<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://taw.net/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Information Technology</title><subtitle type="html" /><id>http://taw.net/blogs/it/atom.aspx</id><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/default.aspx" /><link rel="self" type="application/atom+xml" href="http://taw.net/blogs/it/atom.aspx" /><generator uri="http://communityserver.org" version="3.1.20917.1142">Community Server</generator><updated>2007-11-23T07:14:00Z</updated><entry><title>Security Awareness Training updated</title><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/archive/2010/02/28/security-awareness-trainin-updated.aspx" /><id>http://taw.net/blogs/it/archive/2010/02/28/security-awareness-trainin-updated.aspx</id><published>2010-02-28T20:22:00Z</published><updated>2010-02-28T20:22:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;The Security Awareness Badge is awarded to anyone that reviews the material and passes the test.&lt;/p&gt;&lt;p&gt;It is required for Officers, OS members and any Administrators of servers. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;The post has been updated to clean up some link.&lt;/p&gt;&lt;p&gt;See it here:&amp;nbsp;&lt;a href="http://taw.net/forums/p/7232/19176.aspx#19176" title="Security Awarness Info"&gt; http://taw.net/forums/p/7232/19176.aspx#19176&lt;/a&gt;&lt;/p&gt;&lt;img src="http://taw.net/aggbug.aspx?PostID=99601" width="1" height="1"&gt;</content><author><name>Bones</name><uri>http://taw.net/members/Bones.aspx</uri></author></entry><entry><title>Update your Acrobat Reader</title><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/archive/2008/02/09/update-your-acrobat-reader.aspx" /><id>http://taw.net/blogs/it/archive/2008/02/09/update-your-acrobat-reader.aspx</id><published>2008-02-09T21:40:00Z</published><updated>2008-02-09T21:40:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;There is a vulnerability in Acrobat Reader.&amp;nbsp; You need to update to 8.1.2 or higher to eliminate the vulnerability.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=3958" title="Acrobat Reader Vulnerability"&gt;More info.&amp;nbsp;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://taw.net/aggbug.aspx?PostID=8431" width="1" height="1"&gt;</content><author><name>Bones</name><uri>http://taw.net/members/Bones.aspx</uri></author><category term="acrobat reader security" scheme="http://taw.net/blogs/it/archive/tags/acrobat+reader+security/default.aspx" /></entry><entry><title>Gamers Beware</title><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/archive/2007/12/10/gamers-beware.aspx" /><id>http://taw.net/blogs/it/archive/2007/12/10/gamers-beware.aspx</id><published>2007-12-11T06:39:00Z</published><updated>2007-12-11T06:39:00Z</updated><content type="html">&lt;p&gt;


	
	
	
	
	
	
	
	


&lt;/p&gt;&lt;p style="margin-bottom:0in;"&gt;Like all Internet users, we have to
defend against all the riff raff out there.  There are also attacks
aimed specifically at Gamers.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;Here is alook at some recent incidents
involving malware targetted at gamers.  Back in April, there was a
fake Teamspeak patch loaded on the Teamspeak website.  It looks like
hackers compromised the Teamspeak web site.  Then, they uploaded a
fake patch with malware.  Lastly, they sent an email to everyone with
a forum account on the Teamspeak web site to download the fake patch.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;More info:
&lt;a href="http://isc.sans.org/diary.html?storyid=2634"&gt;http://isc.sans.org/diary.html?storyid=2634&lt;/a&gt;&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;There have been a couple of attacks
aimed specifically at WoW users.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;“The reason for this, according to
the BBC, is that player accounts with WoW are seen as a valuable
target for cybercriminals, “&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;More info:
&lt;a href="http://www.viruslist.com/en/news?id=208274064"&gt;http://www.viruslist.com/en/news?id=208274064&lt;/a&gt;&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;“Online games have long been targeted
by malware, mainly due to the thriving virtual economy underlying
them.”&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;More info:
&lt;a href="http://blog.trendmicro.com/world-of-warcraft-fan-site-compromised/"&gt;http://blog.trendmicro.com/world-of-warcraft-fan-site-compromised/&lt;/a&gt;&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;Another interesting case is a recent
vulnerability in the Quicktime player.  If a users views a specially
crafted movie, their machine can be compromised.  This vulnerability
was leveraged for an attack on the Second Life game.  In the game if
you get close to another user&amp;#39;s property, they can have it set to
play a quicktime video.  If they upload a specially crafted video,
any users that gets close to their property gets compromised.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;To avoid getting compromised, be sure
and do all the standard recommendations.  Use a firewall, keep OS up
to date, run antivirus with updated signatures.  You also need to
keep other applications updated such as media players and document
viewers.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;Most importantly, keep your antenna up
and be suspicious.  If something looks fishy, proceed with caution. 
Try to verify patches etc with a second source.  Keep in mind that
“trusted” sites could be compromised and be hosting malware.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;For TAW members, you can review the
material for the Security Awareness badge and pass the test to earn
the badge.&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p style="margin-bottom:0in;"&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;img src="http://taw.net/aggbug.aspx?PostID=2082" width="1" height="1"&gt;</content><author><name>Bones</name><uri>http://taw.net/members/Bones.aspx</uri></author><category term="security" scheme="http://taw.net/blogs/it/archive/tags/security/default.aspx" /><category term="TAW" scheme="http://taw.net/blogs/it/archive/tags/TAW/default.aspx" /><category term="Active" scheme="http://taw.net/blogs/it/archive/tags/Active/default.aspx" /><category term="frontpage" scheme="http://taw.net/blogs/it/archive/tags/frontpage/default.aspx" /><category term="announcements" scheme="http://taw.net/blogs/it/archive/tags/announcements/default.aspx" /></entry><entry><title>Kidagoat</title><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/archive/2007/11/29/kidagoat.aspx" /><id>http://taw.net/blogs/it/archive/2007/11/29/kidagoat.aspx</id><published>2007-11-29T19:36:00Z</published><updated>2007-11-29T19:36:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;Kidagoat has been moved up to the RA position and is now the rank of Captain&lt;br /&gt;&lt;/p&gt;&lt;img src="http://taw.net/aggbug.aspx?PostID=416" width="1" height="1"&gt;</content><author><name>Ironhead</name><uri>http://taw.net/members/Ironhead.aspx</uri></author></entry><entry><title>VMware for more security</title><link rel="alternate" type="text/html" href="http://taw.net/blogs/it/archive/2007/11/23/vmware-for-more-security.aspx" /><id>http://taw.net/blogs/it/archive/2007/11/23/vmware-for-more-security.aspx</id><published>2007-11-23T08:14:00Z</published><updated>2007-11-23T08:14:00Z</updated><content type="html">&lt;p&gt;The idea is this.&amp;nbsp;&amp;nbsp;Do high risk activities on a VMmachine.&amp;nbsp; If&amp;nbsp;it gets infected,&amp;nbsp;revert or delete and start over.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a class="" title="VMware" href="http://vmware.com/" target="_blank"&gt;VMware&lt;/a&gt; has a couple of free products.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;VMware Player is the easiest one.&amp;nbsp; You can run pre-made VMmachines like the Browser Appliance.&lt;/p&gt;
&lt;p&gt;VMware Server is also free.&amp;nbsp; You need to register to get license keys.&amp;nbsp; It has some additional functionality above the Player.&amp;nbsp; For example, you can create one snapshot for each VM.&amp;nbsp; I recommended VMware Server.&amp;nbsp; It is free and has more capability.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;After you install VMware, the next thing you need is a virtual machine.&amp;nbsp; You can create one or use a pre made appliance like the &lt;a class="" title="Browser Appliance" href="http://www.vmware.com/appliances/directory/browserapp.html" target="_blank"&gt;Browser Appliance&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;If you are browing to some web sites you don&amp;#39;t trust.&amp;nbsp; You can start up the Browser Appliance and surf from there.&amp;nbsp; This is a linux based Virtual Machine (VM) with Firefox.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Worried about bookmarks?&amp;nbsp; You can use &lt;a class="" title="yummy" href="http://del.icio.us/" target="_blank"&gt;del.ico.us&lt;/a&gt; to have centrally managed bookmarks from all the computers you use (real and virutal).&amp;nbsp; With delicious, you can create a bookmark on your PC and then use it from your Browser Appliance.&lt;/p&gt;
&lt;p&gt;Do you have some software you are installing and your not sure if you trust it?&amp;nbsp; Install it on a VM first and make sure it doesn&amp;#39;t do anything mailicious.&amp;nbsp; If you want to run XP on a VM, you need a separate license for it.&lt;/p&gt;&lt;img src="http://taw.net/aggbug.aspx?PostID=349" width="1" height="1"&gt;</content><author><name>Bones</name><uri>http://taw.net/members/Bones.aspx</uri></author><category term="security" scheme="http://taw.net/blogs/it/archive/tags/security/default.aspx" /><category term="vmware" scheme="http://taw.net/blogs/it/archive/tags/vmware/default.aspx" /></entry></feed>