<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Security Blog &#187; Review</title>
	<atom:link href="http://www.it-security-blog.com/category/review/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.it-security-blog.com</link>
	<description></description>
	<lastBuildDate>Tue, 27 Jul 2010 09:48:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>&#8216;Link Hack&#8217; points MySpace users to malicious Phishing site</title>
		<link>http://www.it-security-blog.com/uncategorized/link-hack-points-myspace-users-to-malicious-phishing-site/</link>
		<comments>http://www.it-security-blog.com/uncategorized/link-hack-points-myspace-users-to-malicious-phishing-site/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 07:49:10 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Link Hack]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[Social Network Under Attack]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/link-hack-points-myspace-users-to-malicious-phishing-site/</guid>
		<description><![CDATA[To think the attacks over the internet would end, users of MySpace have been hit by a termed &#8220;Link Hack&#8221; which was discovered and is being studied by Websense which found the hack to re-direct the parsing process from the MySpace profile page, to the malicious site them back to the said legit page. The [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/02/myspace.jpg' title='myspace.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/02/myspace.thumbnail.jpg' alt='myspace.jpg' /></a>To think the attacks over the internet would end, users of MySpace have been hit by a termed &#8220;Link Hack&#8221; which was discovered and is being studied by Websense which found the hack to re-direct the parsing process from the MySpace profile page, to the malicious site them back to the said legit page. The hack allows malicious code to be attached to all aspects of the MySpace page (such as the View Pictures, View Profile and other such legitimate functions that are normally used on the social networking site but instead of doing the requested operation, the user is re-directed to another site which prompts the user to click the back button or try to figure out what the hell just happened with the malicious phishing site getting all the info it needs and the cycle continues again and again.</p>
<p>The hijack process comes in stages and all the while the misguided clicks always execute a piece of JavaScript which re-directs the user to a page that seems to be the MySpace site but actually isn&#8217;t. The problem has seemingly dropped traffic due to the shutting down by the phishing site. Websense has informed the MySpace people regarding the matter and they are surely taking action to provide measures to ensure the privacy (which may be next to impossible to such open sites) of their subscribers. <a href="http://www.symantec.com/enterprise/security_response/weblog/2006/07/myspace_shockwave_flash_hack.html">Symantec</a> has also raised the alarm and has released information that can help users avert the disclosure of personal information to the said phishing site. MySpace has also identified several individuals who might be involved in the attack and have <a href="http://www.myspace.com/hacksuspensions">suspended</a> their accounts as they continue to investigate the actions of these errant users and what part they had with the attach on the social networking site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/link-hack-points-myspace-users-to-malicious-phishing-site/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Reading Technology Website News</title>
		<link>http://www.it-security-blog.com/it-security-basics/reading-technology-website-news/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/reading-technology-website-news/#comments</comments>
		<pubDate>Mon, 19 Mar 2007 18:24:58 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Wireless Security]]></category>
		<category><![CDATA[e-zine]]></category>
		<category><![CDATA[magazines]]></category>
		<category><![CDATA[newspapers]]></category>
		<category><![CDATA[websites]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/it-security-basics/reading-technology-website-news/</guid>
		<description><![CDATA[The best way for people to know what the latest threats and mischievous activities that people are up to over the web is to read the websites that specialize as well in network and computer security. There will always be new viruses, spyware and Trojans over the web and while the scope that these sites [...]]]></description>
			<content:encoded><![CDATA[<p>The best way for people to know what the latest <a href="http://www.biziki.com/">threats</a> and mischievous activities that people are up to over the web is to read the websites that specialize as well in network and <a href="http://www.geeksblog.net">computer security</a>. There will always be new viruses, spyware and Trojans over the web and while the scope that these sites cover may not be saturated, it also depends on the part of the people on how they are inclined to be aware of such. </p>
<p><a><center><img src="http://www.fengshuidiva.com/man_reading_newspaper_lg_nwm.gif" alt="News Reading" /></center></a></p>
<p>Unless there is a real <a href="http://www.newspaperblog.net">outbreak</a> that possesses quite a threat towards every computer, people will not be aware or concerned about technology security today. While the <a href="http://www.charitiesblog.net/">religious practice</a> of keeping track of these threats cannot be readily instilled, it would be best to exhaust all means in being able to do so. Besides, people know for a fact that neglecting such efforts will be at their own risk and network and computer security is something that many would realize when the harm has already been done. </p>
<p>[tags]newspapers, magazines, e-zine, websites[/tags]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/reading-technology-website-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Importance of Knowing Filename Extensions Prior to Opening Them</title>
		<link>http://www.it-security-blog.com/it-security-basics/the-importance-of-knowing-filename-extensions-prior-to-opening-them/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/the-importance-of-knowing-filename-extensions-prior-to-opening-them/#comments</comments>
		<pubDate>Sun, 25 Feb 2007 15:49:57 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[filename-extensions]]></category>
		<category><![CDATA[filenames]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus-scan]]></category>
		<category><![CDATA[zipped]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/it-security-basics/the-importance-of-knowing-filename-extensions-prior-to-opening-them/</guid>
		<description><![CDATA[Computer interface with various developed programs and most would have an assigned file name extension tagged to it. There are the usual files that would have a doc, xls, ppt, jpg and bmp file extensions. There are also the compressed files such as zip and amr. The compressed files offer some potential risk since they [...]]]></description>
			<content:encoded><![CDATA[<p>Computer <a href="http://www.geeksblog.net">interface</a> with various developed programs and most would have an assigned file name extension tagged to it. There are the usual files that would have a doc, xls, ppt, jpg and bmp file extensions. There are also the compressed files such as zip and amr. The compressed files offer some potential <a href="http://hubpages.com/hub/Christmas_party_idea">risk</a> since they are usually zipped to group files into one manageable file. <a href="http://www.downloadinglegally.com">Program</a> scripts and installation software are the common <a href="http://www.wordcontent.com">contents </a>of these zipped folders to save on space and to make it easier for <a href="http://www.downloadinglegally.com">distribution</a> and transfer. </p>
<p><a><center><img src="http://www.jmcpl.ca/images/Graduate_-_Cartoon_2.jpg" alt="Filename Extension Genius" /></center></a></p>
<p>It is best to proceed with caution before totally unzipping the contents to any directory of your computer. It is the <a href="http://www.bizcrunch.net">executable</a> files such as the setup.exe that may garner much doubt. Once executable files are double clicked, it will immediate <a href="http://www.cigar-blog.com">process</a> and try to install itself on the <a href="http://www.geeksblog.net">machine</a>. Once finished, there is no telling what effects it may do or create, thus the need for people to think twice before clicking on the files. </p>
<p>[tags]filename extensions, filenames, zipped, scanning, virus scan, spyware, trojans[/tags]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/the-importance-of-knowing-filename-extensions-prior-to-opening-them/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Penetration of LCD Monitors in the Technology Market</title>
		<link>http://www.it-security-blog.com/review/the-penetration-of-lcd-monitors-in-the-technology-market/</link>
		<comments>http://www.it-security-blog.com/review/the-penetration-of-lcd-monitors-in-the-technology-market/#comments</comments>
		<pubDate>Sun, 14 Jan 2007 10:19:27 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[crt-monitors]]></category>
		<category><![CDATA[desktops]]></category>
		<category><![CDATA[lcd-monitors]]></category>
		<category><![CDATA[lg-collins]]></category>
		<category><![CDATA[samsung]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/168/the-penetration-of-lcd-monitors-in-the-technology-market.htm</guid>
		<description><![CDATA[The cost for owning LCD monitors today have severely been lowered, putting into peril the usual CRT monitors known as the bulky packaged ones that are usually partnered with a desktop system. While the CRT series have gone as far as widening their screens towards the 19” Flat Screen monitor, from all indications, everyone will [...]]]></description>
			<content:encoded><![CDATA[<p>The cost for owning LCD monitors today have severely been lowered, putting into peril the usual CRT monitors known as the bulky packaged ones that are usually <a href="http://www.bloggypro.com/">partnered</a> with a desktop system. While the CRT series have gone as far as widening their screens towards the 19” Flat Screen monitor, from all indications, everyone will be leaning more towards a space consuming and screen <a href="http://www.bloggytutor.com/">optimized</a> LCD monitor regardless of its screen width.</p>
<p><a><center><img src="http://www.lcd-monitor-reviews.com/cheap-computer-monitors-buyers-guide.jpg" alt="LCD Monitors" /></center></a></p>
<p>Such was forthcoming. In its initial introduction to the <a href="http://www.bizcrunch.net">market</a>, a lot of people were hesitant due to the astronomical price that it was pegged at. But like all competing products, once the competition sets in, the need to adjust the price to be competitive in the <a href="http://www.bizcrunch.net">market</a> is a must. Thus, such a trend can be seen with the large drop in the price of LCD monitors such as Samsung and LG Collins, two <a href="http://www.gaming-blog.net">players</a> who are not really tagged to be in the line of Viewsonic and AOC.</p>
<p>As it stands, the final decision would be left on the price and the screen <a href="http://www.bloggytutor.com/">resolution</a> as required. For people who are simply wanting to get in with the times, this is certainly welcome news for the lower costing <a href="http://www.bizcrunch.net">manufacturers</a> who aim to satisfy the need for LCD monitors, regardless if this is just for personal satisfaction or not.</p>
<p>[tags]lcd monitors, samsung, lg collins, crt monitors, desktops[/tags]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/review/the-penetration-of-lcd-monitors-in-the-technology-market/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MajorGeek.com: A Download Site for Computer Care</title>
		<link>http://www.it-security-blog.com/it-security-basics/majorgeekcom-a-download-site-for-computer-care/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/majorgeekcom-a-download-site-for-computer-care/#comments</comments>
		<pubDate>Mon, 08 Jan 2007 18:42:42 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/164/majorgeekcom-a-download-site-for-computer-care.htm</guid>
		<description><![CDATA[
Day-in and Day-out, people surf the web for possible downloads in the form of drivers, security stand alone cleaners, and free programs that will help them in their specific needs. One drawback is the potent threats and reliability of such sites since everyone is aware that such malicious Spyware or Trojans may be present in [...]]]></description>
			<content:encoded><![CDATA[<p><center><a><img id="image165" height=96 alt="Major Geek " src="http://www.it-security-blog.com/wp-content/uploads/2007/01/majorgeek.thumbnail.jpg" width="113" /></a></center></p>
<p>Day-in and Day-out, people surf the web for possible downloads in the form of drivers, security stand alone cleaners, and free programs that will help them in their specific needs. One drawback is the potent <a href="http://www.biziki.com">threats</a> and reliability of such sites since everyone is aware that such malicious Spyware or Trojans may be present in these <a href="http://www.bloggytutor.com">programs </a>which are usually compressed in zip files prior to free downloading. </p>
<p><a href="http://www.majorgeeks.com/">Majorgeeks.com</a> is one site that contains a lot of the helpful tools to aid computer users in their everyday issues and improvements for their overall operating system and performance. One notable thing that most users are aware about is that of intrusions in their system from the usual cookies and attachments that people get from the Internet. With the mischief going around, no one really knows how safe their <a href="http://www.bloggygeek.com">computer</a> is and what files are needed and not on their hard drives. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/majorgeekcom-a-download-site-for-computer-care/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Switched Network Security</title>
		<link>http://www.it-security-blog.com/security-policies/switched-networks-security-%e2%80%93-packet-sniffing/</link>
		<comments>http://www.it-security-blog.com/security-policies/switched-networks-security-%e2%80%93-packet-sniffing/#comments</comments>
		<pubDate>Wed, 08 Nov 2006 14:59:30 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Security Policies]]></category>

		<guid isPermaLink="false">http://it-security-blog.com/?p=17</guid>
		<description><![CDATA[
Many people I speak to think that simply because they are on a switched network, they are immune to packet sniffing, a process whereby a computer listens for packets not intended for that address, and logs them, potentially gathering usernames, passwords, and other useful information within network traffic. For example, every time you log into [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.lansingwireless.com/backdoor/portscan.jpg" alt="" /></p>
<p>Many people I speak to think that simply because they are on a switched network, they are immune to packet sniffing, a process whereby a computer listens for packets not intended for that address, and logs them, potentially gathering usernames, passwords, and other <a href="http://www.up8.org">useful information</a> within network traffic. For example, every time you log into a website which does not use SSL (Secure Sockets Layer), your username and password are transmitted in plain text as part of the HTTP (HyperText Transfer Protocol) request. If another user is running packet sniffing software, this request will get logged for later analysis, which could lead to that user gaining access to the website you visited, under your account.</p>
<p>Packet sniffing was easy on networks connected using hubs, as a hub is a device which sends every packet it receives to every computer connected. This is bad for a number of reasons, including reducing transfer rates due to collisions and unnecessary transmission; if data is not destined for a computer, it would still be sent there. It does, however, also allow for easy packet sniffing; simply set a network card to pass every packet up to the application layer, instead of only those addressed to the specific computer. These can be logged for later analysis.</p>
<p>On a switched network, packets usually go only to the computer to which they are addressed, based on MAC address resolution of the IP. The switch then sends packets to the port <a href="http://billing.aseohosting.com/aff.php?aff=010">hosting</a> that MAC address, and only that port.</p>
<p>So, how is it that switched <a href="http://www.discovereverything.info">networks</a> are still vulnerable to packet sniffing, if packets only get transmitted to their destination?</p>
<p>This is where ARP Poisoning comes in. ARP is the Address Resolution Protocol, and maps IP addresses to MAC addresses. In an ARP Poisoning attack, a system sends out faked ARP responses claiming to be the MAC associated with an IP. As such, packets destined for that IP will be sent to the computer doing the ARP poisoning, as they traverse the switch, instead of the real destination.</p>
<p>Using this mechanism, it is possible to redirect packets between a <a href="http://www.discovercomputers.info">computer</a> on the network to the border router, forcing them to be delivered to a system running a packet sniffer, instead. From here, they can be logged and then sent on to the real MAC address of the router. This is known as a man-in-the-middle ARP Poisoning based network sniffing attack, and is effective against switched networks.</p>
<p>Because this attack is based on ARP requests and responses, which are a local network mechanism, this attack cannot traverse routers or any other level 3 or higher device.
<p><script type="text/javascript"><!--
google_ad_client = "pub-3611539083056510";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel ="5297802266";
google_color_border = "161415";
google_color_bg = "161415";
google_color_link = "94C22C";
google_color_url = "A1A1A1";
google_color_text = "A1A1A1";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/security-policies/switched-networks-security-%e2%80%93-packet-sniffing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can they offer anonymous browsing?</title>
		<link>http://www.it-security-blog.com/programming/can-they-offer-anonymous-browsing/</link>
		<comments>http://www.it-security-blog.com/programming/can-they-offer-anonymous-browsing/#comments</comments>
		<pubDate>Sun, 17 Sep 2006 13:09:15 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Privacy-&-Anonymity]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/100/can-they-offer-anonymous-browsing.htm</guid>
		<description><![CDATA[September saw the introduction of two new web browsers focusing on anonymous web browsing. Early this month, Browzar was launched by Freeserve founder, Ajaz Ahmed. It automatically deletes any cookies after each session, does not save save pages in cached folders, and its relatively small size makes it easy to bring along. There has been [...]]]></description>
			<content:encoded><![CDATA[<p>September saw the introduction of two new web browsers focusing on anonymous web browsing. Early this month, <strong>Browzar</strong> was launched by Freeserve founder, Ajaz Ahmed. It automatically deletes any cookies after each session, does not save save pages in cached folders, and its relatively small size makes it easy to bring along. There has been issues on it being merely an IE shell and that search results lead to sponsored links and adverts. Also, <a href="http://www.bloggy-network.com/">users</a> need to download any security patches from Microsoft once a flaw has been identified for IE. After the two recent attacks on the browser, many are skeptical to its overall usability.<img id="image99" src="http://www.it-security-blog.com/wp-content/uploads/2006/09/browzar_skins.jpg" alt="A screenshot of browzar"  /></p>
<p><strong>Torpack</strong> on the other hand came from Hacktivi<a class="imagelink" href="http://www.it-security-blog.com/wp-content/uploads/2006/09/browzar_skins.jpg" title="A screenshot of browzar"></a>smo, a group of computer security experts and human rights workers, and is based on Mozilla&#8217;s Firefox. No installation is required to run the browser, though the two folders generated from the free download have to be kept together for it to run. This browser encrypts the data passing from the user&#8217;s computer and the TOR network, and causes the IP address seen by the website to change every few minutes.  Torpack does have limitations; browsing speeds will be slower and it&#8217;s suggested not to log-in sites which cannot offer secure log-ins.</p>
<p>Both of these applications are not meant to replace the current browsers you&#8217;re using in your computer. It&#8217;s interesting to note that they both have privacy and secure browsing as their main selling points. These features are useful for users who are leery of going online in public access locations like schools and Internet cafés, where a secure connection cannot be guaranteed. So far both of these are available for free download, and you might want to see which one will stand the test of continuous use. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/programming/can-they-offer-anonymous-browsing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2006 Security Book Roundup</title>
		<link>http://www.it-security-blog.com/it-security-basics/2005-security-book-roundup/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/2005-security-book-roundup/#comments</comments>
		<pubDate>Fri, 18 Aug 2006 05:54:25 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://it-security-blog.com/?p=22</guid>
		<description><![CDATA[
This year has seen a steady increase in the number of books being published on security-related topics. Since the year is about to end, I thought I&#8217;d round up a few of the best I&#8217;ve read, seen, or heard about, and comment briefly on each one!
Apache Security
O&#8217;Reilly
Published March 2006
http://www.amazon.co.uk/exec/obidos/ASIN/0596007248/
This book covers installing a secure Apache [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://i8.ebayimg.com/04/i/06/b5/15/93_2.JPG" alt="" /></p>
<p>This year has seen a steady increase in the number of books being published on security-related topics. Since the year is about to end, I thought I&#8217;d round up a few of the best I&#8217;ve read, seen, or heard about, and comment briefly on each one!</p>
<p><strong>Apache Security</strong><br />
<strong><em>O&#8217;Reilly</em></strong><br />
<em>Published March 2006</em><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0596007248/">http://www.amazon.co.uk/exec/obidos/ASIN/0596007248/</a></p>
<p>This book covers installing a secure Apache <a href="http://www.imandhosting.com">web server</a>, discusses a variety of attack techniques, and looks at securing a multi-user hosting environment. All round, an excellent book for webhosts or anyone running Apache on an Internet-accessible system!</p>
<p><strong>SSH, The Secure Shell: The Definitive Guide, Second Edition </strong><br />
<strong><em>O&#8217;Reilly</em></strong><br />
<em>Published May 2006</em><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0596008953/">http://www.amazon.co.uk/exec/obidos/ASIN/0596008953/</a></p>
<p>This book takes a look at the SSH program, a replacement for telnet or rsh, providing an encrypted link over which programs can be run. SSH also contains programs for <a href="http://www.downloadpuppy.com">file copy</a>, replacing rcp and perhaps even FTP! The book looks at the latest developments in OpenSSH and other SSH implementations, and includes some powerful examples including setting up SSH tunnels and forwarding systems.</p>
<p><strong>Security And Usability</strong><br />
<strong><em>O&#8217;Reilly</em></strong><br />
<em>Published February 2006</em><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0596008279/">http://www.amazon.co.uk/exec/obidos/ASIN/0596008279/</a></p>
<p>This book reaches a compromise between the two design goals of security and <a href="http://www.downloadinglegally.com">usability</a>. I haven&#8217;t actually read this one, but everyone I speak to that has thinks its worthwhile!<br />
<strong></p>
<p>Extrusion Detection</strong><br />
<strong><em>Addison-Wesley</em></strong><br />
<em>Published June 2006</em><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0321349962/">http://www.amazon.co.uk/exec/obidos/ASIN/0321349962/</a></p>
<p>One of the few books in publication which covers the important topic of internal attacks! Again, I haven&#8217;t read this, but it is an important topic, and its nice to see books finally starting to appear to bridge the gap between the generic security books and the knowledge that <a href="http://www.bloggy-network.com">network administrators</a> need!</p>
<p><strong>Cryptography In The Database</strong><br />
<em><strong>Addison-Wesley</strong></em><br />
<em>Published May 2006</em><br />
<a href="http://www.amazon.co.uk/exec/obidos/ASIN/0321320735/">http://www.amazon.co.uk/exec/obidos/ASIN/0321320735/</a></p>
<p>This book approaches security from the opposite end to many; from the innermost structure in many applications. Databases are often left open to attack because it is assumed that the outer layers of a program protect any database access against exploitation. Using cryptography in the database helps to prevent attacks which take advantage of most peoples false sense of local security! Once again, this book is a much-needed addition to the stores!</p>
<p>If I&#8217;ve left out your favourite security book of the year, or, if you&#8217;re one of the lucky few, the book you wrote this year, don&#8217;t be offended! I just chose a few of the ones that stood out most to me. There were, as I said, a large number of books dealing specifically with security this year, from VPNs to SSH, rootkits to software vulnerabilities, Apache to IIS, and PHP to SQL. In each case, the books have contributed new and fresh ideas, shown the latest attack patterns, and offered advice for prevention, or, failing that, cure.</p>
<p>As the threat from malware, malicious <a href="http://www.onebighacker.com">hackers</a> and even corporate software with unintentional (<em>or intentional</em>) security issues grows, books like these serve not only to educate the developer and system administrator in prevention, but also to alert the user to the threat. Most technical users cannot fail to notice the distinct rise in security related books this year, and should easily be able to correlate this to the ever-increasing threat as our world becomes ever more connected!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/2005-security-book-roundup/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>RedHat Enterprise Linux 4 vs. Windows Server 2003</title>
		<link>http://www.it-security-blog.com/operating-systems/redhat-enterprise-linux-4-vs-windows-server-2003/</link>
		<comments>http://www.it-security-blog.com/operating-systems/redhat-enterprise-linux-4-vs-windows-server-2003/#comments</comments>
		<pubDate>Mon, 26 Jun 2006 14:25:02 +0000</pubDate>
		<dc:creator>clouseau</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Review]]></category>

		<guid isPermaLink="false">http://it-security-blog.com/?p=14</guid>
		<description><![CDATA[You will constantly see &#8220;religious&#8221; wars being fought between the camps of the above mentioned platforms. You&#8217;ll also see a lot of comparisons between the two on the net, all of which have a hint of bias in them. Well today I&#8217;m going to cover just facts between the two platforms to see which one [...]]]></description>
			<content:encoded><![CDATA[<p>You will constantly see &#8220;religious&#8221; wars being fought between the camps of the above mentioned <a href="http://www.hostinglook.com">platforms</a>. You&#8217;ll also see a lot of comparisons between the two on the net, all of which have a hint of bias in them. Well today I&#8217;m going to cover just facts between the two platforms to see which one comes out a clear winner, if any.<br />
Let&#8217;s see when each platform launched. If we look up RedHat we&#8217;ll find that they launched version 4 of their highly acclaimed Enterprise Linux on February 15th, 2005 according to CRN. Microsoft Windows Server 2003 was released on March 28th, 2003 according to Microsoft&#8217;s own site. That&#8217;s nearly a two year gap between the two which in the IT <a href="http://www.discovercountries.info">world</a> is nearly a lifetime of most software product versions themselves.<br />
So Windows Server 2003 has a near 2 year head start on RedHat Enterprise Linux 4 to collect all sorts of vulnerabilities that we all know Microsoft is famous for. However, this is where it gets to be a tad bit surprising. Outside the hype and FUD (F<em>ear, Uncertainty and Distrust</em>), it&#8217;s not nearly as bad as the general tech community paints it out to be. A little research from Secunia reveals that it&#8217;s not bad at all. </p>
<p><img src="http://secunia.com/graph/?type=adv&#038;prod=1173&#038;period=all" alt="Graph" /><br />
Since its release in 2003, Windows Server has accumulated a total of 74 Secunia Advisories.  </p>
<p>Now let us take a look at Redhat Enterprise Linux </p>
<p><img src="http://secunia.com/graph/?type=adv&#038;period=all&#038;prod=4669" alt="graph" /></p>
<p>Since its release in 2005, Enterprise Linux 4 has accumulated a total of 128 advisories. </p>
<p>Wait, what? There must be some mistake. Well ok, perhaps the Enterprise Linux 4 vulnerabilities are a lot less severe than Windows Server 2003.  A local vulnerability is a lot less severe than a remote vulnerability. </p>
<p>So let&#8217;s look at RedHat Enterprise Linux 4 first. </p>
<p><img src="http://secunia.com/graph/?type=fro&#038;period=all&#038;prod=4669" alt="graph" /></p>
<p>Ok so 83 percent of all the vulnerabilities are able to be exploited remotely. That&#8217;s a pretty high number. Let&#8217;s take a look at Windows.</p>
<p><img src="http://secunia.com/graph/?type=fro&#038;period=all&#038;prod=1173" alt="Graph" /></p>
<p>59 percent of all Windows Server 2003 Secunia Advisories are remotely exploitable.</p>
<p>Well now, this is fairly interesting. So far, dare I say, Windows is leading in terms of security. </p>
<p>Ah but wait, it&#8217;s not over yet. We have yet to see the type of impact most of these vulnerabilities have, and most importantly, the impact they have at the system level. </p>
<p>So let&#8217;s take a look at RedHat Enterprise Linux 4 first.</p>
<p><img src="http://secunia.com/graph/?type=imp&#038;period=all&#038;prod=4669" alt="Graph" /></p>
<p>We see here that 30 percent of the vulnerabilities allow system access. </p>
<p>Now let&#8217;s take a look at Windows Server 2003.</p>
<p><img src="http://secunia.com/graph/?type=imp&#038;period=all&#038;prod=1173" alt="Graph" /></p>
<p>We see here that Windows Server 2003 is a bit more severe in that 53 percent of their vulnerabilities allowed system access. That&#8217;s a fairly high percentage that is dangerous, especially in an <a href="http://www.discovereverything.info">enterprise environment</a>.<br />
Secunia also keeps track of vulnerabilities that they have discovered and are unpatched as of yet by the vendor, which gives us an idea of the rate at which each vendor responds to security. </p>
<p>The Secunia database currently contains 0 Secunia advisories marked as &#8220;<em>Unpatched</em>&#8220;, which affects RedHat Enterprise Linux AS 4.</p>
<p>That&#8217;s pretty decent, so we know that RedHat responds very quickly to any discovered security threats. Let&#8217;s have a look at Microsoft.</p>
<p>Currently, 8 out of 74 Secunia advisories, is marked as &#8220;<em>Unpatched</em>&#8221; in the Secunia database.</p>
<p>A much more dangerous number than zero. Although, to their credit, all of the &#8220;<em>unpatched</em>&#8221; vulnerabilities are not too critical. However, this still shows us how seriously Microsoft lags behind in their patching efforts. One could only attribute this to the massive complexity of the Windows system that Microsoft engineers must go through in contrast to the modular nature of Linux itself. </p>
<p>In conclusion, what we have here is a very interesting set of differences between the two platforms and neither comes out as a clear winner. (<em>I know, you are disappointed</em>!) However, we did uncover the fact that Windows Server 2003 is not nearly as bad as the general tech community paints it out to be and would be a fairly solid choice in an enterprise environment despite all the <strong>FUD</strong>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/operating-systems/redhat-enterprise-linux-4-vs-windows-server-2003/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
