<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>Security Ripcord &#187; Blogging</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/category/blogging/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Tue, 01 Jun 2010 15:17:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>		<item>
		<title>CutSec Broken RSS</title>
		<link>http://www.cutawaysecurity.com/blog/archives/250</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/250#comments</comments>
		<pubDate>Mon, 19 May 2008 11:41:08 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Creative Commons]]></category>
		<category><![CDATA[Don C. Weber]]></category>
		<category><![CDATA[feed]]></category>
		<category><![CDATA[podPress]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[wpLicense]]></category>
		<category><![CDATA[xmlns]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=250</guid>
		<description><![CDATA[I just noticed that my feeds were broken and I apologize to anybody who has missed my valuable contibutions to the security industry   .  I&#8217;m not sure how long this has been going on.  I assume since I upgraded to WP 2.5.1.  I turns out that either podPress or the [...]]]></description>
			<content:encoded><![CDATA[<p>I just noticed that my feeds were broken and I apologize to anybody who has missed my valuable contibutions to the security industry <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  .  I&#8217;m not sure how long this has been going on.  I assume since I upgraded to WP 2.5.1.  I turns out that either <a href="http://www.mightyseek.com/podpress" target="_blank">podPress</a> or the <a href="http://wiki.creativecommons.org/WpLicense" target="_blank">Creative Commons</a> plugins is not playing nice.  I was getting the following lines concatenated in the feed:</p>
<ul>
<li>xmlns:creativeCommons=&#8221;http://backend.userland.com/creativeCommonsRssModule&#8221;</li>
<li>xmlns:itunes=&#8221;http://www.itunes.com/dtds/podcast-1.0.dtd&#8221;</li>
</ul>
<p>To fix it I added a leading &#8220;\n&#8221; to the &#8220;xmlns:itunes&#8221; line in podPress&#8217;s podpress_feed_functions.php.  This fixed the problem although I do not know if is a podPress bug or a Creative Commons bug.  I have <a href="http://www.mightyseek.com/forum/showthread.php?t=1225" target="_blank">jumped on a similar issue</a> at the <a href="http://www.mightyseek.com/forum" target="_blank">podPress forums</a>.  They are usually very helpful and I should get a response and know more soon.</p>
<p>Welcome back to all.  Please check and make sure you haven&#8217;t missed anything.  I have also <a href="http://www.cutawaysecurity.com/blog/interesting-search-keywords" target="_blank">published</a> a few <a href="http://www.cutawaysecurity.com/blog/windows-incident-response-with-only-system-resources" target="_blank">new pages</a> you should check out.  And don&#8217;t forget to respond to the latest Security Ripcord Poll in the left sidebar.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/250/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not At RSA But Feeling The Love</title>
		<link>http://www.cutawaysecurity.com/blog/archives/236</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/236#comments</comments>
		<pubDate>Fri, 18 Apr 2008 04:23:54 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/236</guid>
		<description><![CDATA[Yes, I was not at RSA 2008 this year.  Although I could have probably received a press pass like last year I would have had to shell out every dime for travel and storage&#8230;.err, lodging myself.  Not an option.  So, I stayed put and watched from the virtual side lines.  This [...]]]></description>
			<content:encoded><![CDATA[<p>Yes, I was not at <a href="http://www.rsaconference.com/2008/US/home.aspx" target="_blank">RSA 2008</a> this year.  Although I could have probably received a press pass like last year I would have had to shell out every dime for travel and storage&#8230;.err, lodging myself.  Not an option.  So, I stayed put and watched from the virtual side lines.  This means I may have missed the event of the year by not attending the <a href="http://www.rsaconference.com/security_topics/developing_with_security/Blog_Security_Bloggers_Meet_up_2008.aspx?blogId=14717" target="_blank">Security Blogger Meetup</a> (come on&#8230;how many parties have a <a href="http://www.mckeay.net/2008/04/09/video-streaming-starting-shortly/" target="_blank">live feed</a> outside of <a href="http://www.pauldotcom.com/" target="_blank">PDC</a>?).  Such is the life of a person who works for a small, cost/benefit conscious, contracting company.  I know there are plenty of us out there so that is enough sniveling.</p>
<p>Of course it is always good to be missed and <a href="http://infosecplace.com/blog/" target="_blank">Michael Farnum</a> took a little time out to let me know that I was missed this year.</p>
<blockquote><p>Don,</p>
<p>A couple of people at RSA asked me why you weren&#8217;t blogging and asked me to<br />
get on your case.  I know you are busy, but your fans miss you. <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Michael R. Farnum</p></blockquote>
<p>Yes, posts have been a little sparce recently.   I did <a href="http://www.cutawaysecurity.com/blog/archives/220" target="_blank">address that a little bit</a> by explaining that my new job had a higher risk when it comes to talking about issues, situations, and most of all things that could be considered vulnerabilities.  Risks like the potential to end up <a href="http://www.lvarea.com/data/usp_info.htm" target="_blank">breaking rocks</a> (or would that be considered a control instead of a risk, a very, very effective control).  I have been trying to do a little better in the past few weeks but it does not seem like to many people have been interested in the directions, <a href="http://www.cutawaysecurity.com/blog/archives/225" target="_blank">and</a> <a href="http://www.cutawaysecurity.com/blog/archives/228" target="_blank">there</a> <a href="http://www.cutawaysecurity.com/blog/archives/229" target="_blank">have</a> <a href="http://www.cutawaysecurity.com/blog/archives/231" target="_blank">been</a> <a href="http://www.cutawaysecurity.com/blog/windows-incident-response-with-only-system-resources" target="_blank">many</a>, that I have taken.  One of my major objectives when I started blogging is to never become a slave to security fashion.  I feel that there are people out there covering specific topics very well.  <a href="http://www.pauldotcom.com/" target="_blank">PDC</a> has pentesting and current and emerging vulnerabilities covered.  <a href="http://www.mckeay.net/" target="_blank">Martin</a> and <a href="http://securosis.com/" target="_blank">Rich</a> have current events wrapped up.  <a href="http://rationalsecurity.typepad.com/blog/" target="_blank">Chris</a> and <a href="http://securosis.com/" target="_blank">Rich</a> have deep, stimulating, and sometimes dry&#8230;err, I mean deep&#8230;.oh damn, I already used that&#8230;.security product evaluations taken care of.  And there are <a href="http://windowsir.blogspot.com/" target="_blank">plenty</a> of <a href="http://www.securitymetrics.org/content/" target="_blank">bloggers</a> who have <a href="http://www.realtime-itcompliance.com/" target="_blank">specific</a> <a href="http://jeremiahgrossman.blogspot.com/" target="_blank">topics</a> that they <a href="http://www.irongeek.com/" target="_blank">expertly</a> <a href="http://blog.didierstevens.com/" target="_blank">handle</a> and <a href="http://taosecurity.blogspot.com/" target="_blank">keep</a> <a href="http://www.guerilla-ciso.com/" target="_blank">up-to-date</a>.  Don&#8217;t forget, of course, the host of Security Blogger Soup&#8230;.<a href="http://securityincite.com/blog/mike-rothman" target="_blank">Mike</a>.  Damn, this is turning into a link party.</p>
<p>I guess my draw back is that I am one of those people who try and take a little something from everything.  Breath instead of depth as they say.  Or, as I prefer, Jack-Of-All-Trades.  This probably goes back to my USMC days when the thought process was, &#8220;Be ready for anything at any time.&#8221; But for some reason I always feel like I am trying to play catch-up to many of the people I have just listed and a few more industry experts (review the list of SANS instructors for most of them).  I came into the computer industry ten years after most of them had already been expert programmers or system/network administrators.  So I find myself trying to keep up with fifteen to twenty years of experience on six years of my own (not including college where I started learning what computer components were&#8230;..this is a hard drive and you store folders and files on it in the form of Ones and Zeros).</p>
<p>Of course, I will periodically delve into deep discussions with some of these experts.  The <a href="http://www.cutawaysecurity.com/blog/archives/217" target="_blank">last time</a> I did that I realized that I am still a <a href="http://www.cutawaysecurity.com/blog/archives/218" target="_blank">little out of my league</a>.  <a href="http://rationalsecurity.typepad.com/blog/" target="_blank">Chris</a> definitely showed me the error in my train of though and more importantly, the way that I evaluate and analyze products.   In all actuality, however, my ultimate goal of starting a conversation and learning about the topic was achieved, I just feel that I did not represent (214 babe! &#8230;.inside joke).  Maybe it has made me a little gun shy, but only because I want to be sure I am better prepared next time.  I would much rather stick my neck out on such posts and have the learning experience, then continue to merely continuing to provide new analogies on topics that the industry has already broken several sticks on.  I had to stop myself committing that sin today, as a matter of fact.  But I do not want to embarrass myself in public, because on the Internet my wife cannot do the, *in that woman whisper voice* &#8220;Could you excuse us please?  He&#8217;s had a tough day.  Don, what were you thinking? I&#8217;ll tell you what&#8230;.&#8221;</p>
<p>So, thank you all for thinking of me.  Hopefully you drank more than one beer and shot for me (if not please start now).  Thank you Michael for taking the time out to show me some lovin&#8217;.  It is always appreciated and the beach is still down here in case you and the family were thinking about it.  I hope everybody keeps checking the Security Ripcord feed for new content and will periodically point a link or post a comment from time to time as it does help.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/236/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Blog Disclosure Poll Results</title>
		<link>http://www.cutawaysecurity.com/blog/archives/210</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/210#comments</comments>
		<pubDate>Sun, 25 Nov 2007 17:58:13 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Poll]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/210</guid>
		<description><![CDATA[Well, the results are in for the Blog Disclosure poll.  I let this one run a while to get more responses and partly because I was out of the loop for a while. 
The original question was:
Should you tell your employer about your blog?
The winning answer, receiving 15 of the 30 votes cast:
You should [...]]]></description>
			<content:encoded><![CDATA[<p>Well, the results are in for the Blog Disclosure poll.  I let this one run a while to get more responses and partly because I was out of the loop for a while. </p>
<p>The original question was:</p>
<blockquote><p>Should you tell your employer about your blog?</p></blockquote>
<p>The winning answer, receiving 15 of the 30 votes cast:</p>
<blockquote><p>You should tell them during your interview or before you start blogging. </p></blockquote>
<p> So I guess you definitely want to tell your employer that you are a blogger.  This makes very good sense.  You don&#8217;t want them finding out after the fact as there may be strict policies about blogging.  Also, as blogging is becoming a marketing initiative in some companies, it might even work in your favor during an interview or for your reviews.</p>
<p>You can check out the full results on the <a href="http://www.cutawaysecurity.com/blog/security-ripcord-polls">Security Ripcord Polls</a> page where you will find the results of this and other Security Ripcord Polls.</p>
<p>Go forth and do good things,<br />
Don C. Weber</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/poll" rel="tag">poll</a>, <a href="http://www.technorati.com/tag/blogging" rel="tag">blogging</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Don+C.+Weber" rel="tag">Don C. Weber</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/210/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Adventures for Cutaway and Security Ripcord</title>
		<link>http://www.cutawaysecurity.com/blog/archives/209</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/209#comments</comments>
		<pubDate>Sun, 25 Nov 2007 17:04:48 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/209</guid>
		<description><![CDATA[I have obviously taken a bit of a break.  There are multiple reasons for this: holiday activity at home, increased side project activity, and a new job.
Yes, I have left my position at an educational organization and accepted the position of Information Assurance Director for a DoD contract here in Corpus Christi.  I [...]]]></description>
			<content:encoded><![CDATA[<p>I have obviously taken a bit of a break.  There are multiple reasons for this: holiday activity at home, increased side project activity, and a new job.</p>
<p>Yes, I have left my position at an educational organization and accepted the position of Information Assurance Director for a DoD contract here in Corpus Christi.  I am leading a new, 15 person team, responsible for providing guidance, assessment, documentation, and monitoring on security matters.  (Yes, I have simplified it a bit.)  Everything has really taken off to a great start.  I am getting along very well with my team and the other managers and our bosses are very enthusiastic about moving forward and getting things accomplished.  This is a great opportunity for me.  Albeit, it moves me further away from the technical side of security, I guess project management is just the next logical step in my career&#8217;s evolution.</p>
<p>Some of you may have also noticed that I have come out from behind the pseudonym of Cutaway and included my real name, Don C. Weber, to several of the pages on this website.  Cutaway started out more as a marketing gimmick as anything.  It quickly turned into a necessity when I accepted my last job.  This helped me distance my job from the consulting I was doing.  It also proved to be useful for other reasons as time went by.  But now it is time to brush it all aside.  Cutaway is retired, long live Don C. Weber. <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>What does this mean for the Security Ripcord?  Nothing really.  It is very possible that the focus will turn to more management style issues.  But, as I try to keep up my understanding of technologies, I&#8217;ll still post the findings or confusions here.</p>
<p>Thank you to all who helped me (no need for names, you all know who you are) through the past year and a half of challenges.  Your advice proved valuable and kept me focused as well as calm.  I would also like to thank my coworkers at my last job.  The challenges and progress we made has definitely helped me grow and become a better security professional.  I can only hope that some of the initiatives I helped start benefit and increased the security of the overall organization.</p>
<p>I am very excited about what the future has in store for me and my family.  I am definitely not gone and you can expect more security related content soon.</p>
<p>Go forth and do good things,<br />
Don C. Weber</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/Cutaway" rel="tag">Cutaway</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Don+C.+Weber" rel="tag">Don C. Weber</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/209/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Login Warning Banner &#8211; Wordpress Plugin</title>
		<link>http://www.cutawaysecurity.com/blog/archives/208</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/208#comments</comments>
		<pubDate>Tue, 30 Oct 2007 06:39:58 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Login Warning Banner]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/208</guid>
		<description><![CDATA[I have created my first WordPress plugin titled &#8220;Login Warning Banner&#8221; to address a simple security concern.  From the plugin readme file:

Login Warning Banners are important aspects for system security. WordPress blogs present a unique challenge as they are designed to provide remote access to multiple users through a publicly accessible authentication mechanism. By [...]]]></description>
			<content:encoded><![CDATA[<p>I have created my first <a href="http://wordpress.org/extend/plugins">WordPress plugin</a> titled &#8220;<a href="http://wordpress.org/extend/plugins/login-warning-banner/">Login Warning Banner</a>&#8221; to address a simple security concern.  From the plugin readme file:</p>
<blockquote><p>
Login Warning Banners are important aspects for system security. WordPress blogs present a unique challenge as they are designed to provide remote access to multiple users through a publicly accessible authentication mechanism. By using a pre-authentication Login Warning Banner the blog administrators can<br />
 be certain that individuals attempting to access the blog have been informed about permissible activities and potential monitoring pertaining to accessing the resource. For more information please refer to the following resources.</p>
<p>Resources:<br />
    &#8211; [CIAC INFORMATION BULLETIN - J-043h: Creating Login Banners] (<a href="http://www.ciac.org/ciac/bulletins/j-043.shtml">http://www.ciac.org/ciac/bulletins/j-043.shtml</a>)<br />
    &#8211; [Whitepaper WP-007: Login Warning Banners] (<a href="http://www.unixworks.net/papers/wp-007.pdf">http://www.unixworks.net/papers/wp-007.pdf</a>) by Bob Radvanovsky
</p></blockquote>
<p>You can download the <a href="http://wordpress.org/extend/plugins/login-warning-banner/">Login Warning Banner plugin</a> from the WordPress Plugin site.  You can also monitor the <a href="http://www.cutawaysecurity.com/blog/login-warning-banner">plugin&#8217;s home page</a> for updates and other information here at Security Ripcord.</p>
<p>If you have any comments or recommendations please post them in the comments section here.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/WordPress" rel="tag">WordPress</a>, <a href="http://www.technorati.com/tag/plugin" rel="tag">plugin</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Login+Warning+Banner" rel="tag">Login Warning Banner</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/208/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Benefits of Security Blogging</title>
		<link>http://www.cutawaysecurity.com/blog/archives/187</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/187#comments</comments>
		<pubDate>Sat, 08 Sep 2007 08:14:46 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/187</guid>
		<description><![CDATA[To increase the security within my organization I decided to have PGP come down and give our administrators and IT manager a demonstration on all of the services that PGP provides.  Since reading about it I have been very impressed with the way that PGP has integrated all of the aspects of encryption into [...]]]></description>
			<content:encoded><![CDATA[<p>To increase the security within my organization I decided to have <a href="http://www.pgp.com/">PGP</a> come down and give our administrators and IT manager a demonstration on all of the services that PGP provides.  Since reading about it I have been very impressed with the way that PGP has integrated all of the aspects of encryption into a centrally managed solution.  Many people, however, are not fully aware of the extent of PGP&#8217;s product line.  Even after an online webcast the administrators within my organization just didn&#8217;t understand how the PGP solution could integrate with our services and centrally manage their Email, File Sharing, Full Disk Encryption, and Split-Managed Key Escrow capabilities for Windows and Macintosh notebooks, workstations, and servers as well as some PDAs.</p>
<p>PGP sent down Bob Adams and Nathan Daniels from their <a href="http://maps.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;q=dallas,+texas&#038;ie=UTF8&#038;t=h&#038;z=10&#038;iwloc=addr&#038;om=1">Dallas</a> office.  Bob is their Texas sales representative and Nathan was their technical expert.  After briefly chatting with both I discovered that Nathan has worked for Network Associates, <a href="http://www.f-secure.com/">F-Secure</a>, <a href="http://www.mcafee.com/">McAfee</a>, and has been with PGP for about three years.  Definitely an impressive background.  Although I don&#8217;t remember the full extent of Bob&#8217;s background, I do know that he worked for <a href="http://www.ibm.com/">IBM</a> in their <a href="http://www.iss.net/">Internet Security Solutions</a> department and he knows several people on their X-Force team.</p>
<p>&#8220;<a href="http://xforce.iss.net/">IBM ISS X-Force</a> team?  Hey, do you know <a href="http://erratasec.blogspot.com/">David Maynor and Robert Graham</a>?&#8221;  Bob knew Robert and spoke very highly of him as well as the rest of the X-Force team. (I just noticed that the <a href="http://blogs.iss.net/">X-Force team has a blog</a>.)</p>
<p>Then later, was we started talking about which companies in <a href="http://maps.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;q=texas&#038;ie=UTF8&#038;ll=31.16581,-100.063477&#038;spn=23.137082,41.132813&#038;t=h&#038;z=5&#038;iwloc=addr&#038;om=1">Texas</a> handled the sales of their product I asked if they worked with <a href="http://www.accuvant.com/">Accuvant</a>.  Nathan responded that they have been working with them recently.  &#8220;Hey, do you know <a href="http://www.infosecplace.com/blog/">Michael Farnum</a>?&#8221;  Indeed Nathan has meet Michael and, of course, spoke highly of him as well.</p>
<p>Now, I&#8217;m not going to tell you that any of this name dropping gained my organization any bargaining collateral.  But I can say that talking to these guys about people that they had met, worked with, and liked did help in the fact that we had a little more in common than before.  This made everybody a little more comfortable and the meeting went very well.  I guess it is just one of the extra benefits of blogging.  </p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/PGP" rel="tag">PGP</a>, <a href="http://www.technorati.com/tag/blogging" rel="tag">blogging</a>, <a href="http://www.technorati.com/tag/encryption" rel="tag">encryption</a>, <a href="http://www.technorati.com/tag/Accuvant" rel="tag">Accuvant</a>, <a href="http://www.technorati.com/tag/IBM" rel="tag">IBM</a>, <a href="http://www.technorati.com/tag/ISS" rel="tag">ISS</a>, <a href="http://www.technorati.com/tag/F-Secure" rel="tag">F-Secure</a>, <a href="http://www.technorati.com/tag/X-Force" rel="tag">X-Force</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Michael+Farnum" rel="tag">Michael Farnum</a>, <a href="http://www.technorati.com/tag/David+Maynor" rel="tag">David Maynor</a>, <a href="http://www.technorati.com/tag/Robert+Graham" rel="tag">Robert Graham</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/187/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Ripcord Poll &#8211; Disclosing Your Blog</title>
		<link>http://www.cutawaysecurity.com/blog/archives/182</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/182#comments</comments>
		<pubDate>Sun, 26 Aug 2007 00:28:40 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Poll]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/182</guid>
		<description><![CDATA[In honor of Rich Mogull&#8217;s return to the security blogsphere I have created a new poll. 

	
		Should you tell your employer about your blog?
		
		
		
			
					
					You should tell them during your interview or before you start blogging.
			
			
					
					You should not worry about it.
			
			
					
					You should blog under a pseudonym.
			
			
					
					Blogging is for people with too much time on their hands....get [...]]]></description>
			<content:encoded><![CDATA[<p>In honor of <a href="http://securosis.com/2007/08/24/going-where-the-weather-suits-my-soul/">Rich Mogull&#8217;s return</a> to the security blogsphere I have created a new poll. </p>
<div>
	<div class='democracy'>
		<strong class="poll-question">Should you tell your employer about your blog?</strong>
		<div class='dem-results'>
		<form action='http://www.cutawaysecurity.com/blog/wp-content/plugins/democracy/democracy.php' onsubmit='return dem_Vote(this)'>
		<ul>
			<li>
					<input type='radio' id='dem-choice-11' value='11' name='dem_poll_3' />
					<label for='dem-choice-11'>You should tell them during your interview or before you start blogging.</label>
			</li>
			<li>
					<input type='radio' id='dem-choice-10' value='10' name='dem_poll_3' />
					<label for='dem-choice-10'>You should not worry about it.</label>
			</li>
			<li>
					<input type='radio' id='dem-choice-12' value='12' name='dem_poll_3' />
					<label for='dem-choice-12'>You should blog under a pseudonym.</label>
			</li>
			<li>
					<input type='radio' id='dem-choice-13' value='13' name='dem_poll_3' />
					<label for='dem-choice-13'>Blogging is for people with too much time on their hands....get to work.</label>
			</li>
		</ul>
			<input type='hidden' name='dem_poll_id' value='3' />
			<input type='hidden' name='dem_action' value='vote' />
			<input type='submit' class='dem-vote-button' value='Vote' />
			<a href='/blog/archives/category/blogging/feed?dem_action=view&amp;dem_poll_id=3' onclick='return dem_getVotes("http://www.cutawaysecurity.com/blog/wp-content/plugins/democracy/democracy.php?dem_action=view&amp;dem_poll_id=3", this)' rel='nofollow' class='dem-vote-link'>View Results</a>
		</form>
		</div>
	</div></div>
<p>I thought about limiting it to security blogs but, what the hell, I guess there are some other blog out there.</p>
<p>Welcom back, Rich.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/securosis" rel="tag">securosis</a>, <a href="http://www.technorati.com/tag/blogging" rel="tag">blogging</a>, <a href="http://www.technorati.com/tag/poll" rel="tag">poll</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Rich+Mogull" rel="tag">Rich Mogull</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/182/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Follow up to Infosecsellout Post</title>
		<link>http://www.cutawaysecurity.com/blog/archives/168</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/168#comments</comments>
		<pubDate>Thu, 19 Jul 2007 12:30:27 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Professionalism]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/168</guid>
		<description><![CDATA[I have been reading a lot of articles saying that I have pointed the finger at LMH and PHC.  I even received a comment to that effect.

#
jf
Comment @ 07/19/07 at 5:26 am &#124;e
eyeroll, common everyone knows that the informant is icer/maynor which basically removes all credibility because (a) he’s a pathological liar and (b) [...]]]></description>
			<content:encoded><![CDATA[<p>I have been reading a lot of articles saying that I have <a href="http://www.cutawaysecurity.com/blog/archives/167">pointed the finger at LMH and PHC</a>.  I even received a comment to that effect.</p>
<blockquote><p>
#<br />
jf<br />
Comment @ 07/19/07 at 5:26 am |e</p>
<p>eyeroll, common everyone knows that the informant is icer/maynor which basically removes all credibility because (a) he’s a pathological liar and (b) he’s got beef with LMH. This stupid irc convo doesn’t prove anything other than you’re gullible.</p>
</blockquote>
<p>So I responded</p>
<blockquote>
<p>@jf</p>
<p>Actually the “informant” is not Maynor. Although I know him I have never talked to him via IRC. You can <a href="http://www.mckeay.net/secure/2007/07/cutaway_broke_the_info_sec_sel.html">check out the comment</a> my source made to Martin McKeay’s blog.</p>
<p>Also, I haven’t said anything in my post that proves LMH or PHC are involved. Actually, I try to follow up on the information the “informant” gave me but didn’t gather any more information than most people who knows these individuals are already aware of as old news. Now, if I had known about the <a href="http://www.immunitysec.com/resources-freesoftware.shtml">Unmask</a> program I would have performed some the actions HD Moore took <a href="http://www.techzi.com/2007/07/18/mac-worm-hacker-vanishes-from-blogosphere/">as described in the article on Techzi</a>.</p>
<p>The main thing this did was get this subject in the news so that the infosec sellout received more publicity then it was worth. What all of these players need to realize is that it is okay to be anonymous, it is okay to be a jerk, but the two shouldn’t be mixed.</p>
</blockquote>
<p>Something I thought of afterwards.  If you are trying to remain anonymous, and you could be fired for writing in a blog, you should not brag about developing a worm for any operating system. It is going to get you attention that you probably do not want as people will start looking at you a lot more closely.  Infosecsellout found this out the hardway.  </p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/Unmask" rel="tag">Unmask</a>, <a href="http://www.technorati.com/tag/infosecsellout" rel="tag">infosecsellout</a>, <a href="http://www.technorati.com/tag/LMH" rel="tag">LMH</a>, <a href="http://www.technorati.com/tag/PHC" rel="tag">PHC</a>, <a href="http://www.technorati.com/tag/Techzi" rel="tag">Techzi</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/HD+Moore" rel="tag">HD Moore</a>, <a href="http://www.technorati.com/tag/David+Maynor" rel="tag">David Maynor</a>, <a href="http://www.technorati.com/tag/Martin+McKeay" rel="tag">Martin McKeay</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/168/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outting the InfoSecSellout?</title>
		<link>http://www.cutawaysecurity.com/blog/archives/167</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/167#comments</comments>
		<pubDate>Wed, 18 Jul 2007 05:34:30 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Professionalism]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/167</guid>
		<description><![CDATA[Today I was minding my own business in a chatroom that I monitor when somebody posted something about infosecsellout.  Normally I ignore anything pertaining to infosecsellout due to an unprofessional and childish comment posted about Alan Shimel.    But this time I had to pay attention.  This time somebody pointed a [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was minding my own business in a chatroom that I monitor when somebody posted something about <a href="http://infosecsellout.blogspot.com/">infosecsellout</a>.  Normally I ignore anything pertaining to infosecsellout due to <a href="http://infosecsellout.blogspot.com/2007/02/bias-in-blogging.html#comment-5775334756558810864">an unprofessional and childish comment</a> posted about <a href="http://www.stillsecureafteralltheseyears.com/">Alan Shimel</a>.    But this time I had to pay attention.  This time somebody pointed a finger at who is behind the content posted on the infosecsellout blog site.  The finger was pointed at <a href="http://blog.info-pull.com/">LMH</a> and the <a href="http://phrack.efnet.ru">Phrack High Council (PHC)</a> (yes, the link is broken but you can check out what it looked like <a href="http://dsr.segfault.es/stuff/website-mirrors/pHC/phcisback.htm">here</a>).</p>
<p>I have no way to confirm any of these statements, but here is the text of the conversation.  And, yes, it has been edited to protect identities.</p>
<blockquote><p>
[3:37pm] [informant] okay- i have permission to officially leak it. we think<br />
sellout is LMH and the PHC kids. spread the word<br />
[3:37pm] [cutaway] HA<br />
[3:37pm] [informant] and we think some of them engage in illegal hacks<br />
[3:37pm] [cutaway] HA<br />
[3:38pm] [cutaway] seriously on that last one?<br />
[3:38pm] [informant] yep, btu no evidence<br />
[3:38pm] [cutaway] That would be an interesting blog post<br />
[3:38pm] [informant] yes it would<br />
[3:38pm] [cutaway] Ou would love to drop that<br />
[3:38pm] [informant] if you look up the phrack high club stuff, they state<br />
clearly their goal is to trash the infosec industry<br />
[3:39pm] [informant] what better way to do that than pretend to be insiders,<br />
and make up a bunch of BS and disinformation<br />
[3:39pm] [informant] a disinformation campaign against the infosec industry<br />
[3:39pm] [informant] almost ingenious<br />
[3:39pm] [informant] feel free to leak to ou if you want<br />
[3:40pm] [innocent.bystander] I don&#8217;t think I want to be the one to post that.<br />
 that is sort of like saying &#8211; that group of kids is robbing houses &#8211; from<br />
your front porch<br />
[3:40pm] [cutaway] I just might wait on that one<br />
[3:40pm] [cutaway] I was just thinking that<br />
[3:40pm] [innocent.bystander] sort of invites them to come on in<br />
[3:40pm] [informant] yeah, no proof on the illegal stuff<br />
[3:40pm] [cutaway] but what points you in that direction?<br />
[3:40pm] [informant] but we&#8217;re pretty sure they do it<br />
[3:41pm] [cutaway] stuff they say or reference in the infosellout blog?<br />
[3:41pm] [informant] when you hear enough rumors from enough sources, and<br />
track that to behavior, eventually a rough picture emerges<br />
[3:41pm] [informant] look at the language on the blog and the pHC stuff<br />
[3:42pm] [cutaway] I am trying to think how to present it when I don&#8217;t<br />
read sellout and I don&#8217;t have references to specifics<br />
[3:42pm] [cutaway] not that I am asking you for any<br />
[3:42pm] [cutaway] just thinking outloud<br />
[3:43pm] [cutaway] Hmm, I&#8217;m going to have to play with that tonight<br />
[3:43pm] [innocent.bystander] gotta go offline for some testing, back in a few<br />
[3:43pm] [cutaway] If I don&#8217;t come up with something I&#8217;ll ping Ou<br />
[3:43pm] innocent.bystander left the chat room.<br />
[3:43pm] [cutaway] Unknown source of course<br />
[3:43pm] [informant] of course<br />
[3:44pm] [informant] you could just say you got an anonymous email, and that<br />
they&#8217;re goal has been to sow chaos
</p></blockquote>
<p>Interesting, yes.  Proving illegal activity&#8230;.well&#8230;.I doubt I even want to start digging around for that information.  But I thought I would check into the claim of PHC trying to discredit the information security industry.  First I started with the <a href="http://www.phrack.org/issues.html?issue=64">latest edition of Phrack</a> where I found <a href="http://www.phrack.org/issues.html?issue=64&#038;id=2#article">this</a>:</p>
<blockquote><p>
Q: And about PHC?<br />
A: Well, thats an interesting question. To be honest, PHC did not just do<br />
   those bad things we were used to learn from the web or irc, we like some<br />
   of them and even know very well a few others. Also, the two attempted<br />
   issues 62 and 63 of PHC had an incontestable renew in the spirit and<br />
   there were even some useful information on honeypots and protecting<br />
   exploits. </p>
<p>   However, we have a problem with unjustified arrogance. If it&#8217;s true<br />
   the security world has a problem with white/black hats, we think that<br />
   the good way to resolve the problem is not to fight everyone,<br />
   especially such a poor demonstrative way. It&#8217;s not our conception of<br />
   hacking. Take the first 20 issues of Phrack and try to find unjustified<br />
   arrogant word/sentence/paragraph: you won&#8217;t find any. The essence of<br />
   hacking is different : it&#8217;s learning. Hacking to learn. </p>
<p>   You can be a blackhat and working in the IT industry, it&#8217;s<br />
   not incompatible. We have nothing against PHC and we think the<br />
   Underground needs a group like PHC. But the Underground needs a magazine<br />
   like Phrack as well. <strong>The main battle of PHC is fighting whitehats but<br />
   it&#8217;s not Phrack&#8217;s battle.</strong> It&#8217;s never been the purpose of Phrack.<br />
   If we have to fight against something, it&#8217;s against the society and<br />
   not targeting whitehats personally (that doesn&#8217;t mean that we support<br />
   whitehat&#8230;). Phrack is about fighting the society by releasing<br />
   information about technologies that we are not supposed to learn. And<br />
   these technologies are not only Unix-related and/or software<br />
   vulnerabilities.</p>
<p>   <strong>We agree with them when they say that recent issues of Phrack helped<br />
   probably too much the security industry and that there was a lack of<br />
   spirit. We&#8217;re doing our best to change it.</strong> But we still need technical<br />
   articles. If they want to change something in the Underground, they are<br />
   welcome to contribute to Phrack. Like everyone in the Underground<br />
   community.</p>
</blockquote>
<p>Next I found <a href="http://seclists.org/fulldisclosure/2005/Nov/0783.html">this</a> post to Full Disclosure:</p>
<blockquote><p>
 &#8212;&#8211; Original Message &#8212;&#8211;<br />
  From: Phrack High Council<br />
  To: full-disclosure_at_lists.grok.org.uk<br />
  Sent: Thursday, November 24, 2005 1:29 PM<br />
  Subject: [Full-disclosure] Return of the Phrack High Council</p>
<p>  Dear FD Reader,</p>
<p>      It&#8217;s been a very long time since we last spoke, but just like the Pheonix (not the city, you dumbfuck!) i was reborn from my own ash. We, the PHC, been for too long in the underground (gathering informations, snooping whitehat tty&#8217;s, backdooring various boxes, etc.) to be able to keep up with the amount of bullshit that goes to this list on a daily basis. But NOW, the Phrack High Council is once more into the lights! <strong>We&#8217;ve been in the underground gathering informations about *YOU* and your fellow &#8216;ethical hackers&#8217;.</strong></p>
<p>     You should expect to find your mail spool and porn collection on our web page soon enough. Don&#8217;t assume you are safe because you are NOT! <strong>No, we don&#8217;t like you and no, we won&#8217;t stop.</strong> But, for now, we proudly present the inside of the Star Hackademy (www.thehackademy.net) and an early _final_ PDF version of their lame zine (thanks core, you are a real pal). We couldn&#8217;t get our hands on the hardcover; it&#8217;s scheduled to be released sometime in december. Sorry!</p>
<p>     PHC is not a hacking group, it&#8217;s a state of mind. PHC is not a group of people, it&#8217;s a movement of people. We do not exist!</p>
<p>     Please enjoy visiting http://phrack.efnet.ru as the next home of your mailspool *g* and remember &#8230;.</p>
<p>      &#8230;. &#8220;keep pr0j3kt m4yh3m alive!&#8221;
</p></blockquote>
<p>The &#8220;keep pr0j3kt m4yh3m alive!&#8221; quote lead me to a <a href="http://dsr.segfault.es/stuff/website-mirrors/pHC/phcisback.htm">mirror of the Phrack RU site index page</a>:</p>
<blockquote><p>
Phrack High Council &#8211; 2005<br />
&#8220;Keep pr0j3kt m4yh3m alive!&#8221;</p>
<p>Official Note</p>
<p>   It&#8217;s been a long time, indeed. Two years of underground, now PHC is back into the scene. I bet<br />
many of you have no fuckin clue *WHY* suddenly, the <strong>anti-infosec</strong> movement slowed down. Some of you<br />
thought it might&#8217;ve been the fedz. Some others said PHC members got security jobs. There were also<br />
some voices stating we have no exploits left. HAHAHAHA! Get real, son! We sit our asses on more<br />
goodies than ISS and iDefense, altogether.</p>
<p>   PHC is *NOT* a hacking group, it&#8217;s a state of mind! Stop asking about us,<br />
we know all about YOU!</p>
<p>   PHC was never *GONE*, we just reached a new state of mind, a new underground level. You, our<br />
faithful follower, our friend, our brother, know where we&#8217;ve been. <strong>We&#8217;ve been scooping the infosec,<br />
getting inside informations, KNOWING OUR ENEMY (thx Spitzc0q), puttin their lifes into misery!</strong> But,<br />
in the mean time, we also had our eyes on the scene: some of you kept pr0j3kt m4yh3m alive. The rest<br />
acted like sheeps left w/o sheppard: bowed yer heads to them wolves! This is your last chance: you<br />
either change or become a target. <strong>Everyone can be a target: security professionals, CISSP (hi<br />
Johnson aka [t]hief, still playing the &#8216;hacker&#8217;?), security companies, bugtraq wannabeez, all kinds<br />
of wannabeez, them bitches, non-believers, haters, etc.<br />
</strong><br />
   Gray is not a choice anymore. It&#8217;s US or THEM. It&#8217;s not a game. <strong>The IT Security industry is<br />
affecting our day-to-day life.</strong> More and more east-europeans, chinese, indians, pakistani, etc.<br />
think they will find milk and honey working at a security company; you fuckin twats! They&#8217;re just<br />
exploiting you. You&#8217;re serving a cause that&#8217;s not yours, making your boss rich! If you don&#8217;t see<br />
our point, then fuck you, you made it to our target list.</p>
<p>   Everybody should remember gayh1tler&#8217;s last wish: keep pr0j3kt m4yh3m alive! Each and every of<br />
you should follow his words of wisdom. You have no right to do otherwise! And if you do, we see you,<br />
we know who you are and your ass is blast.</p>
<p>   <strong>It&#8217;s the WHITEHAT HOLOCAUST! WHITEHATS, STEP INTO MY OVEN!!!!<br />
</strong></p>
<p>                                                                &#8211; Phrack High Council, 2005 AD</p>
</blockquote>
<p>Finally I figured I should check the infosecsellout site to see if I could locate any blantant FUD.  The only thing that really stood out was the <a href="http://infosecsellout.blogspot.com/2007/07/oh-look-apple-worm.html">recent claim of a worm for OS X.</a>  Although this may or may not be an attempt to generate bogus information I did not see anything else that could not be described as just another person&#8217;s opinion.</p>
<p>Apparently, this information has also gotten around a bit already.  It seems that infosecsellout has <a href="http://infosecsellout.blogspot.com/2007/07/oh-drama.html">posted an email</a> from LMH and/or the crew at <a href="http://blog.info-pull.com/">info-pull</a> that claims they are not affiliated with infosecsellout despite <a href="http://erratasec.blogspot.com/">David Maynor</a>&#8217;s opinion.  </p>
<p>You know, I am starting to wish I had ignored the original message about infosecsellout.  Although I cannot say that there is any specific misinformation associated with the blog.  The completely unprofessional attitude and behavior of its author(s) just reminds me of why I started, and should have continued, ignoring this blog, all conversations associated with it, and any claims about who the author(s) may or may not be.  I&#8217;m also glad I did not bother <a href="http://blogs.zdnet.com/Ou/">George Ou</a> with this.  Infosecsellout does not need any more publicity than it already gets.  I have also come to realize, it is just not that interesting.  Although I would like to blame infosecsellout for wasting my time again, I can really only blame myself.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/Phrack" rel="tag">Phrack</a>, <a href="http://www.technorati.com/tag/PHC" rel="tag">PHC</a>, <a href="http://www.technorati.com/tag/LMH" rel="tag">LMH</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Infosec+Sellout" rel="tag">Infosec Sellout</a>, <a href="http://www.technorati.com/tag/David+Maynor" rel="tag">David Maynor</a>, <a href="http://www.technorati.com/tag/Alan+Shimel" rel="tag">Alan Shimel</a>, <a href="http://www.technorati.com/tag/George+Ou" rel="tag">George Ou</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/167/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Site Taken Down For Wordpress Security Problem</title>
		<link>http://www.cutawaysecurity.com/blog/archives/46</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/46#comments</comments>
		<pubDate>Mon, 31 Jul 2006 01:41:02 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/46</guid>
		<description><![CDATA[Some of you may have noticed that the site was down for a couple of days.  This was because of an apparent flaw with Wordpress.  While I was attending the ACUTA conference in San Diego I decided to catch up on the news.  I am glad that I did because I noticed [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you may have noticed that the site was down for a couple of days.  This was because of an apparent flaw with Wordpress.  While I was attending the ACUTA conference in San Diego I decided to catch up on the news.  I am glad that I did because I noticed that <a href="http://www.darknet.org.uk/" title="Darknet">Darknet</a>  had an <a href="http://www.darknet.org.uk/2006/07/serious-wordpress-vulnerabilityexploit-verion-203-and-below/" title="Wordpress Security Problem">entry about a newly discovered security vulnerability with all versions of Wordpress below 2.0.4</a> .  Unfortunately his actual site was down and I was not able to read the full article.  So I made a quick judgment call and decided to take the site down until I understood more about what was actually happening.</p>
<p> Now that the Darknet site is back up, and I am able to get online, I see that the problem lies in allowing anybody to register for an account.  I am not actually sure of the exact problem except that it would lead to escalated privileges for the user.  As stated in his article the temporary fix for the problem is to not check the &quot;Anyone can register&quot; box in the &quot;Options&quot; management tab.  I have verified that I had already disabled this setting and now that site is back up.  I will, however, <a href="http://wordpress.org/development/2006/07/wordpress-204/" title="Wordpress 2.0.4">update to the new version of Wordpress which is version 2.0.4</a>  once I get a chance (i.e. <a href="http://codex.wordpress.org/Backing_Up_Your_Database" title="Back It Up">after I back everything up</a> ).  You should do this as well.
<p>Go forth and do good things.<br /> Cutaway </p>
<p></p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/Darknet" rel="tag">Darknet</a>, <a href="http://www.technorati.com/tag/Wordpress" rel="tag">Wordpress</a>, <a href="http://www.technorati.com/tag/Cutaway+Security" rel="tag">Cutaway Security</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/46/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
