 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; vulnerabilities</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>BlackHat USA technical presentations available online &#8211; not just for hackers</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/blackhat-usa-technical-presentations-available-online-not-just-for-hackers/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/blackhat-usa-technical-presentations-available-online-not-just-for-hackers/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 16:21:12 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[bootkit]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[least user authority]]></category>
		<category><![CDATA[least user privilege]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/blackhat-usa-technical-presentations-available-online-not-just-for-hackers/</guid>
		<description><![CDATA[The media archives have now been posted on the BlackHat website from the BlackHat technical conference held in July 2009. This is the place to go if you want to see some of the latest information security research and the threats that are REAL and may become real someday. I posted a previous blog entry [...]]]></description>
				<content:encoded><![CDATA[<p>The <a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html" target="_blank">media archives</a> have now been posted on the BlackHat website from the BlackHat technical conference held in July 2009. This is the place to go if you want to see some of the latest information security research and the threats that are REAL and may become real someday. I posted a previous blog entry on the presentation about the <strong></strong><a href="http://itknowledgeexchange.techtarget.com/it-trenches/bootkit-rootkit-malware-bypasses-disk-encryption/" target="_blank"><strong><span class="row-title">Bootkit &#8211; rootkit &#8211; malware bypasses disk encryption!</span></strong></a></p>
<p>Some of the presentation titles:</p>
<p>I<strong> Just Found 10 Million SSN&#8217;s</strong></p>
<p><strong>Sniff Keystrokes With Lasers/Voltmeters<br />
Side Channel Attacks Using Optical  Sampling of Mechanical Energy and Power Line Leakage</strong></p>
<p><strong>Anti-Forensics: The Rootkit Connection</strong></p>
<p><strong>Reversing and Exploiting an Apple® Firmware Update</strong></p>
<p><strong>The Language of Trust: Exploiting Trust Relationships in Active Content</strong></p>
<p><strong>Mo&#8217; Money Mo&#8217; Problems: Making A LOT More Money on the Web the Black Hat Way</strong></p>
<p><strong>The Conficker Mystery</strong></p>
<p>These are just some of the titles available in the <a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-archives.html" target="_blank">BlackHat 2009 Technical Conference media library</a>. Check it out even if you are a web developer or an IT professional who manages desktops or networks or staff members who perform these tasks. You need to know what you are up against and possible methods to fight the threats.</p>
<p>Thanks for reading &amp; lets continue to be good network citizens!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/blackhat-usa-technical-presentations-available-online-not-just-for-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bootkit &#8211; rootkit &#8211; malware bypasses disk encryption!</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/bootkit-rootkit-malware-bypasses-disk-encryption/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/bootkit-rootkit-malware-bypasses-disk-encryption/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 12:48:00 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[bootkit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[least user authority]]></category>
		<category><![CDATA[least user privilege]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/bootkit-rootkit-malware-bypasses-disk-encryption/</guid>
		<description><![CDATA[If you have not been nervous before about someone infecting computers without your knowledge then you should be much more nervous after reading this article. In 1987 the Stoned boot sector virus came out and was one of the most prevalent viruses of the early personal computer era. As with most malware concepts, this old [...]]]></description>
				<content:encoded><![CDATA[<p>If you have not been nervous before about someone infecting computers without your knowledge then you should be much more nervous after reading this article.</p>
<p>In 1987 the <a href="http://en.wikipedia.org/wiki/Stoned_virus" target="_blank">Stoned boot sector virus</a> came out and was one of the most prevalent viruses of the early personal computer era. As with most malware concepts, this old threat has been made new again.</p>
<p>An 18-year old security specialist gave a presentation on a bootkit/rootkit (<a href="http://www.stoned-vienna.com/" target="_blank">STONED</a>) at the annual <a href="http://www.blackhat.com/" target="_blank">Blackhat</a> security conference. This bootkit is not your typical bootkit in that it can bypass disk encryption and load itself into memory before the disk encryption software is activated. The demonstration showed the bootkit loading before disk encryption is activated. Once the malware is loaded from the master boot record (MBR), it is then in memory and can download other malware such as trojans to capture banking credentials.</p>
<p>The bootkit software can be installed either by having physical access to the device or by a user with administrative credentials (this makes a good case for the <a href="http://en.wikipedia.org/wiki/Principle_of_least_privilege" target="_blank">&#8220;least user authority&#8221; (LUA) principle</a>). Once the malware is installed and activated it is very difficult to detect. According to <a href="http://www.heise.de/english/newsticker/news/142881" target="_blank">one article</a>:</p>
<p><em>Once installed, Stoned cannot be detected with traditional anti-virus  software because no modifications of Windows components take place in memory,  says Kleissner. Stoned runs in parallel with the actual Windows kernel. Even an  anti-virus function in the BIOS can&#8217;t stop the bootkit, as modern Windows  versions modify the MBR without referring to the BIOS.</em></p>
<p>Our challenge as infosec professionals is laid out before us. How we deal with threats like these and protect our users and organizations becomes more difficult all of the time. We have to stay on top of our game because the rules and game conditions are always changing.</p>
<p>Thanks for reading &amp; let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/bootkit-rootkit-malware-bypasses-disk-encryption/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is unified threat management defense in depth?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/is-unified-threat-management-defense-in-depth/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/is-unified-threat-management-defense-in-depth/#comments</comments>
		<pubDate>Thu, 07 May 2009 19:33:29 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[Defense in Depth]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[Midmarket security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Single Point of Failure]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[Unified Threat Management]]></category>
		<category><![CDATA[UTM]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/is-unified-threat-management-defense-in-depth/</guid>
		<description><![CDATA[An ITKE poster recently asked a great question. Experts tout unified threat management appliances as an ideal antimalware, intrusion prevention and content filtering firewall for midmarket companies. But doesn&#8217;t this counter the long-standing security practice of defense-in-depth? With a one vendor, platform, and management console, aren&#8217;t we talking about a dangerous single point of failure? [...]]]></description>
				<content:encoded><![CDATA[<p>An ITKE poster recently asked a great question.</p>
<blockquote><p>Experts tout unified threat management appliances as an ideal antimalware, intrusion prevention and content filtering firewall for midmarket companies. But doesn&#8217;t this counter the long-standing security practice of defense-in-depth? With a one vendor, platform, and management console, aren&#8217;t we talking about a dangerous single point of failure?</p>
<p>When is UTM good enough? When should we go with standalone devices?</p></blockquote>
<p>Here&#8217;s the answer that I offered:</p>
<p>Actually it is defense in depth even though they are all contained on one appliance or device. Think about the layers in a bullet proof vest. They each work in tandem to prevent damage to the person wearing it. However just one type of layer by itself would likely not be enough protection against certain firearms.</p>
<p>Granted it is a single point of failure, but the ability to manage an entire suite of services from one console is attractive to many smaller organizations that may not be able to provide the care and feeding of single purpose devices. The ability of a vendor to patch the entire product suite against vulnerabilities is another good reason to go to a UTM device. If using multiple devices from different vendors, then the vulnerability exposure could potentially be greater if one vendor addresses a vulnerability in their appliance/service but another does not.</p>
<p>I would go to standalone devices if the potential threat to my organization could create capacity/performance issues on the UTM device.</p>
<p>How do you think about the UTM vs defense in depth issue? Do you agree with the answer I offered? What do you think?</p>
<p>Thanks for reading and let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/is-unified-threat-management-defense-in-depth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security news &#8211; Videos from Hack In The Box 2008 Malaysia available for download</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/security-news-videos-from-hack-in-the-box-2008-malaysia-available-for-download/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/security-news-videos-from-hack-in-the-box-2008-malaysia-available-for-download/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 16:36:59 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/?p=94</guid>
		<description><![CDATA[The videos from HITBSecConf2008 &#8211; Malaysia are now available for download! Day 1 ===== http://thepiratebay.org/torrent/4654588/HITBSecConf2008_-_Malaysia_Videos___Day_1 Keynote Address 1: The Art of Click-Jacking &#8211; Jeremiah Grossman Keynote Address 2: Cyberwar is Bullshit &#8211; Marcus Ranum Presentations: - Delivering Identity Management 2.0 by Leveraging OPSS - Bluepilling the Xen Hypervisor - Pass the Hash Toolkit for Windows [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoPlainText"><!--[if gte mso 9]&gt;  Normal 0     false false false  EN-US X-NONE X-NONE                            &lt;![endif]--><!--[if gte mso 9]&gt;                                                                                                                                            &lt;![endif]-->The videos from HITBSecConf2008 &#8211; Malaysia are now available for download!</p>
<p class="MsoPlainText">
<p class="MsoPlainText">Day 1</p>
<p class="MsoPlainText">=====</p>
<p class="MsoPlainText">
<p class="MsoPlainText"><a href="http://thepiratebay.org/torrent/4654588/HITBSecConf2008_-_Malaysia_Videos___Day_1">http://thepiratebay.org/torrent/4654588/HITBSecConf2008_-_Malaysia_Videos___Day_1</a></p>
<p class="MsoPlainText"><span> </span></p>
<p class="MsoPlainText">Keynote Address 1: The Art of Click-Jacking &#8211; Jeremiah Grossman Keynote Address 2: Cyberwar is Bullshit &#8211; Marcus Ranum</p>
<p class="MsoPlainText">
<p class="MsoPlainText">Presentations:</p>
<p class="MsoPlainText">
<p class="MsoPlainText">- Delivering Identity Management 2.0 by Leveraging OPSS</p>
<p class="MsoPlainText">- Bluepilling the Xen Hypervisor</p>
<p class="MsoPlainText">- Pass the Hash Toolkit for Windows</p>
<p class="MsoPlainText">- Internet Explorer 8 &#8211; Trustworthy Engineering and Browsing</p>
<p class="MsoPlainText">- Full Process Reconsitution from Memory</p>
<p class="MsoPlainText">- Hacking Internet Kiosks</p>
<p class="MsoPlainText">- Analysis and Visualization of Common Packers</p>
<p class="MsoPlainText">- A Fox in the Hen House &#8211; UPnP IGD</p>
<p class="MsoPlainText">- MoocherHunting</p>
<p class="MsoPlainText">- Browser Exploits: A New Model for Browser Security</p>
<p class="MsoPlainText">- Time for a Free Hardware Foundation?</p>
<p class="MsoPlainText">- Mac OS Xploitation</p>
<p class="MsoPlainText">- Hacking a Bird in The Sky 2.0</p>
<p class="MsoPlainText">- How the Leopard Hides His Spots &#8211; OS X Anti-Forensics Techniques</p>
<p class="MsoPlainText">
<p class="MsoPlainText">
<p class="MsoPlainText">Day 2</p>
<p class="MsoPlainText">=====</p>
<p class="MsoPlainText">
<p class="MsoPlainText"><a href="http://thepiratebay.org/torrent/4654974/HITBSecConf2008_-_Malaysia_Videos___Day_2">http://thepiratebay.org/torrent/4654974/HITBSecConf2008_-_Malaysia_Videos___Day_2</a></p>
<p class="MsoPlainText">
<p class="MsoPlainText">Keynote Address 3:<span> </span>Dissolving an Industry as a Hobby &#8211; THE PIRATE BAY</p>
<p class="MsoPlainText">
<p class="MsoPlainText">Presentations:</p>
<p class="MsoPlainText">
<p class="MsoPlainText">- Pushing the Camel Through the Eye of a Needle</p>
<p class="MsoPlainText">- An Effective Methodology to Enable Security Evaluation at RTL Level</p>
<p class="MsoPlainText">- Remote Code Execution Through Intel CPU Bugs</p>
<p class="MsoPlainText">- Next Generation Reverse Shell</p>
<p class="MsoPlainText">- Build Your Own Password Cracker with a Disassembler and VM Magic</p>
<p class="MsoPlainText">- Decompilers and Beyond</p>
<p class="MsoPlainText">- Cracking into Embedded Devices and Beyond!</p>
<p class="MsoPlainText">- Client-side Security</p>
<p class="MsoPlainText">- Top 10 Web 2.0 Attacks</p>
<p class="MsoPlainText">
<p class="MsoPlainText">===</p>
<p class="MsoPlainText">
<p class="MsoPlainText">On a related note, the registration for HITBSecConf2009 &#8211; Dubai (20th &#8211; 23rd April) is now open!</p>
<p class="MsoPlainText">
<p class="MsoPlainText"><a href="http://conference.hitb.org/hitbsecconf2009dubai/">http://conference.hitb.org/hitbsecconf2009dubai/</a></p>
<p class="MsoPlainText">
<p class="MsoPlainText">The Call for Papers (CFP) for HITBSecConf2009 &#8211; Malaysia (October 5th -</p>
<p class="MsoPlainText">8th) will open in March 2009.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/security-news-videos-from-hack-in-the-box-2008-malaysia-available-for-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
