 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Open Source Software and Linux &#187; Security</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/linux-lotus-domino/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino</link>
	<description></description>
	<lastBuildDate>Thu, 02 May 2013 21:07:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>University of Utah gets hit by conficker worm</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/university-of-utah-gets-hit-by-conficker-worm/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/university-of-utah-gets-hit-by-conficker-worm/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 01:06:20 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[operating system]]></category>
		<category><![CDATA[university of utah]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/university-of-utah-gets-hit-by-conficker-worm/</guid>
		<description><![CDATA[Over 700 computers were hit by the most recent release of the conficker worm at the University of Utah. Computers included those at the University&#8217;s three hospitals. The worm was first detected on Thursday on some of the school&#8217;s computers. By Friday it had hit the school&#8217;s computers at the three hospitals, medical school, and [...]]]></description>
				<content:encoded><![CDATA[<p>Over 700 computers were hit by the most recent release of the conficker worm at the University of Utah.  Computers included those at the University&#8217;s three hospitals.</p>
<p>The worm was first detected on Thursday on some of the school&#8217;s computers.  By Friday it had hit the school&#8217;s computers at the three hospitals, medical school, and colleges of nursing, pharmacy and health.</p>
<p>University officials don&#8217;t believe that any patient data or medical records were compromised.  According to officials those are protected &#8220;in a deeper way&#8221;.  That begs the question of what exactly does that mean?  Is that the only data that is virus protected?  Is it on Linux or Unix?</p>
<p>The IT staff at the school shut off internet access for up to 6 hours Friday in an effort to isolate the worm.  The staff worked over the weekend to cleanup the damage caused by the outbreak.  Kind of gives real meaning to the saying &#8220;An ounce of prevention is worth a pound of cure&#8221; doesn&#8217;t it?</p>
<blockquote><p>Mindy Tueller of the university&#8217;s office of information technology said all faculty and students should take steps to make sure they are protected. The virus does not infect Macs. </p></blockquote>
<p> Or Linux, Unix or any other OS besides Windows <img src='http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<blockquote><p>&#8220;It can do a lot of bad things,&#8221; Tueller said. &#8220;Every university member should be concerned about this if they&#8217;re using Windows-based devices.&#8221; </p></blockquote>
<p>Interesting.  Ms. Tueller and school officials apparently recognize that the problem is the OS but apparently don&#8217;t want to do anything about it.  How much does that attitude cost the school?</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/university-of-utah-gets-hit-by-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity bill before Senate for approval</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/cybersecurity-bill-before-senate-for-approval/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/cybersecurity-bill-before-senate-for-approval/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 16:27:32 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/cybersecurity-bill-before-senate-for-approval/</guid>
		<description><![CDATA[A cybersecurity bill is before the Senate for approval. The bill, if passed, would impose standards on the public and private sectors and certifications for cybersecurity professionals. The legislation is aimed streamlining cybersecurity authorities, promoting public awareness and enhanci cybersecurity cooperation between government and industry, The bill would also increase cybersecurity education and research and [...]]]></description>
				<content:encoded><![CDATA[<p>A cybersecurity bill is before the Senate for approval.  The bill, if passed, would impose standards on the public and private sectors and certifications for cybersecurity professionals.</p>
<p>The legislation is aimed streamlining cybersecurity authorities, promoting public awareness and enhanci cybersecurity cooperation between government and industry, The bill would also increase cybersecurity education and research and development efforts.</p>
<p>So far as networks are concerned the bill would give the new national cybersecurity adviser the right to disconnect any network deemed critical to national security or the US infrastructure from the internet.  This would only happen if the network is considered at risk for attack.</p>
<p>According to the <a href="http://fcw.com/Articles/2009/04/01/Web-cybersecurity-bill.aspx">article</a>: </p>
<blockquote><p>The senators also called for a public awareness campaign, a review of the laws that apply to cybersecurity and a report on identity management and civil liberties. They would also further involve the private sector in cybersecurity efforts through the establishment of:</p>
<p>    * A group that would certify that products purchased by the federal government meet cybersecurity standards.<br />
    *<br />
      A panel of outside experts to advise the president on cybersecurity.<br />
    *<br />
      A public-private clearinghouse for information sharing on cyberthreats.<br />
    *<br />
      State and regional cybersecurity centers to help small and medium-sized businesses.</p></blockquote>
<p>I suppose it had to happen sooner or later.  In the past couple of months I have mentioned several cybersecurity attacks, some successful and other networks at risk, in both the private and public sectors.  It is a natural progression of this county&#8217;s government to step in when business, organizations, and government branches refuse to police themselves and protect their constituents and customers from harm.</p>
<p>On the brighter side a whole new market is opening up for security professionals and software.  This is going to happen at the collegiate level as well as in the development of new security software.  If you are looking for a career or career change this is an area that you should investigate.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/cybersecurity-bill-before-senate-for-approval/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>And you thought conficker was dead</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 18:55:02 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[Conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/</guid>
		<description><![CDATA[The conficker worm that infected millions of computers starting last October was believed to be at bay. Not so according to Vincent Weafer, vice president of Symantec&#8217;s security response group. Computers infected with this worm are being updated with a stronger variant. The variant is designed to sidestep security measures attempting to cut the connection [...]]]></description>
				<content:encoded><![CDATA[<p>The conficker worm that infected millions of computers starting last October was believed to be at bay.  Not so according to Vincent Weafer, vice president of Symantec&#8217;s security response group.</p>
<p>Computers infected with this worm are being updated with a stronger variant.  The variant is designed to sidestep security measures attempting to cut the connection between infected machines and it&#8217;s hacker controllers.  An estimated 20 technology companies, including Microsoft, have joined together to try and counter the stronger variant.</p>
<p>They are attempting to stop the worm by pre-registering domains that they believe the worm will use.  According to Symantec and others in the group the worm can register up to 50,000 domain names a day.  The domains are used to band together the infected computers and route the worm to other computers for infection.</p>
<p>The new worm is also better at resisting eradication.  &#8220;It&#8217;s turning off a variety of security services,&#8221; Weafer said, as well as tools often used by security companies to dig into malware.</p>
<p>Weafer also believe that the number of infected computers has peaked.  &#8220;The number of infected machines is constantly dropping, so we&#8217;re dealing with a much smaller pool [of devices] that are potentially getting this update,&#8221; Weafer said.</p>
<p>There is bright side to all of this.  Linux users don&#8217;t have to worry about this.  We don&#8217;t need to download Microsoft&#8217;s patch to fix our machines.  What is really glaring is that so far as I know there are no open source companies joined to the group to protect the Windows computer.  Maybe they should consult with them and teach them how to write software that is not so susceptible to attacks like this.</p>
<p>This whole thing started because of a security vulnerability in the Microsoft OS.  When are Microsoft users and companies going to wake up and realize how expensive it is to continue using this brain dead OS?  FWIW my definition of brain dead is an OS that has users, administrators and anyone else who uses the machine pointing and clicking to set up the OS and not knowing what they just did.  No wonder that OS gets attacked so much.</p>
<p>If you have a Microsoft machine that is infected what you need is the MS08-067 security update.  You&#8217;ll have to look it up yourself &#8211; I have no need for it.  You can read more about this fiasco <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9129239&amp;intsrc=hm_list">here</a>.</p>
<p>I&#8217;ll stick with my Linux and Open Source software thank you very much.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/and-you-thought-conficker-was-dead/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Protect your ssh server with DenyHosts</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/protect-your-ssh-server-with-denyhosts/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/protect-your-ssh-server-with-denyhosts/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 00:18:07 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[denyhosts]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[SSHD]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/protect-your-ssh-server-with-denyhosts/</guid>
		<description><![CDATA[If you have an SSH server that is accessible from the internet then you should look at the DenyHosts application to protect your servers and networks. DenyHosts protects your servers by parsing your ssh log for failed attempts at ssh login. The log where this is recorded varies by distribution. On Red Hat it is [...]]]></description>
				<content:encoded><![CDATA[<p>If you have an SSH server that is accessible from the internet then you should look at the DenyHosts application to protect your servers and networks.</p>
<p>DenyHosts protects your servers by parsing your ssh log for failed attempts at ssh login.  The log where this is recorded varies by distribution.  On Red Hat it is /var/log/secure and /var/log/auth.log on Mandrake.  You should have one of these log files on your system</p>
<p>DenyHosts works by monitoring these logs for failed ssh login attempts.  It also tracks which user accounts are targeted.  When it finds a repeated failures from the same IP address it inserts these into your /etc/hosts.deny file effectively blocking the offending crackers.</p>
<p>Like any security measure this one can be shored up by implementing complementary measures.  These would include disallowing root logins, using a port number other than 22 and disabling password logins.  All of these can be set in your /etc/ssh/sshd_config file.  Your ssh daemon must be restarted after making these changes.</p>
<p>You can download DenyHosts <a href="http://denyhosts.sourceforge.net/">here</a>.<br />
-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/protect-your-ssh-server-with-denyhosts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How safe is your seach engine?</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/how-safe-is-your-seach-engine/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/how-safe-is-your-seach-engine/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 23:38:44 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malicious web sites]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[search engines]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web browsers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/how-safe-is-your-seach-engine/</guid>
		<description><![CDATA[Crackers are increasingly attempting to influence the behavior of search engines to get them to misdirect users to malicious sites says security firm Marshal. Unknowing users are asked to download an anti-malware application to protect their computers. The malware program then installs it&#8217;s malicious code onto the users computer. Microsoft has attempted to help users [...]]]></description>
				<content:encoded><![CDATA[<p>Crackers are increasingly attempting to influence the behavior of search engines to get them to misdirect users to malicious sites says security firm <a href="http://www.marshal.com/TRACE/traceitem.asp?article=884&amp;thesection=trace">Marshal</a>.</p>
<p>Unknowing users are asked to download an anti-malware application to protect their computers.  The malware program then installs it&#8217;s malicious code onto the users computer.  </p>
<p>Microsoft has attempted to help users with it&#8217;s Internet Explorer browser by using what they call a Smartscreen filter.  The filter scans servers that have downloads to determine if those servers have a history of giving out malicious content.  It if does the user is warned that they may be on a malicious web site.</p>
<p>Crackers also add links to bad websites in the comments. Posting links to such sites is known as blog spamming.  When a user goes to one of these sites the cracker has automated tools that help gain entry into the users computer.</p>
<p>Unfortunately there is no firewall rule to prevent the foolishness of people visiting such sites.  Once they are there bad things happen.  Updated browsers, proxy servers and black and white lists certainly help.  Still the best prevention for eliminating problems is educating users what to avoid along with the aforementioned methods.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/how-safe-is-your-seach-engine/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Government scholarships for studying cybersecurity</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/government-scholarships-for-studying-cybersecurity/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/government-scholarships-for-studying-cybersecurity/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 21:09:28 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[federal agency]]></category>
		<category><![CDATA[scholarship]]></category>
		<category><![CDATA[scholarships]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[us government]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/government-scholarships-for-studying-cybersecurity/</guid>
		<description><![CDATA[The US Government give you a full scholarship for college if you want to become a cybersecurity specialist. The scholarship covers room and board, books and tuition. The obvious question here is &#8220;What do I have to give them in return?&#8221; Two years of government service at a federal agency in a cybersecurity position. That&#8217;s [...]]]></description>
				<content:encoded><![CDATA[<p>The US Government give you a full scholarship for college if you want to become a cybersecurity specialist.  The scholarship covers room and board, books and tuition.</p>
<p>The obvious question here is &#8220;What do I have to give them in return?&#8221;  Two years of government service at a federal agency in a cybersecurity position.  That&#8217;s not a whole to ask in my opinion.  Think about.  Your getting a paid-for education in a field whose demand is only going to grow and all you have to do is work at a federal agency for two year using what you majored in at college.  Not bad.</p>
<p>The program, known as SFS (Scholarship for Service), is run by run jointly by the National Science Foundation and DHS.  SFS is quickly becoming known for more than just recruiting talent for their scholarships:  </p>
<blockquote><p>In the information assurance community, SFS is becoming widely recognized as indispensable, especially when government demand for highly skilled information technology security professionals is surging because of Information Systems Management Act requirements, the inexorable growth in security operations centers and an impending wave of retirements.</p></blockquote>
<p>Michelle Kwon who graduated from the program has this to say about it </p>
<blockquote><p>“When I graduated from the SFS program, I really thought I was going to do my two years [of government service] and then jump to industry and make big bucks,” Kwon said. “But I was given opportunities through the program that I wouldn’t have had otherwise.”</p></blockquote>
<p>  Michelle is now in a high-powered position as director of the Homeland Security Department’s U.S. Computer Emergency Readiness Team.  Last year she was named director of US-CERT.</p>
<p>You can read more about the program <a href="http://gcn.com/articles/2009/03/23/sfs-cyber-workforce.aspx">here</a>.</p>
<p>If I were a student and looking for a way to go to college this would be a fantastic way to go.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/government-scholarships-for-studying-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you using myOpenID?  (They launched a WordPress plugin)</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/are-you-using-myopenid-they-launched-a-wordpress-plugin/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/are-you-using-myopenid-they-launched-a-wordpress-plugin/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 19:32:58 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[myopenid]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[single sign on]]></category>
		<category><![CDATA[sso]]></category>
		<category><![CDATA[web authentication]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/are-you-using-myopenid-they-launched-a-wordpress-plugin/</guid>
		<description><![CDATA[myOpenID is an open source third party authentication tool allowing users to have one login across multiple websites. myOpenID is developed my JanRain. Making life even better OpenID works with many websites where you may already have an identity. These include Facebook, MySpace, Google, Yahoo, AOL and Windows Live ID. Many sites will allow you [...]]]></description>
				<content:encoded><![CDATA[<p>myOpenID is an open source third party authentication tool allowing users to have one login across multiple websites.  myOpenID is developed my <a href="http://janrain.com">JanRain</a>.</p>
<p>Making life even better OpenID works with many websites where you may already have an identity.  These include  Facebook, MySpace, Google, Yahoo, AOL and Windows Live ID.  Many sites will allow you to use your authentication information from one of these sites to login to their site.</p>
<p>JanRain eases the integration of OpenID with their RPX product.  RPX allows websites to be up and running in an afternoon with OpenID.  They recently launched a <a href="http://wordpress.org/extend/plugins/rpx/">WordPress plugin</a> for blogging sites.  This site uses WordPress.  I wonder if we&#8217;ll be getting OpenID <img src='http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>OpenID has launched a demo of the RPX product <a href="http://rpxnow.com/">here</a>.  The plugin demonstrates the ease in which the RPX turnkey solution can be implemented.</p>
<p>OpenID now has over 35,000 sites using their product.  These include high profile sites like PayPal, Plaxo, Sun and AOL.</p>
<p>I know that I use it with Yahoo as my identity provider for sites that accept them.  I could use my myOpenID uthentication for all of them if I chose to do so.  You should try it-it&#8217;s nice to able to use existing web identities instead of having to register at sites that you want to use.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/are-you-using-myopenid-they-launched-a-wordpress-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IRS a little lazy on scanning servers for malware</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/irs-a-little-lazy-on-scanning-servers-for-malware/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/irs-a-little-lazy-on-scanning-servers-for-malware/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 23:35:42 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[crackers]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[irs]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/irs-a-little-lazy-on-scanning-servers-for-malware/</guid>
		<description><![CDATA[A recent report by the Treasury Inspector General for Tax Administration (TIGTA) noted that the IRS scans about 89% of it&#8217;s servers weekly for malware and viruses. That should give you a warm and fuzzy feeling. Apparently they believe that employee workstations pose more of a threat. All employee workstations are scanned weekly. Of the [...]]]></description>
				<content:encoded><![CDATA[<p>A recent report by the Treasury Inspector General for Tax Administration (TIGTA) noted that the IRS scans about 89% of it&#8217;s servers weekly for malware and viruses.  That should give you a warm and fuzzy feeling.</p>
<p>Apparently they believe that employee workstations pose more of a threat.  All employee workstations are scanned weekly.  Of the 11% of servers that aren&#8217;t scanned some are scanned intermittently and others not at all.</p>
<p>According to Michael Phillips, the deputy inspector general for audit, The IRS’ Cybersecurity Computer Security Incident Response Center responded to 961 malware incidents in calendar year 2008, an increase of 45 percent over the prior year, </p>
<p>The TIGTA also said that the IRS has adequate controls in place to prevent and respond to malware attacks.  They have also built up the security structure to deal with the increasing threat of crackers.</p>
<p>The inspector general also recommended that IRS administrators should not be accessing the internet with their IRS logons.  Employees and their managers should also be notified when their browsing results in a successful malicious code incident. </p>
<blockquote><p>Terence Milholland, IRS’ chief technology officer, said in response the service would begin to scan all servers weekly by May 1 and implement regular reminders on Internet access restrictions by Aug. 1. The IRS would start notifying employees and their managers when their activity results in a malware incident, he said.</p></blockquote>
<p>You can access the full report <a href="http://www.treas.gov/tigta/auditreports/2009reports/200920045fr.pdf">here</a>.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/irs-a-little-lazy-on-scanning-servers-for-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Want to know how the Federal Government uses virtualization?</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/want-to-know-how-the-federal-government-uses-virtualization/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/want-to-know-how-the-federal-government-uses-virtualization/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 00:20:26 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[computing]]></category>
		<category><![CDATA[consolidation]]></category>
		<category><![CDATA[green computing]]></category>
		<category><![CDATA[los alamos]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/want-to-know-how-the-federal-government-uses-virtualization/</guid>
		<description><![CDATA[I have often wondered how the really big technology users, like the Federal Government, utilize various technologies such as virtualization. Now we can all get a first hand look by watching an eSeminar presented by Government Computer News. They are presenting Anil Karmel, a solutions architect in the network and infrastructure engineering division at Los [...]]]></description>
				<content:encoded><![CDATA[<p>I have often wondered how the really big technology users, like the Federal Government, utilize various technologies such as virtualization.</p>
<p>Now we can all get a first hand look by watching an eSeminar presented by Government Computer News.  They are presenting Anil Karmel, a solutions architect in the network and infrastructure engineering division at Los Alamos National Laboratory, in an eSeminar at 2 p.m. Tuesday, March 24.</p>
<p>In the seminar Mr. Karmel will present on the initiatives taken by Los Alamos to address such things as green computing, disaster recovery and security.  During the presentation he will discuss </p>
<blockquote><p>
How Los Alamos National Laboratory implemented virtualization to reduce their carbon footprint and consolidate data centers across their campus;</p>
<p>How to leverage server virtualization to cost-effectively supplement your disaster-recovery or business-continuity plan;</p>
<p>How to identify “low hanging fruit” for your agency’s green initiatives while achieving a substantial return on your investment; and</p>
<p>Moving computing from the desktop to the data center to enhance your agency’s security.  </p></blockquote>
<p>Sounds like a good place to learn about how some really smart people implement virtualization.  I certainly plan on being there.  You can read more about it <a href="http://fcw.com/Webcasts/2009/03/GCN-Virtualization-Anil-Karmel.aspx">here</a>.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/want-to-know-how-the-federal-government-uses-virtualization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wyndham Hotels gets hacked</title>
		<link>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wyndham-hotels-gets-hacked/</link>
		<comments>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wyndham-hotels-gets-hacked/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 17:45:34 +0000</pubDate>
		<dc:creator>Xjlittle</dc:creator>
				<category><![CDATA[credit card theft]]></category>
		<category><![CDATA[cyber criminals]]></category>
		<category><![CDATA[cyber theft]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[super 8]]></category>
		<category><![CDATA[wyndham hotels]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wyndham-hotels-gets-hacked/</guid>
		<description><![CDATA[The Wyndham Hotel chain&#8217;s computer systems security team discovered in mid-September 2008 that the company&#8217;s central computer systems were infiltrated. The intruder gained access through a franchisee&#8217;s computer system and from there was able to access the central systems of Wyndham. Wyndham believe that as many as 41 properties may have been affected and about [...]]]></description>
				<content:encoded><![CDATA[<p>The Wyndham Hotel chain&#8217;s computer systems security team discovered in mid-September 2008 that the company&#8217;s central computer systems were infiltrated.  The intruder gained access through a franchisee&#8217;s computer system and from there was able to access the central systems of Wyndham.  Wyndham believe that as many as 41 properties may have been affected and about 21,000 people in Florida.</p>
<p>Wyndham immediately retained a qualified investigator to assess the problem and ensure that it was isolated and to strengthen and implement a stronger security system.  The Secret Service, credit card agencies and several state&#8217;s attorney general offices were also notified.  They are making an effort to contact all of the affected customers by working through the credit card companies.  It appears that only the credit card information was stolen without matching names and addresses.  Wyndham says:</p>
<blockquote><p>To ensure our customers’ card numbers were protected, we provided each of the payment card companies (American Express, Visa, Mastercard and Discover) with the actual card numbers that were accessed so that these payment card companies could take such action as they deemed appropriate to monitor the use of the cards.</p></blockquote>
<p>Wyndham does not keep social security numbers or other confidential identifying information and does not believe any identity theft has occured because of the breach.  The criminals did manage to get magnetic stripe information which contains the CVV code.  Card numbers with this code bring a higher price on the black market because it is easier to use the card in a fraudulent transaction.</p>
<p>When a stolen card is used that includes the cvv code the banks are responsible for the charges.  When there is only a card number and an expiration date used in the transaction which occurs in many online sales then the retailer is responsible.</p>
<p>If you believe that you may have been affected by the theft you can find more information <a href="http://www.wyndhamworldwide.com/customer_care/data-claim.cfm">here</a> to get more information.</p>
<p>-j</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/linux-lotus-domino/wyndham-hotels-gets-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
