Welcome!
My new blog has been launched today. This is intended to be a compilation of musings and thoughts with a rough focus on security and privacy. The idea is to provide analysis, commentary and geekspeak translations of news, events, and happenings in the security and technology arenas.
Feel free to comment and reply, the idea is to dialog.
You can read new posts on this blog via the RSS feed.
-J-
Musings - Geek speak elucidations
Bandwidth Hoggin'
2008-04-04 13:25
Two of the most often overlooked aspects of network security are those of reliability and availability...
Do you know how much usable bandwidth you have to the internet? Bandwidth is the amount of data you can upload or download through your internet connection. USABLE bandwidth is the amount of data you can upload or download right now: with all of your email, web browsing, downloads and other communications traffic running across it.
We've recently encountered a couple of situations where the usable bandwidth was so small that email was not coming in and users couldn't open web pages. The culprit? Internet Hogs! Specifically, streaming music and video web sites.
Think of bandwidth as a pipe with water flowing through it: the larger the pipe, the more water can fit through. However, even the largest pipe can be useless to you if the water coming through it is being used by...
>>
———
IFRAME attack underway
2008-04-02 10:30
IFRAME attack
There is a major attack underway that has compromised a slew of well known U.S. websites including (but not limited to) USAToday.com, ABCNews.com, News.com, Target.com, Walmart.com, Bloomingdales.com, WebShots.com, Sears.com, Forbes.com, Circuitcity.com, Epinions.com, JCPenney.com, and those for the University of Vermont and Boise State University.
The iFrame code on these and other sites has been modified to install a number of malicious programs under the guise of codecs (audio/video program files) and security software. This originally appeared to be initiated only when the compromised site searched using the sites internal search features, but is now being reported to be redirecting to malware download pages when the site comes up in a search engine.
I recommend that network administrators block the 4 IP addresses that the malicious code is downloaded from...
>>
Rants - Tech savvey explications
IE 0 Day Exploit
2008-12-12 19:27
Microsoft reported a new "zero-day exploit" that affects most versions of the Internet Explorer browser. A zero-day exploit is a security vulnerability that is being exploited before the software vendor or public know that the issue exists. This particular exploit attacks flaws within Internet...
>>
———
Spoofed NDR issues
2008-04-14 13:05
We've seen a rash of NDR (non-Delivery Response) floods happening to our clients. In all cases, it appears that the spam being NDRed is spoofed, but we are receiving reports from these users that they are being black listed on spam filters.
Is anyone else seeing this problem?
Thanks,
-J-
>>
———


