<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>Security Ripcord &#187; Bunny Ranch</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/category/bunny-ranch/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Tue, 01 Jun 2010 15:17:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>		<item>
		<title>IT Security &#8211; Moonlite Bunny Ranch Style</title>
		<link>http://www.cutawaysecurity.com/blog/archives/27</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/27#comments</comments>
		<pubDate>Sat, 29 Apr 2006 06:10:19 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Bunny Ranch]]></category>
		<category><![CDATA[PDC]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/27</guid>
		<description><![CDATA[The Moonlite Bunny Ranch, providing the oldest service in the world, has some security practices that we could all learn from if we look close enough.]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">I know that I am going to get a lot of flack about this but I just couldn&#8217;t help myself.</p>
<p class="MsoNormal">
<p class="MsoNormal">The other night I was reviewing an assessment report when I looked up at the TV and I realized that it was on HBO and the series <a title="HBO: Cathouse" href="http://www.hbo.com/docs/programs/cathouse2/index.html">Cathouse </a>was showing.  This show is about &#8220;the Moonlite Bunny Ranch, a legal brothel located in a sparsely populated desert community outside of Reno&#8221; so, of course, I was transfixed for the rest of the show.  Well, right at the end of the episode, one of the women was leaving the house when the owner asked somebody to buzz her out.  The camera was pointing out the front door and the woman walked through an iron gate which automatically closed behind her.  I was just about to turn the TV off and get back to my report when I started realizing something about the show.  This show is a great lesson in practical security through proper implementation. Let me walk you through the steps that a client has to go through to have access to the services provided at the Bunny Ranch.</p>
<p class="MsoNormal">
<ol type="1" style="margin-top: 0in" start="1">
<li class="MsoNormal">The      client is let in through the front door which is usually locked but,      during acceptable access time periods, it is unlocked and traffic is      allowed to enter through the single, monitored, entryway.  I consider this the externally facing      router.</li>
<li class="MsoNormal">Next      the client enters a waiting room where he starts talking to the women that      are waiting there to provide a service.       I consider this waiting room the firewall.  The clients are briefly inspected to      determine if they are acceptable.       You could also make the argument that this area also acts as an      intrusion detection or prevention system.</li>
<li class="MsoNormal">Once      it is determined that the client is acceptable he or she is lead back to      the bedroom where a price is negotiated and payment is authorized.  Here we are obviously talking about the      service and how it is using proper authentication and authorization      techniques to determine whether the client is permitted to use the service      and how much privilege he or she will be given to perform the desired task.</li>
<li class="MsoNormal">While the client and the woman and client are interacting they are using safe sex techniques.  This represents input validation. (New)</li>
<li class="MsoNormal">Once      services have been rendered the woman who provided the service leads the      client back to the waiting room and says goodbye.  This resembles the proper termination of      activity provided by the service.</li>
<li class="MsoNormal">As I saw during the final moments of the show, all outgoing traffic has to      be given permission before it is allowed to leave the building.       Obviously egress filtering is just as important at the Cathouse as      it is within a network.</li>
<li class="MsoNormal">During      the whole process the manager on-duty is moving around and talking to all      the employees and keeping tabs on what is actually happening within the whole environment.  This activity reminds me of log      monitoring and a professional that is ready to take action at the first sign of trouble.</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal">So, I feel that we could learn a lot from this very professional business.  I am sure that the Bunny Ranch has come up with this process to protect itself and its clients.  Need is the mother of all invention.  So, if the oldest profession in the world is following this process out of necessity then we should all take heed.</p>
<p class="MsoNormal">
<p class="MsoNormal">This article is in honor of &#8220;<a title="Watch At Your Own Risk" href="http://hydrogen.oshean.org/psw-24.mp4">Hack Naked</a>&#8221; from Pauldotcom.  Guys, this place obviously needs a penetration test (too obvious, no matter&#8230;it had to be said!).</p>
<p class="MsoNormal">Cutaway</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/27/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://hydrogen.oshean.org/psw-24.mp4" length="9551129" type="video/mp4" />
		</item>
	</channel>
</rss>
