<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2420408182672772611</id><updated>2012-02-16T04:27:13.589-08:00</updated><category term='test1'/><category term='test2'/><title type='text'>Information Security Short Takes</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blogxmltest.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://blogxmltest.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Bozidar Spirovski</name><uri>http://www.blogger.com/profile/08748842042511112038</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://4.bp.blogspot.com/_Hu1rpxRsqcU/Sx1nDHNUtEI/AAAAAAAAAYY/KrJCug2cYWM/S220/Bspirovski.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2420408182672772611.post-918234261856169067</id><published>2008-06-19T12:27:00.000-07:00</published><updated>2008-07-10T10:35:25.013-07:00</updated><title type='text'>Google's Ratproxy Web Security Tool for Windows</title><content type='html'>&lt;p&gt;In our previous post, we announced the new security tool - &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Google's&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;ratproxy&lt;/span&gt;. It functions as a proxy, much like &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;paros&lt;/span&gt;.&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Shortinfosec&lt;/span&gt; has compiled &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;ratproxy&lt;/span&gt; v1.51 on windows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;You can download compiled &lt;a href="http://spirovski.b.googlepages.com/ratproxy-1.51.exe"&gt;ratproxy-1.51.exe for Windows here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Verification sums:&lt;br /&gt;ratproxy-1.51.exe &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;SHA&lt;/span&gt;1SUM &lt;span style="font-family: courier new;"&gt;                  42&lt;/span&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6" style="font-family: courier new;"&gt;dbe&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;6&lt;/span&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7" style="font-family: courier new;"&gt;ffa&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;00a3987f32b19a7c6e9ca84240db157&lt;/span&gt;&lt;br /&gt;ratproxy-1.51.exe MD5SUM &lt;span style="font-family: courier new;"&gt;                     c41&lt;/span&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8" style="font-family: courier new;"&gt;acfd&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;5ab7874&lt;/span&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9" style="font-family: courier new;"&gt;dfef&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;3970ac52&lt;/span&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10" style="font-family: courier new;"&gt;eb&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;2a9b&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In order to run it, you need to download and install &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;cygwin&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;runtime&lt;/span&gt;, since &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;ratproxy&lt;/span&gt; is dependant on several &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;cygwin&lt;/span&gt; libraries. Do not forget to update your path variable to include c:\&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;cygwin&lt;/span&gt;\bin.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;Quickstart&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;To run it, use the following steps&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;create a report directory (&lt;tt&gt;&lt;tt style="font-weight: bold;"&gt;&lt;a id="How_to_run_the_proxy?"&gt;&lt;tt&gt;report_&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;outdir&lt;/span&gt;)&lt;/tt&gt;&lt;/a&gt;&lt;/tt&gt;&lt;/tt&gt;&lt;/li&gt;&lt;li&gt;type &lt;tt style="font-weight: bold;"&gt;&lt;a id="How_to_run_the_proxy?"&gt;&lt;tt&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;ratproxy&lt;/span&gt; -v &lt;report_outdir&gt; report_outdir -w report_filename&lt;report_outfile&gt; -&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;lfscm&lt;/span&gt;&lt;/report_outfile&gt;&lt;/report_outdir&gt;&lt;/tt&gt;&lt;/a&gt;&lt;/tt&gt;&lt;/li&gt;&lt;li&gt;reconfigure your browser to use proxy on address &lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;localhost&lt;/span&gt;:8080&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Start browsing, &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;ratproxy&lt;/span&gt; will create reports. &lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Report parsing&lt;/span&gt;&lt;br /&gt;Copy the report generator from this location, and create a file from the text. It's a bash script, so You should run it from a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;cygwin&lt;/span&gt; shell. Make sure that it's a UNIX formatted file (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;LF&lt;/span&gt;/CR), otherwise the shell will report errors.&lt;br /&gt;&lt;a href="http://code.google.com/p/ratproxy/source/browse/trunk/ratproxy-report.sh?r=9"&gt;http://code.google.com/p/ratproxy/source/browse/trunk/ratproxy-report.sh?r=9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It creates a HTML report from the raw report generated by &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;ratproxy&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Related posts&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/07/ratproxy-google-web-security-assessment.html"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;Ratproxy&lt;/span&gt; - Google Web Security Assessment Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;Talkback&lt;/span&gt; and comments are most welcome&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2420408182672772611-918234261856169067?l=blogxmltest.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blogxmltest.blogspot.com/feeds/918234261856169067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2420408182672772611&amp;postID=918234261856169067' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/918234261856169067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/918234261856169067'/><link rel='alternate' type='text/html' href='http://blogxmltest.blogspot.com/2008/06/ttt.html' title='Google&apos;s Ratproxy Web Security Tool for Windows'/><author><name>Bozidar Spirovski</name><uri>http://www.blogger.com/profile/08748842042511112038</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://4.bp.blogspot.com/_Hu1rpxRsqcU/Sx1nDHNUtEI/AAAAAAAAAYY/KrJCug2cYWM/S220/Bspirovski.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2420408182672772611.post-1657712981998780314</id><published>2008-06-19T12:26:00.000-07:00</published><updated>2008-07-10T10:36:33.031-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='test2'/><category scheme='http://www.blogger.com/atom/ns#' term='test1'/><title type='text'>Information theft - Minimize targets of opportunity</title><content type='html'>&lt;p&gt;Information theft is not always a planned and systematic process. A lot of people can become attackers should an opening present itself, for a several motives, most frequently greed. To minimize such incidents, a company needs to be vigilant against "targets of opportunity" within their company.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;By a military definition, a&lt;/strong&gt; &lt;strong&gt;target of opportunity is&lt;/strong&gt; a visible target within range of available weapons against which attack has not been scheduled or planned.&lt;br /&gt;&lt;strong&gt;Similarly, by an information security definition, a target of opportunity&lt;/strong&gt; is an unmonitored information carrier resource within grasp that not been scheduled or planned for theft.&lt;br /&gt;&lt;br /&gt;Under both definitions, an attacker might decide that the target is valuable enough to be taken, and performs an attack.&lt;br /&gt;&lt;strong&gt;Information Targets of opportunity can take many forms:&lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Unattended confidential documents left in an unmonitored environment&lt;/strong&gt; (on the desk in an empty office, in the coffee room, on the network printer, on the photocopier...&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Unattended information carriers&lt;/strong&gt; (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;USB&lt;/span&gt;, CD-ROM, &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;smart card&lt;/span&gt;, laptop) left in an unmonitored environment. Stolen for any purpose, most simply because &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;USB's&lt;/span&gt; can be used or sold. Whatever is contained therein is additional value&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Unlocked (and open) documentation cabinets &lt;/strong&gt;in visitor accessible spaces. All it takes is for someone to reach in and grab a set of papers, for later review.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Unattended key chains &lt;/strong&gt;with keys to documentation cabinets - simple walking and taking a key-chain can go utterly &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;unnoticed&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Unattended Laptops in public spaces &lt;/strong&gt;(left in airport lounges, cafes, malls unmonitored laptops can easily be stolen, simply for the face value of a computer. Any information contained therein is additional value&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improper transport or transport by unauthorized personnel &lt;/strong&gt;of systems from IT to the business or from the business to IT - unmonitored systems due to improper transport can be stolen or dismantled, simply for the face value of the components. Any information contained therein is additional value&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;There is no systematic method to deem which targets will be deemed valuable enough by which attackers, so a company needs to cover all possible bases.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Controls to minimize Information Targets of opportunity&lt;/strong&gt;:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Create and rigidly enforce formal company procedures for clear desk policy &lt;/strong&gt;(no &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;unnecessary&lt;/span&gt; documents left on the desk) &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Create and rigidly enforce a formal company procedure for securing of all media &lt;/strong&gt;containing company information &lt;/li&gt;&lt;li&gt;&lt;strong&gt;If technically possible, encrypt content on all media &lt;/strong&gt;containing company information (especially &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;USB&lt;/span&gt; and Laptops)&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Where technically possible, implement self-locking document cabinets &lt;/strong&gt;with a non-contact lock, so there will be no keys left in the lock&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Where technically possible, implement authorized printing on network printers &lt;/strong&gt;- the person who printed a document has to authenticate on the physical printer before printing commences, thus confirming physical presence of the owner of printout.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Where legally allowed, implement video &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;surveillance&lt;/span&gt;&lt;/strong&gt;. Video surveillance is always an excellent deterrent for attacks of opportunity, since they are not systematic.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Create and rigidly enforce system transport &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;rule set&lt;/span&gt; &lt;/strong&gt;- who is authorized to take, transport and deliver a system from the business to IT and vice-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;versa&lt;/span&gt;. Never entrust an outsider with such transport, regardless of personal trust, unless formal contracts and security verifications are in place.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Related posts&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.shortinfosec.net/2008/06/risk-of-losing-backup-media-real.html"&gt;Risk of losing backup media - real example&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shortinfosec.net/2008/05/8-tips-for-securing-from-security.html"&gt;8 Tips for Securing from the Security expert&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;Talckback&lt;/span&gt; and comments are most welcome&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2420408182672772611-1657712981998780314?l=blogxmltest.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blogxmltest.blogspot.com/feeds/1657712981998780314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2420408182672772611&amp;postID=1657712981998780314' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/1657712981998780314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/1657712981998780314'/><link rel='alternate' type='text/html' href='http://blogxmltest.blogspot.com/2008/06/test2.html' title='Information theft - Minimize targets of opportunity'/><author><name>Bozidar Spirovski</name><uri>http://www.blogger.com/profile/08748842042511112038</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://4.bp.blogspot.com/_Hu1rpxRsqcU/Sx1nDHNUtEI/AAAAAAAAAYY/KrJCug2cYWM/S220/Bspirovski.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2420408182672772611.post-4605680949273318818</id><published>2008-05-02T12:05:00.000-07:00</published><updated>2008-05-02T12:06:02.257-07:00</updated><title type='text'>post1</title><content type='html'>sdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfk&lt;br /&gt;&lt;ol&gt;&lt;li&gt;sdfklasjdfkaj;sdfksdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;/ol&gt;sdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfk&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;sdfklasjdfkaj;sdfksdfklasjdfkaj;sdfksdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;li&gt;sdfklasjdfkaj;sdfk&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2420408182672772611-4605680949273318818?l=blogxmltest.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blogxmltest.blogspot.com/feeds/4605680949273318818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2420408182672772611&amp;postID=4605680949273318818' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/4605680949273318818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2420408182672772611/posts/default/4605680949273318818'/><link rel='alternate' type='text/html' href='http://blogxmltest.blogspot.com/2008/05/post1.html' title='post1'/><author><name>Bozidar Spirovski</name><uri>http://www.blogger.com/profile/08748842042511112038</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://4.bp.blogspot.com/_Hu1rpxRsqcU/Sx1nDHNUtEI/AAAAAAAAAYY/KrJCug2cYWM/S220/Bspirovski.jpg'/></author><thr:total>0</thr:total></entry></feed>
