<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Gilbert Verdian - Security Advocate</title>
	<atom:link href="http://www.gilbertverdian.com/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gilbertverdian.com/security</link>
	<description>talking about security, from the front line</description>
	<pubDate>Fri, 03 Oct 2008 20:55:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>Using Google to Identify Security Trends</title>
		<link>http://www.gilbertverdian.com/security/2008/10/using-google-to-identify-security-trends/</link>
		<comments>http://www.gilbertverdian.com/security/2008/10/using-google-to-identify-security-trends/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 20:55:32 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/?p=50</guid>
		<description><![CDATA[The other day I was thinking about what is the best way to identify current trends on a macro level, to have an overview and understanding of what is currently happening and more importantly where to focus to mitigate against the risks and threats.
Currently my RSS feeds bring in over 1000 items a day, which [...]]]></description>
			<content:encoded><![CDATA[<p>The other day I was thinking about what is the best way to identify current trends on a macro level, to have an overview and understanding of what is currently happening and more importantly where to focus to mitigate against the risks and threats.</p>
<p>Currently my RSS feeds bring in over 1000 items a day, which is great on a micro level, but I wanted something with a wider view. So decided to try Google Trends and feed it some security keywords which gave some interesting results.</p>
<p>Keyword:</p>
<p><strong>1) Hacking</strong></p>
<p> </p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-hacking.png"><img class="alignnone size-full wp-image-51" title="google_trends-hacking" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-hacking.png" alt="" width="500" height="380" /></a></p>
<p>This show&#8217;s Pakistan, India and Indonesia were the top 3 countries who searched for hacking and there&#8217;s a small and general increase for the term since 2004. </p>
<p><strong>2) Zero Day</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-zero_day.png"><img class="alignnone size-full wp-image-52" title="google_trends-zero_day" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-zero_day.png" alt="" width="500" height="332" /></a></p>
<p>Zero day (0 day) was almost non-existent before 2004, the increasing trend seems quite accurate as the previously underground term found itself into in the mainstream media. Surprisingly Finland is on top searching for zero day the most, whereas India who topped &#8220;hacking&#8221; is now listed as number 8. Another noteworthy entry is Romania, which compliments trends of eastern European countries that have been increasing their activity in this area, especially as organised crime is involved.</p>
<p><strong>3) Phishing</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-phishing.png"><img class="alignnone size-full wp-image-53" title="google_trends-phishing" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-phishing.png" alt="" width="500" height="335" /></a></p>
<p>Phishing similarly evolved around 2004, with its peak around the middle of 2005. The trend show a slight decline possibly reflecting the increase in user awareness to not click on suspicious links.</p>
<p><strong>4) Botnet</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-botnet.png"><img class="alignnone size-full wp-image-54" title="google_trends-botnet" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-botnet.png" alt="" width="500" height="378" /></a></p>
<p>2004 seems to be quite a popular year where botnets also took the stage. The gradual rise in the term searches does reflect the amount of attention in the mainstream about them. The peaks show the main headlines covering stories regarding the popular botnets Storm and Kracken and the law enforcement successes by the FBI and Dutch police. Don&#8217;t exactly know why Norway is the top country searching for botnets.</p>
<p><strong>The OS Wars</strong></p>
<p><strong>5) Operating Systems (Linux, XP, Vista, Apple)</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-operating_systems.png"><img class="alignnone size-full wp-image-57" title="google_trends-operating_systems" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-operating_systems.png" alt="" width="500" height="375" /></a></p>
<p>This shows the steady decline of XP and Linux, the rise of Vista and OSX (Mac &amp; Leopard revealed an almost zero result so decided to use the term Apple to be more comparable).</p>
<p><strong>6) Linux</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-linux.png"><img class="alignnone size-full wp-image-55" title="google_trends-linux" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-linux.png" alt="" width="500" height="366" /></a></p>
<p>Linux searches have surprising been decreasing over the last 4 years. I would have thought with the popularity of ubuntu it will be on the rise. The amount of news stories covering linux in the lower graph seems to be constant.</p>
<p><strong>7) Ubuntu</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-ubuntu.png"><img class="alignnone size-full wp-image-58" title="google_trends-ubuntu" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-ubuntu.png" alt="" width="500" height="334" /></a></p>
<p>Showing the unsurprising increase of Ubuntu since 2004. One thing that I find interesting is that Italy is number 1 for Ubuntu searches, open source must be quite popular in Italy.</p>
<p><strong> <img src='http://www.gilbertverdian.com/security/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> Apple</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-apple.png"><img class="alignnone size-full wp-image-56" title="google_trends-apple" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-apple.png" alt="" width="500" height="375" /></a></p>
<p>Apple has had an expected increase reflective of its increase in market share over the years. The launch of the iPhone has obviously helped with its popularity.</p>
<p><strong>9) BSD</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-bsd.png"><img class="alignnone size-full wp-image-59" title="google_trends-bsd" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-bsd.png" alt="" width="500" height="377" /></a></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-bsd.png"></a>A favourite of mine, showing the enormous decline in popularity of the the *BSD family. Still FreeBSD is on top and Russia and Ukraine are the top countries. My favourite, BSDi, has not been around for quite a while.</p>
<p><strong>10) Unix</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-unix.png"><img class="alignnone size-full wp-image-60" title="google_trends-unix" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-unix.png" alt="" width="499" height="377" /></a></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-unix.png"></a>Searching for Solaris, AIX and HPUX reveals and overall steady decline in popularity. Solaris and AIX evening out in 2008 and India, Singapore and Japan being the top countries for Solaris.</p>
<p><strong>The Security Vendors</strong></p>
<p><strong>11)  McAfee Vs Symantec</strong></p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-mcafee-symantec.png"><img class="alignnone size-full wp-image-61" title="google_trends-mcafee-symantec" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-mcafee-symantec.png" alt="" width="500" height="379" /></a></p>
<p>Both companies have been quite close over the years. The next graph details the activity in 2008. Also the Asian countries seem to be on top searching for Symantec.</p>
<p><strong>12) McAfee Vs Symantec 200</strong>8</p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-mcafee-symantec08.png"><img class="alignnone size-full wp-image-62" title="google_trends-mcafee-symantec08" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/10/google_trends-mcafee-symantec08.png" alt="" width="500" height="378" /></a></p>
<p>A closer view show&#8217;s McAfee was searched the most and it overtook Symantec for the first time. </p>
<p><strong>In Conlusion</strong></p>
<p>Google trends doesn&#8217;t replace hard metrics, threat reports from industry sources,  correlated logs and alerts etc. But it does give you an insight on what people are searching for and from which geographic regions, thus giving you some awareness of what is going on, where to focus your attention on and what to look for to help mitigate threats and risks.</p>
<p>If you have some interesting searches please feel free to link back and display your results.</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/10/using-google-to-identify-security-trends/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/10/using-google-to-identify-security-trends/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ubuntu Drink in Vending Machine</title>
		<link>http://www.gilbertverdian.com/security/2008/08/ubuntu-drink-in-vending-machine/</link>
		<comments>http://www.gilbertverdian.com/security/2008/08/ubuntu-drink-in-vending-machine/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 11:23:18 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/?p=45</guid>
		<description><![CDATA[Came across this Ubuntu drink in a vending machine. Does anyone know what it is or tried it?

]]></description>
			<content:encoded><![CDATA[<p>Came across this Ubuntu drink in a vending machine. Does anyone know what it is or tried it?</p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/08/image017.jpg"><img class="alignnone size-full wp-image-46" title="ubuntu" src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/08/image017.jpg" alt="" width="500" height="666" /></a></p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/08/ubuntu-drink-in-vending-machine/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/08/ubuntu-drink-in-vending-machine/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Join the CISA group in LinkedIn - Update</title>
		<link>http://www.gilbertverdian.com/security/2008/07/join-the-cisa-group-in-linkedin-update/</link>
		<comments>http://www.gilbertverdian.com/security/2008/07/join-the-cisa-group-in-linkedin-update/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 23:44:17 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2007/11/join-the-cisa-group-in-linkedin/</guid>
		<description><![CDATA[Using LinkedIn quite extensively, I created a group for CISA qualified professionals to join.
Please visit the following link stating your ISACA membership number and month &#38; year you qualified for the CISA.
http://www.linkedin.com/e/gis/40405/0142006D7B5F
Upon joining you&#8217;ll have the following logo of the CISA letters I made displayed in your profile.

July 2008 - A quick update on the [...]]]></description>
			<content:encoded><![CDATA[<p>Using LinkedIn quite extensively, I created a group for CISA qualified professionals to join.</p>
<p>Please visit the following link stating your ISACA membership number and month &amp; year you qualified for the CISA.</p>
<p><strong><a href="http://www.linkedin.com/e/gis/40405/0142006D7B5F">http://www.linkedin.com/e/gis/40405/0142006D7B5F</a></strong></p>
<p>Upon joining you&#8217;ll have the following logo of the CISA letters I made displayed in your profile.</p>
<p><img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/cisa.png" alt="cisa.png" /></p>
<p>July 2008 - A quick update on the CISA group. We now have over 1300 members in the group! </p>
<p>The group is still only intended for CISAs, as each application is viewed, please also ensure you have your relevant CISA certification &amp; experience detailed in your profile.</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/07/join-the-cisa-group-in-linkedin-update/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/07/join-the-cisa-group-in-linkedin-update/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Get Hacked, Get Sued, Go Out of Business</title>
		<link>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/</link>
		<comments>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 17:33:43 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[hacking]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/</guid>
		<description><![CDATA[I just received the following email from ecademy.com.  It is an unfortunate tale of the site being hacked, the customer database stolen, the company being sued and as a result of the verdict and legal expenses they have decided to shut down. 
 Dear members, clients and guests of our portal,Over the last few years our portal [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="font-family: Helvetica; font-size: 12px; line-height: normal">I just received the following email from ecademy.com.  It is an unfortunate tale of the site being hacked, the customer database stolen, the company being sued and as a result of the verdict and legal expenses they have decided to shut down. </span><br />
<blockquote> Dear members, clients and guests of our portal,<br />Over the last few years our portal has helped you to organize your business, find new partners and increase sales.However, all good things end. Many of you know that we have experienced legal problems over the last year. Our competitors from other social networks are trying to take over our client base.<br />Our website has been hacked and our database was stolen. After that we were taken to court because of identity theft.Unfortunately, legal expenses and unfavorable court verdict with following closure of our bank accounts will lead to closure of our website. All paying members will receive refund starting from March 14th.<br />Please check attached file for legal information in regards to your account.</p>
<p>Best regards,</p>
<p>The Ecademy TeamEcademy - The Social Network for Business People<br />Company Registration:3651083 VAT:718 0377 36 </p></blockquote>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/03/get-hacked-get-sued-go-out-of-business/feed/</wfw:commentRss>
		</item>
		<item>
		<title>InfoSec 2007 Presentation - Issues Faced by Organisations Today</title>
		<link>http://www.gilbertverdian.com/security/2008/01/infosec-2007-presentation-issues-faced-by-organisations-today/</link>
		<comments>http://www.gilbertverdian.com/security/2008/01/infosec-2007-presentation-issues-faced-by-organisations-today/#comments</comments>
		<pubDate>Fri, 04 Jan 2008 12:00:46 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/01/infosec-2007-presentation-issues-faced-by-organisations-today/</guid>
		<description><![CDATA[I did a presentation at Infosec 2007 with Symantec at their display. The talk was about current issues faced by organisations ranging from:- Changes in motivation - how monetary gain is evolving threats- Segregated Security functions within organisations that do not work/talk to each other- Burden of regulation and compliance organisations need to adhere to [...]]]></description>
			<content:encoded><![CDATA[<p>I did a presentation at Infosec 2007 with Symantec at their display. The talk was about current issues faced by organisations ranging from:- Changes in motivation - how monetary gain is evolving threats- Segregated Security functions within organisations that do not work/talk to each other- Burden of regulation and compliance organisations need to adhere to and implement controlsI drew upon the findings from the <a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport" target="_blank">2007 Symantec Threat Report</a>, showing how people are after your information (from databases for example) to use for monetary gain. Its not about bragging rights anymore. Here&#8217;s the presentation hosted on slideshare:</p>
<p><object style="margin: 0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=security-compliance-and-management-issues-faced-by-organisations-today-1199445022662990-2"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=security-compliance-and-management-issues-faced-by-organisations-today-1199445022662990-2" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><a href="http://www.slideshare.net/?src=embed"><img src="http://static.slideshare.net/swf/logo_embd.png" style="border-color: initial; margin-bottom: -5px; border-width: 0px; border-style: none" alt="SlideShare" /></a> | <a href="http://www.slideshare.net/gverdian/security-compliance-and-management-issues-faced-by-organisations-today" title="View 'Security Compliance and Management - Issues Faced by Organisations Today.' on SlideShare">View</a> | <a href="http://www.slideshare.net/upload">Upload your own</a></p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/01/infosec-2007-presentation-issues-faced-by-organisations-today/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/01/infosec-2007-presentation-issues-faced-by-organisations-today/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Internal Facebook Phishing or Worm?</title>
		<link>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</link>
		<comments>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 00:03:09 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[hacking]]></category>

		<category><![CDATA[virus, worms &amp; malware]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/</guid>
		<description><![CDATA[Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall
h11p://www.facebook.com.profile.php.id.371233.cn
He also had the  following from another user on his wall
&#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- h11p://www.facebook.com.profile.php.id.371233.cn&#8221;
Of course, the guilty [...]]]></description>
			<content:encoded><![CDATA[<p>Seems one of my facebook contacts&#8217; account was compromised either by phishing or key logging&#8230; &#8220;he&#8221; had posted the following URL onto my wall</p>
<p>h11p://www.facebook.com.profile.php.id.371233.cn</p>
<p>He also had the  following from another user on his wall</p>
<p>&#8220;lol i cant believe these pics got posted&#8230;.its going to be BADDDD when her boyfriend sees these- <a href="h11p://www.facebook.com.profile.php.id.371233.cn/" target="_blank" rel="nofollow"><span>h11p://www.facebook.com.pr</span><wbr></wbr><span class="word_break"></span>ofile.php.id.371233.cn</a>&#8221;</p>
<p>Of course, the guilty domain is 371233.cn&#8230; a whois doesn&#8217;t reveal much..</p>
<p>whois 371233.cn<br />
Domain Name: 371233.cn<br />
ROID: 20071101s10001s02380333-cn<br />
Domain Status: ok<br />
Registrant Organization: 小问<br />
Registrant Name: 笑纹<br />
Administrative Email: 24@244.com<br />
Sponsoring Registrar: 北京新网互联科技有限公司<br />
Name Server:ns1.4980603.com<br />
Name Server:ns2.4980603.com<br />
Name Server:ns3.4980603.com<br />
Name Server:ns4.4980603.com<br />
Registration Date: 2007-11-01 23:30<br />
Expiration Date: 2008-11-01 23:30</p>
<p>Then the whois of the hosted server 4980603.com is</p>
<p>Domain Name&#8230;&#8230;&#8230;. 4980603.com<br />
Creation Date&#8230;&#8230;.. 2007-10-19 18:26:55<br />
Registration Date&#8230;. 2007-10-19 18:26:55<br />
Expiry Date&#8230;&#8230;&#8230;. 2008-10-19 18:26:55<br />
Organisation Name&#8230;. xiaowen<br />
Organisation Address. No.323 chang&#8217;an road<br />
Organisation Address.<br />
Organisation Address. Beijing<br />
Organisation Address. 100001<br />
Organisation Address. BJ<br />
Organisation Address. CN</p>
<p>Admin Name&#8230;&#8230;&#8230;.. top wen<br />
Admin Address&#8230;&#8230;.. No.323 chang&#8217;an road<br />
Admin Address&#8230;&#8230;..<br />
Admin Address&#8230;&#8230;.. Beijing<br />
Admin Address&#8230;&#8230;.. 100001<br />
Admin Address&#8230;&#8230;.. BJ<br />
Admin Address&#8230;&#8230;.. CN<br />
Admin Email&#8230;&#8230;&#8230;. 24@244.com<br />
Admin Phone&#8230;&#8230;&#8230;. +86.1034546677<br />
Admin Fax&#8230;&#8230;&#8230;&#8230; +86.1067688466</p>
<p>Tech Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Tech Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Tech Address&#8230;&#8230;&#8230;<br />
Tech Address&#8230;&#8230;&#8230; Beijing<br />
Tech Address&#8230;&#8230;&#8230; 100001<br />
Tech Address&#8230;&#8230;&#8230; BJ<br />
Tech Address&#8230;&#8230;&#8230; CN<br />
Tech Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Tech Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Tech Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466</p>
<p>Bill Name&#8230;&#8230;&#8230;&#8230; top wen<br />
Bill Address&#8230;&#8230;&#8230; No.323 chang&#8217;an road<br />
Bill Address&#8230;&#8230;&#8230;<br />
Bill Address&#8230;&#8230;&#8230; Beijing<br />
Bill Address&#8230;&#8230;&#8230; 100001<br />
Bill Address&#8230;&#8230;&#8230; BJ<br />
Bill Address&#8230;&#8230;&#8230; CN<br />
Bill Email&#8230;&#8230;&#8230;.. 24@244.com<br />
Bill Phone&#8230;&#8230;&#8230;.. +86.1034546677<br />
Bill Fax&#8230;&#8230;&#8230;&#8230;. +86.1067688466<br />
Name Server&#8230;&#8230;&#8230;. ns4.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns3.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns2.4980603.com<br />
Name Server&#8230;&#8230;&#8230;. ns1.4980603.com</p>
<p>The site looks quite convincing to the user, they haven&#8217;t updated the year to 2008 yet&#8230;</p>
<p><a href="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" title="facebook_phish.png"><img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/facebook_phish.png" alt="facebook_phish.png" height="155" width="435" /></a></p>
<p>The source of the site is basically the following form&#8230;</p>
<p>&lt;form method=&#8221;post&#8221; action=&#8221;login.php&#8221;&gt;&lt;div id=&#8221;loginform&#8221;&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;email&#8221; id=&#8221;label_email&#8221;&gt;Email:&lt;/label&gt;&lt;input type=&#8221;text&#8221; class=&#8221;inputtext&#8221; id=&#8221;email&#8221; name=&#8221;email&#8221; /&gt;&lt;/div&gt;&lt;div class=&#8221;form_row clearfix&#8221;&gt;&lt;label for=&#8221;pass&#8221; id=&#8221;label_pass&#8221;&gt;Password:&lt;/label&gt;&lt;input type=&#8221;password&#8221; class=&#8221;inputpassword&#8221; id=&#8221;pass&#8221; name=&#8221;pass&#8221; value=&#8221;" /&gt;&lt;/div&gt;&lt;label class=&#8221;persistent&#8221;&gt;&lt;input type=&#8221;checkbox&#8221; class=&#8221;inputcheckbox&#8221; onclick=&#8221;document.getElementById(&#8221;persistent_notification&#8221;).style.display=this.checked?&#8221;block&#8221;:&#8221;none&#8221;;&#8221; id=&#8221;persistent&#8221; name=&#8221;persistent&#8221; value=&#8221;1&#8243; /&gt;&lt;span&gt;Remember me&lt;/span&gt;&lt;/label&gt;&lt;div style=&#8221;display: none&#8221; id=&#8221;persistent_notification&#8221;&gt;&lt;div class=&#8221;status&#8221;&gt;&lt;h2&gt;&lt;span id=status_title&gt;By selecting &#8220;remember me&#8221; you will stay logged into this computer until you click logout. If this is a public computer please do not use this feature.&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;<br />
&lt;/div&gt;&lt;div id=&#8221;buttons&#8221; class=&#8221;form_row clearfix&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;input type=&#8221;submit&#8221; value=&#8221;Login&#8221; name=&#8221;login&#8221; id=&#8221;login&#8221; onclick=&#8221;this.disabled=true; this.form.submit();&#8221; class=&#8221;inputsubmit&#8221; /&gt; or &lt;strong&gt;&lt;a id=reg_btn_link  href=&#8221;https://www.facebook.com/r.php?&#8221; &gt;Sign up for Facebook&lt;/a&gt; &lt;/strong&gt;&lt;/div&gt;&lt;p class=&#8221;reset_password form_row&#8221;&gt;&lt;label&gt;&lt;/label&gt;&lt;a href=&#8221;http://www.facebook.com/reset.php&#8221;&gt;Forgot your password?&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/form&gt;</p>
<p>There&#8217;s also a reference to an internal IP&#8230;</p>
<p>&lt;span title=&#8221;10.1.227.120&#8243;&gt;20&lt;/span&gt;&lt;span title=&#8221;19192216&#8243;&gt;07&lt;/span&gt;</p>
<p>Anyone else seen this?</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/01/internal-facebook-phishing-or-worm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Denied by my own blog</title>
		<link>http://www.gilbertverdian.com/security/2008/01/denied-by-my-own-blog/</link>
		<comments>http://www.gilbertverdian.com/security/2008/01/denied-by-my-own-blog/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 23:35:50 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2008/01/denied-by-my-own-blog/</guid>
		<description><![CDATA[Funny that, bad behaviour picked up something and started denying logins from all different ips&#8230; just kept getting the following denied message&#8230;

Had to get in there manually and remove bad behaviour&#8230; will have a look at it on the weekend&#8230;
At least I know it&#8217;s working 
]]></description>
			<content:encoded><![CDATA[<p>Funny that, bad behaviour picked up something and started denying logins from all different ips&#8230; just kept getting the following denied message&#8230;<br />
<img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/picture-1.png" alt="denied" /></p>
<p>Had to get in there manually and remove bad behaviour&#8230; will have a look at it on the weekend&#8230;</p>
<p>At least I know it&#8217;s working <img src='http://www.gilbertverdian.com/security/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2008/01/denied-by-my-own-blog/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2008/01/denied-by-my-own-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Join the CISA group in LinkedIn</title>
		<link>http://www.gilbertverdian.com/security/2007/11/join-the-cisa-group-in-linkedin/</link>
		<comments>http://www.gilbertverdian.com/security/2007/11/join-the-cisa-group-in-linkedin/#comments</comments>
		<pubDate>Wed, 28 Nov 2007 02:15:42 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/?p=40</guid>
		<description><![CDATA[
Using LinkedIn quite extensively, I created a group for CISA qualified professionals to join.
Please visit the following link stating your ISACA membership number and month &#38; year you qualified for the CISA.
http://www.linkedin.com/e/gis/40405/0142006D7B5F
Upon joining you&#8217;ll have the following logo of the CISA letters I made displayed in your profile.

 
]]></description>
			<content:encoded><![CDATA[<div>
<p>Using LinkedIn quite extensively, I created a group for CISA qualified professionals to join.</p>
<p>Please visit the following link stating your ISACA membership number and month &amp; year you qualified for the CISA.</p>
<p><a href="http://www.linkedin.com/e/gis/40405/0142006D7B5F">http://www.linkedin.com/e/gis/40405/0142006D7B5F</a></p>
<p>Upon joining you&#8217;ll have the following logo of the CISA letters I made displayed in your profile.</p>
<p><img src="http://www.gilbertverdian.com/security/wp-content/uploads/2008/01/cisa.png" alt="cisa.png" /></p>
<p> </p></div>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2007/11/join-the-cisa-group-in-linkedin/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2007/11/join-the-cisa-group-in-linkedin/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Job at Ernst &#038; Young</title>
		<link>http://www.gilbertverdian.com/security/2007/11/new-job-at-ernst-young/</link>
		<comments>http://www.gilbertverdian.com/security/2007/11/new-job-at-ernst-young/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 10:32:09 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2007/11/new-job-at-ernst-young/</guid>
		<description><![CDATA[I have recently joined Ernst &#38; Young in London after almost 6 years at CSC in Sydney and the UK. Apologies for the lack of updates on the blog, took some time out and travelled around Europe before starting at EY.
Things are back on track and am looking forward to talking about security, from the [...]]]></description>
			<content:encoded><![CDATA[<p>I have recently joined Ernst &amp; Young in London after almost 6 years at CSC in Sydney and the UK. Apologies for the lack of updates on the blog, took some time out and travelled around Europe before starting at EY.</p>
<p>Things are back on track and am looking forward to talking about security, from the front line.</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2007/11/new-job-at-ernst-young/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2007/11/new-job-at-ernst-young/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Verify CISSP Certification</title>
		<link>http://www.gilbertverdian.com/security/2007/07/verify-cissp-certification/</link>
		<comments>http://www.gilbertverdian.com/security/2007/07/verify-cissp-certification/#comments</comments>
		<pubDate>Tue, 24 Jul 2007 06:57:15 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
		
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2007/07/verify-cissp-certification/</guid>
		<description><![CDATA[The CISSP certification is seen as a standard for security professionals. The exam is based on the following 10 domains:
 - Domain 1 Security Management Practices
 - Domain 2 Security Architecture and Models
 - Domain 3 Preventive Maintenance
 - Domain 4 Application Development Security
 - Domain 5 Operations Security
 - Domain 6 Physical Security
 - [...]]]></description>
			<content:encoded><![CDATA[<p>The CISSP certification is seen as a standard for security professionals. The exam is based on the following 10 domains:<br />
 - Domain 1 Security Management Practices<br />
 - Domain 2 Security Architecture and Models<br />
 - Domain 3 Preventive Maintenance<br />
 - Domain 4 Application Development Security<br />
 - Domain 5 Operations Security<br />
 - Domain 6 Physical Security<br />
 - Domain 7 Cryptography<br />
 - Domain 8 Telecommunications, Network, and Internet Security<br />
 - Domain 9 Business Continuity Planning<br />
 - Domain 10 Law, Investigations, and Ethics</p>
<p>The exam is multiple choice, 250 questions which you have 6 hours to complete. So it is quite a highly sort after certification to have. </p>
<p>To validate people who claim to be certified, the ISC2 have set up the following<a href="https://www.isc2.org/cgi-bin/cert_verification.cgi"> Certification Verification Site</a>. </p>
<p>If a person has a valid certification, the output will look like this:<br />
<a href='http://www.gilbertverdian.com/wp-content/uploads/2007/02/verify_cissp.png' title='verify_cissp.png'><img src='http://www.gilbertverdian.com/wp-content/uploads/2007/02/verify_cissp.png' alt='verify_cissp.png'  height=247 width=351/></a></p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2007/07/verify-cissp-certification/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2007/07/verify-cissp-certification/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 9.284 seconds -->
<!-- Cached page served by WP-Cache -->
