<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Philosophically Secure &#187; security</title>
	<atom:link href="http://eugk.net/wordpress/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://eugk.net/wordpress</link>
	<description>Eugene Kogan&#039;s blog on information security and software engineering</description>
	<lastBuildDate>Wed, 13 Jan 2010 01:11:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sandia to boot behemoth botnet</title>
		<link>http://eugk.net/wordpress/2009/08/12/sandia-to-boot-behemoth-botnet/</link>
		<comments>http://eugk.net/wordpress/2009/08/12/sandia-to-boot-behemoth-botnet/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 00:18:00 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=261</guid>
		<description><![CDATA[I'm looking forward to finding out the results of this research!
[Sandia's] Thunderbird supercomputer will periodically run a million virtual machines all at once, all with botnet client software. By setting this large network of systems into operation, the researchers, Ron Minnich and Don Rudish, hope to better understand how botnets operate.
It's a cool idea, and [...]]]></description>
			<content:encoded><![CDATA[<p>I'm looking forward to finding out the results of this research!</p>
<blockquote><p>[<a href="http://www.sandia.gov/news/resources/releases/2009/linux.html">Sandia's</a>] Thunderbird supercomputer will periodically run a million virtual machines all at once, all with botnet client software. By setting this large network of systems into operation, the researchers, <a href="http://www.linkedin.com/pub/ron-minnich/3/994/960">Ron Minnich</a> and Don Rudish, hope to better understand how botnets operate.</p></blockquote>
<p>It's a cool idea, and could probably keep me busy forever. The only issue I have with this project is that the time and money would be better spent on trying to improve the fundamental security issues of our computing model, rather than just learning about a symptom (in this case, botnets). Still, it sounds like fun, and will hopefully produce some actionable knowledge in a year or two.</p>
<p>via <a href="http://gcn.com/articles/2009/08/10/sandia-botnet.aspx">Sandia to boot behemoth botnet -- Government Computer News</a>.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DSandia%2520to%2520boot%2520behemoth%2520botnet%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F%26amp%3Btitle%3DSandia%2520to%2520boot%2520behemoth%2520botnet%26amp%3Bbodytext%3DI%2527m%2520looking%2520forward%2520to%2520finding%2520out%2520the%2520results%2520of%2520this%2520research%2521%250D%250A%255BSandia%2527s%255D%2520Thunderbird%2520supercomputer%2520will%2520periodically%2520run%2520a%2520million%2520virtual%2520machines%2520all%2520at%2520once%252C%2520all%2520with%2520botnet%2520client%2520software.%2520By%2520setting%2520this%2520large%2520network%2520of%2520systems%2520into%2520operat';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F%26amp%3Bt%3DSandia%2520to%2520boot%2520behemoth%2520botnet';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F%26amp%3Btitle%3DSandia%2520to%2520boot%2520behemoth%2520botnet%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DI%2527m%2520looking%2520forward%2520to%2520finding%2520out%2520the%2520results%2520of%2520this%2520research%2521%250D%250A%255BSandia%2527s%255D%2520Thunderbird%2520supercomputer%2520will%2520periodically%2520run%2520a%2520million%2520virtual%2520machines%2520all%2520at%2520once%252C%2520all%2520with%2520botnet%2520client%2520software.%2520By%2520setting%2520this%2520large%2520network%2520of%2520systems%2520into%2520operat';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F%26amp%3Btitle%3DSandia%2520to%2520boot%2520behemoth%2520botnet%26amp%3Bnotes%3DI%2527m%2520looking%2520forward%2520to%2520finding%2520out%2520the%2520results%2520of%2520this%2520research%2521%250D%250A%255BSandia%2527s%255D%2520Thunderbird%2520supercomputer%2520will%2520periodically%2520run%2520a%2520million%2520virtual%2520machines%2520all%2520at%2520once%252C%2520all%2520with%2520botnet%2520client%2520software.%2520By%2520setting%2520this%2520large%2520network%2520of%2520systems%2520into%2520operat';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F08%252F12%252Fsandia-to-boot-behemoth-botnet%252F%26amp%3Btitle%3DSandia%2520to%2520boot%2520behemoth%2520botnet';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2009/08/12/sandia-to-boot-behemoth-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The end of the world and Conficker.C</title>
		<link>http://eugk.net/wordpress/2009/03/28/the-end-of-the-world-and-confickerc/</link>
		<comments>http://eugk.net/wordpress/2009/03/28/the-end-of-the-world-and-confickerc/#comments</comments>
		<pubDate>Sat, 28 Mar 2009 11:23:29 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=240</guid>
		<description><![CDATA[There is way too much hype about Conficker.C and what it may or may not do on April 1. I'm not sure who is feeding the media, which is fueling the hype, but it's very counterproductive. There are worse threats out there than this one botnet, and focusing all of our attention on Conficker is [...]]]></description>
			<content:encoded><![CDATA[<p>There is way too much hype about Conficker.C and what it may or may not do on April 1. I'm not sure who is feeding the media, which is fueling the hype, but it's very counterproductive. There are worse threats out there than this one botnet, and focusing all of our attention on Conficker is letting the others go unchecked.</p>
<p>Rather than rehash what's already known about Conficker.C, I'll just point readers to an excellent <a href="http://www.f-secure.com/weblog/archives/00001636.html">Q&amp;A post from F-Secure</a>. Question number one:</p>
<blockquote><p><span class="rss:item">Q: I heard something really bad is going to happen on the Internet on April 1st! Will it?<br />
A: No, not really.</span></p></blockquote>
<p><span class="rss:item">If that's not enough information for you, read the rest of their post, and stop freaking out.</span></p>
<p><span class="rss:item"><strong>Update:</strong> I just read an interesting post on this topic from Verizon Business Security (<a href="http://securityblog.verizonbusiness.com/2009/03/26/risk-group-think-and-the-conficker-worm/">Risk, Group Think and the Conficker Worm</a>), which I saw thanks to <a href="http://taosecurity.blogspot.com/2009/03/network-security-monitoring-lives.html" target="_blank">TaoSecurity</a>.<br />
</span></p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F%26amp%3Btitle%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C%26amp%3Bbodytext%3DThere%2520is%2520way%2520too%2520much%2520hype%2520about%2520Conficker.C%2520and%2520what%2520it%2520may%2520or%2520may%2520not%2520do%2520on%2520April%25201.%2520I%2527m%2520not%2520sure%2520who%2520is%2520feeding%2520the%2520media%252C%2520which%2520is%2520fueling%2520the%2520hype%252C%2520but%2520it%2527s%2520very%2520counterproductive.%2520There%2520are%2520worse%2520threats%2520out%2520there%2520than%2520this%2520one%2520botnet%252C%2520and%2520focu';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F%26amp%3Bt%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F%26amp%3Btitle%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThere%2520is%2520way%2520too%2520much%2520hype%2520about%2520Conficker.C%2520and%2520what%2520it%2520may%2520or%2520may%2520not%2520do%2520on%2520April%25201.%2520I%2527m%2520not%2520sure%2520who%2520is%2520feeding%2520the%2520media%252C%2520which%2520is%2520fueling%2520the%2520hype%252C%2520but%2520it%2527s%2520very%2520counterproductive.%2520There%2520are%2520worse%2520threats%2520out%2520there%2520than%2520this%2520one%2520botnet%252C%2520and%2520focu';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F%26amp%3Btitle%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C%26amp%3Bnotes%3DThere%2520is%2520way%2520too%2520much%2520hype%2520about%2520Conficker.C%2520and%2520what%2520it%2520may%2520or%2520may%2520not%2520do%2520on%2520April%25201.%2520I%2527m%2520not%2520sure%2520who%2520is%2520feeding%2520the%2520media%252C%2520which%2520is%2520fueling%2520the%2520hype%252C%2520but%2520it%2527s%2520very%2520counterproductive.%2520There%2520are%2520worse%2520threats%2520out%2520there%2520than%2520this%2520one%2520botnet%252C%2520and%2520focu';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F03%252F28%252Fthe-end-of-the-world-and-confickerc%252F%26amp%3Btitle%3DThe%2520end%2520of%2520the%2520world%2520and%2520Conficker.C';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2009/03/28/the-end-of-the-world-and-confickerc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We need more than a new Internet</title>
		<link>http://eugk.net/wordpress/2009/02/16/we-need-more-than-a-new-internet/</link>
		<comments>http://eugk.net/wordpress/2009/02/16/we-need-more-than-a-new-internet/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 13:20:08 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=231</guid>
		<description><![CDATA[It's nice to see the New York Times write on the topic of Internet security, and actually focusing on a more radical solution than normal. The article basically says, Internet security is so broken that we need to start over with a "new Internet." Sounds like fun, but that seriously misses the point.
If we are [...]]]></description>
			<content:encoded><![CDATA[<p>It's nice to see the New York Times write on the topic of Internet security, and actually focusing on a more radical solution than normal. The article basically says, Internet security is so broken that we need to start over with a "<a href="http://www.nytimes.com/2009/02/15/weekinreview/15markoff.html?_r=1&amp;ref=weekinreview" target="_blank">new Internet</a>." Sounds like fun, but that seriously misses the point.</p>
<p>If we are going to go down the path of starting over, why not go right to the root of the problem, and fix our hardware? Now that we know what kinds of vulnerabilities exist in our existing designs (based on the <a href="http://www.forth.gr/onassis/lectures/2008-07-21/presentations_08/vonNeumann_and_the_current_computer_security_landscape.pdf" target="_blank">von Neumann architecture</a>), we could create a new hardware platform that has security and privacy protections built in. This would naturally lead to a new kind of software, which could take advantage of the new hardware features and architectural decisions, to keep itself secure. Since the Internet is just a collection of networking hardware and software, it would obviously also benefit.</p>
<p>In fact, by rethinking the very basic underpinnings of computer design, we can propagate the results throughout the entire CPU-based world, not just the Internet. Trying to fix only one part of the problem, such as by creating "a 'gated community' where users would give up their anonymity and certain freedoms in return for safety" would be a disaster. Not only would it quickly be broken and misused, like every other attempt to do something similar, but it would eliminate one of the best features of the Internet that caused it to thrive in the first place.</p>
<p>Sadly, I doubt we will ever be able to "start over" on something like this (IPv6, anyone?). I mean, there are so many aspects of life that could use the benefit of hindsight and a redesign, like politics, tax law, health care... but they are too entrenched in society to be replaced by better systems. That makes for good job security for those of us in the computer security field, as long as we can put up with the feeling of continuous frustration, knowing that a true <a href="http://en.wikipedia.org/wiki/Modified_Harvard_architecture" target="_self">alternative</a> is possible, but we are essentially powerless to pursue it.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F%26amp%3Btitle%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet%26amp%3Bbodytext%3DIt%2527s%2520nice%2520to%2520see%2520the%2520New%2520York%2520Times%2520write%2520on%2520the%2520topic%2520of%2520Internet%2520security%252C%2520and%2520actually%2520focusing%2520on%2520a%2520more%2520radical%2520solution%2520than%2520normal.%2520The%2520article%2520basically%2520says%252C%2520Internet%2520security%2520is%2520so%2520broken%2520that%2520we%2520need%2520to%2520start%2520over%2520with%2520a%2520%2522new%2520Internet.%2522%2520So';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F%26amp%3Bt%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F%26amp%3Btitle%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DIt%2527s%2520nice%2520to%2520see%2520the%2520New%2520York%2520Times%2520write%2520on%2520the%2520topic%2520of%2520Internet%2520security%252C%2520and%2520actually%2520focusing%2520on%2520a%2520more%2520radical%2520solution%2520than%2520normal.%2520The%2520article%2520basically%2520says%252C%2520Internet%2520security%2520is%2520so%2520broken%2520that%2520we%2520need%2520to%2520start%2520over%2520with%2520a%2520%2522new%2520Internet.%2522%2520So';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F%26amp%3Btitle%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet%26amp%3Bnotes%3DIt%2527s%2520nice%2520to%2520see%2520the%2520New%2520York%2520Times%2520write%2520on%2520the%2520topic%2520of%2520Internet%2520security%252C%2520and%2520actually%2520focusing%2520on%2520a%2520more%2520radical%2520solution%2520than%2520normal.%2520The%2520article%2520basically%2520says%252C%2520Internet%2520security%2520is%2520so%2520broken%2520that%2520we%2520need%2520to%2520start%2520over%2520with%2520a%2520%2522new%2520Internet.%2522%2520So';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F02%252F16%252Fwe-need-more-than-a-new-internet%252F%26amp%3Btitle%3DWe%2520need%2520more%2520than%2520a%2520new%2520Internet';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2009/02/16/we-need-more-than-a-new-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security news items</title>
		<link>http://eugk.net/wordpress/2009/01/19/security-news-items/</link>
		<comments>http://eugk.net/wordpress/2009/01/19/security-news-items/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 18:49:55 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=193</guid>
		<description><![CDATA[Some interesting items in today's security news:
Obama plans to keep his BlackBerry
There will be plenty of security and legal hurdles. Here's one already: "The security question was inadvertently highlighted on Friday as Obama's BlackBerry tumbled from his belt as he exited his limousine and got onto his plane..."
Widest night/day megapixel lens without distortion for the [...]]]></description>
			<content:encoded><![CDATA[<p>Some interesting items in today's security news:</p>
<p><strong><a href="http://www.networkworld.com/news/2009/011709-obama-plans-to-keep-his.html?fsrc=rss-security" target="_blank">Obama plans to keep his BlackBerry</a></strong><br />
There will be plenty of security and legal hurdles. Here's one already: <em>"The security question was inadvertently highlighted on Friday as Obama's BlackBerry tumbled from his belt as he exited his limousine and got onto his plane..."</em></p>
<p><strong><a href="http://www.net-security.org/secworld.php?id=6946" target="_blank">Widest night/day megapixel lens without distortion for the security industry</a></strong><br />
This is cool for those into physical security or surveillance: <em>"Theia leveraged their patented Linear Optical Technology platform with all-optical barrel distortion correction to provide a nominal 110 degree horizontal field of view..."</em> The article has a picture showing the difference from a regular wide angle lens.</p>
<p><strong><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=332461&amp;source=rss_topic17" target="_blank">Frankly Speaking: What would really make software more secure</a></strong><br />
Not a bad idea, although I'm not sure how I feel about yet another expensive software certification process: <em>"...SANS says some state governments are already thinking about requiring software suppliers to certify in writing that their code is free of the errors on the list."</em> Hasn't the federal government already tried similar approaches?</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DSecurity%2520news%2520items%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F%26amp%3Btitle%3DSecurity%2520news%2520items%26amp%3Bbodytext%3DSome%2520interesting%2520items%2520in%2520today%2527s%2520security%2520news%253A%250D%250A%250D%250AObama%2520plans%2520to%2520keep%2520his%2520BlackBerry%250D%250AThere%2520will%2520be%2520plenty%2520of%2520security%2520and%2520legal%2520hurdles.%2520Here%2527s%2520one%2520already%253A%2520%2522The%2520security%2520question%2520was%2520inadvertently%2520highlighted%2520on%2520Friday%2520as%2520Obama%2527s%2520BlackBerry%2520tumbl';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F%26amp%3Bt%3DSecurity%2520news%2520items';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F%26amp%3Btitle%3DSecurity%2520news%2520items%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DSome%2520interesting%2520items%2520in%2520today%2527s%2520security%2520news%253A%250D%250A%250D%250AObama%2520plans%2520to%2520keep%2520his%2520BlackBerry%250D%250AThere%2520will%2520be%2520plenty%2520of%2520security%2520and%2520legal%2520hurdles.%2520Here%2527s%2520one%2520already%253A%2520%2522The%2520security%2520question%2520was%2520inadvertently%2520highlighted%2520on%2520Friday%2520as%2520Obama%2527s%2520BlackBerry%2520tumbl';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F%26amp%3Btitle%3DSecurity%2520news%2520items%26amp%3Bnotes%3DSome%2520interesting%2520items%2520in%2520today%2527s%2520security%2520news%253A%250D%250A%250D%250AObama%2520plans%2520to%2520keep%2520his%2520BlackBerry%250D%250AThere%2520will%2520be%2520plenty%2520of%2520security%2520and%2520legal%2520hurdles.%2520Here%2527s%2520one%2520already%253A%2520%2522The%2520security%2520question%2520was%2520inadvertently%2520highlighted%2520on%2520Friday%2520as%2520Obama%2527s%2520BlackBerry%2520tumbl';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2009%252F01%252F19%252Fsecurity-news-items%252F%26amp%3Btitle%3DSecurity%2520news%2520items';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2009/01/19/security-news-items/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Restoring trust in a compromised network</title>
		<link>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/</link>
		<comments>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 21:39:24 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=170</guid>
		<description><![CDATA[If you know that you have a deeply compromised network, but you can't practically shut it down and rebuild it from scratch, how do you go about cleaning it up and restoring trust in its use? This is a very difficult problem, and I would say that in most cases, it's pretty much impossible to [...]]]></description>
			<content:encoded><![CDATA[<p>If you know that you have a deeply compromised network, but you can't practically shut it down and rebuild it from scratch, how do you go about cleaning it up and restoring trust in its use? This is a very difficult problem, and I would say that in most cases, it's pretty much impossible to ever be completely sure that an intrusion has been removed. However, since reformatting every machine and starting over is usually not a viable option for an operating business, it's important to know how to get as close as practical to restoring trust in a compromised network.</p>
<p>This <a href="http://isc.sans.org/diary.html?storyid=5345">post on the SANS ISC Hander's Diary</a> is a great resource to get you started on the process of pinpointing which hosts on a network are still compromised, and need to be carefully reviewed. Since a large network with many servers is assumed, the easiest way to begin is from the network level, working your way down to host-based solutions.</p>
<p>You can read the post for all the details, but the basic tools and techniques mentioned are:</p>
<ul>
<li>log all DNS queries</li>
<li>store netflow data</li>
<li>log accepted firewall connections</li>
<li>deploy IDS with relevant EmergingThreats rule sets</li>
<li>use <a href="http://www.bothunter.net/" target="_blank">BotHunter</a></li>
<li>carefully monitor DNS traffic for anomalies</li>
<li>monitor web traffic for unusual activity</li>
<li>virus scan as many hosts as possible using <a href="http://www.av-comparatives.org/" target="_blank">good heuristic software</a></li>
<li>check for root kits on critical systems, using something like <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx" target="_blank">RootkitRevealer</a></li>
<li>scan for suspicious executables, using something like <a href="http://www.mandiant.com/mrc" target="_blank">Red Curtain</a></li>
</ul>
<p>Yes, this is a long list of actions, and it can take quite a while to implement. Unfortunately, the longer it takes, the more time your adversary has to reinfect your network, especially if you haven't figured out and closed the hole he used in the first place.</p>
<p>This is why being prepared ahead of time is always a huge advantage. If IDS is already deployed and working, and if you know what your network traffic looks like normally, it becomes a lot easier to detect anamolies when something goes wrong. Hey, if all else fails, you could always unplug the company from the Internet for a few days, right...?</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F%26amp%3Btitle%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network%26amp%3Bbodytext%3DIf%2520you%2520know%2520that%2520you%2520have%2520a%2520deeply%2520compromised%2520network%252C%2520but%2520you%2520can%2527t%2520practically%2520shut%2520it%2520down%2520and%2520rebuild%2520it%2520from%2520scratch%252C%2520how%2520do%2520you%2520go%2520about%2520cleaning%2520it%2520up%2520and%2520restoring%2520trust%2520in%2520its%2520use%253F%2520This%2520is%2520a%2520very%2520difficult%2520problem%252C%2520and%2520I%2520would%2520say%2520that%2520in%2520m';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F%26amp%3Bt%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F%26amp%3Btitle%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DIf%2520you%2520know%2520that%2520you%2520have%2520a%2520deeply%2520compromised%2520network%252C%2520but%2520you%2520can%2527t%2520practically%2520shut%2520it%2520down%2520and%2520rebuild%2520it%2520from%2520scratch%252C%2520how%2520do%2520you%2520go%2520about%2520cleaning%2520it%2520up%2520and%2520restoring%2520trust%2520in%2520its%2520use%253F%2520This%2520is%2520a%2520very%2520difficult%2520problem%252C%2520and%2520I%2520would%2520say%2520that%2520in%2520m';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F%26amp%3Btitle%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network%26amp%3Bnotes%3DIf%2520you%2520know%2520that%2520you%2520have%2520a%2520deeply%2520compromised%2520network%252C%2520but%2520you%2520can%2527t%2520practically%2520shut%2520it%2520down%2520and%2520rebuild%2520it%2520from%2520scratch%252C%2520how%2520do%2520you%2520go%2520about%2520cleaning%2520it%2520up%2520and%2520restoring%2520trust%2520in%2520its%2520use%253F%2520This%2520is%2520a%2520very%2520difficult%2520problem%252C%2520and%2520I%2520would%2520say%2520that%2520in%2520m';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F11%252F16%252Frestoring-trust-in-a-compromised-network%252F%26amp%3Btitle%3DRestoring%2520trust%2520in%2520a%2520compromised%2520network';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/11/16/restoring-trust-in-a-compromised-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automated Web-Based Malware Behavior Analysis</title>
		<link>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/</link>
		<comments>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 00:10:12 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=166</guid>
		<description><![CDATA[I just watched a video presentation from September's OWASP conference. The presenter, Tyler Hudak, talked about the Truman-based hybrid sandnet he created to automate the analysis of web-based malware. He references Google's The Ghost in the Browser paper, as well as the Honeynet Project. One tool he used to help automate things in Windows is [...]]]></description>
			<content:encoded><![CDATA[<p>I just watched a video presentation from September's <a href="http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference">OWASP conference</a>. The presenter, Tyler Hudak, talked about the <a href="http://www.secureworks.com/research/tools/truman.html">Truman</a>-based hybrid sandnet he created to <a href="http://video.google.com/videoplay?docid=4204600308807371535&amp;hl=en">automate the analysis of web-based malware</a>. He references Google's <a href="http://www.usenix.org/event/hotbots07/tech/full_papers/provos/provos.pdf">The Ghost in the Browser</a> paper, as well as the <a href="http://www.honeynet.org/papers/">Honeynet Project</a>. One tool he used to help automate things in Windows is <a href="http://www.autoitscript.com/autoit3/index.shtml">AutoIt</a>, something I had not heard of before, but it sounds handy. The demo also shows a tool called <a href="http://www.pcmag.com/article2/0,4149,9882,00.asp">InCtrl5</a>, a utility for Windows that monitors changes to your system, primarily for use when installing some new program. I guess it's used to compliment the usual <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx" target="_blank">Sysinternals</a> tools, so maybe it has some extra features that Tyler finds useful.</p>
<p>Some of the problems this approach is trying to solve are browser-dependent obfuscated JavaScript, plug-in dependencies (like Flash), multiple redirects, etc. All of these issues make malware analysis more complex and time consuming, so any automation you can get away with is a big help. The demo at the end is pretty cool, but he glossed over how the information from the automated analysis is presented to the user. I'm guessing it's not (yet) in a pretty report format. Either way, you still need someone with the right knowledge to analyze the output and decide what to do with it to help defend your network.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bbodytext%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Bt%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bnotes%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CloudAV prototypes anti-virus scanning via cloud computing</title>
		<link>http://eugk.net/wordpress/2008/08/11/cloudav-prototypes-anti-virus-scanning-via-cloud-computing/</link>
		<comments>http://eugk.net/wordpress/2008/08/11/cloudav-prototypes-anti-virus-scanning-via-cloud-computing/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 23:09:19 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[networking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/08/11/cloudav-prototypes-anti-virus-scanning-via-cloud-computing/</guid>
		<description><![CDATA[This is interesting research, but is it something you would use?
The researchers' new approach, called CloudAV, moves antivirus functionality into the "network cloud" and off personal computers. CloudAV analyzes suspicious files using multiple antivirus and behavioral detection programs simultaneously.
In general, that's not a bad idea. It might save a few CPU cycles on your local [...]]]></description>
			<content:encoded><![CDATA[<p>This is interesting research, but is it something you would use?</p>
<blockquote><p>The researchers' new approach, called CloudAV, moves antivirus functionality into the "network cloud" and off personal computers. CloudAV analyzes suspicious files using multiple antivirus and behavioral detection programs simultaneously.</p></blockquote>
<p>In general, that's not a bad idea. It might save a few CPU cycles on your local workstation by not having to directly virus scan files. Then again, you have to use network resources uploading each file to the cloud, where it is scanned for you.</p>
<blockquote><p>Each time a computer or device receives a new document or program, that item is automatically detected and sent to the antivirus cloud for analysis.</p></blockquote>
<p>The privacy concerns here are obvious. Would you trust CloudAV to receive a copy of every file you want to virus scan? How sure can you be that they don't use the contents for something else, or accidentally leak private information?</p>
<p>I think this idea has more merit as an internal virus scanning system for a large organization. That way sensitive data doesn't have to leave the corporate boundary, or be sent to a third party. The benefit is that you have a more thorough and updated virus scanning engine, possibly using several different products at once.</p>
<p><a href="http://www.ns.umich.edu/htdocs/releases/story.php?id=6666">Researchers develop next-generation antivirus system</a>.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F%26amp%3Btitle%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing%26amp%3Bbodytext%3DThis%2520is%2520interesting%2520research%252C%2520but%2520is%2520it%2520something%2520you%2520would%2520use%253F%250D%250AThe%2520researchers%2527%2520new%2520approach%252C%2520called%2520CloudAV%252C%2520moves%2520antivirus%2520functionality%2520into%2520the%2520%2522network%2520cloud%2522%2520and%2520off%2520personal%2520computers.%2520CloudAV%2520analyzes%2520suspicious%2520files%2520using%2520multiple%2520antiv';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F%26amp%3Bt%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F%26amp%3Btitle%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThis%2520is%2520interesting%2520research%252C%2520but%2520is%2520it%2520something%2520you%2520would%2520use%253F%250D%250AThe%2520researchers%2527%2520new%2520approach%252C%2520called%2520CloudAV%252C%2520moves%2520antivirus%2520functionality%2520into%2520the%2520%2522network%2520cloud%2522%2520and%2520off%2520personal%2520computers.%2520CloudAV%2520analyzes%2520suspicious%2520files%2520using%2520multiple%2520antiv';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F%26amp%3Btitle%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing%26amp%3Bnotes%3DThis%2520is%2520interesting%2520research%252C%2520but%2520is%2520it%2520something%2520you%2520would%2520use%253F%250D%250AThe%2520researchers%2527%2520new%2520approach%252C%2520called%2520CloudAV%252C%2520moves%2520antivirus%2520functionality%2520into%2520the%2520%2522network%2520cloud%2522%2520and%2520off%2520personal%2520computers.%2520CloudAV%2520analyzes%2520suspicious%2520files%2520using%2520multiple%2520antiv';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F08%252F11%252Fcloudav-prototypes-anti-virus-scanning-via-cloud-computing%252F%26amp%3Btitle%3DCloudAV%2520prototypes%2520anti-virus%2520scanning%2520via%2520cloud%2520computing';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/08/11/cloudav-prototypes-anti-virus-scanning-via-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ruby vulnerabilities</title>
		<link>http://eugk.net/wordpress/2008/06/25/ruby-vulnerabilities/</link>
		<comments>http://eugk.net/wordpress/2008/06/25/ruby-vulnerabilities/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 01:06:42 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[development]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=83</guid>
		<description><![CDATA[There are already plenty of people talking/screaming/crying about the recent bugs found in the Ruby programming language:

Techworld
Ruby Inside
ZSFA
Matasano Chargen

The list of CVEs created to track these bugs:

CVE-2008-2662
CVE-2008-2663
CVE-2008-2725
CVE-2008-2726
CVE-2008-2664

The funny thing is, these vulnerabilities were created in the run-time implementation of Ruby, which is itself written in C. So it's really not all that surprising, considering how [...]]]></description>
			<content:encoded><![CDATA[<p>There are already plenty of people talking/screaming/crying about the recent bugs found in the Ruby programming language:</p>
<ul>
<li><a href="http://www.techworld.com/security/news/index.cfm?newsID=101993" target="_blank">Techworld</a></li>
<li><a href="http://www.rubyinside.com/june-2008-ruby-security-vulnerabilities-927.html" target="_blank">Ruby Inside</a></li>
<li><a href="http://www.zedshaw.com/rants/the_big_ruby_vulnerabilities.html" target="_blank">ZSFA</a></li>
<li><a href="http://www.matasano.com/log/1070/updates-on-drew-yaos-terrible-ruby-vulnerabilities/" target="_blank">Matasano Chargen</a></li>
</ul>
<p>The list of CVEs created to track these bugs:</p>
<ul>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2662" target="_blank">CVE-2008-2662</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2663" target="_blank">CVE-2008-2663</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2725" target="_blank">CVE-2008-2725</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726" target="_blank">CVE-2008-2726</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2664" target="_blank">CVE-2008-2664</a></li>
</ul>
<p>The funny thing is, these vulnerabilities were created in the run-time implementation of Ruby, which is itself written in C. So it's really not all that surprising, considering how hard it is to write secure, large, bug-free C programs.</p>
<p><img src="http://www.ruby-lang.org/images/logo.gif" alt="" width="331" height="119" /></p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DRuby%2520vulnerabilities%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F%26amp%3Btitle%3DRuby%2520vulnerabilities%26amp%3Bbodytext%3DThere%2520are%2520already%2520plenty%2520of%2520people%2520talking%252Fscreaming%252Fcrying%2520about%2520the%2520recent%2520bugs%2520found%2520in%2520the%2520Ruby%2520programming%2520language%253A%250D%250A%250D%250A%2509Techworld%250D%250A%2509Ruby%2520Inside%250D%250A%2509ZSFA%250D%250A%2509Matasano%2520Chargen%250D%250A%250D%250AThe%2520list%2520of%2520CVEs%2520created%2520to%2520track%2520these%2520bugs%253A%250D%250A%250D%250A%2509CVE-2008-2662%250D%250A%2509CVE-2';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F%26amp%3Bt%3DRuby%2520vulnerabilities';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F%26amp%3Btitle%3DRuby%2520vulnerabilities%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThere%2520are%2520already%2520plenty%2520of%2520people%2520talking%252Fscreaming%252Fcrying%2520about%2520the%2520recent%2520bugs%2520found%2520in%2520the%2520Ruby%2520programming%2520language%253A%250D%250A%250D%250A%2509Techworld%250D%250A%2509Ruby%2520Inside%250D%250A%2509ZSFA%250D%250A%2509Matasano%2520Chargen%250D%250A%250D%250AThe%2520list%2520of%2520CVEs%2520created%2520to%2520track%2520these%2520bugs%253A%250D%250A%250D%250A%2509CVE-2008-2662%250D%250A%2509CVE-2';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F%26amp%3Btitle%3DRuby%2520vulnerabilities%26amp%3Bnotes%3DThere%2520are%2520already%2520plenty%2520of%2520people%2520talking%252Fscreaming%252Fcrying%2520about%2520the%2520recent%2520bugs%2520found%2520in%2520the%2520Ruby%2520programming%2520language%253A%250D%250A%250D%250A%2509Techworld%250D%250A%2509Ruby%2520Inside%250D%250A%2509ZSFA%250D%250A%2509Matasano%2520Chargen%250D%250A%250D%250AThe%2520list%2520of%2520CVEs%2520created%2520to%2520track%2520these%2520bugs%253A%250D%250A%250D%250A%2509CVE-2008-2662%250D%250A%2509CVE-2';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fruby-vulnerabilities%252F%26amp%3Btitle%3DRuby%2520vulnerabilities';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/06/25/ruby-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Classic insider threat example</title>
		<link>http://eugk.net/wordpress/2008/06/25/classic-insider-threat-example/</link>
		<comments>http://eugk.net/wordpress/2008/06/25/classic-insider-threat-example/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 00:50:21 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=82</guid>
		<description><![CDATA[IT director gets fired. IT director still has remote access to company network. IT director deletes a bunch of stuff and causes some damage.
This is a cut and dry example of why the insider threat is such a major issue. I guess some companies need to learn the hard way: Disable all accounts belonging to [...]]]></description>
			<content:encoded><![CDATA[<p>IT director gets fired. IT director still has remote access to company network. <a href="http://www.chron.com/disp/story.mpl/headline/metro/5854484.html" target="_blank">IT director deletes a bunch of stuff and causes some damage.</a></p>
<p>This is a cut and dry example of why the insider threat is such a major issue. I guess some companies need to learn the hard way: Disable all accounts belonging to terminated employees; if it's an admin (or the IT director), change all the root passwords as well. Of course, this implies that a company has to keep track of all the accounts an employee might have, which is not easy. The important thing to remember is that this is more of a people/policy challenge than a technical one.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DClassic%2520insider%2520threat%2520example%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F%26amp%3Btitle%3DClassic%2520insider%2520threat%2520example%26amp%3Bbodytext%3DIT%2520director%2520gets%2520fired.%2520IT%2520director%2520still%2520has%2520remote%2520access%2520to%2520company%2520network.%2520IT%2520director%2520deletes%2520a%2520bunch%2520of%2520stuff%2520and%2520causes%2520some%2520damage.%250D%250A%250D%250AThis%2520is%2520a%2520cut%2520and%2520dry%2520example%2520of%2520why%2520the%2520insider%2520threat%2520is%2520such%2520a%2520major%2520issue.%2520I%2520guess%2520some%2520companies%2520need';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F%26amp%3Bt%3DClassic%2520insider%2520threat%2520example';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F%26amp%3Btitle%3DClassic%2520insider%2520threat%2520example%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DIT%2520director%2520gets%2520fired.%2520IT%2520director%2520still%2520has%2520remote%2520access%2520to%2520company%2520network.%2520IT%2520director%2520deletes%2520a%2520bunch%2520of%2520stuff%2520and%2520causes%2520some%2520damage.%250D%250A%250D%250AThis%2520is%2520a%2520cut%2520and%2520dry%2520example%2520of%2520why%2520the%2520insider%2520threat%2520is%2520such%2520a%2520major%2520issue.%2520I%2520guess%2520some%2520companies%2520need';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F%26amp%3Btitle%3DClassic%2520insider%2520threat%2520example%26amp%3Bnotes%3DIT%2520director%2520gets%2520fired.%2520IT%2520director%2520still%2520has%2520remote%2520access%2520to%2520company%2520network.%2520IT%2520director%2520deletes%2520a%2520bunch%2520of%2520stuff%2520and%2520causes%2520some%2520damage.%250D%250A%250D%250AThis%2520is%2520a%2520cut%2520and%2520dry%2520example%2520of%2520why%2520the%2520insider%2520threat%2520is%2520such%2520a%2520major%2520issue.%2520I%2520guess%2520some%2520companies%2520need';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F06%252F25%252Fclassic-insider-threat-example%252F%26amp%3Btitle%3DClassic%2520insider%2520threat%2520example';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/06/25/classic-insider-threat-example/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows command line utilities</title>
		<link>http://eugk.net/wordpress/2008/05/28/windows-command-line-utilities/</link>
		<comments>http://eugk.net/wordpress/2008/05/28/windows-command-line-utilities/#comments</comments>
		<pubDate>Thu, 29 May 2008 02:26:02 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=80</guid>
		<description><![CDATA[We all know that Windows can't compete with Linux or UNIX when it comes to useful command line utilities (excluding Cygwin). But what most people don't know is how many commands actually are available in Windows. If your job is to investigate intrusions on Windows machines, there are some nifty little command line tools that [...]]]></description>
			<content:encoded><![CDATA[<p>We all know that Windows can't compete with Linux or UNIX when it comes to useful command line utilities (excluding Cygwin). But what most people don't know is how many commands actually are available in Windows. If your job is to investigate intrusions on Windows machines, there are some nifty little command line tools that can help make your job easier.</p>
<p>This <a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1303709,00.html" target="_blank">article by Ed Skoudis</a> lists a few of them, with handy examples of how the commands might be used in a security investigation. He mostly talks about wmic, openfiles (which I had never heard of before), and netstat. Unless you've done recent Windows administration work, you've probably never had to use wmic, but it's really powerful, with tons of options. Also, be sure to check out the <a href="http://searchsecurity.techtarget.com.au/articles/24672-Five-more-built-in-Windows-commands-to-determine-if-a-system-has-been-hacked" target="_blank">second part of his article</a>, which goes into more advanced command line tricks - like "for" loops and querying the registry.</p>
<p>A more comprehensive list, although less detailed, was <a href="http://searchwindowssecurity.techtarget.com/tip/0,289483,sid45_gci1259825,00.html" target="_blank">published by Kevin Beaver</a>. There is overlap, but Kevin mentions a few addiontal commands.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DWindows%2520command%2520line%2520utilities%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F%26amp%3Btitle%3DWindows%2520command%2520line%2520utilities%26amp%3Bbodytext%3DWe%2520all%2520know%2520that%2520Windows%2520can%2527t%2520compete%2520with%2520Linux%2520or%2520UNIX%2520when%2520it%2520comes%2520to%2520useful%2520command%2520line%2520utilities%2520%2528excluding%2520Cygwin%2529.%2520But%2520what%2520most%2520people%2520don%2527t%2520know%2520is%2520how%2520many%2520commands%2520actually%2520are%2520available%2520in%2520Windows.%2520If%2520your%2520job%2520is%2520to%2520investigate%2520intrusi';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F%26amp%3Bt%3DWindows%2520command%2520line%2520utilities';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F%26amp%3Btitle%3DWindows%2520command%2520line%2520utilities%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DWe%2520all%2520know%2520that%2520Windows%2520can%2527t%2520compete%2520with%2520Linux%2520or%2520UNIX%2520when%2520it%2520comes%2520to%2520useful%2520command%2520line%2520utilities%2520%2528excluding%2520Cygwin%2529.%2520But%2520what%2520most%2520people%2520don%2527t%2520know%2520is%2520how%2520many%2520commands%2520actually%2520are%2520available%2520in%2520Windows.%2520If%2520your%2520job%2520is%2520to%2520investigate%2520intrusi';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F%26amp%3Btitle%3DWindows%2520command%2520line%2520utilities%26amp%3Bnotes%3DWe%2520all%2520know%2520that%2520Windows%2520can%2527t%2520compete%2520with%2520Linux%2520or%2520UNIX%2520when%2520it%2520comes%2520to%2520useful%2520command%2520line%2520utilities%2520%2528excluding%2520Cygwin%2529.%2520But%2520what%2520most%2520people%2520don%2527t%2520know%2520is%2520how%2520many%2520commands%2520actually%2520are%2520available%2520in%2520Windows.%2520If%2520your%2520job%2520is%2520to%2520investigate%2520intrusi';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F05%252F28%252Fwindows-command-line-utilities%252F%26amp%3Btitle%3DWindows%2520command%2520line%2520utilities';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/05/28/windows-command-line-utilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
