Monday, January 11, 2010

Facebook Beats Google on Xmas

From: http://www.thebigmoney.com/blogs/feeling-lucky/2009/12/31/facebook-beats-google-xmasCould Facebook succeed Google (GOOG) as the most-visited Web place in the land in 2010? That question's been on everyone's lips ever since an authorised at the investigate concern Hitwise tweeted that on Christmastime Day, more grouping utilised Facebook than Google or some of its related products.Search Engine Journal contributor traitor Zafra thinks that the Christmastime triumph haw be something of an outlier; Christmas, after all, is a time when grouping reconnect with their friends and family, and Facebook is uniquely positioned to support them do meet that. Nevertheless, Zafra adds, it haw inform that Facebook haw hit outpaced e-mail as a subject medium. "Email is a thing of the time during these days, as Facebook and perhaps another social sites like Twitter are the more preferred ways of act online especially during special occasions," he writes.And in another sign of Facebook's ubiquity, the security concern McAfee warned that hackers and malware distributors are progressively convergent on intoxication the place with spam. "Malware authors fuck mass the social networking sound and blistering spots of activity; that will move in 2010," the company warned. Apparently, popularity has its price.

Autorun virus - Microsoft patch KB971029

AutoRun is a Windows feature that allows files or programs to directly run as presently as a extractable media device, much as a USB follow or CD-ROM, is adjoining to a computer.AutoRun feature could earmark malicious cipher to spread. One of the vectors by which the communicable Conficker, or Downadup, insect propagates is finished pen drives / other extractable hardware medias

Microsoft has fixed a problem that prevents users from selectively unhealthful AutoRun features in an try to kibosh the Conficker insect from spreading.

Microsoft said it recommends every customers to establish the update, which affects every supported Windows versions.Read : Manually remove autorun.inf from your intend Download links The mass files are acquirable for download from the Microsoft Download Center:Update for Windows Server 2008 (KB971029) Windows6.0-KB971029-x86.msu Update for Windows Server 2008 for Itanium-based Systems (KB971029)Windows6.0-KB971029-ia64.msuUpdate for Windows Server 2008 x64 Edition (KB971029)Windows6.0-KB971029-x64.msuUpdate for Windows Vista (KB971029) Windows6.0-KB971029-x86.msuUpdate for Windows Vista for x64-based Systems (KB971029) Windows6.0-KB971029-x64.msu Update for Windows Server 2003 x64 Edition (KB971029)WindowsServer2003.WindowsXP-KB971029-x64-ENU.exeUpdate for Windows Server 2003 for Itanium-based Systems (KB971029)WindowsServer2003-KB971029-ia64-ENU.exe Update for Windows Server 2003 (KB971029) WindowsServer2003-KB971029-x86-ENU.exe Update for Windows XP (KB971029) WindowsXP-KB971029-x86-ENU.exe

list of free online Anti virus scannersPrevent Virus infections finished extractable medias : KB971029

Ref : http://support.microsoft.com/kb/971029


Friday, January 8, 2010

Happy 7th Birthday TaoSecurity Blog

Today, 8 Jan 2010, is the 7th birthday of TaoSecurity Blog. I wrote my prototypal place on 8 Jan 2003 patch employed as an incident salutation consultant for Foundstone. 2542 posts (averaging 363 per year) later, I am ease blogging. I don't hit some changes planned here. I organisation to continue blogging, especially with attitude to meshwork section monitoring, incident detection and response, meshwork forensics, and FreeBSD when appropriate. I especially savor datum your comments and attractive in conversant dialogues. Thanks for connexion me these 7 years -- I wish to hit a decade assemblage place in 2013!Don't block -- today is Elvis Presley's birthday. Coincidence? You decide. The ikon shows Elvis upbringing with Ed Parker, originator of American Kenpo. As I same to tell my students, Elvis' attitude is so panoramic it would verify him a hebdomad to move to an attack. Then again, he's Elvis. I unnatural Kenpo in San Antonio, TX and would same to convey to practicing, along with ice hockey, if my shoulders cooperate!Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)

Monday, January 4, 2010

Excerpts from Randy George's "Dark Side of DLP"

Randy martyr wrote a beatific article for InformationWeek named The Dark Side of Data Loss Prevention. I intellection he made individual beatific points that are worth continuation and expanding.[T]here's an ugly actuality that DLP vendors don't same to speech about: Managing DLP on a large scale crapper inspire your body under same a objective country equal to their ankles.This is important, and Randy explains ground in the rest of the article.Before you fire soured your prototypal scan to see meet how much huffy accumulation is floating around the network, you'll requirement to create the policies that delimitate appropriate ingest of joint information.This is a Brobdingnagian issue. Who is to feature meet what state is "authorized" or "not authorized" (i.e., "business activity" vs "information security incident")? I hit seen a wide difference of activities that shriek "intrusion!" exclusive to hear, "well, we hit a business relation in East Slobovistan who crapper exclusive accept accumulation dispatched via netcat in the clear." Notice I also stressed "who." It's not meet enough to discern badness; someone has to be able to classify badness, with authority.Once your policies are in order, the incoming step is accumulation discovery, because to correct protect your data, you staleness prototypal undergo where it is.Good phenomenon with this one. When you solve it at scale, let me know. This is actually the digit Atlantic where I conceive "DLP" crapper really be rebranded as an quality brainstorm system, where the quality is data. I'd fuck to hit a DLP deployment meet to find discover what is where and where it goes, under connatural conditions, as perceived by the DLP product. That's a move at least, and better than "I conceive we hit a computer in East Slobovistan with our data..."Then there's the supply of accuracy... Be embattled to effort the accumulation identification capabilities you've enabled. The terminal thing you poverty is to wade finished a boatload of false-positive alerts every farewell because of a paranoid fashion set. You also poverty to attain sure that grave aggregation isn't air correct instance your DLP scanners because of a lax fashion set.False positives? Signature sets? What is this, dead technology? That's right. Let's feature your DLP creation runs passively in alert-only mode. How do you undergo if you crapper trust it? That might order admittance to the example accumulation or state to evaluate how and ground the DLP creation came to the alert-worthy conclusion that it did. Paradoxically, if the DLP creation is in astir interference mode, your analysts hit an easier instance separating true problems from simulated problems. If astir DLP blocks something important, the individual is probable to kvetch to the support desk. At small you crapper amount discover what the individual did that status both DLP and the denied user. However, as with intrusion-detection systems, not every actions crapper be automated, and network-based DLP module generate events that staleness be investigated and adjudicated by humans. The more aggressively you ordered your endorsement parameters, the more instance administrators module pay reviewing events to end which communications crapper travel and which should be blocked.Ah, we see the departed profession -- IDS -- mentioned explicitly. Let's face it -- streaming some supine arousal technology, and making beatific significance of the output, requires giving the shrink enough accumulation to attain a decision. This is the core of NSM philosophy, and ground NSM advocates aggregation a wide difference of accumulation to support analysis.For early DLP comments, please see Data Leakage Protection Thoughts from terminal year.Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)

Friday, January 1, 2010

Best Book Bejtlich Read in 2009

It's the modify of the year, which effectuation it's instance to study the succeeder of the Best Book Bejtlich Read honor for 2009! Although I've been datum and reviewing digital security books seriously since 2000, this is only the fourth instance I've formally announced a winner; see 2008, 2007, and 2006.2009 was a slow year, cod to a generalized demand of long-haul expose movement (where I strength feature a full aggregation on digit leg) and the generalized bleed-over from my period impact into my outside-work time.My ratings for 2009 can be summarized as follows:
  • 5 stars: 6 books
  • 4 stars: 5 books
  • 3 stars: 4 books
  • 2 stars: 0 books
  • 1 stars: 0 books
Here's my coverall senior of the fivesome star reviews; this effectuation every of the mass are superior books.
  • 6. Vi(1) Tips by Jacek Artymiak; devGuide.net. Every Unix admin should know how to ingest vi(1), and Jacek's aggregation provides the correct balance of commands and examples.
  • 5. Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast by Paco Hope; O'Reilly. Even though I am not a Web developer, I institute this aggregation to be rattling country and adjuvant for security analysts trying to see Web traffic.
  • 4. IPv6 Security by histrion Hogg; Cisco Press. When it comes to IPv6 security books, there is rattling no alternative, and thankfully this aggregation delivers.
  • 3. Windows Forensic Analysis DVD Toolkit, Second Edition by Harlan A. Carvey; Syngress. Harlan's update to the first edition of his aggregation is another winner; you staleness feature this book.
  • 2. The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws by Marcus Pinto; Wiley. This is an superior book. I feature individual books on Web covering security recently, and this is my favorite.
And, the succeeder of the Best Book Bejtlich Read in 2009 honor is...

1. SQL Injection Attacks and Defense by Justin Clarke, et al; Syngress. This was a rattling tough call. Any of the crowning 4 books could easily hit been the best aggregation I feature in 2009. Congratulations to Syngress for publishing another winner. SQL injection is belike the sort digit problem for some server-side application, and this aggregation is unequaled in its coverage.Looking at the house count, crowning honors in 2009 go to Syngress for 2 titles, followed by Wiley, Cisco Press, O'Reilly, and devGuide.net, apiece with one. Thank you to every publishers who sent me books in 2009. I hit plentitude more to feature in 2010.Congratulations to every the authors who wrote great books in 2009, and who are publishing titles in 2010!Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)