<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; internet</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Saving Money &amp; Stopping spam &#8211; change domain names</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/saving-money-stopping-spam-change-domain-names/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/saving-money-stopping-spam-change-domain-names/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 16:47:58 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[cost reduction]]></category>
		<category><![CDATA[cost savings]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[operations]]></category>
		<category><![CDATA[planning]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/saving-money-stopping-spam-change-domain-names/</guid>
		<description><![CDATA[Are you getting lots of SPAM? Is your organization&#8217;s internet link being saturated due to tons of inbound spam and maybe outbound non-delivery notices for invalid addresses? About 3 years ago, ours was too. We also supported several domain names across multiple sites. We subscribed to Postini (now Google) services to reduce the impact on [...]]]></description>
				<content:encoded><![CDATA[<p>Are you getting lots of SPAM? Is your organization&#8217;s internet link being saturated due to tons of inbound spam and maybe outbound non-delivery notices for invalid addresses? About 3 years ago, ours was too. <span id="more-184"></span>We also supported several domain names across multiple sites. We subscribed to <a href="http://www.google.com/postini/index.html" target="_blank">Postini (now Google)</a> services to reduce the impact on the internet connections at our sites. After implementing Postini, we saw a drop in the number of inbound messages and bounced undeliverables of over 85%.</p>
<p>Postini was seeing almost 9 out of every 10 messages as SPAM or bad addresses. This is a huge amount of traffic hitting the circuit(s) and not to mention the email servers and user mailboxes. Postini has saved lots of money on both communication costs and servers. I urge you to take a look at their services or other similar &#8220;cloud&#8221; services.</p>
<p>We recently made a change that was done at NO COST and are seeing savings in network traffic and server load. We got rid of the multiple domain names and went to a single email domain for the entir organization. Before making this change, the total number of inbound messages was about 60,000 per day. After making this change, the number was reduced to 13,000. <strong>This is a &gt;4X reduction in inbound messages!</strong> This was done at no cost. However, it is not without risk so a lot of up-front planning and communication is needed. All employees needed to ensure that their contacts knew their new addresses. An autoreply was also implemented on the edge email gateway to reply to all messages addressed to the old domains.</p>
<p>Savings can come but there are risks. All interested parties need to be kept informed during the changes. Think about what changes can be done in your environment to save costs. It may not be easy, but sometimes can be very effective.</p>
<p>Thanks for reading &amp; let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/saving-money-stopping-spam-change-domain-names/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you manage a firewall and want to find the source of malicious network activity? &#8211; Check out the Internet Malicious Activity Map</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/do-you-manage-a-firewall-and-want-to-find-the-source-of-malicious-network-activity-check-out-the-internet-malicious-activity-map/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/do-you-manage-a-firewall-and-want-to-find-the-source-of-malicious-network-activity-check-out-the-internet-malicious-activity-map/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 19:14:16 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[activity]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[graph]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malicious activity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Subnet]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/?p=107</guid>
		<description><![CDATA[For those of you who manage your own network, you have to consider the strength of the firewall at your network perimiter, the knowledge and skills of those who manage it. You also have to provide technology that can help protect your mobile users. Part of building that secure environment is understanding the environment out [...]]]></description>
				<content:encoded><![CDATA[<p>For those of you who manage your own network, you have to consider the strength of the firewall at your network perimiter, the knowledge and skills of those who manage it. You also have to provide technology that can help protect your mobile users. Part of building that secure environment is understanding the environment out there in the <strong>wild</strong> world web.This is just one of the resources available out there. Please leave feedback if you are aware of others that might be useful to readers.</p>
<p>I recently came across an interesting graph that shows where some of the malicious traffic originates from on the internet. It is called the <a href="http://www.cymru.com/hilbert/full.png">Internet malicious activity map (PNG)</a> The graph is from <a href="http://www.team-cymru.org" target="_blank">Team Cymru</a>. The graph displays in &#8220;heatmap&#8221; style in a <a href="http://en.wikipedia.org/wiki/Hilbert_curve" target="_blank">Hilbert Curve</a> (check this out if you are a fan of fractals). This is an interesting way to graph a lot of data in a small space. As is true in heatmaps, the colors indicate the concentration of malicious activity. The lighter the color, the higher the malicious activity. Take a look at the 85.x.x.x/8, 87.x.x.x/8, and 88.x.x.x/8 sections of the graph. Looks like these networks are major sources of malicious activity on the internet. I would recommend reviewing this graph and determining if the address ranges showing high malicious activities are part of your organization&#8217;s network. If so, then be very concerned. If not, then does your network receive any traffic originating on these subnets? Maybe you should consider blocking traffic from these source subnets. See the <a href="http://www.team-cymru.org/Monitoring/Malevolence/hilbert.html" target="_blank">Team Cymru Malevolence Monitoring website</a> for more security oriented information.</p>
<p>Thanks for reading and let&#8217;s be good network citizens!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/do-you-manage-a-firewall-and-want-to-find-the-source-of-malicious-network-activity-check-out-the-internet-malicious-activity-map/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Microsoft SharePoint Toolkit</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-microsoft-sharepoint-toolkit/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-microsoft-sharepoint-toolkit/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 16:07:14 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[debugging]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[diagnostics]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[MOSS]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-microsoft-sharepoint-toolkit/</guid>
		<description><![CDATA[Many organizations are finding value in the Microsoft SharePoint technologies. Whether you use the free Windows SharePoint Services or the Microsoft Office SharePoint Server, your organization will gain a lot of value from using these services. To enhance your ability to manage these technologies, there is a project on Codeplex called the SharePoint Toolbox. Per [...]]]></description>
				<content:encoded><![CDATA[<p>Many organizations are finding value in the Microsoft SharePoint technologies. Whether you use the free Windows SharePoint Services or the Microsoft Office SharePoint Server, your organization will gain a lot of value from using these services. To enhance your ability to manage these technologies, there is a project on Codeplex called the <a href="http://www.codeplex.com/sptoolbox" target="_blank">SharePoint Toolbox</a>. Per the website, the purpose of this project is as follows:</p>
<blockquote><p>This project includes powerful and useful tools and add-ons for SharePoint that  help developers and IT pros implement SharePoint based solutions more quickly  and managed them more effectively. Contributions will come from the Microsoft  SharePoint Product Group, Microsoft SharePoint Online Services Group, Microsoft  Information Technology Group, and Microsoft Consulting Services Group.</p></blockquote>
<p>I have personally used the <a href="http://www.codeplex.com/sptoolbox/Release/ProjectReleases.aspx?ReleaseId=8366" target="_blank">CopyTimer</a> utility  to measure throughput from remote sites to a SharePoint server. It worked well and helped gather some excellent data about the site and global network performance.</p>
<p>Enjoy using these tools and give me some feedback on what you find useful and how SharePoint provides value to your organization.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-microsoft-sharepoint-toolkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; (Wire)Sharkfest 2008 videos &#8211; including Vint Cerf &#8211; now available</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 20:52:55 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[analysis]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Network TAPs]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/</guid>
		<description><![CDATA[Checkout the Sharkfest 2008 videos at LoveMyTool.com. If you use Wireshark or want to learn network troubleshooting, this is one of the best resources you can have in your toolkit. The videos will give you a better understanding of this tool and other tools out there. There is even a video of Dr. Vinton G. [...]]]></description>
				<content:encoded><![CDATA[<p>Checkout the <a href="http://www.lovemytool.com/blog/sharkfest.html" target="_blank">Sharkfest 2008 videos</a> at LoveMyTool.com. If you use Wireshark or want to learn network troubleshooting, this is one of the best resources you can have in your toolkit. The videos will give you a better understanding of this tool and other tools out there.</p>
<p>There is even a video of Dr. Vinton G. Cerf, vice president and Chief Internet Evangelist for Google. He is responsible for identifying new enabling technologies and applications on the Internet and other platforms for the company.  Widely known as a &#8220;Father of the Internet,&#8221; Vint is the co-designer with Robert Kahn of TCP/IP protocols and basic architecture of the Internet.</p>
<p>Have a great day and thanks for stopping by!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-wiresharkfest-2008-videos-including-vint-cerf-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Process monitor now does TCP/UDP monitoring</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-process-monitor-now-does-tcpudp-monitoring/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-process-monitor-now-does-tcpudp-monitoring/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 13:12:00 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[debugging]]></category>
		<category><![CDATA[diagnostics]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sysinternals]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-process-monitor-now-does-tcpudp-monitoring/</guid>
		<description><![CDATA[If you ever need to get under the covers of running Windows processes for investigating why a system is running slow, then the Sysinternals toolkit has an updated tool that will help you. Per the website: Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It [...]]]></description>
				<content:encoded><![CDATA[<p>If you ever need to get under the covers of running Windows processes for investigating why a system is running slow, then the Sysinternals toolkit has an updated tool that will help you. Per the website:</p>
<blockquote><p><em>Process Monitor</em> is an advanced monitoring tool for Windows that  shows real-time file system, Registry and process/thread activity. It combines  the features of two legacy Sysinternals utilities, <em>Filemon</em> and  <em>Regmon</em>, and adds an extensive list of enhancements including rich and  non-destructive filtering, comprehensive event properties such session IDs and  user names, reliable process information, full thread stacks with integrated  symbol support for each operation, simultaneous logging to a file, and much  more. Its uniquely powerful features will make Process Monitor a core utility in  your system troubleshooting and malware hunting toolkit.</p>
<p><em>Process Monitor</em> runs on Windows 2000 SP4 with Update Rollup 1,  Windows XP SP2, Windows Server 2003 SP1, and Windows Vista as well as x64  versions of Windows XP, Windows Server 2003 SP1 and Windows Vista.</p></blockquote>
<p>I had previously talked about the <a href="http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-sysinternals-live/" target="_blank">Sysinternals Live</a> website. This update to one of the excellent tools is well worth your time in investigating. Take a look at the <a href="http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx" target="_blank">updated tool here</a>. The entire Sysinternals toolset can be found <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx" target="_blank">here</a>.</p>
<p>If you have not used these tools yet, then you are definitely missing a critical item for being successful in your IT position. Check them out… it may save your reputation some time!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-process-monitor-now-does-tcpudp-monitoring/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Open Source Tools University</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-open-source-tools-university/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-open-source-tools-university/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 19:59:03 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[debugging]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[diagnostics]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[LAN]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[network analysis]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[performance monitoring]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Sandbox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[toolkit]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[WAN]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-open-source-tools-university/</guid>
		<description><![CDATA[If you are like me, you like those little goodie tools like nmap and wireshark that do something that is actually pretty complex but do it well and have a great following. I just came across this website that I am going to have to take some time to go through and find all of [...]]]></description>
				<content:encoded><![CDATA[<p>If you are like me, you like those little goodie tools like nmap and wireshark that do something that is actually pretty complex but do it well and have a great following. I just came across this website that I am going to have to take some time to go through and find all of the nuggets it offers. Hope you get some use out of it too and let us know what you discover and how it made your job easier.</p>
<p><a href="http://www.lovemytool.com" target="_blank">LoveMyTool</a></p>
<p>There are presentations on this site like the <a href="http://www.lovemytool.com/blog/2008/07/ray_tompkins_1.html" target="_blank">Wireshark IO Graph for Response Time Analysis (by Ray Tompkins).</a>This should be a great online learning experience. You will find contributors like <a href="http://www.lovemytool.com/blog/sake_blok.html" target="_blank">Sake Blok</a>, a Wireshark Core Developer and <a href="http://www.lovemytool.com/blog/startup-for-less.html" target="_blank">Denny K Miu</a> of StartupforLess.org &#8211; A Survival Guide for Bootstrapping Entrepreneurs</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-open-source-tools-university/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; 2007 Web Application Security Statistics Project</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 16:49:58 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[awareness]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/</guid>
		<description><![CDATA[The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape.   Goals 1. Identify the prevalence and probability of different [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0               false   false   false      EN-US   X-NONE   X-NONE                                                                                                        --><!--[if gte mso 9]&gt;                                                                                                                                                                                                                                                                                                                                                                                                                                --> <!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Consolas; 	panose-1:2 11 6 9 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:modern; 	mso-font-pitch:fixed; 	mso-font-signature:-1610611985 1073750091 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.MsoPlainText, li.MsoPlainText, div.MsoPlainText 	{mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-link:"Plain Text Char"; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.5pt; 	font-family:Consolas; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} span.PlainTextChar 	{mso-style-name:"Plain Text Char"; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-unhide:no; 	mso-style-locked:yes; 	mso-style-link:"Plain Text"; 	mso-ansi-font-size:10.5pt; 	mso-bidi-font-size:10.5pt; 	font-family:Consolas; 	mso-ascii-font-family:Consolas; 	mso-hansi-font-family:Consolas;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;}  --></p>
<p class="MsoPlainText">The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape.</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">Goals</p>
<p class="MsoPlainText">1. Identify the prevalence and probability of different vulnerability classes 2. Compare testing methodologies against what types of vulnerabilities they<span> </span>are likely to identify.</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">The statistics was compiled from web application security assessment projects which were made by the following companies in 2007 (in alphabetic</p>
<p class="MsoPlainText">order):</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">- Booz Allen Hamilton</p>
<p class="MsoPlainText">- BT</p>
<p class="MsoPlainText">- Cenzic with Hailstorm and ClickToSecure</p>
<p class="MsoPlainText">- dblogic.it</p>
<p class="MsoPlainText">- HP Application Security Center with WebInspect</p>
<p class="MsoPlainText">- Positive Technologies with MaxPatrol</p>
<p class="MsoPlainText">- Veracode with Veracode Security Review</p>
<p class="MsoPlainText">- WhiteHat Security with WhiteHat Sentinel</p>
<p class="MsoPlainText"> </p>
<p class="MsoPlainText">The overall statistics includes analysis results of 32,717 sites and 69,476 vulnerabilities of different degrees of severity. The detailed information can be found here:</p>
<p class="MsoPlainText"> </p>
<p><span><a href="http://www.webappsec.org/projects/statistics/">http://www.webappsec.org/projects/statistics/</a></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-2007-web-application-security-statistics-project/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see (listen to) this? &#8211; Podcast on preventing spam</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 19:28:55 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/</guid>
		<description><![CDATA[An audio podcast on how SPAM is generated along with an examination on the frameworks and technologies that help manage and reduce SPAM. This may be a great tutorial for you and/or your users. CERTStation Media &#8211; Spam-Prevent.mp3 I just ran my monthly e-mail statistics and these are the results: 97,000 msgs/day inbound 8,800 msgs/day [...]]]></description>
				<content:encoded><![CDATA[<p>An audio podcast on how SPAM is generated along with an examination on the frameworks and technologies that help manage and reduce SPAM.</p>
<p>This may be a great tutorial for you and/or your users.</p>
<p><a href="http://usp.hdaar.com/radio/hdmedia/Spam-Prevent.mp3" target="_blank">CERTStation Media &#8211; Spam-Prevent.mp3</a></p>
<p>I just ran my monthly e-mail statistics and these are the results:</p>
<p>97,000 msgs/day inbound</p>
<p>8,800 msgs/day delivered to end users &#8211; 9%</p>
<p>22,200 msgs/day quarantined as spam &#8211; 23%</p>
<p>66,000 msgs/day blocked as spam &#8211; 67%</p>
<p>This month had higher than normal quarantine activity. Quarantine has been running about 15% and blocking around 75%.  How does your mail stack up?</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-listen-to-this-podcast-on-preventing-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://usp.hdaar.com/radio/hdmedia/Spam-Prevent.mp3" length="8329825" type="audio/x-mpeg" />
		</item>
		<item>
		<title>Trolls on ITKE &#8211; I think not!</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/trolls-on-itke-i-think-not/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/trolls-on-itke-i-think-not/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 15:46:39 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[intellectual property]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/trolls-on-itke-i-think-not/</guid>
		<description><![CDATA[Here&#8217;s an interesting blog entry I came across this week. I have great respect for John Postel mentioned in the article. He contributed immensely to the design of the protocols on which we depend on for data networks. I really like his Robustness Principle. &#8220;Be conservative in what you do, be liberal in what you [...]]]></description>
				<content:encoded><![CDATA[<p>Here&#8217;s an interesting <a href="http://www.internetevolution.com/author.asp?section_id=696&amp;doc_id=161917" target="_blank">blog entry</a> I came across this week. I have great respect for <a href="http://www.postel.org/postel.html" target="_blank">John Postel</a> mentioned in the article. He contributed immensely to the design of the protocols on which we depend on for data networks. I really like his  Robustness Principle. <em>&#8220;Be conservative in what you do, be liberal  in what you accept from others.&#8221;</em>  This is a good statement for life but can be a challenge to address in the IT world. The article and follow-up postings have a lot of nuggets of great thought. Maybe add your thoughts to Mr Schwartz&#8217;s post or add some thoughts below here.</p>
<p>Have you had to deal with a troll? What were your challenges and how did it end up? What are your suggestions for handling this global issue?</p>
<p>It is quite amazing if you take a minute to think about it how the global internet provides a whole new environment for crime and abuse. There is no single legal body that can deal with this environment. There are no borders (although countries like China try to control what information crosses theirs).</p>
<p>I do want to commend ITKE for seeming to keeping the trolls away from this useful internet resource. I know it is a challenging job but the TechTarget folks are doing a great job! Let&#8217;s thank them for all their hard work by keeping up the knowledge sharing.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/trolls-on-itke-i-think-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Equipment search &amp; seizure at the US borders</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 20:08:36 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CIO]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[intellectual property]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WAN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/</guid>
		<description><![CDATA[I have recently been hearing some rumblings about this issue. I work for a firm with international locations and have travelled out of the country myself. So, this is a personal issue. What I am referring to is the situation described in this article by David Jonas of The Transnational: Airport Laptop Seizures Debated in [...]]]></description>
				<content:encoded><![CDATA[<p>I have recently been hearing some rumblings about this issue. I work for a firm with international locations and have travelled out of the country myself. So, this is a personal issue.</p>
<p>What I am referring to is the situation described in this article by David Jonas of The Transnational: <a href="http://www.thetransnational.travel/news.php?cid=laptop-seizure.Jul-08.09 " target="_blank">Airport Laptop Seizures Debated in Washington</a>. I know that I should have nothing to worry about if I do nothing wrong like any law abiding citizen of the world. However, what about the risk to an organization&#8217;s intellectual property?</p>
<p>Look at the comment <em>&#8230;the laptop seizure policy is not analogous to physical searches of persons and  belongings at airports: &#8220;Not only does the government get access to an  unprecedented wealth of material with a laptop border search, but the government  now has the ability to copy, store and analyze that information at its leisure.  In traditional border searches, travelers carried their suitcases with them once  they cleared customs. With laptop border searches, the government can keep  everything in the computer in perpetuity.&#8221;</em> So, who is responsible for the data once it is out of the traveller&#8217;s hands? What is the care &amp; duty of the government with regards to a company&#8217;s intellectual capital?</p>
<p>This issue seems like a bureaucratic (and maybe totalitarian leaning &#8211; think &#8220;Big Brother&#8221;) nightmare! Who would be considered the appropriate person to review the data on a device? What is their liability if the device or data is damaged during their review?</p>
<p>I know I don&#8217;t have an easy answer to these nagging questions and it will take much better minds and skills than mine to work through the protection and liability issues for an organization. What mechanisms do you use to protect equipment and data during travel? Maybe this situation is a boon to shipping organizations. More people may be shipping their gear ahead of them when travelling across the border or use equipment at a remote site and transfer data across a network.</p>
<p>This situation is definitely one to watch and be concerned about as world citizens.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/it-equipment-search-seizure-at-the-us-borders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
