<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IT Security Attaché &#187; Patches</title>
	<atom:link href="http://theitsecurityattache.com/blogs/tag/patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://theitsecurityattache.com/blogs</link>
	<description>His life, profiles, work, aspirations, agenda and schedule.</description>
	<lastBuildDate>Mon, 26 Jul 2010 22:05:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>VMware patches new critical security vulnerability</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/16/vmware-patches-new-critical-security-vulnerability/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/16/vmware-patches-new-critical-security-vulnerability/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 17:13:15 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT News Articles of Interest]]></category>
		<category><![CDATA[Advisory]]></category>
		<category><![CDATA[Critical]]></category>
		<category><![CDATA[Denial-of-Service]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[ESXi]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[SANS Storm Center]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=450</guid>
		<description><![CDATA[VMware patches new critical security vulnerability

Chuck Miller &#124; http://www.scmagazineus.com/VMware-patches-new-critical-security-vulnerability/article/130518/
April 10 2009


VMware on Friday issued patches for a critical security vulnerability in its ESX and ESXi virtualization products.
The issue is new, different from the vulnerability in a guest virtual device driver that was patched by VMware earlier this week. That earlier flaw could cause a potential denial-of-service, and [...]]]></description>
			<content:encoded><![CDATA[<h1 id="ctl00_ctl00_cphAllPageContent_cphMainContent_PrintArticle1_articleTitle" class="articleTitle">VMware patches new critical security vulnerability</h1>
<div id="byline">
<div id="ctl00_ctl00_cphAllPageContent_cphMainContent_PrintArticle1_articleAuthor" class="articleAuthor"><a title="More Articles by Chuck Miller" href="http://www.scmagazineus.com/Chuck-Miller/author/227/">Chuck Miller</a> | <a href="http://www.scmagazineus.com/VMware-patches-new-critical-security-vulnerability/article/130518/">http://www.scmagazineus.com/VMware-patches-new-critical-security-vulnerability/article/130518/</a></div>
<div id="ctl00_ctl00_cphAllPageContent_cphMainContent_PrintArticle1_articleDate" class="articleDate">April 10 2009</div>
</div>
<div id="ctl00_ctl00_cphAllPageContent_cphMainContent_PrintArticle1_articleBody" class="articleBody">
<p><a href="http://www.scmagazineus.com/search/vmware/">VMware</a> on Friday issued <a href="http://www.vmware.com/security/advisories/VMSA-2009-0006.html">patches</a> for a critical security vulnerability in its ESX and ESXi virtualization products.</p>
<p>The issue is new, different from the vulnerability in a guest virtual device driver that was patched by VMware earlier this week. That earlier flaw could cause a potential denial-of-service, and affected Workstation, Player, ACE, Server, ESX and ESXi virtualization products.</p>
<p>One of the reasons this <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1244">new vulnerability</a> was labeled &#8220;critical&#8221; is that it could affect the underlying host operating system in a virtual environment.</p>
<p>“A critical vulnerability in the virtual machine display function might allow a guest operating system to run code on the host,” the VMware <a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1009853">advisory</a> said.</p>
<p>The VMware advisory lists a number of VMware versions that are affected, and whether the patches will properly address the vulnerability. But apparently, some users who have older versions may not be helped.</p>
<p>“Depending on your version, your only option may be to upgrade rather than patch,” wrote Steve Hall, handler at the SANS Internet Storm Center, on the organization&#8217;s blog.</p>
<p>The typical way to apply patches to ESXi hosts is through the VMware Update Manager, but ESXi hosts can also be updated by downloading a single offline download file, according to VMware.</p></div>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/16/vmware-patches-new-critical-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Self Employed &amp; Home Based Business must take IT Security very seriously</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/13/self-employed-home-based-business-must-take-it-security-very-seriously/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/13/self-employed-home-based-business-must-take-it-security-very-seriously/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 06:57:28 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Breach Notification Laws]]></category>
		<category><![CDATA[Businesses]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Cracked Files]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[Keygens]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Media Player]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[Ning]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[PowerPoint]]></category>
		<category><![CDATA[Self Employed]]></category>
		<category><![CDATA[SMB]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Solaris]]></category>
		<category><![CDATA[SPAM]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Text Messaging]]></category>
		<category><![CDATA[The IT Security Threats Landscape]]></category>
		<category><![CDATA[TITSTL]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=406</guid>
		<description><![CDATA[Good day to you,
 
I would like to take this opportunity to share some very critical information with the self employed and home based business owners about the state of The IT Security Threats Landscape ~TITSTL~ and how it affects you. This is a discussion I have every day as more and more people in these [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Good day to you,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I would like to take this opportunity to share some very critical information with the self employed and home based business owners about the state of The IT Security Threats Landscape ~TITSTL~ and how it affects you. This is a discussion I have every day as more and more people in these categories are finding out the real effects and impacts of these threats are not excluding them and that they fall very much into the mix of it. As the economy tightens its grip on our lives, those who are being laid off are turning to home based and self employed business thus sparking an increased growth in this area of business. The SMB space has grown tremendously since his recession and to that end has become a serious security issue for us security professionals as we look across the IT Security Threats Landscape horizon. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Therefore, the reality of the issue must be faced thus bringing the question of, what am I to do about it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I have published numerous articles on these threats, preventative measures and how to deal with the security issues of today and tomorrow on my blogs but I am going to do this as a summary of those here.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">First let me say this, if it requires a security patch (let’s just keep it at security for now), it is vulnerable.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What does this mean?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Simple, any operating system, Microsoft, Mac, Linux, Solaris, you name it, that requires a security patch for any reason is vulnerable. The patch is to prevent exploit of the vulnerability right so it is a security risk. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I had to get that out of the way so that we wouldn’t get into the ridiculous argument of which is more secure than the other. The way I see it is simply that, if a door is left open for anyone to come through it, the length of time left open versus the threat that comes through it is just as critical. So, any open door is a threat no matter where. What comes through it may differentiate the severity. They all have their insecurities at some point but how the vendor/developer addresses it lessens the impact and wide scale visibility of the issue. While some may announce these vulnerabilities and findings, other may patch/update them behind the scenes thus limiting the visibility and knowledge of the user.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Second, anti-virus alone is NOT going to protect you from the threats of today. It takes a multi-layered approach and as such, the various layers of protection must be enforced. So telling yourself that you have anti-virus protection on your PC is being as naïve as saying the threats doesn’t affect me and i’m not worried about them. While it is true that most anti-virus vendors are bundling multiple threat protection/prevention layers into their solutions, the proper configuration becomes the caveat to that solution. While many deploy with an out of the box config, there will be tweaks needed to customize it to your environment and needs. So one must understand what is being deployed and if it will provide the layers of protection needed.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So why is IT Security so serious for me as a self employed or home based business?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Well, ask yourself these questions,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What is it that you do and how do you do it?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you use email?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you send emails to customers/clients/partners/associates/potential clients?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you leverage the powers of social networking/media (Twitter, LinkedIn, MySpace, Facebook, Ning and the list goes on) today?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you use IM for personal and/or business use?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you browse the internet for data/information on whatever you’re working on or researching?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you do online banking or shopping?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you download multimedia contents from the web (music, movies, flash videos, etc)?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you download online presentations (PDF, PowerPoint)? </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Did you know that PDF files presented one of the biggest security risks over the past 2 years but is the most widely distributed online document format?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you have a printer or some media player connected to you system(s) at home or in the office?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you have any applications running on that system aside from the operating system?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Do you know of the Breach Notification Law in your state and what it means for you?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When was the last time you downloaded a keygens or crack file to open full access to that app or game you really wanted but didn’t want to buy/pay for?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Maybe you didn’t crack/keygen it but someone did and opened a backdoor which planed a rootkit or some nefarious threats on your system(s). What happens when you use that for business purposes, what are you spreading to those you collaborate with?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Well by now i’m sure you’ve caught my drift and I don’t have to get technical for you to see how you’re affected. All these questions pose security risks in various ways and are able to be stopped, prevented and protected if the proper education, awareness and measures are put in place. Don’t ask if you’re affected or if I should be taking these things seriously, you must. You are as much a risk to me as I am to you if the proper steps are not implemented to secure your system and the data/information you have sitting on it about me, you and those you collaborate with.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">That system is being used for personal and business use and at some point the access to/from or by a threat is heightened because of the lack of separation of the two. A system that is used by everyone in the home should not be the same used for doing your business. When someone in the home decides to crack that app and opens that backdoor, you’ll never know what can come through it and what your risk factor will be or are. Separate the two, business is business and personal is personal. The cost of a system today is much more affordable than a few years ago so it shouldn’t be a problem to get an extra one.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">You are not a small business because you have 5 people working for you. You are not a small business because you only have 5 computers in your office or where you decide to conduct your business. To me as a security professional you are not a small business (home based or in an office) when you have records/information and access to 5000 people. A doctor who has an office with 5 employees and 8 systems managing 4000 patients’ info is not a small business in my eyes. If you’re a consultant running your own business and you manage systems or information for your clients you’re now there biggest risk because it’s your responsibility to control that. Every PC must be secured whether it is connected online or not as you never know if/when it will cross the line. This is how I see security.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When you decide to start doing business today you must consider the role you play with those in which you will be doing business and the kinds of interaction you will have with them. When sending an email from an infected system (whether you did or the resident worm) it is still coming from you and the possible effect on the recipient(s) can be adverse which may lead to legal issues.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When using social network can enhance your presence and what you do significantly, it is also an area of heightened risk both personally and professionally. Know the need and use it accordingly. Social networks are the future of collaboration but one must decide why the need and create the separation. If it’s for personal use one should always remember the impact on themselves as they are now putting themselves out there to the world. If for business, one should decide on how they want to be seen and what they would like the world to know about them and what they do. Social networking is a great thing to have and use, it’s the management and control of that presence that matters. The threats people face on social networks are the same they would face outside of it but just through a different medium. Educate yourself on these things and you will be ok.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As for the Breach Notification Law, most people didn’t even know of such laws about digital contents and its security. I strongly suggest you take a look at the law of your state and understand the legal and financial issues it presents for you. Learn it, know it, and understand it. If in doubt, reach out.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The active Conficker worm should be enough of an eye opener for you and if you don’t know what it is then you may have bigger problems that I thought. Security is not just about you, it’s about your way of life today both on and offline. I am not here to scare you but it is better to know before than after as the damage control, legal and financial issues after the fact is much worse and a very daunting issue.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As for the online scams, phishing and SPAM, it is only going to get worse and until you educate and make yourself more aware of and about them, you may fall victim to them as they are craftier than ever.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Ok so I have chatted enough and now you’re saying this is too much so I will leave a few articles of reference.<span style="mso-spacerun: yes;">  </span>Feel free to contact me if you’d like to discuss further and in more details.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="mso-spacerun: yes;"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: The Conficker Worm – my review" href="http://theitsecurityattache.com/blogs/2009/03/29/the-conficker-worm-%e2%80%93-my-review/"><span style="color: #800080;">The Conficker Worm – my review</span></a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: A grim day for browser security at hacker contest" href="http://theitsecurityattache.com/blogs/2009/03/25/a-grim-day-for-browser-security-at-hacker-contest/">A grim day for browser security at hacker contest</a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: State Security Breach Notification Laws as of December 16, 2008 and the Conficker worm" href="http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/"><span style="color: #800080;">State Security Breach Notification Laws as of December 16, 2008 and the Conficker worm</span></a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: IT Security Education and Awareness 04-09 #1 - IT Security is a people problem, not an industry one" href="http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/">IT Security Education and Awareness 04-09 #1 &#8211; IT Security is a people problem, not an industry one</a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website" href="http://theitsecurityattache.com/blogs/2009/03/26/apple-mac-users-warned-of-web-based-malware-threats-rsplug-f-mac-trojan-horse-distributed-via-hdtv-website/">Apple Mac users warned of web-based malware threats RSPlug-F Mac Trojan horse distributed via HDTV website</a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: TITSSN leverages the Twitter network for critical alerting, notification and network happenings (meetings and events) as of April 1st 2009" href="http://theitsecurityattache.com/blogs/2009/04/02/titssn-leverages-the-twitter-network-for-critical-alerting-notification-and-network-happenings-meetings-and-events-as-of-april-1st-2009/">TITSSN leverages the Twitter network for critical alerting, notification and network happenings (meetings and events) as of April 1st 2009</a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a title="Permalink: Security/Privacy Awareness 03-09 #1 - Do you understand the breach notification law is in your country/state, do you know what it means, all are affected." href="http://theitsecurityattache.com/blogs/2009/03/29/securityprivacy-awareness-03-09-1-do-you-understand-the-breach-notification-law-is-in-your-countrystate-do-you-know-what-it-means-all-are-affected/"><span style="color: #800080;">Security/Privacy Awareness 03-09 #1 &#8211; Do you understand the breach notification law is in your country/state, do you know what it means, all are affected.</span></a></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Thank you and have a great day,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~<strong style="mso-bidi-font-weight: normal;">Brett A. Scudder</strong>~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché </span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/13/self-employed-home-based-business-must-take-it-security-very-seriously/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>IT Security Education and Awareness 04-09 #1 &#8211; IT Security is a people problem, not an industry one</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 02:44:27 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[401K]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[Backdoors]]></category>
		<category><![CDATA[Blended Threats]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Crack Files]]></category>
		<category><![CDATA[Crackers]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[End Users]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Health Insurance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Keygens]]></category>
		<category><![CDATA[Life Insurance]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[People problem]]></category>
		<category><![CDATA[The IT Security Threats Landscape]]></category>
		<category><![CDATA[TITSTL]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=352</guid>
		<description><![CDATA[Good day to you,
 
Every day I talk with people across all vertical markets, business sizes, organizations and cultures about the IT Security issues being faced in our world today and how it impacts our everyday lives, and it is becoming one of those awakening kind of issues for many. Whether they like it or not, [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Good day to you,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Every day I talk with people across all vertical markets, business sizes, organizations and cultures about the IT Security issues being faced in our world today and how it impacts our everyday lives, and it is becoming one of those awakening kind of issues for many. Whether they like it or not, they know they are affected in one way or another. While most people tend to try and figure out if and where they fit into this Matrix, the recent mass media explosion of the Conficker worm created somewhat of a sense of understanding as many now saw it from a non technical aspect and as what it really is, a people problem.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As a security attaché, I have relayed this message of IT Security being a people problem and not an industry one for years but it doesn’t resonate well for many because they didn’t understand the matrix and how it worked. Now that they saw and heard of it on the TV (which is an even bigger influencer on people today), the same things we IT people have been trying to tell them now makes some kind of sense. Let us take away the fact that whether the media coverage on the TV was doing much justice or help for the issue(s), it did add a well needed visibility to the scope of the problem and that was very well needed today. It would be nice if we say a segment on the news specific to The IT Security Threats Landscape ~TITSTL~ and issues in and around it. They could bring in some professionals in the field to talk about the issues and what is going on and how people can protect themselves in it. That would be a well needed thing to see at that level today as we are going into this vast technology future of ours which we’re taking head on without looking at the real implications and effects of it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The logic behind the issue is simple, because your system(s) are up and running and have not been wiped out nor shut down by a threat doesn’t mean it is safe, secure or threat free. In many of my health assessments I have shown the owner my findings of worms, trojans and other blended threats that are sitting on their systems because of lack of proper security solutions to protect them or the improper configuration of the solution being used. The fact that they are there is one thing, what they are doing is something else and both are critical issues to ponder.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">While many will refute this fact, I have seen, worked and handled enough of these cases to state as a fact that many fall into this area of The IT Security Threats Landscape. A resident rootkit, keylogger, worm or whatever the variant may be, is actively working its way through your system and causing some form of data loss/theft or compromising the state of applications, connectivity or system stability that we security professionals deem critical. Here is another way to look at this. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If you went to the doctor for a cough that has been bugging you for a while and he says to you, you have a chest or respiratory infection would you tell him no?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If he says to you that you need antibiotics and some cold medicine do you tell him no?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Why not?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Because, this is his field of expertise and study and as such he can make this assessment based on his knowledge of the issue and the facts he has from testing you.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Are you a medical person to dispute his statement and will you seek a second opinion from someone else?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The fact that you’re still alive and well (somewhat, depending on how you define well) does not negate the reality of the issue that you are infected with something that is causing some kind of issue/effect on the body resulting in that cough which in our field of IT we would call an early warning. So, this is the same way in which we look at the IT Security issues of today and how people tend not to look at it. They haven’t gotten that early warning of a cough because the system hasn’t picked up on it yet and when it does happen, because they have not fallen and can’t get up this is not a critical issue. The system becoming slow and unresponsive is that early warning and at that stage most people tend to seek professional help depending on the need/use of the system and how critical it may be for business or even personal use.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So here we stand dealing with people who are harvesters of thousands of people’s information and things about them (whether you know or like it) and they rest idle to this decadent behavior and mindset. Yet, unchecked, their systems sit comfortably hosting these blended threats which are sending/stealing critical private, personal, financial data/information to these hackers unbeknownst to them. The careless whisper of ignorance to these issues is the driving force behind the growing success of such threats today. A hacker have so much more to gain from you giving it to them than for them having to go through getting it from you and is why the botnet issue is such a growing one today. The use of keygens, crack files, peer to peer (P2P), unpatched applications and systems makes it so much easier to exploit what is available that one tends to wonder when and where does it end. It ends with user education and awareness on and about the threats landscape and what these issues are. It end when people start taking this seriously and realizes that you’re just as much a victim as anyone anywhere if you’re not protected properly.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you stop saying I have anti-virus protection and so i’m ok when you know you haven’ renewed that subscription over six months ago and so you’re missing all the latest and greatest signature based protection that it should provide. Anti-virus alone CANNOT protect you from the threats out there today, it has to be a layered approach where various solutions are in play to cover the needed layers.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you wake up from this illusion that my OS is more secure than the other and so I don’t have to worry about these security issues.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when we stop underestimating the knowledge of your youths and start educating them much early on the proper use of the internet and the functions and features of it. IT Security must be a part of the school curriculum today as technology is our future for tomorrow and they are our next generation of professionals and leaders.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you start accepting the fact that you are as much a risk to me as I am to you if we’re not practicing basic IT Security best practices.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you stop taking the cheap way out of operating a business when hosting people’s private and confidential information which is priceless to them and they trust you to keep it secure. Have some respect for your customers and let them rest comfortable knowing that you have their best interests at heart in properly protecting your infrastructure.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you realize that these threats are released in the wild with no specific targets but the system(s) you’re using which unfortunately is in the homes, schools, workplaces and places of general interest. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The treats are not specific to government and their systems. It is not specific to the private or public sectors. It is not specific to the educational institutions and it certainly isn’t targeting the healthcare sector only. All are affected and are in the path of these threats because, they are all sharing the same interconnectivity transport medium, the internet and the internet respects no one and has no boundaries.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It is time that people take this as a basic part of their lives where one does not get consumed on questioning the validity or severity of the threat but questioning the readiness of themselves and their systems to face them. While our government may understand the real scope of these issues, their efforts to create effective management and policies to protect the country’s infrastructure are missing critical elements, the people and the roles they play in strengthening the protective layers or being a weak link and point of entry/compromise for what is being implemented. Unless we strengthen the people through education and awareness they will always be a weak link in the chain of protection.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When a company is hacked or they lose their data by whatever means there is, who suffers the most, the employees, the end users. The company suffers a data loss or has a breach but the actual data may be your private and confidential information. Even if the company loses its financial data, it has a much better recovery rate through insurance and such than an individual who now suffers from the loss of privacy and here in the US, credit ratings. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Think about the many places that have information about you that you consider to be private and confidential. Your employer has your social security info (and possibly family members who are covered by you), some financial info for direct depositing of your paychecks. Your 401K info. Health and life insurance info.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Your doctor has your private health records and, results. They have your family’s private info as well as some kind of visit may have been had over the years and that info is in the system.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Your bank has all your financial info and records. They may have your mortgage info as well (if you own a home). The car loan and all the info in it. Student loans and the works.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So think on these things and when you look at all of them, who is most affected in the event of a data loss or breach at any one of those kinds of organizations or businesses, you, the end user, consumer, employee.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">IT Security is a people problem and must be dealt with accordingly. It is not about selling security, it’s about creating greater education and awareness about it so we can all contribute towards upholding the strengths of the protective security layers that are there for our protection.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Stop asking if this is real, ask yourself, how do I protect myself, my family, my business, my country from these elements and there effects. This is REAL.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When in doubt, reach out.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~Brett A. Scudder~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What the Conficker is going on. All is well so far, still time to patch up and prepare, vendors wild on signature releases</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/01/what-the-conficker-is-going-on-all-is-well-so-far-still-time-to-patch-up-and-prepare-vendors-wild-on-signature-releases/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/01/what-the-conficker-is-going-on-all-is-well-so-far-still-time-to-patch-up-and-prepare-vendors-wild-on-signature-releases/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 07:02:26 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Schedule]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Definitions]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[Security Solutions]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Vendors]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=273</guid>
		<description><![CDATA[Hi all,
 
If your day went like mine then you must be beat, phew, what a week so far.
 
It’s 3am and i’m scanning the wires, net and blogs to see what’s up with Conficker so far. All is well and from the looks of things you still have time to get those patches loaded, get that [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Hi all,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If your day went like mine then you must be beat, phew, what a week so far.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It’s 3am and i’m scanning the wires, net and blogs to see what’s up with Conficker so far. All is well and from the looks of things you still have time to get those patches loaded, get that anti-virus/anti-malware loaded, configured and run a full/deep scan.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I just completed a full scan of my network and double checked my logs and settings and everything looks ok. We’re still early into the day and so who knows.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">For those who are saying it could be a joke/hoax and not preparing for it,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">What if it isn’t?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Would you want to be prepared even if it isn’t?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I see that the anti-virus vendors have been busy. Some have released 4-6 new definition updates over the past 12 hrs and that’s a good sign. It means they are still working diligently on helping us stay secure. By the time it hits morning here in the US everyone should be running some April 1<sup>st</sup> 2009 definitions as I expect there will be at least 1 or 2 within the first 8hrs. If you’re not running with an April 1<sup>st</sup> def, then make sure you’re at least at March 31<sup>st</sup> after running an auto update for definitions.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I haven’t slept since Saturday just from prepping for today and helping people get their systems patched, updated and secured but I am surely going to catch a few zzzzzzz in a few.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The day is young, be safe than sorry, patch and secure up and rest well.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Until later when I rise,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></strong></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/01/what-the-conficker-is-going-on-all-is-well-so-far-still-time-to-patch-up-and-prepare-vendors-wild-on-signature-releases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker&#8217;s cure? So what happens now? Is this the end, NO.</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:04:36 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[My Writings]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Acrobat]]></category>
		<category><![CDATA[Adobe Reader]]></category>
		<category><![CDATA[Blended Threats]]></category>
		<category><![CDATA[Conficker Worm]]></category>
		<category><![CDATA[Fixes]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[Media Players]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[QuickTime]]></category>
		<category><![CDATA[Signatures]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerable Apps]]></category>
		<category><![CDATA[Web Browsers]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=265</guid>
		<description><![CDATA[FYI&#8230; 
Original URL: http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/

Busted! Conficker&#8217;s tell-tale heart uncovered

Researchers find super worm cure, just in time
By Dan Goodin in San Francisco
Posted in Software &#38; Security, 30th March 2009 11:02 GMT
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
My thoughts, feedback and input.
You have a few hours to work on this and I know you’re going to be vigilant about it. Let’s save what and who [...]]]></description>
			<content:encoded><![CDATA[<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">FYI&#8230; </span></span></p>
<p class="orig-url" style="margin: auto 0in; line-height: 14.25pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="color: black; mso-ansi-language: EN;" lang="EN">Original URL: </span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a href="http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/"><span style="font-size: 12pt; color: purple; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">http://www.channelregister.co.uk/2009/03/30/conficker_signature_discovery/</span></a></span></span></span></p>
<p><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"></strong><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 15.5pt; color: #303030; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN;" lang="EN"></p>
<p class="MsoNormal" style="margin: 12pt 0in 3pt; mso-line-height-alt: 14.25pt;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 18pt; color: #303030; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN">Busted! Conficker&#8217;s tell-tale heart uncovered</span></strong></p>
<p></span></strong></span></p>
<p class="standfirst1" style="margin: 0in 0in 3pt; line-height: 14.25pt;"><span style="font-family: Times New Roman;"><strong><span style="font-size: 13.5pt; color: #303030; mso-ansi-language: EN;" lang="EN">Researchers find super worm cure, just in time</span></strong><strong><span style="font-size: 13.5pt;"></span></strong></span></p>
<p class="byline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="font-size: small;"><span style="font-family: Times New Roman;"><span style="color: black; mso-ansi-language: EN;" lang="EN">By </span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a title="Send email to the author" href="http://forms.channelregister.co.uk/mail_author/?story_url=/2009/03/30/conficker_signature_discovery/"><strong><span style="font-size: 12pt; color: #0000dd; font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Dan Goodin in San Francisco</span></strong></a></span></span></span><span style="font-size: 10pt; color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;;"></span></p>
<p class="dateline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="font-family: Times New Roman;"><span style="font-size: small;"><span style="color: black; mso-ansi-language: EN;" lang="EN">Posted in </span><span style="color: black; font-family: &quot;Georgia&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><a href="http://www.channelregister.co.uk/software_security/"><span style="font-family: &quot;Times New Roman&quot;,&quot;serif&quot;;">Software &amp; Security</span></a></span></span><span style="color: black; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">, 30th March 2009 11:02 GMT</span></span></span></p>
<p class="dateline1" style="margin: 6pt 0in; line-height: 14.25pt;"><span style="color: black; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;"><span style="font-family: Times New Roman;">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</span></span></span></p>
<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">My thoughts, feedback and input.</span></span></p>
<p class="orig-url" style="margin: auto 0in;"><span style="color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-ansi-language: EN;" lang="EN"><span style="font-size: small;">You have a few hours to work on this and I know you’re going to be vigilant about it. Let’s save what and who we can with our best efforts. Time is of the essence so get to it. I will be a bit busy for the next few hours checking on new vendor signature releases and info about this, dealing with my internal network and doing some last minute checking and changes so please pardon any delays in my responses for a while.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">So now that signatures are being released for it is it over?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">No it’s not. This is a staged effort. The signatures will be created, disseminated throughout the various security scanners, anti-virus and anti-malware vendor products but then comes the updating and patching of the systems. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are running an older version of a vendor product I strongly suggest you upgrade it now.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are running any definitions other than March 31<sup>st</sup> 2009 for your anti-virus and anti-malware solution then you’re not fully protected yet.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you are still missing Microsoft Windows patches (any and all of them) then there’s still some level of risk for you.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">If you’re running vulnerable applications like Adobe Reader, Acrobat, Firefox, iTunes, QuickTime, web browsers, media players and other applications check to make sure you’re not missing any vendor patches. The developers have released secure versions recently.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I still stick to my original take on this which is, if you are already infected just wipe and start over. There’s no real guarantee that you will fully get rid of the infection and the various pieces it comes with. If not, you have a good set of protective layers to work with.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Keep in mind that a signature based solution works off detecting via signature and not anomaly based threats. As Conficker is a blended threat, I expect to see some aspects of it still evading some security solutions if not configured properly for effective use. Some people have their solutions configured with out of the box settings which may not be optimally configured for a critical threat like this with such a rapid change effect rate.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">I know this is short timing but it is good timing to get the word out and get people to act quickly. Be kind and help to spread the word to your family, friends, partners, associates, peers and anyone you converse with. This is critical info that needs to be shared.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Let’s get to it people. I’ve been up since Saturday helping people with their systems and talking about this and I plan to get some sleep over the next day or two.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">Good luck and please keep me posted on any new developments and happenings around this once April 1<sup>st</sup> kicks in.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">~<strong style="mso-bidi-font-weight: normal;">Brett A. Scudder</strong>~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: 12pt; color: #000099; font-family: &quot;Garamond&quot;,&quot;serif&quot;; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/31/confickers-cure-so-what-happens-now-is-this-the-end-no/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PDF Exploits in the wild, patch people, PATCH. For the love of a safer internet please PATCH your applications</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/30/pdf-exploits-in-the-wild-patch-people-patch-for-the-love-of-a-safer-internet-please-patch-your-applications/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/30/pdf-exploits-in-the-wild-patch-people-patch-for-the-love-of-a-safer-internet-please-patch-your-applications/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 14:09:20 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[FoxIt]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[PDF Exploits]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=248</guid>
		<description><![CDATA[

This just in from Sunbelt Software.
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
 
Fwiw, we&#8217;re seeing a fair number of PDF exploits in the wild.  There are versions attaching vulnerabilities in both Adobe and FoxIt readers.  
 
VIPRE has robust coverage for these threats.  As an example, here is a Virustotal report for this morning on an in-the-wild sample:
 
http://www.virustotal.com/analisis/cebedbb05df33870556200cf45fb510e 
 
I would still encourage all [...]]]></description>
			<content:encoded><![CDATA[<div></div>
<p><span style="font-family: Garamond; color: #000099; font-size: small;"></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">This just in from Sunbelt Software.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Fwiw, we&#8217;re seeing a fair number of PDF exploits in the wild.<span style="mso-spacerun: yes;">  </span>There are versions attaching vulnerabilities in both Adobe and FoxIt readers.<span style="mso-spacerun: yes;">  </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">VIPRE has robust coverage for these threats.<span style="mso-spacerun: yes;">  </span>As an example, here is a Virustotal report for this morning on an in-the-wild sample:</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a href="http://www.virustotal.com/analisis/cebedbb05df33870556200cf45fb510e">http://www.virustotal.com/analisis/cebedbb05df33870556200cf45fb510e</a> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">I would still encourage all of you to make sure that Acrobat readers in your company are updated with the latest versions from Adobe.<span style="mso-spacerun: yes;">  </span>These exploits are quite nasty, as some will infect with just a mouse-over on a file.<span style="mso-spacerun: yes;">  </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><strong>Alex Eckelberry</strong></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">CEO Sunbelt-Software</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a href="http://www.sunbelt-software.com/">www.sunbelt-software.com</a> </span></p>
<p> </p>
<p></span></p>
<p class="MsoPlainText" style="margin: 0in 0in 0pt;"> </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/30/pdf-exploits-in-the-wild-patch-people-patch-for-the-love-of-a-safer-internet-please-patch-your-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>State Security Breach Notification Laws as of December 16, 2008 and the Conficker worm</title>
		<link>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 16:38:58 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Community Programs/Initiatives]]></category>
		<category><![CDATA[IT Security Alerts, Notices and Advisories]]></category>
		<category><![CDATA[Online Articles for Discussion]]></category>
		<category><![CDATA[Schedule]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Breach Notification Laws]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Conficker Worm]]></category>
		<category><![CDATA[Devices]]></category>
		<category><![CDATA[Drivers]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Rogue Anti-Virus 2008/9]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=220</guid>
		<description><![CDATA[This is from an email I sent out to my network distribution list today at 12 noon.
 
Good day to you,
 
This is a critical issue that has been highly overlooked and is a bigger problem than most people care to think. For those of us consultants who are responsible for our client’s infrastructure, please help them [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">This is from an email I sent out to my network distribution list today at 12 noon.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Good day to you,</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">This is a critical issue that has been highly overlooked and is a bigger problem than most people care to think. For those of us consultants who are responsible for our client’s infrastructure, please help them to understand where these laws apply and how it affects them. I’m bringing in someone from the attorney general’s office to do a presentation on this for us in the coming month. I’m trying to work with their schedule so stay tuned for the date of the meeting.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">There are some serious new threats on the loose and the more I look at them is the easier i’m seeing the rate of success in their deliverables. Our organization speaks to these issues and we must understand what they mean for those we’re helping to understand. This new variant of the Conficker worm has some nasty new tricks to it and while following its development and path, i’m more convinced that this is a new level of sophistication way above the rogue Anti-Virus/Anti-Spyware 2008/2009 threat we encountered last year that is still being a major pain point for IT today. Whether this is an April fools days joke or not, as you can see, the financial ramifications of negligence will be heavy.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Get those system (OS, applications, devices) patches updated and current. Most people tend to patch the OS and leave vulnerable applications running with system access to the OS that even fully patched is still vulnerable. Patching is an all round process that applies to the OS, applications running on it and the devices being connected to it. Even the device drivers are a point of entry to a system today so patch them if needed. Check on those security policies and rules and ensure they are up and running. We have a few days before April 1<sup>st</sup> so talk with your people about this and let them understand the need for being prudent about it.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Make no mistake people, this is a new age where technology rules and the threats are more real than ever before. This is not someone physically walking in and taking your data, this is someone sitting anywhere in the world and having access to it (if allowed).</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">I posted this on LinkedIn here <a href="http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950">http://www.linkedin.com/answers/using-linkedIn/ULI/447971-3071950</a> for a broader visibility from the business professional’s community. More feedback and input will be found there as well. Spread the word.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">Thank you and have a great day,</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;">~Brett A. Scudder~</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt;"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><strong><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 18pt;">State Security Breach Notification Laws</span></strong></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-size: small;"><em><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;;">As of December 16, 2008</span></em><em><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"></span></em></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;;"><a href="http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm"><span style="color: #800080; font-size: small;">http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm</span></a></span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/03/29/state-security-breach-notification-laws-as-of-december-16-2008-and-the-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
