<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog de Matias Katz</title>
	<atom:link href="http://www.matiaskatz.com/Index.php?feed=rss2&amp;lang=en" rel="self" type="application/rss+xml" />
	<link>http://www.matiaskatz.com</link>
	<description>Info de IT para la gente Comun, Info Comun para la gente de IT</description>
	<lastBuildDate>Sat, 21 Aug 2010 00:55:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Blog&#8217;s 1st year &#8211; Over 5000 visits</title>
		<link>http://www.matiaskatz.com/?p=604&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=604&amp;lang=en#comments</comments>
		<pubDate>Fri, 20 Aug 2010 20:26:49 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Varios]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[noticias]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=604</guid>
		<description><![CDATA[Dear readers,
It's with great pleasure I announce that this blog has come to its 1st year  
During this year we've covered several important issues, and we've also experienced periods without any posts (for instance, this blog doesn't know what July was  )
The level of visits started slowly, with just a few at the [...]]]></description>
			<content:encoded><![CDATA[<p>Dear readers,</p>
<p>It's with great pleasure I announce that this blog has come to its 1st year <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>During this year we've covered several important issues, and we've also experienced periods without any posts (for instance, this blog doesn't know what July was <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> )</p>
<p>The level of visits started slowly, with just a few at the beginning, but in the last few months the daily average raised significantly.</p>
<p>Just by chance, on the day of its birthday the blog passed the 5000 visits, reaching the total number of 5078 since August 18th 2009, the day I installed the ClusterMaps service.</p>
<p>I leave here as a remembering the map of this year's visits, just before it was reset:</p>
<p><a href="http://www.matiaskatz.com/wp-content/uploads/2010/08/www.matiaskatz.com-2009-08-18_to_2010-08-19.jpg"><img class="aligncenter size-full wp-image-611" title="www.matiaskatz.com-2009-08-18_to_2010-08-19" src="http://www.matiaskatz.com/wp-content/uploads/2010/08/www.matiaskatz.com-2009-08-18_to_2010-08-19.jpg" alt="www.matiaskatz.com-2009-08-18_to_2010-08-19" width="160" height="132" /></a></p>
<p>I wish we can still cover important issues next year, even more than during this year.</p>
<p>I hope you can understand that the writer is a fan of his job, and has always several projects to attend simultaneously <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  so there may be a few days from post to post.</p>
<p>I thank you all for your visits, your support and your words. Do not hesitate to contact me if you need anything.</p>
<p>My deepest regards, here's for a fruitful next period.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;title=Blog%27s%201st%20year%20-%20Over%205000%20visits&amp;bodytext=Dear%20readers%2C%0D%0A%0D%0AIt%27s%20with%20great%20pleasure%20I%20announce%20that%20this%20blog%20has%20come%20to%20its%201st%20year%20%3A%29%0D%0A%0D%0ADuring%20this%20year%20we%27ve%20covered%20several%20important%20issues%2C%20and%20we%27ve%20also%20experienced%20periods%20without%20any%20posts%20%28for%20instance%2C%20this%20blog%20doesn%27t%20know%20wha" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;title=Blog%27s%201st%20year%20-%20Over%205000%20visits&amp;notes=Dear%20readers%2C%0D%0A%0D%0AIt%27s%20with%20great%20pleasure%20I%20announce%20that%20this%20blog%20has%20come%20to%20its%201st%20year%20%3A%29%0D%0A%0D%0ADuring%20this%20year%20we%27ve%20covered%20several%20important%20issues%2C%20and%20we%27ve%20also%20experienced%20periods%20without%20any%20posts%20%28for%20instance%2C%20this%20blog%20doesn%27t%20know%20wha" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;t=Blog%27s%201st%20year%20-%20Over%205000%20visits" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;title=Blog%27s%201st%20year%20-%20Over%205000%20visits&amp;annotation=Dear%20readers%2C%0D%0A%0D%0AIt%27s%20with%20great%20pleasure%20I%20announce%20that%20this%20blog%20has%20come%20to%20its%201st%20year%20%3A%29%0D%0A%0D%0ADuring%20this%20year%20we%27ve%20covered%20several%20important%20issues%2C%20and%20we%27ve%20also%20experienced%20periods%20without%20any%20posts%20%28for%20instance%2C%20this%20blog%20doesn%27t%20know%20wha" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;submitHeadline=Blog%27s%201st%20year%20-%20Over%205000%20visits&amp;submitSummary=Dear%20readers%2C%0D%0A%0D%0AIt%27s%20with%20great%20pleasure%20I%20announce%20that%20this%20blog%20has%20come%20to%20its%201st%20year%20%3A%29%0D%0A%0D%0ADuring%20this%20year%20we%27ve%20covered%20several%20important%20issues%2C%20and%20we%27ve%20also%20experienced%20periods%20without%20any%20posts%20%28for%20instance%2C%20this%20blog%20doesn%27t%20know%20wha&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den&amp;title=Blog%27s%201st%20year%20-%20Over%205000%20visits&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=Dear%20readers%2C%0D%0A%0D%0AIt%27s%20with%20great%20pleasure%20I%20announce%20that%20this%20blog%20has%20come%20to%20its%201st%20year%20%3A%29%0D%0A%0D%0ADuring%20this%20year%20we%27ve%20covered%20several%20important%20issues%2C%20and%20we%27ve%20also%20experienced%20periods%20without%20any%20posts%20%28for%20instance%2C%20this%20blog%20doesn%27t%20know%20wha" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Blog%27s%201st%20year%20-%20Over%205000%20visits%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D604%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=604&amp;lang=en</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Home-made phishing attack</title>
		<link>http://www.matiaskatz.com/?p=602&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=602&amp;lang=en#comments</comments>
		<pubDate>Tue, 17 Aug 2010 05:29:06 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[noticias]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=602</guid>
		<description><![CDATA[I thought about seeing how far I could get when trying to assemble a phishing site.
First, I chose a provider, in this case Gmail. Then, I downloaded the original login site and did the following adjustments:

I cut all communications the site did to Google
I changed the user and password information destination
I manually added a Favicon [...]]]></description>
			<content:encoded><![CDATA[<p>I thought about seeing how far I could get when trying to assemble a phishing site.</p>
<p>First, I chose a provider, in this case Gmail. Then, I downloaded the original login site and did the following adjustments:</p>
<ol>
<li>I cut all communications the site did to Google</li>
<li>I changed the user and password information destination</li>
<li>I manually added a Favicon from the provider's official icon repository</li>
<li>I created a new script that receives the information sent from the login site and shows it on-screen</li>
</ol>
<p>The finished product turned out to be a Gmail home site, dangerously similar to the original, with a behaviour dangerously different.</p>
<p>In order to really know how easy is to make this part of the attack, I can tell you that it took me approximately half an hour of a very relaxed work.</p>
<p>For this to be a full Phishing attack, the next step would be to deceive the user into entering the address where the site is being hosted, believing he's entering Gmail's real site.</p>
<p>I will clearly NOT ease that task for you, but I will leave you with the login site, that independently is harmless.</p>
<p>I invite you to test the site (by entering fake credentials, obviously).</p>
<p>Next provider, Facebook <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Link: <a href="http://www.matiaskatz.com/gmail/" target="_blank">http://www.matiaskatz.com/gmail/</a></p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;title=Home-made%20phishing%20attack&amp;bodytext=I%20thought%20about%20seeing%20how%20far%20I%20could%20get%20when%20trying%20to%20assemble%20a%20phishing%20site.%0D%0A%0D%0AFirst%2C%20I%20chose%20a%20provider%2C%20in%20this%20case%20Gmail.%20Then%2C%20I%20downloaded%20the%20original%20login%20site%20and%20did%20the%20following%20adjustments%3A%0D%0A%0D%0A%09I%20cut%20all%20communications%20the%20site%20" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;title=Home-made%20phishing%20attack&amp;notes=I%20thought%20about%20seeing%20how%20far%20I%20could%20get%20when%20trying%20to%20assemble%20a%20phishing%20site.%0D%0A%0D%0AFirst%2C%20I%20chose%20a%20provider%2C%20in%20this%20case%20Gmail.%20Then%2C%20I%20downloaded%20the%20original%20login%20site%20and%20did%20the%20following%20adjustments%3A%0D%0A%0D%0A%09I%20cut%20all%20communications%20the%20site%20" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;t=Home-made%20phishing%20attack" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;title=Home-made%20phishing%20attack&amp;annotation=I%20thought%20about%20seeing%20how%20far%20I%20could%20get%20when%20trying%20to%20assemble%20a%20phishing%20site.%0D%0A%0D%0AFirst%2C%20I%20chose%20a%20provider%2C%20in%20this%20case%20Gmail.%20Then%2C%20I%20downloaded%20the%20original%20login%20site%20and%20did%20the%20following%20adjustments%3A%0D%0A%0D%0A%09I%20cut%20all%20communications%20the%20site%20" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;submitHeadline=Home-made%20phishing%20attack&amp;submitSummary=I%20thought%20about%20seeing%20how%20far%20I%20could%20get%20when%20trying%20to%20assemble%20a%20phishing%20site.%0D%0A%0D%0AFirst%2C%20I%20chose%20a%20provider%2C%20in%20this%20case%20Gmail.%20Then%2C%20I%20downloaded%20the%20original%20login%20site%20and%20did%20the%20following%20adjustments%3A%0D%0A%0D%0A%09I%20cut%20all%20communications%20the%20site%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den&amp;title=Home-made%20phishing%20attack&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=I%20thought%20about%20seeing%20how%20far%20I%20could%20get%20when%20trying%20to%20assemble%20a%20phishing%20site.%0D%0A%0D%0AFirst%2C%20I%20chose%20a%20provider%2C%20in%20this%20case%20Gmail.%20Then%2C%20I%20downloaded%20the%20original%20login%20site%20and%20did%20the%20following%20adjustments%3A%0D%0A%0D%0A%09I%20cut%20all%20communications%20the%20site%20" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Home-made%20phishing%20attack%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D602%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=602&amp;lang=en</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Ticket drawing: 1st Communication and Mobile Solutions Security Conference</title>
		<link>http://www.matiaskatz.com/?p=596&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=596&amp;lang=en#comments</comments>
		<pubDate>Wed, 04 Aug 2010 18:44:17 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[CXO]]></category>
		<category><![CDATA[Evento]]></category>
		<category><![CDATA[noticias]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=596</guid>
		<description><![CDATA[Sorry, this post is about a conference given in Buenos Aires, Argentina.



Compartir Post


	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p>Sorry, this post is about a conference given in Buenos Aires, Argentina.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;title=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference&amp;bodytext=Sorry%2C%20this%20post%20is%20about%20a%20conference%20given%20in%20Buenos%20Aires%2C%20Argentina." title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;title=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference&amp;notes=Sorry%2C%20this%20post%20is%20about%20a%20conference%20given%20in%20Buenos%20Aires%2C%20Argentina." title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;t=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;title=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference&amp;annotation=Sorry%2C%20this%20post%20is%20about%20a%20conference%20given%20in%20Buenos%20Aires%2C%20Argentina." title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;submitHeadline=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference&amp;submitSummary=Sorry%2C%20this%20post%20is%20about%20a%20conference%20given%20in%20Buenos%20Aires%2C%20Argentina.&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den&amp;title=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=Sorry%2C%20this%20post%20is%20about%20a%20conference%20given%20in%20Buenos%20Aires%2C%20Argentina." title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Ticket%20drawing%3A%201st%20Communication%20and%20Mobile%20Solutions%20Security%20Conference%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D596%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=596&amp;lang=en</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In Fraganti &#8211; Case #3, center-location company, City of Buenos Aires</title>
		<link>http://www.matiaskatz.com/?p=591&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=591&amp;lang=en#comments</comments>
		<pubDate>Wed, 30 Jun 2010 03:59:26 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[noticias]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=591</guid>
		<description><![CDATA[Today I was walking by the street ...I better not tell..., and I stumbled upon a discovery, both beautiful and terrible at the same time.
A working post with its BACK to the street. Yes, as you read it, a fully functional working booth, with drawers and papers and A PC, installed in a way that [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was walking by the street ...I better not tell..., and I stumbled upon a discovery, both beautiful and terrible at the same time.</p>
<p>A working post with its BACK to the street. Yes, as you read it, a fully functional working booth, with drawers and papers and A PC, installed in a way that the operator stays with his back to the street, and having the PC screen and the papers at plain sight from the street, since this company is in the ground floor and the front is made of glass and without curtains.</p>
<p>I leave you with a picture so you can laugh of the situation:</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0486.JPG"><img class="aligncenter" title="IMG_0486" src="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0486-300x225.jpg" alt="IMG_0486" width="300" height="225" /></a></p>
<p>By the time I took the picture the booth had been occupied, but when I first noted the violation there was nobody sitting. In the PC screen you could see the inbox of a corporate mail account. Then, when the operator sat down and the other lady came to ask for something, the inbox was minimized letting a beautiful CRM with the company's content come to focus.</p>
<p>When I got to take the second picture from the far, a security guard had already appeared on the window (as you can see circled in red in the picture), who was making me a negative sign with his finger, letting me know that I wasn't allowed to take pictures... To which I politely answered "I'm on the public street" while comfortably taking the picture, ignoring his incoherent prohibition.</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0487.JPG"><img class="aligncenter" title="IMG_0487" src="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0487-300x225.jpg" alt="IMG_0487" width="300" height="225" /></a></p>
<p>Needless to say, this is a SERIOUS security fault, caused by a LACK of logic from whoever takes the decisions about the subject at this company.</p>
<p>It's such an incredible situation, and it's such an obvious opinion the one any security professional may have about this, that there's no sense in writing anything else about the issue.</p>
<p>I'll simply leave you with the pictures so you can stare with your mouths open, and shaking your heads from left to right trying to understand how this kind of things keep happening.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires&amp;bodytext=Today%20I%20was%20walking%20by%20the%20street%20...I%20better%20not%20tell...%2C%20and%20I%20stumbled%20upon%20a%20discovery%2C%20both%20beautiful%20and%20terrible%20at%20the%20same%20time.%0D%0A%0D%0AA%20working%20post%20with%20its%20BACK%20to%20the%20street.%20Yes%2C%20as%20you%20read%20it%2C%20a%20fully%20functional%20working%20booth%2C%20with%20drawe" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires&amp;notes=Today%20I%20was%20walking%20by%20the%20street%20...I%20better%20not%20tell...%2C%20and%20I%20stumbled%20upon%20a%20discovery%2C%20both%20beautiful%20and%20terrible%20at%20the%20same%20time.%0D%0A%0D%0AA%20working%20post%20with%20its%20BACK%20to%20the%20street.%20Yes%2C%20as%20you%20read%20it%2C%20a%20fully%20functional%20working%20booth%2C%20with%20drawe" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;t=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires&amp;annotation=Today%20I%20was%20walking%20by%20the%20street%20...I%20better%20not%20tell...%2C%20and%20I%20stumbled%20upon%20a%20discovery%2C%20both%20beautiful%20and%20terrible%20at%20the%20same%20time.%0D%0A%0D%0AA%20working%20post%20with%20its%20BACK%20to%20the%20street.%20Yes%2C%20as%20you%20read%20it%2C%20a%20fully%20functional%20working%20booth%2C%20with%20drawe" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;submitHeadline=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires&amp;submitSummary=Today%20I%20was%20walking%20by%20the%20street%20...I%20better%20not%20tell...%2C%20and%20I%20stumbled%20upon%20a%20discovery%2C%20both%20beautiful%20and%20terrible%20at%20the%20same%20time.%0D%0A%0D%0AA%20working%20post%20with%20its%20BACK%20to%20the%20street.%20Yes%2C%20as%20you%20read%20it%2C%20a%20fully%20functional%20working%20booth%2C%20with%20drawe&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=Today%20I%20was%20walking%20by%20the%20street%20...I%20better%20not%20tell...%2C%20and%20I%20stumbled%20upon%20a%20discovery%2C%20both%20beautiful%20and%20terrible%20at%20the%20same%20time.%0D%0A%0D%0AA%20working%20post%20with%20its%20BACK%20to%20the%20street.%20Yes%2C%20as%20you%20read%20it%2C%20a%20fully%20functional%20working%20booth%2C%20with%20drawe" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=In%20Fraganti%20-%20Case%20%233%2C%20center-location%20company%2C%20City%20of%20Buenos%20Aires%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D591%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=591&amp;lang=en</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computer law E-Magazine #4</title>
		<link>http://www.matiaskatz.com/?p=588&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=588&amp;lang=en#comments</comments>
		<pubDate>Wed, 23 Jun 2010 16:28:27 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[noticias]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=588</guid>
		<description><![CDATA[The fourth edition of the Computer Law E-Magazine has been published, in which there's an article written by me about Law &#38; IT.
You can download the magazine from this link (Spanish): http://www.asegurarte.com.ar/Revista_Elderechoinformatico_N4.zip
Link to the full article (Spanish): http://www.elderechoinformatico.com/index.php?option=com_content&#38;view=article&#38;id=321:-revista-electronica-el-derecho-informatico-no-4-junio-2010&#38;catid=82:revista-electronica&#38;Itemid=111
I will publish the article here in 2 weeks.



Compartir Post


	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p>The fourth edition of the Computer Law E-Magazine has been published, in which there's an article written by me about Law &amp; IT.</p>
<p>You can download the magazine from this link (Spanish): <a href="http://www.asegurarte.com.ar/Revista_Elderechoinformatico_N4.zip" target="_blank">http://www.asegurarte.com.ar/Revista_Elderechoinformatico_N4.zip</a></p>
<p>Link to the full article (Spanish): <a href="http://www.elderechoinformatico.com/index.php?option=com_content&amp;view=article&amp;id=321:-revista-electronica-el-derecho-informatico-no-4-junio-2010&amp;catid=82:revista-electronica&amp;Itemid=111" target="_blank">http://www.elderechoinformatico.com/index.php?option=com_content&amp;view=article&amp;id=321:-revista-electronica-el-derecho-informatico-no-4-junio-2010&amp;catid=82:revista-electronica&amp;Itemid=111</a></p>
<p>I will publish the article here in 2 weeks.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;title=Computer%20law%20E-Magazine%20%234&amp;bodytext=The%20fourth%20edition%20of%20the%20Computer%20Law%20E-Magazine%20has%20been%20published%2C%20in%20which%20there%27s%20an%20article%20written%20by%20me%20about%20Law%20%26amp%3B%20IT.%0D%0A%0D%0AYou%20can%20download%20the%20magazine%20from%20this%20link%20%28Spanish%29%3A%20http%3A%2F%2Fwww.asegurarte.com.ar%2FRevista_Elderechoinformatico_N" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;title=Computer%20law%20E-Magazine%20%234&amp;notes=The%20fourth%20edition%20of%20the%20Computer%20Law%20E-Magazine%20has%20been%20published%2C%20in%20which%20there%27s%20an%20article%20written%20by%20me%20about%20Law%20%26amp%3B%20IT.%0D%0A%0D%0AYou%20can%20download%20the%20magazine%20from%20this%20link%20%28Spanish%29%3A%20http%3A%2F%2Fwww.asegurarte.com.ar%2FRevista_Elderechoinformatico_N" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;t=Computer%20law%20E-Magazine%20%234" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;title=Computer%20law%20E-Magazine%20%234&amp;annotation=The%20fourth%20edition%20of%20the%20Computer%20Law%20E-Magazine%20has%20been%20published%2C%20in%20which%20there%27s%20an%20article%20written%20by%20me%20about%20Law%20%26amp%3B%20IT.%0D%0A%0D%0AYou%20can%20download%20the%20magazine%20from%20this%20link%20%28Spanish%29%3A%20http%3A%2F%2Fwww.asegurarte.com.ar%2FRevista_Elderechoinformatico_N" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;submitHeadline=Computer%20law%20E-Magazine%20%234&amp;submitSummary=The%20fourth%20edition%20of%20the%20Computer%20Law%20E-Magazine%20has%20been%20published%2C%20in%20which%20there%27s%20an%20article%20written%20by%20me%20about%20Law%20%26amp%3B%20IT.%0D%0A%0D%0AYou%20can%20download%20the%20magazine%20from%20this%20link%20%28Spanish%29%3A%20http%3A%2F%2Fwww.asegurarte.com.ar%2FRevista_Elderechoinformatico_N&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den&amp;title=Computer%20law%20E-Magazine%20%234&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=The%20fourth%20edition%20of%20the%20Computer%20Law%20E-Magazine%20has%20been%20published%2C%20in%20which%20there%27s%20an%20article%20written%20by%20me%20about%20Law%20%26amp%3B%20IT.%0D%0A%0D%0AYou%20can%20download%20the%20magazine%20from%20this%20link%20%28Spanish%29%3A%20http%3A%2F%2Fwww.asegurarte.com.ar%2FRevista_Elderechoinformatico_N" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Computer%20law%20E-Magazine%20%234%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D588%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=588&amp;lang=en</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encryption over Microsoft SQL Server</title>
		<link>http://www.matiaskatz.com/?p=583&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=583&amp;lang=en#comments</comments>
		<pubDate>Mon, 14 Jun 2010 23:47:35 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[encriptacion]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[noticias]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=583</guid>
		<description><![CDATA[When managing an application security methodology, there are several ways of approaching it. Each method covers different portions of the data access flow, creating the so called "layered defense".
I leave you in this ocation with a document from Microsoft that addresses the management of encrypted database inputs, through native functionalities in its DB engine, MS [...]]]></description>
			<content:encoded><![CDATA[<p>When managing an application security methodology, there are several ways of approaching it. Each method covers different portions of the data access flow, creating the so called "layered defense".</p>
<p>I leave you in this ocation with a document from Microsoft that addresses the management of encrypted database inputs, through native functionalities in its DB engine, MS SQL Server.</p>
<p>This way, an extra protection layer can be easily added, estabilshing an application security strategy in these layers:</p>
<ol>
<li>Encryption when generatin the information</li>
<li>Encryption when exchanging information</li>
<li><strong>Encryption when storing information</strong></li>
</ol>
<p>A more graphic way to explain it can ve seen in the image provided by Microsoft in their article:</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/06/SQLEncryption.jpg"><img class="aligncenter" title="SQLEncryption" src="http://www.matiaskatz.com/wp-content/uploads/2010/06/SQLEncryption-219x300.jpg" alt="SQLEncryption" width="219" height="300" /></a></p>
<p>Link to the article (english): <a href="http://www.microsoft.com/technet/prodtechnol/sql/2005/sqlencryption.mspx" target="_blank">http://www.microsoft.com/technet/prodtechnol/sql/2005/sqlencryption.mspx</a></p>
<p>Link to the document (english): <a href="http://download.microsoft.com/download/8/b/2/8b22991f-3f2f-4cea-b2ba-55c190841145/TDEandEFSBitLocker.docx" target="_blank">http://download.microsoft.com/download/8/b/2/8b22991f-3f2f-4cea-b2ba-55c190841145/TDEandEFSBitLocker.docx</a></p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;title=Encryption%20over%20Microsoft%20SQL%20Server&amp;bodytext=When%20managing%20an%20application%20security%20methodology%2C%20there%20are%20several%20ways%20of%20approaching%20it.%20Each%20method%20covers%20different%20portions%20of%20the%20data%20access%20flow%2C%20creating%20the%20so%20called%20%22layered%20defense%22.%0D%0A%0D%0AI%20leave%20you%20in%20this%20ocation%20with%20a%20document%20from%20" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;title=Encryption%20over%20Microsoft%20SQL%20Server&amp;notes=When%20managing%20an%20application%20security%20methodology%2C%20there%20are%20several%20ways%20of%20approaching%20it.%20Each%20method%20covers%20different%20portions%20of%20the%20data%20access%20flow%2C%20creating%20the%20so%20called%20%22layered%20defense%22.%0D%0A%0D%0AI%20leave%20you%20in%20this%20ocation%20with%20a%20document%20from%20" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;t=Encryption%20over%20Microsoft%20SQL%20Server" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;title=Encryption%20over%20Microsoft%20SQL%20Server&amp;annotation=When%20managing%20an%20application%20security%20methodology%2C%20there%20are%20several%20ways%20of%20approaching%20it.%20Each%20method%20covers%20different%20portions%20of%20the%20data%20access%20flow%2C%20creating%20the%20so%20called%20%22layered%20defense%22.%0D%0A%0D%0AI%20leave%20you%20in%20this%20ocation%20with%20a%20document%20from%20" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;submitHeadline=Encryption%20over%20Microsoft%20SQL%20Server&amp;submitSummary=When%20managing%20an%20application%20security%20methodology%2C%20there%20are%20several%20ways%20of%20approaching%20it.%20Each%20method%20covers%20different%20portions%20of%20the%20data%20access%20flow%2C%20creating%20the%20so%20called%20%22layered%20defense%22.%0D%0A%0D%0AI%20leave%20you%20in%20this%20ocation%20with%20a%20document%20from%20&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den&amp;title=Encryption%20over%20Microsoft%20SQL%20Server&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=When%20managing%20an%20application%20security%20methodology%2C%20there%20are%20several%20ways%20of%20approaching%20it.%20Each%20method%20covers%20different%20portions%20of%20the%20data%20access%20flow%2C%20creating%20the%20so%20called%20%22layered%20defense%22.%0D%0A%0D%0AI%20leave%20you%20in%20this%20ocation%20with%20a%20document%20from%20" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Encryption%20over%20Microsoft%20SQL%20Server%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D583%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=583&amp;lang=en</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In Fraganti &#8211; Case #2, Major supermarket chain, City of Buenos Aires</title>
		<link>http://www.matiaskatz.com/?p=577&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=577&amp;lang=en#comments</comments>
		<pubDate>Thu, 03 Jun 2010 19:18:32 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=577</guid>
		<description><![CDATA[Here's a new post for this section:
Caso #3: Major supermarket chain, Tuesday 8 PM, City of Buenos Aires
After finishing buying groceries I started walking towards the supermarket exit.
When passing through the end of the large hallway I found the "delivery" sector, made by 3-4 PC and a couple of printers.
On this occasion, the hallway was [...]]]></description>
			<content:encoded><![CDATA[<p>Here's a new post for this section:</p>
<p><span style="text-decoration: underline;">Caso #3:</span> Major supermarket chain, Tuesday 8 PM, City of Buenos Aires</p>
<p>After finishing buying groceries I started walking towards the supermarket exit.</p>
<p>When passing through the end of the large hallway I found the "delivery" sector, made by 3-4 PC and a couple of printers.</p>
<p>On this occasion, the hallway was with a complete lack of personnel, as you can see in this first picture:</p>
<p><a href="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0464.JPG"><img style="display: block; margin-left: auto; margin-right: auto; border: 0px initial initial;" title="IMG_0464" src="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0464-300x225.jpg" alt="IMG_0464" width="300" height="225" /></a></p>
<p>After approaching to the PC screen that was on, I managed to see the following:</p>
<ol>
<li>The PC was not locked</li>
<li>The case (and its tempting USB ports) were at plain access</li>
<li>The screen showed a CRM application in which <strong>there were listed all the addresses corresponding to every delivery request that had been recently uploaded to the system</strong></li>
</ol>
<p>I took a picture of that list, but I'm obviously not going to show it to you <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I'm just going to leave you, as a gift, with a second picture (a closer one) showing the CRM application that handles the delivery requests.</p>
<p><a href="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0465.JPG"><img style="display: block; margin-left: auto; margin-right: auto; border: 0px initial initial;" title="IMG_0465" src="http://www.matiaskatz.com/wp-content/uploads/2010/06/IMG_0465-300x225.jpg" alt="IMG_0465" width="300" height="225" /></a><br />
Far beyond the obvious fact of being able to insert a USB device that rapidly infects the PC with some sort of malware, I ask you:</p>
<p>What happens if I capture that list of remaining delivery addresses, I dress myself with clothes that simulate or appear as if they were the uniform of the supermarket boys, go to those addresses, ring the bell and say "I'm from the supermarket?"</p>
<p>The answer is quite obvious.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires&amp;bodytext=Here%27s%20a%20new%20post%20for%20this%20section%3A%0D%0A%0D%0ACaso%20%233%3A%20Major%20supermarket%20chain%2C%20Tuesday%208%20PM%2C%20City%20of%20Buenos%20Aires%0D%0A%0D%0AAfter%20finishing%20buying%20groceries%20I%20started%20walking%20towards%20the%20supermarket%20exit.%0D%0A%0D%0AWhen%20passing%20through%20the%20end%20of%20the%20large%20hallway%20I%20fou" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires&amp;notes=Here%27s%20a%20new%20post%20for%20this%20section%3A%0D%0A%0D%0ACaso%20%233%3A%20Major%20supermarket%20chain%2C%20Tuesday%208%20PM%2C%20City%20of%20Buenos%20Aires%0D%0A%0D%0AAfter%20finishing%20buying%20groceries%20I%20started%20walking%20towards%20the%20supermarket%20exit.%0D%0A%0D%0AWhen%20passing%20through%20the%20end%20of%20the%20large%20hallway%20I%20fou" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;t=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires&amp;annotation=Here%27s%20a%20new%20post%20for%20this%20section%3A%0D%0A%0D%0ACaso%20%233%3A%20Major%20supermarket%20chain%2C%20Tuesday%208%20PM%2C%20City%20of%20Buenos%20Aires%0D%0A%0D%0AAfter%20finishing%20buying%20groceries%20I%20started%20walking%20towards%20the%20supermarket%20exit.%0D%0A%0D%0AWhen%20passing%20through%20the%20end%20of%20the%20large%20hallway%20I%20fou" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;submitHeadline=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires&amp;submitSummary=Here%27s%20a%20new%20post%20for%20this%20section%3A%0D%0A%0D%0ACaso%20%233%3A%20Major%20supermarket%20chain%2C%20Tuesday%208%20PM%2C%20City%20of%20Buenos%20Aires%0D%0A%0D%0AAfter%20finishing%20buying%20groceries%20I%20started%20walking%20towards%20the%20supermarket%20exit.%0D%0A%0D%0AWhen%20passing%20through%20the%20end%20of%20the%20large%20hallway%20I%20fou&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den&amp;title=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=Here%27s%20a%20new%20post%20for%20this%20section%3A%0D%0A%0D%0ACaso%20%233%3A%20Major%20supermarket%20chain%2C%20Tuesday%208%20PM%2C%20City%20of%20Buenos%20Aires%0D%0A%0D%0AAfter%20finishing%20buying%20groceries%20I%20started%20walking%20towards%20the%20supermarket%20exit.%0D%0A%0D%0AWhen%20passing%20through%20the%20end%20of%20the%20large%20hallway%20I%20fou" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=In%20Fraganti%20-%20Case%20%232%2C%20Major%20supermarket%20chain%2C%20City%20of%20Buenos%20Aires%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D577%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=577&amp;lang=en</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malware in a Facebook group invitation</title>
		<link>http://www.matiaskatz.com/?p=572&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=572&amp;lang=en#comments</comments>
		<pubDate>Thu, 13 May 2010 22:05:18 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=572</guid>
		<description><![CDATA[I just got an invitation to join a Facebook group.
Big was my disappointment when I found out that to be able to "join" this group, I should COPY an endless text string and PASTE it in my navigation bar.
What kind of group requires that process to join?
Mmmm,weird...
It got weirder when I analized a little bit [...]]]></description>
			<content:encoded><![CDATA[<p>I just got an invitation to join a Facebook group.</p>
<p>Big was my disappointment when I found out that to be able to "join" this group, I should COPY an endless text string and PASTE it in my navigation bar.</p>
<p>What kind of group requires that process to join?</p>
<p>Mmmm,weird...</p>
<p>It got weirder when I analized a little bit the text and found out that there wasn't a single link or URL to be folowed, but the execution of a Javascript call containing (among other things) the command <strong>"new  RegExp('\\b\\\\n\\g\\j\\g\\F\\g\\i......"</strong></p>
<p>Obviousely, this is a <strong>malicious execution </strong>that needs the poor user to introduce the execution in his/her browser by hand.</p>
<p>I leave you an image of the supposed group, so that you don't fall in the trap.</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/05/Disney-FB.jpg"><img class="aligncenter" title="Disney-FB" src="http://www.matiaskatz.com/wp-content/uploads/2010/05/Disney-FB-300x267.jpg" alt="Disney-FB" width="300" height="267" /></a></p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;title=Malware%20in%20a%20Facebook%20group%20invitation&amp;bodytext=I%20just%20got%20an%20invitation%20to%20join%20a%20Facebook%20group.%0D%0A%0D%0ABig%20was%20my%20disappointment%20when%20I%20found%20out%20that%20to%20be%20able%20to%20%22join%22%20this%20group%2C%20I%20should%20COPY%20an%20endless%20text%20string%20and%20PASTE%20it%20in%20my%20navigation%20bar.%0D%0A%0D%0AWhat%20kind%20of%20group%20requires%20that%20process" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;title=Malware%20in%20a%20Facebook%20group%20invitation&amp;notes=I%20just%20got%20an%20invitation%20to%20join%20a%20Facebook%20group.%0D%0A%0D%0ABig%20was%20my%20disappointment%20when%20I%20found%20out%20that%20to%20be%20able%20to%20%22join%22%20this%20group%2C%20I%20should%20COPY%20an%20endless%20text%20string%20and%20PASTE%20it%20in%20my%20navigation%20bar.%0D%0A%0D%0AWhat%20kind%20of%20group%20requires%20that%20process" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;t=Malware%20in%20a%20Facebook%20group%20invitation" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;title=Malware%20in%20a%20Facebook%20group%20invitation&amp;annotation=I%20just%20got%20an%20invitation%20to%20join%20a%20Facebook%20group.%0D%0A%0D%0ABig%20was%20my%20disappointment%20when%20I%20found%20out%20that%20to%20be%20able%20to%20%22join%22%20this%20group%2C%20I%20should%20COPY%20an%20endless%20text%20string%20and%20PASTE%20it%20in%20my%20navigation%20bar.%0D%0A%0D%0AWhat%20kind%20of%20group%20requires%20that%20process" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;submitHeadline=Malware%20in%20a%20Facebook%20group%20invitation&amp;submitSummary=I%20just%20got%20an%20invitation%20to%20join%20a%20Facebook%20group.%0D%0A%0D%0ABig%20was%20my%20disappointment%20when%20I%20found%20out%20that%20to%20be%20able%20to%20%22join%22%20this%20group%2C%20I%20should%20COPY%20an%20endless%20text%20string%20and%20PASTE%20it%20in%20my%20navigation%20bar.%0D%0A%0D%0AWhat%20kind%20of%20group%20requires%20that%20process&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den&amp;title=Malware%20in%20a%20Facebook%20group%20invitation&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=I%20just%20got%20an%20invitation%20to%20join%20a%20Facebook%20group.%0D%0A%0D%0ABig%20was%20my%20disappointment%20when%20I%20found%20out%20that%20to%20be%20able%20to%20%22join%22%20this%20group%2C%20I%20should%20COPY%20an%20endless%20text%20string%20and%20PASTE%20it%20in%20my%20navigation%20bar.%0D%0A%0D%0AWhat%20kind%20of%20group%20requires%20that%20process" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Malware%20in%20a%20Facebook%20group%20invitation%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D572%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=572&amp;lang=en</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Section: In Fraganti &#8211; Case #1, Important Bank, Buenos Aires City</title>
		<link>http://www.matiaskatz.com/?p=563&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=563&amp;lang=en#comments</comments>
		<pubDate>Wed, 12 May 2010 02:37:13 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Varios]]></category>
		<category><![CDATA[In Fraganti]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Seguridad]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=563</guid>
		<description><![CDATA[People,
I have just opened the "In Fraganti" section. In this section I will be publishing content that puts organizations of all kind in evidence of their failure regarding information security.
I invite you all to collaborate with material of your discovery to publish in our own "wall of shame".
I'll start the opening with the first case:
Case [...]]]></description>
			<content:encoded><![CDATA[<p>People,</p>
<p>I have just opened the "In Fraganti" section. In this section I will be publishing content that puts organizations of all kind in evidence of their failure regarding information security.</p>
<p>I invite you all to collaborate with material of your discovery to publish in our own "wall of shame".</p>
<p>I'll start the opening with the first case:</p>
<p><span style="text-decoration: underline;">Case  #1:</span> Important Bank. Buenos Aires City, "Obelisco" zone, Friday 23 hs.</p>
<p>This bank has their line of ATM machines separated from the bank with a big glass wall. There's a work desk next to that wall:</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/05/IMG_0450.JPG"><img class="aligncenter" title="IMG_0450" src="http://www.matiaskatz.com/wp-content/uploads/2010/05/IMG_0450-300x225.jpg" alt="IMG_0450" width="300" height="225" /></a></p>
<p>You can clearely see an open folder, containing customer information that sould be confidential:</p>
<p style="text-align: center;"><a href="http://www.matiaskatz.com/wp-content/uploads/2010/05/IMG_0449.JPG"><img title="IMG_0449" src="http://www.matiaskatz.com/wp-content/uploads/2010/05/IMG_0449-300x225.jpg" alt="IMG_0449" width="300" height="225" /></a></p>
<p>The following tuesday (today) I approached the bank and asked about that flaw. The employee in information informed me that there are no blinds on purpose, to protect the bank from burglars by not letting them hide behind anything.</p>
<p>When I told him about my discovery, the bank employee said the following: <strong>"Yes, the person who works in that post is a little off"</strong>.</p>
<p><strong> </strong></p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;title=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City&amp;bodytext=People%2C%0D%0A%0D%0AI%20have%20just%20opened%20the%20%22In%20Fraganti%22%20section.%20In%20this%20section%20I%20will%20be%20publishing%20content%20that%20puts%20organizations%20of%20all%20kind%20in%20evidence%20of%20their%20failure%20regarding%20information%20security.%0D%0A%0D%0AI%20invite%20you%20all%20to%20collaborate%20with%20material%20of" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;title=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City&amp;notes=People%2C%0D%0A%0D%0AI%20have%20just%20opened%20the%20%22In%20Fraganti%22%20section.%20In%20this%20section%20I%20will%20be%20publishing%20content%20that%20puts%20organizations%20of%20all%20kind%20in%20evidence%20of%20their%20failure%20regarding%20information%20security.%0D%0A%0D%0AI%20invite%20you%20all%20to%20collaborate%20with%20material%20of" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;t=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;title=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City&amp;annotation=People%2C%0D%0A%0D%0AI%20have%20just%20opened%20the%20%22In%20Fraganti%22%20section.%20In%20this%20section%20I%20will%20be%20publishing%20content%20that%20puts%20organizations%20of%20all%20kind%20in%20evidence%20of%20their%20failure%20regarding%20information%20security.%0D%0A%0D%0AI%20invite%20you%20all%20to%20collaborate%20with%20material%20of" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;submitHeadline=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City&amp;submitSummary=People%2C%0D%0A%0D%0AI%20have%20just%20opened%20the%20%22In%20Fraganti%22%20section.%20In%20this%20section%20I%20will%20be%20publishing%20content%20that%20puts%20organizations%20of%20all%20kind%20in%20evidence%20of%20their%20failure%20regarding%20information%20security.%0D%0A%0D%0AI%20invite%20you%20all%20to%20collaborate%20with%20material%20of&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den&amp;title=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=People%2C%0D%0A%0D%0AI%20have%20just%20opened%20the%20%22In%20Fraganti%22%20section.%20In%20this%20section%20I%20will%20be%20publishing%20content%20that%20puts%20organizations%20of%20all%20kind%20in%20evidence%20of%20their%20failure%20regarding%20information%20security.%0D%0A%0D%0AI%20invite%20you%20all%20to%20collaborate%20with%20material%20of" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=New%20Section%3A%20In%20Fraganti%20-%20Case%20%231%2C%20Important%20Bank%2C%20Buenos%20Aires%20City%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D563%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=563&amp;lang=en</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Security through obscurity. Is it really effective?</title>
		<link>http://www.matiaskatz.com/?p=548&amp;lang=en</link>
		<comments>http://www.matiaskatz.com/?p=548&amp;lang=en#comments</comments>
		<pubDate>Wed, 05 May 2010 18:15:44 +0000</pubDate>
		<dc:creator>Matias Katz</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[obscurity]]></category>
		<category><![CDATA[oscuridad]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.matiaskatz.com/?p=548</guid>
		<description><![CDATA[Throughout our history there have been found uncountable cases in which the main security measure was the obscurity, meaning the hiding of resources or information from public view and/or access.
Secret passages in castles, values hidden inside jars or hollowed books, underground militar bases, etc...
Can't help but wonder: Is that the best of measures?
The daily practice [...]]]></description>
			<content:encoded><![CDATA[<p>Throughout our history there have been found uncountable cases in which the main security measure was the obscurity, meaning the hiding of resources or information from public view and/or access.</p>
<p>Secret passages in castles, values hidden inside jars or hollowed books, underground militar bases, etc...</p>
<p>Can't help but wonder: Is that the best of measures?</p>
<p>The daily practice tells us that the secret passages have no access control, the jars with hidden values have no key, and the vehicles that arrive to the underground militar bases use to drive and park on the "ground floor", publishing their movements.</p>
<p>Do not get me wrong, obscurity is a great method to impose security. It's no wonder it has trascended throughout milenniums. Mi question focuses on the level of effectiveness of a <strong>total</strong> security state if its <strong>only</strong> measure is obscurity.</p>
<p>If I were a king, I would not feel secure at all if the only thing that could stop an attacker from reaching my royal chamber is a secret passage with no access control or guard (as we have seen in many books and movies).</p>
<p>Why can't be a guard in that secret passage also? Hmmm, maybe because in that situation it wouldn't be "secret" any more.</p>
<p>Let's talk of the present day now. Let's list some of the most discussed items about IT security:</p>
<ol>
<li><span style="text-decoration: underline;">Cryptography:</span> Many years have passed since cryptoanalysists have realised that the obscurity in algorithms was not the safest method in providing security. That's why the algorithms were opened and now centralize their security in the key.<br />
Now, does that mean that if I were to create an algorithm of my own and DIDN'T published its code, it would be less secure? Not at all, in fact I'm seriousely considering it <img src='http://www.matiaskatz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  .  It's just that the big fishes in the matter decided to change their posture regarding security concepts in an encryption algorithm.<br />
And all the developers/admins/infosec officers thank them very much for their decision, since thanks to their publication all of us can implement their algorithms in our applications, internally.</li>
<li><span style="text-decoration: underline;">Social Networks:</span> I say it over and over again, in class, in clients and even in dinner with friends.<br />
Many people brag about "not having a Facebook user". Is that a good decision? Aren't we facilitating the job of a falsifier or identity thief, by not having a "computerly tangible" base about our profile? What's easier to falisify than something that is not publicly known?<br />
Imagine the following situation: A supposed archeologist goes to a collector and says "look, I have the holy grail in my possession, I dug it from a grave in Morocco". Far beyond the skepticism, the collector will never truly be sure if the afirmation from the archeologist is false.</p>
<p>Now, imagen the following situation: A smuggler goes to a collector and says "look, I have the Mona Lisa, I stole it from the Louvre". The collector calls the museum and asks "Hi, do you have the Mona Lisa there? - Yes, we have it on display". And the mission of the smuggler to sell a falsification does not succeed.</p>
<p>By having our real profile in the social networks, we increase the difficulty of stealing our identity for the attacker. But please, set a strong password  to the Facebook user!</p>
<p><em>By the side, I invite you to question the following (for those who don't have a user in Facebook): Is it so wrong to belong in this social network, if you can maintain a short, simple, sober, professional profile that does not publish any <strong>really</strong> important information?</em></p>
<p><em> </em></li>
<li><span style="text-decoration: underline;">Network Perimeter:</span> To configure services so they do NOT work in the standard ports is a good practice.<br />
But what happens, at the side of the attacker,  if when scanning the perimeter there are 5 open ports found? The attacker will have a time X of analysis more invasive to find out the services behind those open ports.What if we open 30000 ports in a perimeter? The analysis time calculation is not exactly X * 30000 (it's a little less, actually), but we would be increasing the difficulty of the attacker's job, anyway. The only thing to do is to correctly secure those ports/services and that's it. Having 30000 ports open, from which only 5 point to real services (in non-standard ports) and the rest point to a simple honeypot (or whatever), seems to me more secure than having publicly visible <strong>only</strong> what really exists and works.</li>
</ol>
<p>To sum up, in my opinion it is best to be <strong>shown in a secure way</strong>, than to be <strong>hidden and feel safe.</strong></p>
<p>I'd rather invest in a safe with a security level 10 and to leave it laying in the middle of the hallway, than to buy a safe with a security level 8 and hide it behind a painting.</p>
<p>I'd rather have a Facebook profile, secure it and not publish any really confidential information, than to NOT have it and letting somebody open it in my behalf.</p>
<p>I'd rather have a port scan to my perimeter to throw a result of hundreds of open ports with an effectiveness level of 10%, than to have thrown 4-5 ports with an effectiveness of 100%</p>
<p>And thousands of etceteras.</p>
<p>Is there one only response? I don't know. Feel free to comment (and/or complain) after reading.</p>



Compartir Post


	<a rel="nofollow"  target="_blank" href="http://www.matiaskatz.com/?feed=rss2&amp;lang=en" title="RSS"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/rss.png" title="RSS" alt="RSS" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;title=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F&amp;bodytext=Throughout%20our%20history%20there%20have%20been%20found%20uncountable%20cases%20in%20which%20the%20main%20security%20measure%20was%20the%20obscurity%2C%20meaning%20the%20hiding%20of%20resources%20or%20information%20from%20public%20view%20and%2For%20access.%0D%0A%0D%0ASecret%20passages%20in%20castles%2C%20values%20hidden%20inside%20ja" title="Digg"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;title=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F&amp;notes=Throughout%20our%20history%20there%20have%20been%20found%20uncountable%20cases%20in%20which%20the%20main%20security%20measure%20was%20the%20obscurity%2C%20meaning%20the%20hiding%20of%20resources%20or%20information%20from%20public%20view%20and%2For%20access.%0D%0A%0D%0ASecret%20passages%20in%20castles%2C%20values%20hidden%20inside%20ja" title="del.icio.us"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;t=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F" title="Facebook"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;title=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F&amp;annotation=Throughout%20our%20history%20there%20have%20been%20found%20uncountable%20cases%20in%20which%20the%20main%20security%20measure%20was%20the%20obscurity%2C%20meaning%20the%20hiding%20of%20resources%20or%20information%20from%20public%20view%20and%2For%20access.%0D%0A%0D%0ASecret%20passages%20in%20castles%2C%20values%20hidden%20inside%20ja" title="Google Bookmarks"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;submitHeadline=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F&amp;submitSummary=Throughout%20our%20history%20there%20have%20been%20found%20uncountable%20cases%20in%20which%20the%20main%20security%20measure%20was%20the%20obscurity%2C%20meaning%20the%20hiding%20of%20resources%20or%20information%20from%20public%20view%20and%2For%20access.%0D%0A%0D%0ASecret%20passages%20in%20castles%2C%20values%20hidden%20inside%20ja&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den&amp;title=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F&amp;source=Blog+de+Matias+Katz+Info+de+IT+para+la+gente+Comun%2C+Info+Comun+para+la+gente+de+IT&amp;summary=Throughout%20our%20history%20there%20have%20been%20found%20uncountable%20cases%20in%20which%20the%20main%20security%20measure%20was%20the%20obscurity%2C%20meaning%20the%20hiding%20of%20resources%20or%20information%20from%20public%20view%20and%2For%20access.%0D%0A%0D%0ASecret%20passages%20in%20castles%2C%20values%20hidden%20inside%20ja" title="LinkedIn"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Security%20through%20obscurity.%20Is%20it%20really%20effective%3F%20-%20http%3A%2F%2Fwww.matiaskatz.com%2F%3Fp%3D548%26amp%3Blang%3Den" title="Twitter"><img src="http://www.matiaskatz.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.matiaskatz.com/?feed=rss2&amp;p=548&amp;lang=en</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
