<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-29857200</id><updated>2008-11-13T04:07:36.454+02:00</updated><title type='text'>Away</title><subtitle type='html'>Current issues, reading suggestion and a little bit of cheap philosophy regarding information security.
&lt;br&gt;
&lt;br&gt;
By Andre Fucs</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.fucs.org/english/atom.xml'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>13</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-29857200.post-1992354041067518047</id><published>2008-11-07T13:21:00.007+02:00</published><updated>2008-11-13T04:07:36.474+02:00</updated><title type='text'>No, I'm not coming back yet... but I keep reading the blogsphere...</title><summary type='text'>Hey fellas, hope you still remember this blog exists. :-)

Well... It still does and although I do not frequently write in here from time to time I feel an urge to do so.

Earlier this week I was reading Security Balance, a friend's blog and noticed that his last post raised few concerns on the so called virtualization security. Also is his blog, Mike DiPetrillo criticizes Augusto for spreading </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/1992354041067518047/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=1992354041067518047' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/1992354041067518047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/1992354041067518047'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2008/11/no-im-not-coming-back-yet-but-i-keep.html' title='No, I&apos;m not coming back yet... but I keep reading the blogsphere...'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-9174521041950923950</id><published>2008-07-25T07:53:00.006+03:00</published><updated>2008-07-25T08:09:30.891+03:00</updated><title type='text'>DNS attack reminder</title><summary type='text'>Ladies and Gentleman managing DNS servers.

Please, remind to review your DNS and firewall configurations in order to ensure random source ports!

I've seen several "patched" DNS servers going to the internet with fixed source ports, something that more or less nulls the patches released by the vendors.

Why not to test your DNS today? (tip by Rubens Kuhl Jr.)

https://www.dns-oarc.net/oarc/</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/9174521041950923950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=9174521041950923950' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/9174521041950923950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/9174521041950923950'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2008/07/dns-attack-reminder.html' title='DNS attack reminder'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-116233900337640087</id><published>2006-11-01T01:54:00.000+02:00</published><updated>2006-11-01T01:57:33.790+02:00</updated><title type='text'>Aladdin Day: Tel Aviv</title><summary type='text'>I could never imagine that I would ever hear the expression "two factor authentication" so many times. :-)
</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/116233900337640087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=116233900337640087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116233900337640087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116233900337640087'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/11/aladdin-day-tel-aviv.html' title='Aladdin Day: Tel Aviv'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-116233884555594382</id><published>2006-11-01T01:46:00.000+02:00</published><updated>2006-11-01T01:54:05.556+02:00</updated><title type='text'>IMS Security</title><summary type='text'>In my article, Voice over IP: New Telephony and Security,  I've made a quick comment regarding the IP Multimedia Subsystem however no details or explanations were provided. Recently  Emmanuel Gadaix, a great person and amazing professional, made a introductory presentation regarding IMS Security. The PPT file can be found here.

The picture get clearer every day: It's not only a convergence of </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/116233884555594382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=116233884555594382' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116233884555594382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116233884555594382'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/11/ims-security.html' title='IMS Security'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-116199109874514238</id><published>2006-10-28T00:54:00.000+02:00</published><updated>2006-10-28T01:21:01.940+02:00</updated><title type='text'>The quest for the Holy Grail</title><summary type='text'>Ross Anderson posted a comment regarding an idea that the British banking system is studying as a solution to eliminate phishing attacks. Anderson's comments are greatly precise but I got myself thinking:

Is the search for an ideal strong authentication a quest for a new holy grail?</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/116199109874514238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=116199109874514238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116199109874514238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116199109874514238'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/10/quest-for-holy-grail.html' title='The quest for the Holy Grail'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-116195563481175227</id><published>2006-10-27T15:04:00.000+02:00</published><updated>2006-10-27T15:31:37.360+02:00</updated><title type='text'>It’s a wild world</title><summary type='text'>Recently Pedro Dória, a journalist friend of mine posted some interesting results about this new toy, Google Trends. I was doing some tests when I got surprised by one of the query results.

Bellow we can se the results for volume of search of three different queries: exploit, windows exploit and linux exploit.


exploit


linux exploit


windows exploit

Although I tend to agree that Google is </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/116195563481175227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=116195563481175227' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116195563481175227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116195563481175227'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/10/its-wild-world.html' title='It’s a wild world'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-116177442790128313</id><published>2006-10-25T12:52:00.000+02:00</published><updated>2006-10-25T13:10:23.916+02:00</updated><title type='text'>Laptop seizure, a reality not so distant from you</title><summary type='text'>Not a long time ago, Bruce Schneier posted on his blog a note regarding Laptop seizures by the Sudanese government and mentioned rumors about this practice in Israel. After few days he edited the post observing that currently this is a legal practice within USA borders. Let's say it was a quite funny repercussion.

Now, circa one month after the International Herald Tribune published an article </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/116177442790128313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=116177442790128313' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116177442790128313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/116177442790128313'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/10/laptop-seizure-reality-not-so-distant.html' title='Laptop seizure, a reality not so distant from you'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115914062904383055</id><published>2006-09-25T01:16:00.000+03:00</published><updated>2006-09-25T16:17:05.660+03:00</updated><title type='text'>Where is my shawarma (or, Identity Theft, israeli style)</title><summary type='text'>As some of you know, I was born in Brazil and I had been living in Israel since may 2006. This is my second time in the country. First time was last year when I came here to work. I liked the place so much that I decided to come back and enjoy the Mediterranean life.

Life in this country is quite nice but a little bit peculiar. Firstly because of the fact that most people don't have a single </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115914062904383055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115914062904383055' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115914062904383055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115914062904383055'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/09/where-is-my-shawarma-or-identity-theft.html' title='Where is my shawarma (or, Identity Theft, israeli style)'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115871705816070727</id><published>2006-09-20T04:38:00.000+03:00</published><updated>2006-09-20T04:55:40.100+03:00</updated><title type='text'>Becker and Posner on Identity Theft</title><summary type='text'>The 1992 Nobel Prize in Economic Sciences, Gary Becker and his fellow Professor, Judge Richard Posner posted on Deterring  Identity Theft.

Becker

&amp;

Posner


As an information security professional and frequent reader of their posts all I can say is that I will keep reading their blog despite those weird posts. :-)</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115871705816070727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115871705816070727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115871705816070727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115871705816070727'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/09/becker-and-posner-on-identity-theft.html' title='Becker and Posner on Identity Theft'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115594820214569351</id><published>2006-08-19T03:41:00.000+03:00</published><updated>2006-08-19T03:44:31.143+03:00</updated><title type='text'>Att: Mr Al Kyder and Terry Wrist please board....</title><summary type='text'>Producers of Australian Broadcasting's (ABC) The Chaser's War on Everything satirical programme booked two tickets on a Wednesday flight to Melbourne with low-cost carrier Virgin Blue. The tickets were in the names of "Al Kyder" and "Mr Terry Wrist," New South Wales daily Sydney Morning Herald is reporting.

Source: FlightGlobal.com

I must confess that they had an amazing idea. :-)</summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115594820214569351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115594820214569351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115594820214569351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115594820214569351'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/08/att-mr-al-kyder-and-terry-wrist-please.html' title='Att: Mr Al Kyder and Terry Wrist please board....'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115222587807336899</id><published>2006-07-07T01:37:00.000+03:00</published><updated>2006-07-07T01:44:38.080+03:00</updated><title type='text'>Is "defense-in-depth" the real answer?</title><summary type='text'>Recently I had been involved in a mail thread regarding the well-accepted application of the "defense in depth"  doctrine withing information systems security. I maybe mistaken but it sounds like a mistake to defend such approach when even the modern armies are developing network/information centered warfare tactics.

As the Wikipedia entry for the UK Network Enabled Capability states:
NEC is </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115222587807336899/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115222587807336899' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115222587807336899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115222587807336899'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/07/is-defense-in-depth-real-answer.html' title='Is &quot;defense-in-depth&quot; the real answer?'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115209198639709686</id><published>2006-07-05T11:02:00.000+03:00</published><updated>2006-07-05T12:33:06.420+03:00</updated><title type='text'>VoIP users target by regular phishing</title><summary type='text'>Vono, a leading Brazilian VoIP service, informed their customers about a phishing attempt involving their services. As usual, users were lead by different ways to a clonned website for password recording purposes. Until here no lesson to be learned, Vono service is a prepaid VoIP service that can be paind either by invoice or a non displayed credit card, this last payment method also offers a </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115209198639709686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115209198639709686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115209198639709686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115209198639709686'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/07/voip-users-target-by-regular-phishing.html' title='VoIP users target by regular phishing'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29857200.post-115056419261810481</id><published>2006-06-17T20:09:00.000+03:00</published><updated>2006-06-17T20:09:52.626+03:00</updated><title type='text'>VoIP Security</title><summary type='text'>Brazilian songwriter Chico Science used to say that “one step forward and you’re not at the same place anymore”. Unfortunately, this new place is not always the ideal world we longed to be. This is the reality that many companies are delving into the Voice over IP land are facing. Problems with security are many and, once again are driven by the usual expectation for panaceas; companies are </summary><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/115056419261810481/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=29857200&amp;postID=115056419261810481' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115056419261810481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29857200/posts/default/115056419261810481'/><link rel='alternate' type='text/html' href='http://www.fucs.org/english/2006/06/voip-security.html' title='VoIP Security'/><author><name>Andre Fucs</name><uri>http://www.blogger.com/profile/13598166732495572569</uri><email>noreply@blogger.com</email></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry></feed>