<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2192637225114625455</id><updated>2011-04-21T13:50:40.219-04:00</updated><title type='text'>RAZORPOINT: Realities of Cybersecurity</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://razorpoint.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://razorpoint.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Razorpoint Security Technologies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='11' src='http://bp1.blogger.com/_OQeTtl4ystQ/SFH9asNwBoI/AAAAAAAAAAk/sb_khGtl6Ng/S220/Rz-logo-WSTA.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2192637225114625455.post-2136361561901351987</id><published>2008-07-25T11:34:00.003-04:00</published><updated>2008-07-25T16:56:45.396-04:00</updated><title type='text'>New DNS Exploit In The Wild</title><content type='html'>It's here.  Another malicious DNS exploit that allows for remote manipulation of DNS records.  DNS poisoning and Man-In-The-Middle attacks are nothing new, but they just got much easier.&lt;br /&gt;&lt;br /&gt;Researcher &lt;a href="http://news.cnet.com/8301-10789_3-9985815-57.html"&gt;Dan Kaminsky's recent warnings&lt;/a&gt; are now very real.  A number of remote DNS attacks that allow for the redirection of legitimate Internet traffic.  No breaking through firewalls, no stealing passwords, no decrypting secret messages, just a simple tool to tell a DNS server to send traffic meant for a major corporation to any server of an attacker chooses.  And the tools are free to download (&lt;a href="http://www.packetstormsecurity.org/0807-exploits/bailiwicked_host.rb.txt"&gt;bailiwicked_host&lt;/a&gt; | &lt;a href="http://www.packetstormsecurity.org/0807-exploits/bailiwicked_domain.rb.txt"&gt;bailiwicked_domain&lt;/a&gt; | &lt;a href="http://www.packetstormsecurity.org/0807-exploits/bind9x-poison.txt"&gt;kaminsky-attack&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a style="font-weight: bold;" href="http://www.razorpoint.com/rz.datawatch/"&gt;Razorpoint's Rz.DataWatch&lt;/a&gt; service (launched in May 2007) is still the best detection and defense against these types of attacks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2192637225114625455-2136361561901351987?l=razorpoint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://razorpoint.blogspot.com/feeds/2136361561901351987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2192637225114625455&amp;postID=2136361561901351987' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/2136361561901351987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/2136361561901351987'/><link rel='alternate' type='text/html' href='http://razorpoint.blogspot.com/2008/07/new-dns-exploit-in-wild.html' title='New DNS Exploit In The Wild'/><author><name>Razorpoint Security Technologies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='11' src='http://bp1.blogger.com/_OQeTtl4ystQ/SFH9asNwBoI/AAAAAAAAAAk/sb_khGtl6Ng/S220/Rz-logo-WSTA.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2192637225114625455.post-180478152203977992</id><published>2008-07-10T11:31:00.003-04:00</published><updated>2008-07-10T11:44:19.370-04:00</updated><title type='text'>DNS Poisoning Vulnerability Still A Problem.</title><content type='html'>Security buzz on Tuesday, July 8, 2008 was centered around DNS cache poisoning attacks.  Security researcher Dan Kaminsky has been leading an effort with multiple vendors over the past few months to try and head off the vulnerabilities.  Another researcher however – Ian Green – &lt;a href="http://www.sans.org/reading_room/whitepapers/dns/1567.php"&gt;detailed&lt;/a&gt; the spoofing  vulnerability as long as three years ago.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2008/07/09/dns_bug_student_discovery/"&gt;http://www.theregister.co.uk/2008/07/09/dns_bug_student_discovery/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2008/07/09/dns_fix_alliance/"&gt;http://www.theregister.co.uk/2008/07/09/dns_fix_alliance/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Among other online vulnerabilities, &lt;a href="http://www.razorpoint.com/rz.datawatch/"&gt;Razorpoint's Rz.DataWatch™&lt;/a&gt; monitors online business assets for this style of attack.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2192637225114625455-180478152203977992?l=razorpoint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://razorpoint.blogspot.com/feeds/180478152203977992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2192637225114625455&amp;postID=180478152203977992' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/180478152203977992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/180478152203977992'/><link rel='alternate' type='text/html' href='http://razorpoint.blogspot.com/2008/07/dns-poisoning-vulnerability-still.html' title='DNS Poisoning Vulnerability Still A Problem.'/><author><name>Razorpoint Security Technologies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='11' src='http://bp1.blogger.com/_OQeTtl4ystQ/SFH9asNwBoI/AAAAAAAAAAk/sb_khGtl6Ng/S220/Rz-logo-WSTA.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2192637225114625455.post-3800520910145460708</id><published>2008-06-13T00:55:00.012-04:00</published><updated>2008-06-13T14:21:51.725-04:00</updated><title type='text'>Rz.DataWatch™</title><content type='html'>&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Multi-Attack Detection: Domain Hijacking, Man-In-The-Middle &amp;amp; Pharming. &lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.razorpoint.com/rz.datawatch"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;http://www.razorpoint.com/rz.datawatch&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;div&gt;&lt;br /&gt;Two articles that appeared regarding the Comcast compromise.  They outline the hack and what was done.&lt;br /&gt;(&lt;a href="http://blog.wired.com/27bstroke6/2008/05/comcast-hijacke.html"&gt;article #1: wired&lt;/a&gt; and &lt;a href="http://torrentfreak.com/comcast-hacked-in-bittorrent-throttling-packback-080529/"&gt;article #2: torrentfreak&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;The attackers used a combination of technical and social engineering attacks to compromise Comcast's domain registration information.  After successfully changing the registration information, the attackers had control of Comcast's domain.  Once they had control, the attackers pointed the traffic for Comcast's domain services to their servers.&lt;br /&gt;&lt;br /&gt;The attackers then noticed there was way too much traffic for their servers to handle, so they started re-pointing the domain information to other servers over and over.  All these changes required host, DNS and IP address alterations -- all things Rz.DataWatch monitors for.  Eventually Comcast caught on, however...&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2192637225114625455-3800520910145460708?l=razorpoint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/3800520910145460708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/3800520910145460708'/><link rel='alternate' type='text/html' href='http://razorpoint.blogspot.com/2008/06/rzdatawatch-multi-attack-detection.html' title='Rz.DataWatch™'/><author><name>Razorpoint Security Technologies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='11' src='http://bp1.blogger.com/_OQeTtl4ystQ/SFH9asNwBoI/AAAAAAAAAAk/sb_khGtl6Ng/S220/Rz-logo-WSTA.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2192637225114625455.post-6520872649291042842</id><published>2008-06-12T14:00:00.001-04:00</published><updated>2008-06-13T01:00:46.908-04:00</updated><title type='text'>RAZORPOINT: Realities of Cybersecurity.</title><content type='html'>&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;a href="http://blog.razorpoint.com/"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;blog.razorpoint.com&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; is here.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2192637225114625455-6520872649291042842?l=razorpoint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://razorpoint.blogspot.com/feeds/6520872649291042842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2192637225114625455&amp;postID=6520872649291042842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/6520872649291042842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2192637225114625455/posts/default/6520872649291042842'/><link rel='alternate' type='text/html' href='http://razorpoint.blogspot.com/2008/06/first-blog.html' title='RAZORPOINT: Realities of Cybersecurity.'/><author><name>Razorpoint Security Technologies</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='11' src='http://bp1.blogger.com/_OQeTtl4ystQ/SFH9asNwBoI/AAAAAAAAAAk/sb_khGtl6Ng/S220/Rz-logo-WSTA.jpg'/></author><thr:total>0</thr:total></entry></feed>
