<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance&#187; malware</title>
	<atom:link href="http://blog.kraasecurity.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Thu, 12 Aug 2010 02:54:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Data Loss, this time with Network Solutions</title>
		<link>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</link>
		<comments>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/#comments</comments>
		<pubDate>Mon, 27 Jul 2009 16:55:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[stolen data]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/</guid>
		<description><![CDATA[Data Loss, this time with Network Solution Network Solutions, one of the largest domain registrars recently announced a data breach. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a [...]]]></description>
			<content:encoded><![CDATA[<h1>Data Loss, this time with Network Solution</h1>
<p>Network Solutions, one of the largest domain registrars recently announced a <strong>data breach</strong>. Malicious code was found on its e-commerce server which may have captured transactions from thousands of websites and capturing half a million or more credit cards. The company said they found the code during a routine check. Since the breach occurred between March 12 and June 8th, how routine was the actual checks? I wonder when their last vulnerability assessment or <a href="http://www.kraasecurity.com/">Information security risk assessment</a> was conducted? Data loss prevention is sorely lacking in just about every industry.</p>
<p>Here is what the company said &#8220;At this point, we have no reports or other reasons to believe that any credit card account information has been misused and, under established practice, credit card issuing companies generally will not hold our merchants’ customers liable for any fraudulent purchases made using their credit card account numbers that are reported in a timely way to the issuer,&#8221; a statement from the company reads. All these statements around <strong>hacker breaches </strong>and <strong>stolen credit cards </strong>read the same.</p>
<p>The process now begins where all the merchants have to be identified, then each merchant has to notify their customers. Their customer then have to work with their banks to stop credit cards, have to get credit monitoring and thus goes the Circle of Life (of data breaches) Here is the list of <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2009">data breaches</a> in 2009 alone. If you recall the breaches of Heartland Payment Systems and RBS WorldPay, the breachescaused them to be removed from the <a href="http://www.kraasecurity.com/compliance/pci">PCI security audit</a> () list . Well that should be obvious, or should they have been rated compliant int he first place. Known non-compliance might be a better than weak compliance.</p>
<p>The basic question is what was Network Solution not doing to have malicious software installed on key servers? Was it a breach through a web application, was it through malicious email, a browser based attack, some insider who didn&#8217;t know enough about security and clicked on the wrong thing? What routine check found it and why wasn&#8217;t this check run on a more routine basis, such as weekly or even daily?</p>
<p>At the end of the day, security is a moving target. We can utilize encryption, vulnerability management, <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a>, <strong>email filtering, backup and recovery</strong>, but all will be useless is we follow poor practices or do not have good procedures in place to take into account the human element. Most breaches are insider problems or mis-configurations or plain old stupidity.</p>
<p>Gary Bahadur<br />
<a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p>http://blog.kraasecurity.com</p>
<p>*Managed Security Services<br />
*Vulnerability Management<br />
*Compliance &amp; Policy Development<br />
*PGP Security<br />
*FREE Website Security Test</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/755d6115-051b-8f3d-a5f6-0fd37b657b56/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=755d6115-051b-8f3d-a5f6-0fd37b657b56" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/27/data-loss-this-time-with-network-solutions/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Buying Malware rather than getting it for free</title>
		<link>http://blog.kraasecurity.com/2009/05/22/buy-malware/</link>
		<comments>http://blog.kraasecurity.com/2009/05/22/buy-malware/#comments</comments>
		<pubDate>Fri, 22 May 2009 12:27:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=41</guid>
		<description><![CDATA[This kind of incident (see article below) seems to be happening every few months. So you purchase a product (netbook) and it comes infected. No longer do you just have to worry about it working, or if the OS will behave nicely or the drivers will work with your printer. If the manufacturer can not control malware, [...]]]></description>
			<content:encoded><![CDATA[<p>This kind of incident (see article below) seems to be happening every few months. So you purchase a product (netbook) and it comes infected. No longer do you just have to worry about it working, or if the OS will behave nicely or the drivers will work with your printer. If the manufacturer can not control malware, what hope is there?</p>
<p>I am pretty puzzled about how the malware actually got on the machine. The article doesnt delve into too much detail, but looks like maybe a driver was infected that got placed on the machine. This seems to say the manufacturer does not use any kind of antivirus, or antimalware to test the security of the system before shipping it out. It also calls into question the security processes in place around managing software and development. A bit scary.</p>
<p>So what are some things you can do to protect against malware (i hope you know most of these already)</p>
<p>1) Use a firewall - A good personal firewall will help defend your system, especially if it has the capability to monitor outbound traffic or stop unknow programs from being run or installed. Try <strong>Zonealarm</strong>, free version.</p>
<p>2) Run anti-virus &#8211; This is obvious. while many antivirus programs will miss a lot of malware, you need a defense in depth strategy. Try <strong>AVG</strong> or <strong>Avast.</strong></p>
<p>3) Install patches - A must do. Keep your systems patched because many worms, virus, and malware take advantage of unpatched system vulnerabilities</p>
<p>4) Use antispyware &#8211; This is a bit different from antivirus. It can stop malicious code from running and warn you of registry changes. A good start for the beginner is <strong>SpywareGuard</strong> and  <strong>Spybot S &amp; D. </strong></p>
<p>5) Protect the browser &#8211; Browser protection software can stop activex controls from running, protect you from tracking cookies and known malware. Two examples are SpywareBlaster and IE-SpyAd</p>
<p>6) Stop Surfing Porn!</p>
<p>Baha</p>
<p><a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com">www.kraasecurity.com</a></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Managed Security Services</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Vulnerability Management</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*Compliance &amp; Policy Development</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*PGP Security</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #c00000; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-no-proof: yes;"><span style="font-size: small;"><span style="font-family: Calibri;">*FREE Website Security Test</span></span></span></p>
<p>++++++++++++++++++++++++++++++++++++++++++++++++++++</p>
<p>Netbook comes with factory-sealed malware<br />
Chuck MillerMay 20, 2009<br />
SC Magazine</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/05/22/buy-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
