Monday, June 30, 2008

Monday News Feed 6/30/08

DC Goes for a Universal City ID Document
The District of Columbia has announced an ambitious plan to link multi-use documents to a centralized tracking system that would span a wide range of city services including summer jobs programs, public schools, attendance at public meetings, metro fare cards, and city health service offices. The citywide ID plan is proposed in a climate where a national ID debate is advanced under the scheme called REAL ID.
New ID Card Serves Students, Rec Centers, Libraries in D.C., Washington Post, June 27, 2008
Posted by EPIC on June 27, 2008.Permanent link to this item.






Pentagon Consulting Social Scientists on Security
This seems like a good idea:
Eager to embrace eggheads and ideas, the Pentagon has started an ambitious and unusual program to recruit social scientists and direct the nation’s brainpower to combating security threats like the Chinese military, Iraq, terrorism and religious fundamentalism.
The article talks a lot about potential conflicts of interest and such, and less on what sorts of insights the social scientists can offer. I think there is a lot of potential value here.
Posted on June 30, 2008 at 12:13 PM2 Comments
View Blog Reactions






Internet Explorer 6 Window "location" Handling Vulnerability - Moderately critical - From remoteIssued 4 days ago. Updated 3 days ago. Ph4nt0m Security Team has discovered a vulnerability in Internet Explorer 6, which can be exploited by malicious people to conduct cross-domain scripting attacks.







Internet Explorer 7 Frame Location Handling Vulnerability - Moderately critical - From remoteIssued 4 days ago. Updated 10 hours ago. sirdarckcat has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct spoofing attacks.






http://blogs.washingtonpost.com/securityfix/
Posted at 08:00 AM ET, 06/30/2008
Data Breach Reports Up 69 Percent in 2008
Businesses, governments and universities reported a record number of data breaches in the first half of this year, a 69 percent increase over the same period in 2007 driven by a spike in data thefts attributed to employees and contractors, according to an analysis by identity theft experts.
The San Diego-based Identity Theft Resource Center tracked 342 data breach reports from Jan. 1 to June 27. Nearly 37 percent of reports came from businesses -- an increase from almost 29 percent last year.






Breach-notification laws not working? Robert Lemos, 2008-06-25 Research fails to find a correlation between states with disclosure laws and reduced identity theft, suggesting the best defense for concerned citizens is to take action themselves.







EU advisors: Secure ISPs, form "cyber-NATO"News Brief, 2008-06-26Academic researchers tasked with making information-security recommendations to the European Union call for Internet service providers to clean up their networks and for the creation of a group to aid international investigations.






Controls? What controls?
Pentagon Worker Spent Tax MoneyOn Exotic Dancer, Prosecutors Say
By JOE HARRIS
ST. LOUIS (CN) - A Defense Department civilian employee and an exotic dancer charged more than $56,000 on the employee's Defense Department credit card, federal prosecutors say. Steven C. Brown, 49, of Godfrey, Ill., and the dancer, Teressa V. Shrum, 33, of Hannibal, Mo., were indicted on 20 felony counts of theft of public money.





Phone Phreak Rap: You're In Jail, and I'm Not
With Stuart Rosoff and his gang of SWATters all sentenced to up to five years in prison for sending cops bursting into the homes of their party line enemies, phone hackers and ersatz hip-hop artists Lucky225 and Lotus recorded this (.mp3) nerdcore track to taunt their convicted foes.






FBI access to private data in Europe pending
Richard Thurston June 30, 2008
The European Commission is said to be close to finalizing an agreement with the U.S. that would allow the FBI to see the credit card histories and internet browsing habits of European citizens.






Researchers reveal VoIP vulnerabilities
Sue Marquette Poremba June 27, 2008
VoIPshield Laboratories has alerted companies that market voice over IP systems of new security vulnerabilities.






Report: Montgomery Ward fails to alert victims of breach
Chuck Miller June 27, 2008
Mongomery Ward, an old-line merchant now operating as an internet retailer, suffered a breach of some 51,000 customer credit card numbers, and failed to report it to customers.








New PDF exploits: “Old wine in a new bottle!”
Thursday June 26, 2008 at 8:30 pm CSTPosted by Yichong Lin
No Comments
We came across some samples and some vendors claims that the these samples were exploiting the new PDF vulnerability CVE-2008-2641.
We took a look at this issue and found that this is not the case, it’s still exploiting the old vulnerability CVE-2007-5659, which is a buffer overflow vulnerability in JavaScript function Collab.collectEmailInfo in Adobe PDF Reader’s own JavaScript Engine.






Good Always Comes Out of Bad
Not sure I agree, but it's more reading about the Turkish hackers who grabbed ICANN's DNS records...

Friday, June 27, 2008

Friday News Feed 6/27/08

Hackers hijack critical Internet organizations Turkish hackers on Thursday managed to deface the Web sites of the international organizations that run the Internet's critical routing infrastructure and regulate domain names. Read more...

Turkish gang redirect ICANN, IANA traffic, taunt 'We control the domains!'




Web firewalls trumping other options as PCI deadline nears





'Vista Capable' lawyers bicker over document discovery





Researchers warn of IE6 zero-day bug





Avaya, Cisco and Nortel face VoIP vulnerabilities





Preventing SQL injection






Startup Promises to Slow Software Tampering - 6/25/2008 12:03:00 PM Metaforic says its anti-hacking tools aren't invulnerable, but definitely will make software exploits less fun





News from FIRST 2008: Driving Security Response Excellence and Innovation







Laptop Searches at Airports Raises Privacy Questions
TSA agents' search of air travelers' laptops is under scrutiny by the US Senate. The search of air travelers' luggage is routine, while the search of electronic devices is not. The practice by government agents at airports of accessing and copying the content of computers and other digital devices have raised 4th Amendment questions. The Senate Judiciary Subcommittee hearing Laptop Searches and Other Violations of Privacy Faced by Americans Returning from Overseas Travel explored the issue.
Laptop Searches in Airports Draw Fire at Senate Hearing, New York Times, June 26, 2008
Posted by EPIC on June 26, 2008.Permanent link to this item.






Carrier Pigeons Bringing Contraband into Prisons
In Brazil.
I think this is the first security vulnerability found in RFC 1149: "Standard for the transmission of IP datagrams on avian carriers." Deep packet inspection seems to be the only way to prevent this attack, although adequate fencing will prevent the protocol from running in the first place.
Posted on June 27, 2008 at 6:32 AM






Internet Explorer 7 Frame Location Handling Vulnerability - Moderately critical - From remoteIssued 1 day ago. sirdarckcat has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct spoofing attacks.






Internet Explorer 6 Window "location" Handling Vulnerability - Moderately critical - From remoteIssued 1 day ago. Updated 11 hours ago. Ph4nt0m Security Team has discovered a vulnerability in Internet Explorer 6, which can be exploited by malicious people to conduct cross-domain scripting attacks.






New PDF exploits: “Old wine in a new bottle!”







National health-record privacy law in Congress
Chuck Miller June 26, 2008
A new law in Congress would require every U.S. citizen to have electronic health records by 2014. It would also set up privacy rules for those records, requiring information keepers to notify patients of security breaches.






Privacy standards help safeguard online health data
Dan Kaplan June 26, 2008
Just a few months after Google and Microsoft announced they were launching online consumer health platforms, a nonprofit has unveiled a common framework to protect sensitive medical records.






Man's "Parrot Fever" Death Tests Products Liability Law
The family of a Texas man who allegedly died of a disease contracted from a sick cockatiel has sued PetSmart for wrongful death, but the fate of similar cases around the country suggests their products liability theory will not fly.
http://www.onpointnews.com/







Former White House Advisor: Hackers Didn't Cause 2003 Blackout
By Kevin Poulsen June 27, 2008 1:38:56 PMCategories: Cybarmageddon!
Cyber security consultant Paul Kurtz threw some cold water this week on a report that Chinese hackers caused the massive 2003 northeastern U.S. blackout. He worked for the White House at the time of the outage.






Marshall Islands email paralysed by 'zombie' attack AFP - Tue Jun 24, 6:42 AM ET
MAJURO (AFP) - Email communication in the Marshall Islands was paralysed Tuesday after hackers launched a "zombie" computer attack on the western Pacific nation's only Internet service provider, officials said.







Antispam Group Outlines Defenses to Block Botnet SpamPC World - Thu Jun 26, 9:40 AM ET
A major antispam organization is pushing a set of new best practices for ISPs to stop increasing volumes of spam generated by...






Russian hackers working inside China…






Summary: Chinese cyberwarfare threat by the Heritage Foundation






European Union Study Security Economics and The Internal Market By Grey McKenzie Today







Can Your Employer Read Your Personal Email After You Are No Longer Employed There?
from the questions-for-the-courts dept
While we already know that plenty of companies have systems in place to monitor your corporate email, what about your personal email accounts? And, just to make it more interesting, what about your personal email accounts after you are no longer employed at the firm? That's what's at stake in a new lawsuit, filed by a guy who was fired from a company, and later learned that they were reading his personal Yahoo email -- including messages he sent to his lawyer about responding to the firing.

Apparently, he left a computer at the office logged in to his Yahoo account, and that made it easy for the company to read his email -- and the company claims that since it's on a company computer, it's fair game. It's not exactly clear how he found out they were reading his email, however. Also, the company claims that the reason they looked at his email was because after getting fired, he used a computer (in plain view of other employees) to send himself various confidential company info. Even if that's true, it's not clear that the company should still be able to read emails in his personal account.







Nate McFeters: Another Trojan hits Mac OS X







Nate McFeters: Russian hackers planning attacks against Baltic countries and Ukraine






The World of Warcraft developer is announcing that it plans to release a "Blizzard Authenticator". It’s a keychain addition which gives all WoW players a six digit security code designed especially by the company to "help prevent unauthorized account access".






.confusion: ICANN opens up Pandora's Box of new TLDs
ICANN voted today on a measure that will allow businesses and other organizations to apply for almost any new top level domain they can think of. The organization believes the measure will help foster growth in online properties, despite some looming concerns about user frustration.
June 26, 2008 - 12:11PM CT - by Jacqui Cheng






Breach-notification laws not working? Robert Lemos, 2008-06-25 Research fails to find a correlation between states with disclosure laws and reduced identity theft, suggesting the best defense for concerned citizens is to take action themselves.






EU advisors: Secure ISPs, form "cyber-NATO"News Brief, 2008-06-26Academic researchers tasked with making information-security recommendations to the European Union call for Internet service providers to clean up their networks and for the creation of a group to aid international investigations.

Thursday, June 26, 2008

Thursday News Feed 6/26/08

Researchers warn of IE6 zero-day bug
Cross-site scripting flaw is variant of a bug reported to Microsoft in May
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9103859&taxonomyId=17&intsrc=kc_top





Fired Director of IT accused of destroying organ donor information of former company






http://www.wyff4.com/news/16710144/detail.html
GREENVILLE, S.C. -- Greenville County technical staff members told county council members Thursday that least five county-owned computers have been accessed illegally. Thursday's meeting included nine council members, but Councilman Tony Trout was not one of them.

The FBI has accused Trout of accessing information on county administrator Joe Kernell's computer as well as council chairman Butch Kirven's computer.







State attorney general becomes identity theft victim
http://www.kentucky.com/210/story/444133.html







Avaya, Cisco and Nortel face VoIP vulnerabilities






Cleaning Chinese malware sites a 'bigger challenge' than in U.S., says researcher






ISP backs off behavioral ad plan






Senators question border laptop searches






$1B market for meddling with DNS poses security problem






CNET employees notified after data breach

Wednesday, June 25, 2008

Wednesday Daily Feed 6/25/08

SQL Injection Attacks Exploiting Unverified User Data InputPosted Tuesday, June 24, 2008 11:35 AM by MSRCTEAM

New tools to block and eradicate SQL injection






Adobe Reader and Acrobat 8.1.2 Security Update


Vulnerability in Adobe Acrobat leads to public exploit
Dan Kaplan June 24, 2008
Adobe has updated its Reader and Acrobat products to shore up a major vulnerability that already is being exploited in the wild.






Using Google Earth to Find Unguarded Houses
UK teens are using Google Earth to find swimming pools they can crash.
How long before someone finds a more serious crime that can be aided by Google Earth?






Malicious Spam Traffic Triples in One Week - 6/25/2008 6:30:00 AM Sudden massive bot recruitment campaign by Srizbi botnet drives malicious spam up 9.9%, according to researchers at Marshal






The Difference Between Application and Session Layer Firewalls
by Ricky M. Magalhaes
Articles / Firewalls & VPNs
A review of the differences between Application and Session layer firewalls.






Two new Linux kernel vulnerabilities discovered & patched








Safari update fixes "carpet bomb" flawNews Brief, 2008-06-20Apple releases a patch for the Windows version of its browser, fixing four flaws including one that allows attackers to place an unlimited number of untrusted executable files on the desktop.






You Thought You Hated Windows? Check Out What Bill Gates Had To Say
from the classic dept
This one is getting passed around pretty quickly, but as he retires from Microsoft, we couldn't resist highlighting this fantastic internal email from Bill Gates complaining about the usability of some Windows features. It's old -- from 2003 -- but it's difficult to read it and not identify with some of the complaints.

Monday, June 23, 2008

Monday News Feed 6/23/08

Laptops break - Do your backups!





Flooded Firms Reassess Disaster Recovery Plans Executives from companies in Cedar Falls, Iowa, said they are assessing how the massive Midwestern floods are affecting their IT operations, and how it is forcing them to reassess disaster recovery plans. Read more...





Microsoft security fix clobbers 2 million password stealers






One-third of IT admins admit snooping with privileged passwords






Filling Out Forms: Still a Dangerous Game - 6/20/2008 5:00:00 PM Despite upgrades and fixes, most browsers are still vulnerable to attacks via Web forms, researcher says






Tech Insight: Finding Security-Sensitive Data – on a Shoestring Budget - 6/20/2008 2:50:00 PM Thanks to open-source tools, discovering the heart of your data doesn't always mean paying an arm and a leg






Fraud-Fighting Community Launches in US - 6/19/2008 5:40:00 PM Subscribers share information about fraudulent online transactions in online service






FCC moves ahead with plan for smut-free wireless broadband






Serious Security Vulnerabilty In Apple OS X Leopard
An unpatched security hole in Apple's OS X operating system could be used by attackers to change key system settings or to take control of vulnerable computers, security researchers warn.
In a posting to news-for-nerds site Slashdot.org on Wednesday, an anonymous reader noted that a core component of OS X 10.4 (Tiger) and 10.5 (Leopard) called Apple Remote Desktop Agent could be leveraged by any user on the machine to install new programs or alter important system settings. Generally, these tasks are reserved for only the "root" account -- the most powerful user account on the system -- or at the very least they require the user to first enter a password for the requested changes to take effect.







Researchers disclose Firefox 3 flawsNews Brief, 2008-06-19Looking to make a big splash, at least three researchers publish details of flaws a few hours after the release of Mozilla's latest browser.






SPY PICTURE: First image of Virgin Galactic SpaceShipTwo structure
http://www.flightglobal.com/articles/2008/06/21/224834/spy-picture-first-image-of-virgin-galactic-spaceshiptwo-structure.html






MPAA Explains Why Proof Shouldn't Be Necessary In Copyright Infringement Cases







Disgruntled hacker sentenced to five years
Sue Marquette Poremba June 20, 2008
A network engineer and technical services manager for San Diego's Council of Community Health Clinics was sentenced to 63 months in prison on federal hacking charges.






The Web's Dark Energy
By Jonathan Zittrain 0 Comments
Community policing can help make the Web safe.






Your Medical Data Online
By Amanda Schaffer 0 Comments
Google and Microsoft are offering rival programs that let people manage their own health information. Do potential users understand the risks?






Four Shanghai hackers admit to DoS extortion - promise not to do it again.






Bank Accounts And PINs Stolen Over Internet Reap Hackers Millions From Citibank By Grey McKenzie 06/20/2008

Friday, June 20, 2008

Friday News Feed 6/20/08

Apple does about-face, fixes Safari's 'carpet bomb' bug Apple has updated the Windows version of Safari, patching four flaws including one that prompted rival Microsoft to urge users to stop using Apple's browser. Read more...

Safari 3.1.2 for Windows released to address vulnerabilities






EBay boosts fraud protections for PayPal users






Fraudulent ATM transactions overseas could be tied to Indiana bank breach






Microsoft admits XP's Bluetooth patch didn't work






Mozilla investigates critical Firefox 3.0 bug
Windows, Mac and Linux versions all have the vulnerability
June 19, 2008 (Computerworld) Mozilla Corp. today downplayed a threat posed by the first vulnerability reported for Firefox 3.0, telling users that the risk is "minimal."
"There is no public exploit, the details are private, and so the risk to users is minimal," Window Snyder, Mozilla's chief security officer, said in an entry to a company blog.
...
Snyder was responding to news yesterday that 3Com Corp.'s TippingPoint, a security vendor that runs the Zero Day Initiative bug bounty program, had purchased a critical Firefox 3.0 vulnerability from an unnamed researcher and then forwarded information on the bug to Mozilla.






Nuance sues start-up Vlingo over speech recognition patent infringement
I wonder who their lawyers are... ;-)






Patch-blocking bug also stymies Microsoft's WSUS







Fraud-Fighting Community Launches in US - 6/19/2008 5:40:00 PM Subscribers share information about fraudulent online transactions in online service







ID Protection Startup Prepares Commercial Push - 6/19/2008 10:00:00 AM After completing identity theft study and numerous breach response engagements, Debix says it's good to go







Stolen Healthcare, Airline Credentials Found on Servers - 6/18/2008 5:45:00 PM Researchers at Finjan say cybercriminals are looking beyond stolen credit card accounts







Why Global Hackers Are Nearly Impossible to Catch
livescience.com — They're in our computers, reading our files. The Chinese government, that is, according to two U.S. Congressmen who recently accused Beijing of sending hackers to ferret out secret documents stored on Congressional computers. The Chinese deny any involvement, but if they were lying, would we be able to prove it?More… (Security)







Teens Charged With Loading Spyware, Changing GradesPC World - Wed Jun 18, 8:30 PM ET
Two Orange County teenagers have been charged with breaking into school computers, installing spyware and altering grades.






MS08-030 Re-released for Windows XP SP2 and SP3








Federal Court Limits Employers' Access to Employees' E-Communications
The 9th Circuit Court upheld the workplace privacy rights of employees in its decision in Quon v. Arch Wireless. Sgt. Jeff Quon and 3 other officers sued Arch Wireless for sharing wireless communication records with their employer, the Ontario Police Department. The City contracted for text messaging service for employees, and later obtained records to investigate whether all communications were work related. The court's decision reversed a lower court ruling, and found that the carrier was in violation of the 4th Amendment and California constitutional guarantees.
Court limits employer access to worker messages, Associated Press, June 19, 2008
Posted by EPIC on June 19, 2008.Permanent link to this item.







Citibank to Replace ATMs Following Crime Spree
http://blogs.washingtonpost.com/securityfix/
One of my sources, the other day, tipped me off that Citibank was in the process of replacing most of its automated teller machines (ATMs), but the source couldn't definitively say why. Citibank told ATM & Debit News that it was replacing some 2,000 proprietary ATMs in "a bid to improve customer service." But a story today by Wired.com reporter Kevin Poulsen suggests that the financial giant is responding to a computer intrusion into a Citibank server that processes ATM withdrawals, an incident that appears to have led to an ATM crime spree.







FISA deal worries privacy groupsNews Brief, 2008-06-18Congressional leaders are reportedly close to a compromise on revamping the Foreign Intelligence Surveillance Act and allowing telecoms a way to sidestep wiretapping lawsuits.







...And worth every penny...
Windows Live OneCare 2.0 Available for Free

Microsoft is indeed offering Windows Live OneCare 2.0 for free, but only the 90-day trial period version. However, the fully fledged security solution can be grabbed from Amazon.com for a total cost of $0. The official price of the product is $49.95. But the actual deducted price is just $30, the e-commerce website offering no less than 40%, or $19.95 off. But in addition to the discount, Amazon.com has also set up a rebate of no less than $30, e...







AP: China admits taking, burying US POW (AP)







Local root escalation vulnerability in Mac OS X 10.4 and 10.5 discovered








Breaking News… NOT!
Friday June 20, 2008 at 4:18 am CSTPosted by Kevin McGhee
No Comments
There mustn’t be much going on in the world today as the Nuwar spammers have moved from jumping on real news of natural disasters and current affairs to creating their own fictional events! This high volume spam campaign is using some wacky subjects to lure people into clicking on the links:

Subject: Britney found hanged in locker room
Subject: White House hit by lightning, catches fire
Subject: Oprah found sleeping the streets
Subject: Eiffel Tower damaged by massive earthquake
Subject: Donald Trump missing, feared kidnapped
Subject: Lastest! Obama quits presidential race

This clever social engineering technique plays on peoples inquisitiveness in news of natural disasters and celebrities. The emails also follow the simple format of some text and a link that looks fairly harmless to the uneducated user.
All the links go to a fake pornotube page hosted on legitimate sites that have been hacked. If you click on the video (that’s actually just an image) it tries to download a .exe file. This is detected as BackDoor-DNM and the spam is also currently detected with our Anti-Spam products.
So it goes without saying.. NEVER click on links in an email unless you are sure of its origin, keep your Anti-Virus software up-to-date and if you have a website make sure its properly secured so you’re not hosting stuff like this.







Disgruntled hacker sentenced to five years
Sue Marquette Poremba June 19, 2008
A network engineer and technical services manager for San Diego's Council of Community Health Clinics was sentenced to 63 months in prison on federal hacking charges.







Kentucky Agrees To Stop Selectively Blocking State Employees From Reading Critical Blogs








Lame NHS loses 31,000 patient records
Michael Krigsman:Setting an example for irresponsibility while violating internal Department of Health policies, the UK National Health Service has lost unencrypted data on 31,000 patients.

Wednesday, June 18, 2008

Wednesday News Feed 06/18/2008

iPhone 3G's business-readiness still in question, Gartner says

On Friday, analyst Jack Gold, of J.Gold Associates LLC, issued a report citing security and support concerns regarding the iPhone 3G, concluding that it is "still coming up short for the enterprise." Gold said he was particularly concerned about the lack of native encryption to protect data on the device if it is stolen. Research in Motion Ltd. offers encryption of the data on its BlackBerries, and the latest versions of Windows Mobile and some other operating systems offer similar functionality, according to Gold

Dulaney said the new iPhone 3g has neither a firewall nor native encryption, "so banks and federal officials are not going to use it." He said Nokia Corp. has introduced native encryption on its E series devices, and he added that the iPhone 3G could eventually have something comparable, but so far it does not.






Blogging gets more dangerous as worldwide arrests triple A University of Washington study found that arrests of bloggers not affiliated with news organizations tripled from 2006 to 2007, mostly due to organizing or reporting on protest movements or exposing public corruption. Read more...






China quake fake in police custody





IBM's Roadrunner zooms to No. 1 on Top500 supercomputer list





Former 'spam king' must pay MySpace $6 million






Iowa floods forcing firms to race to keep IT afloat
June 17, 2008 (Computerworld) As historic floodwaters continue to hammer Cedar Falls, Iowa, local businesses are already assessing the environmental disaster's impact on IT operations, and how their disaster recovery plans are faring.

As of today, 100 blocks in the city's downtown are underwater and 3,900 homes have been evacuated in Cedar Falls.





Microsoft fixes patch-blocking bug
The problem, which Microsoft acknowledged late last Friday, affected administrators using System Center Configuration Manager (ConfigMgr) 2007 to update users' PCs running System Management Server (SMS) 2003 software.

System Center Configuration Manager 2007 is the successor to SMS 2003 that assesses, deploys and updates server and client computers.

According to Microsoft, customers with that combination had been unable to push June's security updates to end users' PCs. Those updates, which patched 10 vulnerabilities in Windows and Internet Explorer, were released on June 10.





June 17, 2008 Ex-official readies suit over bogus child porn rap
http://www.crime-research.org/news/17.06.2008/3417/
...“The overall forensics of the laptop suggest that it had been compromised by a virus,” said Jake Wark, spokesman for Suffolk District Attorney Daniel Conley.

Nationally recognized computer forensic analyst Tami Loehrs told the Herald Michael Fiola’s ordeal was “one of the most horrific cases I’ve seen.” “As soon as you mention child pornography, everybody’s senses go out the window,” she said. Loehrs, who spent a month dissecting the computer for the defense, explained in a 30-page report that the laptop was running corrupted virus-protection software, and Fiola was hit by spammers and crackers bombarding its memory with images of incest and pre-teen porn not visible to the naked eye.

Two forensic examinations conducted by the state Attorney General’s Office for the prosecution concurred with that conclusion, Wark said. Still, Fiola, 53, whose wife, Robin, described as “computer-illiterate,” wants his day in court. He intends to sue the DIA for “destroying our lives.”

“Our lives have been hell,” said Fiola, a former state park ranger now living in Rhode Island. “I hope to recover my reputation, but our friends all ran.”

DIA spokeswoman Linnea Walsh confirmed Fiola “was terminated,” but declined to say if any internal discipline has been meted out as a result of his name being cleared in court.“We stand by our decision,” she said.






Encryption: DLP's Newest Ingredient - 6/17/2008 6:00:00 PM Major vendors increasingly add encryption offerings to their data loss prevention packages





New DNS Trojan Hacks Home Routers - 6/17/2008 5:40:00 PM Researchers discover new variant of DNSChanger that changes DNS settings in home routers





Olympics Part II
On June 16th we published a short diary asking for comments about the dangers of bringing laptops, PDAs, cell phones, etc. to China if you are planning to attend the Olympics in August. We've received a number of interesting comments and I want to share two of them with our readers.

"...I can say that senior scientists and engineers employed by great Asian nations have not been bringing any laptops/notebooks/gadgets to said meetings (in the US). When they carry cel phones/PDAs, these are all scrupiously powered off and tucked out of sight, prior to entering "foreign" (to them) corporate campuses. It is a parking lot ritual of sorts that I have personally witnessed. "






Online Terror Threats Result in Jail Time
A federal court sentenced a Wisconsin man to 6 months in jail plus house arrest for false online threats. 14-Jun-2008







Dallas Airport's Very Revealing Passenger Screening
The Dallas Fort Worth International Airport is testing two millimeter wave whole body imaging machines on travelers. The technology allows a very detailed view of what is under clothing. Unlike an x-ray which penetrates skin, this technology does not. The technology also known as Backscatter X-Ray has been called a virtual strip-search.
New security scan at DFW Airport has privacy advocates worried, Dallas Morning News, June 16, 2008
Posted by EPIC on June 16, 2008.Permanent link to this item.







Magnetic Ring Attack on Electronic Locks
Impressive:
The 'ring of the devil' is capable of attacking this kind of electronic motor lock on two ways.





From http://www.schneier.com/blog/
In reality, forcing lenders to verify identity before issuing credit is exactly the sort of thing we need to do to fight identity theft. Basically, there are two ways to deal with identity theft: Make personal information harder to steal, and make stolen personal information harder to use. We all know the former doesn't work, so that leaves the latter. If Congress wanted to solve the problem for real, one of the things it would do is make fraud alerts permanent for everybody. But the credit industry's lobbyists would never allow that.






from http://blogs.washingtonpost.com/securityfix/
...
Out of the 15,000 spam-advertised domains we examined, nearly half -- 7,142 names -- were registered through a Broomfield, Colo. company called Dynamic Dolphin. As I noted in my previous story, Dynamic Dolphin is the seventh most-popular registrar among spammers who provide patently false information in their public WHOIS records.

Dynamic Dolphin is owned by a company called CPA Empire, which in turn is owned by Media Breakaway LLC. The CEO of Media Breakaway is none other than Scott Richter, the once self-avowed "Spam King" who claims to have quit the business. Anti-spam groups also have recently implicated Media Breakaway in the alleged hijacking of more than 65,000 Internet addresses for use in sending e-mail and hosting commercial Web sites.
...
Continue reading this post »»






"Web traffic volumes will almost double every two years from 2007 to 2012, driven by video and web 2.0 applications, according to a report from Cisco Systems. Cisco's Visual Networking Index (PDF) predicts that visual networking will account for 90 per cent of the traffic coursing through the world's IP networks by 2012. The upward trend is not only driven by consumer demand for YouTube clips and IPTV, according to the report, as business use of video conferencing will grow at 35 per cent CAGR over the same period."







"Craig Wright discovered that the Jura F90 Coffee maker, with its honest-to-God Jura Internet Connection Kit, can be taken over by a remote attacker, who can cause the coffee to be weaker or stronger; change the amount of water per cup; or cause the machine to require service (call this one a DDoC). 'Best yet, the software allows a remote attacker to gain access to the Windows XP system it is running on at the level of the user.' An Internet-enabled, remote-controlled coffee-machine and XP backdoor — what more could a hacker ask for?"







How to repair a dropped Wi-Fi signal on Vista laptops







Virginia Won't Stop Publishing People's Social Security Numbers; But Will Fine You For Republishing Them







Vendor IT security software revenue increases
Dan Kaplan June 17, 2008
Fueled by continued compliance demands and an evolving threat landscape, global software security revenue totaled $10.4 billion last year, a jump of nearly 20 percent, an analyst firm said Tuesday.





Breaking Phone-Call Encryption
By Erica NaoneTuesday, June 17, 2008
A data compression scheme could leave Internet phone calls vulnerable to eavesdroppers.






Bogus Domain Registrar Scamming Small Business, FTC Says







Anonymouse proxy now blocked in PRC






Stolen Medical, Business and Airline Data Discovered on Crimeware Servers in Argentina and Malaysia By Grey McKenzie Today






Islamic Jihad Adds Cyber-War Division To Its Armed Al-Quds Brigades By Grey McKenzie Today