<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Veracode Security Blog: Application security research, security trends and opinions &#187; Miscellaneous</title>
	<atom:link href="http://www.veracode.com/blog/category/miscellaneous/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Fri, 18 May 2012 16:17:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Thought Leader&#8230; One Year Later</title>
		<link>http://www.veracode.com/blog/2011/12/the-thought-leader-one-year-later/</link>
		<comments>http://www.veracode.com/blog/2011/12/the-thought-leader-one-year-later/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 14:00:47 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=2836</guid>
		<description><![CDATA[When we last left our intrepid hero, he was embarking on an quest to become an information security thought leader. A year has passed; let&#8217;s see how he&#8217;s doing! Enjoy.]]></description>
			<content:encoded><![CDATA[<p>When we last left our intrepid hero, he was embarking on an quest to <a href="http://www.veracode.com/blog/2010/12/how-to-become-an-information-security-thought-leader/">become an information security thought leader</a>. A year has passed; let&#8217;s see how he&#8217;s doing!  Enjoy.</p>
<p><center><iframe id="xtranormal_Thought leadership, part 2" name="xtranormal_Thought leadership, part 2" style="width:480px;height:299px;" src="http://www.xtranormal.com/xtraplayr/12849060/thought-leadership-part-2" marginwidth="0" marginheight="0" border="0" frameborder="0" scrolling="auto"></iframe></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2011/12/the-thought-leader-one-year-later/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to Become an Information Security Thought Leader</title>
		<link>http://www.veracode.com/blog/2010/12/how-to-become-an-information-security-thought-leader/</link>
		<comments>http://www.veracode.com/blog/2010/12/how-to-become-an-information-security-thought-leader/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:19:36 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[ALL THINGS SECURITY]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=1332</guid>
		<description><![CDATA[I created this video for an internal Veracode video contest. It&#8217;s intended to poke fun at the abundance of &#8220;thought leaders&#8221; we have in our industry. I shared it on Twitter yesterday but thought I would post here on the blog as well. A handful of people have asked if it&#8217;s meant to satirize any [...]]]></description>
			<content:encoded><![CDATA[<p>I created this video for an internal Veracode video contest.  It&#8217;s intended to poke fun at the abundance of &#8220;thought leaders&#8221; we have in our industry.  I shared it on Twitter yesterday but thought I would post here on the blog as well.  A handful of people have asked if it&#8217;s meant to satirize any particular person &#8212; sorry to disappoint, it&#8217;s just a composite.  Enjoy!</p>
<p><center><br />
<object width="480" height="390"><param name="movie" value="http://www.xtranormal.com/site_media/players/jwplayer.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><param name="flashvars"value="height=390&#038;width=480&#038;file=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.mp4&#038;image=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.jpg&#038;link=http://www.xtranormal.com/watch/7897173&#038;searchbar=false&#038;autostart=false"/><embed src="http://www.xtranormal.com/site_media/players/jwplayer.swf" width="480" height="390" allowscriptaccess="always" allowfullscreen="true" flashvars="height=390&#038;width=480&#038;file=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.mp4&#038;image=http://newvideos.xtranormal.com/web_final_lo/4181e632-fdbd-11df-a437-003048d69c21_3.jpg&#038;link=http://www.xtranormal.com/watch/7897173&#038;searchbar=false&#038;autostart=false"></embed></object><object width="480" height="390"><param name="movie" value="http://www.xtranormal.com/site_media/players/embedded-xnl-stats.swf"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.xtranormal.com/site_media/players/embedded-xnl-stats.swf" width="1" height="1" allowscriptaccess="always"></embed></object><br />
</center></p>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2010/12/how-to-become-an-information-security-thought-leader/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>SOURCE Boston Conference Was a Blast</title>
		<link>http://www.veracode.com/blog/2009/03/source-boston-conference-was-a-blast/</link>
		<comments>http://www.veracode.com/blog/2009/03/source-boston-conference-was-a-blast/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 22:46:18 +0000</pubDate>
		<dc:creator>Chris Wysopal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=707</guid>
		<description><![CDATA[I had a great time at the SOURCE Boston conference last week. Veracode was a sponsor and a few Veracoders participated as advisory members or volunteers. I had the pleasure, along with Chris Eng, of presiding over the application security track. I think all the talks were of high quality but still a few stood [...]]]></description>
			<content:encoded><![CDATA[<p>I had a great time at the SOURCE Boston conference last week.  Veracode was a sponsor and a few Veracoders participated as advisory members or volunteers.  I had the pleasure, along with Chris Eng, of presiding over the application security track.  I think all the talks were of high quality but still a few stood out for me:  </p>
<p>Dino Dai Zovi on Mac OS Xploitation.  Dino showed how to exploit a quicktime heap overflow.  He got the built in iSight camera to take a picture of his victim and send it to him just by clicking on a malicious quicktime movie file.  He talked about how exploiting OS X is 1999 all over again because of the lack of ASLR and stack canary protection.  He said hacking Windows and Linux is a chore, but OS X is still fun.</p>
<p>Chris Gates and Vince Marvelli on Attacking Layer 8: Client Side Penetration Testing.  Client side attacks are on the rise and now the corporate attack of choice yet we don&#8217;t pen test for them.  What&#8217;s up with that?  The video for this one is already available online at <a href="http://vimeo.com/channels/fullscopesecurity">Vimeo</a>. </p>
<p>Val Smith on Dissecting Foreign Web Attacks.  Val unwound one of the popular attacks of our time: compromising web sites to install malicious code that owns the browser and then installs a bot.  We all understand it is possible but it is great to see all the tricks of the trade.  It is pretty clear that the source of this one was China.</p>
<p>Chris Hoff on The Frogs Who Desired A King: A Virtualization and Cloud Computing Security Fable Set To Interpretive Dance.  This talk is being touted as the best ever.  Unfortunately I missed it.  Can&#8217;t wait to see the video.</p>
<p>The videos for all the SOURCE talks should be on-line over the next few weeks.  Check <a href="http://www.sourceconference.com">www.sourceconference.com</a></p>
<p>There are some other reviews of the conference out there that will help you decide which videos are worth watching:</p>
<ul>
<li><a href="http://g0ne.wordpress.com/2009/03/15/thoughts-on-source-boston/">Thoughts On Source Boston</a></li>
<li><a href="http://blog.decurity.com/index.php/dec_template/more/review_sourceboston_2009/">Review Source Boston 2009</a></li>
<li><a href="http://www.rationalsurvivability.com/blog/?p=8">Comments on Chris Hoff&#8217;s talk</a></li>
</ul>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/security/web-security">Website Security</a><br />
<a href="http://www.veracode.com/security/vulnerability-assessment-software">Vulnerability Assessment</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Analysis</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/">Application Security</a></div>
<p></p>
<h5 style="margin-bottom: 10px">Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/csrf">CSRF</a><br />
<a href="http://www.veracode.com/security/ldap-injection">LDAP Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection</a><br />
<a href="http://www.veracode.com/security/xss">Cross Site Scripting Vulnerabilities</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2009/03/source-boston-conference-was-a-blast/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New To The Team &#8211; Old To The Game</title>
		<link>http://www.veracode.com/blog/2008/10/new-to-the-team-old-to-the-game/</link>
		<comments>http://www.veracode.com/blog/2008/10/new-to-the-team-old-to-the-game/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 13:57:48 +0000</pubDate>
		<dc:creator>Tyler Shields</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Add new tag]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=406</guid>
		<description><![CDATA[Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself! I may be new to the team, but I&#8217;m (reasonably) old to the game. My name is Tyler Shields and I&#8217;m the latest addition to the Veracode research team. I started at Veracode in September 2008 as a [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself!</p>
<p>I may be new to the team, but I&#8217;m (reasonably) old to the game. My name is Tyler Shields and I&#8217;m the latest addition to the Veracode research team. I started at Veracode in September 2008 as a Senior Security Researcher and have been immediately thrown into the fire. Working for a fast paced, highly energetic company like Veracode, keeps you busy and challenges you every day. I plan to blog on the most interesting pieces of my work with Veracode and hope that you find it enlightening or at the very least entertaining.</p>
<p>In the past I have worked as the security engineer at a .com startup, as an incident response and forensics specialist for the United States Postal Service (think HUGE network), and most recently as a security consultant for @stake and Symantec. I have consulted on engagements for Fortune 500 companies, most major financial institutions, and the highest levels of the United States government. As a consultant my focus was on anything related to application security including, application penetration assessments, product security assessments, secure development lifecycle consulting, and secure application architecture engagements. I lead the @stake/Symantec Application Security Center of Excellence that was used to help guide the knowledge of the global consulting team.  I also spent time as the lead for the Symantec Vulnerability Research program in which a number of interesting vulnerabilities were discovered and publicly released. In my spare time I enjoy reverse engineering and malware research. I recently completed my graduate degree in Information Security/Computer Science from James Madison University in Virginia.</p>
<p>So&#8230; Here&#8217;s to a new job, a new blog poster, and of course lots of fun to come.</p>
<p>&nbsp;</p>
<h3>FREE Security Tutorials from Veracode</h3>
<p><a href="http://www.veracode.com/security/flash-security">Flash Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Attack</a><br />
<a href="http://www.veracode.com/security/cyber-security">Cyber Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Phone Security</a><br />
<a href="http://www.veracode.com/security/crlf-injection">CRLF Injection</a><br />
&nbsp;</p>
<h3>Veracode Security Solutions</h3>
<p><a href="http://www.veracode.com/security/binary-code-analysis">Binary Analysis</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing Tool</a><br />
<a href="http://www.veracode.com/security/software-security-testing">Software Security</a><br />
&nbsp;</p>
<h3>Veracode Data Security Resources</h3>
<p><a href="http://www.veracode.com/security/data-loss-prevention">Data Loss</a><br />
<a href="http://www.veracode.com/security/data-security">Data Security</a><br />
<a href="http://www.veracode.com/security/data-breach">Data Breach</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/10/new-to-the-team-old-to-the-game/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>(ISC)2&#8242;s Newest Cash Cow: The CSSLP Certification</title>
		<link>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/</link>
		<comments>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/#comments</comments>
		<pubDate>Mon, 29 Sep 2008 15:08:38 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[cissp]]></category>
		<category><![CDATA[csslp]]></category>
		<category><![CDATA[isc2]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=321</guid>
		<description><![CDATA[Last week, during the OWASP AppSec 2008 Conference, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the Certified Software Security Lifecycle Professional (CSSLP). In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the Executive Director of (ISC)2 outlined this new certification designed to appeal to [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8242;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/web-security">Web Security</a><br />
<a href="http://www.veracode.com/security/vulnerability-assessment-software">Vulnerability Assessment</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Analysis</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis Tool</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/">Application Security</a></div>
<p></p>
<h5 style="margin-bottom: 10px">Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/ldap-injection">LDAP Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection</a><br />
<a href="http://www.veracode.com/security/xss">XSS</a><br />
<a href="http://www.veracode.com/security/csrf">CSRF</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>Speculation on Palin E-mail Hack</title>
		<link>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/</link>
		<comments>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 18:12:08 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[palin]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=282</guid>
		<description><![CDATA[Assuming the mailbox hack is not an elaborate ruse, how did they do it? Almost as bad as the Sprint PCS password reset fiasco that made the news in April, here is the Yahoo Mail password reset screen: As you can see, you need to know the user&#8217;s birthday, country of residence, and postal code. [...]]]></description>
			<content:encoded><![CDATA[<p>Assuming <a href="http://www.veracode.com/blog/2008/09/sarah-palins-yahoo-mailbox-compromised/">the mailbox hack</a> is not an elaborate ruse, how did they do it?</p>
<p>Almost as bad as the <a href="http://consumerist.com/376845/flawed-security-lets-sprint-accounts-get-easily-hijacked">Sprint PCS password reset fiasco</a> that made the news in April, here is the Yahoo Mail password reset screen:</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset.gif"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset-300x178.gif" alt="" title="yahooreset" width="300" height="178" class="aligncenter size-medium wp-image-283 photoborder" /></center></a></p>
<p>As you can see, you need to know the user&#8217;s birthday, country of residence, and postal code.  Not difficult information to dig up in Palin&#8217;s case, <a href="http://wikileaks.org/leak/sarah-palin-hack-2008/email-account-info.txt">as shown here</a>.  After you enter this information correctly, you are asked to type in the alternate e-mail address that&#8217;s associated with the account.  But they give you hints &#8212; so if your alternate e-mail was sarah@alaska.gov, they would show you s****@a*****.gov.</p>
<p>Assuming you guess the alternate e-mail correctly, Yahoo mails a password reset link to that address.  So it&#8217;s likely that the attacker may have also had to gain access to her alternate e-mail account.  Either that, or they exploited a vulnerability in the Yahoo password reset mechanism itself, which seems less likely but not implausible.</p>
<p>So Yahoo itself probably didn&#8217;t get hacked, per se, even though there will probably be a lot of FUD in the media about that.</p>
<p><b>Update 08/18/2008 1:00am EST:</b> </p>
<p>Just found this writeup describing how it transpired: <a href="http://pastebin.com/f7fb944c5">http://pastebin.com/f7fb944c5</a>.    Again, not vouching for the authenticity but it does seem plausible, and it&#8217;s consistent with my password reset theory.  I guess my Yahoo account doesn&#8217;t have a secret question defined so I wasn&#8217;t presented that option when I tested the reset mechanism earlier today.</p>
<p>Just for fun, here&#8217;s the list of non-customizable secret questions Yahoo lets you pick from, as of tonight:</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset2.gif"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/yahooreset2-300x118.gif" alt="" title="yahooreset2" width="300" height="118" class="aligncenter size-medium wp-image-294 photoborder" /></center></a></p>
<p>And they sure don&#8217;t make it easy for you to <a href="http://help.yahoo.com/l/us/yahoo/acct/info/sqachange.html">update your secret question</a>, do they?  (must be logged in to Yahoo for that link to work)</p>
<h5>Veracode Security Solutions</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing Tool</a><br />
<a href="http://www.veracode.com/security/static-analysis-tool">Static Analysis</a><br />
<a href="http://www.veracode.com/security/penetration-testing">Penetration Testing</a><br />
<a href="http://www.veracode.com/security/static-code-analysis">Static Code Analysis</a><br />
<a href="http://www.veracode.com/security/vulnerability-scanning">Vulnerability Scanning Tools</a><br />
<a href="http://www.veracode.com/security/web-application-security-testing">Web Application Security</a><br />
<a href="http://www.veracode.com/security/software-testing-tools">Software Testing Tools</a><br />
<a href="http://www.veracode.com/security/source-code-security-analyzer">Source Code Security Analyzer</a><br />
<a href="http://www.veracode.com/security/code-security">Software Code Security</a><br />
<a href="http://www.veracode.com/security/code-analysis">Source Code Analysis</a><br />
<a href="http://www.veracode.com/security/code-review">Code Review</a></div>
<h5>Veracode Security Threat Guides</h5>
<div style="margin-left:15px;">
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Vulnerabilities</a><br />
<a href="http://www.veracode.com/security/xss">Cross Site Scripting</a><br />
<a href="http://www.veracode.com/security/csrf">Cross Site Request Forgery</a><br />
<a href="http://www.veracode.com/security/ldap-injection">LDAP Injection</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Code Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/09/speculation-on-palin-e-mail-hack/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>MBTA Hacking Injunction Lifted</title>
		<link>http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/</link>
		<comments>http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 05:49:55 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[ciscogate]]></category>
		<category><![CDATA[eff]]></category>
		<category><![CDATA[injunction]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[mbta]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=248</guid>
		<description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at DEFCON 16. In summary: The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the <a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
<p>&nbsp;</p>
<h3>FREE Security Tutorials from Veracode</h3>
<p><a href="http://www.veracode.com/security/flash-security">Flash Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Attack</a><br />
<a href="http://www.veracode.com/security/cyber-security">Cyber Security</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Phone Security</a><br />
<a href="http://www.veracode.com/security/crlf-injection">CRLF Injection</a><br />
&nbsp;</p>
<h3>Veracode Security Solutions</h3>
<p><a href="http://www.veracode.com/security/binary-code-analysis">Binary Analysis</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing Tool</a><br />
<a href="http://www.veracode.com/security/software-security-testing">Software Security</a><br />
&nbsp;</p>
<h3>Veracode Data Security Resources</h3>
<p><a href="http://www.veracode.com/security/data-loss-prevention">Data Loss</a><br />
<a href="http://www.veracode.com/security/data-security">Data Security</a><br />
<a href="http://www.veracode.com/security/data-breach">Data Breach</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>BlackHat Recap</title>
		<link>http://www.veracode.com/blog/2008/08/blackhat-recap/</link>
		<comments>http://www.veracode.com/blog/2008/08/blackhat-recap/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 22:43:18 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Binary Analysis]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[Software Development]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[recap]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=202</guid>
		<description><![CDATA[Another BlackHat has come and gone. As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations. I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the Security Twits and others in the [...]]]></description>
			<content:encoded><![CDATA[<p>Another BlackHat has come and gone.  As usual, it was a very busy week juggling customer meetings, recruiting, conference planning, vendor parties, and, oh yes, the actual BlackHat presentations.  I had a fantastic time catching up with old friends and finally getting the opportunity to meet more of the <a href="http://n0where.org/security-twits/">Security Twits</a> and others in the security community.  I didn&#8217;t submit a talk this year, but nevertheless, <a href="http://flickr.com/photos/fakedankaminsky/">fake Dan Kaminsky</a> was still excited to see me.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b.jpg"><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/08/chris_2742966251_1b47297b33_b-300x225.jpg" alt="" title="chris_2742966251_1b47297b33_b" width="300" height="225" class="aligncenter size-medium wp-image-215 photoborder" /></center></a></p>
<p>My favorite talk, as expected, was the Sotirov/Dowd talk on <a href="http://taossa.com/archive/bh08sotirovdowd.pdf">How To Impress Girls With Browser Memory Protection Bypasses</a>.  The attack is a conceptually simple, yet completely reliable technique for exploiting vulnerabilities in web browsers.  Of course, the media has <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324395,00.html">sensationalized</a> the impact of their findings, but ultimately, this is still significant as far as browser-based exploits are concerned (here is a <a href="http://blogs.zdnet.com/Bott/?p=513">more accurate report</a>).  It&#8217;s worth mentioning that part of the technique allowing them to load a .NET DLL at an arbitrary location under Vista was reliant on an implementation bug wherein the OS disables ASLR if the version in the .NET COR header was below a certain value.  However, the address space spraying and stack spraying techniques are likely to be extended to other platforms utilizing similar memory protection mechanisms.  </p>
<p>As for the girls?  I can report first-hand that the ladies at TAO on Wednesday night were hanging on <a href="http://twitter.com/alexsotirov">Alex</a>&#8216;s every word.  They were particularly impressed when he whipped out the laptop for a live demo.  Unfortunately, none of the dozen iPhone owners in the immediate vicinity thought to snap a picture (too busy Twittering).  Oh well.  </p>
<p>I also enjoyed Hovav Shacham&#8217;s talk on return-oriented programming.  Simply put, he described a generalization of the return-to-libc shellcode approach with the intent to demonstrate that one could achieve Turing-complete computation using &#8220;found code&#8221; in process images.  By chaining together series of mini-computations ending in return (RET) instructions, it was possible to build higher-level programming constructs such as branches and loops.  The nature of the x86 instruction set provides some flexibility because instructions are interpreted differently depending on how you align the instruction pointer (i.e. the old shellcode trick of searching the process image for any JMP EBX instruction and using that as your EIP).  In RISC architectures such as SPARC, however, you don&#8217;t have that luxury; if your %pc isn&#8217;t aligned properly you get a bus error.  So it was quite interesting to see that they were able to extend the concept to RISC.  The practicality of the attack technique is limited by the fact that the shellcode is tuned to a particular binary image &#8212; if the shellcode was built using instructions extrapolated from glibc 2.3.5, it won&#8217;t work for a system running glibc 2.4.  </p>
<p>I thought Scott Stender&#8217;s talk on <a href="http://isecpartners.com/files/iSEC%20Partners%20-%20Concurrency%20Attacks%20in%20Web%20Applications.pdf">Concurrency Attacks in Web Applications</a> was interesting as well.  In a nutshell, spewing thousands of simultaneous requests at web application transactions that are not thread-safe can create interesting problems.  In the presentation, Scott ran his demo against a VM running on the attack machine.  I found myself wondering how effective the same attack would be over the Internet &#8212; would it be significantly less reliable (or not at all)?  Race conditions are generally easier to exploit locally than remotely due to more predictable execution conditions.  Certainly this is an under-tested vulnerability class though.</p>
<p>One presentation I wasn&#8217;t able to attend but want to follow up on is <a href="http://twitter.com/nate_mcfeters">Nate McFeters</a>, John Heasman, and Rob Carter&#8217;s talk which discussed the GIFAR attack I&#8217;ve been hearing so much about lately.  The gist is that you can create a file that is both a valid GIF and a valid JAR, then use some Java applet tricks to initiate HTTP requests on behalf of the victim.  </p>
<p>Finally, the <a href="http://pwnie-awards.org/2008/">Pwnie Awards</a> didn&#8217;t fail to disappoint.  Drama ensued over the Most Overhyped award, but at least this year some of the winners showed up to claim their awards!  <a href="http://twitter.com/halvarflake">Halvar</a> rapping Symantec lyrics was also quite memorable.</p>
<p>All in all, a fun and informative week, but as usual, I was relieved to get the hell out of Vegas and head home on Friday morning. </p>
<p>P.S. For a much more entertaining BlackHat/Defcon Recap, read <a href="http://securityuncorked.net/2008/08/anecdotes-blackhat-defcon/">Jennifer Jabbusch&#8217;s account</a> of the week&#8217;s events.  It&#8217;s my favorite one so far!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/08/blackhat-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Journalist On Journalist Hacking at BlackHat</title>
		<link>http://www.veracode.com/blog/2008/08/journalist-on-journalist-hacking-at-black-hat/</link>
		<comments>http://www.veracode.com/blog/2008/08/journalist-on-journalist-hacking-at-black-hat/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 13:10:15 +0000</pubDate>
		<dc:creator>Chris Wysopal</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=179</guid>
		<description><![CDATA[Three French journalists have been booted for life from Black Hat and Defcon for compromising the Black Hat press room wired network and grabbing the credentials for at least one reporter. Their goal was to publicize the risks to reporters especially current given the massive reporter presence in Bejing for the Olympics. This risk is [...]]]></description>
			<content:encoded><![CDATA[<p>Three French journalists have been booted for life from Black Hat and Defcon for <a href="http://news.cnet.com/8301-1009_3-10010989-83.html">compromising the Black Hat press room wired network</a> and grabbing the credentials for at least one reporter.  Their goal was to publicize the risks to reporters especially current given the massive reporter presence in Bejing for the Olympics.  This risk is certainly real and it is a shame that these journalists had to compromise and embarass one of their own and potentially run afoul of US Federal wiretap laws.</p>
<p><a href="http://packetstormsecurity.org/sniffers/antisniff/"><center><img class="alignnone size-medium wp-image-181 photoborder" title="antisniff-splash-smgif" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/antisniff-splash-smgif-300x147.jpg" alt="" width="300" height="147" /></center></a></p>
<p>Sniffing, or monitoring all traffic on a network, is so 1999.  That is when <a href="http://www.lopht.com">L0pht</a> came out with <a href="http://windowsitpro.com/article/articleid/7258/antisniff-beta-2.html">AntiSniff</a>, which could detect many scenarios where someone was sniffing a wired network.  How can we be using plain text authentication protocols in 2008?  It is a well known and easily solved problem. But people authenticate in clear text everyday when they log into social networking or blogs or other &#8220;unimportant&#8221; applications.  The problem is when they <a href="http://news.cnet.com/8301-1009_3-9989071-83.html">use those same credentials for work or online banking</a>.</p>
<p>We need to think of any application that alows users to authenticate in the clear as broken.  If 3 journalists can monitor passwords, anyone can.</p>
<p><strong>Update 08/08/2008 12:30pm EST:</strong></p>
<p>It turns out the attack was likely a MITM attack where the attackers ran their own DHCP server and handed out a gateway IP that was controlled by them. At least one reporter was connecting to his organization&#8217;s content management system over unencrypted HTTP and got his password compromised. More details in &#8220;<a href="http://www.eweek.com/c/a/Security/How-I-Got-Hacked-at-Black-Hat/">How eWeek Got Hacked at Black Hat</a>.&#8221;</p>
<p>&nbsp;</p>
<h3>FREE Security Tutorials from Veracode</h3>
<p><a href="http://www.veracode.com/security/cyber-security">Cyber Security Threats</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Phone Security</a><br />
<a href="http://www.veracode.com/security/flash-security">Flash Player Security</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Attack</a><br />
<a href="http://www.veracode.com/security/crlf-injection">CRLF Injection</a><br />
&nbsp;</p>
<h3>Veracode Security Solutions</h3>
<p><a href="http://www.veracode.com/security/software-security-testing">Software Security Testing</a><br />
<a href="http://www.veracode.com/security/binary-code-analysis">Binary Code Analysis</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing</a><br />
&nbsp;</p>
<h3>Veracode Data Security Resources</h3>
<p><a href="http://www.veracode.com/security/data-breach">Data Breaches</a><br />
<a href="http://www.veracode.com/security/data-loss-prevention">Data Loss Prevention</a><br />
<a href="http://www.veracode.com/security/data-security">Data Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/08/journalist-on-journalist-hacking-at-black-hat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackHat Picks, Day 2</title>
		<link>http://www.veracode.com/blog/2008/08/blackhat-picks-day-2/</link>
		<comments>http://www.veracode.com/blog/2008/08/blackhat-picks-day-2/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 17:48:24 +0000</pubDate>
		<dc:creator>Chris Eng</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[RESEARCH]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[day two]]></category>

		<guid isPermaLink="false">http://www.veracode.com/blog/?p=163</guid>
		<description><![CDATA[Here&#8217;s the rest of my list: 10:00-11:00 FX, Developments in Cisco IOS Forensics. 11:15-12:30 Oliver Friedrichs, Threats to the 2008 Presidential Election (and more). 13:45-15:00 Option 1: Scott Stender, Concurrency Attacks in Web Applications. Option 2: Travis Goodspeed, Side-channel Timing Attacks on MSP430 Microcontroller Firmware. 15:15-16:30 Option 1: Alexander Sotirov and Mark Dowd, How To [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s the rest of my list:</p>
<p><b>10:00-11:00</b> <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Lindner">FX</a>, Developments in Cisco IOS Forensics.</p>
<p><b>11:15-12:30</b> <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Friedrichs">Oliver Friedrichs</a>, Threats to the 2008 Presidential Election (and more).</p>
<p><b>13:45-15:00</b> Option 1: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Stender">Scott Stender</a>, Concurrency Attacks in Web Applications. Option 2: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Goodspeed">Travis Goodspeed</a>, Side-channel Timing Attacks on MSP430 Microcontroller Firmware.  </p>
<p><b>15:15-16:30</b> Option 1: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Sotirov">Alexander Sotirov and Mark Dowd</a>, How To Impress Girls With Browser Memory Protection Bypasses.  Option 2: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Nohl">Karsten Nohl</a>, Mifare &#8211; Little Security, Despite Obscurity.  This is one of the toughest time slots as you also have McFeters/Carter/Heasman and Grossman/Evans in the lineup.  Choices, choices.</p>
<p><b>16:45-18:00</b> Option 1: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Dang">Bruce Dang</a>, Methods for Understanding Targeted Attacks with Office Documents.  Option 2: <a href="http://blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Tarnovsky">Christopher Tarnovsky</a>, Inducing Momentary Faults Within Secure Smartcards/Microcontrollers.</p>
<p>Lots of intriguing hardware talks on Day 2.  A lot of it is probably over my head and my first options are more applicable to my day job.  There might have to be some room hopping.</p>
<p>I fly out to Vegas tonight &#8212; see you all there!</p>
<p>&nbsp;</p>
<h3>FREE Security Tutorials from Veracode</h3>
<p><a href="http://www.veracode.com/security/flash-security">Flash Security Settings</a><br />
<a href="http://www.veracode.com/security/sql-injection">SQL Injection Tutorial</a><br />
<a href="http://www.veracode.com/security/cyber-security">Cyber Threats</a><br />
<a href="http://www.veracode.com/security/mobile-code-security">Mobile Security Threats</a><br />
<a href="http://www.veracode.com/security/crlf-injection">CRLF Injection</a><br />
&nbsp;</p>
<h3>Veracode Security Solutions</h3>
<p><a href="http://www.veracode.com/security/binary-code-analysis">Binary Analysis</a><br />
<a href="http://www.veracode.com/security/application-testing-tool">Application Testing</a><br />
<a href="http://www.veracode.com/security/software-security-testing">Software Security</a><br />
&nbsp;</p>
<h3>Veracode Data Security Resources</h3>
<p><a href="http://www.veracode.com/security/data-loss-prevention">Data Leaks</a><br />
<a href="http://www.veracode.com/security/data-security">Secure Data</a><br />
<a href="http://www.veracode.com/security/data-breach">Data Breach</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.veracode.com/blog/2008/08/blackhat-picks-day-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

