<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1848924428889833079</id><updated>2012-02-17T04:37:53.665+08:00</updated><category term='CISCO'/><category term='China'/><category term='Power Grid'/><category term='Homeland Security'/><category term='Israel'/><category term='OWASP'/><category term='Identity Theft'/><category term='Penetration Tests'/><category term='Threat'/><category term='Cyber Preparedness'/><category term='Vulnerability'/><category term='Financial Institutions'/><category term='Critical Infrastructure'/><category term='Limits of Authority'/><category term='Potential Threats'/><category term='Video'/><category term='OPC'/><category term='Automation'/><category term='Internal Controls'/><category term='Guidelines'/><category term='Gaming'/><category term='Initiatives'/><category term='Control Systems'/><category term='Security Companies'/><category term='Georgia'/><category term='Mortgage'/><category term='Strategy'/><category term='Vendor'/><category term='Radar'/><category term='Massive'/><category term='Failure'/><category term='SQL Injects'/><category term='Segregation of Responsibilities'/><category term='Back Door'/><category term='Acculturation'/><category term='Espionage'/><category term='Guide'/><category term='Preventive Measures'/><category term='NHS'/><category term='Expert'/><category term='Web Attack'/><category term='Breach'/><category term='GAO'/><category term='DDOS'/><category term='US-Cert'/><category term='iWork'/><category term='Unauthorized'/><category term='Statistics'/><category term='Criminal'/><category term='Chinese'/><category term='London'/><category term='Cyber Sheriff'/><category term='Interview'/><category term='Lawsuit'/><category term='ISP'/><category term='Information Sharing'/><category term='Tests'/><category term='Blackberry'/><category term='Defense'/><category term='Industry'/><category term='Private'/><category term='Electronic Warfare'/><category term='Intrusion'/><category term='Teachers'/><category term='Cybersecurity Bill'/><category term='Risk'/><category term='Crypto'/><category term='Health'/><category term='India'/><category term='ePrivacy'/><category term='Cloud'/><category term='School'/><category term='Flight'/><category term='Top Mishaps'/><category term='Worm'/><category term='Web Servers'/><category term='Certification'/><category term='Interruptions'/><category term='Controls'/><category term='Hackers'/><category term='Cyber War'/><category term='Countries'/><category term='Power Systems'/><category term='IRS'/><category term='Internet Security'/><category term='Task Force'/><category term='Gaza'/><category term='Safe Internet'/><category term='Hardware'/><category term='Drone'/><category term='Public'/><category term='DOS'/><category term='Security Posture Assessment'/><category term='Legislation'/><category term='Security Breach'/><category term='Experts'/><category term='DNS'/><category term='Airport'/><category term='Weapons'/><category term='Standards'/><category term='Infrastructure'/><category term='Crime'/><category term='Malicious'/><category term='Incidents'/><category term='Water Utility'/><category term='France'/><category term='Symposium'/><category term='Vulnerabilities'/><category term='EC Directive'/><category term='Rootkits'/><category term='Australia'/><category term='NIST'/><category term='Oil and Gas'/><category term='Trends'/><category term='Pentagon'/><category term='Compliance'/><category term='Countermeasures'/><category term='Data Loss'/><category term='Privacy'/><category term='Underground Economy'/><category term='Antivirus'/><category term='Blogs'/><category term='SCADA'/><category term='Process Control'/><category term='DCS'/><category term='Backdoor'/><category term='Policy'/><category term='Cable'/><category term='Impact'/><category term='TV'/><category term='Hacks'/><category term='Logic Bomb'/><category term='Exercise'/><category term='CNII'/><category term='Best Practices'/><category term='CERTS'/><category term='Manufacturing'/><category term='Grounded'/><category term='Physical Security'/><category term='Control of Internet'/><category term='Bugs'/><category term='Hospital'/><category term='Estonia'/><category term='Incident Response'/><category term='Collaboration'/><category term='Russia'/><category term='Publications'/><category term='Trojan'/><category term='Hacking'/><category term='Year Summary'/><category term='Education'/><category term='OS'/><category term='Security Flaw'/><category term='Legal'/><category term='Korea'/><category term='Plans'/><category term='Credit'/><category term='CIP'/><category term='Control Tower'/><category term='Patch'/><category term='Indigeneous'/><category term='Awareness'/><category term='Loopholes'/><category term='PLC'/><category term='Report'/><category term='Teens'/><category term='USA'/><category term='Healthcare'/><category term='Data Protection'/><category term='Government'/><category term='Forgery'/><category term='Virus Attack'/><category term='FAA'/><category term='Exposures'/><category term='Toolkits'/><category term='Bank'/><category term='Virus'/><category term='Air Traffic'/><category term='Software'/><category term='Coordination'/><category term='Middle East'/><category term='Kids'/><category term='DHS'/><category term='PCI'/><category term='Predictions'/><category term='Weaknesses'/><category term='Compromised'/><category term='Common Criteria'/><category term='Ukriane'/><category term='Computer Failure'/><category term='Secure Programming'/><category term='HITB'/><category term='Malware'/><category term='Glitches'/><category term='Copy Machines'/><category term='Insider'/><category term='Security Education'/><category term='Smartcard'/><category term='Exploits'/><category term='Botnet'/><category term='RFID'/><category term='Threats'/><category term='Iframe'/><category term='Screw Up'/><category term='US'/><category term='Cyber Attack'/><category term='Hijack'/><category term='Training'/><category term='Air Defense'/><category term='Audit'/><title type='text'>Critical Information Infrastructure Protection and Security</title><subtitle type='html'>This blog infraprotect.blogspot.com (or infraprotect dot blogspot dot com ) focuses on the Critical Information Infrastructure (CII) Security issues. CII means the information layer which critical infrastructures depend on for planning, operation and management. Security compromises in the information layer may impact the infrastructure service operations and continuity which in turn affects the national economy and integrity.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default?start-index=101&amp;max-results=100'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>108</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7120123730590104574</id><published>2010-03-20T02:09:00.001+08:00</published><updated>2010-03-20T02:12:18.709+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='Cybersecurity Bill'/><title type='text'>Latest Version Of Cybersecurity Act Lessens Presidential Power</title><content type='html'>&lt;p&gt;The Senate Wednesday re-introduced a cybersecurity bill it considered last year, minus a provision that would have allowed the president to shut down the Internet in the event of a major cyber attack. &lt;/p&gt;&lt;p&gt;The Cybersecurity Act, S. 773, co-sponsored by Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine), is aimed at protecting critical U.S. network infrastructure against cybersecurity threats by fostering collaboration between the federal government and the private sectors that maintain that infrastructure... &lt;a href="http://www.darkreading.com/security/cybercrime/showArticle.jhtml?articleID=224000097&amp;amp;cid=nl_DR_DAILY_2010-03-19_t"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7120123730590104574?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/cybercrime/showArticle.jhtml?articleID=224000097&amp;cid=nl_DR_DAILY_2010-03-19_t' title='Latest Version Of Cybersecurity Act Lessens Presidential Power'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7120123730590104574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7120123730590104574' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7120123730590104574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7120123730590104574'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2010/03/latest-version-of-cybersecurity-act.html' title='Latest Version Of Cybersecurity Act Lessens Presidential Power'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7838478773906195832</id><published>2010-03-20T02:04:00.001+08:00</published><updated>2010-03-20T02:09:04.590+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Copy Machines'/><category scheme='http://www.blogger.com/atom/ns#' term='Privacy'/><title type='text'>Copy Machines Can Store Your Private Info</title><content type='html'>The dangers of identity theft are well-publicized. We've all been warned to shred our documents, be on the lookout for fishing scams and check our credit report regularly.&lt;br /&gt;&lt;br /&gt;But there is a new potential threat to our identity lurking in warehouses across the country. We're talking about copy machines.&lt;br /&gt;&lt;br /&gt;"Copy machines today are just like computers," explained Boston security expert Robert Siciliano. "They have hard drives and can store data that can be extracted." .. &lt;a href="http://wbztv.com/local/iteam.copy.machines.2.1549368.html"&gt;More &gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7838478773906195832?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://wbztv.com/local/iteam.copy.machines.2.1549368.html' title='Copy Machines Can Store Your Private Info'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7838478773906195832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7838478773906195832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7838478773906195832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7838478773906195832'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2010/03/copy-machines-can-store-your-private.html' title='Copy Machines Can Store Your Private Info'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-1903755992663397598</id><published>2010-03-20T02:00:00.001+08:00</published><updated>2010-03-20T02:03:57.072+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><title type='text'>Cyber attacks shift to the cloud, too</title><content type='html'>Cyber warfare against enterprises grows more brutal by the year, but now carriers are getting caught in the crossfire as more organizations move sensitive data into operators' clouds, according to a survey sponsored by telecom network security vendor Arbor Networks. Cloud security is a telecom issue as much as it is an enterprise issue. .. &lt;a href="http://www.telecomasia.net/content/cyber-attacks-shift-cloud-too?section=CLOUDCOMPUTING&amp;amp;utm_source=lyris&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=top10"&gt;More &gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-1903755992663397598?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.telecomasia.net/content/cyber-attacks-shift-cloud-too?section=CLOUDCOMPUTING&amp;utm_source=lyris&amp;utm_medium=newsletter&amp;utm_campaign=top10' title='Cyber attacks shift to the cloud, too'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/1903755992663397598/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=1903755992663397598' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1903755992663397598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1903755992663397598'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2010/03/cyber-attacks-shift-to-cloud-too.html' title='Cyber attacks shift to the cloud, too'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7373584222780621403</id><published>2010-03-20T01:57:00.001+08:00</published><updated>2010-03-20T02:00:15.792+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><title type='text'>China Schools Seen Behind Cyberattacks on Google</title><content type='html'>Cyberattacks on Google and other US companies came from two Chinese schools—including one with ties to the country’s military, sources close to the investigation tell the &lt;a target="_blank" href="http://www.nytimes.com/2010/02/19/technology/19china.html"&gt;&lt;em&gt;New York Times&lt;/em&gt;&lt;/a&gt;. .. &lt;a href="http://www.newser.com/story/81289/china-schools-seen-behind-cyberattacks-on-google.html?utm_source=part&amp;amp;utm_medium=inbox&amp;amp;utm_campaign=newser"&gt;More&gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7373584222780621403?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.newser.com/story/81289/china-schools-seen-behind-cyberattacks-on-google.html?utm_source=part&amp;utm_medium=inbox&amp;utm_campaign=newser' title='China Schools Seen Behind Cyberattacks on Google'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7373584222780621403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7373584222780621403' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7373584222780621403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7373584222780621403'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2010/03/china-schools-seen-behind-cyberattacks.html' title='China Schools Seen Behind Cyberattacks on Google'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-337866462957625411</id><published>2010-03-20T01:49:00.001+08:00</published><updated>2010-03-20T01:56:55.304+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Critical Infrastructure'/><title type='text'>Government and infrastructure tops hacking league</title><content type='html'>Cybercriminals are now aggressively targeting government and critical infrastructure companies, a review of malware and attack    patterns over the last year has found. .. &lt;a href="http://www.networkworld.com/news/2010/021210-government-and-infrastructure-tops-hacking.html?source=NWWNLE_nlt_security_2010-02-15"&gt;More &gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-337866462957625411?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networkworld.com/news/2010/021210-government-and-infrastructure-tops-hacking.html?source=NWWNLE_nlt_security_2010-02-15' title='Government and infrastructure tops hacking league'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/337866462957625411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=337866462957625411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/337866462957625411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/337866462957625411'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2010/03/government-and-infrastructure-tops.html' title='Government and infrastructure tops hacking league'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4652798485119150913</id><published>2009-12-22T03:51:00.002+08:00</published><updated>2009-12-22T03:55:04.952+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='Guide'/><title type='text'>Cloud Computing Security Guidance</title><content type='html'>The Cloud Security Alliance has released its latest guide titled "Security Guidance for Critical Areas of Focus in Cloud Computing V2.1" which can be found &lt;a href="http://www.cloudsecurityalliance.org/csaguide.pdf"&gt;here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4652798485119150913?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cloudsecurityalliance.org/csaguide.pdf' title='Cloud Computing Security Guidance'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4652798485119150913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4652798485119150913' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4652798485119150913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4652798485119150913'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/12/cloud-computing-security-guidance.html' title='Cloud Computing Security Guidance'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-81386646592699267</id><published>2009-12-22T03:46:00.001+08:00</published><updated>2009-12-22T03:48:26.289+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Video'/><category scheme='http://www.blogger.com/atom/ns#' term='Hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='Defense'/><category scheme='http://www.blogger.com/atom/ns#' term='Drone'/><title type='text'>Hackers Intercepted Drone Spy Videos</title><content type='html'>Insurgents in Iraq have hacked into live video feeds from Predator drones, a key weapon in a Pentagon spy system that serves as the military's eyes in the sky for surveillance and intelligence collection.&lt;br /&gt;&lt;br /&gt;Though militants could see the video, there is no evidence they were able to jam the electronic signals from the unmanned aerial craft or take control of the vehicles, a senior defense official said Thursday, speaking on condition of anonymity to discuss sensitive intelligence issues.&lt;br /&gt;&lt;br /&gt;Obtaining the video feeds can provide insurgents with critical information about what the military may be targeting, including buildings, roads and other facilities.&lt;br /&gt;&lt;br /&gt;Shiite fighters in Iraq used off-the-shelf software programs such as SkyGrabber -- available for as little as $25.95 on the Internet -- to regularly capture drone video feeds, the Wall Street Journal reported Thursday. The hacking was possible because the remotely flown planes have an unprotected communications Relevant Products/Services link.  .. &lt;a href="http://it.toolbox.com/blogs/talk-to-the-hand/hackers-intercepted-drone-spy-videos-35970"&gt;More &gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-81386646592699267?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://it.toolbox.com/blogs/talk-to-the-hand/hackers-intercepted-drone-spy-videos-35970' title='Hackers Intercepted Drone Spy Videos'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/81386646592699267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=81386646592699267' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/81386646592699267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/81386646592699267'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/12/hackers-intercepted-drone-spy-videos.html' title='Hackers Intercepted Drone Spy Videos'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6775200655012653448</id><published>2009-12-22T03:40:00.002+08:00</published><updated>2009-12-22T03:45:58.171+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Computer Failure'/><category scheme='http://www.blogger.com/atom/ns#' term='Air Traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='Flight'/><title type='text'>FAA glitch causes widespread US air travel delays</title><content type='html'>&lt;span class="Apple-style-span"   style="  line-height: 16px; font-family:arial, helvetica, clean, sans-serif;font-size:13px;"&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; line-height: 18px; "&gt;ATLANTA – &lt;span class="yshortcuts" id="lw_1258666215_0"&gt;Air travelers nationwide&lt;/span&gt; scrambled to revise their plans Thursday after an FAA computer glitch caused widespread cancellations and delays for the second time in 15 months. The&lt;span class="yshortcuts" id="lw_1258666215_1" style="background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: rgb(220, 238, 255); color: rgb(0, 0, 0); border-bottom-style: dashed; border-bottom-width: 1px; border-bottom-color: rgb(0, 102, 204); cursor: pointer; background-position: initial initial; "&gt;Federal Aviation Administration&lt;/span&gt; said the problem, which lasted about four hours, was fixed around 9 a.m., but it was unclear how long flights would be affected.&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; line-height: 18px; "&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; line-height: 18px; "&gt;It started when a single circuit board in a piece of networking equipment at a computer center in &lt;span class="yshortcuts" id="lw_1258666215_2"&gt;Salt Lake City&lt;/span&gt; failed around 5 a.m., the &lt;span class="yshortcuts" id="lw_1258666215_3"&gt;FAA&lt;/span&gt; said in a statement.&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; line-height: 18px; "&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; line-height: 18px; "&gt;That failure prevented &lt;span class="yshortcuts" id="lw_1258666215_4"  style="cursor: pointer; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; border-bottom-style: none; border-bottom-width: initial; border-bottom- background-position: initial initial; color:initial;"&gt;air traffic control computers&lt;/span&gt; in different parts of the country from talking to each other. &lt;span class="yshortcuts" id="lw_1258666215_5"  style="border-bottom-style: dashed; border-bottom-width: 1px; border-bottom-color: rgb(0, 102, 204); cursor: pointer; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background- background-position: initial initial; color:transparent;"&gt;Air traffic controllers&lt;/span&gt; were forced to type in complicated flight plans themselves because they could not be transferred automatically from computers in one region of the country to computers in another, slowing down the whole system. .. &lt;a href="http://news.yahoo.com/s/ap/20091119/ap_on_bi_ge/us_flight_delays"&gt;More &gt;&gt;&lt;/a&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6775200655012653448?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.yahoo.com/s/ap/20091119/ap_on_bi_ge/us_flight_delays' title='FAA glitch causes widespread US air travel delays'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6775200655012653448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6775200655012653448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6775200655012653448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6775200655012653448'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/12/faa-glitch-causes-widespread-us-air.html' title='FAA glitch causes widespread US air travel delays'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2568213742968155003</id><published>2009-10-25T20:34:00.004+08:00</published><updated>2009-10-25T20:41:54.166+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blackberry'/><category scheme='http://www.blogger.com/atom/ns#' term='Cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='HITB'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>Hackers Plan to Clobber the Cloud, Spy on Blackberries</title><content type='html'>&lt;p&gt;                   &lt;span class="date"&gt;October 05, 2009&lt;/span&gt;        —                            IDG News Service —                               A new era of computing is on the rise and viruses, spies and malware developers are tagging along for the ride.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;The new playground for hackers is "the cloud," the term for computer applications and services hosted on the Internet. Some of the devices making the cloud more popular these days are BlackBerries and other smartphones. &lt;/p&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;"The focus [of security] is definitely moving towards 'the cloud' and to the security of embedded devices (Android, iPhone) to more advanced client-side attacks which leverage on Web 2.0 technologies, such as attacks on Facebook, Twitter and other popular sites," said Dhillon Andrew Kannabhiran, host and organizer of the &lt;a href="http://conference.hitb.org/hitbsecconf2009kl/?page_id=37"&gt;Hack In The Box&lt;/a&gt; (HITB) security conference in Kuala Lumpur, Malaysia this week.&lt;/p&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;HITB is one of the most prominent security conferences in Asia and now runs twice a year. The big show is in Malaysia, while the newer, yet smaller HITB is held in Dubai. The conference brings together leading security experts and draws self-proclaimed hackers, but Kannabhiran says it's not a wild hacker party. It offers knowledgeable presentations by leading experts in an informal setting, where people can ask questions and meet presenters at events throughout the week.&lt;/p&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;"Clobbering the Cloud" and "Spying on BlackBerry Users for Fun" are actually titles of two presentations slated for the HITB conference on Wednesday. Other interesting titles include "How to Own the World - One Desktop at a Time" and "Offensive Cloud Computing With Hadoop and Backtrack." .. &lt;a href="http://www.csoonline.com/article/504122/Hackers_Plan_to_Clobber_the_Cloud_Spy_on_Blackberries?source=CSONLE_nlt_techwatch_2009-10-12"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2568213742968155003?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.csoonline.com/article/504122/Hackers_Plan_to_Clobber_the_Cloud_Spy_on_Blackberries?source=CSONLE_nlt_techwatch_2009-10-12' title='Hackers Plan to Clobber the Cloud, Spy on Blackberries'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2568213742968155003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2568213742968155003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2568213742968155003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2568213742968155003'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/10/hackers-plan-to-clobber-cloud-spy-on.html' title='Hackers Plan to Clobber the Cloud, Spy on Blackberries'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-14038384629404695</id><published>2009-09-14T20:05:00.001+08:00</published><updated>2009-09-14T20:07:54.542+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Korea'/><category scheme='http://www.blogger.com/atom/ns#' term='Countermeasures'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Sheriff'/><title type='text'>SKorea to train 3,000 'cyber sheriffs': report</title><content type='html'>SEOUL — South Korea plans to train 3,000 "cyber sheriffs" by next year to protect businesses after a spate of attacks on state and private websites, a report said Sunday.&lt;br /&gt;&lt;br /&gt;The "cyber sheriffs" would be tasked with "protecting corporate information and preventing the leaks of industrial secrets," Yonhap news agency said.&lt;br /&gt;&lt;br /&gt;In the event of cyber attacks, the National Intelligence Service, the country's main spy agency, would set up a taskforce including civilian and government experts to counter the online threats, it added. ... &lt;a href="http://www.google.com/hostednews/afp/article/ALeqM5gH8okYUQo2jeNuKY8fkO3F-qkzkA"&gt;More &gt;&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-14038384629404695?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.google.com/hostednews/afp/article/ALeqM5gH8okYUQo2jeNuKY8fkO3F-qkzkA' title='SKorea to train 3,000 &apos;cyber sheriffs&apos;: report'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/14038384629404695/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=14038384629404695' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/14038384629404695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/14038384629404695'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/09/skorea-to-train-3000-cyber-sheriffs.html' title='SKorea to train 3,000 &apos;cyber sheriffs&apos;: report'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5718987045749683132</id><published>2009-08-01T11:21:00.003+08:00</published><updated>2009-08-01T11:25:00.810+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Experts'/><category scheme='http://www.blogger.com/atom/ns#' term='Training'/><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Preparedness'/><title type='text'>Government Is Falling Behind on Cybersecurity, Report Finds</title><content type='html'>"Cyber In-Security" says the federal government is falling behind in the race to keep its computer operations safe because the workforce has too few well-trained cybersecurity experts.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;"Critical government and private sector computer networks are under constant attack from foreign nations, criminal groups, hackers, virus writers and terrorist organizations," says the &lt;a href="http://www.ourpublicservice.org/" target=""&gt;study&lt;/a&gt;, published by the Partnership for Public Service and Booz Allen Hamilton. .. &lt;a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/07/22/AR2009072203698.html?sub=AR"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5718987045749683132?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.washingtonpost.com/wp-dyn/content/article/2009/07/22/AR2009072203698.html?sub=AR' title='Government Is Falling Behind on Cybersecurity, Report Finds'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5718987045749683132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5718987045749683132' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5718987045749683132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5718987045749683132'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/08/government-is-falling-behind-on.html' title='Government Is Falling Behind on Cybersecurity, Report Finds'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4661813899561416569</id><published>2009-06-09T11:08:00.004+08:00</published><updated>2009-06-09T11:11:28.839+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Identity Theft'/><title type='text'>Insider May Have Breached More Than 10,000 Patient Records At Johns Hopkins</title><content type='html'>&lt;p&gt;An employee at Johns Hopkins Hospital may have leaked the personal information of more than 10,000 patients in an identity fraud scam.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt; According to a &lt;a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-168293.pdf" target="new"&gt;report filed to the administrator of the state of Maryland's Identity Theft Program&lt;/a&gt; (PDF), some 31 individuals with connections to Johns Hopkins have reported identity thefts since Jan. 20. Law enforcement agencies suspect the thefts might be part of a fraudulent driver's license scheme discovered in neighboring Virginia.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;In researching the thefts, members of the Johns Hopkins security department discovered that a single employee who worked in patient registration may have used her access privileges to review data on more than 10,000 patients while working at the hospital. The now-former employee is expected to be indicted for stealing the data, the report states.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt; The hospital emphasizes that the breach was not a hacking incident, but that the employee had access to the records as part of her job... &lt;a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=217400831&amp;amp;cid=nl_DR_WEEKLY_T"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4661813899561416569?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=217400831&amp;cid=nl_DR_WEEKLY_T' title='Insider May Have Breached More Than 10,000 Patient Records At Johns Hopkins'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4661813899561416569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4661813899561416569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4661813899561416569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4661813899561416569'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/06/insider-may-have-breached-more-than.html' title='Insider May Have Breached More Than 10,000 Patient Records At Johns Hopkins'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4997716251487651390</id><published>2009-06-09T11:03:00.003+08:00</published><updated>2009-06-09T11:07:11.892+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Gaming'/><category scheme='http://www.blogger.com/atom/ns#' term='Hackers'/><title type='text'>Hackers Arrested In China After Feud Causes Major Outage</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;" class="text"  &gt;DDoS feud between underground gaming services allegedly caused temporary Internet outage across more than 20 provinces .. &lt;a href="http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=217701926&amp;amp;cid=nl_DR_DAILY_T"&gt;More &gt;&gt;&lt;/a&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4997716251487651390?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=217701926&amp;cid=nl_DR_DAILY_T' title='Hackers Arrested In China After Feud Causes Major Outage'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4997716251487651390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4997716251487651390' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4997716251487651390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4997716251487651390'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/06/hackers-arrested-in-china-after-feud.html' title='Hackers Arrested In China After Feud Causes Major Outage'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7710433975535734824</id><published>2009-05-10T02:15:00.002+08:00</published><updated>2009-05-10T02:19:08.597+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Control Tower'/><category scheme='http://www.blogger.com/atom/ns#' term='Air Traffic'/><category scheme='http://www.blogger.com/atom/ns#' term='FAA'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilities'/><title type='text'>Thousands of Vulnerabilities Detected In FAA's Air Traffic Control Apps</title><content type='html'>&lt;p&gt;A &lt;a href="http://www.oig.dot.gov/StreamFile?file=/data/pdfdocs/ATC_Web_Report.pdf" target="new"&gt;government audit&lt;/a&gt; (PDF) has pinpointed more than 3,800 vulnerabilities -- 763 of which are high-risk -- in the Federal Aviation Administration's Web-based air traffic control system applications, including some that could potentially put air travel at risk.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The U.S. Department of Transportation report, with the help of auditors from KPMG, determined that the ATC's Web-based applications aren't secured from attacks or unauthorized access, and that the FAA hasn't set up the necessary intrusion-detection functions to catch security incidents at ATC locations. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;And the FAA's Air Traffic Organization, which heads up ATC operations, received more than 800 security incident alerts in fiscal 2008, but still had not fixed 17 percent of the flaws that caused them, "including critical incidents in which hackers may have taken over control of ATO computers," the report says. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The auditors tested 70 of the FAA's ATC Web applications, including ones that provide information to the general public, as well as to pilots and controllers, and some internal apps. Of the vulnerabilities they discovered, nearly 2,600 were considered low-risk threats, such as unprotected folders of sensitive data and weak passwords... &lt;a href="http://www.darkreading.com/security/government/showArticle.jhtml;jsessionid=KUNCTGKR2N4BIQSNDLRSKHSCJUNN2JVN?articleID=217400024"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7710433975535734824?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/government/showArticle.jhtml;jsessionid=KUNCTGKR2N4BIQSNDLRSKHSCJUNN2JVN?articleID=217400024' title='Thousands of Vulnerabilities Detected In FAA&apos;s Air Traffic Control Apps'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7710433975535734824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7710433975535734824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7710433975535734824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7710433975535734824'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/05/thousands-of-vulnerabilities-detected.html' title='Thousands of Vulnerabilities Detected In FAA&apos;s Air Traffic Control Apps'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6556243011064372462</id><published>2009-04-28T18:13:00.002+08:00</published><updated>2009-04-28T18:16:43.354+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='Ukriane'/><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><title type='text'>Researchers Find Massive Botnet On Nearly 2 Million Infected Consumer, Business, Government PCs</title><content type='html'>&lt;p&gt;Researchers have discovered a major botnet operating out of the Ukraine that has infected 1.9 million machines, including large corporate and government PCs mainly in the U.S.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The botnet, which appears to be larger than the infamous Storm botnet was in its heyday, has infected machines from some 77 government-owned domains -- 51 of which are U.S. government ones, according to Ophir Shalitin, marketing director of Finjan, which &lt;a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2237" target="new"&gt;recently found the botnet&lt;/a&gt;.  Shalitin says the botnet is controlled by six individuals and is hosted in Ukraine. .. &lt;a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=217000166&amp;amp;cid=nl_DR_DAILY_T"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6556243011064372462?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=217000166&amp;cid=nl_DR_DAILY_T' title='Researchers Find Massive Botnet On Nearly 2 Million Infected Consumer, Business, Government PCs'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6556243011064372462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6556243011064372462' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6556243011064372462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6556243011064372462'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/researchers-find-massive-botnet-on.html' title='Researchers Find Massive Botnet On Nearly 2 Million Infected Consumer, Business, Government PCs'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-466503607108987735</id><published>2009-04-26T06:48:00.003+08:00</published><updated>2009-04-26T06:52:10.034+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Intrusion'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Computer Spies Breach Fighter-Jet Project</title><content type='html'>&lt;p&gt;WASHINGTON -- Computer spies have broken into the Pentagon's $300 billion Joint Strike Fighter project -- the Defense Department's costliest weapons program ever -- according to current and former government officials familiar with the attacks.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;Similar incidents have also breached the Air Force's air-traffic-control system in recent months, these people say. In the case of the fighter-jet program, the intruders were able to copy and siphon off several terabytes of data related to design and electronics systems, officials say, potentially making it easier to defend against the craft. .. &lt;a href="http://online.wsj.com/article/SB124027491029837401.html?cid=nl_DR_DAILY_T"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-466503607108987735?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://online.wsj.com/article/SB124027491029837401.html?cid=nl_DR_DAILY_T' title='Computer Spies Breach Fighter-Jet Project'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/466503607108987735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=466503607108987735' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/466503607108987735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/466503607108987735'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/computer-spies-breach-fighter-jet.html' title='Computer Spies Breach Fighter-Jet Project'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8612596560889336238</id><published>2009-04-18T19:52:00.005+08:00</published><updated>2009-04-18T19:58:19.352+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Hospital'/><title type='text'>Conficker worm hits University of Utah computers</title><content type='html'>&lt;p&gt;SALT LAKE CITY (AP) — University of Utah officials say a computer virus has infected more than 700 campus computers, including those at the school's three hospitals.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;University health sciences spokesman Chris Nelson said the outbreak of the Conficker worm, which can slow computers and steal personal information, was first detected Thursday. By Friday, the virus had infiltrated computers at the hospitals, medical school, and colleges of nursing, pharmacy and health.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Nelson says patient data and medical records have not been compromised.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;"That's secured in a much deeper way because of the implications," he said.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Nelson said the virus is mainly attacking personal computers and could be siphoning login and password data, credit card numbers and banking information.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Directions for purging the virus from personal computers and equipment like thumb drives, digital cameras and smart phones has been distributed to staff and students.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Information technology staff shut of Internet access for up to six hours at some campus locations Friday so they could isolate the virus. They were expected to work through the weekend to eradicate it from the system. .. &lt;a href="http://www.google.com/hostednews/ap/article/ALeqM5glHoytrRzwnvGp8sAaLo7L4skvowD97GPM6G0"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8612596560889336238?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.google.com/hostednews/ap/article/ALeqM5glHoytrRzwnvGp8sAaLo7L4skvowD97GPM6G0' title='Conficker worm hits University of Utah computers'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8612596560889336238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8612596560889336238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8612596560889336238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8612596560889336238'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/conficker-worm-hits-university-of-utah.html' title='Conficker worm hits University of Utah computers'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-467857507009283630</id><published>2009-04-12T11:06:00.003+08:00</published><updated>2009-04-12T11:13:29.730+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Posture Assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Tests'/><title type='text'>Some articles on penetration testing</title><content type='html'>&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Cybercrime_and_Hacking&amp;amp;articleId=9087441&amp;amp;taxonomyId=82&amp;amp;intsrc=kc_li_story"&gt;Six hours to hack the FBI&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9087439"&gt;5 free penetration testing tools&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9087440"&gt;Cost effective penetration testing&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.coresecurity.com/content/core-impact-overview"&gt;Core Impact penetration testing tool (not free)&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-467857507009283630?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/467857507009283630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=467857507009283630' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/467857507009283630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/467857507009283630'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/some-articles-on-penetration-testing.html' title='Some articles on penetration testing'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6243260233772769787</id><published>2009-04-12T05:21:00.004+08:00</published><updated>2009-04-12T11:04:19.357+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CNII'/><category scheme='http://www.blogger.com/atom/ns#' term='Power Grid'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Electric Power Grid Vulnerabilities</title><content type='html'>&lt;p&gt;The following is a collection of news articles (non-exhaustive) on the vulnerabilities of the power grid and alleged penetration. Click the titles of the articles below for further information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9039678"&gt;Simulated attack points to vulnerable power infrastructure (Sept 28,2007)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9119838"&gt;Critical infrastructure often under attack (Nov 11, 2008)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9130178"&gt;Power grid is found susceptible to cyberattack (March 21, 2009)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://online.wsj.com/article/SB123914805204099085.html"&gt;Electric Grid in US Penetrated by Spies (April 8, 2009)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=cybercrime_and_hacking&amp;amp;articleId=9131418&amp;amp;taxonomyId=82&amp;amp;intsrc=kc_top"&gt;China denies attack on US power grid (April 9, 2009)&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6243260233772769787?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6243260233772769787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6243260233772769787' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6243260233772769787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6243260233772769787'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/electric-power-grid-vulnerabilities.html' title='Electric Power Grid Vulnerabilities'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2384879962855866097</id><published>2009-04-11T18:36:00.001+08:00</published><updated>2009-04-11T18:39:53.914+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='CNII'/><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='CIP'/><category scheme='http://www.blogger.com/atom/ns#' term='Lawsuit'/><category scheme='http://www.blogger.com/atom/ns#' term='Legislation'/><title type='text'>Senate bill would give feds bigger cybersecurity role in private sector</title><content type='html'>&lt;p&gt;Legislation calls for new security standards for government and critical infrastructure systems&lt;br /&gt;By Jaikumar Vijayan&lt;br /&gt;&lt;br /&gt;April 1, 2009 (Computerworld) Two U.S. senators are proposing legislation that would give federal officials significant new authority to create and enforce data security standards both for government agencies and key parts of the private sector.&lt;br /&gt;&lt;br /&gt;The Cybersecurity Act of 2009, which was introduced by Sens. Olympia Snowe (R-Maine) and Jay Rockefeller (D-W.Va.), would empower the National Institute of Standards and Technology (NIST) to establish "measurable and auditable" security standards for all networks and systems run by federal agencies, government contractors and businesses that support critical infrastructure services. In addition, NIST would be charged with developing a standard for testing and accrediting software built by or for those groups.&lt;br /&gt;&lt;br /&gt;The bill also calls for the creation of a national cybersecurity adviser's office within the Executive Office of the President. Under the proposal, the new operation would be modeled after the Office of the U.S. Trade Representative and have the power to compel federal agencies to comply with government security mandates.&lt;br /&gt;&lt;br /&gt;According to a statement posted on Snowe's Web site Wednesday, the new legislation is aimed at reinforcing ongoing cybersecurity efforts within the government while also ensuring that proper safeguards are implemented for critical infrastructure targets within the private sector, such as banking and power systems. .. &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9130958"&gt;More &gt;&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2384879962855866097?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9130958' title='Senate bill would give feds bigger cybersecurity role in private sector'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2384879962855866097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2384879962855866097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2384879962855866097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2384879962855866097'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/04/senate-bill-would-give-feds-bigger.html' title='Senate bill would give feds bigger cybersecurity role in private sector'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8548472140088869558</id><published>2009-03-25T15:15:00.001+08:00</published><updated>2009-03-25T15:17:57.323+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Worm'/><title type='text'>Conficker/Downadup Evolves To Defend Itself</title><content type='html'>&lt;p&gt;The enigmatic Conficker worm has evolved, adopting new capabilities that make it more difficult than ever to find and eradicate, security researchers say. &lt;/p&gt;&lt;p&gt; In a &lt;a href="https://forums2.symantec.com/t5/Malicious-Code/W32-Downadup-C-Digs-in-Deeper/ba-p/393245#A249" target="new"&gt;blog published late last week&lt;/a&gt;, researchers at Symantec said they found "a completely new variant" of Conficker, sometimes called Downadup, that is being pushed out to machines previously infected with earlier versions of the worm. &lt;/p&gt;&lt;p&gt;The new variant, which Symantec calls W32.Downadup.C, appears to have defensive capabilities that weren't present in earlier versions. While it spreads in the same manner, "Conficker.C" can disable some of the tools used to detect and eradicate it, including antivirus and other antimalware detection tools. &lt;/p&gt;&lt;p&gt;W32.Downadup C also can switch domains at a much greater rate, Symantec said. "The Downadup authors have now moved from a 250-a-day domain-generation algorithm to a new 50,000-a-day domain generation algorithm," the researchers reported. "The new domain generation algorithm also uses one of a possible 116 domain suffixes."  .. &lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=215900041&amp;amp;cid=nl_DR_WEEKLY_T"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8548472140088869558?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=215900041&amp;cid=nl_DR_WEEKLY_T' title='Conficker/Downadup Evolves To Defend Itself'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8548472140088869558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8548472140088869558' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8548472140088869558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8548472140088869558'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/03/confickerdownadup-evolves-to-defend.html' title='Conficker/Downadup Evolves To Defend Itself'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8353147509364646309</id><published>2009-03-25T15:08:00.001+08:00</published><updated>2009-03-25T15:10:44.424+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Financial Institutions'/><category scheme='http://www.blogger.com/atom/ns#' term='Credit'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><title type='text'>'The Analyzer' Hack Probe Widens; $10 Million Allegedly Stolen From U.S. Banks</title><content type='html'>&lt;p&gt; Ehud Tenenbaum, an Israeli hacker arrested in Canada last year for allegedly stealing about $1.5 million from Canadian banks, also allegedly hacked two U.S. banks, a credit and debit card distribution company and a payment processor in what U.S. authorities are calling a global "cashout" conspiracy. &lt;/p&gt;  &lt;p&gt;The U.S. hacks have resulted in at least $10 million in losses, according to court records obtained by Threat Level, and are just part of a larger international conspiracy to hack financial institutions in the United States and abroad. .. &lt;a href="http://blog.wired.com/27bstroke6/2009/03/the-analyzer-ha.html"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8353147509364646309?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blog.wired.com/27bstroke6/2009/03/the-analyzer-ha.html' title='&apos;The Analyzer&apos; Hack Probe Widens; $10 Million Allegedly Stolen From U.S. Banks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8353147509364646309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8353147509364646309' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8353147509364646309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8353147509364646309'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/03/analyzer-hack-probe-widens-10-million.html' title='&apos;The Analyzer&apos; Hack Probe Widens; $10 Million Allegedly Stolen From U.S. Banks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4589339550682562940</id><published>2009-03-25T15:04:00.001+08:00</published><updated>2009-03-25T15:08:11.947+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Incidents'/><category scheme='http://www.blogger.com/atom/ns#' term='Control Systems'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Breach'/><title type='text'>Expert: Hackers Penetrating Control Systems</title><content type='html'>&lt;p&gt;The networks powering industrial control systems have been breached more than 125 times in the past decade, with one resulting in U.S. deaths, a control systems expert said Thursday.&lt;/p&gt;&lt;p&gt;Joseph Weiss, managing partner of control systems security consultancy Applied Control Solutions, didn't detail the breach that caused deaths during his testimony before a U.S. Senate committee, but he did say he's been able to find evidence of more than 125 control systems breaches involving systems in nuclear power plants, hydroelectric plants, water utilities, the oil industry and agribusiness.&lt;/p&gt;&lt;p&gt;"The impacts have ranged from trivial to significant environmental damage to significant equipment damage to deaths," he told the Senate Commerce, Science and Transportation Committee. "We've already had a cyber incident in the United States that has killed people." .. &lt;a href="http://www.pcworld.com/businesscenter/article/161584/expert_hackers_penetrating_control_systems.html"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4589339550682562940?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.pcworld.com/businesscenter/article/161584/expert_hackers_penetrating_control_systems.html' title='Expert: Hackers Penetrating Control Systems'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4589339550682562940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4589339550682562940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4589339550682562940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4589339550682562940'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/03/expert-hackers-penetrating-control.html' title='Expert: Hackers Penetrating Control Systems'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2408140532622188232</id><published>2009-03-25T15:01:00.001+08:00</published><updated>2009-03-25T15:04:28.617+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Incidents'/><category scheme='http://www.blogger.com/atom/ns#' term='Control Systems'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Industrial Control Systems Killed Once and Will Again, Experts Warn</title><content type='html'>&lt;p&gt;On June 10th, 1999 a 16-inch diameter steel pipeline operated by the now-defunct Olympic Pipeline Co.  ruptured near Bellingham, Washington, flooding two local creeks with 237,000 gallons of gasoline. The gas ignited into a mile-and-a-half river of fire that claimed the lives of two 10-year-old boys and an 18-year-old man, and injured eight others.&lt;/p&gt;  &lt;p&gt;Wednesday, computer-security experts who recently re-examined the Bellingham incident called its victims the first verified human causalities of a control-system computer incident. They argue that government cybersecurity standards currently under debate might have prevented the tragedy. ... &lt;a href="http://blog.wired.com/27bstroke6/2008/04/industrial-cont.html"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2408140532622188232?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blog.wired.com/27bstroke6/2008/04/industrial-cont.html' title='Industrial Control Systems Killed Once and Will Again, Experts Warn'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2408140532622188232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2408140532622188232' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2408140532622188232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2408140532622188232'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/03/industrial-control-systems-killed-once.html' title='Industrial Control Systems Killed Once and Will Again, Experts Warn'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5268172323908318949</id><published>2009-02-23T07:54:00.004+08:00</published><updated>2009-02-23T08:03:22.075+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Grounded'/><title type='text'>French fighter planes grounded by computer virus</title><content type='html'>&lt;span style="font-size:100%;"&gt;French fighter planes were unable to take off after military computers were infected by a  computer virus, an intelligence magazine claims.&lt;br /&gt;&lt;br /&gt;The aircraft were unable to download their flight plans after databases were    infected by a Microsoft virus they had already been warned about several    months beforehand. &lt;/span&gt; &lt;p&gt;&lt;span style="font-size:100%;"&gt; At one point French naval staff were also instructed not to even open their    computers. &lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:100%;"&gt; Microsoft had warned that the "Conficker" virus, transmitted through    Windows, was attacking computer systems in October last year, but according    to reports the French military ignored the warning and failed to install the    necessary security measures. &gt;&gt; &lt;a href="http://www.telegraph.co.uk/news/worldnews/europe/france/4547649/French-fighter-planes-grounded-by-computer-virus.html"&gt;More ..&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5268172323908318949?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.telegraph.co.uk/news/worldnews/europe/france/4547649/French-fighter-planes-grounded-by-computer-virus.html' title='French fighter planes grounded by computer virus'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5268172323908318949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5268172323908318949' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5268172323908318949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5268172323908318949'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/02/french-fighter-planes-grounded-by.html' title='French fighter planes grounded by computer virus'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6716004595872838916</id><published>2009-02-07T11:23:00.001+08:00</published><updated>2009-02-07T11:25:43.889+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='iWork'/><title type='text'>Trojan Virus affects thousands of pirated copies of Apple’s iWork ‘09 Suite - Botnets attack websites</title><content type='html'>&lt;p&gt;Malware masquerading as part of Apple’s iWork ‘09 suite has targeted unsuspecting Mac users foolish enough to illegally download and install the pirated version of the software commonly found on warez sites around the Web.&lt;/p&gt; &lt;p&gt;Once iWork ‘09 is downloaded and installed, the trojan horse named &lt;em&gt;OSX.Trojan.iServices.A,&lt;/em&gt; obtains unrestrained root access, which it immediately uses to connect to a remote server over the Internet. A secondary download installs malware that makes victims part of a botnet army that is said to be attacking undisclosed websites. According to Mac antivirus software maker Intego, this is the latest reminder of the growing popularity of Apple’s OS X and virus &amp;amp; malware developers. Over the past year, a mix of trojans and exploits have been targeting OS X at increasing rates. &lt;a href="http://www.atomicsub.net/2009/01/iwork-09-virus/"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6716004595872838916?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.atomicsub.net/2009/01/iwork-09-virus/' title='Trojan Virus affects thousands of pirated copies of Apple’s iWork ‘09 Suite - Botnets attack websites'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6716004595872838916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6716004595872838916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6716004595872838916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6716004595872838916'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/02/trojan-virus-affects-thousands-of.html' title='Trojan Virus affects thousands of pirated copies of Apple’s iWork ‘09 Suite - Botnets attack websites'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3411882117614166081</id><published>2009-02-07T09:33:00.003+08:00</published><updated>2009-02-07T09:37:55.861+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Lawsuit'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injects'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Protection'/><title type='text'>Electronics Firm Faces FTC Lawsuit Following Multiple Hacks</title><content type='html'>&lt;p&gt;Warning to security professionals: If you don't do your job right, then it might not only be a firing offense -- it might be a federal offense. &lt;/p&gt;&lt;p&gt;Case in point: An online seller of computer supplies and other consumer electronics today agreed to settle Federal Trade Commission (FTC) charges that it violated federal law by failing to provide reasonable security to protect sensitive customer data. The FTC is charging that the company didn't do enough to prevent SQL injection attacks that compromised customer data. &lt;a href="http://www.darkreading.com/security/management/showArticle.jhtml?articleID=213201976&amp;amp;cid=nl_DR_DAILY_T"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3411882117614166081?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/management/showArticle.jhtml?articleID=213201976&amp;cid=nl_DR_DAILY_T' title='Electronics Firm Faces FTC Lawsuit Following Multiple Hacks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3411882117614166081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3411882117614166081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3411882117614166081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3411882117614166081'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/02/electronics-firm-faces-ftc-lawsuit.html' title='Electronics Firm Faces FTC Lawsuit Following Multiple Hacks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-9182916117217184781</id><published>2009-02-01T12:46:00.001+08:00</published><updated>2009-02-01T12:50:58.894+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Threats'/><category scheme='http://www.blogger.com/atom/ns#' term='Potential Threats'/><category scheme='http://www.blogger.com/atom/ns#' term='Predictions'/><title type='text'>Four Threats For '09 That You've Probably Never Heard Of (Or Thought About)</title><content type='html'>The 2009 potential threats are ... mainly large-scale Internet threats that could trickle down to your organization. We're talking Internet network infrastructure attacks, radical extremist hackers, Web attacks that adversely affect online ad revenue, and even the unthinkable -- human casualties as a result of a cyberattack.  &lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=212700328&amp;amp;pgno=1&amp;amp;queryText=&amp;amp;isPrev="&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-9182916117217184781?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=212700328&amp;pgno=1&amp;queryText=&amp;isPrev=' title='Four Threats For &apos;09 That You&apos;ve Probably Never Heard Of (Or Thought About)'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/9182916117217184781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=9182916117217184781' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/9182916117217184781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/9182916117217184781'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/02/four-threats-for-09-that-youve-probably.html' title='Four Threats For &apos;09 That You&apos;ve Probably Never Heard Of (Or Thought About)'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7279419283667857101</id><published>2009-01-31T16:04:00.004+08:00</published><updated>2009-01-31T16:11:14.794+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mortgage'/><category scheme='http://www.blogger.com/atom/ns#' term='Insider'/><category scheme='http://www.blogger.com/atom/ns#' term='Logic Bomb'/><title type='text'>Insider plot to take down Fannie Mae's (a mortgage lender) servers thwarted</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;strong style="font-weight: normal; font-family: arial;"&gt;Washington (DC) - On October 29, 2008, a vigilant senior Unix engineer happened across a "logic bomb" that was allegedly planted by a contractor, Rajendrasinh Babubhai Makwana, who had worked in their Urbana, MD facility until October 24, 2008 when his contract was terminated. The script was set to activate on January 31, 2009 and would completely wipe all of Fannie Mae's 4,000 servers. According to engineers, had it done so it would've caused "millions of dollars in damage, and possibly shut down operations for a week."&lt;/strong&gt;&lt;/span&gt; ..&gt;&gt; &lt;a href="http://www.tgdaily.com/html_tmp/content-view-41262-118.html"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: arial;font-size:100%;" &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7279419283667857101?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.tgdaily.com/html_tmp/content-view-41262-118.html' title='Insider plot to take down Fannie Mae&apos;s (a mortgage lender) servers thwarted'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7279419283667857101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7279419283667857101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7279419283667857101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7279419283667857101'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/insider-plot-to-take-down-fannie-maes.html' title='Insider plot to take down Fannie Mae&apos;s (a mortgage lender) servers thwarted'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3361464353822667724</id><published>2009-01-13T03:51:00.003+08:00</published><updated>2009-01-13T03:54:50.264+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gaza'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><category scheme='http://www.blogger.com/atom/ns#' term='Israel'/><title type='text'>Israel hacks Arab TV station -  Cyberspace becomes battleground in Gaza conflict</title><content type='html'>Israeli military forces have reportedly hacked into a Hamas-run TV station to broadcast propaganda. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2009/01/06/idf_al_aqsa_hack/"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3361464353822667724?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2009/01/06/idf_al_aqsa_hack/' title='Israel hacks Arab TV station -  Cyberspace becomes battleground in Gaza conflict'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3361464353822667724/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3361464353822667724' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3361464353822667724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3361464353822667724'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/israel-hacks-arab-tv-station-cyberspace.html' title='Israel hacks Arab TV station -  Cyberspace becomes battleground in Gaza conflict'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4719556713345518178</id><published>2009-01-13T03:44:00.001+08:00</published><updated>2009-01-13T03:46:37.143+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Year Summary'/><title type='text'>2008: A year of cowboys in IT security</title><content type='html'>&lt;p&gt;Security pundits are fond are characterising personalties in information security with reference to Westerns - hence hackers wear either a "black hat" or a "white hat" like their cowboy counterparts.&lt;/p&gt;Probably the biggest security story of the year was the take-down of infamous cybercrime hosting outfit McColo. The rogue ISP hosted the command and control systems for three botnets - Srizbi, Rustock and Mega-D. Junk mail levels temporarily fell to a third their normal level following the takedown of McColo in November. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2008/12/31/infosec_cowboys/"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4719556713345518178?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2008/12/31/infosec_cowboys/' title='2008: A year of cowboys in IT security'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4719556713345518178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4719556713345518178' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4719556713345518178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4719556713345518178'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/2008-year-of-cowboys-in-it-security.html' title='2008: A year of cowboys in IT security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7565776721349696619</id><published>2009-01-13T03:39:00.002+08:00</published><updated>2009-01-13T03:42:50.890+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='Private'/><category scheme='http://www.blogger.com/atom/ns#' term='Exercise'/><category scheme='http://www.blogger.com/atom/ns#' term='Public'/><category scheme='http://www.blogger.com/atom/ns#' term='Failure'/><title type='text'>US cybersecurity defences fail to thwart mock cyberattack</title><content type='html'>&lt;p&gt;Critical US electronic systems have failed to withstand a simulated cyberattack.&lt;/p&gt;  &lt;p&gt;Participants in a recent cyber-warfare exercise told Reuters that the exercise highlighted problems in leadership, communications and readiness. The two-day exercise brought together 230 government agencies, private firms and other participants. Participants were split into two groups - attackers and defenders - before each developed tactics for attacking and defending critical infrastructure systems, such as those controlling banking, telecommunications and utilities. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2008/12/22/cyberwar_exercise/"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7565776721349696619?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2008/12/22/cyberwar_exercise/' title='US cybersecurity defences fail to thwart mock cyberattack'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7565776721349696619/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7565776721349696619' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7565776721349696619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7565776721349696619'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/us-cybersecurity-defences-fail-to.html' title='US cybersecurity defences fail to thwart mock cyberattack'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4492942195957767665</id><published>2009-01-13T03:36:00.001+08:00</published><updated>2009-01-13T03:38:57.318+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='NHS'/><category scheme='http://www.blogger.com/atom/ns#' term='Hospital'/><category scheme='http://www.blogger.com/atom/ns#' term='London'/><title type='text'>London Hospital back online after computer virus shutdown</title><content type='html'>&lt;p&gt;Computer systems at three major London hospitals are largely back online on Friday morning, three days after a major computer virus outbreak forced staff to disconnect the network.&lt;/p&gt;  &lt;p&gt;IT systems at St Bartholomew's (Barts), the Royal London Hospital in Whitechapel and the London Chest Hospital in Bethnal Green were taken down on Tuesday following infection by the Mytob worm. The three hospitals make up the Barts and the London NHS Trust. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2008/11/21/barts_mytob_recovery/"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4492942195957767665?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2008/11/21/barts_mytob_recovery/' title='London Hospital back online after computer virus shutdown'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4492942195957767665/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4492942195957767665' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4492942195957767665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4492942195957767665'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/london-hospital-back-online-after.html' title='London Hospital back online after computer virus shutdown'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3838818283358446351</id><published>2009-01-13T03:32:00.001+08:00</published><updated>2009-01-13T03:35:48.123+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Georgia'/><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Russia'/><title type='text'>DDoS attack floors Georgia prez website</title><content type='html'>&lt;p&gt;A denial of service attack hit government websites in the former Soviet republic of Georgia over the weekend amid growing diplomatic tensions between the country and Russia.&lt;/p&gt;  &lt;p&gt;The DDoS assault on the &lt;a href="http://www.president.gov.ge/" target="_blank"&gt;website&lt;/a&gt; of Georgian President Mikhail Saakashvili rendered it unavailable over the weekend. The attack was run via botnet networks of compromised PCs. Shadowserver charts the command and control servers used in the attack, in an analysis &lt;a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080720" target="_blank"&gt;here&lt;/a&gt;. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2008/07/21/georgia_presidential_site_ddos/"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3838818283358446351?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2008/07/21/georgia_presidential_site_ddos/' title='DDoS attack floors Georgia prez website'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3838818283358446351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3838818283358446351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3838818283358446351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3838818283358446351'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2009/01/ddos-attack-floors-georgia-prez-website.html' title='DDoS attack floors Georgia prez website'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2217978275155416689</id><published>2008-11-01T21:33:00.001+08:00</published><updated>2008-11-01T21:35:49.784+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Hack Turns Application Code Against Itself ... New attack uses application flaws to force good code to go rogue</title><content type='html'>&lt;p&gt;Turns out you don't need malware to exploit a security flaw in an application: A pair of researchers has found a way to automatically make good code do bad things. &lt;/p&gt;&lt;p&gt;Researchers from the University of California at San Diego (UCSD) have devised a technique that basically lets an attacker bypass built-in system defenses aimed at blocking malware, and then execute instructions from inside the application. The process uses an application's vulnerability to turn it against the system on which it runs. &lt;/p&gt;&lt;p&gt;An attacker could take advantage of a flaw in a Web browser, for instance, to force the browser to spam the user's address book using only the browser's own code, according to the researchers. .. &lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=211800104&amp;amp;cid=nl_DR_DAILY_T"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2217978275155416689?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=211800104&amp;cid=nl_DR_DAILY_T' title='Hack Turns Application Code Against Itself ... New attack uses application flaws to force good code to go rogue'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2217978275155416689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2217978275155416689' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2217978275155416689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2217978275155416689'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/11/hack-turns-application-code-against.html' title='Hack Turns Application Code Against Itself ... New attack uses application flaws to force good code to go rogue'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-751003438062619561</id><published>2008-11-01T21:29:00.001+08:00</published><updated>2008-11-01T21:31:46.010+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Weaknesses'/><category scheme='http://www.blogger.com/atom/ns#' term='Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='IRS'/><title type='text'>Auditors rap IRS for weak information security</title><content type='html'>&lt;span id="content_text"&gt;&lt;p&gt;The Internal Revenue Service has failed to secure sensitive electronic taxpayer information properly, increasing the potential for identity theft, according to an audit report released on Thursday.&lt;/p&gt;  &lt;p&gt;The inspector general &lt;a href="http://www.treas.gov/tigta/auditreports/2008reports/200820176fr.pdf"&gt;review&lt;/a&gt; of three computer systems at the IRS Office of Research, Analysis and Statistics showed several weaknesses in control over access to applications containing sensitive information.&lt;/p&gt;  &lt;p&gt;"Managers and system administrators had not placed sufficient emphasis on maintaining the security and privacy of the taxpayer data they are charged with protecting," the report stated. Furthermore, officials failed to provide guidance or monitor compliance with IRS information security policies, and did not supply software to scan for security weaknesses, the IG found. .. &lt;a href="http://www.nextgov.com/nextgov/ng_20081009_3974.php"&gt;More &gt;&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-751003438062619561?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.nextgov.com/nextgov/ng_20081009_3974.php' title='Auditors rap IRS for weak information security'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/751003438062619561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=751003438062619561' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/751003438062619561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/751003438062619561'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/11/auditors-rap-irs-for-weak-information.html' title='Auditors rap IRS for weak information security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6949771886529342610</id><published>2008-11-01T21:25:00.001+08:00</published><updated>2008-11-01T21:29:12.165+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Servers'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='IRS'/><category scheme='http://www.blogger.com/atom/ns#' term='Unauthorized'/><title type='text'>IRS finds unauthorized Web servers connected to its networks</title><content type='html'>&lt;span id="content_text"&gt;&lt;p&gt;The Internal Revenue Service found more than 1,000 unauthorized Web servers connected to its networks, leaving the agency's systems open to hackers, according to a report released on Thursday by the IRS inspector general.&lt;/p&gt;  &lt;p&gt;In September 2007, the IRS Computer Security Incident Response Center scanned the agency's Web servers and identified 2,093 that had at least one security vulnerability. When the center matched those servers to the IRS database of registered Web sites and servers, an inventory of systems that the agency uses to perform security maintenance and apply patches, it found 1,811, or 87 percent, were not listed in the database.&lt;/p&gt;  &lt;p&gt;Of the unregistered servers, the IRS identified 661 that were used for legitimate agency business, leaving 1,150 servers being used for potentially unauthorized activity, according to the report. .. &lt;a href="http://www.nextgov.com/nextgov/ng_20080904_3324.php"&gt; More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6949771886529342610?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.nextgov.com/nextgov/ng_20080904_3324.php' title='IRS finds unauthorized Web servers connected to its networks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6949771886529342610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6949771886529342610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6949771886529342610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6949771886529342610'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/11/irs-finds-unauthorized-web-servers.html' title='IRS finds unauthorized Web servers connected to its networks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-798542513985916919</id><published>2008-09-21T09:28:00.000+08:00</published><updated>2008-09-21T09:30:24.417+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Bugs'/><category scheme='http://www.blogger.com/atom/ns#' term='Glitches'/><title type='text'>Revealed: The Internet's Biggest Security Hole</title><content type='html'>&lt;p&gt; Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency. &lt;/p&gt;  &lt;p&gt;The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination.&lt;/p&gt;  &lt;p&gt; The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy.  The world was reminded of the quaintness of that assumption in July, when researcher &lt;a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html"&gt;Dan Kaminsky disclosed&lt;/a&gt; a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness. .. &lt;a href="http://http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-798542513985916919?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html' title='Revealed: The Internet&apos;s Biggest Security Hole'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/798542513985916919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=798542513985916919' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/798542513985916919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/798542513985916919'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/09/revealed-internets-biggest-security.html' title='Revealed: The Internet&apos;s Biggest Security Hole'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4625533884017275602</id><published>2008-09-21T09:24:00.002+08:00</published><updated>2008-09-21T09:27:24.052+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='EC Directive'/><category scheme='http://www.blogger.com/atom/ns#' term='ePrivacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Loss'/><title type='text'>European companies forced to own up to data losses</title><content type='html'>European companies will be forced to tell customers if their personal data has been lost or stolen, as part of a new EC directive. &lt;span id="intelliTXT"&gt;&lt;p&gt;The data breach notification provision is part of the ePrivacy Directive that is currently being debated by the EU.  ... &lt;a href="http://www.pcpro.co.uk/news/224478/european-companies-forced-to-own-up-to-data-losses.html"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4625533884017275602?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.pcpro.co.uk/news/224478/european-companies-forced-to-own-up-to-data-losses.html' title='European companies forced to own up to data losses'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4625533884017275602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4625533884017275602' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4625533884017275602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4625533884017275602'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/09/european-companies-forced-to-own-up-to.html' title='European companies forced to own up to data losses'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5847400669805909741</id><published>2008-09-21T09:15:00.000+08:00</published><updated>2008-09-21T09:18:17.699+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>Hacked Texas National Guard site serves up malware</title><content type='html'>Attackers have hacked the Web site of the Texas National Guard and are using it to serve up offers of fake security software and plant rootkits on unpatched PCs. .. &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9115060&amp;amp;source=rss_news10"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5847400669805909741?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115060&amp;source=rss_news10' title='Hacked Texas National Guard site serves up malware'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5847400669805909741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5847400669805909741' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5847400669805909741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5847400669805909741'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/09/hacked-texas-national-guard-site-serves.html' title='Hacked Texas National Guard site serves up malware'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-794049077388321647</id><published>2008-09-21T09:06:00.001+08:00</published><updated>2008-09-21T09:11:16.330+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GAO'/><category scheme='http://www.blogger.com/atom/ns#' term='DHS'/><category scheme='http://www.blogger.com/atom/ns#' term='US-Cert'/><title type='text'>GAO Report Slams US Cybersecurity, US-CERT, and DHS</title><content type='html'>The U.S. Government Accountability Office (GAO) is finalizing its report on the country's capability to protect and defend itself from cyber-attack, and its words are not kind. The primary responsibility for monitoring and securing the country's networks and digital assets falls to the United States Computer Emergency Readiness Team, or US-CERT, a partnership organization between the Department of Homeland Security (DHS) and both the public and private sectors. Founded in September 2003, US-CERT was responsible for the 2004 Einstein initiative, meant to detect and collect information on attacks at government agencies, and is currently backing the expanded (and hopefully more widely deployed) Einstein 2 program. .. &lt;a href="http://arstechnica.com/news.ars/post/20080917-gao-report-slams-us-cybersecurity-us-cert-and-dhs.html"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-794049077388321647?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://arstechnica.com/news.ars/post/20080917-gao-report-slams-us-cybersecurity-us-cert-and-dhs.html' title='GAO Report Slams US Cybersecurity, US-CERT, and DHS'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/794049077388321647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=794049077388321647' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/794049077388321647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/794049077388321647'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/09/gao-report-slams-us-cybersecurity-us.html' title='GAO Report Slams US Cybersecurity, US-CERT, and DHS'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6628807808758686066</id><published>2008-05-28T20:19:00.001+08:00</published><updated>2008-05-28T20:22:20.772+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='Australia'/><title type='text'>Hacker Shuts Down Government Computers</title><content type='html'>AN EXPERT hacker allegedly shut down the Northern Territory Government computer system and deleted thousands of employees' identities, a Darwin court heard yesterday.&lt;br /&gt;&lt;br /&gt;And the court heard the Government could still be at risk of another cyber attack.&lt;br /&gt;&lt;br /&gt;David Anthony McIntosh, 27, allegedly hacked in and shut down several NT Government databases on May 5, including servers for the Health Department, Royal Darwin Hospital, Berrimah Prison and Supreme Court using his laptop at a Palmerston home. &lt;a href="http://www.news.com.au/story/0,23599,23707457-2,00.html"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6628807808758686066?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.news.com.au/story/0,23599,23707457-2,00.html' title='Hacker Shuts Down Government Computers'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6628807808758686066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6628807808758686066' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6628807808758686066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6628807808758686066'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/05/hacker-shuts-down-government-computers.html' title='Hacker Shuts Down Government Computers'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5111736482215028728</id><published>2008-05-11T21:56:00.004+08:00</published><updated>2008-05-11T22:02:53.375+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Countermeasures'/><category scheme='http://www.blogger.com/atom/ns#' term='Information Sharing'/><category scheme='http://www.blogger.com/atom/ns#' term='Threat'/><category scheme='http://www.blogger.com/atom/ns#' term='DHS'/><title type='text'>Homeland Security reveals threats and the plans to counter the threats and attacks</title><content type='html'>The US Department of Homeland Security had a security summit where the Assistant Secretary of Cybersecurity and Communications, Greg Garcia, provided some remarks about the current challenges and threats and the need for all critical infrastructure entities to work together to share information to face the threats that are not merely increasing but alos has gone to another level of sophistication. More details can be found here .. &lt;a href="http://www.dhs.gov/xnews/releases/pr_1197409593155.shtm"&gt;&gt;&gt; More .. &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5111736482215028728?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.dhs.gov/xnews/releases/pr_1197409593155.shtm' title='Homeland Security reveals threats and the plans to counter the threats and attacks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5111736482215028728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5111736482215028728' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5111736482215028728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5111736482215028728'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/05/homeland-security-reveals-threats-and.html' title='Homeland Security reveals threats and the plans to counter the threats and attacks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8252162397902636080</id><published>2008-05-11T21:51:00.001+08:00</published><updated>2008-05-11T21:54:52.662+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Electronic Warfare'/><category scheme='http://www.blogger.com/atom/ns#' term='India'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><title type='text'>India Cites Ongoing Chinese Cyber Attacks</title><content type='html'>A year and a half of electronic warfare against public and private network resources in India has been traced back to a variety of attacks and antagonists in China.&lt;br /&gt;&lt;br /&gt;Botnets, keyloggers, and network mapping all plague India on a regular basis, as its gigantic rival in Asia seeks weaknesses within the country's information infrastructure.  &lt;a href="http://www.securitypronews.com/insiderreports/insider/spn-49-20080505IndiaCitesOngoingChineseCyberAttacks.html"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8252162397902636080?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securitypronews.com/insiderreports/insider/spn-49-20080505IndiaCitesOngoingChineseCyberAttacks.html' title='India Cites Ongoing Chinese Cyber Attacks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8252162397902636080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8252162397902636080' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8252162397902636080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8252162397902636080'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/05/india-cites-ongoing-chinese-cyber.html' title='India Cites Ongoing Chinese Cyber Attacks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2821791896772401801</id><published>2008-04-23T13:17:00.007+08:00</published><updated>2008-04-23T13:26:44.567+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><title type='text'>CNN Site Hit by China Attack</title><content type='html'>In the recent unrest between China and Tibet, the CNN site has been attacked.&lt;br /&gt;&lt;br /&gt;At its peak, the attack has sucked up 100MB/S in bandwidth, enough to slow the news Web site for some visitors. &lt;span style="font-size:130%;"&gt;&lt;span style=";font-family:times new roman;font-size:100%;"  &gt;   &gt;&gt; &lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=3491"&gt;More ..&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="homepage_content_15"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2821791896772401801?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networksasia.net/article.php?type=article&amp;id_article=3491' title='CNN Site Hit by China Attack'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2821791896772401801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2821791896772401801' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2821791896772401801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2821791896772401801'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/04/cnn-site-hit-by-china-attack.html' title='CNN Site Hit by China Attack'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6834840282048434369</id><published>2008-03-20T16:42:00.001+08:00</published><updated>2008-03-20T16:44:28.013+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Smartcard'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='RFID'/><title type='text'>Hackers find a way to crack popular smartcard in minutes</title><content type='html'>People are starting to wake up to the fact that RFID-enabled smartcards now can be far more easily, and cheaply, cracked than ever before, as a trio of young computer experts recently showed.&lt;br /&gt;&lt;br /&gt;These are a particular type of processor-embedded cards, and are different from credit cards. The actual decryption work by the researchers was done on the widely deployed Mifare Classic wireless smartcard, now manufactured by a Philips spinoff, NXP Semiconductors. Decrypted, the cards can be counterfeited, and users' personal and bank data is exposed. &gt;&gt; &lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=3196"&gt;More .. &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6834840282048434369?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networksasia.net/article.php?type=article&amp;id_article=3196' title='Hackers find a way to crack popular smartcard in minutes'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6834840282048434369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6834840282048434369' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6834840282048434369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6834840282048434369'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/hackers-find-way-to-crack-popular.html' title='Hackers find a way to crack popular smartcard in minutes'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6711683268353043251</id><published>2008-03-20T16:34:00.001+08:00</published><updated>2008-03-20T16:36:54.017+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internet Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Homeland Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Initiatives'/><title type='text'>US Law makers voice concerns over cybersecurity plan</title><content type='html'>Members of the House of Representative sought details, on Thursday, of a $30 billion plan to secure federal government systems and upgrade network defenses to ward off attacks from foreign nations and online criminals.&lt;br /&gt;&lt;br /&gt;Known as the Cyber Initiative, the Bush Administration project would dramatically reduce the number of interconnections between federal government networks and the Internet and put more advanced network security in place to monitor data traffic for signs of malicious attacks. While the 5- to 7-year project could dramatically improve the network defenses of government agencies, law makers questioned whether the initiative will be too little, too late, and whether the resulting network monitoring could undermine privacy.&lt;br /&gt;&lt;br /&gt;"It's hard to believe that this Administration now believes it has the answers to secure our federal networks and critical infrastructure," Representative Bennie Thompson (D-MS), chairman of the House Committee on Homeland Security, said in prepared remarks at the opening of the hearing on Thursday. "I believe cybersecurity is a serious problem -- maybe the most complicated national security issue in terms of threat and jurisdiction. This problem will be with us for decades to come." &gt;&gt; &lt;a href="http://www.securityfocus.com/news/11507?ref=rss"&gt;More ...&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6711683268353043251?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securityfocus.com/news/11507?ref=rss' title='US Law makers voice concerns over cybersecurity plan'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6711683268353043251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6711683268353043251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6711683268353043251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6711683268353043251'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/us-law-makers-voice-concerns-over.html' title='US Law makers voice concerns over cybersecurity plan'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4223850871157239699</id><published>2008-03-20T16:25:00.002+08:00</published><updated>2008-03-20T16:28:07.542+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Vendor'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>Trend Micro Hit by Massive Web Hack</title><content type='html'>Security vendor Trend Micro has fallen victim to a widespread Web attack that splashed malicious software onto hundreds of legitimate Web sites in recent days.&lt;br /&gt;&lt;br /&gt;A Trend Micro spokesman confirmed that the company’s site had been hacked Thursday, saying that the attack took place earlier in the week. "A portion of our site -- some pages were attacked," said Mike Sweeny, a Trend Micro spokesman. "We took the pages down overnight Tuesday night -- and took corrective action." &gt;&gt; &lt;a href="http://www2.csoonline.com/blog_view.html?CID=33614"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4223850871157239699?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www2.csoonline.com/blog_view.html?CID=33614' title='Trend Micro Hit by Massive Web Hack'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4223850871157239699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4223850871157239699' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4223850871157239699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4223850871157239699'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/trend-micro-hit-by-massive-web-hack.html' title='Trend Micro Hit by Massive Web Hack'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4190234085783453138</id><published>2008-03-11T11:01:00.001+08:00</published><updated>2008-03-11T11:04:43.214+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='Chinese'/><title type='text'>Chinese hackers: No site is safe</title><content type='html'>ZHOUSHAN, China (CNN) -- They operate from a bare apartment on a Chinese island. They are intelligent 20-somethings who seem harmless. But they are hard-core hackers who claim to have gained access to the world's most sensitive sites, including the Pentagon.&lt;br /&gt;&lt;a onmouseover="CNN_changeImg('cnnImgChngrPrvsBtn',1)" style="CURSOR: default" onclick="CNN_ArticleChanger.CNN_navChngBack(); return false;" onmouseout="CNN_changeImg('cnnImgChngrPrvsBtn')" href="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest#"&gt;&lt;/a&gt;&lt;br /&gt;In fact, they say they are sometimes paid secretly by the Chinese government -- a claim the Beijing government denies.&lt;br /&gt;&lt;br /&gt;"No Web site is one hundred percent safe. There are Web sites with high-level security, but there is always a weakness," says Xiao Chen, the leader of this group. &gt;&gt; &lt;a href="http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4190234085783453138?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cnn.com/2008/TECH/03/07/china.hackers/index.html?eref=rss_latest' title='Chinese hackers: No site is safe'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4190234085783453138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4190234085783453138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4190234085783453138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4190234085783453138'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/chinese-hackers-no-site-is-safe.html' title='Chinese hackers: No site is safe'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2142802776216905809</id><published>2008-03-11T10:17:00.001+08:00</published><updated>2008-03-11T11:01:15.571+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Coordination'/><category scheme='http://www.blogger.com/atom/ns#' term='US'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Preparedness'/><category scheme='http://www.blogger.com/atom/ns#' term='Symposium'/><title type='text'>Cyber Preparedness Symposium Leaves Unanswered Questions</title><content type='html'>WASHINGTON -- National Symposium on Unifying Cyber Preparedness Efforts -- Leaders of industry and academia today agreed that they need to work better together to prepare for cyber security threats. They just didn’t seem sure how to do it, or exactly what the threats are.&lt;br /&gt;&lt;br /&gt;In a microcosm of the cross-industry, cross-disciplinary problems that it was called to help resolve, the symposium demonstrated a desire among some sectors to improve the security situation in the U.S., but few concrete ideas on how to coordinate the so-called “silos of excellence” that remain disconnected across the country.&lt;br /&gt;&lt;br /&gt;Indeed, the panelists and participants showed little agreement on what “cyber preparedness” really means -- the half-day discussion meandered from defending against attacks on the nation’s government and infrastructure to resolving specific vulnerabilities on end-user PCs.&lt;br /&gt;&lt;br /&gt;The idea was to discuss how government, industry, critical infrastructure providers, Congress, and academia can work together to build a cross-disciplinary effort to prepare for cyber threats.&lt;br /&gt;&gt;&gt; &lt;a href="http://www.darkreading.com/document.asp?doc_id=147896&amp;amp;f_src=drdaily"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2142802776216905809?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/document.asp?doc_id=147896&amp;f_src=drdaily' title='Cyber Preparedness Symposium Leaves Unanswered Questions'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2142802776216905809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2142802776216905809' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2142802776216905809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2142802776216905809'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/cyber-preparedness-symposium-leaves.html' title='Cyber Preparedness Symposium Leaves Unanswered Questions'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3070637995179703285</id><published>2008-03-01T17:04:00.005+08:00</published><updated>2008-03-01T17:16:23.840+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internal Controls'/><category scheme='http://www.blogger.com/atom/ns#' term='Bank'/><category scheme='http://www.blogger.com/atom/ns#' term='Segregation of Responsibilities'/><category scheme='http://www.blogger.com/atom/ns#' term='Limits of Authority'/><category scheme='http://www.blogger.com/atom/ns#' term='Loopholes'/><title type='text'>Forgotten IT chores may have led to bank meltdown</title><content type='html'>While the protection of CII may often be focused on protection from external threats and internal threats, some of the simple and basic practices pertaining to security must be followed to ensure that there are no loopholes in the system that can be exploited. Employees should generally be trusted (if not you have a big problem in your organisation). However segregation of responsibilities and implementing management controls are still important practices that must be enforced.&lt;br /&gt;&lt;br /&gt;In January 2008, a French Bank incurred huge losses due to poor enforcement of internal controls and segregation of responsibilities. The losses were result of an employee ... who was doing his job!!.&lt;br /&gt;&lt;br /&gt;The huge losses reported by French bank Société Générale, apparently caused by a rogue trader with inside knowledge of the bank's procedures, don't necessarily point to an IT systems failure but rather to poor management of those systems, analysts say.&lt;br /&gt;&lt;br /&gt;The bank has accused 31-year-old employee Jerome Kerviel of creating a fraudulent trading position in the bank's computers that ultimately caused it to lose around €4.9 billion (US$7.3 billion).&lt;br /&gt;&lt;br /&gt;Kerviel achieved this by, among other things, misappropriating computer passwords, the bank said. It has revealed few other technical details of what caused the losses.&lt;br /&gt;&lt;br /&gt;Management of passwords, including rescinding the old passwords of employees who move to different positions within the bank, or modifying the level of access those passwords allow, is often a task given to the lowest-level IT worker.&lt;br /&gt;&lt;br /&gt;"It's dull and routine 99 percent of the time, but a vital backstop," said Bob McDowall, senior analyst at the TowerGroup. Senior IT managers should conduct more frequent reviews of password policies, he said.&lt;br /&gt;&lt;br /&gt;In some cases, it may not have been the security of the passwords themselves that posed a problem, but rather the access those passwords allowed, said Ian Walden, professor of information and communications law at Queen Mary, University of London.&lt;br /&gt;&lt;br /&gt;Organizations tend to think of access as being binary in nature: you get access to it all, or you don't, Walden said. In reality, there are many more levels of access. "In modern, complicated systems, the granularity has to be much more sophisticated."&lt;br /&gt;&lt;br /&gt;To make the best use of systems with advanced access controls, the IT department must have a thorough understanding of how the business works and where there is risk.&lt;br /&gt;&lt;br /&gt;IT departments and business managers have yet to find a way to wrap security into business processes so it is not an impediment, Walden said. &gt;&gt; &lt;a href="http://security.itworld.com/4366/societe-generale-meltdown-080204/page_1.html"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3070637995179703285?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://security.itworld.com/4366/societe-generale-meltdown-080204/page_1.html' title='Forgotten IT chores may have led to bank meltdown'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3070637995179703285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3070637995179703285' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3070637995179703285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3070637995179703285'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/forgotten-it-chores-may-have-led-to.html' title='Forgotten IT chores may have led to bank meltdown'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3141465677515268982</id><published>2008-03-01T16:57:00.003+08:00</published><updated>2008-03-01T17:02:14.710+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Best Practices'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Preventive Measures'/><category scheme='http://www.blogger.com/atom/ns#' term='Patch'/><title type='text'>Half of 2006 vulnerabilities still unpatched</title><content type='html'>It is important that when vendors send patch updates, these are implemented to prevent weaknesses from being exploited and depending on the system set up, can cause major interruptions to infrastructure. Despite its importance organisations still lack the diligence to keep up in updating the patches.&lt;br /&gt;&lt;br /&gt;More than 3600 vulnerabilities discovered last year remain unpatched, according to a study.&lt;br /&gt;&lt;br /&gt;The IBM Internet Security Systems (ISS) X-Force report for 2007 found of the 6437 vulnerabilities discovered, 20 percent of those targeting Microsoft, Apple, Oracle, IBM and Cisco were still in the wild up to 12 months later.&lt;br /&gt;&lt;br /&gt;More than 50 percent of remaining 6200 flaws targeting other solutions remain currently unpatched. &gt;&gt; &lt;a href="http://www.csoonline.com.au/index.php/id;1746640414"&gt;More....&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3141465677515268982?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.csoonline.com.au/index.php/id;1746640414' title='Half of 2006 vulnerabilities still unpatched'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3141465677515268982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3141465677515268982' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3141465677515268982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3141465677515268982'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/03/half-of-2006-vulnerabilities-still.html' title='Half of 2006 vulnerabilities still unpatched'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-9009864348223307002</id><published>2008-02-17T07:40:00.002+08:00</published><updated>2008-02-17T07:43:47.248+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Homeland Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Air Defense'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Idaho National Laboratory - Research on National Security</title><content type='html'>The Idaho National Laporatory's (INL) National and Homeland Security Division is one of serveral organisations inthe USA involved in CNII protection research.&lt;br /&gt;&lt;br /&gt; The National and Homeland Security Division conducts sustainable programs focused in &lt;a href="http://www.inl.gov/nationalsecurity/globalsecurity/"&gt;Global Security&lt;/a&gt;, &lt;a href="http://www.inl.gov/nationalsecurity/homelandsecurity/"&gt;Homeland Security&lt;/a&gt;, &lt;a href="http://www.inl.gov/nationalsecurity/nationaldefense/"&gt;National Defense&lt;/a&gt;, &lt;a href="http://www.inl.gov/nationalsecurity/energysecurity/"&gt;Energy Security&lt;/a&gt;, and &lt;a href="http://www.inl.gov/nationalsecurity/specialprograms/"&gt;Special Programs&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-9009864348223307002?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.inl.gov/nationalsecurity/' title='Idaho National Laboratory - Research on National Security'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/9009864348223307002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=9009864348223307002' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/9009864348223307002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/9009864348223307002'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/02/idaho-national-laboratory-research-on.html' title='Idaho National Laboratory - Research on National Security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-1872349853523090314</id><published>2008-02-17T07:28:00.003+08:00</published><updated>2008-02-17T07:32:05.885+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injects'/><category scheme='http://www.blogger.com/atom/ns#' term='Massive'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Hackers Gone Wild ... Hacks on a massive scale</title><content type='html'>While previously hacks may be one off incidents posing threats to a small segment. Today the scenario is different.&lt;br /&gt;&lt;br /&gt;We're looking at massive, well-organized plans to take over vast portions of the Net. Case in point: The SQL Injection exploit that infected more 70,000 sites .. &lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=2905"&gt;more&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-1872349853523090314?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networksasia.net/article.php?type=article&amp;id_article=2905' title='Hackers Gone Wild ... Hacks on a massive scale'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/1872349853523090314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=1872349853523090314' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1872349853523090314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1872349853523090314'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/02/hackers-gone-wild-hacks-on-massive.html' title='Hackers Gone Wild ... Hacks on a massive scale'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4595575671712637823</id><published>2008-02-17T07:24:00.004+08:00</published><updated>2008-02-17T07:28:11.562+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='Control of Internet'/><title type='text'>US plans to 'fight the net' revealed</title><content type='html'>A newly declassified document gives a fascinating glimpse into the US military's plans for "information operations" - from psychological operations, to attacks on hostile computer networks.&lt;br /&gt;&lt;br /&gt;Should nations care and worry about this as a threat to their CNII, we dont really know. But apart from the US, it is possible that some other nations or organised entities have similar aspirations, if not plans.  .. &lt;a href="http://news.bbc.co.uk/1/hi/world/americas/4655196.stm"&gt;more&lt;/a&gt;..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4595575671712637823?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.bbc.co.uk/1/hi/world/americas/4655196.stm' title='US plans to &apos;fight the net&apos; revealed'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4595575671712637823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4595575671712637823' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4595575671712637823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4595575671712637823'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/02/us-plans-to-fight-net-revealed.html' title='US plans to &apos;fight the net&apos; revealed'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8925794917845258183</id><published>2008-02-17T07:13:00.004+08:00</published><updated>2008-02-17T07:18:14.927+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Interruptions'/><category scheme='http://www.blogger.com/atom/ns#' term='Cable'/><category scheme='http://www.blogger.com/atom/ns#' term='Middle East'/><title type='text'>Cut cable disrupts Internet in Middle East</title><content type='html'>Two underwater cables in the Mediterranean Sea were damaged in January 2008, dragging Internet connections throughout the Middle East and in parts of Asia to a crawl. This is a classic example of massive interruptions to CNII, though the scenario if one for which most would not have incorporated in the list of probabilities .. &lt;a href="http://www.networkworld.com/news/2008/013108-cut-cable-disrupts-internet-in.html"&gt;more..&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Further questions are raised about the said vulnerability, possible but deemed improbable. &lt;a href="http://www.networkworld.com/columnists/2008/020708eyejohnson.html?netht=ts_020708&amp;amp;nladname=020708dailynewspmal"&gt;more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8925794917845258183?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networkworld.com/news/2008/013108-cut-cable-disrupts-internet-in.html' title='Cut cable disrupts Internet in Middle East'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8925794917845258183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8925794917845258183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8925794917845258183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8925794917845258183'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/02/cut-cable-disrupts-internet-in-middle.html' title='Cut cable disrupts Internet in Middle East'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-1639642950151628453</id><published>2008-01-03T01:11:00.000+08:00</published><updated>2008-01-03T01:14:46.488+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>The 5 Coolest Hacks of 2007</title><content type='html'>Hackers are creative folk, for sure. But some researchers are more imaginative and crafty than others. We're talking the kind of guys who aren't content with finding the next bug in Windows or a Cisco router. Instead, they go after the everyday things we take for granted even more than our PCs -- our cars, our wireless connections, and (gulp) the electronic financial trading systems that record our stock purchases and other online transactions. &gt;&gt; &lt;a href="http://www.darkreading.com/document.asp?doc_id=142127&amp;amp;f_src=drdaily"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-1639642950151628453?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/document.asp?doc_id=142127&amp;f_src=drdaily' title='The 5 Coolest Hacks of 2007'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/1639642950151628453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=1639642950151628453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1639642950151628453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1639642950151628453'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/5-coolest-hacks-of-2007.html' title='The 5 Coolest Hacks of 2007'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3756423483597103479</id><published>2008-01-03T00:51:00.000+08:00</published><updated>2008-01-03T01:00:28.140+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trends'/><category scheme='http://www.blogger.com/atom/ns#' term='CISCO'/><category scheme='http://www.blogger.com/atom/ns#' term='Report'/><title type='text'>CISCO's 2007 Annual Security Report</title><content type='html'>CISCO has released its 2007 Annual Security Report which provides an overview of the combined security intelligence of the entire CISCO organisation. The report encompasses threat information and trends collected between January and September 2007, and provides a snapshot of the state of security for that period. The report provides recommendations from CISCO security experts and predictions of how identified trends will continue to unfold in 2008.&lt;br /&gt;&lt;br /&gt;Security trends and recommendations are organized into seven major risk categories:&lt;br /&gt;&lt;br /&gt;- Vulnerability&lt;br /&gt;- Physical&lt;br /&gt;- Legal&lt;br /&gt;- Trust&lt;br /&gt;- Identity&lt;br /&gt;- Human&lt;br /&gt;- Geopolitical&lt;br /&gt;&lt;br /&gt;The report also provides a high-level perspective on the issues currently shaping the security space, as well as insights into how security professionals and businesses can expect the industry to change over the next several years. The report can be downloaded &lt;a href="http://www.cisco.com/web/about/security/cspo/docs/Cisco2007Annual_Security_Report.pdf"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3756423483597103479?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cisco.com/web/about/security/cspo/docs/Cisco2007Annual_Security_Report.pdf' title='CISCO&apos;s 2007 Annual Security Report'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3756423483597103479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3756423483597103479' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3756423483597103479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3756423483597103479'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/ciscos-2007-annual-security-report.html' title='CISCO&apos;s 2007 Annual Security Report'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4663625070107764182</id><published>2008-01-03T00:38:00.000+08:00</published><updated>2008-01-03T00:45:15.671+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tests'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus'/><title type='text'>Antivirus Protection Worse Than a Year Ago</title><content type='html'>The effectiveness of antivirus software has fallen off, and more and more pests can now slip past these barriers. This is the sobering conclusion the german &lt;a href="http://www.heise.de/ct"&gt;computer magazine c't&lt;/a&gt; comes to in issue 1/08 with a test on 17 antivirus solutions. For the first time, c't also tested the behavioural blocking system they use. &lt;a href="http://www.heise-security.co.uk/news/100900"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4663625070107764182?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.heise-security.co.uk/news/100900' title='Antivirus Protection Worse Than a Year Ago'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4663625070107764182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4663625070107764182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4663625070107764182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4663625070107764182'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/antivirus-protection-worse-than-year.html' title='Antivirus Protection Worse Than a Year Ago'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6017113597226333333</id><published>2008-01-03T00:18:00.000+08:00</published><updated>2008-01-03T00:28:05.702+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Industry'/><category scheme='http://www.blogger.com/atom/ns#' term='Oil and Gas'/><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='Collaboration'/><title type='text'>LOGIIC – Linking the Oil and Gas Industry to Improve Cyber Security</title><content type='html'>LOGIIC is a unique collaborative forum (initiated by the US Department of Homeland Security) where government and industry are focusing on cyber security issues for the oil and gas industry that are best addressed collaboratively. The needs of the infrastructure owners and operators are driving the formation of projects, supported by government and independent experts. The forms for future collaboration are currently being established, and new projects will be forthcoming.&lt;br /&gt;&lt;br /&gt;One such project was the the LOGIIC 2005-2006 Correlation Project.&lt;br /&gt;&lt;br /&gt;The LOGIIC Correlation Project was a 12-month technology integration and demonstration project jointly supported by industry partners and the U.S. Department of Homeland Security Science and Technology Directorate (DHS S&amp;amp;T). The project demonstrated an opportunity to reduce vulnerabilities of oil and gas process control environments by sensing, correlating and analyzing abnormal events to identify and prevent cyber security threats.&lt;br /&gt;&lt;br /&gt;A detailed description of the LOGIIC Correlation Project can be downloaded from &lt;a href="http://www.cyber.st.dhs.gov/docs/LOGIICbrochureHighRes.pdf"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This collaboration model between Government and industry can be similarly applied to other industry sectors.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cyber.st.dhs.gov/docs/LOGIICbrochure.pdf"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6017113597226333333?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cyber.st.dhs.gov/logiic.html' title='LOGIIC – Linking the Oil and Gas Industry to Improve Cyber Security'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6017113597226333333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6017113597226333333' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6017113597226333333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6017113597226333333'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/logiic-linking-oil-and-gas-industry-to.html' title='LOGIIC – Linking the Oil and Gas Industry to Improve Cyber Security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4376300018082940626</id><published>2008-01-03T00:07:00.000+08:00</published><updated>2008-01-03T00:13:13.328+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CNII'/><category scheme='http://www.blogger.com/atom/ns#' term='Blogs'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>SCADA Security and CNII - Digital Bond</title><content type='html'>This Digital Bond site is a site that has articles and blogs on SCADA security with a focus on CNII issues. There are several blog categories that discusses a wide range of related topics. Have a look at the site to get some key information and knowlegde about SCADA security. &lt;a href="http://www.digitalbond.com/"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4376300018082940626?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.digitalbond.com/' title='SCADA Security and CNII - Digital Bond'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4376300018082940626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4376300018082940626' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4376300018082940626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4376300018082940626'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/scada-security-and-cnii-digital-bond.html' title='SCADA Security and CNII - Digital Bond'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8239258936400090726</id><published>2008-01-02T23:37:00.000+08:00</published><updated>2008-01-02T23:57:34.723+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Interview'/><category scheme='http://www.blogger.com/atom/ns#' term='Control Systems'/><category scheme='http://www.blogger.com/atom/ns#' term='PLC'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='DCS'/><category scheme='http://www.blogger.com/atom/ns#' term='Expert'/><title type='text'>SCADA and Control System Security - Views From An Expert</title><content type='html'>Joseph Weiss is one of the leading experts in control system security. He provides some interesting insights about control systems and including SCADA, DCS and PLC and the security issues surrounding these in an interview found &lt;a href="http://www.pbs.org/wgbh/pages/frontline/shows/cyberwar/interviews/weiss.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;He explains among other things that "A control system has several unique attributes. Number one, a control system must be absolutely highly reliable. It can't shut down very often. So, unlike a business system where you can shut it down over the weekend, the system that controls the power plant must have almost 100 percent reliability or some form of backup to maintain the 100 percent reliability. It is extremely important." This characteristic brings in itself a very unique perspective about security implementation related to control systems.&lt;br /&gt;&lt;br /&gt;In a later part of the interview he has this to say about control systems getting hit: "My very, very, very strong feeling is, if and when we get hit, we will never know why we were hit. All we will know is breakers are opening, valves are closing, certain things are happening. But we won't have a clue as to why."&lt;br /&gt;&lt;br /&gt;The interview contains a lot of other interesting insights and examples of incidents and lessons learnt that would be useful for anybody interested in CNII and control systems in particular. &lt;a href="http://www.pbs.org/wgbh/pages/frontline/shows/cyberwar/interviews/weiss.html"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8239258936400090726?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.pbs.org/wgbh/pages/frontline/shows/cyberwar/interviews/weiss.html' title='SCADA and Control System Security - Views From An Expert'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8239258936400090726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8239258936400090726' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8239258936400090726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8239258936400090726'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/scada-and-control-system-security-views.html' title='SCADA and Control System Security - Views From An Expert'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4368459943427960082</id><published>2008-01-02T23:11:00.000+08:00</published><updated>2008-01-02T23:36:49.213+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Teens'/><category scheme='http://www.blogger.com/atom/ns#' term='School'/><category scheme='http://www.blogger.com/atom/ns#' term='Teachers'/><category scheme='http://www.blogger.com/atom/ns#' term='Safe Internet'/><category scheme='http://www.blogger.com/atom/ns#' term='Kids'/><title type='text'>ICT Security Education and Awareness for Students</title><content type='html'>Learning to use the Internet safely should begin at a young age in school so that the generation of youth has the basic knowledge to practice and infuse or inculcate safe Internet use when they join the workforce. Some students have the ability to explore and find out the best practices themselves while yet the majority of others need to be taught or guided. The Hacker Highschool site is one of several websites that provides easy to follow materials on safe Internet use for school children.&lt;br /&gt;&lt;br /&gt;The Hacker Highschool project is the development of license-free, security and privacy awareness teaching materials and back-end support for teachers.&lt;br /&gt;&lt;br /&gt;Today's kids and teens are in a world with major communication and productivity channels open to them and they don't have the knowledge to defend themselves against the fraud, identity theft, privacy leaks and other attacks made against them just for using the Internet. This is the reason for Hacker Highschool.&lt;br /&gt;&lt;br /&gt;In HHS, you will find lessons on utilizing Internet resources safely such as web privacy, chat protection, viruses and trojans (malware), and the over-all focus on how to recognize security problems on your computer. HHS is a great supplement to student course work or as part of after-school and club activities.The HHS program is developed by &lt;a href="http://www.isecom.org/" target="_blank"&gt;ISECOM&lt;/a&gt;, a non-profit, open-source research group focused on security awareness and professional security development and accreditation. &lt;a href="http://www.hackerhighschool.org/"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4368459943427960082?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.hackerhighschool.org/' title='ICT Security Education and Awareness for Students'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4368459943427960082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4368459943427960082' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4368459943427960082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4368459943427960082'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2008/01/ict-security-education-and-awareness.html' title='ICT Security Education and Awareness for Students'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5557329695231272194</id><published>2007-12-28T15:43:00.000+08:00</published><updated>2007-12-28T15:48:37.351+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Healthcare'/><category scheme='http://www.blogger.com/atom/ns#' term='Health'/><category scheme='http://www.blogger.com/atom/ns#' term='Exposures'/><title type='text'>Insecurities in Healthcare Applications</title><content type='html'>Healthcare applications can be exploited with disastrous consequences if not adequately secured.&lt;br /&gt;&lt;br /&gt;Healthcare apps keep sensitive medical records of patients. Though different types of healthcare applications are exposed to different sets of threats, there’s a pattern to threats they face.&lt;br /&gt;This articel discusses some of the exposures that healthcare applications face.  &lt;a href="http://palisade.plynt.com/issues/2006Dec/healthcare-applications/"&gt;&gt;&gt; More ....&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5557329695231272194?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://palisade.plynt.com/issues/2006Dec/healthcare-applications/' title='Insecurities in Healthcare Applications'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5557329695231272194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5557329695231272194' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5557329695231272194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5557329695231272194'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/12/insecurities-in-healthcare-applications.html' title='Insecurities in Healthcare Applications'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-1179024779791237056</id><published>2007-12-28T15:27:00.000+08:00</published><updated>2007-12-31T04:53:57.300+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Threat'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Impact'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk'/><category scheme='http://www.blogger.com/atom/ns#' term='Controls'/><title type='text'>Top Ten Information Security Risks of 2008</title><content type='html'>This list which in fact covers Threats, Vulnerabilities, Impacts, Risks and Controls assembled by the &lt;a href="http://www.noticebored.com/html/cisspforumfaq.html"&gt;CISSP Forum &lt;/a&gt;and the &lt;a href="http://groups.google.com/group/iso27001security"&gt;ISO 27K Implementers' Forum&lt;/a&gt;. The list of course includes threats and risks to Critical Information Infrastructure.&lt;br /&gt;&lt;br /&gt;Those who are still confused with the definition and differences of Threat, Vulnerabilityu, Impact, Risk and Control, this article does list and discuss the brief definitions and the actual lists of the above will illustrate the definition further.&lt;br /&gt;&lt;br /&gt;This is a must read for all involved in security. &gt;&gt; &lt;a href="http://www.iso27001security.com/Top_information_security_risks_for_2008.pdf"&gt;More...&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-1179024779791237056?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.iso27001security.com/Top_information_security_risks_for_2008.pdf' title='Top Ten Information Security Risks of 2008'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/1179024779791237056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=1179024779791237056' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1179024779791237056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1179024779791237056'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/12/top-ten-information-security-risks-of.html' title='Top Ten Information Security Risks of 2008'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4471015557185630950</id><published>2007-12-03T10:30:00.000+08:00</published><updated>2007-12-03T10:42:06.930+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Criminal'/><category scheme='http://www.blogger.com/atom/ns#' term='Interview'/><category scheme='http://www.blogger.com/atom/ns#' term='Crime'/><category scheme='http://www.blogger.com/atom/ns#' term='Forgery'/><title type='text'>Catch me if you can star offers IT security advice</title><content type='html'>Frank Abagnale started off on the wrong side of the law by deceit and forgery to earn large amounts of money but was later caught. This was in the 60s when he was a teenager. His forgery talents did not go unnoticed and he was offered a job with the FBI in lieu of the rest of his jail sentence. His job is ... of course ... to pin down on forgery crimes.&lt;br /&gt;&lt;br /&gt;His adventures were told in a book and a subsequent movie called "Catch me if you can".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.networksasia.net/article.php?id_article=2290&amp;amp;page=1"&gt;This article &lt;/a&gt;is an interview with him where amongst other things he explained that:&lt;br /&gt;1. It is  way easier to commit forgery today than 40 years ago&lt;br /&gt;2. We can have all the sophisticated security systems but the weakest link is still the human link.&lt;br /&gt;3. Some laws passed recently are plain stupid.&lt;br /&gt;4. Ethics must be reintroduced in education and must be a part of corporate culture.&lt;br /&gt;5. We must be thinking out of the box when addressing security.&lt;br /&gt;6. Simple solutions should be preferred than sophisticated ones.&lt;br /&gt;&lt;br /&gt;While the above points appear obvious, it is certainly refreshing from a person who has been on both sides of the law. His thoughts and views are certainly key pointers for any entity managing critical infrastructures to gain a lesson or two from the perspective of security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4471015557185630950?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networksasia.net/article.php?id_article=2290&amp;page=1' title='Catch me if you can star offers IT security advice'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4471015557185630950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4471015557185630950' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4471015557185630950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4471015557185630950'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/12/catch-me-if-you-can-star-offers-it.html' title='Catch me if you can star offers IT security advice'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4686738257428715399</id><published>2007-12-03T07:28:00.000+08:00</published><updated>2007-12-03T07:32:52.197+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Top Mishaps'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Breach'/><title type='text'>Top 5 Worst IT Security Mishaps of 2007</title><content type='html'>Even though 2007 is not over, there are more than sufficient contenders for the top 5 position of the worst IT Security Mishaps of 2007. Though most of the mishaps relate to substantial data leakage, the examples are enough to raise alarm and concern about security breaches in the most trivial of cicumstances. &gt;&gt; More ..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4686738257428715399?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://resources.zdnet.co.uk/articles/features/0,1000002000,39290745,00.htm?user_rating=1' title='Top 5 Worst IT Security Mishaps of 2007'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4686738257428715399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4686738257428715399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4686738257428715399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4686738257428715399'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/12/top-5-worst-it-security-mishaps-of-2007.html' title='Top 5 Worst IT Security Mishaps of 2007'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6702129193924282050</id><published>2007-12-03T07:14:00.000+08:00</published><updated>2007-12-03T07:21:55.398+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Weapons'/><category scheme='http://www.blogger.com/atom/ns#' term='Espionage'/><category scheme='http://www.blogger.com/atom/ns#' term='Countries'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><title type='text'>World on Brink of Cyber Cold War</title><content type='html'>A "cyber cold war" waged over the world's computers threatens to become one of the biggest threats to security in the next decade, according to a report published on Thursday.&lt;br /&gt;&lt;br /&gt;About 120 countries are developing ways to use the internet as a weapon to target financial markets, government computer systems and utilities, internet security company McAfee said in an annual report. &gt;&gt; &lt;a href="http://news.zdnet.co.uk/security/0,1000000189,39291156,00.htm"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In yet another article titled "US warned of 'aggressive' Chinese cyberspying,  it was mentioned that &lt;em&gt;Chinese espionage poses "the single greatest risk" to US technology, a congressional advisory panel said on Thursday. The panel also called for efforts to protect industrial secrets and computer networks. &gt;&gt;&lt;/em&gt; &lt;a href="http://news.zdnet.co.uk/security/0,1000000189,39290843,00.htm?r=162"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6702129193924282050?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.zdnet.co.uk/security/0,1000000189,39291156,00.htm' title='World on Brink of Cyber Cold War'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6702129193924282050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6702129193924282050' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6702129193924282050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6702129193924282050'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/12/world-on-brink-of-cyber-cold-war.html' title='World on Brink of Cyber Cold War'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7951564032752635492</id><published>2007-11-20T07:07:00.000+08:00</published><updated>2007-11-20T07:19:32.096+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='Indigeneous'/><category scheme='http://www.blogger.com/atom/ns#' term='Back Door'/><category scheme='http://www.blogger.com/atom/ns#' term='Crypto'/><title type='text'>Did NSA Put a Secret Backdoor in New Encryption Standard?</title><content type='html'>In a recent article, Bruce Schneier, a renowned expert on cryptology and security highlighted that a new random-number standard (for encryption) includes an algorithm that is slow, badly designed and just might contain a backdoor for the US National Security Agency.&lt;br /&gt;&lt;br /&gt;The standard is found in &lt;a href="http://csrc.nist.gov/publications/nistpubs/800-90/SP800-90revised_March2007.pdf"&gt;NIST Special Publication 800-90&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The article may be quite technical but is enough to raise concerns that backdoors may exist in a puportedly secure software component.&lt;br /&gt;&lt;br /&gt;This leads to the conclusion and emphasis that it is imperative for nations to have their own indigeneous technologies inkey security areas in order to minimise exposure to shortcomings or backdoors that leave the system vulnerable to attacks or intrusions. &gt;&gt; &lt;a href="http://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115"&gt;More .. &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7951564032752635492?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115' title='Did NSA Put a Secret Backdoor in New Encryption Standard?'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7951564032752635492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7951564032752635492' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7951564032752635492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7951564032752635492'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/did-nsa-put-secret-backdoor-in-new.html' title='Did NSA Put a Secret Backdoor in New Encryption Standard?'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2429168479228533430</id><published>2007-11-19T05:22:00.000+08:00</published><updated>2007-11-19T05:24:09.817+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OS'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>2006 OS Vulnerability Summary</title><content type='html'>This report analyses and discuss about the OS Vulnerabilities. &gt;&gt; &lt;a href="http://www.omninerd.com/articles/2006_Operating_System_Vulnerability_Summary"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2429168479228533430?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.omninerd.com/articles/2006_Operating_System_Vulnerability_Summary' title='2006 OS Vulnerability Summary'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2429168479228533430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2429168479228533430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2429168479228533430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2429168479228533430'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/2006-os-vulnerability-summary.html' title='2006 OS Vulnerability Summary'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6550094787634659966</id><published>2007-11-14T07:28:00.001+08:00</published><updated>2007-11-18T11:47:44.020+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Compromised'/><title type='text'>Make No Assumptions. Security Begins With the Basics. YOU</title><content type='html'>There have been previous news about vendors releasing software with viruses, security vendor sites being compromised and similar incidents.&lt;br /&gt;&lt;br /&gt;The mishaps continue ...&lt;br /&gt;&lt;br /&gt;In a recent news article in Network World Asia titled "&lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=2424"&gt;Seagate ships virus-laden hard drives&lt;/a&gt;", it was reported that:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"If you bought one of Seagate's Maxtor Basics consumer hard drives recently, check it for viruses. Especially if you're a gamer.&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Seagate is warning that a "small number" of its Maxtor Basics Personal Storage 3200 hard drives recently shipped with the Virus.Win32.AutoRun.ah virus, malicious software that "searches for passwords for online games and sends them to a server located in China," according to a note posted on the Seagate Web site. Only drives purchased since August 2007 are affected, Seagate said."&lt;/em&gt; &gt;&gt; &lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=2424"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This time it is gaming software players who are the targets. Could it be anything else next time like bank accounts or access to corporate sites .... the possibility is so broad.&lt;br /&gt;&lt;br /&gt;In yet another article in Network World Asia titled "&lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=2426"&gt;Indian news site dispensing malware&lt;/a&gt;", it was mentioned that:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"The Web site of IndiaTimes, the online news site of the Times Group, one of India's large news and entertainment groups, exposed visitors to malware, according to an advisory Friday by ScanSafe Inc.&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ScanSafe first detected and blocked malware on the site on October 25. ScanSafe is still investigating the reach of this attack, but given the popularity of the site and the amount of malware involved, the company is urging caution, it said in its advisory Friday. Only certain pages of the Indiatimes.com are infected, the advisory added."&lt;/em&gt; &lt;a href="http://www.networksasia.net/article.php?type=article&amp;amp;id_article=2426"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The above news basically pass the message that all users should not make any assumptions about any hardware or software they acquire or install and any website that they access as the malware can be embedded in just about anywhere and in the most unlikely of all places.&lt;br /&gt;&lt;br /&gt;Hence defence against the consequences of such incidents requires users to be sufficiently aware, educated and acculturated about good computing practices including:&lt;br /&gt;&lt;br /&gt;1. Having good anti-malware protection that is installed and running&lt;br /&gt;2. Access to credible sites only and avoid strange or unusual sites&lt;br /&gt;3. Ensure that any devices plugged in especially the usb devices are scanned for viruses before use.&lt;br /&gt;4. Reminding peers about good computing practices.&lt;br /&gt;&lt;br /&gt;A good defence for both personal and organisational or corporate use begins with &lt;strong&gt;&lt;span style="color:#ff6666;"&gt;YOU&lt;/span&gt;&lt;/strong&gt;.&lt;br /&gt;It may be that through &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;your&lt;/strong&gt;&lt;/span&gt; simple negligence, the whole corporate network that you are using and critical systems can be affected.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6550094787634659966?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6550094787634659966/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6550094787634659966' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6550094787634659966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6550094787634659966'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/make-no-assumptions-security-begins.html' title='Make No Assumptions. Security Begins With the Basics. YOU'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-373371552229388517</id><published>2007-11-12T13:03:00.000+08:00</published><updated>2007-11-12T13:07:27.011+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malicious'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Backdoor'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure Programming'/><title type='text'>Pentagon: Our new robot army will be controlled by malware</title><content type='html'>This article emphasises the importance of developing indigeneous technologies rather than outsource the critical elements.&lt;br /&gt;&lt;br /&gt;A US defence department advisory board has warned of the danger that American war robots scheduled for delivery within a decade might be riddled with malicious code. The kill machines will use software largely written overseas, and it is feared that sinister forces might meddle with it in production, thus gaining control of the future mechanoid military.&lt;br /&gt;&lt;br /&gt;The most eye-catching of the equipment mentioned is the lineup of the US Army's Future Combat Systems (FCS) programme. FCS was originally supposed to include a wide range of deadly unmanned systems, including a small, possibly rocket-firing flying Dalek, a heavily armed autonomous helicopter gunship, and a robot tank packing guided missiles and cannon. There would also be intelligent sensor minefields, droid-mule transport systems and loads of other stuff; and all of it is supposed to be linked together by a data network. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2007/11/06/open_source_malware_future_combat_systems_robot_hack_war/"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-373371552229388517?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2007/11/06/open_source_malware_future_combat_systems_robot_hack_war/' title='Pentagon: Our new robot army will be controlled by malware'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/373371552229388517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=373371552229388517' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/373371552229388517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/373371552229388517'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/pentagon-our-new-robot-army-will-be.html' title='Pentagon: Our new robot army will be controlled by malware'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4301599653203478633</id><published>2007-11-12T12:55:00.000+08:00</published><updated>2007-11-12T13:01:10.580+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Air Defense'/><category scheme='http://www.blogger.com/atom/ns#' term='Radar'/><title type='text'>Israel suspected of 'hacking' Syrian air defences</title><content type='html'>Questions are mounting over how Israeli planes were able to sneak past Syria's defences and bomb a "strategic target" in the country in September 2007&lt;br /&gt;&lt;br /&gt;Israeli F-15s and F-16s bombed a military construction site on 6 September. Earlier reports of the attack were confirmed this week when Israeli Army radio said Israeli planes had attacked a military target "deep inside Syria", quoting the military censor.&lt;br /&gt;&lt;br /&gt;The motives for the strike, much less what was hit and what damage was caused, remain unclear. One theory is that a fledgling nuclear research centre, the fruits of alleged collaboration between Syria and North Korea, may have been hit. Others speculate that a store of arms shipments bound for the Lebanese militant group Hezbollah might have been targeted. A test against Syria's air defences has also being suggested in some quarters. None of these theories appear to be much better than educated guesswork.&lt;br /&gt;&lt;br /&gt;Bombers carrying out the raid are believed to have entered Syrian airspace from the Mediterranean Sea. Unmarked fuel drop tanks were later found on Turkish soil near the Syrian border, providing evidence of a possible escape route. Witnesses said the Israeli jets were engaged by Syrian air defences in Tall al-Abyad, near the border with Turkey.&lt;br /&gt;&lt;br /&gt;This location is deep within Turkey, prompting questions about how the fighters avoided detection until so long into their mission. Neither F-15s nor F-16s used by the Israeli air force in the raids are fitted with stealth technology. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2007/10/04/radar_hack_raid/"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4301599653203478633?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2007/10/04/radar_hack_raid/' title='Israel suspected of &apos;hacking&apos; Syrian air defences'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4301599653203478633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4301599653203478633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4301599653203478633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4301599653203478633'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/israel-suspected-of-hacking-syrian-air.html' title='Israel suspected of &apos;hacking&apos; Syrian air defences'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8320067835533744962</id><published>2007-11-12T12:51:00.000+08:00</published><updated>2007-11-12T12:53:31.704+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>Two charged with hacking PeopleSoft to fix grades</title><content type='html'>Two Cal State-Fresno students face up to 20 years in prison and fines up to $250,000 for hacking into the school's PeopleSoft system to change their grades. &gt;&gt; &lt;a href="http://www.infoworld.com/article/07/11/02/Two-charged-with-hacking-PeopleSoft-to-fix-grades_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/07/11/02/Two-charged-with-hacking-PeopleSoft-to-fix-grades_1.html"&gt;More..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8320067835533744962?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.infoworld.com/article/07/11/02/Two-charged-with-hacking-PeopleSoft-to-fix-grades_1.html?source=rss&amp;url=http://www.infoworld.com/article/07/11/02/Two-charged-with-hacking-PeopleSoft-to-fix-grades_1.html' title='Two charged with hacking PeopleSoft to fix grades'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8320067835533744962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8320067835533744962' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8320067835533744962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8320067835533744962'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/two-charged-with-hacking-peoplesoft-to.html' title='Two charged with hacking PeopleSoft to fix grades'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5146419243748401452</id><published>2007-11-12T12:44:00.000+08:00</published><updated>2007-11-12T12:47:11.388+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bank'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>US regional bank hacked</title><content type='html'>Hackers infiltrated the systems of Commerce Bank and accessed the records of 20 customers, the US regional bank said in October 2007.&lt;br /&gt;&lt;br /&gt;The attack by persons unknown was partially thwarted - but not before a database of 3,000 records was hacked into and the data of 20 exposed. Compromised data included personal information such as names, addresses, Social Security numbers, phone numbers and, in a few cases, Commerce Bank account numbers, the Columbia Business Journal reports&lt;br /&gt;&lt;br /&gt;Security staff shut down the attack and called in police to investigate after uncovering the breach a week ago. The FBI is investigating.&lt;br /&gt;&lt;br /&gt;The method used in the attack is unclear, and something the bank will be keen that it stays unclear, to avoid the possibility of copycat attacks. There are many avenues of assault, of which one common tactic is to exploit web application vulnerabilities by using SQL injection attacksto access information of back-end databases. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2007/10/11/commerce_bank_hack/"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5146419243748401452?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2007/10/11/commerce_bank_hack/' title='US regional bank hacked'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5146419243748401452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5146419243748401452' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5146419243748401452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5146419243748401452'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/us-regional-bank-hacked.html' title='US regional bank hacked'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7915932339215367598</id><published>2007-11-12T12:39:00.000+08:00</published><updated>2007-11-12T12:41:48.609+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Tests'/><category scheme='http://www.blogger.com/atom/ns#' term='Loopholes'/><title type='text'>Online trading site was left wide open</title><content type='html'>The conventional wisdom that banking organisations are more diligent with security was skewered in a presentation at the RSA conference this week.&lt;br /&gt;&lt;br /&gt;Security consultancy Comsec outlined how they discovered that an online stock trading website they were asked to test was riddled with security holes. A rush job meant that basic security measures, such as the use of a secure login, were absent from the multimillion dollar system. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2007/10/25/online_trading_pen_test/"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7915932339215367598?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2007/10/25/online_trading_pen_test/' title='Online trading site was left wide open'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7915932339215367598/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7915932339215367598' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7915932339215367598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7915932339215367598'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/online-trading-site-was-left-wide-open.html' title='Online trading site was left wide open'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5861845681200067550</id><published>2007-11-12T12:33:00.000+08:00</published><updated>2007-11-12T12:36:03.307+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Education'/><category scheme='http://www.blogger.com/atom/ns#' term='Awareness'/><title type='text'>More security education needed to avoid a cybersecurity disaster, experts warn</title><content type='html'>The United States is more prepared than ever for a major cybersecurity attack, but a panel of prominent security experts warned Tuesday that more needs to be done to increase awareness about cybersecurity issues and better educate future IT pros.&lt;br /&gt;&lt;br /&gt;"We need to provide resources for future problems," said Eugene Spafford, the executive director of Purdue University's Center for Education and Research in Information Assurance and Security (CERIAS). "Patching the latest problem isn't getting us anywhere."&lt;br /&gt;&lt;br /&gt;Spafford joined well known security experts Howard Schmidt, president and CEO of H&amp;amp;L Security Consulting and security luminary Bruce Schneier at the Information Security Decisions conference in Chicago for a discussion about cyber threats in 2008 and beyond. The panelists agreed that it would likely take a major cybersecurity event before the public becomes motivated enough to demand better security.&lt;br /&gt;&lt;br /&gt;The panelists agreed that growing backdoor Trojan horse programs and herds of bots continue to be a problem moving forward, but it's unclear if they'll by used by cybercriminals to take down the electronic infrastructure of entire nations or in isolated targeted incidents for financial gain. &gt;&gt; &lt;a href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1281145,00.html"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5861845681200067550?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1281145,00.html' title='More security education needed to avoid a cybersecurity disaster, experts warn'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5861845681200067550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5861845681200067550' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5861845681200067550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5861845681200067550'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/more-security-education-needed-to-avoid.html' title='More security education needed to avoid a cybersecurity disaster, experts warn'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5002431449835932494</id><published>2007-11-12T12:19:00.000+08:00</published><updated>2007-11-12T12:26:12.543+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Software'/><category scheme='http://www.blogger.com/atom/ns#' term='Certification'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure Programming'/><title type='text'>Secure Program Coding</title><content type='html'>It has often be questioned as to whether software developers are doing enough and knowledgable enough to code their applications with security in mind.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.darkreading.com/document.asp?doc_id=138262&amp;amp;f_src=drweekly"&gt;This article &lt;/a&gt;discusses this issue.&lt;br /&gt;&lt;br /&gt;A new certification called the GIAC Secure Software Programmer (GSSP) program, teaches programmers how to write secure code. This can be taught or incorporated in the software curriculum in institutions of higher learning so that software developers can graduate ready with secure software development in mind. &gt;&gt; &lt;a href="http://www.darkreading.com/document.asp?doc_id=120550"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5002431449835932494?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/document.asp?doc_id=138262&amp;f_src=drweekly' title='Secure Program Coding'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5002431449835932494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5002431449835932494' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5002431449835932494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5002431449835932494'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/secure-program-coding.html' title='Secure Program Coding'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3914238868134241531</id><published>2007-11-11T18:40:00.001+08:00</published><updated>2007-11-11T18:48:32.797+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><title type='text'>Website for Computer Security Experts Hacked</title><content type='html'>It can happen to anybody's website, including a security website..&lt;br /&gt;&lt;br /&gt;First Forensic Forum - a UK based association of computer security professionals - has been hacked.&lt;br /&gt;&lt;br /&gt;F3.org's website was defaced with a message poking fun at the association of computer forensic experts. The timing of the defacement on Thursday was fortuitous (or well planned) since the organisation is coming to the end of a two day conference.&lt;br /&gt;document.&lt;br /&gt;&lt;br /&gt;The perpetrator of the attack posted a message taunting the organisation. "The F3 For Security Hacked. What's Happened In The world. Thay Are No Security Or What," S4udi-S3curity-T3rror writes. &gt;&gt; &lt;a href="http://www.theregister.co.uk/2007/11/08/forensic_forum_hack/"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3914238868134241531?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2007/11/08/forensic_forum_hack/' title='Website for Computer Security Experts Hacked'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3914238868134241531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3914238868134241531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3914238868134241531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3914238868134241531'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/website-for-computer-security-experts.html' title='Website for Computer Security Experts Hacked'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3913735759624448243</id><published>2007-11-11T18:30:00.000+08:00</published><updated>2007-11-11T18:34:43.980+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Task Force'/><category scheme='http://www.blogger.com/atom/ns#' term='USA'/><category scheme='http://www.blogger.com/atom/ns#' term='Plans'/><category scheme='http://www.blogger.com/atom/ns#' term='Critical Infrastructure'/><title type='text'>Task Force Aims to improve US Cybersecurity</title><content type='html'>A blue-ribbon panel of three dozen security experts hopes to craft a strategy to improve the United States' cybersecurity by the time the next president takes office, the Center for Strategic and International Studies (CSIS), and the task force's Congressional sponsors, announced on Tuesday.&lt;br /&gt;&lt;br /&gt; The bipartisan Commission on Cyber Security for the 44th Presidency will be tasked with creating a plan to secure the nation's computers and critical infrastructure and presenting that plan to the next president. &gt;&gt; &lt;a href="http://www.securityfocus.com/news/11494?ref=rss"&gt;More ...&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3913735759624448243?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securityfocus.com/news/11494?ref=rss' title='Task Force Aims to improve US Cybersecurity'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3913735759624448243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3913735759624448243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3913735759624448243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3913735759624448243'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/task-force-aims-to-improve-us.html' title='Task Force Aims to improve US Cybersecurity'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-1291074927033819614</id><published>2007-11-03T07:39:00.000+08:00</published><updated>2007-11-03T07:54:22.443+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Companies'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Breach'/><title type='text'>Security Companies also Vulnerable to Attacks</title><content type='html'>Nobody is perfect and no company is perfect. But all try their best to protect themselves from attacks. The lesson learnt as always, is that security is an ongoing process and not a destination. And the process has to be alert to both internal measures that has to be diligently kept updated as well as to be aware of new threats and attack vectors.&lt;br /&gt;&lt;br /&gt;The following &lt;a href="http://attrition.org/errata/irony.html"&gt;link&lt;/a&gt; provides a list of security companies and organisations including CERTS whose web presence have been compromised in one way or another. There are other interesting information as well. &lt;a href="http://attrition.org/errata/irony.html"&gt;Read on ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-1291074927033819614?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://attrition.org/errata/irony.html' title='Security Companies also Vulnerable to Attacks'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/1291074927033819614/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=1291074927033819614' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1291074927033819614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/1291074927033819614'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/11/security-companies-also-vulnerable-to.html' title='Security Companies also Vulnerable to Attacks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7987546764941889475</id><published>2007-10-24T03:29:00.000+08:00</published><updated>2007-10-24T03:33:06.281+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CNII'/><category scheme='http://www.blogger.com/atom/ns#' term='Legal'/><category scheme='http://www.blogger.com/atom/ns#' term='Strategy'/><title type='text'>Open Group Security Forum and ABA’s Cyberspace Law Committee issue whitepaper on information-centric security governance</title><content type='html'>&lt;span&gt;&lt;p&gt;The Open Group, a vendor- and technology-neutral consortium focused on open standards and global interoperability within and between enterprises, today announced the general availability of a new whitepaper about information security strategy. Co-written by The Open Group Security Forum and the American Bar Association’s Cyberspace Law Committee, the whitepaper presents a strategic framework for information-centric security governance. Additionally, the paper offers a methodology for security compliance both within and beyond the perimeter of the enterprise, and recommends further standards to support information security in a boundary-less environment. &lt;/p&gt;&lt;p&gt;Previously, securing ownership of proprietary information security was accomplished mainly through securing a physical ‘perimeter’ via network hardware and software technologies. The new realities of information access and use, based now on distributed relationships within and between enterprises that use a mix of proprietary and non proprietary information, require securing information and infrastructure access and flows beyond the perimeter. This new paradigm requires dynamic interaction of technologists, legal advisors, and business policy makers alike. The whitepaper is available for free download &lt;a href="http://www.opengroup.org/bookstore/catalog/w075.htm"&gt;here.&lt;/a&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7987546764941889475?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.opengroup.org/bookstore/catalog/w075.htm' title='Open Group Security Forum and ABA’s Cyberspace Law Committee issue whitepaper on information-centric security governance'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7987546764941889475/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7987546764941889475' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7987546764941889475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7987546764941889475'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/open-group-security-forum-and-abas.html' title='Open Group Security Forum and ABA’s Cyberspace Law Committee issue whitepaper on information-centric security governance'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2212811414337896554</id><published>2007-10-17T03:26:00.000+08:00</published><updated>2007-10-17T03:34:02.301+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Espionage'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Tests'/><category scheme='http://www.blogger.com/atom/ns#' term='Power Grid'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>How To Take Down The Power Grid</title><content type='html'>Ira Wrinkler, who performs espionage or terrorist simulations  (or mundanely known as penetration tests) wrote:&lt;br /&gt;&lt;br /&gt;&lt;span class="bigsmalltallline"&gt;"The first time I broke into our country’s electrical power grid was a decade or so ago. Hacking into the control systems set up by utility companies wasn’t surprising then, and it isn’t surprising now. While people find this shocking, it really isn’t. When you think about how insecure computer infrastructures are, why would you think that the power grid would be any more secure? Frankly, &lt;span style="font-weight: bold;"&gt;the power grid is even less secure than most other computer networks&lt;/span&gt;. I wrote about it many times, including some details in my recent book, &lt;em&gt;&lt;a href="http://www.irawinkler.com/" target="_blank"&gt;Spies Among Us&lt;/a&gt;&lt;/em&gt;.&lt;/span&gt;" &gt;&gt; &lt;a href="http://www.internetevolution.com/author.asp?doc_id=136047&amp;amp;f_src=drnewsalert"&gt;More ..&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Text in bold are my emphasis.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2212811414337896554?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.internetevolution.com/author.asp?doc_id=136047&amp;f_src=drnewsalert' title='How To Take Down The Power Grid'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2212811414337896554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2212811414337896554' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2212811414337896554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2212811414337896554'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/how-to-take-down-power-grid.html' title='How To Take Down The Power Grid'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6845401033610607991</id><published>2007-10-16T11:33:00.000+08:00</published><updated>2007-10-16T11:41:29.024+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Strategy'/><category scheme='http://www.blogger.com/atom/ns#' term='Homeland Security'/><title type='text'>US National Strategy for Homeland Security - October 2007</title><content type='html'>The US has released the latest document on the National Strategy for Homeland Security this month which has added emphasis on cyber security.  The document can be found &lt;a href="http://www.whitehouse.gov/infocus/homeland/nshs/2007/index.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;A quote from the sidebar of that document is as follows:&lt;br /&gt;&lt;br /&gt;"Cyber Security: A Special Consideration&lt;br /&gt;&lt;br /&gt;Many of the Nation’s essential and emergency&lt;br /&gt;services, as well as our critical infrastructure, rely&lt;br /&gt;on the uninterrupted use of the Internet and the&lt;br /&gt;communications systems, data, monitoring, and&lt;br /&gt;control systems that comprise our cyber infra-&lt;br /&gt;structure.  A cyber attack could be debilitating to&lt;br /&gt;our highly interdependent CI/KR and ultimately to&lt;br /&gt;our economy and national security.  &lt;br /&gt;&lt;br /&gt;A variety of actors threaten the security of our&lt;br /&gt;cyber infrastructure.  Terrorists increasingly exploit&lt;br /&gt;the Internet to communicate, proselytize, recruit,&lt;br /&gt;raise funds, and conduct training and operational&lt;br /&gt;planning.  Hostile foreign governments have the&lt;br /&gt;technical and financial resources to support&lt;br /&gt;advanced network exploitation and launch attacks&lt;br /&gt;on the informational and physical elements of our&lt;br /&gt;cyber infrastructure.  Criminal hackers threaten&lt;br /&gt;our Nation’s economy and the personal informa-&lt;br /&gt;tion of our citizens, and they also could pose a&lt;br /&gt;threat if wittingly or unwittingly recruited by foreign&lt;br /&gt;intelligence or terrorist groups.  Our cyber net-&lt;br /&gt;works also remain vulnerable to natural disasters. &lt;br /&gt;&lt;br /&gt;In order to secure our cyber infrastructure against&lt;br /&gt;these man-made and natural threats, our Federal,&lt;br /&gt;State, and local governments, along with the pri-&lt;br /&gt;vate sector, are working together to prevent dam-&lt;br /&gt;age to, and the unauthorized use and exploitation&lt;br /&gt;of, our cyber systems.  We also are enhancing our&lt;br /&gt;ability and procedures to respond in the event of&lt;br /&gt;an attack or major cyber incident.  The National&lt;br /&gt;Strategy to Secure Cyberspace and the NIPP’s&lt;br /&gt;Cross-Sector Cyber Security plan are guiding our&lt;br /&gt;efforts. "&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6845401033610607991?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.whitehouse.gov/infocus/homeland/nshs/2007/index.html' title='US National Strategy for Homeland Security - October 2007'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6845401033610607991/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6845401033610607991' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6845401033610607991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6845401033610607991'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/us-national-strategy-for-homeland.html' title='US National Strategy for Homeland Security - October 2007'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5269196987346399730</id><published>2007-10-15T17:43:00.000+08:00</published><updated>2007-10-15T17:50:32.552+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OPC'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Hole Found in Protocol Handling Vital National Infrastructure</title><content type='html'>&lt;span id="intelliTXT"&gt; Researchers on March 21 announced that the systems which control dams, oil refineries, railroads and nuclear power plants have a vulnerability that could be used to cause a denial of service or a system takeover.&lt;br /&gt;&lt;br /&gt;       &lt;!-- Third block : GS--&gt;           The flaw, reported by Neutralbit , is the first remotely exploitable SCADA security vulnerability, according to the security services provider.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span id="intelliTXT"&gt;Neutralbit identified the vulnerability in NETxAutomation NETxEIB OPC (OLE for Process Control) Server. OPC is a Microsoft Windows standard for easily writing GUI applications for SCADA. It's used for interconnecting process control applications running on Microsoft platforms. OPC servers are often used in control systems to consolidate field and network device information.  &lt;a href="http://www.physorg.com/news94025004.html"&gt;&gt;&gt; More&lt;/a&gt; ..&lt;br /&gt;&lt;br /&gt;Those who want more technical details on the vulnerabilities can find them &lt;a href="http://www.neutralbit.com/en/rd/advisories/#NB07-07"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5269196987346399730?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.physorg.com/news94025004.html' title='Hole Found in Protocol Handling Vital National Infrastructure'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5269196987346399730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5269196987346399730' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5269196987346399730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5269196987346399730'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/hole-found-in-protocol-handling-vital.html' title='Hole Found in Protocol Handling Vital National Infrastructure'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-99437576935256978</id><published>2007-10-15T15:31:00.000+08:00</published><updated>2007-10-15T16:02:13.713+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Physical Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Airport'/><title type='text'>Serious Security Breach in KLIA</title><content type='html'>The New Straits Times today reported in a news article titled &lt;a href="http://www.nst.com.my/Current_News/NST/Monday/Frontpage/2059785/Article/index_html"&gt;"Red faces over  'phantom'  stowaway"&lt;/a&gt;  that KLIA had a security breach on Thursday 11 Oct 2007 when a man managed to stow away inside the front nose wheel chamber aboard a Singapore Airlines flight from KL to Singapore. The &lt;a href="http://www.nst.com.my/Current_News/NST/Monday/Columns/2060116/Article/index_html"&gt;editorial&lt;/a&gt; discussed the matter in a bit more detail.&lt;br /&gt;&lt;br /&gt;What was even more interesting is that the stowaway did not turn up on any CCTV recordings in KLIA.&lt;br /&gt;&lt;br /&gt;So what has this got to do with CIIP? Well the transportation sector is one of the Critical National Information Infrastructure. Physical security is about the most visible of all security measures that anybody can enforce and where there would usually be traceability.  If an entity is not able to handle physical security well and is unable to trace back how it happened from their own records, its left to the imagination as to what can happen if cyber breaches of the KLIA systems does occur, since comparatively, cyber intrusions and breaches are harder to detect.&lt;br /&gt;&lt;br /&gt;We are not drawing any conclusions but the incident does raise some fundamental questions about the overall security and surveillance measures in such an  important  infrastructure entity, be it physical security or cyber security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-99437576935256978?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.nst.com.my/Current_News/NST/Monday/Frontpage/2059785/Article/index_html' title='Serious Security Breach in KLIA'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/99437576935256978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=99437576935256978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/99437576935256978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/99437576935256978'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/klia-serious-airport-security-breach.html' title='Serious Security Breach in KLIA'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3556723848167328166</id><published>2007-10-12T21:36:00.000+08:00</published><updated>2007-10-12T21:41:28.593+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='Compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='Power Grid'/><category scheme='http://www.blogger.com/atom/ns#' term='Power Systems'/><title type='text'>Cyber Security Standards for Electric Power Systems</title><content type='html'>&lt;p&gt;The &lt;b&gt;North American Reliability Corporation&lt;/b&gt; or NERC has produced standards for Cyber Security for the power systems industry. Further details can be found &lt;a href="http://www.nerc.com/cip.html"&gt;here&lt;/a&gt; but a summary is described below. The standards are part of a full set of Reliability Standards including Emergency Preparedness and Operations and the full list of standards is listed and can be downloaded &lt;a href="http://www.nerc.com/%7Efilez/standards/Reliability_Standards.html#Critical_Infrastructure_Protection"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;NERC Cyber Security &lt;/strong&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt; &lt;br /&gt;&lt;p&gt;The purpose of NERC's new cyber security standards is to ensure that all entities responsible for the reliability of the bulk electric systems of &lt;st1:place st="on"&gt;North America&lt;/st1:place&gt; identify and protect critical cyber assets that control or could impact the reliability of the bulk electric systems. An urgent action cyber security standard was initially adopted in August 2003 and renewed for a second year in August 2004. NERC adopted permanent cyber security standards on May 2, 2006. &lt;b&gt;&lt;i&gt;&lt;span style="color:red;"&gt;On June 4, 2007 compliance with approved NERC Reliability Standards becomes mandatory and enforceable in the &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;United   States&lt;/st1:place&gt;&lt;/st1:country-region&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="titletext"&gt;&lt;strong&gt;NERC CIP-002 to CIP-009 &lt;/strong&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;NERC's new cyber security standard was originally called NERC 1300, but this has changed to 8 separate standards, &lt;strong&gt;CIP-002 to CIP-009. &lt;/strong&gt;As summarized in the table below, these standards contain definitions, policies, reporting requirements, and issues related to personnel security, electronics (or network) security, and physical security (such as access). &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;div align="center"&gt;  &lt;table class="MsoNormalTable" style="width: 425px; height: 202px;" border="1" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style="" border="" bg=""&gt;   &lt;td style="padding: 0.75pt; width: 100.35pt;" width="134"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;span style="color: rgb(228, 18, 0);"&gt;New Std #&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; width: 290.45pt;" width="387"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;&lt;strong&gt;&lt;span style="color: rgb(228, 18, 0);"&gt;Topic&lt;/span&gt;&lt;/strong&gt;&lt;span style="color: rgb(228, 18, 0);"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-002-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal"&gt;Critical Cyber Assets&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-003-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal"&gt;Security Management Controls&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-004-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal"&gt;Personnel and Training&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-005-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal"&gt;Electronic Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-006-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt;"&gt;   &lt;p class="MsoNormal"&gt;Physical Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-007-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal"&gt;Systems Security Management&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt; background: white none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-008-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; background: white none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal"&gt;Incident Reporting and Response Planning&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="" bordercolor="#999999"&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal" style="text-align: center;" align="center"&gt;CIP-009-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="padding: 0.75pt; background: rgb(224, 223, 227) none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;   &lt;p class="MsoNormal"&gt;Recovery Plans&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;  &lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;&lt;a href="http://www.ruggedcom.com/applications/nerc_cyber_security/#Top"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3556723848167328166?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.nerc.com/cip.html' title='Cyber Security Standards for Electric Power Systems'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3556723848167328166/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3556723848167328166' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3556723848167328166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3556723848167328166'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/cyber-security-standards-for-electric_12.html' title='Cyber Security Standards for Electric Power Systems'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3191139334000955921</id><published>2007-10-12T20:43:00.000+08:00</published><updated>2007-10-12T20:45:16.726+08:00</updated><title type='text'>Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks' Data</title><content type='html'>SecureWorks, one of the industry’s leading managed security services providers protecting over 1,800 clients and 100 utilities, has seen a 90 percent increase in the number of hackers attempting to attack its utility clients this year. From January through April, SecureWorks blocked an average of 49 attackers per utility client per day. Whereas, from May through September, it saw an average of 93 hackers attempt attacks on each of its utility clients per day. &lt;p&gt;“When researching these new statistics, we found that Web Browser attacks represented a large number of the attacks attempted against our clients, including our utility customers,” said Wayne Haber, director of development at SecureWorks.&lt;/p&gt; &lt;p&gt;Computer users can become victims of browser attacks by visiting Web sites, which unbeknownst to them is hosting malware, or by clicking on a malicious link in an email or instant message. &lt;a href="http://www.secureworks.com/media/press_releases/20071005-utilitiesincrease"&gt;&gt;&gt;More..&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3191139334000955921?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.secureworks.com/media/press_releases/20071005-utilitiesincrease' title='Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks&apos; Data'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3191139334000955921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3191139334000955921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3191139334000955921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3191139334000955921'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/number-of-hackers-targeting-utilities.html' title='Number of Hackers Targeting Utilities Increases 90 Percent According to SecureWorks&apos; Data'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-7206701196643049298</id><published>2007-10-12T07:10:00.000+08:00</published><updated>2007-10-12T07:25:53.881+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ISP'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Statistics'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><title type='text'>How to Trace a DDOS Attack</title><content type='html'>&lt;span&gt;&lt;span&gt;DDOS attacks can cripple an organization's website or portal.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;ISPs consider DDOS attacks -- where an attacker floods network connections, Websites, or systems with packets -- one of their biggest threats. Most of these attacks are being waged by botnets -- some as large as tens of thousands of bot machines, according to a recent survey of ISPs by Arbor Networks. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;Arbor found an average of 1,200 DDOS attacks each day across 38 ISP networks. On 220 of the last 365 days, there has been at least one DDOS attack of one million packets per second, says Danny McPherson, chief research officer for Arbor Networks.&lt;br /&gt;&lt;br /&gt;What is more alarming is that &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;despite reports that some ISPs have experienced fewer DDOS attacks overall during the last six months, there is a DDOS attack underway somewhere on the Internet.  It's a matter of quality, not quantity: "When DDOSes do occur, they are done with much greater purpose than they used to be".&lt;br /&gt;&lt;br /&gt;Read the full article &lt;a href="http://www.darkreading.com/document.asp?doc_id=135457"&gt;here&lt;/a&gt; which includes the tracing indicators and steps to stop the DDOS attacks. It is not that easy though as it involves investigative work by the ISP and worldwide cooperation among ISPs.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-7206701196643049298?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/document.asp?doc_id=135457' title='How to Trace a DDOS Attack'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/7206701196643049298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=7206701196643049298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7206701196643049298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/7206701196643049298'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/how-to-trace-ddos-attack.html' title='How to Trace a DDOS Attack'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3126500999457398920</id><published>2007-10-12T04:20:00.000+08:00</published><updated>2007-10-12T04:29:42.960+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><category scheme='http://www.blogger.com/atom/ns#' term='Hijack'/><category scheme='http://www.blogger.com/atom/ns#' term='Screw Up'/><title type='text'>Ooops: DC Feds Delete CA.Gov In Response to Hackers</title><content type='html'>When an organisation does not have a proper response plan to incidents, a bad incident can get worse.&lt;br /&gt;&lt;br /&gt;"Case in point: A hacker's diversion of traffic from a California county government Web site to a porn purveyor spiraled into IT chaos yesterday after a countermeasure applied from Washington essentially "deleted the ca.gov domain."&lt;br /&gt;&lt;br /&gt;The original story can be found &lt;a href="http://www.networkworld.com/community/node/20192"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3126500999457398920?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.nowpublic.com/life/ooops-dc-feds-delete-ca-gov-response-hackers' title='Ooops: DC Feds Delete CA.Gov In Response to Hackers'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3126500999457398920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3126500999457398920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3126500999457398920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3126500999457398920'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/ooops-dc-feds-delete-cagov-in-response.html' title='Ooops: DC Feds Delete CA.Gov In Response to Hackers'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8639059534865917527</id><published>2007-10-12T01:02:00.000+08:00</published><updated>2007-10-12T01:13:10.356+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Certification'/><title type='text'>OWASP Preps Framework for Website Security Certification</title><content type='html'>&lt;span&gt;&lt;p&gt; &lt;span&gt;The Open Web Application Security Project (OWASP) is working on a potential framework for evaluating and certifying Websites as secure, including the criteria that would entail. The project is still in progress and not quite ready for prime time, but the goal is to provide a framework for certifying the security of a site's apps, which entails much more than just the usual vulnerability scan.&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;"A black box scan doesn't mean a site is secure," says Dinis Cruz, OWASP's technology evangelist and project coordinator for the so-called &lt;a href="http://www.owasp.org/index.php/SpoC_007_-_The_OWASP_Web_Security_Certification_Framework" target="new"&gt;Web Security Application Certification Framework Project&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span&gt;Several commercial certifications already exist, including ScanAlert's Hacker Safe, and ControlScan, which indicate that a site has been vulnerability-scanned. And the Extended Validation SSL (EV SSL) moniker, championed by digital certificate vendors such as VeriSign and Cybertrust, helps verify that a site is legitimate. (See &lt;a href="http://www.darkreading.com/document.asp?doc_id=116862" target="new"&gt;Are 'Sealed' Websites Any Safer?&lt;/a&gt;).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;span&gt;But security experts say today's Good Housekeeping-style seal-of-approvals aren't enough. "The fact is that in this day and age, the VeriSign logo and the lock icon in your browser just don't cut it," says Caleb Sima, CTO of SPI Dynamics. &lt;a href="http://www.darkreading.com/document.asp?doc_id=135797&amp;amp;f_src=drdaily"&gt;&gt;&gt; More ..&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8639059534865917527?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.darkreading.com/document.asp?doc_id=135797&amp;f_src=drdaily' title='OWASP Preps Framework for Website Security Certification'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8639059534865917527/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8639059534865917527' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8639059534865917527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8639059534865917527'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/owasp-preps-framework-for-website.html' title='OWASP Preps Framework for Website Security Certification'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8111845772227796470</id><published>2007-10-11T15:22:00.000+08:00</published><updated>2007-10-11T15:26:56.255+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CNII'/><category scheme='http://www.blogger.com/atom/ns#' term='Policy'/><category scheme='http://www.blogger.com/atom/ns#' term='Government'/><category scheme='http://www.blogger.com/atom/ns#' term='Australia'/><title type='text'>Australia's Critical Infrastructure Protection</title><content type='html'>Information on Australia's Critical Infrastructure Protection issues and initiatives can be found &lt;a href="http://www.tisn.gov.au/agd/WWW/tisnhome.nsf/AllDocs/6CDEB795D882C902CA25717000240E3C?OpenDocument"&gt;here&lt;/a&gt;. This of course includes Critical Information Infrastructure.&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://www.tisn.gov.au/agd/WWW/attorneygeneralHome.nsf/Page/Media_Releases_1999_August_Protecting_Australia&amp;apos;s_Information_Infrastructure" target="_blank" rwp_href_backup="/agd/WWW/attorneygeneralHome.nsf/Page/Media_Releases_1999_August_Protecting_Australia&amp;apos;s_Information_Infrastructure"&gt;here&lt;/a&gt; to view the then Attorney-General’s press announcement on protecting the National Information Infrastructure&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8111845772227796470?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.tisn.gov.au/agd/WWW/tisnhome.nsf/AllDocs/6CDEB795D882C902CA25717000240E3C?OpenDocument' title='Australia&apos;s Critical Infrastructure Protection'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8111845772227796470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8111845772227796470' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8111845772227796470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8111845772227796470'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/australias-critical-infrastructure.html' title='Australia&apos;s Critical Infrastructure Protection'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-2262418353145314376</id><published>2007-10-09T11:46:00.000+08:00</published><updated>2007-10-09T11:56:51.061+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><category scheme='http://www.blogger.com/atom/ns#' term='Guide'/><title type='text'>NIST Guide to Industrial Control Systems Security (SCADA)</title><content type='html'>The second draft of the above document which deals with security for Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS) and Programmable Logic Controllers (PLC) has been released for public comment on 28 Sep 2007.&lt;br /&gt;&lt;br /&gt;The draft can be downloaded &lt;a href="http://csrc.nist.gov/publications/drafts/800-82/2nd-Draft-SP800-82-clean.pdf.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The document is 157 pages and information on what other organisations are doing in this area can be found in Appendix C of the document. This Appendix C provides useful information to those who are doing further research or comparative studies or implementation alternatives on SCADA security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-2262418353145314376?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://csrc.nist.gov/publications/drafts/800-82/2nd-Draft-SP800-82-clean.pdf.zip' title='NIST Guide to Industrial Control Systems Security (SCADA)'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/2262418353145314376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=2262418353145314376' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2262418353145314376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/2262418353145314376'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/nist-guide-to-industrial-control.html' title='NIST Guide to Industrial Control Systems Security (SCADA)'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6539736586476052998</id><published>2007-10-09T10:36:00.000+08:00</published><updated>2007-10-09T11:43:33.021+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='Guidelines'/><category scheme='http://www.blogger.com/atom/ns#' term='Publications'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>NIST Publications on ICT Security</title><content type='html'>The USA Department of Commerce's National Institute of Standards and Technology or NIST produces various standards and guidelines documents on ICT implementation and ICT Security.&lt;br /&gt;&lt;br /&gt;The list of documents on ICT Security can be found and downloaded &lt;a href="http://csrc.nist.gov/publications/PubsSPs.html"&gt;here&lt;/a&gt; but a more general introduction page on the publications category types is &lt;a href="http://csrc.nist.gov/publications/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The list is summarized also in the following documents which should be useful as a big picture reference:&lt;br /&gt;1. &lt;a href="http://csrc.nist.gov/publications/CSD_DocsGuide.pdf"&gt;Guide to NIST Information Security Documents&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://csrc.nist.gov/publications/CSD_DocsGuide_Trifold.pdf"&gt;Roadmap to NIST Information Security Documents&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;There are hundreds of documents in the whole set and a selection of the relevant topic clusters is listed below (each topic cluster has a list of relevant documents):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Audit &amp;amp; Accountability&lt;br /&gt;Authentication&lt;br /&gt;Awareness &amp;amp; Training&lt;br /&gt;Certification &amp;amp; Accreditation (C&amp;amp;A)&lt;br /&gt;Communications &amp;amp; Wireless&lt;br /&gt;Contingency Planning&lt;br /&gt;General IT Security&lt;br /&gt;Incident Response&lt;br /&gt;Maintenance&lt;br /&gt;Planning&lt;br /&gt;Risk Assessment &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Viruses &amp;amp; Malware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;On the topic of Critical Infrastructure Protection, the documents relevant to the &lt;a href="http://www.faa.gov/about/office_org/headquarters_offices/aio/documents/media/152644_HSPD-7.pdf"&gt;Homeland Security Presidential Directive-7 (HSPD-7), Critical Infrastructure Identification, Prioritization, and Protection&lt;/a&gt; are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;FIPS 199 Standards for Security Categorization of Federal Information and Information Systems&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;FIPS 200 Security Controls for Federal Information Systems &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-18 Guide for Developing Security Plans for Information Technology Systems &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-30 Risk Management Guide for Information Technology Systems &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-37 Guide for Security Certiication and Accreditation of Federal Information Systems &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-53 Recommended Security Controls for Federal Information Systems &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-59 Guideline for Identifying an Information System as a National Security System&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;SP 800-82 Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control System Security&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6539736586476052998?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://csrc.nist.gov/publications/PubsSPs.html' title='NIST Publications on ICT Security'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6539736586476052998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6539736586476052998' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6539736586476052998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6539736586476052998'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/nist-publications-on-ict-security.html' title='NIST Publications on ICT Security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-8970675754200779855</id><published>2007-10-08T22:20:00.000+08:00</published><updated>2007-10-08T22:29:40.105+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='Process Control'/><category scheme='http://www.blogger.com/atom/ns#' term='Common Criteria'/><title type='text'>New security standards to strengthen SCADA</title><content type='html'>This 2004 Computerworld article says that "The security of critical-infrastructure processes, long festering as a thorny issue in securing everything from food and water to energy and transportation, will be getting a boost from proposed standards for industrial controls. The National Institute of Standards and Technology (NIST) fostered the creation of the Process Control Security Requirements Forum in 2001. The group issued the first draft of its &lt;a href="http://www.isd.mel.nist.gov/projects/processcontrol/SPP-ICSv1.0.doc" target="NEW"&gt;System Protection Profile for Industrial Control Systems &lt;/a&gt;(SPP ICS) in October." &lt;a href="http://www.computerworld.com/securitytopics/security/story/0,10801,97606,00.html"&gt;&gt;More... &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-8970675754200779855?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.computerworld.com/securitytopics/security/story/0,10801,97606,00.html' title='New security standards to strengthen SCADA'/><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/8970675754200779855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=8970675754200779855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8970675754200779855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/8970675754200779855'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/new-security-standards-to-strengthen.html' title='New security standards to strengthen SCADA'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-5137666727073686321</id><published>2007-10-07T17:03:00.000+08:00</published><updated>2007-10-07T17:05:36.178+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Acculturation'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='Education'/><title type='text'>Knowledge is Greatest Threat to Critical Infrastructure</title><content type='html'>Australia's critical infrastructure is still under threat due to a shortage of educational resources, according to researchers and security experts.&lt;br /&gt;&lt;br /&gt;The major concern is security of Supervisory Control and Data Acquisition (SCADA) systems -- the central nervous system for sensors, alarms and switches that provide automated control and monitoring functions for utilities such as water, gas and electricity, as well as large manufacturers. &lt;a href="http://www.zdnet.com.au/news/security/soa/Knowledge-is-greatest-threat-to-critical-infrastructure/0,130061744,339281010,00.htm"&gt;More ..&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-5137666727073686321?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/5137666727073686321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=5137666727073686321' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5137666727073686321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/5137666727073686321'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/knowledge-is-greatest-threat-to.html' title='Knowledge is Greatest Threat to Critical Infrastructure'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-286229863775670493</id><published>2007-10-07T16:14:00.000+08:00</published><updated>2007-10-07T16:19:24.057+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='Manufacturing'/><category scheme='http://www.blogger.com/atom/ns#' term='Automation'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>ISA99 cyber security guidelines provide full user resources</title><content type='html'>Manufacturers concerned about cyber security as it relates to plant equipment and factory automation systems should look at the new ‘ISA-99 Security Guidelines and User Resources for Industrial Automation and Control Systems’ CD-ROM.&lt;br /&gt;&lt;br /&gt;There are two technical reports: ANSI/ISA-TR99.00.01-2004, ‘Security Technologies for Manufacturing and Control Systems’, and ANSI/ISA-TR99.00.02-2004, ‘Integrating Electronic Security into the Manufacturing and Control Systems Environment’.&lt;br /&gt;&lt;br /&gt;The former provides an evaluation and assessment of current types of electronic security technologies and tools that apply to the manufacturing and control systems environment, including development, implementation, operations and maintenance.&lt;br /&gt;&lt;br /&gt;The latter provides a framework for developing an electronic security programme and provides a recommended organisation and structure for the security plan. The information provides detailed information about the minimum elements to include. &lt;br /&gt;&lt;br /&gt;The original article can be found &lt;a href="http://www.mcsolutions.co.uk/article/8368/ISA99-cyber-security-guidelines-provide-full-user-resources-.aspx"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-286229863775670493?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/286229863775670493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=286229863775670493' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/286229863775670493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/286229863775670493'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/isa99-cyber-security-guidelines-provide.html' title='ISA99 cyber security guidelines provide full user resources'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-3043972770346110373</id><published>2007-10-07T16:11:00.000+08:00</published><updated>2007-10-12T01:11:39.869+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Hackers Step Up SCADA Attacks</title><content type='html'>This 2004 article says that "A majority of cyber attacks on industrial control systems now come from the outside, reversing earlier assumptions, according to research at the British Columbia Institute of Technology."&lt;br /&gt;&lt;br /&gt;The full article can be found &lt;a href="http://www.automationworld.com/view-898"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-3043972770346110373?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/3043972770346110373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=3043972770346110373' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3043972770346110373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/3043972770346110373'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/hackers-step-up-scada-attacks.html' title='Hackers Step Up SCADA Attacks'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-6069602557290860090</id><published>2007-10-07T15:45:00.000+08:00</published><updated>2007-10-07T16:06:27.540+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><category scheme='http://www.blogger.com/atom/ns#' term='Manufacturing'/><category scheme='http://www.blogger.com/atom/ns#' term='Automation'/><category scheme='http://www.blogger.com/atom/ns#' term='Control Systems'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Power Grid'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><title type='text'>Control Systems, Instrumentation Systems and Automation Security</title><content type='html'>A number of articles relating to Control Systems, Instrumentation Systems and Automation security can be found from the Instrumentation Systems and Automation site &lt;a href="http://www.isa.org/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Amongst the relavant articles are:&lt;br /&gt;1. &lt;a href="http://www.isa.org/InTechTemplate.cfm?Section=Article_Index1&amp;amp;template=/ContentManagement/ContentDisplay.cfm&amp;amp;ContentID=64756"&gt;Making Cyber Security Work in the Refinery&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://www.isa.org/Content/ContentGroups/InTech2/Features/20061/January27/Uncovering_Cyber_Flaws.htm"&gt;Uncovering Cyber Flaws&lt;/a&gt;&lt;br /&gt;3. &lt;a href="http://www.isa.org/Content/ContentGroups/InTech2/Features/2003/October19/SP99_counterattacks.htm"&gt;SP99 Counterattacks &lt;/a&gt;&lt;br /&gt;4. &lt;a href="http://www.isa.org/content/contentgroups/news/20051/september29/securing_the_power_grid.htm"&gt;Securing the Power Grid &lt;/a&gt;. This article also has a good chronological chart on the 2003 power blackout in OHIO that crippled a part of the nation.&lt;br /&gt;5. &lt;a href="http://www.isa.org/MSTemplate.cfm?MicrositeID=988&amp;amp;CommitteeID=6821"&gt;ISA99, Manufacturing and Control Systems Security&lt;/a&gt; ISA99 is a new standard for Manufacturing and Control Systems Security. The current edition covers only security technologies and their strengths/weaknesses in the manufacturing environment.  Eventually this would be expanded to include traditional strengths and weaknesses of the different types of control systems (DCS, PLC, SCADA, HMI, etc). The end of the article contain a list of materials in the development of ISA99 by the ISA SP-99 Committee.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-6069602557290860090?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/6069602557290860090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=6069602557290860090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6069602557290860090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/6069602557290860090'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/control-systems-instrumentation-systems.html' title='Control Systems, Instrumentation Systems and Automation Security'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1848924428889833079.post-4936406060922904221</id><published>2007-10-07T12:34:00.001+08:00</published><updated>2007-10-07T16:30:26.252+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='SCADA'/><category scheme='http://www.blogger.com/atom/ns#' term='Infrastructure'/><title type='text'>America's Hackable Backbone</title><content type='html'>This article is a MUST READ article. It highlights the vulnerability of SCADA systems.&lt;br /&gt;&lt;br /&gt;SCADA systems are used around the country to control infrastructure like water filtration and&lt;br /&gt;distribution, trains and subways, natural gas and oil pipelines, and practically every kind of industrial manufacturing. And as some security professionals are pointing out, those weaknesses are increasingly connected to the Internet, leaving large parts of America's critical infrastructure exposed to anyone with moderate information technology training and a laptop.&lt;br /&gt;&lt;br /&gt;The full article can be found &lt;a href="http://www.forbes.com/2007/08/22/scada-hackers-infrastructure-tech-security-cx_ag_0822hack.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;However those who want a pictorial rundown of the story can find it &lt;a href="http://www.forbes.com/2007/08/22/scada-hackers-infrastructure-tech-security-cx_ag_0822hack_slide_2.html?thisspeed=20000"&gt;here&lt;/a&gt;. The pictorial story covers incidents and potential vulnerabilities of SCADA systems controlling power plants, oil and gas pipelines, transportation, dams, manufacturing, water distribution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1848924428889833079-4936406060922904221?l=infraprotect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infraprotect.blogspot.com/feeds/4936406060922904221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1848924428889833079&amp;postID=4936406060922904221' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4936406060922904221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1848924428889833079/posts/default/4936406060922904221'/><link rel='alternate' type='text/html' href='http://infraprotect.blogspot.com/2007/10/americas-hackable-backbone.html' title='America&apos;s Hackable Backbone'/><author><name>A Fattah Yatim</name><uri>http://www.blogger.com/profile/00775312548742426062</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://2.bp.blogspot.com/__6WmxAIFnKY/SWulLofK-hI/AAAAAAAAAAM/IDRQwxw7NLY/S220/AFY2.JPG'/></author><thr:total>0</thr:total></entry></feed>
