<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Nerds On Site Blog &#124; Business Technology Partners &#124; IT Support &#187; Cybersecurity</title>
	<atom:link href="http://www.nerdsonsite.com/blog/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nerdsonsite.com/blog</link>
	<description>Nerds On Site - Local Nerds... Powered by a Global TEAM</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:11:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Nerds On Site Client Podcast. We interview Nerds On Site SME clients about what they do and how they make sure of technology to increase their business productivity!</itunes:summary>
	<itunes:author>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile.jpg" />
	<itunes:owner>
		<itunes:name>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:name>
		<itunes:email>nerdcast@nerdsonsite.com</itunes:email>
	</itunes:owner>
	<managingEditor>nerdcast@nerdsonsite.com (Nerds On Site Blog | Business Technology Partners | IT Support)</managingEditor>
	<copyright>Copyright 2009 Nerds On Site Inc.</copyright>
	<itunes:subtitle>Nerds On Site - Local Nerds... Powered by a Global TEAM</itunes:subtitle>
	<itunes:keywords>nerds on site, nerds, nerd, podcast, client</itunes:keywords>
	<image>
		<title>Nerds On Site Blog | Business Technology Partners | IT Support &#187; Cybersecurity</title>
		<url>http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile_128.jpg</url>
		<link>http://www.nerdsonsite.com/blog</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
		<item>
		<title>Security News  Stuff to Make You Say &#8220;Really?&#8221;</title>
		<link>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 13:28:44 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Cybersecurity]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5061</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &#60;br /&#62; Stuff to Make You Say &#8220;Really?&#8221; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Your grandmother could run a botnet. Really? You probably thought hacking skills and technical know-how were needed to be botmaster. Nope &#8211; just $2500 US, an email address, and a desire to do some evil. Don&#8217;t worry &#8211; Nana&#8217;s (probably) not herding bots, but it&#8217;s not because she lacks the necessary skills. This may explain [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &#60;br /&#62; Stuff to Make You Say &#8220;Really?&#8221; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &lt;br /&gt; Stuff to Make You Say &#8220;Really?&#8221; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F23%2Fsecurity-news-stuff-to-make-you-say-really%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F23%2Fsecurity-news-stuff-to-make-you-say-really%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/older-people-bo-computer.jpg" rel="shadowbox[sbpost-5061];player=img;" title="older-people-bo-computer" rel="lightbox[5061]"><img class="alignleft size-full wp-image-5063" style="margin: 15px;" title="older-people-bo-computer" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/older-people-bo-computer.jpg" alt="" width="235" height="201" /></a><a href="http://www.net-security.org/secworld.php?id=9015" target="_blank">Your grandmother could run a botnet</a>. Really? You probably thought hacking skills and technical know-how were needed to be botmaster. Nope &#8211; just $2500 US, an email address, and a desire to do some evil. Don&#8217;t worry &#8211; Nana&#8217;s (probably) not herding bots, but it&#8217;s not because she lacks the necessary skills.</p>
<p>This may explain why <a href="http://www.theregister.co.uk/2010/03/15/cybercrime_complaint_surge/" target="_blank">cyber crime losses almost doubled last year</a>. The number of web-based botnets doubled in the second half of 2009 and web-based bodnets now outnumber the &#8220;old school&#8221; irc-based botnets. Really? Yeah, really.</p>
<p>You might want to hold off on Firefox 3.6 for a while. Really? There is a <a href="http://secunia.com/advisories/38608/" target="_blank">known vulnerability </a>that will not be patched until March 30.</p>
<p>100% guaranteed malware detection? Really? That is the claim that <a href="http://www.fatskunk.com/" target="_blank">Dr. Markus Jakobsson makes for his new technique</a>. He is being taken seriously by some major companies, too. This is a nerdy read, but an interesting one.</p>
<p><a href="http://www.computerworlduk.com/management/security/data-control/news/index.cfm?newsId=19351" target="_blank">Humans are still the weak link in security.</a> Really? That&#8217;s not exactly big news, but it is worth repeating.</p>
<p>Lock down the security on that&#8230;&#8230;<a href="http://www.thestar.com/news/gta/article/781567--high-tech-copy-machines-a-gold-mine-for-data-thieves" target="_blank">copier?</a> Really? Think about it &#8211; high end all-in-one office machines are copiers, scanners, and printers. They often have hard drives containing TONS of sensitive data and they are generally not on the radar screen when it comes to security. Permissions are often wide open. The next time you visit your SME clients, CHECK THE COPIER! If it has a hard drive, there is probably a lot of stuff on there that your client would like to keep private.</p>
<p>Takin&#8217; names and kickin&#8217; a** &#8211; Really?<a href="http://www.krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/" target="_blank">Publicizing the names of ISPs that allow their clients to do mischief</a> is one way to get them to stop taking money from the bad guys &#8211; at least in places where people care about that sort of thing.</p>
<p>One more time &#8211; be careful where you put that payment card. Really? <a href="http://www.theregister.co.uk/2010/03/15/fradulent_payment_card_processors/" target="_blank">Here</a> is another case of credit card fraud involving fake PIN pads that were planted in a chain of stores in the UK. Actually, the fake pads were visually identical to real ones, so no amount care would have saved you. Some are now arguing that credit cards are safer than debit cards, since the crooks cannot empty your bank account and credit card companies provide more protections against credit fraud than against debit fraud, especially if a PIN number was entered. <a href="http://www.theregister.co.uk/2010/03/15/fradulent_payment_card_processors/" target="_blank">This article</a> explains further.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>March 23, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &lt;br /&gt; Stuff to Make You Say &#8220;Really?&#8221; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>From SANS &#8211; The Top Cybersecurity Risks</title>
		<link>http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/</link>
		<comments>http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 14:55:19 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Cybersecurity]]></category>

		<guid isPermaLink="false">http://nerdsonsite.com/blog/?p=4512</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/' addthis:title='From SANS &#8211; The Top Cybersecurity Risks '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>This will come as no big surprise to most of us, but the threat model for cybersecuriy has shifted considerably in the past couple years. Believe it or not, operating system security has gotten better. The number of vulnerabilities is down, and more people are getting automatic updates and keeping their operating systems patched. This [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/' addthis:title='From SANS &#8211; The Top Cybersecurity Risks ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/' addthis:title='From SANS &#8211; The Top Cybersecurity Risks '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F10%2F23%2Ffrom-sans-the-top-cybersecurity-risks%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2009%2F10%2F23%2Ffrom-sans-the-top-cybersecurity-risks%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This will come as no big surprise to most of us, but the threat model for cybersecuriy has shifted considerably in the past couple years. Believe it or not, operating system security has gotten better. The number of vulnerabilities is down, and more people are getting automatic updates and keeping their operating systems patched. This is the good news. By far the most common threats exploiting Windows vulnerabilities are variants of the Conficker / Downadup virus, which exploits a hole patched almost a year ago. Unfortunately, there are still lots of un-patched systems left to infect. Amazingly, Sasser and Blaster, those worms of old from 2003 an 2004 are still infecting unpatched systems!</p>
<p>Now for the bad news &#8211; the attacks have shifted to applications and web vulnerabilities. Applications that are exposed to the web, such as browser plugins like flash, and applications that open files that are commonly downloaded from the web, such as Quicktime and Acrobat Reader, have been a common source of infection. Most users and organizations are less likely to keep these applications up to date because they do not understand the risks.</p>
<p>Worse yet &#8211; websites are positively under siege. Password guessing attacks have become more prevalent, as have web application attacks, such as SQL injection attacks, PHP include attacks, and cross-site scripting attacks. Recently, many users with unpatched browsers were infected by simply visiting major commercial websites that were displaying malicious banner ads.</p>
<p>The final, an most disturbing, piece of bad news &#8211; social engineering, phishing, and spear phishing attacks are on the rise and have become even more sophisticated.</p>
<p>What do we do to help protect ourselves and our clients? First, check for unpatched applications in addition to checking for OS patches. We have discussed Secunia PSI in past Security Corner articles, but I want to do another article on it soon &#8211; it is a great tool for finding unpatched applications running on systems. Second, educate, educate, and then educate some more. Remind clients at every opportunity that the weakest link is always the users. We don&#8217;t want to be fear mongers or make people paranoid, but everyone must be aware and vigilant. Finally, web facing services MUST use strong passwords &#8211; this is the best defense against brute-force password guessing attacks.</p>
<p>Over the next couple of months, the Nerds On Site Security Team will be rolling out a number of services and tools to help you in this battle, including external and internal vulnerability scanning, regular port scanning for routers and gateways, intrusion detection and prevention, security policy creation and review, endpoint security, full-scale penetration testing, and user-awareness training.</p>
<p>If you have an interest in the changing security landscape, take a few minutes to look over <a href="http://www.sans.org/top-cyber-security-risks/" target="_blank">the latest report from SANS</a>.  it covers the period from September 2008 to August 2009.</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>October 3, 2009</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/' addthis:title='From SANS &#8211; The Top Cybersecurity Risks ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2009/10/23/from-sans-the-top-cybersecurity-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

