<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MSI :: State of Security</title>
	<atom:link href="http://stateofsecurity.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://stateofsecurity.com</link>
	<description>Insight from the Information Security Experts</description>
	<lastBuildDate>Fri, 05 Feb 2010 17:18:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Emerging Web Scans from the HITME</title>
		<link>http://stateofsecurity.com/?p=910</link>
		<comments>http://stateofsecurity.com/?p=910#comments</comments>
		<pubDate>Fri, 05 Feb 2010 17:18:24 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=910</guid>
		<description><![CDATA[We started picking up a few very low intensity scans last night. The pace of them are increasing. They appear to be aimed at cataloging users of the ANT tool. You can find a list of the scanning targets and a link to BrainWebScan here, if you would like to check for them yourself.
If you [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D910"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D910" height="61" width="51" /></a></div><p>We started picking up a few very low intensity scans last night. The pace of them are increasing. They appear to be aimed at cataloging users of the ANT tool. <a title="Targets and tool" href="http://hurl.ws/ayqq" target="_blank">You can find a list of the scanning targets and a link to BrainWebScan here</a>, if you would like to check for them yourself.</p>
<p>If you are a MicroSolved Managed Assessment (GuardDog) client, your systems will be tested during your next scheduled assessment.</p>
<p>If you have any questions or would like to know more about our ongoing assessment services, threat management or application security testing, feel free to email us at info [at] microsolved [dot] C O M or give us a shout at 1-877-351-1237. We would love to discuss it with you!</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=910</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Media and Reputational Risk: 3 Ways to Keep It Real &#8211; And Safe</title>
		<link>http://stateofsecurity.com/?p=900</link>
		<comments>http://stateofsecurity.com/?p=900#comments</comments>
		<pubDate>Tue, 02 Feb 2010 19:50:03 +0000</pubDate>
		<dc:creator>mmaguire</dc:creator>
				<category><![CDATA[End-user Focused]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=900</guid>
		<description><![CDATA[
You have employees who are addicted to social media, updating their status, sharing everything from discovering a helpful business link to where they went for lunch. However, they also may be broadcasting information not intended for public consumption.
One of the most difficult tasks  for an organization is  conveying the importance of discretion for [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D900"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D900" height="61" width="51" /></a></div><p><a href="http://stateofsecurity.com/wp-content/uploads/2010/02/1104507_70670260.jpg"><img class="alignleft size-medium wp-image-901" title="1104507_70670260" src="http://stateofsecurity.com/wp-content/uploads/2010/02/1104507_70670260-225x300.jpg" alt="" width="180" height="240" /></a></p>
<p>You have employees who are addicted to social media, updating their status, sharing everything from discovering a helpful business link to where they went for lunch. However, they also may be broadcasting information not intended for public consumption.</p>
<p>One of the most difficult tasks  for an organization is  conveying the importance of discretion for employees who use social media. Not only are organizations at risk from having their networks attacked, but they must protect their reputation and proprietary ideas.  What makes these two areas difficult to protect is their mobile nature. Ideas are invisible and have a habit of popping into conversations &#8211; and not always with the people who should be hearing them. They can get lost or stolen without anyone knowing they&#8217;re even gone. Suddenly, you find your competitor releasing a great product to your market that you thought was yours alone.</p>
<p>If you want to decrease such liabilities, you have a few options. Initiate some guidelines for employees. Send friendly reminders from newsworthy “social-media-gone-bad” stories. The more employees know where an organization stands in regard to safe social media use, the more they can be smart about using it. Here are three basic rules to help them interact safely:</p>
<p><strong>1. Don&#8217;t announce interviews, raises, new jobs, or new projects.</strong><br />
Talking about any of these sensitive topics on social networking sites can be damaging.  If an employee suddenly announces to the world that they’re working on a new project with XYZ Company, there’s a good chance the news will be seen by a competitor. You may see them in the waiting room of your client on your next visit. One caveat: If you’re hiring, it’s a good thing. Your organization will be seen as successful and growing. However, those types of updates are usually best left to the HR department.</p>
<p><strong>2. Don&#8217;t badmouth current or previous employers.</strong><br />
It’s good to remember what mom used to say, “If you don’t have anything positive to say, then say nothing at all.” The Internet never forgets. When an employee rants about either their past employer, or worse &#8211; their current one, it can poison a customer’s view of the organization. Nothing can kill the possibility of a new sale than hearing an employee broadcast sour grapes. If this is a common occurrence, it can give  the image of a badly managed company. This isn’t the message to send to either customers or future employees.</p>
<p><strong>3. Stay professional. Represent the organization’s values well.</strong><br />
Employees are often tempted to mix their personal and work information together when using social media. Although many times, such information can be benign, you don’t want to hear about an employee’s wild night at the local strip club. There are mixed opinions among experts whether an employee should establish a personal account, separate from their work life.</p>
<p>Emphasize your organization’s values and mission. Ask employees to TBP (Think Before Posting). Social media can be a good experience as long as its done responsibly.</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=900</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Cheat Sheets, A Collection!</title>
		<link>http://stateofsecurity.com/?p=896</link>
		<comments>http://stateofsecurity.com/?p=896#comments</comments>
		<pubDate>Wed, 27 Jan 2010 16:55:58 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=896</guid>
		<description><![CDATA[I don&#8217;t know about you, but I LOVE cheat sheets. I absolutely use the crap out of them.
Today, someone (I lost the email since then), sent me this page that has a boatload of cheat sheets in one locale. Thanks to whoever sent it, you know who you are.  
Check them out here. 
I [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D896"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D896" height="61" width="51" /></a></div><p>I don&#8217;t know about you, but I LOVE cheat sheets. I absolutely use the crap out of them.</p>
<p>Today, someone (I lost the email since then), sent me this page that has a boatload of cheat sheets in one locale. Thanks to whoever sent it, you know who you are. <img src='http://stateofsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://hurl.ws/afw2" target="_blank">Check them out here. </a></p>
<p>I hope you find something useful there. I know I did!</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=896</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We Have An iPhone App for Our Blog!</title>
		<link>http://stateofsecurity.com/?p=894</link>
		<comments>http://stateofsecurity.com/?p=894#comments</comments>
		<pubDate>Mon, 25 Jan 2010 20:20:23 +0000</pubDate>
		<dc:creator>mmaguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=894</guid>
		<description><![CDATA[Our press release:
MSI RELEASES IPHONE APP FOR “STATE OF SECURITY” BLOG 
MSI Offers Free Tool to Allow Access to Blog’s RSS Through iPhone App
COLUMBUS, Ohio January 26, 2010 &#8212; MicroSolved, Inc. (MSI) is pleased to introduce a fun free tool to add to a user’s iPhone app menu. Now readers of the “State of Security” [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D894"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D894" height="61" width="51" /></a></div><p>Our press release:</p>
<p><strong>MSI RELEASES IPHONE APP FOR “STATE OF SECURITY” BLOG </strong><br />
MSI Offers Free Tool to Allow Access to Blog’s RSS Through iPhone App</p>
<p>COLUMBUS, Ohio January 26, 2010 &#8212; MicroSolved, Inc. (MSI) is pleased to introduce a fun free tool to add to a user’s iPhone app menu. Now readers of the “State of Security” blog can easily keep track of updates through a simple application that is available through Apple’s iTunes Store. The tool is designed to make it easier for security people to track emerging threats and stay up to date with security news.</p>
<p>MicroSolved’s “State of the Security” blog not only covers an array of security topics, but also is the launching pad for collaborative projects and quick online chats regarding “hot” threats of the day. The blog is very popular among security teams, CISOs and others with an interest in information security.</p>
<p><strong>Those who would like to add the free application to their iPhone can download it </strong><a href="http://itunes.apple.com/us/app/stateofsecurity/id348972481?mt=8"><strong>here</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=894</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Transcript From Aurora Vulnerability Chat</title>
		<link>http://stateofsecurity.com/?p=891</link>
		<comments>http://stateofsecurity.com/?p=891#comments</comments>
		<pubDate>Fri, 22 Jan 2010 18:30:11 +0000</pubDate>
		<dc:creator>mmaguire</dc:creator>
				<category><![CDATA[Chat]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=891</guid>
		<description><![CDATA[If you were unable to join us for the chat today, covering the Aurora Vulnerability, you can now view the transcript here.
AuroraVulnChat 1-22-10
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D891"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D891" height="61" width="51" /></a></div><p>If you were unable to join us for the chat today, covering the Aurora Vulnerability, you can now view the transcript here.</p>
<p><a href="http://stateofsecurity.com/wp-content/uploads/2010/01/AuroraVulnChat-1-22-10.pdf">AuroraVulnChat 1-22-10</a></p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=891</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FLASH Campfire Chat January 22 at 10 AM: The Aurora Vulnerability</title>
		<link>http://stateofsecurity.com/?p=889</link>
		<comments>http://stateofsecurity.com/?p=889#comments</comments>
		<pubDate>Thu, 21 Jan 2010 15:23:02 +0000</pubDate>
		<dc:creator>mmaguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=889</guid>
		<description><![CDATA[Much media attention has been focused on the recent Internet Explorer vulnerabilities and the attacks and compromises of several large companies. Rumors are flying fast and furious around the Internet. Come learn about the technical exposures of these vulnerabilities, the suggest options for protection of your organization, and a discussion about what your peers are [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D889"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D889" height="61" width="51" /></a></div><p>Much media attention has been focused on the recent Internet Explorer vulnerabilities and the attacks and compromises of several large companies. Rumors are flying fast and furious around the Internet. Come learn about the technical exposures of these vulnerabilities, the suggest options for protection of your organization, and a discussion about what your peers are doing to manage this and other client-side attacks. Cut through the hype, ignore the hyperbole and let&#8217;s get down to the brass tacks. Attendees of this session will get an overview of the Aurora vulnerability, insights into client-side attack tactics and come away with suggestions for risk minimization.</p>
<p>Here are the details:</p>
<p>Date: Friday, January 22<br />
Time: 10:00 AM EST<br />
<a href="https://microsolved.campfirenow.com/89622"><strong>Location: Our Campfire Chat Room</strong></a></p>
<p>Looking forward to seeing you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=889</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is IE Still on the Desktop at Your Organization?</title>
		<link>http://stateofsecurity.com/?p=884</link>
		<comments>http://stateofsecurity.com/?p=884#comments</comments>
		<pubDate>Tue, 19 Jan 2010 13:47:45 +0000</pubDate>
		<dc:creator>Brent Huston</dc:creator>
				<category><![CDATA[End-user Focused]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=884</guid>
		<description><![CDATA[
I know that the IE infection is hard to kick. The most common argument I hear, many sites just don&#8217;t work with anything but Internet Explorer.
Is this a true issue, or merely an excuse for inaction? I know a few organizations that have installed alternative browsers (OK, Firefox, in all cases), and blocked all external [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D884"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D884" height="61" width="51" /></a></div><p><a href="http://stateofsecurity.com/wp-content/uploads/2010/01/image_49a4a1ea3063c.jpg"><img class="alignleft size-medium wp-image-885" title="image_49a4a1ea3063c" src="http://stateofsecurity.com/wp-content/uploads/2010/01/image_49a4a1ea3063c-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>I know that the IE infection is hard to kick. The most common argument I hear, many sites just don&#8217;t work with anything but Internet Explorer.</p>
<p>Is this a true issue, or merely an excuse for inaction? I know a few organizations that have installed alternative browsers (OK, Firefox, in all cases), and blocked all external access to IE users. They then take the help desk calls, check the sites that the users say won&#8217;t work with anything but IE, make sure they meet a business need, and then one by one add them into the proxy to be allowed out with IE.</p>
<p>Sure, this is a lot of work on the front end. Here&#8217;s the rub, though. 30 days out, the work drops like a hot stone in the hands of a yeti. Basically, the ongoing need to add sites become so infrequent as to be non-existant and handled with a one-off approval process. In terms of risk, the few who have taken this approach claim such a huge reduction in spyware cleanup, infections and basic break/fix calls that they say the longer term savings paid for the work of the 30 day period in less than 3 months. Thats a 90 day, 100% ROI for a 120 day project!!!! In business terms, this is a NO BRAINER.</p>
<p>Given the oddity of Aurora, the history of IE vulnerabilities and the ease at which new users of Firefox, Opera, Chrome, Safari, et all become proficient, the deck begins to stack in favor of replacing IE for Internet-bound traffic in all but a limited set of cases. Sure, use IE for that odd website, for those internal legacy apps where code-rewrite is not feasible. Heck, in this case, maybe even allow IE 6 to live on for internal use only (pray for no internal malware or xss attacks). We all know the real attack surface for IE is overwhelmingly the Internet.</p>
<p>Maybe this approach will work for you. Consider it. It works even better when combined with proper egress filtering, enclaving and role-based access controls.</p>
<p>Let me know what you think!</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=884</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Honeypots Can Help You</title>
		<link>http://stateofsecurity.com/?p=881</link>
		<comments>http://stateofsecurity.com/?p=881#comments</comments>
		<pubDate>Thu, 14 Jan 2010 12:33:09 +0000</pubDate>
		<dc:creator>mmaguire</dc:creator>
				<category><![CDATA[General InfoSec]]></category>
		<category><![CDATA[HoneyPoint]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=881</guid>
		<description><![CDATA[A honeypot is a trap set to detect or deflect attempts at unauthorized use of information systems. Generally it consists of a computer, data or a network site that appears to be part of a network but which is actually isolated and protected, and which seems to contain information that would be of value to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D881"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D881" height="61" width="51" /></a></div><p>A honeypot is a trap set to detect or deflect attempts at unauthorized use of information systems. Generally it consists of a computer, data or a network site that appears to be part of a network but which is actually isolated and protected, and which seems to contain information that would be of value to attackers.</p>
<p>It is important to note that honeypots are not a solution in themselves. They are a tool. How much they can help you depends upon what you are trying to achieve.</p>
<p>There are two different types of honeypots: production and research. Production honeypots are typically used by companies and corporations. They’re easy to use and capture only limited information.</p>
<p>Research honeypots are more complex. They capture extensive information, and used primarily by research, military, or government organizations.</p>
<p>The purpose of a production honeypot is to mitigate risk to an organization. It’s part of the larger security strategy to detect threats. The purpose of a research honeypot is to collect data on the blackhat community. They are used to gather the general threats against an organization, enabling the organization to strategize their response and protect their data.</p>
<p>The value of honeypots lies in its simplicity. It’s technology that is intended to be compromised. There is little or no production traffic going to or from the device. This means that any time a connection is sent to the honeypot, it is most likely to be a probe, scan, or even attack. Any time a connection is initiated from the honeypot, this most likely means the honeypot was compromised. As we say about our HoneyPoint Security Server, any traffic going to or from the honeypot is, by definition, suspicious at best, malicious at worst. Now, this is not always the case. Mistakes do happen, such as an incorrect DNS entry or someone from accounting inputting the wrong IP address. But in general, most honeypot traffic represents unauthorized activity. What are the advantages to using honeypots?</p>
<ol>
<li><strong>Honeypots collect very little data.</strong> What they do collect is normally of high value. This eliminates the noise, making  it much easier to collect and archive data. One of the greatest problems in security is sifting through gigabytes of useless data to find something meaningful. Honeypots can give users the exact information they need in a quick and easy to understand format.</li>
<li><strong>Many security tools can drown in bandwidth usage  or activity. </strong>NIDs (Network Intrusion Detection devices)  may not be able to handle network activity, and important data can fall through the cracks. Centralized log servers may not be able to collect all the system logs, potentially dropping logs. The beauty of honeypots is that they only capture that which comes to them.</li>
</ol>
<p><strong>Many of our clients swear by our <a href="http://microsolved.com/2009/HoneyPoint.html">HoneyPoint</a><a href="http://microsolved.com/2009/HoneyPoint.html"> family of products</a> to help save resources. With its advantages, it’s easy to see why! Leveraging the power of honeypots is an excellent way to safeguard your data.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=881</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware: Fraudulent W-2 Emails Ahead</title>
		<link>http://stateofsecurity.com/?p=876</link>
		<comments>http://stateofsecurity.com/?p=876#comments</comments>
		<pubDate>Tue, 12 Jan 2010 20:09:00 +0000</pubDate>
		<dc:creator>vthomas</dc:creator>
				<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=876</guid>
		<description><![CDATA[Tax season is upon us and spammers are taking full advantage of the situation.  Reports of fraudulent emails that appear to come from the IRS are popping up.  The email states that all employers need to complete the attached W-2 update form.  Unfortunately, the attachment contains a remote administration tool that allows [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D876"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D876" height="61" width="51" /></a></div><p>Tax season is upon us and spammers are taking full advantage of the situation.  Reports of fraudulent emails that appear to come from the IRS are popping up.  The email states that all employers need to complete the attached W-2 update form.  Unfortunately, the attachment contains a remote administration tool that allows the attacker to execute commands on the system.</p>
<p>The malicious file is named <strong>W2-Form</strong> and has various file extensions including <strong>.rtf, .pdf, and ,.doc</strong>.</p>
<p>While this attack targets employers, I suspect that the next wave will target employees.  Possible scenarios include malicious attachments as described above and directing employees to fake corporate websites.<br />
Employers should notify their employees of how W-2 information will be delivered and warm them of possible fraudulent emails.  For more information on reporting these types of malicious emails visit</p>
<p><a href="http://www.irs.gov/privacy/article/0,,id=179820,00.html">http://www.irs.gov/privacy/article/0,,id=179820,00.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=876</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Directory scanning efforts</title>
		<link>http://stateofsecurity.com/?p=873</link>
		<comments>http://stateofsecurity.com/?p=873#comments</comments>
		<pubDate>Thu, 07 Jan 2010 21:47:20 +0000</pubDate>
		<dc:creator>pgrimes</dc:creator>
				<category><![CDATA[HoneyPoint]]></category>

		<guid isPermaLink="false">http://stateofsecurity.com/?p=873</guid>
		<description><![CDATA[The HITME has been abuzz with alerts from around the globe of scans attempting to find various mobile directories on HoneyPoint hosts. Here is a list of targets that are being checked for: 
/iphone
/m
/mobi
/mobile
While no scanner signatures or identifiers are being sent with the probes, it&#8217;s still cause for concern over the recent surge in [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-right: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D873"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstateofsecurity.com%2F%3Fp%3D873" height="61" width="51" /></a></div><p>The HITME has been abuzz with alerts from around the globe of scans attempting to find various mobile directories on HoneyPoint hosts. Here is a list of targets that are being checked for: </p>
<p>/iphone<br />
/m<br />
/mobi<br />
/mobile</p>
<p>While no scanner signatures or identifiers are being sent with the probes, it&#8217;s still cause for concern over the recent surge in interest of these directories. Web Admins should check their servers for these signatures. You can do so using our <a href="http://dl.getdropbox.com/u/397669/BrainWebScan100Win.zip">BrainWebScan tool</a> if you would like (FREE). You can copy and paste the signatures from this page into the brain file and scan your environments for these targets.</p>
]]></content:encoded>
			<wfw:commentRss>http://stateofsecurity.com/?feed=rss2&amp;p=873</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
