<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Nerds On Site Blog &#124; Business Technology Partners &#124; IT Support &#187; Security News</title>
	<atom:link href="http://www.nerdsonsite.com/blog/tag/security-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nerdsonsite.com/blog</link>
	<description>Nerds On Site - Local Nerds... Powered by a Global TEAM</description>
	<lastBuildDate>Sat, 04 Feb 2012 01:11:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>Nerds On Site Client Podcast. We interview Nerds On Site SME clients about what they do and how they make sure of technology to increase their business productivity!</itunes:summary>
	<itunes:author>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile.jpg" />
	<itunes:owner>
		<itunes:name>Nerds On Site Blog | Business Technology Partners | IT Support</itunes:name>
		<itunes:email>nerdcast@nerdsonsite.com</itunes:email>
	</itunes:owner>
	<managingEditor>nerdcast@nerdsonsite.com (Nerds On Site Blog | Business Technology Partners | IT Support)</managingEditor>
	<copyright>Copyright 2009 Nerds On Site Inc.</copyright>
	<itunes:subtitle>Nerds On Site - Local Nerds... Powered by a Global TEAM</itunes:subtitle>
	<itunes:keywords>nerds on site, nerds, nerd, podcast, client</itunes:keywords>
	<image>
		<title>Nerds On Site Blog | Business Technology Partners | IT Support &#187; Security News</title>
		<url>http://blog.nerdsonsite.com/wp-content/uploads/2009/04/2006_nerdmobile_128.jpg</url>
		<link>http://www.nerdsonsite.com/blog</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
		<item>
		<title>Dennis&#8217;s Security Corner Returns &#8211; Cybercrime, Android Malware, and How Children Are Vulnerable Online</title>
		<link>http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/</link>
		<comments>http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 00:40:23 +0000</pubDate>
		<dc:creator>Kevin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[nerds on site]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=7869</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/' addthis:title='Dennis&#8217;s Security Corner Returns &#8211; Cybercrime, Android Malware, and How Children Are Vulnerable Online '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>The Security Corner has been quite for some time. Lots of other things competing for time.

I want to change the focus a bit - to alerting you to the security news that crosses my desk pretty much every day.<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/' addthis:title='Dennis&#8217;s Security Corner Returns &#8211; Cybercrime, Android Malware, and How Children Are Vulnerable Online ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/' addthis:title='Dennis&#8217;s Security Corner Returns &#8211; Cybercrime, Android Malware, and How Children Are Vulnerable Online '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2012%2F02%2F01%2Fdenniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2012%2F02%2F01%2Fdenniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>[this post is from Dennis Houseknecht, a Nerd in West Virginia, USA]</p>
<p>The Security Corner has been quite for some time. Lots of other things competing for time.</p>
<p>I want to change the focus a bit &#8211; to alerting you to the security news that crosses my desk pretty much every day.</p>
<p>For instance, here is one about how <a href="http://www.google.com/hostednews/ukpress/article/ALeqM5h6RPZleoyXkpaL1dRgt9M1kf8Ekg?docId=N0201421327858363145A" target="_blank">children are vulnerable to internet attacks</a> that everyone should read.</p>
<p>Here is an article about &#8220;malware&#8221; (or &#8220;<a href="http://www.net-security.org/malware_news.php?id=1981&amp;utm_source=Help+Net+Security+Daily+News&amp;utm_campaign=2a9461e828-RSS-hns&amp;utm_medium=email" target="_blank">aggressive adware</a>&#8220;, depending on who you want to believe) that is of interest to all Android users.</p>
<p>And here is one about personal data as the <a href="http://forumblog.org/2012/01/cybercriminals-main-commodity-personal-data/" target="_blank">main commodity of cyber criminals</a>.</p>
<p>Please share this post with your friends and family, as everyone can benefit with knowing about these issues.</p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/' addthis:title='Dennis&#8217;s Security Corner Returns &#8211; Cybercrime, Android Malware, and How Children Are Vulnerable Online ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2012/02/01/denniss-security-corner-returns-cybercrime-android-malware-and-how-children-are-vulnerable-online/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Old News or Old New News?</title>
		<link>http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 20:10:33 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Adobe Flash]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5128</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/' addthis:title='New Old News or Old New News? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>&#160; There is a major security vulnerability in Adobe Flash / Reader that is being actively exploited. Hmmm, that sounds familiar. Sorry to have to say &#8211; there is another one which was announced on Friday. You can find out more here. &#160; Here is another announcement that will seem familiar &#8211; this Tuesday&#8217;s patch [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/' addthis:title='New Old News or Old New News? ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/' addthis:title='New Old News or Old New News? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F06%2F07%2Fnew-old-news-or-old-new-news%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F06%2F07%2Fnew-old-news-or-old-new-news%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/06/flash.png" rel="shadowbox[sbpost-5128];player=img;" title="flash" rel="lightbox[5128]"><img class="alignleft size-thumbnail wp-image-5130" style="margin: 10px;" title="flash" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/06/flash-150x150.png" alt="" width="75" height="75" /></a></p>
<p>&nbsp;</p>
<p>There is a major security vulnerability in <strong>Adobe Flash / Reader</strong> that is being actively exploited. Hmmm, that sounds familiar. Sorry to have to say &#8211; there is another one which was announced on Friday. You can find out more <a href="http://www.computerworld.com/s/article/9177705/Update_Attackers_exploit_critical_bug_in_Adobe_s_Flash_Reader?source=rss_news" target="_blank">here</a>.</p>
<p>&nbsp;</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/06/microsoft-windows-vista-logo1-300x299.jpg" rel="shadowbox[sbpost-5128];player=img;" title="microsoft-windows-vista-logo1-300x299" rel="lightbox[5128]"><img class="alignleft size-thumbnail wp-image-5131" style="margin: 10px;" title="microsoft-windows-vista-logo1-300x299" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/06/microsoft-windows-vista-logo1-300x299-150x150.jpg" alt="" width="75" height="75" /></a></p>
<p>Here is another announcement that will seem familiar &#8211; this Tuesday&#8217;s patch cycle from <strong>Microsoft</strong> will be a <strong>BIG</strong> one &#8211; <em>34 vulnerabilities fixed</em> &#8211; at least three of which are critical. Make sure everyone gets updated.</p>
<p><a href="http://online.wsj.com/article/SB10001424052748703340904575284532175834088.html" target="_blank">Here</a> is some more news that&#8217;s not new. <strong>Smartphones are about to become the next frontier for malware</strong>. There&#8217;s an app for that!</p>
<p>In keeping with this theme, here is something that is (not) news &#8211; <a href="http://www.bankinfosecurity.com/articles.php?art_id=2601" target="_blank">Internal fraud</a> is a problem that continues to grow. Small businesses are especially vulnerable because they often do not have anti-fraud controls in place. Look for an upcoming article on preventing fraud in small businesses.</p>
<p>Well, that&#8217;s the recycled <strong>old news / new news.</strong> Why do we keep treading in the same circles? Because the bad guys are still bad and we just don&#8217;t pay enough attention to protecting ourselves. The next time you are face-to-face with an SME client, <strong>spend a little time talking about security.</strong></p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>June 7, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/' addthis:title='New Old News or Old New News? ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/06/07/new-old-news-or-old-new-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tidbits From the World of Infosec</title>
		<link>http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 20:10:21 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5084</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/' addthis:title='Tidbits From the World of Infosec '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Companies, System Administrators, (and your Clients) could all learn a lesson from the &#8220;Click-It or Ticket&#8221; campaign &#8211; launched a few years ago in the US to encourage the use of seat belts in automobiles to save lives. This article by Bruce Schneier discusses the fact that states with the strongest enforcement had the greatest [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/' addthis:title='Tidbits From the World of Infosec ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/' addthis:title='Tidbits From the World of Infosec '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F28%2Ftidbits-from-the-world-of-infosec%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F28%2Ftidbits-from-the-world-of-infosec%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/seat-belts.jpg" rel="shadowbox[sbpost-5084];player=img;" title="seat belts" rel="lightbox[5084]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/seat-belts-150x144.jpg" alt="" title="seat belts" width="150" height="144" class="alignleft size-thumbnail wp-image-5087" /></a>Companies, System Administrators, (and your Clients) could all learn a lesson from the &#8220;Click-It or Ticket&#8221; campaign &#8211; launched a few years ago in the US to encourage the use of seat belts in automobiles to save lives. <a href="http://www.schneier.com/blog/archives/2010/04/seat_belt_use_a.html" target="_blank">This</a> article by Bruce Schneier discusses the fact that states with the strongest enforcement had the greatest success. The amount of money spend on media advertising was a less important predictor of success. Of course, with security awareness, or with any other attempt to change behavior, it&#8217;s not an either / or proposition. The important point is that enforcement is a key component. Without it, rules have little benefit.</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/ipad.jpg" rel="shadowbox[sbpost-5084];player=img;" title="ipad" rel="lightbox[5084]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/ipad-150x134.jpg" alt="" title="ipad" width="150" height="134" class="alignleft size-thumbnail wp-image-5088" /></a>Of course, the popularity of the iPad has brought about a new attack vector for the purveyors of malware. <a href="http://www.crn.com.au/News/173074,backdoor-malware-targets-apple-ipad.aspx" target="_blank">The attack</a> does not actually affect the iPad, but is another way to trick Windows users into downloading malware. I suppose there is a touch of irony in using the iPad to attack Windows.</p>
<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=2241" target="_blank">This story</a> is a bit US-centric, but I suspect it&#8217;s only a matter of time until the same issue pops up in Canada and in other countries. The state of Massachusetts in the US has passed a law requiring ANYONE storing or transmitting Personally Identifiable Information about its residents to encrypt and protect that information. The fines for failing to do so are substantial. This is interesting because this law seeks to reach beyond the borders of the state. It will be interesting to see how this plays out in the courts over time. In any case, the growing problem is identity theft is likely to spawn similar laws around the world.</p>
<p>If you have clients who redact data from PDF documents before sending them, they should know that <a href="http://isc.sans.org/diary.html?storyid=8680&amp;rss" target="_blank">the &#8220;redacted&#8221; data may still be visible</a>.</p>
<p>In an other round of the ever-escalating &#8220;armor vs. ordinance&#8221; malware battle, some malicious websites are now able to <a href="http://www.h-online.com/security/news/item/Malware-hides-from-search-engines-986087.html" target="_blank">detect search engine &#8220;bots&#8221;</a> and hide the malware from them. Detecting malware on websites is a priority for Google and Firefox, who use APIs to blacklist malicious sites.</p>
<p>On another front of that same battle, <a href="http://krebsonsecurity.com/2010/04/fake-anti-virus-peddlers-outmaneuvering-legitimate-av/" target="_blank">fake malware vendors are gaining ground</a> and the legitimate AV products are having more difficulty detecting the &#8220;rogues&#8221;.</p>
<p>Breaches are going to happen. <a href="https://blogs.apache.org/infra/entry/apache_org_04_09_2010" target="_blank">Here</a> is an example of what a responsible dissemination of information looks like. Sadly, you rarely see this sort of transparency.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>April 28, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/' addthis:title='Tidbits From the World of Infosec ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/04/28/tidbits-from-the-world-of-infosec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bits and Bytes &#8211; News from the World of Security (and elsewhere)</title>
		<link>http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 15:03:28 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5078</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/' addthis:title='Bits and Bytes &#8211; News from the World of Security (and elsewhere) '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Zeus + PDF = another security challenge. PDF files have become one of the leading attack vectors on the internet, and everyone needs to know to be careful. Zeus, one of the nastiest banking trojans, is now being spread this way. &#8220;No updates for you!&#8221; Microsoft is a bit gun-shy after recent blue-screen problems that [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/' addthis:title='Bits and Bytes &#8211; News from the World of Security (and elsewhere) ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/' addthis:title='Bits and Bytes &#8211; News from the World of Security (and elsewhere) '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F21%2Fbits-and-bytes-news-from-the-world-of-security-and-elsewhere%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F21%2Fbits-and-bytes-news-from-the-world-of-security-and-elsewhere%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/Pdf-icon-logo.jpg" rel="shadowbox[sbpost-5078];player=img;" title="Pdf icon logo" rel="lightbox[5078]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/Pdf-icon-logo-150x150.jpg" alt="" title="Pdf icon logo" width="150" height="150" class="alignleft size-thumbnail wp-image-5076" /></a><a href="http://www.computerworld.com/s/article/9175612/Zeus_botnet_exploits_unpatched_PDF_flaw?source=rss_news" target="_blank">Zeus + PDF = another security challenge</a>. PDF files have become one of the leading attack vectors on the internet, and everyone needs to know to be careful. Zeus, one of the nastiest banking trojans, is now being spread this way.</p>
<p><a href="http://www.pcpro.co.uk/news/security/357262/microsoft-refuses-to-patch-infected-windows-xp-machines" target="_blank">&#8220;No updates for you!&#8221;</a> Microsoft is a bit gun-shy after recent blue-screen problems that were actually the result of underlying malware infections. Some new updates will not install if &#8220;certain abnormal conditions&#8221; exist in the kernel (a likely indication of a malware infection). Running &#8220;mrt&#8221; from the &#8220;Run&#8221; box on XP or from the search bar on Vista / W7 will remove most of these infections.</p>
<p><a href="http://www.computerworld.com/s/article/9175880/The_ultimate_guide_to_Windows_7_security?taxonomyId=89&amp;pageNumber=6" target="_blank">Here</a> is a good summary of the security features of W7 that we should all be familiar with.</p>
<p>Not many Nerds are big fans of <a href="http://www.computerworld.com/s/article/9175848/Norton_Internet_Security_2011_public_beta_attacks_new_dangers?source=rss_news" target="_blank">Norton Internet Security</a>, but it&#8217;s good to see what they are up to. The 2011 version has some interesting new features, which are likely to consume even more resources that with previous versions. The additional complexity will probably confuse users as well.</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/ie8-logo.png" rel="shadowbox[sbpost-5078];player=img;" title="ie8-logo" rel="lightbox[5078]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/ie8-logo-150x150.png" alt="" title="ie8-logo" width="150" height="150" class="alignleft size-thumbnail wp-image-5082" /></a><a href="http://blogs.zdnet.com/security/?p=6221" target="_blank">Fix a problem &#8211; create a bigger one</a>. Microsoft has incorporated cross-site scripting (XSS) protection into IE8, but researchers have found a way to turn this &#8220;fix&#8221; into an even bigger problem. Security is not easy.</p>
<p>In case you were wondering &#8211; yes, there are &#8220;security / spyware (depending on your perspective)&#8221; <a href="http://www.networkworld.com/news/2010/041910-your-blackberrys-dirty-little-security.html" target="_blank">apps for the Blackberry</a>.</p>
<p><a href="http://www.networkworld.com/news/2010/041910-your-blackberrys-dirty-little-security.html" target="_blank">Here are 3 reasons</a> employees break security rules: They don&#8217;t know about them, the rule are not enforced, and the rules hinder productivity.</p>
<p><a href="http://www.computerworld.com/s/article/9175780/Hot_spot_dangers_That_Internet_cafe_could_cost_you_way_more_than_a_cup_of_coffee_?taxonomyId=15&amp;pageNumber=1" target="_blank">Public networks + smart phones = business risk</a>. Everyone likes to be mobile, and what we used to call a &#8220;cell phone&#8221; is now a portable computer. The problem is, security on smart phones is often less robust and / or mis-configured.</p>
<p>Finally, <a href="http://broadcast.oreilly.com/2010/04/protecting-children-online---p-1.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+oreilly%2Fnews+%28O%27Reilly+News%29&amp;utm_content=Google+Reader" target="_blank">here</a> is a link to part two (so you can link back to part one) of a two-part series on protecting children online. It is a good summary and should be passed on to your clients who have young children.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>April 20, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/' addthis:title='Bits and Bytes &#8211; News from the World of Security (and elsewhere) ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/04/21/bits-and-bytes-news-from-the-world-of-security-and-elsewhere/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware the PDF</title>
		<link>http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 00:09:19 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5074</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/' addthis:title='Beware the PDF '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>PDF files have become the de-facto standard for sending documents. We think of them as being relatively innocuous because they are generally not editable. The specs for these documents are very powerful, though. Contained within these specifications is the power to run code within the document. If that sounds a little scary &#8211; it should. [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/' addthis:title='Beware the PDF ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/' addthis:title='Beware the PDF '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F07%2Fbeware-the-pdf%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F04%2F07%2Fbeware-the-pdf%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/Pdf-icon-logo.jpg" rel="shadowbox[sbpost-5074];player=img;" title="Pdf icon logo" rel="lightbox[5074]"><img src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/04/Pdf-icon-logo-150x150.jpg" alt="" title="Pdf icon logo" width="150" height="150" class="alignleft size-thumbnail wp-image-5076" /></a>PDF files have become the de-facto standard for sending documents. We think of them as being relatively innocuous because they are generally not editable. The specs for these documents are very powerful, though. Contained within these specifications is the power to run code within the document. If that sounds a little scary &#8211; it should.</p>
<p>PDF documents have become one of the most widely-used attack vectors for malicious code writers. This has been mostly related to security holes in the programs used to interpret .pdf files, specifically Adobe Acrobat Reader and (to a lesser degree) Foxit Reader. Most of these attacks can be thwarted by disabling the javascript execution features of these readers.</p>
<p>The native code-execution features of PDF files are supposed to be sandboxed. We have seen, though, that a &#8220;sandbox&#8221; is not the digital equivalent of a maximum-security prison. There have been several instances where Java code has managed to &#8220;escape&#8221; from the sandbox.</p>
<p>Recently, <a href="http://blog.didierstevens.com/2010/03/29/escape-from-pdf/" target="_blank">Didier Stevens</a> showed that it is possible to embed malicious code within .pdf files without relying on javascript. <a href="http://www.computerworld.com/s/article/9174904/Wormy_attack_could_spread_via_PDF?source=rss_news" target="_blank">Jeremy Conway</a> has also shown that it is possible to create PDF worms that can overwrite and infect other PDF files.</p>
<p>The bottom line &#8211; advise all clients to be very cautious about opening PDF files, especially those that are unexpected or from untrusted sources. Attacks have been surfacing in the wild and we may reach the point where even PDF files from trusted sources are a threat.</p>
<p>Both Adobe and Foxit are scrambling to address this issue. In most cases, Adobe (and now Foxit, with the latest patch) will warn before executing code, but the attacker can manipulate the text in the warning dialogue, so there will be efforts to trick users into allowing the code to execute. Warn clients about this!!!</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>April 07, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/' addthis:title='Beware the PDF ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/04/07/beware-the-pdf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More News for You&#8217;s</title>
		<link>http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 12:46:17 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5066</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/' addthis:title='More News for You&#8217;s '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>I sat down to write an article on Virtual Machine security / insecurity (coming soon), but there was just too much interesting news to pass up. Charlie Miller &#8211; hacking genius, good guy, or bad guy? Charlie Miller, perhaps the best-known white-hat hacker, took the $10,000 prize for the fastest compromise of OS X 10.6 [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/' addthis:title='More News for You&#8217;s ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/' addthis:title='More News for You&#8217;s '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F29%2Fmore-news-for-yous%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F29%2Fmore-news-for-yous%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/charlieMiller.jpg" rel="shadowbox[sbpost-5066];player=img;" title="charlieMiller" rel="lightbox[5066]"><img class="alignleft size-full wp-image-5068" style="margin: 15px;" title="charlieMiller" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/charlieMiller-e1269868011484.jpg" alt="" width="150" height="269" /></a>I sat down to write an article on Virtual Machine security / insecurity (coming soon), but there was just too much interesting news to pass up.</p>
<p><a href="http://www.computerworld.com/s/article/9174120/Pwn2Own_winner_tells_Apple_Microsoft_to_find_their_own_bugs?source=rss_news" target="_blank">Charlie Miller &#8211; hacking genius, good guy, or bad guy?</a> Charlie Miller, perhaps the best-known white-hat hacker, took the $10,000 prize for the fastest compromise of OS X 10.6 for the third year in a row. Charlie says he is fed up with the poor security practices from Apple, Microsoft , and Adobe. He is declining to reveal the flaws he has uncovered, but will tell the vendors how to find the vulnerabilities. He thinks they will benefit more from this than they would if he simply told them what the flaws are.</p>
<p>Charlie found most of these flaws by using a &#8220;dumb fuzzer&#8221; that he wrote. Vendors use fuzzers as well, but apparently Charlie&#8217;s is better.</p>
<p>We are always telling clients to update their applications, as well as their operating systems. The bad news is that there is now <a href="http://www.computerworld.com/s/article/9174126/New_malware_overwrites_software_updaters?source=rss_news" target="_blank">malware that overwrites software updaters</a>. This is doubly bad news &#8211; people will be infected by doing the &#8220;right thing&#8221; and updating. Worse, they will be afraid to update in the future because of the experience. Let&#8217;s hope that software vendors find a way to solve this problem quickly.</p>
<p><a href="http://www.mozilla.com/en-US/plugincheck/" target="_blank">Mozilla Plugin Check</a> is a place where you can go to check Firefox for the latest versions of plugins. Mozilla is going to take this service one step further and <a href="http://www.theregister.co.uk/2010/03/25/moz_plugin_security_check/" target="_blank">check other browsers as well.</a></p>
<p><a href="http://www.net-security.org/secworld.php?id=9063" target="_blank">Spam pays</a>. Why? Because even savvy users can&#8217;t resist the temptation to CLICK THOSE LINKS, OPEN THOSE ATTACHMENTS, AND FORWARD THAT MESSAGE ON TO INFECT OTHERS! People just won&#8217;t learn.</p>
<p>Another threat warn clients about: <a href="http://www.net-security.org/secworld.php?id=9065" target="_blank">Rogue toolbars.</a> Sheesh!</p>
<p>What are the <a href="http://www.networkworld.com/news/2010/031210-layer8-fbi-internet-scams.html?page=1" target="_blank">biggest scams on the internet</a>? Fake anti-virus popups are one of them, but I was shocked to see that &#8220;hitman&#8221; &#8220;pay me or I will kill you&#8221; scams are also on the list. Double sheesh!</p>
<p>If you want to read the sick stats on SPAM, <a href="http://www.messagelabs.com/mlireport/MLI_2010_03_Mar_FINAL-EN.pdf" target="_blank">here</a> is an article for you. What is the probability that a .rar email attachment is infected with malware? Almost 97%. Go figure. It not one of the most common malware-laced attachments, though. Those would be .xls, .doc, .zip, .pdf, .exe, .jpg, and .ppt.</p>
<p>I am looking for GOOD NEWS in the security world to match the title of the post, but not seeing much. I guess the Good News is that YOU are there to HELP your clients be the ones who STAY SAFE. Come to think of it, that really is Good News.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>March 29, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/' addthis:title='More News for You&#8217;s ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/03/29/more-news-for-yous/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News  Stuff to Make You Say &#8220;Really?&#8221;</title>
		<link>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 13:28:44 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Cybersecurity]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5061</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &#60;br /&#62; Stuff to Make You Say &#8220;Really?&#8221; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Your grandmother could run a botnet. Really? You probably thought hacking skills and technical know-how were needed to be botmaster. Nope &#8211; just $2500 US, an email address, and a desire to do some evil. Don&#8217;t worry &#8211; Nana&#8217;s (probably) not herding bots, but it&#8217;s not because she lacks the necessary skills. This may explain [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &#60;br /&#62; Stuff to Make You Say &#8220;Really?&#8221; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &lt;br /&gt; Stuff to Make You Say &#8220;Really?&#8221; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F23%2Fsecurity-news-stuff-to-make-you-say-really%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F23%2Fsecurity-news-stuff-to-make-you-say-really%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/older-people-bo-computer.jpg" rel="shadowbox[sbpost-5061];player=img;" title="older-people-bo-computer" rel="lightbox[5061]"><img class="alignleft size-full wp-image-5063" style="margin: 15px;" title="older-people-bo-computer" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/older-people-bo-computer.jpg" alt="" width="235" height="201" /></a><a href="http://www.net-security.org/secworld.php?id=9015" target="_blank">Your grandmother could run a botnet</a>. Really? You probably thought hacking skills and technical know-how were needed to be botmaster. Nope &#8211; just $2500 US, an email address, and a desire to do some evil. Don&#8217;t worry &#8211; Nana&#8217;s (probably) not herding bots, but it&#8217;s not because she lacks the necessary skills.</p>
<p>This may explain why <a href="http://www.theregister.co.uk/2010/03/15/cybercrime_complaint_surge/" target="_blank">cyber crime losses almost doubled last year</a>. The number of web-based botnets doubled in the second half of 2009 and web-based bodnets now outnumber the &#8220;old school&#8221; irc-based botnets. Really? Yeah, really.</p>
<p>You might want to hold off on Firefox 3.6 for a while. Really? There is a <a href="http://secunia.com/advisories/38608/" target="_blank">known vulnerability </a>that will not be patched until March 30.</p>
<p>100% guaranteed malware detection? Really? That is the claim that <a href="http://www.fatskunk.com/" target="_blank">Dr. Markus Jakobsson makes for his new technique</a>. He is being taken seriously by some major companies, too. This is a nerdy read, but an interesting one.</p>
<p><a href="http://www.computerworlduk.com/management/security/data-control/news/index.cfm?newsId=19351" target="_blank">Humans are still the weak link in security.</a> Really? That&#8217;s not exactly big news, but it is worth repeating.</p>
<p>Lock down the security on that&#8230;&#8230;<a href="http://www.thestar.com/news/gta/article/781567--high-tech-copy-machines-a-gold-mine-for-data-thieves" target="_blank">copier?</a> Really? Think about it &#8211; high end all-in-one office machines are copiers, scanners, and printers. They often have hard drives containing TONS of sensitive data and they are generally not on the radar screen when it comes to security. Permissions are often wide open. The next time you visit your SME clients, CHECK THE COPIER! If it has a hard drive, there is probably a lot of stuff on there that your client would like to keep private.</p>
<p>Takin&#8217; names and kickin&#8217; a** &#8211; Really?<a href="http://www.krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/" target="_blank">Publicizing the names of ISPs that allow their clients to do mischief</a> is one way to get them to stop taking money from the bad guys &#8211; at least in places where people care about that sort of thing.</p>
<p>One more time &#8211; be careful where you put that payment card. Really? <a href="http://www.theregister.co.uk/2010/03/15/fradulent_payment_card_processors/" target="_blank">Here</a> is another case of credit card fraud involving fake PIN pads that were planted in a chain of stores in the UK. Actually, the fake pads were visually identical to real ones, so no amount care would have saved you. Some are now arguing that credit cards are safer than debit cards, since the crooks cannot empty your bank account and credit card companies provide more protections against credit fraud than against debit fraud, especially if a PIN number was entered. <a href="http://www.theregister.co.uk/2010/03/15/fradulent_payment_card_processors/" target="_blank">This article</a> explains further.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>March 23, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/' addthis:title='Security News &lt;br /&gt; Stuff to Make You Say &#8220;Really?&#8221; ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/03/23/security-news-stuff-to-make-you-say-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security NewsStuff You Might Just Want to Know About</title>
		<link>http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 20:17:40 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5053</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/' addthis:title='Security News&#60;br /&#62;Stuff You Might Just Want to Know About '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>This USB battery charger from Eveready has been sold in the US and Europe since 2007. The software that comes with it includes a trojan that stays active, listening for commands on port 7777, even when the device is not connected. I aways found that cute bunny with the sunglasses to be a little suspicious. [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/' addthis:title='Security News&#60;br /&#62;Stuff You Might Just Want to Know About ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/' addthis:title='Security News&lt;br /&gt;Stuff You Might Just Want to Know About '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F08%2Fsecurity-newsstuff-you-might-just-want-to-know-about%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F08%2Fsecurity-newsstuff-you-might-just-want-to-know-about%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/energizer-bunny.jpg" rel="shadowbox[sbpost-5053];player=img;" title="energizer-bunny" rel="lightbox[5053]"><img class="alignleft size-thumbnail wp-image-5054" style="margin: 10px 15px;" title="energizer-bunny" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/energizer-bunny-150x150.jpg" alt="" width="150" height="150" /></a><a href="http://www.computerworld.com/s/article/9166978/Energizer_Bunny_s_software_infects_PCs" target="_blank">This USB battery charger</a> from Eveready has been sold in the US and Europe since 2007. The software that comes with it includes a trojan that stays active, listening for commands on port 7777, even when the device is not connected. I aways found that cute bunny with the sunglasses to be a little suspicious.</p>
<p>We trust Mr. Google to find us what we are looking for, but even the venerable Mr. Google gets attacked by the bad guys. It is called <a href="http://isc.sans.org/diary.html?storyid=8383&amp;rss" target="_blank">search engine poisoning</a>, and it can trap the unwary. Think before you click, and don&#8217;t always assume Mr. Google is right.</p>
<p>Anyone can digitally sign a file. The question is whether the digital signature traces back to a trusted Certificate Authority. Virus writers are becoming more sophisticated all the time, and some are now digitally signing their poison, making it look more official to those who are not careful about examining the signature. Fake signatures are easy to spot &#8211; IF you take the time to look. Your browser / OS will usually warn you as well, IF you pay attention. Education and awareness are still the best defense. More information can be found <a href="http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1462" target="_blank">here</a>.</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/Secunia_logo1.png" rel="shadowbox[sbpost-5053];player=img;" title="Secunia_logo" rel="lightbox[5053]"><img class="alignleft size-full wp-image-5056" style="margin: 15px;" title="Secunia_logo" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/Secunia_logo1.png" alt="" width="166" height="63" /></a>Patching is a real pain &#8211; that is no secret to any of you. I have recommended <a href="http://secunia.com/vulnerability_scanning/personal/" target="_blank">Secunia PSI</a> on numerous occasions for keeping third-party applications up to date. Secunia is <a href="http://www.theregister.co.uk/2010/03/05/secunia_patching_results/" target="_blank">working on an update</a> that will make these updates automatic. Easy is good.</p>
<p>Endpoint Security &#8211; clients need to gain control over all those portable devices (USB drives, smart phones, MP3 players, etc.) that come and go from the work place. Along with them, malware can come and sensitive data can go. <a href="http://www.computerworld.com/s/article/347196/Just_Watching_Is_No_Longer_Enough?source=rss_news" target="_blank">Here</a> is an article that offers more information. The GOOD NEWS is that Nerds On Site will soon be able to offer endpoint protection as part of NerdCare.</p>
<p>This last one is not security-related, but it is worth noting. Microsoft is <a href="http://www.computerworld.com/s/article/9166819/Microsoft_pulls_plug_on_business_server_package?source=rss_news" target="_blank">pulling the plug</a> on the Windows Essentials Business Server product.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>March 8, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/' addthis:title='Security News&lt;br /&gt;Stuff You Might Just Want to Know About ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/03/08/security-newsstuff-you-might-just-want-to-know-about/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News &#8211; helping you to help your clients stay safe</title>
		<link>http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 16:11:52 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.nerdsonsite.com/blog/?p=5046</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/' addthis:title='Security News &#8211; helping you to help your clients stay safe '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>DON&#8217;T press the F1 key &#8211; there is a current vulnerability in Windows XP / IE that has not been patched. If an attacker can convince the user to press the F1 (the default help key in Windows&#8230;well, you know the rest of the story. There is no definite word about when there will be [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/' addthis:title='Security News &#8211; helping you to help your clients stay safe ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/' addthis:title='Security News &#8211; helping you to help your clients stay safe '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F03%2Fsecurity-news-helping-you-to-help-your-clients-stay-safe%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F03%2F03%2Fsecurity-news-helping-you-to-help-your-clients-stay-safe%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/keys-F1.jpg" rel="shadowbox[sbpost-5046];player=img;" title="keys-F1" rel="lightbox[5046]"><img class="alignleft size-thumbnail wp-image-5051" style="margin: 10px 15px;" title="keys-F1" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/keys-F1-150x150.jpg" alt="" width="150" height="150" /></a>DON&#8217;T press the F1 key &#8211; there is a current <a href="http://www.computerworld.com/s/article/9164038/Microsoft_Don_t_press_F1_key_in_Windows_XP?source=rss_news" target="_blank">vulnerability in Windows XP / IE</a> that has not been patched. If an attacker can convince the user to press the F1 (the default help key in Windows&#8230;well, you know the rest of the story. There is no definite word about when there will be a patch available.</p>
<p>On a positive note, Microsoft has been taking the battle against botnets <a href="http://www.computerworld.com/s/article/9163238/Microsoft_to_target_other_botnets_with_legal_weapon?source=rss_news" target="_blank">to the courts</a>. Let&#8217;s hope that others follow suit. This certainly will not cure the problem, but it sure helps.</p>
<p>Thick clients, thin clients, and now&#8230;<a href="http://www.panologic.com/pano-device" target="_blank">zero clients.</a>. This device has no OS, no memory, no drivers. I simply connects a keyboard, mouse and display to a remote server via standard TCP/IP protocols. Now this is centralized management &#8211; and centralized security.</p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/Lenovo_ThinkPad_SL500_3.jpg" rel="shadowbox[sbpost-5046];player=img;" title="Lenovo_ThinkPad_SL500_3" rel="lightbox[5046]"><img class="alignleft size-thumbnail wp-image-5049" style="margin: 10px 15px;" title="Lenovo_ThinkPad_SL500_3" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/03/Lenovo_ThinkPad_SL500_3-150x150.jpg" alt="" width="150" height="150" /></a>Have a Lenovo Thinkpad? Don&#8217;t forget the supervisor password &#8211; Lenovo says the only fix is to <a href="http://www.theregister.co.uk/2010/03/01/thinkpad_password_reset_hard_luck/" target="_blank">replace the motherboard.</a>. Ouch!</p>
<p>Which is more secure &#8211; open source or commercial software? According to <a href="http://www.theregister.co.uk/2010/03/01/software_security_mot/" target="_blank">this article</a>, open source software is patched more quickly.</p>
<p>Could your use of social networking raise your insurance premiums? According to <a href="http://www.computerworld.com/s/article/9162919/I_don_t_bleepin_believe_it?source=rss_news" target="_blank">this article</a>, it could &#8211; at least in the UK.</p>
<p>Microsoft Security Essentials &#8211; it&#8217;s free, it&#8217;s good, but is it the REAL Security Essentials? Watch out, because there is a <a href="http://www.theregister.co.uk/2010/02/26/microsoft_security_essentials_rogue/" target="_blank">rogue pretending to be MS Security Essentials.</a>.</p>
<p>Another small <a href="http://wifinetnews.com/archives/2010/02/another_better_tkip_attack_thats_still_limited.html" target="_blank">chink</a> has appeared in the armor of WPA / TKIP. This protocol is still pretty secure, but best practice is now to move on to WPA2 and AES encryption.</p>
<p>Are <a href="http://www.computerworld.com/s/article/9162338/One_or_Two_Anti_Malware_Programs_?source=rss_news" target="_blank">two malware programs better than one?</a> Well, of course &#8211; we knew that (but then again, we know stuff).</p>
<p>Spam + drive-by download + Zeus = empty bank account. Watch out for fake IRS (Revenue Canada, etc.) <a href="http://www.scmagazineus.com/zeus-spreading-through-drive-by-download/article/158691/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+SCMagazineNews+%28SC+Magazine+News%29&amp;utm_content=Google+Reader" target="_blank">email messages</a>. Zeus is a nasty password-stealing trojan that has emptied many a bank account. It is also being spread through fake <a href="http://www.scmagazineus.com/new-version-of-zeus-targeting-aim-users/article/162090/" target="_blank">AIM updates.</a></p>
<p>Want to know more about how SQL injection attacks work? <a href="http://threatpost.com/en_us/blogs/anatomy-sql-injection-attack-022510" target="_blank">Here</a> is a good place to learn more. SQL injection attacks are among the most common web attacks.</p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>March 3, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/' addthis:title='Security News &#8211; helping you to help your clients stay safe ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/03/03/security-news-helping-you-to-help-your-clients-stay-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News More Stuff Worth Knowing</title>
		<link>http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/</link>
		<comments>http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 12:53:03 +0000</pubDate>
		<dc:creator>Dennis H in West Virginia, US</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Stuff Worth Knowing]]></category>

		<guid isPermaLink="false">http://nerdsonsite.com/blog/?p=4997</guid>
		<description><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/' addthis:title='Security News &#60;br/&#62;More Stuff Worth Knowing '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>Tomorrow is Patch Tuesday (again). This is going to be another big one &#8211; 13 patches, 5 of which are critical. Here is another reason that access to commercial bank accounts should be limited to computers that are used for nothing else. Online bank accounts should NOT be accessed by computers used for general-purpose web [...]<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/' addthis:title='Security News &#60;br/&#62;More Stuff Worth Knowing ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="addthis_toolbox addthis_default_style " addthis:url='http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/' addthis:title='Security News &lt;br/&gt;More Stuff Worth Knowing '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F02%2F09%2Fsecurity-news-more-stuff-worth-knowing%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.nerdsonsite.com%2Fblog%2F2010%2F02%2F09%2Fsecurity-news-more-stuff-worth-knowing%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/01/microsoft-logo11-e1264079947455.jpg" rel="shadowbox[sbpost-4997];player=img;" title="microsoft-logo1" rel="lightbox[4997]"><img class="alignleft size-thumbnail wp-image-4972" style="margin: 10px 15px;" title="microsoft-logo1" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/01/microsoft-logo11-e1264079947455-150x126.jpg" alt="" width="152" height="123" /></a><a href="http://www.networkworld.com/news/2010/020410-microsoft-slates-colossal-windows-patch.html?t51hb" target="_blank">Tomorrow is Patch Tuesday (again).</a> This is going to be another big one &#8211; 13 patches, 5 of which are critical.</p>
<p><a href="http://www.theregister.co.uk/2010/02/05/online_bank_heist/" target="_blank">Here is another reason that access to commercial bank accounts should be limited to computers that are used for nothing else.</a> Online bank accounts should NOT be accessed by computers used for general-purpose web surfing! Having a dedicated computer may seem like an extreme measure, but not to the City of Poughkeepsie, NY (at least not now)!! Instead of retiring that old desktop or laptop, install a hardened and restricted version of Linux and make it the only computer that has access to bank accounts.</p>
<p><a href="http://www.theregister.co.uk/2010/02/05/malicious_firefox_extensions/" target="_blank">We all love those Firefox add-ons, but watch out for the ones in the &#8220;experimental&#8221; section &#8211; user beware.</a></p>
<p><a href="http://www.itworld.com/security/95398/can-you-trust-chinese-computer-equipment" target="_blank">Made in China?  That may be a reason to think twice when it comes to hardware.</a></p>
<p><a href="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/02/800px-flag_of_the_red_cross-copy-Small.jpg" rel="shadowbox[sbpost-4997];player=img;" title="800px-flag_of_the_red_cross-copy (Small)" rel="lightbox[4997]"><img class="alignleft size-full wp-image-5006" style="margin: 10px 15px;" title="800px-flag_of_the_red_cross-copy (Small)" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2010/02/800px-flag_of_the_red_cross-copy-Small.jpg" alt="" width="90" height="60" /></a><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=222601178" target="_blank">Think banks and retailers are the biggest target for hackers?</a> Think again &#8211; think hotels and the hospitality industry. For those of you who have hotel clients, this is worth bringing to their attention.</p>
<p>Why should employers invest in the technology and your services to make SURE P2P and social networking are not part of the workplace? Show them <a href="http://www.networkworld.com/news/2010/020710-shmoocon-p2p-snoopers-know-whats.html" target="_blank">this</a> and <a href="http://www.computerworld.com/s/article/9153159/ShmooCon_Inside_FarmVille_s_sinister_underbelly" target="_blank">this</a>.</p>
<p><a href="http://www.networkworld.com/news/2010/020310-black-hat-wi-fi-attackers.html?t51hb" target="_blank">Think the dangers of public wifi are limited to the time you are connected to them?  Then you MUST read this.</a></p>
<p>This has NOTHING to do with security, and I by no means want to encourage anything you consider a bad habit, but some or you will consider this good news &#8211; <a href="http://www.theregister.co.uk/2010/02/08/beer_not_pop//" target="_blank">beer is good for your bones (but too much of it may lead to breaking them).</a></p>
<p>&nbsp;</p>
<p><strong><img class="alignleft size-full wp-image-4922" title="Dennis" src="http://www.nerdsonsite.com/blog/wp-content/uploads/2009/11/dennis.jpg" alt="Dennis" width="110" height="127" /></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Dennis H</strong> in West Virginia, US</p>
<p><strong>February 09, 2010</strong></p>
<div class="addthis_toolbox addthis_default_style addthis_32x32_style" addthis:url='http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/' addthis:title='Security News &lt;br/&gt;More Stuff Worth Knowing ' ><a class="addthis_button_preferred_1"></a><a class="addthis_button_preferred_2"></a><a class="addthis_button_preferred_3"></a><a class="addthis_button_preferred_4"></a><a class="addthis_button_compact"></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.nerdsonsite.com/blog/2010/02/09/security-news-more-stuff-worth-knowing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

