<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Info Magazine</title>
	<atom:link href="http://www.itinfomag.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itinfomag.com</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 08:26:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>The Two Faces of Social Networks</title>
		<link>http://www.itinfomag.com/general/the-two-faces-of-social-networks/</link>
		<comments>http://www.itinfomag.com/general/the-two-faces-of-social-networks/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 08:24:11 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Law enforcement]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[SN]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1700</guid>
		<description><![CDATA[Is it possible to acquire a valuable gift such as the latest iPad by simply following some links as advertised on social networks? You will come across legitimate competitions run by the major vendors that give away expensive gadgets for free! So, why do people (bad guys!) pay advertising costs to promote fake offers? What do they get in return? Simply, they take you to online forms to get your personal details or take you to rogue sites so that they can push malware or spyware to your computer. Social network platforms have become the main tool that allows for the spreading of scams and other malicious activities – the environment makes it easy to entice users to follow the dangling carrot! I mean the environment is attractive in its very nature and while, more and more users are becoming aware of these scams, still it is very easy to be tricks! On the other hand, law enforcement officers are also leveraging the attractive environment of social networks to track down criminals and may have in place monitoring tools collecting information about users. In this process law enforcement officers may end up with personal information of users not related to [...]]]></description>
			<content:encoded><![CDATA[<p>Is it possible to acquire a valuable gift such as the latest iPad by simply following some links as advertised on social networks? You will come across legitimate competitions run by the major vendors that give away expensive gadgets for free! So, why do people (bad guys!) pay advertising costs to promote fake offers? What do they get in return? Simply, they take you to online forms to get your personal details or take you to rogue sites so that they can push malware or spyware to your computer.</p>
<p>Social network platforms have become the main tool that allows for the spreading of scams and other malicious activities – the environment makes it easy to entice users to follow the dangling carrot! I mean the environment is attractive in its very nature and while, more and more users are becoming aware of these scams, still it is very easy to be tricks!</p>
<p>On the other hand, law enforcement officers are also leveraging the attractive environment of social networks to track down criminals and may have in place monitoring tools collecting information about users. In this process law enforcement officers may end up with personal information of users not related to any crime or whatsoever!</p>
<p>For instance, the FBI is planning to develop a monitoring system that collects intelligence from social networks.</p>
<p>Read more &#8211; <a href="http://www.bbc.co.uk/news/technology-16738209">http://www.bbc.co.uk/news/technology-16738209</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/general/the-two-faces-of-social-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Storage Gateway</title>
		<link>http://www.itinfomag.com/cloud-computing/the-storage-gateway/</link>
		<comments>http://www.itinfomag.com/cloud-computing/the-storage-gateway/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:07:47 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[Gateway]]></category>
		<category><![CDATA[iSCSI]]></category>
		<category><![CDATA[S3]]></category>
		<category><![CDATA[storage]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1696</guid>
		<description><![CDATA[An organization may have both on-premises and cloud-based storages running on different platforms while hosting a copy of each other’s data, then the organization has to implement a software mechanism to keep data on both storages in sync. Organizations using Amazon’s AWS can enhance the integration of their on-premises storage appliances with the respective AWS storage. The new AWS Storage Gateway supports the iSCSI interface which makes it compatible with many internal storage systems. In addition, the new service provides low-latency performance and secure connection to Amazon’s S3 online storage. The new AWS service can enhance existing solutions such as, online backups and introduce new ones such as, storing snapshots of on-premises applications. Also, it can help organizations integrate their disaster recovery and capacity scalability processes with Amazon’s EC2 and S3. The AWS Storage Gateway&#8217;s software appliance is installed on a host machine in the organization&#8217;s data center. Read more &#8211; http://aws.amazon.com/storagegateway/?ref_=pe_12300_22527220]]></description>
			<content:encoded><![CDATA[<p>An organization may have both on-premises and cloud-based storages running on different platforms while hosting a copy of each other’s data, then the organization has to implement a software mechanism to keep data on both storages in sync. Organizations using Amazon’s AWS can enhance the integration of their on-premises storage appliances with the respective AWS storage. The new AWS Storage Gateway supports the iSCSI interface which makes it compatible with many internal storage systems. In addition, the new service provides low-latency performance and secure connection to Amazon’s S3 online storage.</p>
<p>The new AWS service can enhance existing solutions such as, online backups and introduce new ones such as, storing snapshots of on-premises applications. Also, it can help organizations integrate their disaster recovery and capacity scalability processes with Amazon’s EC2 and S3. The AWS Storage Gateway&#8217;s software appliance is installed on a host machine in the organization&#8217;s data center.</p>
<p>Read more &#8211; <a href="http://aws.amazon.com/storagegateway/?ref_=pe_12300_22527220">http://aws.amazon.com/storagegateway/?ref_=pe_12300_22527220</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cloud-computing/the-storage-gateway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Google gets info about You!</title>
		<link>http://www.itinfomag.com/security-governance/how-google-gets-info-about-you/</link>
		<comments>http://www.itinfomag.com/security-governance/how-google-gets-info-about-you/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 07:14:32 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Google Analytics]]></category>
		<category><![CDATA[IRS]]></category>
		<category><![CDATA[track]]></category>
		<category><![CDATA[tracking features]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1694</guid>
		<description><![CDATA[Google’s capabilities of tracking users&#8217; activities on the web is a well known fact but there is one important detail you need to know which may surprise you! With your browser’s tracking features and cookies disabled, Google can still reveal information if the website you are visiting references any JavaScript hosted by Google (practically every site) and if you happen to be logged in to any Google service such as gmail, then the information they collect can be directly linked to you! Although, Google claims that the data collected is only used to provide users with products and services related to them which may seems to be a valid case but they (Google) cannot apply this practice across the board. I can assure you that all major websites use Google Analytics to track and analyze their traffic but some of these may not offer services that you wish Google to know about or you consider highly confidential such as a visit to the Internal Revenue Service’s website. In his example, Michael Devine gives an excellent demonstration of what information Google receives while he visits the IRS website and how Google receives this information. Read more &#8211; http://devinedev.blogspot.com/2012/01/death-taxes-and-google.html]]></description>
			<content:encoded><![CDATA[<p>Google’s capabilities of tracking users&#8217; activities on the web is a well known fact but there is one important detail you need to know which may surprise you! With your browser’s tracking features and cookies disabled, Google can still reveal information if the website you are visiting references any JavaScript hosted by Google (practically every site) and if you happen to be logged in to any Google service such as gmail, then the information they collect can be directly linked to you!</p>
<p>Although, Google claims that the data collected is only used to provide users with products and services related to them which may seems to be a valid case but they (Google) cannot apply this practice across the board. I can assure you that all major websites use Google Analytics to track and analyze their traffic but some of these may not offer services that you wish Google to know about or you consider highly confidential such as a visit to the Internal Revenue Service’s website.</p>
<p>In his example, Michael Devine gives an excellent demonstration of what information Google receives while he visits the IRS website and how Google receives this information.</p>
<p>Read more &#8211; <a href="http://devinedev.blogspot.com/2012/01/death-taxes-and-google.html">http://devinedev.blogspot.com/2012/01/death-taxes-and-google.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/how-google-gets-info-about-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Megaupload’s shutdown triggers DDoS attacks!</title>
		<link>http://www.itinfomag.com/cyber-attacks/megaupload%e2%80%99s-shutdown-triggers-ddos-attacks/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/megaupload%e2%80%99s-shutdown-triggers-ddos-attacks/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 12:58:44 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[arrest]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[Internet censorship]]></category>
		<category><![CDATA[Internet Piracy]]></category>
		<category><![CDATA[Megaupload]]></category>
		<category><![CDATA[Money laundering]]></category>
		<category><![CDATA[Online Piracy]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1687</guid>
		<description><![CDATA[Megaupload&#8217;s shutdown triggered a global protest by hackers who quickly organized DDoS attacks against the Justice Department and FBI websites, as well as other sites. According to Anonymous, who took credit of these attacks, Megaupload shutdown goes against the freedom of speech and is part of a bigger picture towards Internet censorship! US law enforcement officials are investigating the source of these attacks. According to various reports, the founder and boss of Megaupload known as Kim Dotcom was forced out of a safe room. He is charged with Internet piracy and money laundering. The arrest has been made as the debate over online piracy is hot, with the US Congress or better the movie and music industries are pushing for tougher legislation. Dotcom’s arrest is a demonstration that authorities do not need SOPA or PIPA like legislation to take down websites allegedly participating in Internet piracy. Although authorities may have a valid case against Megaupload’s founder as he is also accused of money laundering, but there are in place ways and means how to control online piracy without disrupting the free and open Internet &#8211; Two wrongs don&#8217;t make a right!!! Read more &#8211; http://www.reuters.com/article/2012/01/23/us-internet-piracy-megaupload-idUSTRE80K07Q20120123 http://edition.cnn.com/2012/01/20/business/megaupload-shutdown/index.html]]></description>
			<content:encoded><![CDATA[<p>Megaupload&#8217;s shutdown triggered a global protest by hackers who quickly organized DDoS attacks against the Justice Department and FBI websites, as well as other sites. According to Anonymous, who took credit of these attacks, Megaupload shutdown goes against the freedom of speech and is part of a bigger picture towards Internet censorship! US law enforcement officials are investigating the source of these attacks.</p>
<p>According to various reports, the founder and boss of Megaupload known as Kim Dotcom was forced out of a safe room. He is charged with Internet piracy and money laundering. The arrest has been made as the debate over online piracy is hot, with the US Congress or better the movie and music industries are pushing for tougher legislation.</p>
<p>Dotcom’s arrest is a demonstration that authorities do not need SOPA or PIPA like legislation to take down websites allegedly participating in Internet piracy. Although authorities may have a valid case against Megaupload’s founder as he is also accused of money laundering, but there are in place ways and means how to control online piracy without disrupting the free and open Internet &#8211; <em>Two wrongs don&#8217;t make a right</em>!!!</p>
<p>Read more &#8211; <a href="http://www.reuters.com/article/2012/01/23/us-internet-piracy-megaupload-idUSTRE80K07Q20120123">http://www.reuters.com/article/2012/01/23/us-internet-piracy-megaupload-idUSTRE80K07Q20120123</a></p>
<p><a href="http://edition.cnn.com/2012/01/20/business/megaupload-shutdown/index.html">http://edition.cnn.com/2012/01/20/business/megaupload-shutdown/index.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/megaupload%e2%80%99s-shutdown-triggers-ddos-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China&#8217;s Commitment towards Cyber Security!!!</title>
		<link>http://www.itinfomag.com/cyber-attacks/chinas-commitment-towards-cyber-security/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/chinas-commitment-towards-cyber-security/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 08:31:51 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[card reader]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[CSDN]]></category>
		<category><![CDATA[DOD]]></category>
		<category><![CDATA[fabricate]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Smart card]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1678</guid>
		<description><![CDATA[The recent news that personal information of more than 6 million users of the Chinese Software Developer Network (CSDN) had been leaked by hackers was all fabricated. The news was announced by China’s leading anti-virus software provider. The investigations conducted by the Chinese police show that the leaks were only a fabrication and that no personal information was ever leaked from these sites. National authorities in China are determined to take effective measures to protect online privacy and security, and will severely punish those who are caught in this illegitimate business, or fabricating rumours in this regard! In fact, four people have been detained and another eight received formal warnings for the above mentioned incident. Read more &#8211; http://www.chinadaily.com.cn/usa/china/2012-01/11/content_14418278.htm In the meantime, it is reported that Chinese attackers targeted the US Department of Defense (DOD) smart cards&#8217; details with Sykipot malware. Skipot is deposited into machines with card readers and the keystroke logging software is able to steal PIN numbers used with users&#8217; smart cards. The malware infects machines through spam and is able to identify which machines have an installed card reader! Smart card-based authentication is standardized at the DOD and at many other US government agencies. According to AlienVault, a security [...]]]></description>
			<content:encoded><![CDATA[<p>The recent news that personal information of more than 6 million users of the Chinese Software Developer Network (CSDN) had been leaked by hackers was all fabricated. The news was announced by China’s leading anti-virus software provider. The investigations conducted by the Chinese police show that the leaks were only a fabrication and that no personal information was ever leaked from these sites.</p>
<p>National authorities in China are determined to take effective measures to protect online privacy and security, and will severely punish those who are caught in this illegitimate business, or fabricating rumours in this regard! In fact, four people have been detained and another eight received formal warnings for the above mentioned incident.</p>
<p>Read more &#8211; <a href="http://www.chinadaily.com.cn/usa/china/2012-01/11/content_14418278.htm">http://www.chinadaily.com.cn/usa/china/2012-01/11/content_14418278.htm</a></p>
<p>In the meantime, it is reported that Chinese attackers targeted the US Department of Defense (DOD) smart cards&#8217; details with Sykipot malware. Skipot is deposited into machines with card readers and the keystroke logging software is able to steal PIN numbers used with users&#8217; smart cards. The malware infects machines through spam and is able to identify which machines have an installed card reader! Smart card-based authentication is standardized at the DOD and at many other US government agencies. According to AlienVault, a security information and event management (SIEM) company when a card is inserted into the reader, the malware acts as the authenticated user and can access sensitive information.</p>
<p>Read more &#8211; <a href="http://www.networkworld.com/news/2012/011412-chinese-attack-us-dod-smart-254927.html">http://www.networkworld.com/news/2012/011412-chinese-attack-us-dod-smart-254927.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/chinas-commitment-towards-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Instances available with Amazon’s EC2 Free Usage Tier</title>
		<link>http://www.itinfomag.com/cloud-computing/windows-instances-available-with-amazon%e2%80%99s-ec2-free-usage-tier/</link>
		<comments>http://www.itinfomag.com/cloud-computing/windows-instances-available-with-amazon%e2%80%99s-ec2-free-usage-tier/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 07:30:12 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[GovCloud]]></category>
		<category><![CDATA[instance]]></category>
		<category><![CDATA[micro]]></category>
		<category><![CDATA[Windows Server 2008]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1673</guid>
		<description><![CDATA[Amazon Cloud free usage tier service now includes Microsoft Windows Servers 2008 R2 on micro instances. The one year almost free trial which give users up to 750 hours per month of cloud computing services is an excellent starting point for users wanting to learn Cloud computing using Amazon’s EC2. Running Linux on micro instances provides an adequate platform to run personal websites or small test environments for software development, however, such instances are not appropriate for high-end services. The limited processing power of micro instances has to be combined with the capabilities of medium or high spec instances if higher levels of resources are required. Amazon stated that the new micro instances were fined tuned to run Windows Servers and are available in all AWS regions with the exception of GovCloud. Read more &#8211; http://aws.amazon.com/free/]]></description>
			<content:encoded><![CDATA[<p>Amazon Cloud free usage tier service now includes Microsoft Windows Servers 2008 R2 on micro instances. The one year almost free trial which give users up to 750 hours per month of cloud computing services is an excellent starting point for users wanting to learn Cloud computing using Amazon’s EC2.</p>
<p>Running Linux on micro instances provides an adequate platform to run personal websites or small test environments for software development, however, such instances are not appropriate for high-end services. The limited processing power of micro instances has to be combined with the capabilities of medium or high spec instances if higher levels of resources are required. Amazon stated that the new micro instances were fined tuned to run Windows Servers and are available in all AWS regions with the exception of GovCloud.</p>
<p>Read more &#8211; <a href="http://aws.amazon.com/free/">http://aws.amazon.com/free/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cloud-computing/windows-instances-available-with-amazon%e2%80%99s-ec2-free-usage-tier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When to Trust a Website</title>
		<link>http://www.itinfomag.com/security-governance/when-to-trust-a-website/</link>
		<comments>http://www.itinfomag.com/security-governance/when-to-trust-a-website/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 15:46:29 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[address bar]]></category>
		<category><![CDATA[bogus links]]></category>
		<category><![CDATA[criminals]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[HTTP]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[Padlock]]></category>
		<category><![CDATA[sensitive data]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Trust]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1668</guid>
		<description><![CDATA[The Internet provides services necessary to the functioning of governments, corporations and financial institutions, not to mention schools, medical facilities and SMEs. Extensive use of the Internet by such a wide variety of parties has naturally caused the volume of sensitive or valuable data carried on the Internet—such as financial transactions, medical data and other proprietary data—to grow rapidly. Consequently, cybercrime is becoming more organized and established as a transnational business, seeking technical means to subvert the Internet for illicit purposes. Criminals are exploiting weaknesses using social engineering, bogus links and other means to direct people to sites that resemble those they frequently use. The outcome of such malicious activity may fool people to give up confidential details that can then be used for fraudulent purposes. Criminals may place malware onto a user’s computer that quietly turns the machine into a tool for further crime, and may allow a criminal to impersonate someone sending email from that domain or spying on their conversations. The need to know how to trust sites you are visiting has become an urgent one and there are ways to establish trustworthiness which include: Padlock icon: The most common sign that a site is more trustworthy than others coincides [...]]]></description>
			<content:encoded><![CDATA[<p>The Internet provides services necessary to the functioning of governments, corporations and financial institutions, not to mention schools, medical facilities and SMEs. Extensive use of the Internet by such a wide variety of parties has naturally caused the volume of sensitive or valuable data carried on the Internet—such as financial transactions, medical data and other proprietary data—to grow rapidly.</p>
<p>Consequently, cybercrime is becoming more organized and established as a transnational business, seeking technical means to subvert the Internet for illicit purposes.</p>
<p>Criminals are exploiting weaknesses using social engineering, bogus links and other means to direct people to sites that resemble those they frequently use. The outcome of such malicious activity may fool people to give up confidential details that can then be used for fraudulent purposes. Criminals may place malware onto a user’s computer that quietly turns the machine into a tool for further crime, and may allow a criminal to impersonate someone sending email from that domain or spying on their conversations.</p>
<p>The need to know how to trust sites you are visiting has become an urgent one and there are ways to establish trustworthiness which include:</p>
<p><strong>Padlock icon:</strong> The most common sign that a site is more trustworthy than others coincides with the use of “https” rather than “http” as the prefix to the page’s web address.</p>
<p><strong>Green address bar:</strong> More recently, users will have become aware that the highlighting of part of the address bar denotes even greater security. The colouring of the first piece of the address bar shows that the site’s owner has gone a step further and offered themselves up for extensive vetting and authentication procedures, to prove the site is what it says it is.</p>
<p>To read more about ‘When to trust a website’ go  &#8211; <a href="http://windows.microsoft.com/en-US/windows-vista/When-to-trust-a-website">http://windows.microsoft.com/en-US/windows-vista/When-to-trust-a-website</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/when-to-trust-a-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Status Checks for EC2 Instances</title>
		<link>http://www.itinfomag.com/cloud-computing/status-checks-for-ec2-instances/</link>
		<comments>http://www.itinfomag.com/cloud-computing/status-checks-for-ec2-instances/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 07:25:46 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Check]]></category>
		<category><![CDATA[EC2]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[instance]]></category>
		<category><![CDATA[Reachability]]></category>
		<category><![CDATA[Status]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1664</guid>
		<description><![CDATA[Amazon EC2 functionality now includes a status check to help identify problems related to an instance ability to run applications. EC2 contains an automated process that tests every running instance and tries to detect both hardware and software issues. The mechanism reports problems back to customers where they would be able to distinguish software problems from issues with the underlying infrastructure. The two new status checks are System and Instance status checks: System status checks detect problems with the underlying EC2 systems that are used by each individual instance. The first System status check is a reachability check that confirms that the EC2 monitoring system is able to get network packets to the customer’s instance. Instance Status checks detect problems within the instance. Typically, these are problems that the customer can fix, for example by rebooting the instance or making changes in the operating system. There is currently one Instance status check which is the Instance Reachability check that confirms that the monitoring system is able to deliver network packets to the operating system hosted on the customer’s instance. Read more http://aws.typepad.com/aws/2012/01/ec2-instance-status-checks.html?utm_source=feedburner&#38;utm_medium=email&#38;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29]]></description>
			<content:encoded><![CDATA[<p>Amazon EC2 functionality now includes a status check to help identify problems related to an instance ability to run applications. EC2 contains an automated process that tests every running instance and tries to detect both hardware and software issues. The mechanism reports problems back to customers where they would be able to distinguish software problems from issues with the underlying infrastructure. The two new status checks are System and Instance status checks:</p>
<p>System status checks detect problems with the underlying EC2 systems that are used by each individual instance. The first System status check is a reachability check that confirms that the EC2 monitoring system is able to get network packets to the customer’s instance.</p>
<p>Instance Status checks detect problems within the instance. Typically, these are problems that the customer can fix, for example by rebooting the instance or making changes in the operating system. There is currently one Instance status check which is the Instance Reachability check that confirms that the monitoring system is able to deliver network packets to the operating system hosted on the customer’s instance.</p>
<p>Read more <a href="http://aws.typepad.com/aws/2012/01/ec2-instance-status-checks.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29">http://aws.typepad.com/aws/2012/01/ec2-instance-status-checks.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cloud-computing/status-checks-for-ec2-instances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 Online Backup Procedure</title>
		<link>http://www.itinfomag.com/data-backup-recovery/windows-7-online-backup-procedure/</link>
		<comments>http://www.itinfomag.com/data-backup-recovery/windows-7-online-backup-procedure/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 09:19:21 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Data Backup & Recovery]]></category>
		<category><![CDATA[BitLocker]]></category>
		<category><![CDATA[data backup]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[remote backup]]></category>
		<category><![CDATA[SkyDrive]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1661</guid>
		<description><![CDATA[There are many online backup solutions out there! But if your system runs on Windows 7 Enterprise or Ultimate edition you can create your own secure online backup solution at zero price. You just need a free online storage account such as, Microsoft’s SkyDrive and some time to set up a secure backup procedure. You could upload your data to online storage and rely on the storage provider for the safety and privacy of your data, however, if your data is highly sensitive then this is not advisable. A secure and free online backup procedure posted on windows7library.com would provide the necessary security through BitLocker encryption and virtual hard drives. BitLocker is a full volume encryption and system protection feature that is available on computers running the Enterprise and Ultimate editions of Windows 7. To learn how to create your own secure and free online backup solution go here: http://www.windows7library.com/blog/bkup/secure-and-free-online-backup-procedure/]]></description>
			<content:encoded><![CDATA[<p>There are many online backup solutions out there! But if your system runs on Windows 7 Enterprise or Ultimate edition you can create your own secure online backup solution at zero price. You just need a free online storage account such as, Microsoft’s SkyDrive and some time to set up a secure backup procedure.</p>
<p>You could upload your data to online storage and rely on the storage provider for the safety and privacy of your data, however, if your data is highly sensitive then this is not advisable. A secure and free online backup procedure posted on windows7library.com would provide the necessary security through BitLocker encryption and virtual hard drives. BitLocker is a full volume encryption and system protection feature that is available on computers running the Enterprise and Ultimate editions of Windows 7.</p>
<p>To learn how to create your own secure and free online backup solution go here:<br />
<a href="http://www.windows7library.com/blog/bkup/secure-and-free-online-backup-procedure/">http://www.windows7library.com/blog/bkup/secure-and-free-online-backup-procedure/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/data-backup-recovery/windows-7-online-backup-procedure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wi-Fi WPS Brute Force Vulnerability</title>
		<link>http://www.itinfomag.com/security-governance/wi-fi-wps-brute-force-vulnerability/</link>
		<comments>http://www.itinfomag.com/security-governance/wi-fi-wps-brute-force-vulnerability/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 18:11:35 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Brute force]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Wi-Fi]]></category>
		<category><![CDATA[Wi-Fi Protected Setup]]></category>
		<category><![CDATA[WPS]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1656</guid>
		<description><![CDATA[Disable WPS on your wireless device before an attacker discovers your device’s PIN code! Wi-Fi Protected Setup (WPS) is a feature that makes it easier to set up wireless networks and devices but its design is vulnerable to brute force attacks. In simple words the time required to brute force the entire PIN is relatively short – 4 to 10 hours for an attacker to guess the 8 digit PIN. US-CERT has released a report on the vulnerability of Wi-Fi Protected Setup (WPS), explaining the risk of an attacker gaining full access to the network by using a brute force attack to discover the PIN. WPS is a feature on many of today’s wireless devices so researchers say millions of devices could be affected and it could take a long time to fix them all. Read the full vulnerability report here: http://www.kb.cert.org/vuls/id/723755]]></description>
			<content:encoded><![CDATA[<p>Disable WPS on your wireless device before an attacker discovers your device’s PIN code! Wi-Fi Protected Setup (WPS) is a feature that makes it easier to set up wireless networks and devices but its design is vulnerable to brute force attacks. In simple words the time required to brute force the entire PIN is relatively short – 4 to 10 hours for an attacker to guess the 8 digit PIN.</p>
<p>US-CERT has released a report on the vulnerability of Wi-Fi Protected Setup (WPS), explaining the risk of an attacker gaining full access to the network by using a brute force attack to discover the PIN. WPS is a feature on many of today’s wireless devices so researchers say millions of devices could be affected and it could take a long time to fix them all.</p>
<p>Read the full vulnerability report here:<br />
<a href="http://www.kb.cert.org/vuls/id/723755">http://www.kb.cert.org/vuls/id/723755</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/wi-fi-wps-brute-force-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Emergency Christmas Anonymous Press Release!</title>
		<link>http://www.itinfomag.com/cyber-attacks/emergency-christmas-anonymous-press-release/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/emergency-christmas-anonymous-press-release/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 08:00:48 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[pastebin]]></category>
		<category><![CDATA[Stratfor]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1650</guid>
		<description><![CDATA[The Anonymous group threaten to publish information including emails from the U.S. military which they managed to steal from a private firm following a successful break in and defacement of the firm’s website. Stratfor (Strategic Forecasting Inc) is a large private intelligence corporation with numerous intelligence agencies as their clients admitted the breach. Stratfor website defacement can be viewed here &#8211; http://theelitist.net/tag/hack The hacktivists uploaded a short list of compromised accounts to pastebin, it is reported that over 90,000 credit card details have been stolen by Anonymous. They also uploaded a long report or long-winded Q&#38;A which is worth reading. Although, this report is aimed at Stratfor&#8217;s IT security, I reckon that any admin would find it useful as it discusses security controls and procedures that we all may lack in our environments. To read the full message, go here &#8211; http://pastebin.com/CAWDEW8G On the other hand, there are members of the Anonymous group who value the freedom of press and consider Stratfor&#8217;s work as such. These members disapproved the attack and stated that this is not the work of Anonymous, see the Emergency Christmas Anonymous Press Release here &#8211; http://pastebin.com/8yrwyNkt Read more about this story here – http://www.msnbc.msn.com/id/45799865/ns/technology_and_science-security/]]></description>
			<content:encoded><![CDATA[<p>The Anonymous group threaten to publish information including emails from the U.S. military which they managed to steal from a private firm following a successful break in and defacement of the firm’s website. Stratfor (Strategic Forecasting Inc) is a large private intelligence corporation with numerous intelligence agencies as their clients admitted the breach. Stratfor website defacement can be viewed here &#8211; <a href="http://theelitist.net/tag/hack">http://theelitist.net/tag/hack</a></p>
<p>The hacktivists uploaded a short list of compromised accounts to <a href="http://pastebin.com/8MtFze0s" target="_blank">pastebin</a>, it is reported that over 90,000 credit card details have been stolen by Anonymous. They also uploaded a long report or long-winded Q&amp;A which is worth reading. Although, this report is aimed at Stratfor&#8217;s IT security, I reckon that any admin would find it useful as it discusses security controls and procedures that we all may lack in our environments. To read the full message, go here &#8211; <a href="http://pastebin.com/CAWDEW8G">http://pastebin.com/CAWDEW8G</a></p>
<p>On the other hand, there are members of the Anonymous group who value the freedom of press and consider Stratfor&#8217;s work as such. These members disapproved the attack and stated that this is not the work of Anonymous, see the Emergency Christmas Anonymous Press Release here &#8211; <a href="http://pastebin.com/8yrwyNkt">http://pastebin.com/8yrwyNkt</a></p>
<p>Read more about this story here –<br />
<a href="http://www.msnbc.msn.com/id/45799865/ns/technology_and_science-security/">http://www.msnbc.msn.com/id/45799865/ns/technology_and_science-security/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/emergency-christmas-anonymous-press-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon&#8217;s AWS Console Update</title>
		<link>http://www.itinfomag.com/cloud-computing/amazons-aws-console-update/</link>
		<comments>http://www.itinfomag.com/cloud-computing/amazons-aws-console-update/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 10:10:56 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[management consoles]]></category>
		<category><![CDATA[Route 53]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1644</guid>
		<description><![CDATA[Amazon’s Cloud computing management console now includes complete support for Amazon DNS service, Route 53. Route 53 is a highly available and scalable Domain Name System (DNS) web service. The DNS service allows you to create your hosted zones and set up the appropriate records in a similar manner that you may be accustomed with traditional DNS service providers. To register a domain and set it up from the AWS Management Console you need to buy a domain name from a registrar, create a hosted zone, update the NS (Name Server) records at the registrar, set up hosting and create an A record or other records as required. Amazon has provided a How To procedure that will help you set up Weighted Round Robin (WRR) DNS. To implement WRR with Route 53, you will need multiple servers (and the corresponding IP addresses). WRR allows you to send a certain proportion of your inbound traffic to a test server for A/B testing. Route 53 also supports Weighted Round Robin (WRR) record sets. To see how to set up Weighted Round Robin (WRR) DNS go here: http://aws.typepad.com/aws/2011/11/aws-management-console-now-supports-amazon-route-53.html?utm_source=feedburner&#38;utm_medium=email&#38;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29]]></description>
			<content:encoded><![CDATA[<p>Amazon’s Cloud computing management console now includes complete support for Amazon DNS service, Route 53. Route 53 is a highly available and scalable Domain Name System (DNS) web service. The DNS service allows you to create your hosted zones and set up the appropriate records in a similar manner that you may be accustomed with traditional DNS service providers.</p>
<p>To register a domain and set it up from the AWS Management Console you need to buy a domain name from a registrar, create a hosted zone, update the NS (Name Server) records at the registrar, set up hosting and create an A record or other records as required.</p>
<p>Amazon has provided a How To procedure that will help you set up Weighted Round Robin (WRR) DNS. To implement WRR with Route 53, you will need multiple servers (and the corresponding IP addresses). WRR allows you to send a certain proportion of your inbound traffic to a test server for A/B testing. Route 53 also supports Weighted Round Robin (WRR) record sets.</p>
<p>To see how to set up Weighted Round Robin (WRR) DNS go here:<br />
<a href="http://aws.typepad.com/aws/2011/11/aws-management-console-now-supports-amazon-route-53.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29">http://aws.typepad.com/aws/2011/11/aws-management-console-now-supports-amazon-route-53.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+AmazonWebServicesBlog+%28Amazon+Web+Services+Blog%29</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cloud-computing/amazons-aws-console-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Defender Offline Beta</title>
		<link>http://www.itinfomag.com/security-governance/windows-defender-offline-beta/</link>
		<comments>http://www.itinfomag.com/security-governance/windows-defender-offline-beta/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 08:46:55 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[malicious programs]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1630</guid>
		<description><![CDATA[The latest version of Microsoft’s Windows Defender anti-malware software can help remove such hard to find malicious and potentially unwanted programs using definitions that recognize threats. Apart, from detecting malicious software Windows Defender Offline Beta can notify you of the risks and is able to scan for malicious code even before Windows boots. The new version is available in beta now, in both 32- and 64-bit editions and  you can run it off a CD, DVD or USB flash drive. This makes it possible to detect rootkits and other boot process malware. To use Windows Defender Offline Beta, follow these steps: Download Windows Defender Offline Beta and create a CD, DVD, or USB flash drive. Restart your PC using the Windows Defender Offline Beta media. Scan your PC for malicious and other potentially unwanted software. Remove any malware that is found from your PC. It is recommended that you download Windows Defender Offline Beta and create the CD, DVD, or USB flash drive on a PC that isn&#8217;t infected with malware and run the version that matches your installed system. To check the operating system version on computers running Windows Vista or Windows 7, click the Start button, right-click Computer, and [...]]]></description>
			<content:encoded><![CDATA[<p>The latest version of Microsoft’s Windows Defender anti-malware software can help remove such hard to find malicious and potentially unwanted programs using definitions that recognize threats. Apart, from detecting malicious software Windows Defender Offline Beta can notify you of the risks and is able to scan for malicious code even before Windows boots. The new version is available in beta now, in both 32- and 64-bit editions and  you can run it off a CD, DVD or USB flash drive. This makes it possible to detect rootkits and other boot process malware.</p>
<p>To use Windows Defender Offline Beta, follow these steps:</p>
<ol>
<li>Download Windows Defender Offline Beta and create a CD, DVD, or USB flash drive.</li>
<li>Restart your PC using the Windows Defender Offline Beta media.</li>
<li>Scan your PC for malicious and other potentially unwanted software.</li>
<li>Remove any malware that is found from your PC.<br />
<a href="http://www.itinfomag.com/wp-content/uploads/2011/12/Windows-Defender.jpg"><img class="aligncenter size-medium wp-image-1632" style="margin-top: 5px; margin-bottom: 5px;" title="Windows Defender" src="http://www.itinfomag.com/wp-content/uploads/2011/12/Windows-Defender-300x188.jpg" alt="" width="300" height="188" /></a></li>
</ol>
<p>It is recommended that you download Windows Defender Offline Beta and create the CD, DVD, or USB flash drive on a PC that isn&#8217;t infected with malware and run the version that matches your installed system. To check the operating system version on computers running Windows Vista or Windows 7, click the <em>Start </em>button, right-click Computer, and then click <em>Properties</em>.</p>
<ul>
<li>If &#8220;64-bit Operating System&#8221; is listed next to System type, you’re running the 64-bit version of Windows Vista or Windows 7.</li>
<li>If &#8220;32-bit Operating System&#8221; is listed next to System type, you’re running the 32-bit version of Windows Vista or Windows 7.</li>
</ul>
<p>To download the latest Windows Defender 32-bit or 64-bit beta version go here:<br />
<a href="http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline">http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/windows-defender-offline-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A variant of the “Zeus” malware for Christmas!</title>
		<link>http://www.itinfomag.com/cyber-attacks/a-variant-of-the-%e2%80%9czeus%e2%80%9d-malware-for-christmas/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/a-variant-of-the-%e2%80%9czeus%e2%80%9d-malware-for-christmas/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 09:45:28 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Bank]]></category>
		<category><![CDATA[Cyber Squad]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[money transfer]]></category>
		<category><![CDATA[mule]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1635</guid>
		<description><![CDATA[We have become accustomed with threats that surface during the festive season and this year is no exception. The Federal Bureau of Investigation (FBI) is warning consumers about a spear phishing campaign involving personal and business bank accounts based on Zeus trojan, DDoS attacks, and money mules. According to FBI Denver Cyber Squad, “the spam campaign pretends to be legitimate e-mails from the National Automated Clearing House Association (NACHA), advising the user there is a problem with the ACH transaction at their bank. Once they click on the link they are infected with a variant of the Zeus trojan known as Gameover, which is able to keylog their information and steal their online banking credentials. After the accounts are compromised, the perpetrators conduct a DDoS attack on the financial institution. The DDoS is used to deflect attention from the wire transfers as well to make them unable to reverse the transactions (if found). A portion of the wire transfers (not all) are being transmitted directly to high-end jewelry stores, wherein the money mule comes to the actual store to pick up his $100K in jewels (or whatever dollar amount was wired)”. The above explanation from FBI created immediate response from some [...]]]></description>
			<content:encoded><![CDATA[<p>We have become accustomed with threats that surface during the festive season and this year is no exception. The Federal Bureau of Investigation (FBI) is warning consumers about a spear phishing campaign involving personal and business bank accounts based on Zeus trojan, DDoS attacks, and money mules.</p>
<p>According to FBI Denver Cyber Squad, “<em>the spam campaign pretends to be legitimate e-mails from the National Automated Clearing House Association (NACHA), advising the user there is a problem with the ACH transaction at their bank. Once they click on the link they are infected with a variant of the Zeus trojan known as Gameover, which is able to keylog their information and steal their online banking credentials. After the accounts are compromised, the perpetrators conduct a DDoS attack on the financial institution. The DDoS is used to deflect attention from the wire transfers as well to make them unable to reverse the transactions (if found). A portion of the wire transfers (not all) are being transmitted directly to high-end jewelry stores, wherein the money mule comes to the actual store to pick up his $100K in jewels (or whatever dollar amount was wired)”</em>.</p>
<p>The above explanation from FBI created immediate response from some banks. Banks claimed that in the event of a successful DDoS attack on their IT infrastructure, the bank under attack would not be able to transfer any money and that would include the criminals’ fraudulent transfers!!!</p>
<p>Read the FBI news item here:<br />
<a href="http://www.fbi.gov/denver/press-releases/2011/fbi-denver-cyber-squad-advises-citizens-to-be-aware-of-a-new-phishing-campaign">http://www.fbi.gov/denver/press-releases/2011/fbi-denver-cyber-squad-advises-citizens-to-be-aware-of-a-new-phishing-campaign</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/a-variant-of-the-%e2%80%9czeus%e2%80%9d-malware-for-christmas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Management Features for Amazon’s SES</title>
		<link>http://www.itinfomag.com/cloud-computing/new-management-features-for-amazon%e2%80%99s-ses/</link>
		<comments>http://www.itinfomag.com/cloud-computing/new-management-features-for-amazon%e2%80%99s-ses/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 08:15:09 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[SES]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1626</guid>
		<description><![CDATA[Amazon’s Simple Email Service (SES) is now accessible from the management console.  A new tab in AWS Management Console provides access to all SES important features freeing users from installing and running the command line version. However, users still need to call the SES API to send production emails. The Amazon Simple Email Service gives you a simple and cost-effective way to send any volume of bulk or transactional email. The new console feature allows users to see detailed metrics of SES activities, such as verifying addresses during testing and view statistics and limits. To read more go here: http://aws.amazon.com/documentation/ses/]]></description>
			<content:encoded><![CDATA[<p>Amazon’s Simple Email Service (<a href="http://www.itinfomag.com/cloud-computing/amazon-simple-email-service/" target="_blank">SES</a>) is now accessible from the management console.  A new tab in AWS Management Console provides access to all SES important features freeing users from installing and running the command line version. However, users still need to call the SES API to send production emails. The Amazon Simple Email Service gives you a simple and cost-effective way to send any volume of bulk or transactional email.</p>
<p>The new console feature allows users to see detailed metrics of SES activities, such as verifying addresses during testing and view statistics and limits.</p>
<p>To read more go here:<br />
<a href="http://aws.amazon.com/documentation/ses/">http://aws.amazon.com/documentation/ses/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cloud-computing/new-management-features-for-amazon%e2%80%99s-ses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Check your Online Privacy!</title>
		<link>http://www.itinfomag.com/security-governance/check-your-online-privacy/</link>
		<comments>http://www.itinfomag.com/security-governance/check-your-online-privacy/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 08:29:03 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Online Privacy]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Profile]]></category>
		<category><![CDATA[Reputation]]></category>
		<category><![CDATA[Secure me]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1621</guid>
		<description><![CDATA[A new service Secure.me provided by a German company allows you to analyse your Facebook profile for any data that’s putting your privacy at risk! The service helps you protect your online privacy and gives you control over your reputation. The service also allows you to identify privacy threats on Facebook and to protect yourself from compromised photos using an intuitive interface with scores and displayed in real-time. Simply logging on to Facebook will trigger the service to initiate a scan of your Facebook profile to identify any potential risks. On the service site one can get a summary of all risks, analyses of your photos and activities, as well as sections on your profile, network and overall privacy. The service includes parental control features, which allows parents to keep track of their children’s Facebook profile. For instance, parents can see what their children are sharing, and can make sure they don‘t make friends with the wrong people. Learn how secure.me protects your personal data here: http://www.secure.me/]]></description>
			<content:encoded><![CDATA[<p>A new service Secure.me provided by a German company allows you to analyse your Facebook profile for any data that’s putting your privacy at risk!</p>
<p>The service helps you protect your online privacy and gives you control over your reputation. The service also allows you to identify privacy threats on Facebook and to protect yourself from compromised photos using an intuitive interface with scores and displayed in real-time.</p>
<p>Simply logging on to Facebook will trigger the service to initiate a scan of your Facebook profile to identify any potential risks. On the service site one can get a summary of all risks, analyses of your photos and activities, as well as sections on your profile, network and overall privacy.</p>
<p>The service includes parental control features, which allows parents to keep track of their children’s Facebook profile. For instance, parents can see what their children are sharing, and can make sure they don‘t make friends with the wrong people.</p>
<p>Learn how secure.me protects your personal data here:<br />
<a href="http://www.secure.me/">http://www.secure.me/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/check-your-online-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Best Defence is to Attack!</title>
		<link>http://www.itinfomag.com/cyber-attacks/the-best-defence-is-to-attack/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/the-best-defence-is-to-attack/#comments</comments>
		<pubDate>Thu, 08 Dec 2011 18:37:51 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[British]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyber Unit]]></category>
		<category><![CDATA[cyber-attacks]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hacktivists]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1617</guid>
		<description><![CDATA[The British government is working on a national plan that empowers its cyber unit with the capability of launching cyber-attacks against hostile nations and terrorists! The government is aware of possible threats against the British infrastructure such as water, energy and the financial sector, and the possible use of cyber weapons in these attacks. Britain alone suffers 27 billion Sterlings a year in fraud committed by hacktivists. The British plans include a new joint cyber unit working on new defence tactics, techniques and plans to deliver military effects through operations in cyberspace. However, it is believed that the development of an offensive capability to deal with cyber threats was discussed at the National Security Council. To read the full news item go here: http://www.telegraph.co.uk/news/uknews/defence/8915871/Britain-prepares-for-cyber-war.html?utm_source=dlvr.it&#38;amp;utm_medium=twitter]]></description>
			<content:encoded><![CDATA[<p>The British government is working on a national plan that empowers its cyber unit with the capability of launching cyber-attacks against hostile nations and terrorists! The government is aware of possible threats against the British infrastructure such as water, energy and the financial sector, and the possible use of cyber weapons in these attacks. Britain alone suffers 27 billion Sterlings a year in fraud committed by hacktivists.</p>
<p>The British plans include a new joint cyber unit working on new defence tactics, techniques and plans to deliver military effects through operations in cyberspace. However, it is believed that the development of an offensive capability to deal with cyber threats was discussed at the National Security Council.</p>
<p>To read the full news item go here:</p>
<p><a href="http://www.telegraph.co.uk/news/uknews/defence/8915871/Britain-prepares-for-cyber-war.html?utm_source=dlvr.it&amp;amp;utm_medium=twitter">http://www.telegraph.co.uk/news/uknews/defence/8915871/Britain-prepares-for-cyber-war.html?utm_source=dlvr.it&amp;amp;utm_medium=twitter</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/the-best-defence-is-to-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDoS attacks against DNS servers using spam</title>
		<link>http://www.itinfomag.com/cyber-attacks/ddos-attacks-against-dns-servers-using-spam/</link>
		<comments>http://www.itinfomag.com/cyber-attacks/ddos-attacks-against-dns-servers-using-spam/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 09:24:32 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[NS Record]]></category>
		<category><![CDATA[SMTP]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1614</guid>
		<description><![CDATA[A DDoS attack against DNS servers can take different forms but one approach which is rarely mentioned was researched by Jakub Alimov from the Seznam.cz and published on zon-h.org. In his research Jakub observed a new attacking scenario against DNS servers which involves sending spam messages from SMTP services with high Internet bandwidth. The attacker first obtains the IP address of the target DNS server, and set the NS record of a registered domain to the same IP address of the target DNS and allow the changes to propagate. A spam botnet is then initiated and target email accounts residing on high bandwidth SMTP (email) servers such as, Google, Yahoo, Hotmail (referred to as white horses). Spam messages are sent using different sub-domains of the pre-register domain. When the high bandwidth email servers get the spam messages they check whether the sender’s domain resolves to the domain MX record and this background task is performed against the target DNS server. Remember, that the attacker has set the target DNS as the server servicing such requests! The result is that the target DNS server receives multiple regular DNS requests for the bogus sub-domain records and responds negatively to these requests. However, multiple [...]]]></description>
			<content:encoded><![CDATA[<p>A DDoS attack against DNS servers can take different forms but one approach which is rarely mentioned was researched by Jakub Alimov from the Seznam.cz and published on zon-h.org. In his research Jakub observed a new attacking scenario against DNS servers which involves sending spam messages from SMTP services with high Internet bandwidth.</p>
<p>The attacker first obtains the IP address of the target DNS server, and set the NS record of a registered domain to the same IP address of the target DNS and allow the changes to propagate. A spam botnet is then initiated and target email accounts residing on high bandwidth SMTP (email) servers such as, Google, Yahoo, Hotmail (referred to as white horses). Spam messages are sent using different sub-domains of the pre-register domain. When the high bandwidth email servers get the spam messages they check whether the sender’s domain resolves to the domain MX record and this background task is performed against the target DNS server. Remember, that the attacker has set the target DNS as the server servicing such requests!</p>
<p>The result is that the target DNS server receives multiple regular DNS requests for the bogus sub-domain records and responds negatively to these requests. However, multiple valid DNS requests from high bandwidth email servers can easily overwhelm the target DNS server.</p>
<p>Read the full report here:</p>
<p><a href="http://www.zone-h.org/news/id/4739">http://www.zone-h.org/news/id/4739</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/cyber-attacks/ddos-attacks-against-dns-servers-using-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone&#8217;s Siri may expose your Personal Information!</title>
		<link>http://www.itinfomag.com/security-governance/iphones-siri-may-expose-your-personal-information/</link>
		<comments>http://www.itinfomag.com/security-governance/iphones-siri-may-expose-your-personal-information/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 14:09:21 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[lock]]></category>
		<category><![CDATA[pass]]></category>
		<category><![CDATA[Siri]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1609</guid>
		<description><![CDATA[Although, iPhone’s voice-recognition incorporates cutting edge technology features, it may expose confidential information to third-parties!  The voice-recognition feature known as Siri lets you use your voice to send messages, schedule meetings, place phone calls, and not only understands what you say, it’s smart enough to know what you mean. However, Siri bypasses iPhone security and locking features! A third-party can grab the phone and activate Siri even if it has a screen-lock pass code set. Then, the same third-party can load a contact list and compose a text or email in the name of the owner. If the owner has corporate email access enabled then the risks are even higher! Although, users can disable Siri’s access when the phone is locked, administrators administering smart phones within the enterprise have no capability to do so! Read the full article here: http://searchconsumerization.techtarget.com/tip/iPhones-Siri-security-flaws-Is-IT-powerless?asrc=EM_NLN_15556274&#38;track=NL-544&#38;ad=856082]]></description>
			<content:encoded><![CDATA[<p>Although, iPhone’s voice-recognition incorporates cutting edge technology features, it may expose confidential information to third-parties!  The voice-recognition feature known as Siri lets you use your voice to send messages, schedule meetings, place phone calls, and not only understands what you say, it’s smart enough to know what you mean. However, Siri bypasses iPhone security and locking features!</p>
<p>A third-party can grab the phone and activate Siri even if it has a screen-lock pass code set. Then, the same third-party can load a contact list and compose a text or email in the name of the owner. If the owner has corporate email access enabled then the risks are even higher! Although, users can disable Siri’s access when the phone is locked, administrators administering smart phones within the enterprise have no capability to do so!</p>
<p>Read the full article here:</p>
<p><a href="http://searchconsumerization.techtarget.com/tip/iPhones-Siri-security-flaws-Is-IT-powerless?asrc=EM_NLN_15556274&amp;track=NL-544&amp;ad=856082">http://searchconsumerization.techtarget.com/tip/iPhones-Siri-security-flaws-Is-IT-powerless?asrc=EM_NLN_15556274&amp;track=NL-544&amp;ad=856082</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/iphones-siri-may-expose-your-personal-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security-as-a-Service from HP</title>
		<link>http://www.itinfomag.com/security-governance/security-as-a-service-from-hp/</link>
		<comments>http://www.itinfomag.com/security-governance/security-as-a-service-from-hp/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 18:44:22 +0000</pubDate>
		<dc:creator>George</dc:creator>
				<category><![CDATA[Security Governance]]></category>
		<category><![CDATA[Fortify]]></category>
		<category><![CDATA[Fortify on Demand]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[ISV]]></category>
		<category><![CDATA[Saas]]></category>
		<category><![CDATA[security as a service]]></category>

		<guid isPermaLink="false">http://www.itinfomag.com/?p=1605</guid>
		<description><![CDATA[Software security testing in the Cloud can help ISVs (Independent Software Vendors) or organizations assess their applications robustness without requiring them to invest in costly solutions and excessive time! HP Fortify on Demand is a Security-as-a-Service (SaaS) testing solution that allows any organization to test the security of software quickly, accurately, affordably, and without any software to install or manage. This automated on-demand service helps organizations with two key challenges: Ensuring the security of applications licensed from third parties Increasing the speed and efficiency of building security into a development lifecycle HP Fortify on Demand tests the security of in-house or third-party applications in three steps, allowing customers to login and upload their applications, the system performs comprehensive testing and finally, the results are issued and sent to customers. HP Fortify on Demand helps users achieve their software security assessment objectives by providing a robust application-testing environment. For more information about HP’s Fortify on Demand go here: https://www.fortify.com/products/hpfssc/hpfod/index.html]]></description>
			<content:encoded><![CDATA[<p>Software security testing in the Cloud can help ISVs (Independent Software Vendors) or organizations assess their applications robustness without requiring them to invest in costly solutions and excessive time! HP Fortify on Demand is a Security-as-a-Service (SaaS) testing solution that allows any organization to test the security of software quickly, accurately, affordably, and without any software to install or manage. This automated on-demand service helps organizations with two key challenges:</p>
<ol>
<li>Ensuring the security of applications licensed from third parties</li>
<li>Increasing the speed and efficiency of building security into a development lifecycle</li>
</ol>
<p>HP Fortify on Demand tests the security of in-house or third-party applications in three steps, allowing customers to login and upload their applications, the system performs comprehensive testing and finally, the results are issued and sent to customers. HP Fortify on Demand helps users achieve their software security assessment objectives by providing a robust application-testing environment.</p>
<p>For more information about HP’s Fortify on Demand go here:<br />
<a href="https://www.fortify.com/products/hpfssc/hpfod/index.html">https://www.fortify.com/products/hpfssc/hpfod/index.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itinfomag.com/security-governance/security-as-a-service-from-hp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 1.809 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-05 20:53:23 -->

