<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IT Security Attaché &#187; Activated</title>
	<atom:link href="http://theitsecurityattache.com/blogs/tag/activated/feed/" rel="self" type="application/rss+xml" />
	<link>http://theitsecurityattache.com/blogs</link>
	<description>His life, profiles, work, aspirations, agenda and schedule.</description>
	<lastBuildDate>Mon, 26 Jul 2010 22:05:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>So you opened the door and let Conficker in now what? You’ve been activated.</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/31/so-you-opened-the-door-and-let-conficker-in-now-what-you%e2%80%99ve-been-activated/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/31/so-you-opened-the-door-and-let-conficker-in-now-what-you%e2%80%99ve-been-activated/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 17:48:54 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Activated]]></category>
		<category><![CDATA[April 1st]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Serious Threats]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=257</guid>
		<description><![CDATA[Well, it’s simple, you’re SCREWED, so just start the wiping and rebuilding process and don’t waste time trying to clean it up.  This is not one of those small time threats that you can clean up and rest well knowing that you’re ok. This is a new level of sophistication that took serious time, effort [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Well, it’s simple, you’re SCREWED, so just start the wiping and rebuilding process and don’t waste time trying to clean it up.<span style="mso-spacerun: yes;">  </span>This is not one of those small time threats that you can clean up and rest well knowing that you’re ok. This is a new level of sophistication that took serious time, effort and though into creating and mapping out its deliverables.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">So you scanned your system after hearing all this talk and alerts about this “serious threat” and now you’ve found something suspicious and you’re wondering what to do. Well, it’s not that you had blocked it nor was the system fully patched and the doors closed, it was already on the system and has already done its rounds of spreading and attaching itself to critical areas of the system. This kind of threat isn’t the kind that you can rest comfortably with (well I can’t/don’t) and I wouldn’t feel comfortable knowing that it is on a network of someone I converse with.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I mean, things do happen but there should be due diligence in your system security best practices and how they are handled prior to an issue like this.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Now comes April 1st and you’re wondering, oh my God, what am I going to do?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Well, you’re about to be activated and who know what your command, effects and impact will be.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I hope that this is more of a hoax than what I have concluded from my own personal analysis. Maybe it&#8217;s time you start being more proactive than reactive.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">We’ll just have to wait and see.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">IT Security IS a people problem, not an industry one.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"><strong>The IT Security Attaché</strong></span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/31/so-you-opened-the-door-and-let-conficker-in-now-what-you%e2%80%99ve-been-activated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This is amazing, it’s as if Conficker is a new threat. Guess what, it isn’t, it’s just a more serious one. You’ve been activated.</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/31/this-is-amazing-it%e2%80%99s-as-if-conficker-is-a-new-threat-guess-what-it-isn%e2%80%99t-it%e2%80%99s-just-a-more-serious-one/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/31/this-is-amazing-it%e2%80%99s-as-if-conficker-is-a-new-threat-guess-what-it-isn%e2%80%99t-it%e2%80%99s-just-a-more-serious-one/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 09:33:32 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[IT Security Programs and Initiatives]]></category>
		<category><![CDATA[My Writings]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Activated]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Risks]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Webcasts]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=253</guid>
		<description><![CDATA[Over the past week I have had so many requests to talk about this worm and why it is so bad and what it really means that I almost convinced myself that it was a brand new threat. Most people are so caught up on it as if it is a new threat but it [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Over the past week I have had so many requests to talk about this worm and why it is so bad and what it really means that I almost convinced myself that it was a brand new threat. Most people are so caught up on it as if it is a new threat but it really isn’t. It’s just a new level of sophistication that warrants the time and attention from the security professionals and vendors to stop whatever possibilities it may bring come April 1<sup>st</sup> and beyond and for the general public to be aware that these are real life issues here. As I say every day, IT Security is a people problem, not an industry one because the impact and effects are felt in every area of our society and daily lives.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When CBS’s 60 minutes ran the story on Sunday March 29<sup>th</sup> at 7pm, it’s as if the world woke up to the realization that this is serious. The very same words and things I have been telling people didn’t resonate until they heard and saw it on 60 minutes. Wow, and you wonder why the state of our security is so weak and poor, people don’t know who to listen to nor trust in these matters. So now I am talking to the same people who I talked o a year ago about the importance of properly protecting themselves from these risks and why it is needed today.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">One person call me and was saying, “hey Brett, did you watch 60 minutes and see that new worm they are talking about. Man that’s serious isn’t it?”</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So now i’m sitting on the other end of the line going, huh, are you serious, this is the same thing I have been talking about for years and trying to get you to understand, this is just a named threat but a threat none the less with a more sophisticated architecture and attack vector. It’s amazing.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I had more people asking which anti-virus software can stop this threat than what is this threat really about. This is one of the issues I have with a scenario like this because people need to take the time to learn and understand more about the threat and how it proliferates so they can better help to prevent the infection or spread even if they have security installed and running on their systems. We need more educated people to help maintain a strong wall of protection against the spread of these threats/risk via the internet today and tomorrow. Learn, get the facts, understand the need and activate the common sense.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Guess what, you’ve been activated. You’re now more alert, more intrigued, more prone to fighting these issues because it is in your backyard and you MUST DEAL WITH IT. How you decide to handle yourself is another issue.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I hosted an IT Security Webcast on March 22<sup>nd</sup> and 5 people who declined to attend the session via the event invite on Facebook ended up with some form of infection two days later.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When asked how they got it, I was told,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I’m not sure or I don’t know.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The reason for declining my invite was that they have anti-virus on their system to protect them so they are ok and good to go.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What can I say?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Many will fall under these kinds of issues because they think they are good to go and not needing to learn or know more about how to protect themselves online. While they rest assured that they are protected by their AV client they still practice bad browsing, file sharing, file cracking, key generation and illegal software downloads everyday which gives systems access to these hackers via backdoors. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The next time you decide to download a keygen, password generator, cracked file, music from unknown people/sites or browse a website from an IM someone may have sent you, think twice about what you’re doing to your system, yourself and those you share and converse with. Support the developers and buy the apps. Get the real code.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The next time you decide to click ok on that pop up window without reading what it says while browsing, think again and take a minute to read it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The next time you decide to open that chain mail and click on the link, hey, hey, hey, watch out now. You may know and trust the sender but do you know if he/she really sent it?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When in doubt, reach out.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">And so we wait for April 1<sup>st</sup> to see what Conf*ker will do to those systems already under its control.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What are you doing about it?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/31/this-is-amazing-it%e2%80%99s-as-if-conficker-is-a-new-threat-guess-what-it-isn%e2%80%99t-it%e2%80%99s-just-a-more-serious-one/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
