<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>Realtime Community | Messaging and Web Security</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/" />
   <link rel="self" type="application/atom+xml" href="http://www.realtime-websecurity.com/atom.xml" />
   <id>tag:www.realtime-websecurity.com,2009://1</id>
   <updated>2009-05-22T16:40:37Z</updated>
   <subtitle>The Realtime Messaging and Web Security Community is an objective source for security information related to email, instant messaging, content filtering and related services. The community provides a wide range of resources including blogs, articles, white papers, forums and podcast as well as links to external resources. Topics range from technical details of threats and vulnerabilities to best practices and procedures for protecting messaging and web infrastructures.</subtitle>
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.1</generator>


<entry>
   <title>Low-Tech Attacks on The Rise</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/lowtech_attacks_on_the_rise.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1058</id>
   
   <published>2009-05-22T16:19:55Z</published>
   <updated>2009-05-22T16:40:37Z</updated>
   
   <summary>Phishers are re-working old attacks and coming up with some variations on past attacks as they continue to try to scam social networking site users. This isn&apos;t new, but as Symantec points out, the attacks are on the rise....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="32" label="phishing" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1490" label="social networking" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="502" label="Symantec" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Phishers are re-working old attacks and coming up with some variations on past attacks as they continue to try to scam social networking site users. This isn't new, but as Symantec points out, the attacks are on the rise....
   </content>
</entry>

<entry>
   <title>Risks of Consolidation</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/risks_of_consolidation.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1057</id>
   
   <published>2009-05-20T11:38:34Z</published>
   <updated>2009-05-20T11:56:22Z</updated>
   
   <summary>Consolidating account information in a single service is appealing - log into one place and get a snap shot of your financial state. Sounds good in theory, but the practice went wrong for Rudder, a free personal financial service....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="665" label="data leak" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="473" label="online banking" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3085" label="personal financial services" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3083" label="Rudder" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Consolidating account information in a single service is appealing - log into one place and get a snap shot of your financial state. Sounds good in theory, but the practice went wrong for Rudder, a free personal financial service....
   </content>
</entry>

<entry>
   <title>New Technique for Denying Denial of Service Attacks</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/new_technique_for_denying_deni.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1056</id>
   
   <published>2009-05-19T11:19:41Z</published>
   <updated>2009-05-19T11:33:30Z</updated>
   
   <summary>Denial of service attacks that flood a site with requests can be blunted by blocking users sending large number of requests. More advanced techniques send a small number of resource intensive requests. Researchers at IBM and Georgia Institute of Technology have created a way to deal with these attacks, too....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="698" label="denial of service" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3079" label="Georgia Tech" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="397" label="IBM" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3081" label="IEEE Computer" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Denial of service attacks that flood a site with requests can be blunted by blocking users sending large number of requests. More advanced techniques send a small number of resource intensive requests. Researchers at IBM and Georgia Institute of Technology have created a way to deal with these attacks, too....
   </content>
</entry>

<entry>
   <title>Business Needs to Get Out Ahead of Security Regulation</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/business_needs_to_get_out_ahea.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1055</id>
   
   <published>2009-05-18T13:39:05Z</published>
   <updated>2009-05-18T13:57:37Z</updated>
   
   <summary>An interesting quote in a USA Today story on security company acquisitions speaks to the increasing level of concern about current levels of information security....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="3077" label="industry regulation" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="431" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="20" label="risk management" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
An interesting quote in a USA Today story on security company acquisitions speaks to the increasing level of concern about current levels of information security....
   </content>
</entry>

<entry>
   <title>More on Facebook Phishing</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/more_on_facebook_phishing.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1054</id>
   
   <published>2009-05-15T17:48:05Z</published>
   <updated>2009-05-15T17:52:52Z</updated>
   
   <summary>Symantec has been following the trends in Facebook phishing and the current wave of attacks looks similar to previous ones. Of course no one goes to this much trouble to vandalize Facebook pages, there is money to be made (stolen) at the end of the game....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="1098" label="Facebook" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1070" label="passwords" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="32" label="phishing" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Symantec has been following the trends in Facebook phishing and the current wave of attacks looks similar to previous ones. Of course no one goes to this much trouble to vandalize Facebook pages, there is money to be made (stolen) at the end of the game....
   </content>
</entry>

<entry>
   <title>Key to Online Apps Success: Control, Control, Control</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/key_to_online_apps_success_con.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1053</id>
   
   <published>2009-05-14T16:22:54Z</published>
   <updated>2009-05-14T16:33:35Z</updated>
   
   <summary>BusinessWeek asks what&apos;s Holding back Google Apps?. The answer is the same thing that always kills deals to move corporate data to the cloud: control....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="1718" label="cloud computing" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="175" label="compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="299" label="Google" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="959" label="Google Apps" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2181" label="liability" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="95" label="regulations" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
BusinessWeek asks what's Holding back Google Apps?. The answer is the same thing that always kills deals to move corporate data to the cloud: control....
   </content>
</entry>

<entry>
   <title>Open Source Intelligence and Cyberspying</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/open_source_intelligence_and_c.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1052</id>
   
   <published>2009-05-13T22:23:45Z</published>
   <updated>2009-05-13T22:27:02Z</updated>
   
   <summary>The New York Times has a cybersecurity-with-a-human-interest-angle story well worth reading. It covers some of the work of Rafal Rohozinski, a social scientist turned cyber-investigator....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="813" label="cybersecurity" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3075" label="intelligence" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
The New York Times has a cybersecurity-with-a-human-interest-angle story well worth reading. It covers some of the work of Rafal Rohozinski, a social scientist turned cyber-investigator....
   </content>
</entry>

<entry>
   <title>Critical Patch Available for Adobe Reader, Multiple Platforms</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/critical_patch_available_for_a.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1051</id>
   
   <published>2009-05-13T12:33:15Z</published>
   <updated>2009-05-13T12:37:20Z</updated>
   
   <summary>Adobe has released patches for Adobe Reader on multiple platforms to correct vulnerability that could allow attackers to take control of a machine....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="839" label="Adobe" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2997" label="critical patch" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3074" label="Reader" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Adobe has released patches for Adobe Reader on multiple platforms to correct vulnerability that could allow attackers to take control of a machine....
   </content>
</entry>

<entry>
   <title>Critical Patch Available for Microsoft PowerPoint</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/critical_patch_available_for_m.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1050</id>
   
   <published>2009-05-13T12:24:51Z</published>
   <updated>2009-05-13T12:31:57Z</updated>
   
   <summary>Microsoft has released a patch for a zero-day PowerPoint vulnerability that has been exploited in the wild. A Windows version of the patch is available, the Mac version should be out soon....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="2997" label="critical patch" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="133" label="Microsoft" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3071" label="PowerPoint" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3072" label="zero-day vulnerability" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Microsoft has released a patch for a zero-day PowerPoint vulnerability that has been exploited in the wild. A Windows version of the patch is available, the Mac version should be out soon....
   </content>
</entry>

<entry>
   <title>EU Proposing Software Liability Protections; Malpractice May Be Better Model</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/eu_proposing_software_liabilit.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1049</id>
   
   <published>2009-05-12T13:28:31Z</published>
   <updated>2009-05-12T13:49:36Z</updated>
   
   <summary>EU Commissioners are proposing stronger consumer protections for software security and efficacy. Software industry advocates want no part of this. The EU was ahead of the US on privacy protections which are common place today so it is worth watching how this story unfolds....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="1701" label="EU" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3065" label="European Commission" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3067" label="medical malpractice" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="239" label="privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1" label="security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3069" label="software reliability" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
EU Commissioners are proposing stronger consumer protections for software security and efficacy. Software industry advocates want no part of this. The EU was ahead of the US on privacy protections which are common place today so it is worth watching how this story unfolds....
   </content>
</entry>

<entry>
   <title>US Missle Defense Details Found on Computer Purchased from eBay</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/us_missle_defense_details_foun.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1048</id>
   
   <published>2009-05-07T21:14:22Z</published>
   <updated>2009-05-07T21:36:54Z</updated>
   
   <summary>A collaboration of researchers in US, UK and Austrailia trying to raise awareness risks of improperly disposing personal data found their poster child for the year: a computer with details on a US anti-missile defense system....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="3058" label="boot n nuke" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="665" label="data leak" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="355" label="data loss" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3059" label="dban" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="815" label="Department of Defense" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3061" label="disk drive" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3063" label="missle defense" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
A collaboration of researchers in US, UK and Austrailia trying to raise awareness risks of improperly disposing personal data found their poster child for the year: a computer with details on a US anti-missile defense system....
   </content>
</entry>

<entry>
   <title>SQL Injection Attacks in Content Management Systems</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/sql_injection_attacks_in_conte.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1047</id>
   
   <published>2009-05-07T21:04:56Z</published>
   <updated>2009-05-07T21:38:02Z</updated>
   
   <summary>Web sites built using content management systems may be vulnerable to SQL injection attacks, the trick is to find them....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="2330" label="content management system" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="266" label="SQL injection" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3056" label="Web site" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="224" label="worms" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Web sites built using content management systems may be vulnerable to SQL injection attacks, the trick is to find them....
   </content>
</entry>

<entry>
   <title>Hacking Air Traffic Control Systems</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/hacking_air_traffic_control_sy.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1046</id>
   
   <published>2009-05-07T16:49:03Z</published>
   <updated>2009-05-07T16:55:55Z</updated>
   
   <summary>The Wall Street Journal is reporting air traffic control networks have been attacked on multiple occasions in the past several years. The FAA doesn&apos;t agree with all the findings of the Transportation Department&apos;s inspector general who issued the report but the undisputed facts are troubling enough....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="3053" label="air traffic control" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2702" label="complexity" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="176" label="cybercrime" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3051" label="FAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="411" label="hacking" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3054" label="transportation" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
The Wall Street Journal is reporting air traffic control networks have been attacked on multiple occasions in the past several years. The FAA doesn't agree with all the findings of the Transportation Department's inspector general who issued the report but the undisputed facts are troubling enough....
   </content>
</entry>

<entry>
   <title>Researchers Hijack Botnet Gain Insight to Bots and Their Victims</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/researchers_hijack_botnet_gain.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1045</id>
   
   <published>2009-05-05T11:33:20Z</published>
   <updated>2009-05-05T12:13:34Z</updated>
   
   <summary>Researchers from the Security Group at the UC Santa Barbara Computer Science department hijacked the Torpig botnet for 10 days. In that time the found what you&apos;d expect (some users are very lax with security) and some things not so expected (how difficult it is to notify victims)....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="394" label="botnet" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="810" label="credit card" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="219" label="fraud" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="malware" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3049" label="password stealing" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1070" label="passwords" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="32" label="phishing" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3047" label="Torpig" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
Researchers from the Security Group at the UC Santa Barbara Computer Science department hijacked the Torpig botnet for 10 days. In that time the found what you'd expect (some users are very lax with security) and some things not so expected (how difficult it is to notify victims)....
   </content>
</entry>

<entry>
   <title>Supreme Court Justice: Publishing Cybersnooping Results is Free Speech</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-websecurity.com/articles_and_analysis/2009/05/supreme_court_justice_cybersno.html" />
   <id>tag:www.realtime-websecurity.com,2009://1.1044</id>
   
   <published>2009-05-04T13:02:07Z</published>
   <updated>2009-05-04T16:34:16Z</updated>
   
   <summary>I&apos;ve come to expect more from Supreme Court justices than I found in some recent comments by Justice Scalia regarding online privacy....</summary>
   <author>
      <name>Dan Sullivan</name>
      
   </author>
   
      <category term="Articles and Analysis" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="574" label="Internet" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3045" label="online" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="239" label="privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3040" label="Scalia" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3042" label="Souter" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="3044" label="Supreme Court" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-websecurity.com/">
I've come to expect more from Supreme Court justices than I found in some recent comments by Justice Scalia regarding online privacy....
   </content>
</entry>

</feed>
