rss">http://www.sophos.com/pressoffice/news/articles/2009/03/mac-malware.html?_log_from=rss</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/26/apple-mac-users-warned-of-web-based-malware-threats-rsplug-f-mac-trojan-horse-distributed-via-hdtv-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Newfangled rootkits survive hard disk wiping</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/25/newfangled-rootkits-survive-hard-disk-wiping/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/25/newfangled-rootkits-survive-hard-disk-wiping/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 15:17:34 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[ACPI]]></category>
		<category><![CDATA[Advanced Configuration and Power Interface]]></category>
		<category><![CDATA[BIOS]]></category>
		<category><![CDATA[CanSecWest security conference]]></category>
		<category><![CDATA[Core Security Technologies]]></category>
		<category><![CDATA[Injecting Code]]></category>
		<category><![CDATA[OpenBSD]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Researchers]]></category>
		<category><![CDATA[Rootkits]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=182</guid>
		<description><![CDATA[Original URL: http://www.theregister.co.uk/2009/03/24/persistent_bios_rootkits/
Newfangled rootkits survive hard disk wiping
BIOS attack targets PC nether region
By Dan Goodin in San Francisco
Posted in Anti-Virus, 24th March 2009 22:17 GMT
Free whitepaper – Trend Micro delivers security cloud

Researchers have demonstrated how to create rootkits that survive hard-disk reformatting by injecting malware into the low-level system instructions of a target computer.
The researchers, from [...]]]></description>
			<content:encoded><![CDATA[<p class="orig-url">Original URL: <a href="http://www.theregister.co.uk/2009/03/24/persistent_bios_rootkits/">http://www.theregister.co.uk/2009/03/24/persistent_bios_rootkits/</a></p>
<h2>Newfangled rootkits survive hard disk wiping</h2>
<p class="standfirst">BIOS attack targets PC nether region</p>
<p class="byline">By <a title="Send email to the author" href="http://forms.theregister.co.uk/mail_author/?story_url=/2009/03/24/persistent_bios_rootkits/">Dan Goodin in San Francisco</a></p>
<p class="dateline">Posted in <a href="/security/virus/">Anti-Virus</a>, 24th March 2009 22:17 GMT</p>
<p class="wptl top"><a href="http://go.theregister.com/tl/44/-755/smart-protection-network-analyst-brief-ogren.pdf?td=wptl44">Free whitepaper – Trend Micro delivers security cloud</a></p>
<div id="body">
<p>Researchers have demonstrated how to create rootkits that survive hard-disk reformatting by injecting malware into the low-level system instructions of a target computer.</p>
<p>The researchers, from Core Security Technologies, used the techniques to inject rootkits into two computers, one running the OpenBSD operating system and the other Windows. Because the infection lives in the computer&#8217;s BIOS, or basic input/output system, it persists even after the operating system is reinstalled or a computer&#8217;s hard drive is replaced.</p>
<div id="ad-mpu1-spot" class="print" style="width: auto; height: auto;"><noscript></noscript></p>
<div id="ad-mpu1" class="ad-load">While researchers have focused on <a href="http://www.theregister.co.uk/2006/01/27/rootkits_bios/">BIOS-based rootkits</a> (<span class="URL">http://www.theregister.co.uk/2006/01/27/rootkits_bios/</span>) for at least three years, earlier techniques generally attacked specific types of BIOSes, such as those that used ACPI, or Advanced Configuration and Power Interface. The techniques demonstrated by the Core researchers work on virtually all types of systems, they said.</div>
</div>
<p>Of course, injecting code into the BIOS is no easy feat. It requires physical access to the machine or an exploit that hands an attacker unfettered root access. But the research, presented at last week&#8217;s CanSecWest security conference by Anibal L. Sacco and Alfredo A. Ortega, does demonstrate that infections will only become harder to spot and remove over time. ®</p></div>
<div id="related-stories">
<h3>Related stories</h3>
<ul class="headline-list">
<li><a title="Done the basics - or sleepwalking along a precipice?" href="/2009/02/06/laptop_data_security/">Of laptop data security</a> <small><span style="font-size: x-small;">(6 February 2009)</span></small>
<p class="related-url">http://www.theregister.co.uk/2009/02/06/laptop_data_security/</p>
</li>
<li><a title="Curse of the ROMmon" href="/2009/01/05/cisco_router_hijacking/">Boffin brings &#8216;write once, run anywhere&#8217; to Cisco hijacks</a> <small><span style="font-size: x-small;">(5 January 2009)</span></small>
<p class="related-url">http://www.theregister.co.uk/2009/01/05/cisco_router_hijacking/</p>
</li>
<li><a title="To subscribe to The Register's weekly newsletter - seven days of IT in a single hit - click here" href="/2007/06/29/reg_weekly_290607/">Boffins go HPC crazy while America stands in the iQ</a> <small><span style="font-size: x-small;">(29 June 2007)</span></small>
<p class="related-url">http://www.theregister.co.uk/2007/06/29/reg_weekly_290607/</p>
</li>
<li><a title="The VBootkit authors speak out" href="/2007/04/26/vbootkit_authors_interview/">0wning Vista from the boot</a> <small><span style="font-size: x-small;">(26 April 2007)</span></small>
<p class="related-url">http://www.theregister.co.uk/2007/04/26/vbootkit_authors_interview/</p>
</li>
<li><a title="The outsourcing of security" href="/2007/02/09/rsa_fear/">Fear and Loafing at RSA</a> <small><span style="font-size: x-small;">(9 February 2007)</span></small>
<p class="related-url">http://www.theregister.co.uk/2007/02/09/rsa_fear/</p>
</li>
<li><a title="Flash warning" href="/2006/01/27/rootkits_bios/">Researchers say rootkits are headed for BIOS</a> <small><span style="font-size: x-small;">(27 January 2006)</span></small>
<p class="related-url">http://www.theregister.co.uk/2006/01/27/rootkits_bios/</p>
</li>
</ul>
</div>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/25/newfangled-rootkits-survive-hard-disk-wiping/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview &#8211; New Security Risks from USB Flash Drives by Michelle V. Rafter</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/interview-new-security-risks-from-usb-flash-drives-by-michelle-v-rafter/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/interview-new-security-risks-from-usb-flash-drives-by-michelle-v-rafter/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 02:43:03 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Flash Drives]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[USB Drives]]></category>
		<category><![CDATA[USB Threats]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=90</guid>
		<description><![CDATA[Hi all,
Here is an article I recently contributed to about USB drives, the threats they present and how to safeguard them. Take a read.
I&#8217;d like your feedback and input on these issues.
New Security Risks from USB Flash Drives
By Michelle V. Rafter
http://www.yoursecurityresource.com/articles/usbdrives/
Thank you,
The IT Security Attaché
]]></description>
			<content:encoded><![CDATA[<div>Hi all,</p>
<p>Here is an article I recently contributed to about USB drives, the threats they present and how to safeguard them. Take a read.</p>
<p>I&#8217;d like your feedback and input on these issues.</p>
<p>New Security Risks from USB Flash Drives<br />
By Michelle V. Rafter<br />
<a onmousedown="UntrustedLink.bootstrap($(this), &quot;56f12a2a11cb13c5de08734a79608e4b&quot;, event)" rel="nofollow" href="http://www.yoursecurityresource.com/articles/usbdrives/" target="_blank"><span style="color: #3b5998;"><span>http://www.yoursecurityres</span></span><span>ource.com/articles/usbdriv</span>es/</a></p>
<p>Thank you,</p>
<p>The IT Security Attaché</p></div>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/interview-new-security-risks-from-usb-flash-drives-by-michelle-v-rafter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; What does the internet mean to you today and where do you see it tomorrow?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-what-does-the-internet-mean-to-you-today-and-where-do-you-see-it-tomorrow/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-what-does-the-internet-mean-to-you-today-and-where-do-you-see-it-tomorrow/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:44:20 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=65</guid>
		<description><![CDATA[Good day to you,
The Internet means different things to different people and i&#8217;d just like to get a sense of your feelings on it and why it is important to/for you.
Nothing specific, I just want to hear your thought on it as it comes to mind.
Thank you and have a great day,
~Brett A. Scudder~
More answers [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>The Internet means different things to different people and i&#8217;d just like to get a sense of your feelings on it and why it is important to/for you.</p>
<p>Nothing specific, I just want to hear your thought on it as it comes to mind.</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/379604-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/379604-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-what-does-the-internet-mean-to-you-today-and-where-do-you-see-it-tomorrow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; Do you have an online presence, if yes, is it separate from your offline one? If so, how do you do it?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-do-you-have-an-online-presence-if-yes-is-it-separate-from-your-offline-one-if-so-how-do-you-do-it/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-do-you-have-an-online-presence-if-yes-is-it-separate-from-your-offline-one-if-so-how-do-you-do-it/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:41:07 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Offline Presence]]></category>
		<category><![CDATA[Online Presence]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=63</guid>
		<description><![CDATA[Good day to you,
This is a conversation I kick off a lot as I try to get people to understand the two elements and when/how they are intertwined.
What does this presence mean to you and how much time have you put into framing and maintaining it?
Is this presence important to/for you?
What if this presence was [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>This is a conversation I kick off a lot as I try to get people to understand the two elements and when/how they are intertwined.</p>
<p>What does this presence mean to you and how much time have you put into framing and maintaining it?</p>
<p>Is this presence important to/for you?</p>
<p>What if this presence was stolen/framed, would you be affected, if so, how?</p>
<p>Your thoughts.</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/384092-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/384092-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-do-you-have-an-online-presence-if-yes-is-it-separate-from-your-offline-one-if-so-how-do-you-do-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; At what age should IT/Internet Security and best practices be taught to youths? Do we see the internet as a threat to them?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-at-what-age-should-itinternet-security-and-best-practices-be-taught-to-youths-do-we-see-the-internet-as-a-threat-to-them/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-at-what-age-should-itinternet-security-and-best-practices-be-taught-to-youths-do-we-see-the-internet-as-a-threat-to-them/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:37:52 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Blended Threats]]></category>
		<category><![CDATA[Children]]></category>
		<category><![CDATA[Defense-in-depth]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[IT/Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Online Privacy]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[SPAM]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=60</guid>
		<description><![CDATA[Good day to you,
With technology becoming a more integral part of our everyday lives and more gadgets, devices, and electronics being converged on the information superhighway (World Wide Web ), at what age do you believe we should start the education and awareness of IT/Internet Security for our youths in the school systems?
Things like,
How to [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>With technology becoming a more integral part of our everyday lives and more gadgets, devices, and electronics being converged on the information superhighway (World Wide Web ), at what age do you believe we should start the education and awareness of IT/Internet Security for our youths in the school systems?</p>
<p>Things like,</p>
<p>How to browse/use the internet safely,<br />
Instant Messaging security and best practices<br />
Social Networking security and best practices<br />
Mobile security and best practices.<br />
Online predators and how they target children and how to be protected from them.<br />
What is are viruses, worms, trojans, spyware, malware, blended threats?<br />
What are web attacks (like drive-by-downloads) and how they are orchestrated?<br />
What is social engineering?<br />
What is phishing?<br />
What is SPAM and why is it being used today?<br />
How do these threats proliferate?<br />
Secure messaging implementation and use.<br />
Defense-in-depth &#8211; definition, purpose and maintenance. Anti-virus, anti-malware, firewalls and intrusion detection/prevention.</p>
<p>Our Secure Minds Initiative is about integrating this level of training and education in the school’s curriculum and I wanted to get your thoughts as adults, parents, educators and professionals on this matter. I have seen 10-12yrs old who can hack into a network and do some serious things that IT Pros in their adult years can’t.</p>
<p>Why not nurture this knowledge and ability for good?</p>
<p>Please make note that I didn&#8217;t ask if it should, I asked at what age should this be done signifying that I believe it should and i’m for it. Imagine having our youths graduating from high/middle schools with this advance early knowledge and what contributions they would be to the IT field. Even if they don’t become IT professionals having this education and knowledge will help any organization they join stay more secure.</p>
<p>Your thoughts.</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/394739-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/394739-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-at-what-age-should-itinternet-security-and-best-practices-be-taught-to-youths-do-we-see-the-internet-as-a-threat-to-them/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; Security/Privacy Awareness # 1 &#8211; When/Where/Who should I give my social security number to and why and what are the impacts of doing so? Are there any protective laws in place?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-securityprivacy-awareness-1-whenwherewho-should-i-give-my-social-security-number-to-and-why-and-what-are-the-impacts-of-doing-so-are-there-any-protective-laws-in-place/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-securityprivacy-awareness-1-whenwherewho-should-i-give-my-social-security-number-to-and-why-and-what-are-the-impacts-of-doing-so-are-there-any-protective-laws-in-place/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:31:04 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Online Protection]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy laws]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Social Security Number]]></category>
		<category><![CDATA[SSN]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=58</guid>
		<description><![CDATA[Good day to you,
Here is another education and awareness question in my series on the use of your social security number today.
Ever since the financial crisis has begun (which isn’t just today, look 18 months back), more and more people have been trying to avert the issues and impacts of the job losses and downturn [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>Here is another education and awareness question in my series on the use of your social security number today.</p>
<p>Ever since the financial crisis has begun (which isn’t just today, look 18 months back), more and more people have been trying to avert the issues and impacts of the job losses and downturn in the economic trends. For this reason, they have been opening themselves up to more “risky business” opportunities/ventures in the name of finding a job or making some quick money to pay the bills and put food on the table. This is a bad sign of worse things to come for these people and by us taking a look at this now we can help educate others.</p>
<p>As more people are jobless the use of the internet increases, it takes away the human face-to-face elements that would help to validate the business or offerings/opportunities. More job sites/opportunities offering the hopes of new jobs/loans with a request for signing up with personal/private info is only a fraction of the bigger issues.</p>
<p>This has lead to an increase in identity theft and the loss of people’s personal/private information that trickles down to the core of our lives. As the economy will get worse before it gets better and more “rescue” opportunities/offers are being circulated, one can only imagine the dramatic increase in phishing and social engineering scams that will come about as a result of the new stimulus package and government initiatives. Sometimes we give up this information because we don’t know how/where/where to do so and then it becomes an after the fact issue. We will address the identity theft education and awareness issues later.</p>
<p>So, let us take a concerted look at when/where/who should I give my social security number to and why, and what are the impacts of doing so.</p>
<p>Are there any protective laws in place for it?</p>
<p>Your thoughts/feedback/input.</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~<br />
The IT Security Attaché</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/417629-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/417629-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-securityprivacy-awareness-1-whenwherewho-should-i-give-my-social-security-number-to-and-why-and-what-are-the-impacts-of-doing-so-are-there-any-protective-laws-in-place/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; Professional Messaging Ethics # 1 &#8211; The importance of a proper subject, is or isn’t it?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-professional-messaging-ethics-1-the-importance-of-a-proper-subject-is-or-isn%e2%80%99t-it/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-professional-messaging-ethics-1-the-importance-of-a-proper-subject-is-or-isn%e2%80%99t-it/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:27:00 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Etiquette]]></category>
		<category><![CDATA[Professional Messaging Ethics]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=56</guid>
		<description><![CDATA[Good day to you,
I am creating a series of education and awareness questions (as usual) and this one is on Professional Messaging Ethics and the importance of having a proper subject that reflects the nature of the message.
As a recipient of thousands of messages daily, I cannot begin to tell you how important it is [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>I am creating a series of education and awareness questions (as usual) and this one is on Professional Messaging Ethics and the importance of having a proper subject that reflects the nature of the message.</p>
<p>As a recipient of thousands of messages daily, I cannot begin to tell you how important it is to look at my inbox and choose what messages are worth looking at first not only by sender by but the subject. Many times legitimate messages come in from new connections and they tend to be off on the labeling of the message and so it gets passed by inadvertently.</p>
<p>Many people don’t realize that an email is something that may have no end to where it reaches and so creating a proper posture is very critical to both sender and recipient.</p>
<p>So my question to the professional’s community is,</p>
<p>How important is the subject line of a message to you?</p>
<p>Your thoughts.</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~<br />
The IT Security Attaché</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/414712-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/414712-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-professional-messaging-ethics-1-the-importance-of-a-proper-subject-is-or-isn%e2%80%99t-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My LinkedIn Q&amp;A &#8211; Your thoughts &#8211; &#8220;Report Calls Online Threats to Children Overblown&#8221;. What do you think, is this for real or not?</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:21:10 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Children]]></category>
		<category><![CDATA[Online Threats]]></category>
		<category><![CDATA[Parents]]></category>
		<category><![CDATA[Predators]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=54</guid>
		<description><![CDATA[Good day to you,
When I see an article like this I tend to sit back and go wow, where have I been living and what have I been seeing/hearing or, am I in denial to the truth. I have always said that we, the people in the field who live and die working in the [...]]]></description>
			<content:encoded><![CDATA[<p>Good day to you,</p>
<p>When I see an article like this I tend to sit back and go wow, where have I been living and what have I been seeing/hearing or, am I in denial to the truth. I have always said that we, the people in the field who live and die working in the field, have always seen thing different from the people in these high level positions and is why they fail to implement the proper things needed because there is in synergy between us and them.</p>
<p>It’s like a cop on the street who has to deal with the everyday violence and issues but he’s able to quell them and bring peace in his areas because he’s know and knows how to deal with people. While these issues are real and happening everyday they don’t get reported back to the precinct and so the captain (or seniors) thinks all is well and can say that there district is not violent nor has issues like anywhere else. It’s not that you don’t have issues, you’re just not getting the info about them because they are not critical enough to report in or cause a major stir. Yet, unchecked, the high profile ones are added to the statistics and generate facts.</p>
<p>They don&#8217;t come down to our neck of the woods and talk with us to see what is &#8220;really going on&#8221; in the world, instead, they use statistics that is published by some agency or group. Well, I must be in denial because I truly see this as a growing problem and have talked with parent/student alike who have been victimized online to the point that it affects their offline experience/life.</p>
<p>So, before I get carried away in myself and this issue (as it really upsets me), i&#8217;d like to throw this out to this professional’s network to get your real professional insight/thoughts on the report of the report.</p>
<p>http://www.nytimes.com/2009/01/14/technology/internet/14cyberweb.html</p>
<p>Thank you and have a great day,</p>
<p>~Brett A. Scudder~</p>
<p>More answers on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/398900-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/398900-3071950</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/02/my-linkedin-qa-your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your thoughts &#8211; &#8220;Report Calls Online Threats to Children Overblown&#8221;. What do you think, is this for real or not?</title>
		<link>http://theitsecurityattache.com/blogs/2009/01/13/your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/01/13/your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 03:02:09 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Children's safety]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Online Predators]]></category>
		<category><![CDATA[Online Safety]]></category>
		<category><![CDATA[Parental Controls]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=41</guid>
		<description><![CDATA[
Hi all, 
I really had to bring this to your attention and if you&#8217;d like to add your thoughts that&#8217;d be great. The report has prompted my desire to see the real report that was submitted for them to come to this conclusion. I&#8217;d like to have a sit down with them to shed some [...]]]></description>
			<content:encoded><![CDATA[<p><body></p>
<p>Hi all, </p>
<p>I really had to bring this to your attention and if you&#8217;d like to add your thoughts that&#8217;d be great. The report has prompted my desire to see the real report that was submitted for them to come to this conclusion. I&#8217;d like to have a sit down with them to shed some light to the issues from another angle, the &quot;unreported cases&quot;. </p>
<p>As I said, there’s a lot that goes on that doesn’t get reported so where does that info go and what influence (if any) would it have on the real state of affairs about online threats to children. Children are being used as backdoors and an access point to private/personal information about the family, the home and financial status, not just for sex or sexual acts. </p>
<p>If there wasn’t a threat why do we have taskforce and other agencies manning it? </p>
<p>I guess you can tell that i’m very worked up over this one huh. It just shows how limited the mindset is at that level. It’s like saying if I teach the children to secure the door by always locking it I don’t have to worry about the windows. </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; <br />
The question on LinkedIn.<br />
<a href="http://www.linkedin.com/answers/using-linkedIn/ULI/398900-3071950" target="_blank">http://www.linkedin.com/answers/using-linkedIn/ULI/398900-3071950<br />
</a><br />
Your thoughts &#8211; &quot;Report Calls Online Threats to Children Overblown&quot;. What do you think, is this for real or not? </p>
<p>Good day to you, </p>
<p>When I see an article like this I tend to sit back and go wow, where have I been living and what have I been seeing/hearing or, am I in denial to the truth. I have always said that we, the people in the field who live and die working in the field, have always seen thing different from the people in these high level positions and is why they fail to implement the proper things needed because there is in synergy between us and them. </p>
<p>It’s like a cop on the street who has to deal with the everyday violence and issues but he’s able to quell them and bring peace in his areas because he’s known and knows how to deal with people. While these issues are real and happening every day, they don’t get reported back to the precinct and so the captain (or seniors) thinks all is well and can say that there district is not violent nor has issues like anywhere else. It’s not that you don’t have issues, you’re just not getting the info about them because they are not critical enough to report in or cause a major stir. Yet, unchecked, the high profile ones are added to the statistics and generate facts. </p>
<p>They don&#8217;t come down to our neck of the woods and talk with us to see what is &quot;really going on&quot; in the world, instead, they use statistics that is published by some agency or group. Well, I must be in denial because I truly see this as a growing problem and have talked with parent/student alike who have been victimized online to the point that it affects their offline experience/life. </p>
<p>So, before I get carried away in myself and this issue (as it really upsets me), i&#8217;d like to throw this out to this professional’s network to get your real professional insight/thoughts on the report of the report. </p>
<p><a href="http://www.nytimes.com/2009/01/14/technology/internet/14cyberweb.html">http://www.nytimes.com/2009/01/14/technology/internet/14cyberweb.html</a> &nbsp;</p>
<p>Thank you and have a great day, </p>
<p>~Brett A. Scudder~
</p>
<p></body></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/01/13/your-thoughts-report-calls-online-threats-to-children-overblown-what-do-you-think-is-this-for-real-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
