<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PathSecurity.com &#187; Updates</title>
	<atom:link href="http://www.pathsecurity.com/category/updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pathsecurity.com</link>
	<description>Security is a Journey, Not a Destination</description>
	<lastBuildDate>Mon, 24 Oct 2011 04:27:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=311</generator>
		<item>
		<title>So you got: Clampi/Ilomo</title>
		<link>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/</link>
		<comments>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 21:43:25 +0000</pubDate>
		<dc:creator>Rev. Richard E. Baker</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=218</guid>
		<description><![CDATA[So you got one of the most interesting pieces of Malware I have every had the displeasure of doing IR on&#8230; Multi-Stage, evolving, silent&#8230; It seems to always come from drive-by attacks and silently waits for the C&#38;C to provide [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>So you got one of the most interesting pieces of Malware I have every had the displeasure of doing IR on&#8230;</p>
<p>Multi-Stage, evolving, silent&#8230;</p>
<p>It seems to always come from drive-by attacks and silently waits for the C&amp;C to provide instructions&#8230;</p>
<p>I drops onto the system and creates a number of registry keys with difficult to anticipate keys, and files with semi random names. That can make it hard to find, but the one key you can count on appearing is,</p>
<p> &#8211; <strong>HKCUSoftwareMicrosoftInternet ExplorerSettingsGateslist</strong></p>
<p>The most important thing you can do to prevent the spread of Clampi/Ilomo once it is on your network is to do no work with Domain Administrator privileges.  One of the most dangerous aspects of Clampi/Ilomo is its ability to log user credentials and use them to spread across your network using legitimate tools like PSEXEC.</p>
<p>@echo off &amp;&amp; reg query HKCUSoftwareMicrosoftInternet ExplorerSettingsGateslist /s || echo Does not Exist!!!!</p>
<p><a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/ilomo_external.pdf">Ilomo Botnet analyzation by TrendMicro</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2010/06/so-you-got-clampiilomo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>To the 9&#8242;s (my rant)</title>
		<link>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/</link>
		<comments>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 02:00:27 +0000</pubDate>
		<dc:creator>Rev. Richard E. Baker</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Random Rants]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=264</guid>
		<description><![CDATA[System Uptime&#8230; The 9&#8242;s&#8230; We all know it&#8230; We all love it&#8230; But can we ever really reach the holy grail&#8230;. Can we get dressed up for all 5 mythical 9&#8242;s? Let&#8217;s look at exactly what we are shooting for. [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>System Uptime&#8230;<br />
The 9&#8242;s&#8230;<br />
We all know it&#8230;<br />
We all love it&#8230;<br />
But can we ever really reach the holy grail&#8230;.<br />
Can we get dressed up for all 5 mythical 9&#8242;s?<br />
Let&#8217;s look at exactly what we are shooting for.<br />
<span id="more-264"></span></p>
<table width="480" border="5" bgcolor="">
<tbody>
<tr>
<td>9&#8242;s Rating</td>
<td>Percentage Uptime</td>
<td>Annual Downtime</td>
<td>Downtime Per Day</td>
</tr>
<tr>
<td>2</td>
<td>99.000</td>
<td>3 days, 15 hours, 36 minutes</td>
<td>8.4 minutes</td>
</tr>
<tr>
<td>3</td>
<td>99.900</td>
<td>8 hours, 46 minutes</td>
<td>1.4 Minutes</td>
</tr>
<tr>
<td>4</td>
<td>99.990</td>
<td>53 minutes</td>
<td>8.7 seconds</td>
</tr>
<tr>
<td>5</td>
<td>99.999</td>
<td>5 minutes</td>
<td>0.8 Seconds</td>
</tr>
</tbody>
</table>
<p>Thats right we are trying for less then 0.8 seconds of down time per day.</p>
<p>Lets face it customers don&#8217;t care if its your fault that they cant reach you&#8230; they just cant reach you&#8230; They dont know if its your server or a router or your firewall or your internet WAN provider&#8230; all that they see is a service that cannot be connected to&#8230;</p>
<p>So&#8230;</p>
<p>Lets make some assumptions, average ping 50ms, from anywhere to anywhere, thats a 16 packet window&#8230; if only one user was utilizing the &#8220;stream&#8221;&#8230; thats insane&#8230; how do you guaranty that you wont lose 16 packets. Now I know any Company that thinks it needs a 5 9 service is going to have more then ONE user at a time&#8230;</p>
<p>So maybe 16 packets is so small that customers wont notice&#8230; but it still happened&#8230; and you&#8217;ve already blown your 9&#8242;s&#8230;</p>
<p>To often small and medium companies focus on making sure that their back end and servers have the 9&#8242;s but forget to factor in the rest of the world, the tubes that connect us all are not under our control&#8230; accidents and congestion happens&#8230; (<a href="http://arstechnica.com/old/content/2008/02/insecure-routing-redirects-youtube-to-pakistan.ars">occasionally black holes appear the suck up all the traffic from Youtube</a>). Unless you&#8217;ve got the power and cash of Google your never gonna reach more then 3 9&#8242;s&#8230; if you&#8217;re moving a Million USD a minute then maybe you have a business case&#8230;</p>
<p>Downtime is never acceptable&#8230; but ask your self can you afford to be truly dressed to the 9&#8242;s?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/12/to-the-9s-my-rant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Things To Do:</title>
		<link>http://www.pathsecurity.com/2009/04/things-to-do/</link>
		<comments>http://www.pathsecurity.com/2009/04/things-to-do/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 00:16:28 +0000</pubDate>
		<dc:creator>Rev. Richard E. Baker</dc:creator>
				<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.pathsecurity.com/?p=90</guid>
		<description><![CDATA[I have been doing a significant amount of self evaluation lately.  Thinking about the things I want to do, not just professionally, but personally.  Things I have held off of because the timing was never right, money was never there, insert some other excuses here. The list [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>I have been doing a significant amount of self evaluation lately.  Thinking about the things I want to do, not just professionally, but personally.  Things I have held off of because the timing was never right, money was never there, insert some other excuses here.</p>
<p>The list is always changing&#8230; but there are a few things that always seem to come up.  There are items on the list that are new, but still eat at the back of my thoughts.  Some I think everyone wishes they could do.</p>
<p>The list includes:</p>
<ul>
<li>Learn To Fly.</li>
<li>Train for MMA, and then fight in at least one real fight.</li>
<li>Get a degree (There will be hacking, more to come on this one).</li>
<li>Teach SANS 401.</li>
<li>Post to this blog once a day.</li>
<li>Goto cooking school, something like the California Cooking Academy</li>
<li>Learn a foreign language, something like Japanese or Chinese.</li>
<li>Write a book.</li>
</ul>
<p>Not a great list, nothing that will change the world, but other then monetary gains, buying a house and such, thats what I want to do&#8230; People say the best way to get things done is to tell others your going to do them, Now I have.  Watch for updates.</p>
<p>(P.S. If you can help me with any of these  let me know.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pathsecurity.com/2009/04/things-to-do/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

