<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Malta Info Security</title>
    <link>http://maltainfosec.org/</link>
    <description>Creating an Information Security community on the Maltese islands</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Fri, 18 Jul 2008 20:43:28 GMT</pubDate>

    <image>
        <url>http://maltainfosec.org/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Malta Info Security - Creating an Information Security community on the Maltese islands</title>
        <link>http://maltainfosec.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>5 lessons learned about computer security</title>
    <link>http://maltainfosec.org/archives/107-5-lessons-learned-about-computer-security.html</link>
    
    <comments>http://maltainfosec.org/archives/107-5-lessons-learned-about-computer-security.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=107</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=107</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;p&gt;Extracts from the original article found &lt;a href=&quot;http://www.networkworld.com/news/2008/071408-five-lessons-learned-about-computer.html?page=1&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;... include some sane advice to those who get thrilled by the term &#039;hacker&#039; by none other than the infamous &lt;a href=&quot;http://en.wikipedia.org/wiki/Kevin_Mitnick&quot; target=&quot;_blank&quot;&gt;Kevin Mitnick&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://tbn0.google.com/images?q=tbn:DremSaHtWPFQ4M:http://theparadigm.in/ohc/images/300_mitnick1.jpg&quot; /&gt;Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career.&lt;/p&gt;&lt;br /&gt;Learn the rules before you play the game. I knew hacking was sneaky when I started, but I didn&#039;t think it would get me into trouble. Back in my day, they didn&#039;t teach us about ethics in respect to hacking or using computers. Now, I tell kids to not follow in my footsteps. As computers become more accessible, there are more ethical ways to learn about computer security. Plus, there are laws now.&lt;br /&gt;&lt;br /&gt;Use your powers for good, not evil.&lt;br /&gt;&lt;br /&gt;Before, I was doing something exciting-but it was unauthorized and illegal. Now, I do the same thing that got me in trouble, except I do it with authorization. Clients hand me their network and tell me to break in so they can fix security vulnerabilities. To me, it&#039;s the same act but it helps my clients and it&#039;s legal and ethical, so it&#039;s a win-win situation.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Even hackers get hacked. Attackers found a way onto my Web server.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href=&quot;http://www.networkworld.com/news/2008/071408-five-lessons-learned-about-computer.html?page=1&quot; target=&quot;_blank&quot;&gt;&lt;p&gt;Source&lt;/p&gt;&lt;/a&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 17 Jul 2008 15:03:09 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/107-guid.html</guid>
    
</item>
<item>
    <title>Europe Grants First Privacy Certification</title>
    <link>http://maltainfosec.org/archives/106-Europe-Grants-First-Privacy-Certification.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/106-Europe-Grants-First-Privacy-Certification.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=106</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=106</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;font&gt;&lt;img src=&quot;http://www.european-privacy-seal.eu/logo.gif&quot; /&gt;&lt;font&gt;&lt;p&gt;The European Commission today granted its first privacy &amp;quot;seal of approval&amp;quot; to an online service, paving the way for e-businesses across Europe to certify their practices for protecting users&#039; personal information.&lt;/p&gt;&lt;p&gt;&lt;font&gt;&lt;p&gt;&lt;font&gt;The privacy seal, dubbed &lt;a href=&quot;http://www.european-privacy-seal.eu/press-room/press-releases/20080714-europrise-press-release-en.html&quot; target=&quot;new&quot;&gt;EuroPriSe&lt;/a&gt; (European Privacy Seal), is a detailed conformance and testing program designed to certify that an online service meets all of the European Union&#039;s laws and regulations regarding the handling of customer data. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;
&lt;font&gt;In a nutshell, the seal assures the user that a Website or online business doesn&#039;t store personal data (including IP addresses) for long periods of time or monitor user behavior in ways that are not allowed under EU regulations. The seal also assures users that the personal information collected by the site is kept secure.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;Is it a matter of time before we have to comply?&lt;font&gt;&lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/106-Europe-Grants-First-Privacy-Certification.html#extended&quot;&gt;Continue reading &quot;Europe Grants First Privacy Certification&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 15 Jul 2008 12:25:17 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/106-guid.html</guid>
    
</item>
<item>
    <title>Dilbert on workplace surveillance</title>
    <link>http://maltainfosec.org/archives/105-Dilbert-on-workplace-surveillance.html</link>
            <category>Humor</category>
    
    <comments>http://maltainfosec.org/archives/105-Dilbert-on-workplace-surveillance.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=105</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=105</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;img src=&quot;http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/10000/1000/100/13538/13538.strip.print.gif&quot; /&gt;&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 15 Jul 2008 11:03:26 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/105-guid.html</guid>
    
</item>
<item>
    <title>Protecting your GMail account</title>
    <link>http://maltainfosec.org/archives/104-Protecting-your-GMail-account.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/104-Protecting-your-GMail-account.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=104</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=104</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;bottom&quot; src=&quot;https://mail.google.com/mail/help/images/logo.gif&quot; alt=&quot;GMail&quot; /&gt;&lt;/p&gt;&lt;p&gt;Google have added a cool feature for users of GMail - the ability to sign out from previously logged in sessions - therefore if you have the habbit of signing into GMail from multiple PC&#039;s and &amp;quot;forget&amp;quot; to logoff, scroll to the bottom of you current GMail screen and you will see the new feature titling &amp;quot;Last account activity: xx minutes ago on this computer. Details..&amp;quot;&lt;/p&gt;&lt;p&gt;Click the &amp;lt;details&amp;gt; link and you&#039;re presented with a list of previous sessions which allows you to quickly verify that all the GMail activity was indeed yours. To be extra cautious you can click on &amp;quot;Sign out all other sessions&amp;quot; - this way you prevent any unauthorised usage of previous sessions.&lt;/p&gt;&lt;p&gt;Full report can be read &lt;a title=&quot;Remote sign out and info to help you protect your Gmail account&quot; target=&quot;_blank&quot; href=&quot;http://gmailblog.blogspot.com/2008/07/remote-sign-out-and-info-to-help-you.html&quot;&gt;here&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;span id=&quot;1f69&quot; class=&quot;l73JSe&quot; tabindex=&quot;0&quot; role=&quot;link&quot;&gt;&lt;p /&gt;&lt;/span&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 08 Jul 2008 07:30:50 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/104-guid.html</guid>
    
</item>
<item>
    <title>The perils of popular Facebook</title>
    <link>http://maltainfosec.org/archives/103-The-perils-of-popular-Facebook.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/103-The-perils-of-popular-Facebook.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=103</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=103</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;p&gt;&lt;b&gt;&lt;i&gt;An article written for the Sunday Times of Malta - IT Supplement dated 8-6-2008&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Often enough, most people tend to have their own way of perceiving how secure they actual are when doing things online. Indeed a lot of people tend to be naive and prefer not to think of what can go wrong right after they post or publish something personal about themselves or even others.&lt;br /&gt;
&lt;br /&gt;
&lt;/p&gt;&lt;p&gt;The way we perceive how secure we are, largely depends on past personal experiences. If you ever suffered some sort of data loss due to a virus - you would know exactly what I mean - in that - once bitten twice shy. So worst memory tends to prevail over your decisions and even perceptions of how secure you really are. More over, misconceptions surround us such as &amp;quot;I have antivirus software, so I am secure&amp;quot; or “I have a firewall, so I am safe”. The reality is that to be secure you need to employ a suite of tools (antivirus being one of them) to help you reduce your risk exposure to an acceptable level.&lt;br /&gt;
&lt;br /&gt;
&lt;/p&gt;&lt;p&gt;These days there is a lot of talk about Facebook. First off - it is a social networking tool which anybody can freely sign up for and use. So far so good! One of reasons it is so popular with people (in particular with youngsters) is that it allows for virtual social interactivity - therefore somewhat redefining the way people meet, talk and share things with each other. In many ways I feel it has affected our social culture. If you feel shy, then you can look for your soul mate online without having to sweat it out before you pluck up enough courage to go talk to a guy/girl face to face. One facility Facebook offers is the ability to check how compatible you are with different people and linkup to different friends through existing friends to build a spider web of friends. One idea might be - the more friends you accumulate online (say on Facebook) the more popular you are perceived to be. At face value, Facebook sounds cool especially if you are a budding teen. So where&#039;s the catch?&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;
&lt;/p&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/103-The-perils-of-popular-Facebook.html#extended&quot;&gt;Continue reading &quot;The perils of popular Facebook&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Mon, 09 Jun 2008 10:16:03 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/103-guid.html</guid>
    
</item>
<item>
    <title> Wireless modem considerations</title>
    <link>http://maltainfosec.org/archives/102-Wireless-modem-considerations.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/102-Wireless-modem-considerations.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=102</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=102</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;!-- s9ymdb:94 --&gt;&lt;img width=&quot;110&quot; height=&quot;78&quot; class=&quot;serendipity_image_right&quot; style=&quot;border: 0px none ; float: right; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://maltainfosec.org/uploads/images/lock.serendipityThumb.jpg&quot; /&gt;I am pretty sure that there are a number of you out there reading this blog over a wireless network. Given that wireless is so widely distributed these days, its not uncommon that users are unaware of how insecure their wireless setup maybe.&lt;/p&gt;&lt;p&gt;Unfortunately one other reality is that a number of ISP&#039;s install wireless modems without setting up any sort of security. What&#039;s worse is that if the client doesn&#039;t speak up - they don&#039;t quite advise the customer of what could be at risk. Basically as long as your laptop/device successfully connects to the wireless LAN that is setup up for you, they&#039;re out of there. SOO - this is where we come in to offer some advice.&lt;/p&gt;&lt;p&gt;If you connect to your wireless router without a password, its time to get hold of a technician who knows his business and set up some security on it. That&#039;s not all...&lt;/p&gt;&lt;p&gt;Recent developments published by &lt;a href=&quot;http://www.gnucitizen.org/blog/default-key-algorithm-in-thomson-and-bt-home-hub-routers/&quot; target=&quot;_blank&quot;&gt;Petko D. Petkov&lt;/a&gt; reveal some pretty nasty things an attacker can do to Thomson Speedtouch wireless modems - which is what a lot of us Maltese people have at home to connect to the internet.&lt;/p&gt;&lt;p&gt;Thanks to a friend of mine who first pointed out the article above, it is now possible that if an attacker sees your default network name (SSID) then it would be possible for him to crack your default password and use your internet connection. Therefore here are some healthy tips you could pass onto your technician if you&#039;re not confident to set them yourself.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Use WPA2 encryption rather than WEP/WPA.&lt;/b&gt; &lt;/p&gt;&lt;p&gt;Note that this will affect usage of early PDA&#039;s wireless and even computers with Windows XP. In fact you will need to download a patch for Windows XP to use WPA2. Also certain old wireless adapters (802.11b) might not have updated drivers, so do your homework to see if your adapter can use WPA2 before you start changing anything.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Change the default network name (SSID)&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Change the default name of your router to something else. Invent an name. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Change the default password (preshared key)&lt;/b&gt;&lt;/p&gt;&lt;p&gt;If you don&#039;t have a password - PUT ONE. If the router is using a default password, its a good idea to change it unless you don&#039;t mind sharing your internet conenction with your neighbours.&lt;/p&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/102-Wireless-modem-considerations.html#extended&quot;&gt;Continue reading &quot; Wireless modem considerations&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 30 Apr 2008 08:11:38 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/102-guid.html</guid>
    
</item>
<item>
    <title>The Real Security Icon</title>
    <link>http://maltainfosec.org/archives/101-The-Real-Security-Icon.html</link>
    
    <comments>http://maltainfosec.org/archives/101-The-Real-Security-Icon.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=101</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=101</wfw:commentRss>
    

    <author>nospam@example.com (Giannella De Leonardo)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;Sunday is the most relaxed day of the week.  I&#039;ve been pondering about a strange (and useless) subject, just to fill in my precious Sunday morning.&lt;br /&gt;
&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;Some time ago I had a brief discussion with &lt;a href=&quot;http://enablesecurity.com&quot;&gt;Sandro&lt;/a&gt; about the padlock and why it&#039;s not a very good symbolic figure for security.  In reality this is true since padlocks nowadays are a weak and most basic form of physical security.  &lt;br /&gt;
&lt;/p&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/101-The-Real-Security-Icon.html#extended&quot;&gt;Continue reading &quot;The Real Security Icon&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Sun, 20 Apr 2008 08:40:09 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/101-guid.html</guid>
    
</item>
<item>
    <title>Yoggie - Personal Laptop Security on USB</title>
    <link>http://maltainfosec.org/archives/100-Yoggie-Personal-Laptop-Security-on-USB.html</link>
    
    <comments>http://maltainfosec.org/archives/100-Yoggie-Personal-Laptop-Security-on-USB.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=100</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=100</wfw:commentRss>
    

    <author>nospam@example.com (Giannella De Leonardo)</author>
    <content:encoded>
    &lt;br /&gt;
Just stumbled upon www.yoggie.com, a security &#039;server&#039; that is able to provide a laptop with the same level of security as within the&lt;br /&gt;
corporate network. &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/100-Yoggie-Personal-Laptop-Security-on-USB.html#extended&quot;&gt;Continue reading &quot;Yoggie - Personal Laptop Security on USB&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 17 Apr 2008 14:50:22 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/100-guid.html</guid>
    
</item>
<item>
    <title>Open ID &amp; Alternative Login Methods</title>
    <link>http://maltainfosec.org/archives/98-Open-ID-Alternative-Login-Methods.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/98-Open-ID-Alternative-Login-Methods.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=98</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=98</wfw:commentRss>
    

    <author>nospam@example.com (Giannella De Leonardo)</author>
    <content:encoded>
    &lt;p&gt;Recently I created an Open ID Login in order to log-in to a website. Since this was something new for me I did some research of my own and I found this instructional video that explains this in detail:&lt;/p&gt;&lt;p align=&quot;center&quot;&gt;&lt;object width=&quot;425&quot; height=&quot;355&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/xcmY8Pk-qEk&amp;hl=en&quot; /&gt;&lt;param name=&quot;wmode&quot; value=&quot;transparent&quot; /&gt;&lt;embed width=&quot;425&quot; height=&quot;355&quot; src=&quot;http://www.youtube.com/v/xcmY8Pk-qEk&amp;hl=en&quot; type=&quot;application/x-shockwave-flash&quot; wmode=&quot;transparent&quot; /&gt;&lt;/object&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;
More Info:&lt;br /&gt;
&lt;br /&gt;
&lt;/p&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/98-Open-ID-Alternative-Login-Methods.html#extended&quot;&gt;Continue reading &quot;Open ID &amp;amp; Alternative Login Methods&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 15 Apr 2008 11:04:25 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/98-guid.html</guid>
    
</item>
<item>
    <title>Businesses: Top 10 security threats to watch out for</title>
    <link>http://maltainfosec.org/archives/97-Businesses-Top-10-security-threats-to-watch-out-for.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/97-Businesses-Top-10-security-threats-to-watch-out-for.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=97</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=97</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    There are lots of ways business networks can be compromised, and more are developing all the time.&lt;br /&gt;
&lt;br /&gt;
They range from technology exploits to social engineering attacks, and all can compromise corporate data, reputation and the ability to conduct business effectively.&lt;br /&gt;
&lt;br /&gt;
Since we all like lists &lt;img src=&quot;http://maltainfosec.org/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt; here are 10 such threats and some suggestions on what to do about them.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;1. Virtual host security&lt;br /&gt;
2. Protecting the virtual machine monitor (hypervisor)&lt;br /&gt;
3. Botnets&lt;br /&gt;
4. Targeted attacks&lt;br /&gt;
5. Attacks via gaming and virtual reality sites&lt;br /&gt;
6. Browser threats&lt;br /&gt;
7. Mobile phone browser exploits&lt;br /&gt;
8. Lost mobile devices&lt;br /&gt;
9. Insecure Web applications&lt;br /&gt;
10. Rust-out&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Read the full-article and grab the details &lt;a href=&quot;http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/news/2008/040908-10-security-threats.html&amp;pagename=/news/2008/040908-10-security-threats.html&amp;pageurl=http://www.networkworld.com/news/2008/040908-10-security-threa&quot;   target=&quot;_blank&quot;&gt;here&lt;/a&gt;. Take a look at the NSA&#039;s published 10 best security practices.&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://maltainfosec.org/uploads/nsa_best_practices.jpg&#039; onclick=&quot;F1 = window.open(&#039;/uploads/nsa_best_practices.jpg&#039;,&#039;Zoom&#039;,&#039;height=358,width=495,top=340.5,left=400,toolbar=no,menubar=no,location=no,resize=1,resizable=1,scrollbars=yes&#039;); return false;&quot;&gt;&lt;!-- s9ymdb:91 --&gt;&lt;img width=&#039;110&#039; height=&#039;79&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://maltainfosec.org/uploads/nsa_best_practices.serendipityThumb.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 15 Apr 2008 08:12:50 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/97-guid.html</guid>
    
</item>
<item>
    <title>Credit Card Data Leaks</title>
    <link>http://maltainfosec.org/archives/96-Credit-Card-Data-Leaks.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/96-Credit-Card-Data-Leaks.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=96</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=96</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    In view of a recent article on the Times of Malta dated 9-4-2008 titled &lt;strong&gt;Some Visa cards replaced due to possible fraud&lt;/strong&gt; we would like to take the opportunity to remind our readers about exercising caution to disclosing personal card details to untrusted people or websites through email or otherwise.&lt;br /&gt;
&lt;br /&gt;
VISA provides a link with Fraud Prevention TIPS some of which are listed below - so there is no excuse for being negligent. Take your time to make sure you are duly diligent with personal details. There are many physical and logical attacks that can take place such as skimming, phising and even social engineering.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;When providing payment information online, look for the &#039;padlock&#039; icon on your browser&#039;s status bar - this signals that your information is kept secure during transactions.&lt;br /&gt;
&lt;br /&gt;
Do not reply to unsolicited e-mails or telephone calls that request your personal information such as your SIN, password or bank account number.&lt;br /&gt;
&lt;br /&gt;
When possible, keep an eye on your Visa card when it is swiped at the merchant&#039;s terminal to ensure information on the magnetic stripe is not copied through a skimming device.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Precautionary measures are good - but prevention is better than cure - and preceding that being aware is the first step. The hard part is getting the message out there - and that is where strive to make a difference.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Sources/References&lt;/em&gt;&lt;br /&gt;
http://www.timesofmalta.com/articles/view/20080409/local/some-visa-cards-replaced-due-to-possible-fraud&lt;br /&gt;
http://www.visa.ca/en/personal/securewithvisa/fraudprevtips.cfm&lt;br /&gt;
http://www.visa.ca/phishing/ 
    </content:encoded>

    <pubDate>Wed, 09 Apr 2008 13:58:23 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/96-guid.html</guid>
    
</item>
<item>
    <title>Blackhat Europe + Twitter</title>
    <link>http://maltainfosec.org/archives/95-Blackhat-Europe-+-Twitter.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/95-Blackhat-Europe-+-Twitter.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=95</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=95</wfw:commentRss>
    

    <author>nospam@example.com (Sandro Gauci)</author>
    <content:encoded>
    &lt;!-- s9ymdb:90 --&gt;&lt;img width=&#039;69&#039; height=&#039;110&#039; style=&quot;float: right; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://maltainfosec.org/uploads/images/BH.serendipityThumb.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
[Sandro]&lt;br /&gt;
Just a quick notice - If anyone&#039;s interested in what&#039;s going on @ Blackhat Europe, I&#039;m posting quick notes on my twitter account. &lt;a href=&quot;http://twitter.com/sandrogauci&quot; target=&quot;_blank&quot;&gt;http://twitter.com/sandrogauci&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[Donald]&lt;br /&gt;
So we&#039;re back from Black Hat and the cold Dutch weather and I must admit that overall the amount of cool stuff that goes on during the conference overwhelmed me. More than the presentations (which hook you in themselves) - it was the people that we met and socialized with in the evenings. Amsterdam city is a great city for the urban runner - a must visit if you enjoy hectic run-arounds. Fine restaurants and lots of good company. On the other hand, if you&#039;re a bit like me, I would tend to go for a more relaxed area - nevertheless (I&#039;m not complaining) - I loved it and would definitely jump at the opportunity to go there again next year.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 27 Mar 2008 11:57:45 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/95-guid.html</guid>
    
</item>
<item>
    <title>SMART City - Malta</title>
    <link>http://maltainfosec.org/archives/94-SMART-City-Malta.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/94-SMART-City-Malta.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=94</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=94</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    We&#039;d like to show you some big aspirations for Malta through SMART City - Malta!&lt;br /&gt;
&lt;a href=&quot;http://www.smartcity.ae/malta/video.html&quot; target=&quot;_blank&quot;&gt;Original source&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/94-SMART-City-Malta.html#extended&quot;&gt;Continue reading &quot;SMART City - Malta&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 19 Mar 2008 19:02:57 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/94-guid.html</guid>
    
</item>
<item>
    <title>Congrats: you are a winner</title>
    <link>http://maltainfosec.org/archives/93-Congrats-you-are-a-winner.html</link>
            <category>Articles</category>
    
    <comments>http://maltainfosec.org/archives/93-Congrats-you-are-a-winner.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=93</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=93</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;em&gt;&lt;strong&gt;PLEASE BEWARE:&lt;/strong&gt;&lt;br /&gt;
&lt;/em&gt;&lt;br /&gt;
This morning I recieved an SMS with the following text:&lt;br /&gt;
&lt;strong&gt;&lt;blockquote&gt;&lt;br /&gt;
CONGRATS: YOUR MOBILE NUMBER HAS WON FOR YOU THE SUM 192,000 POUNDS IN THIS YEARS NOKIA MTN PROMO. FOR CLAIM CALL: +2347035278214 &amp;amp; E-MAIL: nokia@luckymail.com&lt;/blockquote&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Doing a little research, first thing to notice is that the number above (+234) is Nigerian. Already smells bad...&lt;br /&gt;
A little more research on google and you will find other reports of this message with people asking whether it is a hoax or not.&lt;br /&gt;
The sum, number and email vary accordingly - and it IS a hoax.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;So readers BEWARE - as much as everybody likes the sound of it, don&#039;t bother calling or emailing or disclosing any personal information.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
If you know of any other reports, feel free to comment below. 
    </content:encoded>

    <pubDate>Wed, 19 Mar 2008 10:11:21 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/93-guid.html</guid>
    
</item>
<item>
    <title>Recovering passwords from RAM</title>
    <link>http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html</link>
            <category>Articles</category>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=92</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=92</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    A joint group of people from &lt;a href=&quot;http://citp.princeton.edu/memory/&quot; target=&quot;_blank&quot;&gt;Princeton&lt;/a&gt; have recently managed to prove the fact that RAM chips, when cooled to a very low temperature, can continue to retain the contents of RAM for up to several minutes after they have been physically removed from a computer. &lt;br /&gt;
&lt;br /&gt;
The group, then built their own tools and programs to read off the contents of the memory after the computers were rebooted - proving that disk encryption technologies (such as Truecrypt for instance) can be defied. This is demonstrated in a video posted on youtube (see extended body of article)&lt;br /&gt;
&lt;br /&gt;
The concept can also be also easily demonstrated following a simple experiment outlined on the groups page &lt;a href=&quot;http://citp.princeton.edu/memory/exp/&quot; &gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Q. What can users do to protect themselves?&lt;br /&gt;
A. The most effective way for users to protect themselves is to fully shut down their computers several minutes before any situation in which the computers’ physical security could be compromised. On most systems, locking the screen or switching to “suspend” or “hibernate” mode does not provide adequate protection. (Exceptions exist; some systems may not be protected even when powered off. Check with the developer of your disk encryption software for further guidance.)&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Following up this, according to Ivan Krstic, director of security architecture at OLPC (One Laptop per Child) - the recently announced MacBook Air is resistant to what is now known as the &quot;Cold-Boot Encyption Attack&quot; simply because the machines DDR2 RAM (2gb) is soldered on and cannot be physically removed. In addition, if Apple release an EFI firmware upgrade to zero the contents of the RAM at every boot, then the MacBook  &lt;blockquote&gt;&quot;...would become one of the only—if not the only—mainstream laptop featuring full-disk encryption that&#039;s highly-resistant to the troublesome Princeton attack.&quot;&lt;/blockquote&gt; &lt;br /&gt;
&lt;br /&gt;
(&lt;a href=&quot;http://www.eweek.com/c/a/Security/MacBook-Air-Resistant-to-ColdBoot-Encryption-Attack/&quot; &gt;source&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
Microsoft also reacts to this vis-a-vis their BitLocker technology in Vista. &lt;a href=&quot;http://www.eweek.com/c/a/Security/MacBook-Air-Resistant-to-ColdBoot-Encryption-Attack/1/&quot; target=&quot;_blank&quot; &gt;Ryan Naraine&lt;/a&gt; reports on this here.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Microsoft suggests that the most secure method to use BitLocker is in hibernate mode and with multi-factor authentication.&lt;br /&gt;
According to Robert Hensing, a software engineer in Microsoft&#039;s SWI (Secure Windows Initiative) team, this class of attack is not new and was actually raised at the 2006 Hack in the Box conference in Kuala Lumpur, Malaysia.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.theregister.co.uk/2008/02/22/eff_unbitlocker/&quot; &gt;&lt;br /&gt;
The Register&lt;/a&gt; also has their views on this...BitLocker, meet BitUnlocker.&lt;br /&gt;
&lt;br /&gt;
A question directed to Digital Forensic experts - Is this a blessing in disguise? What&#039;s your take on it?&lt;br /&gt;
&lt;br /&gt;
Update: More information on the discussion can be found &lt;a href=&quot;http://computer.forensikblog.de/en/2008/02/acquisition_6_the_guillotine.html&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html#extended&quot;&gt;Continue reading &quot;Recovering passwords from RAM&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 27 Feb 2008 09:37:00 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/92-guid.html</guid>
    
</item>

</channel>
</rss>