<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Veracode Security Blog: Application security research, security trends and opinions &#187; 2008 &#187; September</title>
	<atom:link href="http://www.veracode.com/blog/2008/09/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Wed, 16 May 2012 18:18:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>(ISC)2&#8242;s Newest Cash Cow: The CSSLP Certification</title>
		<link>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/</link>
		<comments>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/#comments</comments>
		<pubDate>Mon, 29 Sep 2008 15:08:38 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cissp]]></category>
		<category><![CDATA[csslp]]></category>
		<category><![CDATA[isc2]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=321</guid>
		<description><![CDATA[Last week, during the OWASP AppSec 2008 Conference, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the Certified Software Security Lifecycle Professional (CSSLP). In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the Executive Director of (ISC)2 outlined this new certification designed to appeal to [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8242;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/web-security">Web Security</a><br />
<a href="http://www.veracode.com/security/vulnerability-assessment-software">Vulnerability Assessment</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Analysis</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis Tool</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/">Application Security</a></div>
<p></p>
<h5 style="margin-bottom: 10px">Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/ldap-injection">LDAP Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection</a><br />
<a href="http://www.veracode.com/security/xss">XSS</a><br />
<a href="http://www.veracode.com/security/csrf">CSRF</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>Learning From Sarah Palin&#8217;s Yahoo Mail Compromise</title>
		<link>http://www.veracode.com/blog/2008/09/learning-from-sarah-palin-yahoo-email-compromise/</link>
		<comments>http://www.veracode.com/blog/2008/09/learning-from-sarah-palin-yahoo-email-compromise/#comments</comments>
		<pubDate>Thu, 18 Sep 2008 13:31:56 +0000</pubDate>
		<dc:creator>Chris Wysopal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=303</guid>
		<description><![CDATA[The password reset functionality of any online service is a major source of risk. They are especially problematic when they use only a &#8220;secret question&#8221; concerning personal information only and don&#8217;t tie back to another email account or a text message. Another account or cell phone number is something &#8220;out of band&#8221; from a direct [...]]]></description>
			<content:encoded><![CDATA[<p><strong>The password reset functionality of any online service is a major source of risk</strong>.  They are especially problematic when they use only a &#8220;secret question&#8221; concerning personal information only and don&#8217;t tie back to another email account or a text message.  Another account or cell phone number is something &#8220;out of band&#8221; from a direct transaction with the online service.  It becomes 2-factor authentication.</p>
<p>When an alternate email account or cell phone number is not tied to an account, online services often use personal information, supposedly only known by the account holder, to verify identity and reset a password. The risk here is the personal information is often known to other individuals and if the account holder is a public figure then the information may be easily researched.  <strong>Birthdays, names of pets, locations of homes, schools, and events can often be discovered online or guessed.</strong> </p>
<p><a href="http://www.theregister.co.uk/2005/02/21/paris_hacked/">Paris Hilton&#8217;s T-Mobile account</a>, and thus all her Sidekick cell phone contents which were mirrored online, was compromised when someone &#8220;guessed&#8221; the answer to her secret question.  The secret questions was, &#8220;What is your pet&#8217;s name.&#8221; The answer of course was, &#8220;Tinkerbell&#8221;.  Something easily researched.  Many people would not have their pets name online but friends, family memebers, or perhaps an ex would know the answer.  Using a pet&#8217;s name is a very bad security practice.</p>
<p>Now we have Sarah Palin, another public figure, having her online account compromised because someone <a href="http://michellemalkin.com/2008/09/17/the-story-behind-the-palin-e-mail-hacking/">used the password reset functionality and guessed the answer to Sarah Palin&#8217;s secret question</a>. This is how the attacker says he found out her personal information and guessed the answer to her secret question. He detials this on 4chan.org</p>
<blockquote><p><em>rubico 09/17/08(Wed)12:57:22 No.85782652 </em></p>
<p><em>Hello, /b/ as many of you might already know, last night sarah palin’s yahoo was “hacked” and caps were posted on /b/, i am the lurker who did it, and i would like to tell the story.</em></p>
<p><em>In the past couple days news had come to light about palin using a yahoo mail account, it was in news stories and such, a thread was started full of newfags trying to do something that would not get this off the ground, for the next 2 hours the acct was locked from password recovery presumably from all this bullshit spamming.</em></p>
<p><em>after the password recovery was reenabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!)</em></p>
<p><em>the second was somewhat harder, the question was “where did you meet your spouse?” did some research, and apparently she had eloped with mister palin after college, if youll look on some of the screenshits that I took and other fellow anon have so graciously put on photobucket you will see the google search for “palin eloped” or some such in one of the tabs.</em></p>
<p><em>I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on “Wasilla high” I promptly changed the password to popcorn and took a cold shower…</em></p></blockquote>
<p><strong>Best practices for setting up the password reset functionality of any online service:</strong></p>
<ol>
<li>Tie an account to another email account or cell phone number if that is an option. This will cause the service to send an out of band message and in essence make the password reset a 2-factor authentication.</li>
<li>Do not use any personal information that can be guessed as the answers to secret questions. Treat these answers like passwords. Don&#8217;t use dictionary words. Add some numbers or symbols to the answer. For example is Sarah Palin had used &#8220;Wasilla high 1964&#8243; or &#8220;!Wasilla high!&#8221; it is far less likely it would be guessed.  Pick a scheme to modify your secret answers so they aren&#8217;t guessable.</li>
<li>Try resetting your password.  See if there are downgrade attacks which make it easier to reset the password.  Yahoo for instance will allow you to specify that you don&#8217;t have access to the email address tied to your account and thus not send a password reset email.  Since an attacker can do this the safety of using another account is eliminated thus making the answers to the secret question all that more important.</li>
<p>
</ol>
<p><b>Update 9/18/2008 2:44pm EST:</b></p>
<p>Google has a much more secure password reset function.  The following is from the Google password reset page:</p>
<blockquote><p>
To initiate the password reset process, please follow the instructions sent to your secondary email address.</p>
<p>If you don&#8217;t have a secondary email address, or if you no longer have access to that account, please try the &#8216;Forgot your password?&#8217; link again after five days. At that point, you&#8217;ll be able to reset your password by answering the security question you provided when you created your account.</p>
<p>To prevent someone from trying to break into an account you&#8217;re actively using, the security question is only used for account recovery after an account has been idle for five days. The Gmail team cannot waive the five day requirement or access your password under any circumstances.</p>
<p>If you&#8217;re unable to answer your security question or access your secondary email account, we regret that the Gmail team cannot provide further assistance. If you&#8217;re concerned about the security of your account, please visit our Security Center.
</p></blockquote>
<p>This makes it quite difficult to change the password if you are not the account owner even if you know the answer to the secret question.  Nice going Google!</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis Tool</a><br />
<a href="http://www.veracode.com/security/penetration-testing">Penetration Testing Tool</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/vulnerability-scanning">Vulnerability Scanning</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Testing</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/source-code-security-analyzer">Source Code Security Analyzer</a><br />
<a href="http://www.veracode.com/security/code-security">Software Code Security</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing Tool</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-review">Code Review Tools</a></div>
<h5>Veracode Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/sql-injection">Prevention of SQL Injection</a><br />
<a href="http://www.veracode.com/security/xss">Cross Site Scripting Vulnerabilities</a><br />
<a href="http://www.veracode.com/security/csrf">CSRF Attacks</a><br />
<a href="http://www.veracode.com/security/ldap-injection">LDAP Injection</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Code Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/learning-from-sarah-palin-yahoo-email-compromise/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Speculation on Palin E-mail Hack</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/</link>
		<comments>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 18:12:08 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[palin]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282</guid>
		<description><![CDATA[Assuming the mailbox hack is not an elaborate ruse, how did they do it? Almost as bad as the Sprint PCS password reset fiasco that made the news in April, here is the Yahoo Mail password reset screen: As you can see, you need to know the user&#8217;s birthday, country of residence, and postal code. [...]]]></description>
			<content:encoded><![CDATA[<p>Assuming <a href="http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/">the mailbox hack</a> is not an elaborate ruse, how did they do it?</p>
<p>Almost as bad as the <a href="http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked">Sprint PCS password reset fiasco</a> that made the news in April, here is the Yahoo Mail password reset screen:</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset.gif"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset-300x178.gif" alt="" title="yahooreset" width="300" height="178" class="aligncenter size-medium wp-image-283 photoborder" /></center></a></p>
<p>As you can see, you need to know the user&#8217;s birthday, country of residence, and postal code.  Not difficult information to dig up in Palin&#8217;s case, <a href="http://wikileaks.org/leak/sarah-palin-hack-2008/email-account-info.txt">as shown here</a>.  After you enter this information correctly, you are asked to type in the alternate e-mail address that&#8217;s associated with the account.  But they give you hints &#8212; so if your alternate e-mail was sarah@alaska.gov, they would show you s****@a*****.gov.</p>
<p>Assuming you guess the alternate e-mail correctly, Yahoo mails a password reset link to that address.  So it&#8217;s likely that the attacker may have also had to gain access to her alternate e-mail account.  Either that, or they exploited a vulnerability in the Yahoo password reset mechanism itself, which seems less likely but not implausible.</p>
<p>So Yahoo itself probably didn&#8217;t get hacked, per se, even though there will probably be a lot of FUD in the media about that.</p>
<p><b>Update 08/18/2008 1:00am EST:</b> </p>
<p>Just found this writeup describing how it transpired: <a href="http://pastebin.com/f7fb944c5">http://pastebin.com/f7fb944c5</a>.    Again, not vouching for the authenticity but it does seem plausible, and it&#8217;s consistent with my password reset theory.  I guess my Yahoo account doesn&#8217;t have a secret question defined so I wasn&#8217;t presented that option when I tested the reset mechanism earlier today.</p>
<p>Just for fun, here&#8217;s the list of non-customizable secret questions Yahoo lets you pick from, as of tonight:</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset2.gif"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset2-300x118.gif" alt="" title="yahooreset2" width="300" height="118" class="aligncenter size-medium wp-image-294 photoborder" /></center></a></p>
<p>And they sure don&#8217;t make it easy for you to <a href="http://help.yahoo.com/l/us/yahoo/acct/info/sqachange.html">update your secret question</a>, do they?  (must be logged in to Yahoo for that link to work)</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing Tool</a><br />
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis</a><br />
<a href="http://www.veracode.com/security/penetration-testing">Penetration Testing</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/vulnerability-scanning">Vulnerability Scanning Tools</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/source-code-security-analyzer">Source Code Security Analyzer</a><br />
<a href="http://www.veracode.com/security/code-security">Software Code Security</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-review">Code Review</a></div>
<h5>Veracode Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Vulnerabilities</a><br />
<a href="http://www.veracode.com/security/xss">Cross Site Scripting</a><br />
<a href="http://www.veracode.com/security/csrf">Cross Site Request Forgery</a><br />
<a href="http://www.veracode.com/security/ldap-injection">LDAP Injection</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Code Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Sarah Palin&#8217;s Yahoo Mailbox Compromised</title>
		<link>http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/</link>
		<comments>http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 15:57:33 +0000</pubDate>
		<dc:creator>Chris Wysopal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[palin]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=277</guid>
		<description><![CDATA[A group of individuals has compromised VP candidate Sarah Palin&#8217;s personal email and sent the information to Wikileaks which has posted the information publicly. http://wikileaks.org/wiki/Sarah_Palin_Yahoo_email_hack_2008 Alternate link (wikilieaks is down): http://cryptome.org/palin-email.zip Circa midnight Tuesday the 16th of September (EST) Wikileaks&#8217; sources loosely affiliated with the activist group &#8216;anonymous&#8217; gained access to U.S. Republican Party Vice-presidential [...]]]></description>
			<content:encoded><![CDATA[<p>A group of individuals has compromised VP candidate Sarah Palin&#8217;s personal email and sent the information to Wikileaks which has posted the information publicly.</p>
<p><a href="http://wikileaks.org/wiki/Sarah_Palin_Yahoo_email_hack_2008">http://wikileaks.org/wiki/Sarah_Palin_Yahoo_email_hack_2008</a></p>
<p>Alternate link (wikilieaks is down): <a href="http://cryptome.org/palin-email.zip">http://cryptome.org/palin-email.zip</a></p>
<blockquote><p>Circa midnight Tuesday the 16th of September (EST) Wikileaks&#8217; sources loosely affiliated with the activist group &#8216;anonymous&#8217; gained access to U.S. Republican Party Vice-presidential candidate Sarah Palin&#8217;s Yahoo email account <em>gov.palin@yahoo.com</em>. Governor Palin has come under criticism for using private email accounts to avoid government transparency mechanisms. The zip archive made available by Wikileaks contains screen shots of Palin&#8217;s inbox, example emails, address book and two family photos. The list of correspondence, together with the account name, appears to re-enforce the criticism.</p></blockquote>
<p>Internet security has finally become an issue in presidential politics.</p>
<p>Palin&#8217;s use of a Yahoo account has been the subject of <a href="http://seattletimes.nwsource.com/html/nationworld/2008180084_palinemail15.html">recent newspaper articles</a>. The Washington Post <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/09/AR2008090903044.html">published her Yahoo email address</a>, which was likely a precursor to the attack.</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis Tool</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/security/web-security">Web Security</a><br />
<a href="http://www.veracode.com/security/vulnerability-assessment-software">Vulnerability Assessment</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Analysis</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/">Application Security</a></div>
<p></p>
<h5 style="margin-bottom: 10px">Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/sql-injection">SQL Injection</a><br />
<a href="http://www.veracode.com/security/xss">Cross Site Scripting</a><br />
<a href="http://www.veracode.com/security/csrf">CSRF</a><br />
<a href="http://www.veracode.com/security/ldap-injection">LDAP Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Distributing Malware Through Trusted Websites</title>
		<link>http://www.veracode.com/blog/2008/09/distributing-malware-through-trusted-websites/</link>
		<comments>http://www.veracode.com/blog/2008/09/distributing-malware-through-trusted-websites/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 20:14:01 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[business week]]></category>
		<category><![CDATA[noscript]]></category>
		<category><![CDATA[trusted]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=271</guid>
		<description><![CDATA[Why bother setting up dedicated websites to host malicious content when you can just infect trusted sites like BusinessWeek? This is becoming something of a trend, as evidenced by the mass SQL Injection attacks from a few months ago. The idea is simple &#8212; find SQL Injection vulnerabilities in high-traffic, trusted websites where the site&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Why bother setting up dedicated websites to host malicious content when you can just <a href="http://www.net-security.org/malware_news.php?id=990">infect trusted sites like BusinessWeek</a>?  This is becoming something of a trend, as evidenced by the <a href="http://hackademix.net/2008/04/26/mass-attack-faq/">mass SQL Injection</a> attacks from a few months ago.</p>
<p>The idea is simple &#8212; find SQL Injection vulnerabilities in high-traffic, trusted websites where the site&#8217;s content is dynamically fetched from a database (i.e. just about any content-rich site).  Then use an automated tool to prepend or append malicious content to that content in the database.  When the unsuspecting user visits the page to read an article, they will be treated to a barrage of &lt;script&gt; or other tags fetching content from sites in .ru, .cn, or who knows where else.</p>
<p>The guidance you give to mom and dad, &#8220;don&#8217;t visit sketchy looking sites in other countries,&#8221; is no longer good enough.  If BusinessWeek can be compromised, it&#8217;s a given that USA Today, CNN, the New York Times, and other establishments are being targeted as well.</p>
<p>For this and similar examples, <a href="http://noscript.net/">NoScript</a> would have thwarted the attack because it wouldn&#8217;t permit the .js file to be loaded from an off-domain location.  But what happens when the attackers start injecting the entire .js payload into the database instead of just a &lt;script&gt; tag?  Now the malicious code is coming from the trusted domain, and if I&#8217;ve configured NoScript to allow scripts from businessweek.com, I&#8217;m out of luck.  In fact, I have no idea why the attackers aren&#8217;t using this tactic already.  Any ideas?</p>
<p>&nbsp;</p>
<h3>FREE Security Tutorials from Veracode</h3>
<p><a href="http://www.veracode.com/security/cyber-security">Cyber Security Threats</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Phone Security</a><br />
<a href="http://www.veracode.com/security/flash-security">Flash Player Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Attack</a><br />
<a href="http://www.veracode.com/security/crlf-injection">CRLF Injection</a><br />
&nbsp;</p>
<h3>Veracode Security Solutions</h3>
<p><a href="http://www.veracode.com/security/software-security-testing">Software Security Testing</a><br />
<a href="http://www.veracode.com/security/binary-code-analysis">Binary Code Analysis</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing</a><br />
&nbsp;</p>
<h3>Veracode Data Security Resources</h3>
<p><a href="http://www.veracode.com/security/data-breach">Data Breaches</a><br />
<a href="http://www.veracode.com/security/data-loss-prevention">Data Loss Prevention</a><br />
<a href="http://www.veracode.com/security/data-security">Data Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/distributing-malware-through-trusted-websites/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

