<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-15182237</id><updated>2011-12-02T03:18:01.834-05:00</updated><category term='medical devices running windows'/><category term='TJX'/><category term='John Sammons'/><category term='Twitter StalkDaily Worm'/><category term='SQL Injection'/><category term='virut virux security'/><category term='Mac at 25'/><category term='Weak Passwords'/><category term='how to'/><category term='Russian Business Network'/><category term='john strand'/><category term='Network Scan'/><category term='FDA'/><category term='wireshark ethereal'/><category term='malware servered via adserver'/><category term='60 Minutes'/><category term='virux'/><category term='WSUS'/><category term='excel. security'/><category term='WV Record'/><category term='Adobe'/><category term='Fail'/><category term='Google Safe Browsing'/><category term='419 Scam'/><category term='business continuituy'/><category term='downadup/conflicker'/><category term='Gozi trojan'/><category term='SANS JBIG2 stream'/><category term='Sys Admin'/><category term='SANS'/><category term='SATAN'/><category term='Thomson'/><category term='Antivirus2009'/><category term='The Long Now Foundation'/><category term='WV State Bar'/><category term='FBI'/><category term='crimeware'/><category term='disgruntled ex-employee'/><category term='Mdropper'/><category term='fake antivirus'/><category term='FreedomTM'/><category term='WV State Police. Antivirus2009'/><category term='wireless security'/><category term='koobface'/><category term='cybercrime'/><category term='Network Forensics'/><category term='iPhone'/><category term='Internet Investigations'/><category term='computer crime'/><category term='insider threat'/><category term='Daniel Suarez'/><category term='worm'/><category term='iPhone App'/><category term='304Geeks'/><category term='Dan Farmer'/><category term='RBN'/><category term='0-day Mircrosoft'/><category term='Data Breach'/><category term='Gonzalez'/><category term='Twitter'/><category term='Microsoft'/><category term='Email'/><category term='Exchange'/><category term='trojans'/><category term='Windows Update'/><category term='Acrobat'/><category term='autorun conflicker cert'/><category term='spearfishing'/><category term='Security'/><category term='Kevin Metnick'/><category term='mailware servered via adserver'/><category term='Daemon'/><category term='PDFs'/><category term='Steve Jobs'/><category term='organized crime'/><category term='zeus'/><category term='virut'/><category term='Heartland'/><category term='conflicker'/><category term='Passwords'/><category term='Prolaw'/><category term='Cyber Security'/><category term='law firm it'/><category term='disaster recovery'/><category term='SET'/><category term='vundo'/><category term='Facebook'/><category term='disgruntled employee'/><category term='Tsutomu Shimomura'/><category term='eWeek'/><category term='ARP spoofing AV webserver javascript'/><category term='bots'/><category term='PaulDotCom'/><category term='Dictionary Attack'/><category term='Breach Notification'/><category term='Macintosh'/><category term='John Markoff'/><category term='OWA'/><category term='Updates'/><category term='nmap'/><category term='ghostnet'/><category term='symantec'/><category term='backups'/><category term='Louisville InfoSec'/><category term='dojosec'/><category term='nessus'/><category term='hackers'/><category term='Appalachian Institute of Digital Evidence'/><category term='botnet'/><category term='zero-day'/><category term='Digital Evidence'/><category term='Windows Update Server'/><category term='Malware'/><category term='Security Bulletin Webcast Video'/><category term='Black Tuesday'/><category term='wep'/><category term='Elite'/><category term='Electronic Discovery'/><category term='Trojan.Vundo'/><title type='text'>Law Firm IT</title><subtitle type='html'>The view from the server room.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default?start-index=101&amp;max-results=100'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>415</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-15182237.post-2822667966682459217</id><published>2010-08-30T05:48:00.006-04:00</published><updated>2010-08-30T05:58:30.059-04:00</updated><title type='text'>Hack3rCon in Today's Charleston Daily Mail</title><content type='html'>There is a &lt;a href="http://www.dailymail.com/News/201008290407"&gt;nice story&lt;/a&gt; about &lt;a href="http://hack3rcon.org/"&gt;Hack3rCon&lt;/a&gt; in today's Charleston Daily Mail with info about the conference and interviews with me and Rob Dixon. Being a former journalist it is ofter uncomfortable to be the subject of an interview, but &lt;a href="http://www.dailymail.com/News/contact/cnhy.snyyba+qnvylznvy+pbz+return=/News/201008290407" rel="nofollow" title="Click to reveal email with your email client" class="blue fn"&gt;Paul Fallon&lt;/a&gt; does a pretty good job of not misquoting me.&lt;br /&gt;&lt;br /&gt;For more information about Hack3rCon visit &lt;a href="http://hack3rcon.org/"&gt;http://hack3rcon.org/&lt;/a&gt;. A portion of the proceeds will benefit &lt;a href="http://www.hackersforcharity.org/"&gt;Hackers for Charity&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://player.vimeo.com/video/14326554" width="400" frameborder="0" height="240"&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href="http://vimeo.com/14326554"&gt;Welcome to Hack3rCon 2010&lt;/a&gt; from &lt;a href="http://vimeo.com/user1234121"&gt;The 304 Geeks&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2822667966682459217?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2822667966682459217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2822667966682459217' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2822667966682459217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2822667966682459217'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/08/hack3rcon-in-todays-charleston-daily.html' title='Hack3rCon in Today&apos;s Charleston Daily Mail'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6930639185001942118</id><published>2010-08-21T16:09:00.001-04:00</published><updated>2010-08-21T16:11:11.189-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Security'/><category scheme='http://www.blogger.com/atom/ns#' term='304Geeks'/><category scheme='http://www.blogger.com/atom/ns#' term='SET'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><title type='text'>Hack3rCon</title><content type='html'>The 304Geeks will be hosting "&lt;a href="http://hack3rcon.org/" target="_blank"&gt;Hack3rCon&lt;/a&gt;", the first of its kind Information  Security Conference in this State!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hack3rcon.org/" target="_blank"&gt;http://www.hack3rcon.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.charcon.org/cart" target="_blank"&gt;Register Now!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Events:&lt;br /&gt;Ethical Hacking Workshops with the guys that created, teach and develop  Backtrack, the most widely distributed open source penetration testing  toolkit.&lt;br /&gt;&lt;br /&gt;We have a full day of special gust discussion on everything from  advanced password cracking in 2010 to detecting and stopping intruders  to hands on hacking lads.&lt;br /&gt;&lt;br /&gt;That is right, we will be holding a hacking village all weekend. Get  hands on experience on our private network. Experience mentor will be on  hand to guide you through the exercises. Prizes***&lt;br /&gt;&lt;br /&gt;We will also be hold a Hacker's Capture the Flag event! Go against other  ethical hackers in an attempt to get all the flags first!!!&lt;br /&gt;&lt;br /&gt;*****WINNER GETS A NETBOOK PREINSTALLED WITH BACKTRACK!!!&lt;br /&gt;&lt;br /&gt;Special Guests:&lt;br /&gt;&lt;br /&gt;Dave Kennedy a.k.a. Rel1k Creator of SET&lt;br /&gt;Adrian Crenshaw a.k.a. Irongeek - Security Researcher&lt;br /&gt;Dennis Boas - **Classified**&lt;br /&gt;Martin Bos a.k.a Purehate - Core Developer Backtrack-Linux&lt;br /&gt;Lee Baird a.k.a. LeeRock - Security Consultant, Ciphent&lt;br /&gt;Mark Baggett - SANS Instructor, Security Blogger - Pauldotcom&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$10 Hack3rCon All Access Weekend Pass when you purchase a CharCon  weekend pass. (requires pre-registration before the event)&lt;br /&gt;&lt;br /&gt;Keep an eye out for technology driven events and contest that will be  host by the 304geeks!!&lt;br /&gt;&lt;br /&gt;The 304Geeks is a local technology group here in Charleston. It was  founded in 2009 by Rob Dixon and myself.&lt;br /&gt;&lt;br /&gt;More on Hack3rCon to come!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6930639185001942118?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6930639185001942118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6930639185001942118' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6930639185001942118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6930639185001942118'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/08/hack3rcon.html' title='Hack3rCon'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-134678819434752104</id><published>2010-06-10T13:22:00.002-04:00</published><updated>2010-06-10T13:26:32.991-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyber Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Appalachian Institute of Digital Evidence'/><category scheme='http://www.blogger.com/atom/ns#' term='John Sammons'/><category scheme='http://www.blogger.com/atom/ns#' term='Electronic Discovery'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet Investigations'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Evidence'/><title type='text'>Appalachian Institute of Digital Evidence First Annual Conference</title><content type='html'>Appalachian Institute of Digital Evidence&lt;br /&gt;First Annual Conference&lt;br /&gt;July 27- 30, 2010&lt;br /&gt;Marshall University Forensic Science Center&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Seating is limited. To reserve a seat, email John Sammons at sammons17@marshall.edu with name, agency and contact information.&lt;br /&gt;&lt;br /&gt;July 27  - 0800 to 1600 Cyber Security &amp;amp; Network Forensics&lt;br /&gt;&lt;br /&gt;Schedule coming soon!&lt;br /&gt;&lt;br /&gt;July 28  - 0800 to 1600 Law Enforcement&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Today's Smoking Gun: An Introduction to Digital Evidence&lt;br /&gt;John Sammons, Assistant Professor, Marshall University&lt;br /&gt;&lt;br /&gt;Are you leaving evidence behind? Computers are everywhere and as such, they need to be considered as a vital source of potential evidence. Valuable digital evidence may be discovered in nearly any case, not just child pornography and identity theft. Homicide, robbery, drug violations are just a few of the cases that could be solved with digital evidence.&lt;br /&gt;&lt;br /&gt;In this course learn the fundamentals of digital evidence, how it's different, how it's collected and how it could benefit your investigations.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Internet Investigations&lt;br /&gt;Josh Brunty&lt;br /&gt;Marshall University Forensic Science Center&lt;br /&gt;&lt;br /&gt;Investigating a cybercrime and/or cybercriminal can be one of the most complex tasks facing the law enforcement professional today and requires a multidisciplinary approach supported by technical expertise that was once not needed with traditional crime.  This session will focus on investigations and operations centered on the use of the internet and its many communities that are being exploited for criminal activity.&lt;br /&gt;&lt;br /&gt;This session will teach investigators how to retrieve and/or extract such evidence using a variety of tools and techniques.&lt;br /&gt;&lt;br /&gt;These two classes have already been submitted and approved for LET credit (4 hrs per).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;July 29 0800 – 1600 – Digital Forensics&lt;br /&gt;&lt;br /&gt;Windows 7 Forensics and USB Device Tracking&lt;br /&gt;&lt;br /&gt;This technically intensive class is designed for the experienced digital forensic investigator. This class will provide an introduction to the Windows 7 operating system from a forensic standpoint. It will also cover the techniques used to track USB devices. The course is taught by Dustin Hurlbut, an Instructor from AccessData. AccessData is the world's largest provider of digital forensic software.&lt;br /&gt;&lt;br /&gt;NOTE: LET credit approval pending&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;July 30 0800 – 1600 – Electronic Discovery&lt;br /&gt;&lt;br /&gt;“Zubulake Revisited” - 2010 Guidance on Preservation Obligations and Spoliation&lt;br /&gt;Douglas Crouse&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Tips For Developing an E-Discovery Response Action Plan&lt;br /&gt;Matthew A. Kelly&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;“Cull,” “Image,” “Early Case Assessment,” and Other Key Vocabulary&lt;br /&gt;Jill McIntyre&lt;br /&gt;(25 min.)&lt;br /&gt;&lt;br /&gt;How to Assess Reasonable Accessibility&lt;br /&gt;Jill McIntyre&lt;br /&gt;(25 min.)&lt;br /&gt;&lt;br /&gt;eDiscovery Collection&lt;br /&gt;Dustin Hurlbut&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;eDiscovery Analysis&lt;br /&gt;Dustin Hurlbut&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Reforms of Civil Pretrial Discovery on the Horizon&lt;br /&gt;Jill McIntyre&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Data as Evidence:  Issues Governing the Admissibility of Electronically&lt;br /&gt;Stored Information at Trial and in Summary Judgment Practice&lt;br /&gt;Douglas Crouse&lt;br /&gt;(50 min.)&lt;br /&gt;&lt;br /&gt;Controlling E-Discovery Costs in Litigation&lt;br /&gt;Jill McIntyre&lt;br /&gt;(50 min.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-134678819434752104?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/134678819434752104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=134678819434752104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/134678819434752104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/134678819434752104'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/06/appalachian-institute-of-digital.html' title='Appalachian Institute of Digital Evidence First Annual Conference'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5453087712629207009</id><published>2010-03-20T10:03:00.003-04:00</published><updated>2010-03-20T10:21:41.995-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='law firm it'/><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><title type='text'>A Chilling Article About Law Firms Becoming Targets of Cyber Criminals</title><content type='html'>I have long said that law firms are lucrative targets for hackers. Today &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/03/19/BU3E1CIIGE.DTL"&gt;a story&lt;/a&gt; appears on page DC - 1 of the San Francisco Chronicle called "Law firms are lucrative targets of cyberscams".&lt;br /&gt;&lt;blockquote&gt;Last spring, a Long Beach law firm received an e-mail from a Hong Kong businessman seeking help collecting debts from American customers. An attorney with the firm saw it as a great opportunity to reel in more business during the economic downturn and agreed to help.&lt;br /&gt;&lt;br /&gt;After a month of signing paperwork and exchanging telephone calls with his client, the attorney received word from one debtor who sent a $200,000 cashier's check to pay off his balance. The attorney deposited it in his firm's account, subtracted his $10,000 fee and wired the remaining amount to his Hong Kong client.&lt;br /&gt;&lt;br /&gt;An hour-and-a-half later, the attorney's bank called and told him the check bounced. Fortunately, the bank was able to prevent the wire transfer from reaching its destination. He almost had been duped out of $190,000.&lt;br /&gt;&lt;br /&gt;"They send me a nice, big, worthless check," said the attorney, who asked to remain anonymous. "Needless to say that was not a fun day. They were the hardest 24 hours of my life.&lt;/blockquote&gt;&lt;br /&gt;The threat has been very real for a long time. Scammers have moved from just scamming "rich americans" and have moved on to targeting "rich american lawyers". The best defense against these sorts of scams are a good spam filter and user education.&lt;br /&gt;&lt;br /&gt;If you don't have a user education program at your firm, start one. Your IT staff should be trained in security as well. Something like the CompTIA Security+ certification is a good start. Even the MCSE has track has security some great security components to it. You should also probably have a CEH or a CISSP on staff as well, or at least a security professional you can bring in to consult on a contract basis.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;...Alex Stamos, a founding partner at iSEC Partners, a San Francisco security consulting firm that recently published research identifying about 100 organizations hit by the attack, said that law firms are on the list of organizations most at risk of being targets in the future.&lt;br /&gt;&lt;br /&gt;"Most law firms are going to be in trouble if this is the level of adversary they're going to deal with," he said. "It's impossible even for the largest law firms to have a dedicated security team that can hold their own against these people."&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;This threat isn't going away anytime soon. Be alert and be careful. The threat is no long the 14 year old in the basement. It's organized crime.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5453087712629207009?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5453087712629207009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5453087712629207009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5453087712629207009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5453087712629207009'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/03/chilling-article-about-law-firms.html' title='A Chilling Article About Law Firms Becoming Targets of Cyber Criminals'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2587132013360161367</id><published>2010-02-26T00:10:00.000-05:00</published><updated>2010-02-26T00:12:50.510-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='organized crime'/><category scheme='http://www.blogger.com/atom/ns#' term='RBN'/><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='bots'/><title type='text'>How Cybercriminals Steal Money</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2587132013360161367?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2587132013360161367/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2587132013360161367' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2587132013360161367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2587132013360161367'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/02/how-cybercriminals-steal-money.html' title='How Cybercriminals Steal Money'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7558489731324339399</id><published>2010-02-25T23:55:00.007-05:00</published><updated>2010-02-26T00:30:53.669-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FreedomTM'/><category scheme='http://www.blogger.com/atom/ns#' term='Daemon'/><category scheme='http://www.blogger.com/atom/ns#' term='The Long Now Foundation'/><category scheme='http://www.blogger.com/atom/ns#' term='Daniel Suarez'/><title type='text'>Two Great Novels</title><content type='html'>&lt;a href="http://www.amazon.com/Daemon-Daniel-Suarez/dp/0451228731/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1260943402&amp;amp;sr=1-1"&gt;Daemon&lt;/a&gt; and its sequel, &lt;a href="http://www.amazon.com/Freedom-TM-Daniel-Suarez/dp/0525951571/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1257207412&amp;amp;sr=1-1"&gt;FreedomTM&lt;/a&gt; may be the best novels I have ever read. Below is a video of the author, &lt;a href="http://thedaemon.com/"&gt;Daniel Suarez&lt;/a&gt;, speaks on "Bot-Mediated Reality".&lt;br /&gt;&lt;br /&gt;Bots, or hardware and software robots, are already a large part of human life. Including botnets used to send spam or generally threaten the Internet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0" width="400" height="264"&gt;&lt;param name="flashvars" value="webhost=fora.tv&amp;amp;clipid=7142&amp;amp;cliptype=clip"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="movie" value="http://fora.tv/embedded_player"&gt;&lt;embed flashvars="webhost=fora.tv&amp;amp;clipid=7142&amp;amp;cliptype=clip" src="http://fora.tv/embedded_player" allowscriptaccess="always" allowfullscreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" width="400" height="264"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7558489731324339399?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7558489731324339399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7558489731324339399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7558489731324339399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7558489731324339399'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2010/02/two-great-novels.html' title='Two Great Novels'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7105463296481119723</id><published>2009-10-30T18:59:00.005-04:00</published><updated>2009-10-30T19:16:54.481-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Louisville InfoSec'/><category scheme='http://www.blogger.com/atom/ns#' term='john strand'/><title type='text'>The Internet is Evil John Strand Louisville Infosec Conference Video</title><content type='html'>I had to miss &lt;a href="http://www.louisvilleinfosec.com/"&gt;Louisville InfoSec&lt;/a&gt;, but &lt;a href="http://www.irongeek.com/"&gt;Irongeek&lt;/a&gt; comes to the recuse with &lt;a href="http://www.irongeek.com/i.php?page=videos%2Flouisville-infosec-2009-videos"&gt;videos from the conference&lt;/a&gt;. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Below is a talk by &lt;a href="http://lawfirmit.blogspot.com/"&gt;Law Firm IT&lt;/a&gt; favorite &lt;a href="http://www.vimeo.com/user595761"&gt;John Strand&lt;/a&gt;. John is a SANS instructor and a member of the &lt;a href="http://pauldotcom.com/"&gt;PaulDotCom&lt;/a&gt; crew, called "The Internet is Evil".  Thanks to &lt;a href="http://www.irongeek.com/"&gt;Irongeek&lt;/a&gt; for taking the time to record, post and host these on &lt;a href="http://www.irongeek.com/i.php?page=security/hackingillustrated"&gt;his site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://blip.tv/play/AYGriW0C" type="application/x-shockwave-flash" width="380" height="290" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7105463296481119723?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7105463296481119723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7105463296481119723' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7105463296481119723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7105463296481119723'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/10/internet-is-evil-john-strand-louisville.html' title='The Internet is Evil John Strand Louisville Infosec Conference Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4987720748954202790</id><published>2009-08-27T07:39:00.006-04:00</published><updated>2009-08-27T08:48:09.910-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zeus'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>Zeus, King of the Underground Crimeware Toolkits</title><content type='html'>This &lt;a href="ttp://www.symantec.com/connect/blogs/zeus-king-underground-crimeware-toolkits"&gt;blog post&lt;/a&gt; and &lt;a href="http://www.youtube.com/watch?v=CzdBCDPETxk"&gt;video&lt;/a&gt; explains how Zeus, currently the world's largest botnet, works.&lt;br /&gt;&lt;br /&gt;&lt;object width="80" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/CzdBCDPETxk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/CzdBCDPETxk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="300" height="240"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4987720748954202790?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4987720748954202790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4987720748954202790' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4987720748954202790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4987720748954202790'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/zeus-king-of-underground-crimeware.html' title='Zeus, King of the Underground Crimeware Toolkits'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2288975095256641560</id><published>2009-08-25T04:28:00.003-04:00</published><updated>2009-08-25T04:34:44.909-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Weak Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Email'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange'/><category scheme='http://www.blogger.com/atom/ns#' term='OWA'/><title type='text'>OWA+Weak Passwords=Big Trouble</title><content type='html'>Now's the time to make sure your users are using strong passwords. As pointed out in &lt;a href="http://www.redspin.com/blog/2009/08/04/attacking-webmail-user-accounts/"&gt;this post&lt;/a&gt; from the RedSpin Security Blog, Outlook Web Access makes getting email on the go very easy for users, but it opens up yet another attack surface that is pretty easy to attack using commonly used tools.&lt;br /&gt;&lt;br /&gt;This an another example of why law firm IT folks needs to encourage the use of strong passwords.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2288975095256641560?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2288975095256641560/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2288975095256641560' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2288975095256641560'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2288975095256641560'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/owaweak-passwordsbig-trouble.html' title='OWA+Weak Passwords=Big Trouble'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7770776789896308767</id><published>2009-08-23T05:42:00.006-04:00</published><updated>2009-08-23T06:28:19.930-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gonzalez'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='TJX'/><category scheme='http://www.blogger.com/atom/ns#' term='Heartland'/><title type='text'>What's so interesting about the TJX Hacker Charged With Heartland, Hannaford Breaches</title><content type='html'>Here's a few details I find interesting in &lt;a href="http://www.wired.com/threatlevel/2009/08/tjx-hacker-charged-with-heartland/"&gt;this story&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;* The hackers allegedly stole more than 130 million credit and debit card numbers from Heartland and Hannaford combined.&lt;br /&gt;* Gonzalez and 10 others were charged in May and August 2008 with network intrusions into TJX, OfficeMax, Dave &amp;amp; Busters restaurant chain and other companies.&lt;br /&gt;* The attack vector was SQL-injection&lt;br /&gt;* The hackers tested their malware against some 20 different antivirus programs to make sure they wouldn’t be detected, and also programmed the malware to erase evidence from the hacked networks to avoid forensic detection.&lt;br /&gt;* The thieves captured card account numbers and expiration dates and, in 20 percent of cases, the customer’s name as well.&lt;br /&gt;* Gonzalez called his credit card theft ring “Operation Get Rich or Die Tryin.”&lt;br /&gt;* Another hacker &lt;a href="http://www.wired.com/threatlevel/2009/07/hacker/"&gt;linked to the crime&lt;/a&gt; committed suicide in 2008.&lt;br /&gt;* Gonzalez &lt;a href="http://www.wired.com/threatlevel/2009/08/gonzalez-evidence/#more-8659"&gt;goes to trial&lt;/a&gt; in New York on September 14th for the Dave &amp;amp; Buster’s hack.&lt;br /&gt;* Next year, Gonzalez &lt;a href="http://www.wired.com/threatlevel/2009/08/gonzalez-evidence/#more-8659"&gt;faces trial&lt;/a&gt; in Massachusetts on the TJX hack and may eventually face trial in New Jersey on new charges levied against him this week for allegedly hacking into five other companies, including Heartland Payment Systems and 7-11, and stealing more than 130 million credit and debit card numbers — the largest data breach prosecuted in the United States to date.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Some are wondering if Gonzalez was hired to do these jobs for the Russian mob. I can find no coverage of such a link.&lt;br /&gt;&lt;br /&gt;Two of my debt cards were involved in these breaches. One was replaced. My bank give me one year of free fraud monitoring on the other.&lt;br /&gt;&lt;br /&gt;While we as law firm IT don't usually process credit card transactions, most of us have SQL databases, many of them Internet facing or running our websites.&lt;br /&gt;&lt;br /&gt;As defenders what can we learn from the breach? Secure your web applications. SQL-injection is a common thread in many recent breaches. It's a quick and easy way to get behind your firewall.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7770776789896308767?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7770776789896308767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7770776789896308767' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7770776789896308767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7770776789896308767'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/08/whats-so-interesting-about-tjx-hacker.html' title='What&apos;s so interesting about the TJX Hacker Charged With Heartland, Hannaford Breaches'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-793414948759690212</id><published>2009-06-28T13:54:00.003-04:00</published><updated>2009-06-28T14:47:42.475-04:00</updated><title type='text'>What a OS X exploit looks like</title><content type='html'>&lt;object width="380" height="360"&gt;&lt;param name="movie" value="http://www.youtube.com/v/dpnWncJH-bk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/dpnWncJH-bk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="380" height="360"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;This video helped to convince me that I needed an antivirus program for my Mac. I didn't purchase Sophos since it requires a Windows server to manage the client installation on a Mac. I downloaded and installed &lt;a href="http://www.clamxav.com/index.php?page=dl"&gt;ClamXAV&lt;/a&gt;. It's free.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-793414948759690212?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/793414948759690212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=793414948759690212' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/793414948759690212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/793414948759690212'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/06/what-os-x-exploit-looks-like.html' title='What a OS X exploit looks like'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6416471450257835031</id><published>2009-06-27T10:55:00.002-04:00</published><updated>2009-06-28T13:42:02.273-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Weak Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Video: Simple Tips to Pick a Strong Password</title><content type='html'>&lt;object width="560" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/VYzguTdOmmU&amp;amp;hl=en&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/VYzguTdOmmU&amp;amp;hl=en&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="360" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6416471450257835031?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6416471450257835031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6416471450257835031' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6416471450257835031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6416471450257835031'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/06/video-simple-tips-to-pick-strong.html' title='Video: Simple Tips to Pick a Strong Password'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2995745040012851953</id><published>2009-05-25T09:48:00.008-04:00</published><updated>2009-05-25T10:25:07.059-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='419 Scam'/><title type='text'>Facebook Spear Phishing, New 419 Scam</title><content type='html'>I received the follow email via Facebook last night that is a new variation on the &lt;a href="http://www.419eater.com/html/419faq.htm"&gt;old 419 scam&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;Wilson sent you a message.&lt;br /&gt;&lt;br /&gt;--------------------&lt;br /&gt;Subject: Attn: Bill Gardner&lt;br /&gt;&lt;br /&gt;Alexander JLO - Solicitors&lt;br /&gt;11 Lanark Square&lt;br /&gt;Glengall Bridge&lt;br /&gt;London E14 9RE&lt;br /&gt;United Kingdom.&lt;br /&gt;TEL:+44 794 4145 981&lt;br /&gt;Fax:+44 794 4416 262&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Good day: Bill ,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is a personal E-mail directed to you and I request that&lt;br /&gt;it be treated as such.&lt;br /&gt;&lt;br /&gt;I am Barrister Wilson Baker, a solicitor at law. I am the personal attorney/sole executor to the late Engr Gerald Gardner herein after referred to as'my client' who worked as an independent oil magnate in my country and who died in a plane crash with his immediate family in December 2003.&lt;br /&gt;&lt;br /&gt;Since the death of my client, I have written several letters to the embassy with an intent to locate any of his extended relatives whom shall be&lt;br /&gt;claimants/beneficiaries of his abandoned personal estate and all such efforts have been to no avail.&lt;br /&gt;&lt;br /&gt;More-so, I have received official letters in the last few weeks suggesting a likely proceeding for confiscation of his abandoned personal assets in line with existing laws by the bank in which my client deposited a notably high amount of money.&lt;br /&gt;&lt;br /&gt;On this note i decided to search for a credible person and finding that you bear a similar last name, I was urged to contact you, that I may with your consent, present you to the "trustee" bank as my late client's surviving family member so as to enable you put up a claim to the bank in that capacity as a next of kin of my client.&lt;br /&gt;&lt;br /&gt;I find this possible for the fuller reasons that you bear a similar last name with my client making it a lot easier for you to put up a claim in that&lt;br /&gt;capacity.&lt;br /&gt;&lt;br /&gt;I propose that 35% of the net sum will accrue to you at the conclusion of this deal in so far as I do not incure further expenses.&lt;br /&gt;&lt;br /&gt;Therefore, to facilitate the immediate transfer of this funds, you need, first to contact me via my private email:(wilsonbaker3@yahoo.co.uk) for better confidentiality, signifying your interest and as soon as I obtain your confidence I will immediately appraise you with the complete details as well as fax you the documents, with which you are to proceed and i shall direct you on how to put up an application to the bank.&lt;br /&gt;&lt;br /&gt;However, you will have to accent to an express agreement which I will forward to you in order to bind us in this transaction.&lt;br /&gt;&lt;br /&gt;Upon the receipt of your reply,I will send you by fax or E-mail the next step to take.I will not fail to bring to your notice that this proposal is hitch-free and that you should not entertain any fears as the required arrangements have been made for the completion of this transfer.&lt;br /&gt;&lt;br /&gt;Like I said, I require only a solemn confidentiality on this.&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Wilson Baker Esq&lt;br /&gt;--------------------&lt;/blockquote&gt;&lt;br /&gt;I have to admit this version of the scam is compelling enough to make me actually read the email. This version of the scam actually lists an address and telephone number, but why would a lawyer use a Yahoo email address? This is just another example of how far people will go to attempt to get between you and your money.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2995745040012851953?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2995745040012851953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2995745040012851953' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2995745040012851953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2995745040012851953'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/facebook-spear-phishing-new-419-scam.html' title='Facebook Spear Phishing, New 419 Scam'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-9089301677718230206</id><published>2009-05-15T07:15:00.011-04:00</published><updated>2009-05-19T04:56:39.325-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><title type='text'>Lessons learned from the WV State Bar breach</title><content type='html'>According to the &lt;a href="http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html"&gt;FAQ&lt;/a&gt; released by the WV State Bar yesterday, the data breach reported a couple of weeks ago was the result of a unpatched Linux sever being compromised. The Bar further says it has "an unsupported FoxPro database containing member information" some where on its network that was also compromised.&lt;br /&gt;&lt;br /&gt;It's unclear from the FAQ how the hacker or hackers took control of the Bar's webserver and started &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-remains-offline-after.html"&gt;serving malware&lt;/a&gt;. The bar does say, "The State Bar will no longer host its own website internally, it will be hosted off-site at a secure location with a company that specializes in website development and internet security. The State Bar website will be completely re-written in a more secure manner."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://toolbar.netcraft.com/site_report?url=http://www.wvbar.org"&gt;Netcraft shows&lt;/a&gt; the Bar site was running on Windows 2000 on Apache/2.0.54 Win32 PHP/5.0.4 on 22-Mar-2006. Previously the site ran Windows 2000, Microsoft-IIS/5.07 as of Nov-2004 &lt;a href="http://toolbar.netcraft.com/site_report?url=http://www.wvbar.org"&gt;according to Netcraft&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;As far as secruity, they &lt;a href="http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html"&gt;say&lt;/a&gt; they had a firewall, "The State Bar's computer system was equipped with a firewall, which previously was believed to be secure. However, the State Bar's forensic computer experts have advised that no firewall would have prevented the sophisticated hack of the website and database. The State Bar is taking extraordinary measures, as set forth in response to question number 1 above, to prevent a security breach from occurring again in the future."&lt;br /&gt;&lt;br /&gt;The Bar has pulled the unpatched Linus box off its network, has stopped hosting it's website internally, and has removed social security number from it's databases. Also it says it's website is being rewritten in a more secure manner.&lt;br /&gt;&lt;br /&gt;So what can we learn from the breach. First, don't run unpatched servers, Linux, Windows, or any other OS on your network.&lt;br /&gt;&lt;br /&gt;Second, attacks on webservers are very much in style by hackers. Since most of us have deployed firewalls, antivirus, patch management, vulnerability scanners, and intrusion detection systems, the webserver is often the weekest link in some networks. As a result, web application security has becoming very important. Secure you web apps and use web application firewalls. Also don't host websites in-house or on the same network as your production network.&lt;br /&gt;&lt;br /&gt;Third, know what applicatons, operating systems, and servers are on  your network and where they are, and document eveything.  The Bar says, "Further complicating matters, there existed no documentation regarding the State Bar network layout, hardware, software and/or legacy applications. As such, the upgrade process has been a cycle of discovery and repair which has taken longer than anyone could have expected or foreseen."&lt;br /&gt;&lt;br /&gt;As far as the breach itself, the Bar say, "The State Bar had social security numbers for approximately 4,000 members. Members whose social security numbers are believed to have been contained on the State Bar's database should have received a second and third email notifying them of that fact. Some members do not have an email address on file with the State Bar. For those members, a separate letter was mailed to them through the United States Postal Service."&lt;br /&gt;&lt;br /&gt;The Bar has turned hard drives over to the FBI and says it will keep it's member up-to-date on the investigation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-9089301677718230206?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/9089301677718230206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=9089301677718230206' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9089301677718230206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9089301677718230206'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/what-wv-state-bar-faq-on-its-data.html' title='Lessons learned from the WV State Bar breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6319028442170428471</id><published>2009-05-14T14:43:00.003-04:00</published><updated>2009-05-15T08:24:26.957-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><title type='text'>The West Virginia State Bar Has Posted An FAQ on Its Recent Data Breach</title><content type='html'>The West Virginia State Bar has posted an FAQ on its recent data breach.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;COMPUTER SECURITY BREACH FAQ&lt;br /&gt;&lt;br /&gt;By now, most members of The West Virginia State Bar have received either one or two emails regarding the security breach at the State Bar website. If you received only one email, as far as the State Bar is aware, your social security number was not in the State Bar's database. Approximately 4,000 of the 7,000 State Bar members received a second email advising that we had your social security number was in the State Bar's database. As of this date, the State Bar has no knowledge that the hackers have looked at any personal information in the State Bar database and the State Bar has received no reports that any of its members have suffered any identity theft. Nonetheless, and out of an abundance of caution, the State Bar provided an alert to each of its members regarding this security breach. This alert has led to numerous questions which the State Bar has attempted to answer below so that all of its members will continue to be informed about this situation.&lt;br /&gt;&lt;br /&gt;1. Does the Bar have any idea of how this could happen?&lt;br /&gt;&lt;br /&gt;In late 2006 or early 2007, the State Bar determined that it needed to upgrade its computers, its network, its member database, and its website. All of these were hosted by the State Bar onsite. Since 2007, the State Bar has been working with computer consultants to upgrade the computers, network and security at the State Bar. The upgrade process has been hampered by the existence of an outdated Linux server, and an unsupported FoxPro database containing member information. Further complicating matters, there existed no documentation regarding the State Bar network layout, hardware, software and/or legacy applications. As such, the upgrade process has been a cycle of discovery and repair which has taken longer than anyone could have expected or foreseen.&lt;br /&gt;&lt;br /&gt;In working with the computer consultants, it was learned very recently that outside computer hackers were able to enter the State Bar computer system through the Linux server and State Bar website. From there they create access to the remainder of the State Bar network, including the member database. It is not possible for the computer consultants to determine whether the hackers did or did not look at the member database, they can only advise that the hackers had the opportunity to look at any and all computer data on the State Bar's network.&lt;br /&gt;&lt;br /&gt;2. What will the State Bar do to make sure this does not happen again?&lt;br /&gt;&lt;br /&gt;The State Bar has now shut down its Linux server and its website. The Linux server will be eliminated. All hard drives in the State Bar network and individual work stations were replaced. The hard drives are being turned over to the Federal Bureau of Investigation. The State Bar will no longer host its own website internally, it will be hosted off-site at a secure location with a company that specializes in website development and internet security. The State Bar website will be completely re-written in a more secure manner. These steps combined should prevent similar security breaches in the future.&lt;br /&gt;The State Bar has worked with its computer consultants to delete all social security numbers from the FoxPro database and no records will be kept in the future regarding social security numbers.&lt;br /&gt;&lt;br /&gt;3. Why did the State Bar have my social security number and when did it get it?&lt;br /&gt;&lt;br /&gt;At various points in time prior to 2007, the State Bar collected social security numbers. Many people provided this information at the time they were admitted to the State Bar. In addition, some social security numbers were collected by the State Bar when the West Virginia Supreme Court of Appeals first considered the possibility of e-filing. More recently, members provided social security numbers at the time they applied for a photo identification card. Beginning immediately, all communications regarding the applications for new photo identification cards will be via U.S. Mail and in paper form. No electronic records will be kept by the State Bar.&lt;br /&gt;&lt;br /&gt;4. Did the State Bar have my social security number or not?&lt;br /&gt;&lt;br /&gt;The State Bar had social security numbers for approximately 4,000 members. Members whose social security numbers are believed to have been contained on the State Bar's database should have received a second and third email notifying them of that fact. Some members do not have an email address on file with the State Bar. For those members, a separate letter was mailed to them through the United States Postal Service.&lt;br /&gt;&lt;br /&gt;5. Why did the State Bar wait so long to notify me of the breach?&lt;br /&gt;&lt;br /&gt;The State Bar acted very quickly after the computer consultants advised The Bar of the potential for a security breach. The State Bar Linux server and website were immediately brought down. The Linux server housed the State Bar's listserv which was its prior method of communicating with all members.&lt;br /&gt;The State Bar's Board of Governors was advised of the security breach and it authorized the dissemination of a press release. The Supreme Court of Appeals of West Virginia was contacted and provided technical assistance in sending out a press release advising of the compromise of the State Bar's network. During this time, the State Bar did not have any ability to mail or email its members as its membership database was inaccessible. The State Bar has now created a new email system to communicate with all members of the State Bar that have their emails on file. The State Bar sent an email to its members within a few hours of its membership database and email listserv being reinstated.&lt;br /&gt;&lt;br /&gt;6. What information did the hackers get in the security breach?&lt;br /&gt;&lt;br /&gt;It is not possible for the computer consultants to advise the State Bar that any information was reviewed during the security breach. The computer consultants can only advise that the outside hackers had access to the member database and all other data on the State Bar network. The computer consultants reviewed the data in the member database. They have advised that it is not infected with any virus.&lt;br /&gt;&lt;br /&gt;7. Why wasn't the site secure?&lt;br /&gt;&lt;br /&gt;The State Bar's computer system was equipped with a firewall, which previously was believed to be secure. However, the State Bar's forensic computer experts have advised that no firewall would have prevented the sophisticated hack of the website and database. The State Bar is taking extraordinary measures, as set forth in response to question number 1 above, to prevent a security breach from occurring again in the future.&lt;br /&gt;&lt;br /&gt;8. Did the State Bar report this to the credit reporting agencies?&lt;br /&gt;&lt;br /&gt;The State Bar has notified the credit reporting agencies of this security breach. The State Bar has also provided the contact information for all three major credit reporting agencies to our members and it has encouraged each member to separately contact those agencies.&lt;br /&gt;&lt;br /&gt;9. Is the State Bar going to pay for my credit monitoring costs?&lt;br /&gt;&lt;br /&gt;Some State Bar members have requested the State Bar to pay for credit monitoring. Unfortunately, the State Bar has no unallocated funds to pay for any credit monitoring services. To put such a program in place could require an assessment of the members as a whole. Given the lack of any reported identity theft affecting any of its members, the State Bar believes that a special dues assessment to pay for this credit monitoring is an unnecessary expense for its members at this time.&lt;br /&gt;&lt;br /&gt;10. Has this been reported to a law enforcement agency so I can file a 7 year report?&lt;br /&gt;&lt;br /&gt;Yes, this matter has been turned over to the Federal Bureau of Investigation. They are conducting a formal investigation of the security breach. Within the next few days, it is anticipated that the FBI will begin its forensic analysis of the removed hard drives. The FBI has assured the State Bar that it will pursue location and prosecution of the individual or individuals who breached the State Bar's system.&lt;br /&gt;&lt;br /&gt;11. Will we be advised of any information the State Bar receives from the FBI?&lt;br /&gt;&lt;br /&gt;Yes, the State Bar will keep its members up to date regarding any public results of the FBI investigation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Since 2007, the State Bar has been working to correct the flaws in the old computer system and to insure that a completely safe and fully operational system is up and running as soon as possible. The State Bar regrets any inconvenience to its members.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6319028442170428471?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6319028442170428471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6319028442170428471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6319028442170428471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6319028442170428471'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/west-virginia-state-bar-has-posted-faq.html' title='The West Virginia State Bar Has Posted An FAQ on Its Recent Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-714587068235197764</id><published>2009-05-08T07:57:00.005-04:00</published><updated>2009-05-08T08:07:05.634-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='malware servered via adserver'/><category scheme='http://www.blogger.com/atom/ns#' term='WV Record'/><title type='text'>The West Virginia Record Malware Problem Fixed</title><content type='html'>The problem with &lt;a href="http://lawfirmit.blogspot.com/2009/05/another-west-virginia-law-related.html"&gt;ads serving malware&lt;/a&gt; at &lt;a href="http://www.wvrecord.com/"&gt;the West Virginia Record&lt;/a&gt; was corrected quickly after they learned of the problem, Chris Dickerson, Editor of the Record told me yesterday. He said the issue was with a compromised ad server that was a part of a ad network serving 100s of newspapers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-714587068235197764?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/714587068235197764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=714587068235197764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/714587068235197764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/714587068235197764'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/west-virginia-record-malware-problem.html' title='The West Virginia Record Malware Problem Fixed'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8354903069973081738</id><published>2009-05-05T15:44:00.006-04:00</published><updated>2009-05-08T09:08:07.875-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Breach Notification'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><title type='text'>Attorneys Receiving Individual Notification of Social Security Number Compromise in Recent WV State Bar Data Breach</title><content type='html'>Individual attorneys began receiving notices this afternoon that their social security numbers we involved in the resent breach of the WV State Bar website and other computer system.&lt;br /&gt;&lt;blockquote&gt;Important Notice to Members Regarding Social Security Information&lt;br /&gt;&lt;br /&gt;From:&lt;br /&gt;The West Virginia State Bar&lt;br /&gt;2006 Kanawha Boulevard, East&lt;br /&gt;Charleston, WV 25311-2204&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar has learned that there are two sets of persons whose Social Security numbers were contained on its computer system, which was recently hacked.　The first group of persons are those who recently completed applications to receive the new West Virginia State Bar photo ID card.　 Those persons included their Social Security numbers on the application forms, which were sent to Cheryl Wright at The State Bar, scanned into The State Bar's computer system, and e-mailed or faxed back to the requesting members.&lt;br /&gt;&lt;br /&gt;　　&lt;br /&gt;The other group of persons whose Social Security numbers were contained on The State Bar's computer system are those who provided their Social Security numbers to The State Bar at some point in time during their membership tenure.　These Social Security numbers existed on The State Bar's membership database along with the members' names, addresses, telephone numbers, email addresses, and dates of admittance.　It was not until late in the day on May 4, 2009, that The State Bar's retained experts were able to retrieve this information.　&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Unfortunately, you are receiving this email because you are among one or both of these groups of people.　Although, as has been explained in the two prior notices, The State Bar has received no evidence or reports of any identity theft, fraud or other unauthorized use of any member's personal information, because your Social Security number was contained on The State Bar's computer system, there is a possibility that it may have been viewed by the hackers.　&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar has notified the three major credit reporting agencies of this potential security breach and is working with the FBI to identify the person(s) or entity(s) responsible.　 If you have any evidence that your personal information has been compromised, please contact The West Virginia State Bar immediately.　 In addition, you also may wish to contact the major credit reporting agencies to ask that a fraud alert be placed in your file to notify potential creditors and others that you may be a victim of identity theft.　The contact information for the credit reporting agencies is as follows:&lt;br /&gt;&lt;br /&gt;Equifax Information Services&lt;br /&gt;PO Box 740256&lt;br /&gt;Atlanta, GA 30374&lt;br /&gt;1-877-576-5734&lt;br /&gt;www.fraudalerts.equifax.com&lt;br /&gt;&lt;br /&gt;　&lt;br /&gt;Experian&lt;br /&gt;NCAC&lt;br /&gt;PO Box 9556&lt;br /&gt;Allen, TX 750131-888-397-3742&lt;br /&gt;www.experian.com/fraud&lt;br /&gt;&lt;br /&gt;　&lt;br /&gt;TransUnion&lt;br /&gt;Customer Disclosure Center&lt;br /&gt;TransUnion Consumer Relations&lt;br /&gt;PO Box 2000&lt;br /&gt;Chester, PA 19022-2000&lt;br /&gt;1-800-680-7289&lt;br /&gt;www.transunion.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar deeply regrets any concern or stress that this has caused you.　If you have any additional questions, please send them to Anita Casey, Executive Director of The West Virginia State Bar.　Ms. Casey will work with The State Bar's Ad Hoc Technology Committee to respond to your questions as quickly as possible.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8354903069973081738?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8354903069973081738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8354903069973081738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8354903069973081738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8354903069973081738'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/attorneys-receiving-individual.html' title='Attorneys Receiving Individual Notification of Social Security Number Compromise in Recent WV State Bar Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4387212344207634827</id><published>2009-05-05T08:27:00.005-04:00</published><updated>2009-05-05T08:40:41.920-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Breach Notification'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><title type='text'>WV State Bar Sends Member Notice of Data Breach</title><content type='html'>The West Virginia State bar sent notice of the breach of it's site and internal servers by hackers yesterday. The notice, posted below, shreds no new light on what happen or if person data was compromised, but it does disclose the FBI is now involved.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: rgb(51, 51, 51);font-family:Arial,Helvetica,sans-serif;font-size:85%;"  &gt; &lt;div   style="color: rgb(0, 0, 0);font-family:Arial Narrow,Arial MT Condensed Light,sans-serif;font-size:14pt;" styleclass="style_ArticleHead"&gt;&lt;span style="color: rgb(0, 0, 0);font-family:Arial Narrow,Arial MT Condensed Light,sans-serif;font-size:130%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Important Notice to Our Members&lt;/b&gt;&lt;/span&gt;  &lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;From:&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;          &lt;br /&gt;&lt;span style="font-style: italic;"&gt;The West Virginia State Bar &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;2006 Kanawha Boulevard, East  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Charleston, WV 25311&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Using a sophisticated computer hack, an unknown person or entity gained  unauthorized access to The West Virginia State Bar website and internal computer  network, potentially compromising certain personal information The State Bar  maintains about its current and former members.&lt;br /&gt;&lt;br /&gt;The security breach was  discovered recently during an upgrade of The State Bar's website. The website  was taken offline on Friday, April 17, 2009.  The State Bar has retained  forensic computer experts to help investigate the suspected security breach. The  State Bar is also working with the FBI to investigate the breach and attempt to  locate the responsible party(s).&lt;br /&gt;&lt;br /&gt;The West Virginia State Bar's Ad Hoc  Technology Committee met with its retained forensic computer experts and learned  that the security breach extended beyond the web server to the Bar's internal  computer network.  Given the sophistication of this security breach, and out of  an abundance of caution, the Committee is considering all personal information  on The State Bar's network as potentially compromised.&lt;br /&gt;&lt;br /&gt;The State Bar  provided notice to all of its members regarding this security breach through a  press release issued on April 28, 2009, with the assistance of the West Virginia  Supreme Court of Appeals as The West Virginia State Bar did not have computer  access to its member lists until May 4, 2009.  This second notice is being sent  to all members at this time because the State Bar's listserv capability was  reinstated late this afternoon.&lt;br /&gt;&lt;br /&gt;Members of the Ad Hoc Technology  Committee, representatives of the company which has been working with The State  Bar's computer system for the past several years, and the forensic computer  experts worked all last week and over the weekend to remediate the  problem.&lt;br /&gt;&lt;br /&gt;While the website itself contained no personal data, the  website was connected to The State Bar's internal database server which houses  the membership data.  Membership data includes names, mailing addresses, email  addresses, birth dates, lawyer identification numbers, and some members' and  former members' social security numbers.  The State Bar Ad Hoc Technology  Committee also has just obtained a list of the names of its members whose social  security numbers were on the system.  Those members will receive a separate  e-mail communication from The State Bar.&lt;br /&gt;&lt;br /&gt;Importantly, the Ad Hoc  Technology Committee has confirmed that information provided by clients to their  attorneys has never been maintained on The State Bar's computer systems and,  therefore, such information is unaffected by this recently discovered security  breach.&lt;br /&gt;&lt;br /&gt;The Ad Hoc Technology Committee has been advised by its forensic  computer experts that it is impossible to determine exactly when the security  breach occurred. The State Bar has no evidence and has received no reports of  any identity theft, fraud or other unauthorized use of its members' personal  information at this time.  If any members of The West Virginia State Bar have  any evidence that their personal information has been compromised, they should  contact The West Virginia State Bar immediately.  Members may also contact the  major credit reporting agencies to ask that a fraud alert be placed in their  files to notify potential creditors and others that they may be victims of  identity theft.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Equifax Information  Services &lt;/span&gt;&lt;br /&gt;PO Box 740256&lt;br /&gt;Atlanta, GA 30374&lt;br /&gt;1-877-576-5734&lt;br /&gt;&lt;a title="blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZye_ejrWCxcuAzX3xs4M5jrARqFkYpD7RYzbroXxh4CAKe4gBOcWu2mPr2f51JXCRxshdgfrMNPyYq1LwD2j-_WdMFTzOIemdC2p41IpTX4NvUaCLe9OAc" href="http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZye_ejrWCxcuAzX3xs4M5jrARqFkYpD7RYzbroXxh4CAKe4gBOcWu2mPr2f51JXCRxshdgfrMNPyYq1LwD2j-_WdMFTzOIemdC2p41IpTX4NvUaCLe9OAc" target="_blank" track="on" linktype="link"&gt;www.fraudalerts.equifax.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Experian&lt;/span&gt;&lt;br /&gt;NCAC&lt;br /&gt;PO Box 9556&lt;br /&gt;Allen, TX  75013&lt;br /&gt;1-888-397-3742&lt;br /&gt;&lt;a title="blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUbPNbihh77A5hjihma_O047Xv8AvmFgfXBSxv1fArKF4YGvzoirpyJIm6DeFbzT6DK2gIDUCIJ1A1_oy3lXWYLOMtOeQSXzdpJs3dROkgkPew==" href="http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUbPNbihh77A5hjihma_O047Xv8AvmFgfXBSxv1fArKF4YGvzoirpyJIm6DeFbzT6DK2gIDUCIJ1A1_oy3lXWYLOMtOeQSXzdpJs3dROkgkPew==" target="_blank" track="on" linktype="link"&gt;www.experian.com/fraud&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;TransUnion &lt;/span&gt;&lt;br /&gt;Customer Disclosure  Center&lt;br /&gt;TransUnion Consumer Relations&lt;br /&gt;PO Box 2000&lt;br /&gt;Chester, PA  19022-2000&lt;br /&gt;1-800-680-7289&lt;br /&gt;&lt;a title="blocked::http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZU21LZlbkq3LKyGzXG4AKyHXcx4gWdLeWV_0pNy-4ckl9GsmfMAp9dN2HAYiDqhxpJHTGV00_ZVuvMFSaRgBDtSFDrUPmSuImp_XGWDnFulA==" href="http://rs6.net/tn.jsp?et=1102570585766&amp;amp;s=3154&amp;amp;e=001DRxxchcrdUZU21LZlbkq3LKyGzXG4AKyHXcx4gWdLeWV_0pNy-4ckl9GsmfMAp9dN2HAYiDqhxpJHTGV00_ZVuvMFSaRgBDtSFDrUPmSuImp_XGWDnFulA==" target="_blank" track="on" linktype="link"&gt;www.transunion.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;All questions should be directed to:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; The West Virginia State Bar&lt;br /&gt;2006 Kanawha Blvd., East&lt;br /&gt;Charleston, WV  25311&lt;br /&gt;c/o Anita Casey, Executive Director&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;Problems with the State Bar website go back to &lt;a href="http://www.charlestondailymail.com/News/200809100161"&gt;September 2009&lt;/a&gt;, and I've &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html"&gt;posted&lt;/a&gt; previously about problems with the Bar's website &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html"&gt;hosting malware&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4387212344207634827?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4387212344207634827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4387212344207634827' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4387212344207634827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4387212344207634827'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/wv-state-bar-sends-member-notice-of.html' title='WV State Bar Sends Member Notice of Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-824326126483245644</id><published>2009-05-04T11:08:00.003-04:00</published><updated>2009-05-04T11:29:26.957-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware servered via adserver'/><category scheme='http://www.blogger.com/atom/ns#' term='WV Record'/><title type='text'>Another West Virginia Law Related Website Compromised</title><content type='html'>The WV Record, a local newspaper that covers state legal matters, is server ads containing malware. It doesn't appears the site itself, www.wvrecord.com, is compromised this morning. The site is serving compromised ads. Until they get this problem cleared up, I wouldn't go there.&lt;br /&gt;&lt;br /&gt;This is the second WV law related site to be compromised recently. The WV State Bar &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html"&gt;reported last week&lt;/a&gt; that its webserver and a number of internal servers were compromised.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-824326126483245644?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/824326126483245644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=824326126483245644' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/824326126483245644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/824326126483245644'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/another-west-virginia-law-related.html' title='Another West Virginia Law Related Website Compromised'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2738479619396743122</id><published>2009-05-03T06:20:00.006-04:00</published><updated>2009-05-03T07:09:39.231-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='medical devices running windows'/><category scheme='http://www.blogger.com/atom/ns#' term='conflicker'/><category scheme='http://www.blogger.com/atom/ns#' term='FDA'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Update'/><title type='text'>FDA Rule on Appying Windows Patches on Medical Devices Could Put Human Life at Risk</title><content type='html'>One of the scariest uses of Windows OS is that it is installed on medical devices. As a result, every piece of malware coming down the pike can infect this medical devices, putting human life at risk. SANS &lt;a href="http://www.mercurynews.com/breakingnews/ci_12257206"&gt;announced last week&lt;/a&gt; that it had discovered Conficker worm infections on medical devices, including MRI machines.&lt;br /&gt;&lt;blockquote&gt;A few weeks ago, we discovered medical devices, MRI machines, infected with Conficker," said Marcus Sachs, director of the Internet Storm Center, an early warning system for Internet threats that is operated by the SANS Institute.&lt;br /&gt;&lt;br /&gt;Around March 24, researchers monitoring the worm noticed that an imaging machine used to review high-resolution images was reaching out over the Internet to get instructions — presumably from the programmers who created Conficker.&lt;br /&gt;&lt;br /&gt;The researchers dug deeper and discovered that more than 300 similar devices at hospitals around the world had been compromised. The manufacturer of the devices told them none of the machines were supposed to be connected to the Internet — and yet they were. And because the machines were running an unpatched version of Microsoft's operating system used in embedded devices they were vulnerable.&lt;br /&gt;&lt;br /&gt;Normally, the solution would be simply to install a patch, which Microsoft released in October. But the device manufacturer said rules from the U.S. Food and Drug Administration required that a 90-day notice be given before the machines could be patched.&lt;/blockquote&gt;&lt;br /&gt;Yes you read that correctly. Windows patches for medical devices must be approved by the FDA, and the FDA must receive a 90-day notice to apply patches. The result is epic fail that could put human life at risk. This FDA rule needs to be revisited.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2738479619396743122?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2738479619396743122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2738479619396743122' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2738479619396743122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2738479619396743122'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/05/fda-rule-on-appying-windows-patches.html' title='FDA Rule on Appying Windows Patches on Medical Devices Could Put Human Life at Risk'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-9186141510383104467</id><published>2009-04-29T08:09:00.004-04:00</published><updated>2009-04-29T08:20:30.899-04:00</updated><title type='text'>WV State Bar Data Breach</title><content type='html'>The WV State Bar &lt;a href="http://www.wsaz.com/news/headlines/43912207.html"&gt;reported yesterday&lt;/a&gt; that the &lt;a href="http://www.wvbar.org/"&gt;Bar's website&lt;/a&gt; and servers on its internal network have been compromised. The compromised data might include members' names, mail and email addresses, lawyer identification numbers, and the Social Security numbers of some members and former members.&lt;br /&gt;&lt;br /&gt;The Bar says there is no evidence that the information listed above has been used for identity theft or fraud, but that members who have concerns should check their credit reports.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.wvbar.org/"&gt;WV State Bar site&lt;/a&gt; remains offline this morning. The Bar has called in data forensics experts to try to determine the extent of the breach. They are in the process of rebuilding the site from scratch.&lt;br /&gt;&lt;br /&gt;The Bar's website &lt;a href="http://www.charlestondailymail.com/News/200809100161"&gt;first showed signs of problems back in September&lt;/a&gt; when it was blocked by Google's Safe Browsing feature for serving malware.  And I' ve posted about the &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html"&gt;Bar's website hosting malware&lt;/a&gt; earlier this month.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-9186141510383104467?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/9186141510383104467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=9186141510383104467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9186141510383104467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9186141510383104467'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/wv-state-bar-data-breach.html' title='WV State Bar Data Breach'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1908686881423221727</id><published>2009-04-23T08:16:00.004-04:00</published><updated>2009-04-23T08:30:06.970-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Prolaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Thomson'/><category scheme='http://www.blogger.com/atom/ns#' term='Elite'/><title type='text'>Elite User Conference 2009 coming up Jun 9-11</title><content type='html'>Just saw a thread on the &lt;a href="http://tech.groups.yahoo.com/group/prolaw/"&gt;FWMI ProLaw Yahoo Group&lt;/a&gt; about the &lt;a href="http://www.elite.com/uc09/"&gt;Elite User Conference 2009&lt;/a&gt; coming up Jun 9-11 at the Hilton San Diego Bayfront in San Diego, CA. As in past years, Thomson is rolling Prolaw into the Elite Conference.&lt;br /&gt;&lt;br /&gt;Thomson is offering Individual and Multiple Registration discounts:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Receive a $100 discount off the $1,495 Standard Registration Fee when you register before May 8th. That means you attend for just $1,395.&lt;br /&gt;&lt;br /&gt;Multiple Registrations: Register multiple employees before May 8th and receive even more discounts. The second person you register pays only $1,095 and the third person pays just $795!&lt;/blockquote&gt;&lt;br /&gt;It would be nice to see Prolaw have its own user conference again. I'm not sure how useful the Elite Conference is to Prolaw users.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1908686881423221727?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1908686881423221727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1908686881423221727' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1908686881423221727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1908686881423221727'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/elite-user-conference-2009-coming-up.html' title='Elite User Conference 2009 coming up Jun 9-11'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5105093853495623380</id><published>2009-04-23T05:54:00.007-04:00</published><updated>2009-04-23T06:10:45.111-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus2009'/><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Safe Browsing'/><title type='text'>WV State Bar Site Remains Offline After Last Malware Infection</title><content type='html'>The WV State Bar site remains offline today. The site was taken offline last Friday, four days after it was discovered &lt;a href="http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html"&gt;the site was hosting malware&lt;/a&gt; yet again. &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In an email, the Bar published information the site would be offline for maintenance:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;“SPECIAL EDITION BAR BLAST”&lt;br /&gt;&lt;br /&gt;* wvbar.org is currently offline for maintenance&lt;br /&gt;* For Casemaker access, click here - https://demo.lawriter.net &lt;https://demo.lawriter.net&gt;  - login and password are westva (lowercase)&lt;br /&gt;* For registration &amp;amp; other inquiries regarding the 2009 Annual Meeting, please contact Cheryl L. Wright at&lt;br /&gt;cheryl@wvbar.org or 304.558.0828&lt;br /&gt;*For Information regarding pro hac vice admissions, please contact Cheryl L. Wright at cheryl@wvbar.org &lt;mailto:cheryl@wvbar.org&gt;  or&lt;br /&gt;304.558.0828&lt;/mailto:cheryl@wvbar.org&gt;&lt;/https://demo.lawriter.net&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;https://demo.lawriter.net&gt;&lt;mailto:cheryl@wvbar.org&gt;This is the same information currently on the website at &lt;a href="http://www.wvbar.org/"&gt;http://www.wvbar.org/&lt;/a&gt;. It appears the site has been taken down to fix whatever problem was causing the site &lt;a href="http://www.charlestondailymail.com/News/200809100161"&gt;to be compromised&lt;/a&gt; on an almost monthly basis. &lt;/mailto:cheryl@wvbar.org&gt;&lt;/https://demo.lawriter.net&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While my firm has not reported any infections that can be traced to the Bar's website, it remains to be seen if others firms have been so lucky.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5105093853495623380?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5105093853495623380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5105093853495623380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5105093853495623380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5105093853495623380'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-remains-offline-after.html' title='WV State Bar Site Remains Offline After Last Malware Infection'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1036342709991873411</id><published>2009-04-18T05:39:00.003-04:00</published><updated>2009-04-18T05:41:24.381-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Bulletin Webcast Video'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Microsoft April 2009 Security Bulletin Webcast Video</title><content type='html'>In case you missed it, here it is. I signed up for it, but had to miss it.&lt;br /&gt;&lt;br /&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" height="240" width="320"&gt;&lt;br /&gt;&lt;param name="source" value="http://edge.technet.com/App_Themes/default/VideoPlayer2009_01_29.xap"&gt;&lt;br /&gt;&lt;param name="initParams" value="m=mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/6/9/7/2/MSRCwebcastApril09_s_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://mschnlnine.vo.llnwd.net/d1/edge/6/9/7/2/MSRCwebcastApril09_large_edge.png, postid=2796"&gt;&lt;br /&gt;&lt;param name="background" value="#00FFFFFF"&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt;&lt;br /&gt;&lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none;" /&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1036342709991873411?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1036342709991873411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1036342709991873411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1036342709991873411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1036342709991873411'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/microsoft-april-2009-security-bulletin.html' title='Microsoft April 2009 Security Bulletin Webcast Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6257161500094258385</id><published>2009-04-18T04:30:00.003-04:00</published><updated>2009-04-18T04:43:05.725-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Russian Business Network'/><category scheme='http://www.blogger.com/atom/ns#' term='RBN'/><category scheme='http://www.blogger.com/atom/ns#' term='Gozi trojan'/><title type='text'>Video: Gozi trojan</title><content type='html'>A member of my team forwarded &lt;a href="http://www.youtube.com/watch?v=lw9IeuKkNbc"&gt;this video&lt;/a&gt; to me last week. (I'm sorry I can't embed the video. Embedding disabled by request)  The video shows the Russian Business Network (RBN) partners HangUP Team and 76service subscription-based data mining service for stolen data gathered by the Gozi trojan.&lt;br /&gt;&lt;br /&gt;It's another fascinating look a tool build for hacker by hackers for profit rather than fun. For another fascinating look at a current hacking tool, take a look at &lt;a href="http://lawfirmit.blogspot.com/2009/04/symantec-video-using-backdoorghostnet.html"&gt;the GhostNet video&lt;/a&gt; I previously posted.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6257161500094258385?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6257161500094258385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6257161500094258385' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6257161500094258385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6257161500094258385'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/video-gozi-trojan.html' title='Video: Gozi trojan'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2390797465288819614</id><published>2009-04-14T15:07:00.002-04:00</published><updated>2009-04-14T15:11:10.459-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Black Tuesday'/><category scheme='http://www.blogger.com/atom/ns#' term='Updates'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Microsoft Releases Patch Tuesday Advisory</title><content type='html'>There are &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS09-apr.mspx"&gt;eight patches&lt;/a&gt; on tap for tonight. Five are listed as Critical. Two are listed as Important. One is listed as moderate. They all may require restarts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2390797465288819614?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2390797465288819614/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2390797465288819614' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2390797465288819614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2390797465288819614'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/microsoft-releases-patch-tuesday.html' title='Microsoft Releases Patch Tuesday Advisory'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1539506005716449330</id><published>2009-04-13T12:18:00.002-04:00</published><updated>2009-04-14T07:40:28.100-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WV State Bar'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>WV State Bar Site Infected with Malware</title><content type='html'>Google Safe Browsing is blocking access to www.wvbar.org this morning. The diagnostics pages lists 9 scripting exploit, 8 trojan.&lt;br /&gt;&lt;br /&gt;Malicious software is hosted on 3 domain, including v3i9.cn/, nvi3.cn/, said7.com/.&lt;br /&gt;&lt;br /&gt;One domain appear to be functioning as intermediaries for distributing malware to visitors of this site, including tejary.net/.&lt;br /&gt;&lt;br /&gt;This site was hosted on 1 network(s) including AS7795 (NTELOSINC).&lt;br /&gt;&lt;br /&gt;This is &lt;a href="http://www.charlestondailymail.com/News/200809100161"&gt;not the first time&lt;/a&gt; the WV State Bar site has been infected with malware. It happened the first time back in September of 2008.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update&lt;/span&gt;: This issue got resolved overnight. The site isn't hosting malware now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1539506005716449330?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1539506005716449330/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1539506005716449330' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1539506005716449330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1539506005716449330'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/wv-state-bar-site-infected-with-malware.html' title='WV State Bar Site Infected with Malware'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-177718242736353397</id><published>2009-04-11T21:39:00.009-04:00</published><updated>2009-04-12T08:53:37.390-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Twitter StalkDaily Worm'/><title type='text'>Twitter "StalkDaily Worm" (Updated)</title><content type='html'>Twitter &lt;a href="http://mashable.com/2009/04/11/stalkdaily/"&gt;is buzzing&lt;/a&gt; tonight with &lt;a href="http://www.techcrunch.com/2009/04/11/twitter-hit-by-stalkdaily-worm/"&gt;news&lt;/a&gt; of a fast spreading worm.&lt;br /&gt;&lt;span class="status-body"&gt;&lt;span class="entry-content"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/"&gt;Here&lt;/a&gt; is a Postmortem of what's being called the “StalkDaily Worm” by &lt;a href="http://twitter.com/dacort"&gt;&lt;span class="fn"&gt;Damon Cortesi&lt;/span&gt;&lt;/a&gt;: "What’s happening here is that it looks like somebody realized they could save url encoded data to the profile URL field that would not be properly escaped when re-displayed. This is particularly nasty because &lt;strong&gt;you could get infected simply by viewing somebody’s profile page &lt;em&gt;on Twitter&lt;/em&gt; that was already infected&lt;/strong&gt;. If you visited an infected profile, the JavaScript in the profile would execute and by doing so tweet the mis-leading link, and update your profile with the same malicious JavaScript thereby infecting anybody that then visits your profile on twitter.com."&lt;br /&gt;&lt;br /&gt;The&lt;span class="status-body"&gt;&lt;span class="entry-content"&gt; &lt;a href="http://twitter.com/al3x"&gt;Twitter security team&lt;/a&gt; has &lt;a href="http://status.twitter.com/post/95332007/update-on-stalkdaily-com-worm"&gt;deployed a patch&lt;/a&gt; to stop the worm.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update&lt;/span&gt;: F-Secure has a great &lt;a href="http://www.f-secure.com/weblog/archives/00001653.html"&gt;update &lt;/a&gt;including screenshots.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Another Update&lt;/span&gt;: Mikeyy Mooney, the 17-year-old creator of StalkDaily.com&lt;span class="status-body"&gt;&lt;span class="entry-content"&gt;&lt;a href="http://kgmb9.com/main/content/view/16148/76/"&gt; claims responsibility&lt;/a&gt; for the worm. (Yes he spells his name with two y's).&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Yet Another Update:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;a href="http://moretimespace.wordpress.com/2009/04/12/twitter-mickeyy-hack-how-to-fix-avoid/"&gt;Twitter Mikeyy Hack - How to fix &amp;amp; avoid&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-177718242736353397?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/177718242736353397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=177718242736353397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/177718242736353397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/177718242736353397'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/twitter-stalkdaily-worm.html' title='Twitter &quot;StalkDaily Worm&quot; (Updated)'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-28550961024148146</id><published>2009-04-11T13:14:00.000-04:00</published><updated>2009-04-11T13:16:14.855-04:00</updated><title type='text'>Understanding IPSEC</title><content type='html'>&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/DH1zI8QYi4A&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/DH1zI8QYi4A&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-28550961024148146?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/28550961024148146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=28550961024148146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/28550961024148146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/28550961024148146'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/understanding-ipsec.html' title='Understanding IPSEC'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3343346966832428085</id><published>2009-04-08T22:22:00.005-04:00</published><updated>2009-04-08T22:46:50.948-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='John Markoff'/><category scheme='http://www.blogger.com/atom/ns#' term='Dan Farmer'/><category scheme='http://www.blogger.com/atom/ns#' term='Tsutomu Shimomura'/><category scheme='http://www.blogger.com/atom/ns#' term='SATAN'/><category scheme='http://www.blogger.com/atom/ns#' term='Kevin Metnick'/><title type='text'>A piece of hacker history?</title><content type='html'>If this video is what it claims to be, it is truly a piece of his history. The poster of the video writes: "Steals a copy of SATAN, Dan's remote network security probing tool.&lt;br /&gt;&lt;br /&gt;In the course of tracking the attacker(kevin), a great deal of network traffic was captured by a specially modified version of tcpdump (here's information on the legality of the acquisition of this evidence), and then a program written by Tsutomu was used to produce playable logs."&lt;br /&gt;&lt;br /&gt;Kevin is &lt;a href="http://en.wikipedia.org/wiki/Kevin_Mitnick"&gt;Kevin Mitnick&lt;/a&gt; the famous hacker. Dan is &lt;a href="http://en.wikipedia.org/wiki/Dan_Farmer"&gt;Dan Farmer&lt;/a&gt;, one of the developers of &lt;a href="http://en.wikipedia.org/wiki/Security_Administrator_Tool_for_Analyzing_Networks"&gt;SATAN (Security Administrator Tool for Analyzing Networks)&lt;/a&gt; and Tsutomu is &lt;a href="http://en.wikipedia.org/wiki/Tsutomu"&gt;Tsutomu Shimomura&lt;/a&gt;, the security researcher credited with tracking down Kevin Mitnick in 1995.  Shimomura and New York Times reporter &lt;a href="http://en.wikipedia.org/wiki/John_Markoff" title="John Markoff"&gt;John Markoff&lt;/a&gt; wrote a book about Shimomura's pursuit and assistance in the &lt;a href="http://www.wired.com/science/discoveries/news/2007/02/72647"&gt;arrest&lt;/a&gt; of Mitnick. The book is called &lt;a href="http://www.amazon.com/Takedown-Pursuit-Americas-Computer-Outlaw/dp/0786862106/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1239244830&amp;amp;sr=8-1"&gt;Takedown&lt;/a&gt; and is a pretty good read, although most &lt;a href="http://www.spectacle.org/898/mitnick.html"&gt;Mitnick supporters say&lt;/a&gt; the book is mostly a work of fiction and that Shimomura broke into his own computer in order to have an excuse to go after Mitnick.&lt;br /&gt;&lt;br /&gt;This footage appears to be from Feb. 1995 while Tsutomu Shimomura was monitoring Mitnick and shows Mitnick actually breaking into Farmer's computer to steal a copy of SATAN.&lt;br /&gt;&lt;br /&gt;It should be noted that &lt;a href="http://www.youtube.com/watch?v=8_VYWefmy34"&gt;Kevin says&lt;/a&gt; he simply copied software and that he never used any software he copied for any financial gain.&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/69rei214eDE&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/69rei214eDE&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3343346966832428085?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3343346966832428085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3343346966832428085' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3343346966832428085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3343346966832428085'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/piece-of-hacker-history.html' title='A piece of hacker history?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-46100293515376287</id><published>2009-04-05T08:01:00.010-04:00</published><updated>2009-04-05T12:28:01.799-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='ghostnet'/><title type='text'>Symantec Video: Using Backdoor.Ghostnet Toolkit for Attacks</title><content type='html'>Once the exe is built using &lt;a href="https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/malicious_code/article-id/259"&gt;Backdoor.Ghostnet&lt;/a&gt; and installed on the victim computer, it can be controlled using the toolkit built into &lt;a href="http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network"&gt;Backdoor.Ghostnet&lt;/a&gt;. One of the tricks being used by attackers is to view the webcams of the victim computers and view the users actually sitting in front of their keyboards. Rather creepy. It doesn't appear there is anything keeping the attacker from turning on the victim computers built-in microphones as well.&lt;br /&gt;&lt;br /&gt;&lt;object height="395" width="480"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Vz-gg8hxaVQ&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/Vz-gg8hxaVQ&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="295" width="380"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-46100293515376287?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/46100293515376287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=46100293515376287' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/46100293515376287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/46100293515376287'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/04/symantec-video-using-backdoorghostnet.html' title='Symantec Video: Using Backdoor.Ghostnet Toolkit for Attacks'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7832359224342574745</id><published>2009-03-29T14:49:00.001-04:00</published><updated>2009-03-29T14:53:18.751-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conflicker'/><category scheme='http://www.blogger.com/atom/ns#' term='60 Minutes'/><title type='text'>Tonight on 60 Minutes: Conficker and cyber-crime</title><content type='html'>In this video, Lesley Stahl previews her report on computer viruses and cyber crime which airs tonight.&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://www.cbs.com/thunder/swf30can10cbsnews/rcpHolderCbs-3-4x3.swf" flashvars="link=http%3A%2F%2Fwww%2Ecbsnews%2Ecom%2Fvideo%2Fwatch%2F%3Fid%3D4894763&amp;amp;partner=news&amp;amp;vert=News&amp;amp;autoPlayVid=false&amp;amp;releaseURL=http://release.theplatform.com/content.select?pid=OIF1W7h9AnBbgvlOBTmauW6syByuKMzZ&amp;amp;name=cbsPlayer&amp;amp;allowScriptAccess=always&amp;amp;wmode=transparent&amp;amp;embedded=y&amp;amp;scale=noscale&amp;amp;rv=n&amp;amp;salign=tl" allowfullscreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" width="425" height="324"&gt;&lt;/embed&gt;&lt;br /&gt;&lt;a href="http://www.cbs.com/"&gt;Watch CBS Videos Online&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7832359224342574745?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7832359224342574745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7832359224342574745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7832359224342574745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7832359224342574745'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/tonight-on-60-minutes-conficker-and.html' title='Tonight on 60 Minutes: Conficker and cyber-crime'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6439433380532270978</id><published>2009-03-26T17:50:00.004-04:00</published><updated>2009-03-26T18:12:07.951-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vundo'/><title type='text'>XPAntiVirus2009 Morphs Into FileFix Professional 2009</title><content type='html'>I've had a couple of incidents involving &lt;a href="http://en.wikipedia.org/wiki/Vundo"&gt;Vundo&lt;/a&gt; over the past six months. Vundo once posed as antivirus software. A new version of Vundo &lt;a href="http://www.darkreading.com/security/attacks/showArticle.jhtml;jsessionid=PQOE4BMM0EAUSQSNDLPSKHSCJUNN2JVN?articleID=216300413"&gt;has a new trick&lt;/a&gt; up its sleeve. It now extracts money from the infected user by &lt;a href="http://blogs.zdnet.com/security/?p=3014"&gt;encrypting the user files&lt;/a&gt; and asking $40.00 for the tools to decrypt their data.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Obekm8R9tIc/Scv85fmuu9I/AAAAAAAAAGo/hoEWg5xADD0/s1600-h/filefix_pro_2009_scareware.jpg"&gt;&lt;img style="cursor: pointer; width: 306px; height: 64px;" src="http://1.bp.blogspot.com/_Obekm8R9tIc/Scv85fmuu9I/AAAAAAAAAGo/hoEWg5xADD0/s320/filefix_pro_2009_scareware.jpg" alt="" id="BLOGGER_PHOTO_ID_5317621849707690962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There is some good new. There's a free service called &lt;a href="https://filefix.fireeye.com/"&gt;the FileFix File Decrypter&lt;/a&gt; will decrypt the data for free. Score: Bad Guys 1/Good Guys 1.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6439433380532270978?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6439433380532270978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6439433380532270978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6439433380532270978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6439433380532270978'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/xpantivirus2009-morphs-into-filefix.html' title='XPAntiVirus2009 Morphs Into FileFix Professional 2009'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Obekm8R9tIc/Scv85fmuu9I/AAAAAAAAAGo/hoEWg5xADD0/s72-c/filefix_pro_2009_scareware.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8836776970252385306</id><published>2009-03-22T03:54:00.002-04:00</published><updated>2009-03-22T03:56:45.486-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='how to'/><category scheme='http://www.blogger.com/atom/ns#' term='john strand'/><title type='text'>Video: Basic Nessus</title><content type='html'>Another great video by John Strand. I use Nessus on my home network to find and fix vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="302" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=1442767&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=1442767&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="302" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/1442767"&gt;Basic Nessus&lt;/a&gt; from &lt;a href="http://vimeo.com/user595761"&gt;John Strand&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8836776970252385306?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8836776970252385306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8836776970252385306' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8836776970252385306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8836776970252385306'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/video-basic-nessus.html' title='Video: Basic Nessus'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3258091813398380477</id><published>2009-03-21T06:35:00.003-04:00</published><updated>2009-03-21T07:04:01.740-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conflicker'/><title type='text'>Efforts to combat Conficker worm an arms race</title><content type='html'>Combating malware &lt;a href="http://lawfirmit.blogspot.com/2009/03/malware-is-big-money.html"&gt;continues to be an arms race&lt;/a&gt;. The bad guys are always one step ahead.  The majority of malware writers are often well educated, well funded and supported by large criminal organizations like &lt;a href="http://en.wikipedia.org/wiki/Russian_Business_Network"&gt;the Russian Business Network&lt;/a&gt; . The days of teenagers writting malware in their parent's basement are far gone.&lt;br /&gt;&lt;br /&gt;Yesterday came word that &lt;a href="http://www.threatpost.com/blogs/conficker-worm-continues-evolve-confound-researchers"&gt;Conflicker has evolved again&lt;/a&gt;, and continues to find ways to confound and frustrate security researchers. A new &lt;a href="http://mtc.sri.com/Conficker/addendumC/"&gt;analysis of Conficker by SRI International&lt;/a&gt; reports: "In addition to the dual layers of packing and encryption used to protect A and B from reverse engineering, this latest variant also cloaks its newest code segments, along with its latest functionality, under a significant layer of code obfuscation to further hinder binary analysis."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related Story:&lt;/span&gt; &lt;a href="http://lawfirmit.blogspot.com/2009/03/confickerdownadup-evolves.html"&gt;Conficker/Downadup Evolves &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3258091813398380477?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3258091813398380477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3258091813398380477' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3258091813398380477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3258091813398380477'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/efforts-to-combat-conficker-worm-arms.html' title='Efforts to combat Conficker worm an arms race'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7994630219174749660</id><published>2009-03-20T23:23:00.001-04:00</published><updated>2009-03-20T23:25:07.711-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireshark ethereal'/><title type='text'>Basic Wireshark Video</title><content type='html'>Here's another good video from John Strand&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="250" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=1438590&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=1438590&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="250" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/1438590"&gt;Basic Wireshark.&lt;/a&gt; from &lt;a href="http://vimeo.com/user595761"&gt;John Strand&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7994630219174749660?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7994630219174749660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7994630219174749660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7994630219174749660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7994630219174749660'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/basic-wireshark-video.html' title='Basic Wireshark Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4167687167668956123</id><published>2009-03-18T07:50:00.003-04:00</published><updated>2009-03-18T10:49:27.650-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus2009'/><category scheme='http://www.blogger.com/atom/ns#' term='fake antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>New Fake AntiVirus warning screen</title><content type='html'>With looking at this screen closely you might not recognize this is a web page rendered in Firefox. Once gain the bad guys have upped the ante in the high stakes poker game of malware. This particular trick attempts to make the end user believe they are looking at a Windows Explorer screen with warning messages of a large number of trojans and virus infections. It next presents a popup box to entice the user to download the fake antivirus, probably our old friend Antivirus2009.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Obekm8R9tIc/Sb6uTYODFGI/AAAAAAAAAGg/6ZgSn3MB9Go/s1600-h/screenshot.JPG"&gt;&lt;img style="cursor: pointer; width: 403px; height: 301px;" src="http://1.bp.blogspot.com/_Obekm8R9tIc/Sb6uTYODFGI/AAAAAAAAAGg/6ZgSn3MB9Go/s320/screenshot.JPG" alt="" id="BLOGGER_PHOTO_ID_5313876258285884514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Click on the picture of a better view.&lt;br /&gt;&lt;br /&gt;This is another example of how malware writers continue to excelerate the arms race in the battle of keeping users from clicking on things.&lt;br /&gt;&lt;br /&gt;If you see a screen like this kill it from the process viewer. There has been reports clicking anywhere on this screen will cause infection. In this case the user was looking for NCAA brackets using a Google search. Thankfully he called to report the incident before taking any other action.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related Story: &lt;/span&gt;&lt;a href="http://securitylabs.websense.com/content/Alerts/3323.aspx"&gt;NCAA March Madness Malicious Blog Links&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4167687167668956123?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4167687167668956123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4167687167668956123' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4167687167668956123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4167687167668956123'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/new-fake-antivirus-warning-screen.html' title='New Fake AntiVirus warning screen'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Obekm8R9tIc/Sb6uTYODFGI/AAAAAAAAAGg/6ZgSn3MB9Go/s72-c/screenshot.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7939743784198592062</id><published>2009-03-15T14:12:00.004-04:00</published><updated>2009-03-15T14:59:47.335-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireless security'/><category scheme='http://www.blogger.com/atom/ns#' term='dojosec'/><category scheme='http://www.blogger.com/atom/ns#' term='wep'/><title type='text'>Another video on wireless security</title><content type='html'>How easy it really is to crack WEP 128bit encryption?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="300" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3410674&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=3410674&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="300" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/3410674"&gt;DojoSec Monthly Briefings - February 2009 - Jesse Varsalone&lt;/a&gt; from &lt;a href="http://vimeo.com/marcuscarey"&gt;Marcus Carey&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7939743784198592062?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7939743784198592062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7939743784198592062' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7939743784198592062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7939743784198592062'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/another-video-on-wireless-security.html' title='Another video on wireless security'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3059363672033080008</id><published>2009-03-15T09:01:00.003-04:00</published><updated>2009-03-15T15:00:41.758-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nmap'/><category scheme='http://www.blogger.com/atom/ns#' term='PaulDotCom'/><category scheme='http://www.blogger.com/atom/ns#' term='john strand'/><title type='text'>Basic Nmap Video</title><content type='html'>Here's a basic video on how to install and run nmap from SANS instructor and &lt;a href="http://pauldotcom.com/"&gt;PaulDotCom Security Weekly&lt;/a&gt; co-host John Strand.&lt;br /&gt;&lt;br /&gt;&lt;object height="250" width="400"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=1438554&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=1438554&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="250" width="400"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/1438554"&gt;Basic Nmap part 2&lt;/a&gt; from &lt;a href="http://vimeo.com/user595761"&gt;John Strand&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3059363672033080008?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3059363672033080008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3059363672033080008' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3059363672033080008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3059363672033080008'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/basic-nmap-video.html' title='Basic Nmap Video'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1116368438450933629</id><published>2009-03-13T06:11:00.002-04:00</published><updated>2009-03-13T06:18:23.052-04:00</updated><title type='text'>British Law Firms Increase Employee Surveillance</title><content type='html'>Some British law firms have increased employee surveillance in light of economic presures. Many IT managers fear data loss as they fear some employees might be temped to steal data to sell to competitors, Legal Technology Journal &lt;a href="http://www.legaltechnologyjournal.co.uk/content/view/442/62/"&gt;reports&lt;/a&gt;.&lt;br /&gt;&lt;blockquote&gt;IT heads at the top 20 firms admit that they are particularly wary of confidential material being downloaded into a transportable form now that the credit crunch has begun to bite and is costing jobs both internally and among their top financial institution clients.&lt;br /&gt;&lt;br /&gt;At magic circle giant Allen &amp;amp; Overy (A&amp;amp;O), which last month announced jobs cuts affecting 9% of its workforce, IT director Jason Haines said: “Most law firm employees are bound by a professional conduct code but we would be careless if we weren’t being a bit more vigilant.”&lt;br /&gt;&lt;br /&gt;The pressure is arising not only out of concerns that disgruntled employees may download firm precedents and other closely guarded intellectual property, but out of the need to meet a higher security bar imposed by many clients in relation to confidential material.&lt;br /&gt;&lt;br /&gt;Addleshaw Goddard’s head of IT Graham van Terhayden said: “Clients want to do extra audits and are asking more questions about our capability and redoubling their questions.&lt;br /&gt;&lt;br /&gt;“The more clients ask the question, the more we will focus on it.”&lt;br /&gt;&lt;br /&gt;While many of the top firms have long banned access to social networking sites such as Facebook, the majority allow lawyers to use mobile media such as USB keys.&lt;br /&gt;&lt;br /&gt;But where some firms are still monitoring activity on an ad hoc basis, others have rolled out constant surveillance of all employees.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1116368438450933629?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1116368438450933629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1116368438450933629' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1116368438450933629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1116368438450933629'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/british-law-firms-increase-employee.html' title='British Law Firms Increase Employee Surveillance'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8963565243146141765</id><published>2009-03-13T05:05:00.005-04:00</published><updated>2009-03-21T12:32:43.632-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='computer crime'/><title type='text'>Malware is big money</title><content type='html'>My users often ask why people write malware. The simple answer is &lt;a href="http://www.pcworld.com/article/161649/crooks_flock_to_rogue_antivirus_apps.html"&gt;money&lt;/a&gt;. &lt;span style="font-family:tahoma,arial,helvetica,sans-serif;"&gt;There are huge illegal businesses behind this type of &lt;a href="http://en.wikipedia.org/wiki/Cyber_crime"&gt;cyber-crime&lt;/a&gt; and criminal organizations are making a huge profit from identity and data theft. Many of these organizations are based in &lt;a href="http://en.wikipedia.org/wiki/Russian_Business_Network"&gt;Russia&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Red_Hacker_Alliance"&gt;China&lt;/a&gt;. The days of teenagers writing viruses in their parent's basement to impress their online buddies are over. Malware is big money now.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8963565243146141765?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8963565243146141765/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8963565243146141765' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8963565243146141765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8963565243146141765'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/malware-is-big-money.html' title='Malware is big money'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5405152929289508687</id><published>2009-03-13T04:09:00.002-04:00</published><updated>2009-03-13T04:20:41.927-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='downadup/conflicker'/><title type='text'>Conficker/Downadup Evolves</title><content type='html'>Researchers at at Symantec &lt;a href="https://forums2.symantec.com/t5/Malicious-Code/W32-Downadup-C-Digs-in-Deeper/ba-p/393245#A249"&gt;reported last week&lt;/a&gt; that they have found a completely new variant of Conficker, AKA Downadup, last week. The new variant has the ability to disable antimalware tools, switch domains more frequently.&lt;br /&gt;&lt;br /&gt;Dark Reading further&lt;a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml;jsessionid=UWX045CY2YV5GQSNDLPSKH0CJUNN2JVN?articleID=215900041"&gt; reports&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="smalltext"&gt;&lt;p&gt; The new variant, which Symantec calls W32.Downadup.C, appears to have defensive capabilities that weren't present in earlier versions. While it spreads in the same manner, "Conficker.C" can disable some of the tools used to detect and eradicate it, including antivirus and other antimalware detection tools. &lt;/p&gt;&lt;p&gt;W32.Downadup C also can switch domains at a much greater rate, Symantec said. "The Downadup authors have now moved from a 250-a-day domain-generation algorithm to a new 50,000-a-day domain generation algorithm," the researchers reported. "The new domain generation algorithm also uses one of a possible 116 domain suffixes." &lt;/p&gt;&lt;p&gt; A &lt;a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77976" target="new"&gt;report from CA about Conficker.C&lt;/a&gt; confirms Symantec's findings, although the CA researchers said the jump from 500 to 50,000 domains will not occur until April 1. &lt;/p&gt;&lt;p&gt;The ability to quickly switch domains will make it difficult for Internet security organizations, such as ICANN and OpenDNS, to block the domains used by the worm, industry experts note. &lt;/p&gt;&lt;p&gt; The new variant emerges just as some vendors have come out with tools they say will eradicate the worm. &lt;a href="http://www.enigmasoftware.com/" target="new"&gt;today issued a new, free toolz&lt;/a&gt; that it says will remove Conficker.A and Conficker.B from infected machines. A spokesman says the company has begun work on the new variant. And BitDefender also is offering a &lt;a href="http://www.bdtools.net/" target="new"&gt;free tool&lt;/a&gt; it says will remove all variants of the worm.  &lt;/p&gt;&lt;p&gt; Perhaps the most disconcerting aspect of the worm is that although it has reportedly infected hundreds of thousands of machines, it does not, as yet, seem to have a purpose. Although it has been contacting domains and spreading itself through various means, security experts say it has yet to be given a task -- such as distributing spam or launching a DDoS attack -- and researchers are still uncertain as to what it might be used for. &lt;/p&gt;&lt;p&gt;And some experts say there may be other exploits that behave like Conficker/Downadup. "BitDefender Labs has been seeing an increase in worms, like Downadup, that have a built-in mathematical algorithm, generating strings based on the current date," says Vlad Valceanu, BitDefender's senior malware analyst. "The worms then produce a fixed number of domain names on a daily basis and check them for updates. This makes it easy for malware writers and cybercriminals to upgrade a worm or give it a new payload, as they only have to register one of the domains and then upload the files."&lt;/p&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The AV vs virus writer arms race continues. The bad guys always seem to be one step ahead, but with a worm as big as Conficker/Downadup AV researchers are watching this situation closely.&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5405152929289508687?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5405152929289508687/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5405152929289508687' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5405152929289508687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5405152929289508687'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/confickerdownadup-evolves.html' title='Conficker/Downadup Evolves'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-855147481735634260</id><published>2009-03-11T07:30:00.002-04:00</published><updated>2009-03-11T07:42:20.238-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ARP spoofing AV webserver javascript'/><title type='text'>ARP spoofing attacks on web sites</title><content type='html'>SANS&lt;a href="http://isc.sans.org/diary.html?storyid=6001&amp;amp;rss"&gt; reports&lt;/a&gt; attackers are using ARP spoofing to inject malicious JavaScript into content served off other web sites. Using ARP to inject packets is common in cracking wifi keys. In this attack ARP is used to send packets containing fake data to the target.&lt;br /&gt;&lt;blockquote&gt;This is exactly what happened in both incidents I was involved in. A server on a local subnet was compromised and the attacker installed ARP spoofing malware (together with keyloggers and other Trojans) on the machine. The ARP spoofing malware poisoned local subnet so the outgoing traffic was tunneled through it. The same malware then inserted malicious JavaScript into every HTML page served by any server on that subnet. You can see how this is fruitful for the attacker – with one compromised server they can effectively attack hundreds of web sites (if it’s a hoster indeed).&lt;br /&gt;&lt;br /&gt;The ARP spoofing malware they used was relatively common, but still AV detection was miserable with major AV programs missing it (both compromised machines had up to date AV programs installed).&lt;/blockquote&gt;&lt;br /&gt;This is another example of how we cannot &lt;a href="http://www.darkreading.com/security/antivirus/showArticle.jhtml?articleID=215600282&amp;amp;cid=RSSfeed"&gt;depend on antivirus programs&lt;/a&gt; to protect against all threats.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-855147481735634260?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/855147481735634260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=855147481735634260' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/855147481735634260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/855147481735634260'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/arp-spoofing-attacks-on-web-sites.html' title='ARP spoofing attacks on web sites'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-9206182389644221852</id><published>2009-03-08T16:36:00.004-04:00</published><updated>2009-03-08T16:40:31.933-04:00</updated><title type='text'>Scary video: Cracking your WPA/WPA2 catchphrase no clients.</title><content type='html'>This is only for whitebox testing. Cracking WEP or WPA key is illegal.&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://blip.tv/play/AbGuBgA" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="400" height="462"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-9206182389644221852?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/9206182389644221852/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=9206182389644221852' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9206182389644221852'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/9206182389644221852'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/scary-video-cracking-your-wpawpa2.html' title='Scary video: Cracking your WPA/WPA2 catchphrase no clients.'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5675194271109257778</id><published>2009-03-05T21:21:00.002-05:00</published><updated>2009-03-05T21:28:18.777-05:00</updated><title type='text'>No patch coming on Tuesday for Excel zero-day</title><content type='html'>Microsoft has released the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx"&gt;Security Bulletin Advance Notification for March 2009&lt;/a&gt;, but a patch for the recently discovered &lt;a href="http://www.microsoft.com/technet/security/advisory/968272.mspx"&gt;Excel zero-day&lt;/a&gt;  is not included. The &lt;a href="http://blog.security4all.be/2009/03/excel-zero-day-patch-not-included-in.html"&gt;security4all blog&lt;/a&gt; has complete coverage.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5675194271109257778?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5675194271109257778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5675194271109257778' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5675194271109257778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5675194271109257778'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/no-patch-coming-on-tuesday-for-excel.html' title='No patch coming on Tuesday for Excel zero-day'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4251574152950524154</id><published>2009-03-05T21:19:00.001-05:00</published><updated>2009-03-05T21:21:18.107-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='virut'/><category scheme='http://www.blogger.com/atom/ns#' term='virux'/><title type='text'>All my Virut/Virux links in one place</title><content type='html'>All my Virut/Virux links can be found &lt;a href="http://delicious.com/oncee/virut?setcount=25"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4251574152950524154?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4251574152950524154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4251574152950524154' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4251574152950524154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4251574152950524154'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/all-my-virutvirux-links-in-one-place.html' title='All my Virut/Virux links in one place'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-404481636777028967</id><published>2009-03-03T10:41:00.002-05:00</published><updated>2009-03-03T10:50:44.983-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='koobface'/><title type='text'>WORM_KOOBFACE.AZ worm spreading via Facebook and other social networking sites</title><content type='html'>Beware of messages from friends on social networking sites saying “Take a look of this picture of you” or “Check out this video I found of you.”  The links lead to a malicious website that looks like YouTube. You will then bee asked to install a viewer or a new version of flash which is actually the &lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KOOBFACE.AZ"&gt;WORM_KOOBFACE.AZ&lt;/a&gt; worm. The worm will then use your contact list or friends list to send the same fake message to all your friends. The message will look legitimate to them because it will say it’s from you.&lt;br /&gt;&lt;br /&gt;The TrendLabs Malware Blog has&lt;a href="http://blog.trendmicro.com/new-variant-of-koobface-worm-spreading-on-facebook/"&gt; a very good description&lt;/a&gt; of what these fake messages look like and how this thing spreads.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-404481636777028967?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/404481636777028967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=404481636777028967' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/404481636777028967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/404481636777028967'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/wormkoobfaceaz-worm-spreading-via.html' title='WORM_KOOBFACE.AZ worm spreading via Facebook and other social networking sites'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8174882519252202906</id><published>2009-03-02T20:33:00.004-05:00</published><updated>2009-03-02T20:41:53.328-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Vundo'/><title type='text'>Mass mailing worm delivers Trojan.Vundo payload</title><content type='html'>Symantec Security Response &lt;a href="http://www.securityfocus.com/blogs/1720"&gt;reports&lt;/a&gt; that &lt;span class="body"&gt; &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-022520-1425-99&amp;amp;tabid=2" target="_blank"&gt;W32.Ackantta.B@mm&lt;/a&gt; and  &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99&amp;amp;tabid=1" target="_blank"&gt;Trojan.Vundo&lt;/a&gt; infections are on the rise. They also report that Symantec has &lt;/span&gt;&lt;span class="body"&gt;released more aggressive heuristics that detect and block hundreds of &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112111-3912-99&amp;amp;tabid=1" target="_blank"&gt;Trojan.Vundo&lt;/a&gt; variants as a response to the threat.&lt;br /&gt;&lt;br /&gt;They have a nice graph of how the attack vector works.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8174882519252202906?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8174882519252202906/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8174882519252202906' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8174882519252202906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8174882519252202906'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/03/mass-mailing-worm-delivers-trojanvundo.html' title='Mass mailing worm delivers Trojan.Vundo payload'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5327119596050398005</id><published>2009-02-27T04:58:00.004-05:00</published><updated>2009-02-27T05:41:27.931-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDFs'/><category scheme='http://www.blogger.com/atom/ns#' term='fake antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='eWeek'/><category scheme='http://www.blogger.com/atom/ns#' term='mailware servered via adserver'/><title type='text'>Update on compromised adservers serving malware (eWeek/other Ziff Davis Enterprise sites)</title><content type='html'>Websense &lt;a href="http://securitylabs.websense.com/content/Alerts/3310.aspx"&gt;reports&lt;/a&gt; the recent eWeek PDF attack via adservers took no user interaction.&lt;br /&gt;&lt;blockquote&gt;eWeek.com is the online version of the popular business computing magazine.&lt;br /&gt;&lt;br /&gt;When users browse to the home page of eWeek, a malvertisement hosted on the DoubleClick advertisement network performs a redirect to a malicious Web site through a series of iframes. This causes a redirect to one of two files on hxxp://[removed]inside.com/&lt;br /&gt;&lt;br /&gt;Either a pdf document containing exploit code is served, or index.php redirects to the rogue ad-server.&lt;br /&gt;&lt;br /&gt;With no user interaction, a file named "winratit.exe" (MD5: A12DA1D62B7335CBE6D6EA270247BBC1) is installed in the user's temporary files folder. Two additional files are dropped onto the user's machine and are bound to startup. The host file is also modified so that if the user tries to browse to popular software download sites to remedy the infected machine, s/he is instead directed to a malicious Web site offering further rogue AV downloads.&lt;br /&gt;&lt;br /&gt;The name of the rogue AV application is Anti-Virus-1. If the user chooses to register the rogue AV, a connection is made to hxxp://[removed]-site.info/ which has been setup to collect payment details.&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://blog.security4all.be/2009/02/pdf-attacks-are-becoming-more.html"&gt;Security4all says&lt;/a&gt; this isn't the &lt;a href="http://lawfirmit.blogspot.com/2009/02/google-doubleclick-and-akamai-hosting.html"&gt;recent 0-day&lt;/a&gt; &lt;a href="http://lawfirmit.blogspot.com/2009/02/os-x-iphone-and-malformed-jbig2-streams.html"&gt;Adobe Reader PDF exploit&lt;/a&gt; also served by compromised adservers, but a&lt;a href="http://blog.security4all.be/2008/11/monitoring-successful-acrobat-reader.html"&gt; previous one&lt;/a&gt; reported last November. This attack hit eWeek and other Ziff Davis Enterprise site ad servers this week. The goal of this attack is to install fake antivirus software.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5327119596050398005?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5327119596050398005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5327119596050398005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5327119596050398005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5327119596050398005'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/update-on-compromised-adservers-serving.html' title='Update on compromised adservers serving malware (eWeek/other Ziff Davis Enterprise sites)'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1814918369664376243</id><published>2009-02-26T12:03:00.000-05:00</published><updated>2009-02-26T12:04:00.008-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='autorun conflicker cert'/><title type='text'>Microsoft released a patch to correct the "disable autorun registry key" enforcement.</title><content type='html'>The details can be found at this link: http://support.microsoft.com/kb/967715&lt;br /&gt;&lt;br /&gt;This patch is in response to the &lt;a href="http://www.us-cert.gov/cas/techalerts/TA09-020A.html"&gt;Jan. 20 US Cert advisory&lt;/a&gt; that Microsoft Windows does not disable AutoRun properly.&lt;br /&gt;&lt;br /&gt;The Conficker worm spreads via autorun and many other pieces of malware spread via autorun. Disabling autorun is a first line of defense against these sorts of attacks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1814918369664376243?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1814918369664376243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1814918369664376243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1814918369664376243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1814918369664376243'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/microsoft-released-patch-to-correct.html' title='Microsoft released a patch to correct the &quot;disable autorun registry key&quot; enforcement.'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4719958195864579147</id><published>2009-02-26T07:14:00.004-05:00</published><updated>2009-02-26T10:33:46.727-05:00</updated><title type='text'>Google, DoubleClick and Akamai hosting malware</title><content type='html'>I received word yesterday &lt;a href="http://www.internetnews.com/security/article.php/3806696/Supertoxic+Site+Infects+eWeekcom.htm"&gt;via various sources&lt;/a&gt; that Google and DoubleClick are serving malware via ads.&lt;br /&gt;&lt;a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;amp;hl=en-US&amp;amp;site=doubleclick.net/"&gt;&lt;br /&gt;Here's&lt;/a&gt; the Google diagnostic page for DoubleClick.net:&lt;br /&gt;&lt;blockquote&gt;Of the 230717 pages we tested on the site over the past 90 days, 24 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-02-25, and the last time suspicious content was found on this site was on 2009-02-24.&lt;br /&gt;&lt;br /&gt;Malicious software includes 25 scripting exploit(s), 13 trojan(s), 8 adware(s). Successful infection resulted in an average of 9 new processes on the target machine.&lt;br /&gt;&lt;br /&gt;Malicious software is hosted on 7 domain(s), including auctlva.com/, advancedantivirusproscan.com/, liteantivirusproscan.com/.&lt;br /&gt;&lt;br /&gt;3 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including fitnessfactory.com/, me9x.cn/, www-union.com/.&lt;br /&gt;&lt;br /&gt;This site was hosted on 22 network(s) including AS15169 (GOOGLE), AS6432 (DOUBLELCICK), AS20940 (AKAMAI).&lt;/blockquote&gt;&lt;br /&gt;Maybe it's time to block all ads in our environments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4719958195864579147?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4719958195864579147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4719958195864579147' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4719958195864579147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4719958195864579147'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/google-doubleclick-and-akamai-hosting.html' title='Google, DoubleClick and Akamai hosting malware'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7234982552200395292</id><published>2009-02-25T08:32:00.005-05:00</published><updated>2009-02-25T12:14:44.897-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Acrobat'/><category scheme='http://www.blogger.com/atom/ns#' term='SANS JBIG2 stream'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day Mircrosoft'/><title type='text'>OS X , iPhone, and malformed JBIG2 streams</title><content type='html'>SANS Internet Storm Center has an interesting look at the &lt;a href="http://lawfirmit.blogspot.com/2009/02/attackers-using-unpatched-acrobat-flaw.html"&gt;recent&lt;/a&gt; &lt;a href="http://lawfirmit.blogspot.com/2009/02/adobe-zero-day-symantect-says-theyve.html"&gt;Adobe 0-day&lt;/a&gt; and platforms most of us assume are safe: OS X, iPhone, and Linux.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://isc.sans.org/diary.html?storyid=5932&amp;amp;rss"&gt;current version of the pos&lt;/a&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=5932&amp;amp;rss"&gt;t&lt;/a&gt; shows some concerning results when viewing PDFs with a malformed JBIG2 streams with OS X and iPhone PDF viewers.&lt;br /&gt;&lt;br /&gt;SANS promise Linux results soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7234982552200395292?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7234982552200395292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7234982552200395292' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7234982552200395292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7234982552200395292'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/os-x-iphone-and-malformed-jbig2-streams.html' title='OS X , iPhone, and malformed JBIG2 streams'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4126884667891687834</id><published>2009-02-24T09:49:00.005-05:00</published><updated>2009-02-24T10:01:27.609-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDFs'/><category scheme='http://www.blogger.com/atom/ns#' term='spearfishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Acrobat'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day Mircrosoft'/><title type='text'>Attackers using unpatched Acrobat flaw for spearphishing</title><content type='html'>&lt;span class="headline"&gt;Security Focus &lt;a href="http://www.securityfocus.com/brief/912"&gt;reported yesterday&lt;/a&gt; that attackers are using an unpatched Acrobat flaw to target &lt;/span&gt;&lt;span class="body"&gt;high-ranking people including CEO's. The exploit &lt;a href="http://lawfirmit.blogspot.com/2009/02/adobe-zero-day-symantect-says-theyve.html"&gt;reported last week&lt;/a&gt; is still a 0-day since Adobe is yet to release a patch.&lt;br /&gt;&lt;br /&gt;The best defense is not to open PDFs from unknown sources.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4126884667891687834?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4126884667891687834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4126884667891687834' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4126884667891687834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4126884667891687834'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/attackers-using-unpatched-acrobat-flaw.html' title='Attackers using unpatched Acrobat flaw for spearphishing'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2152145919831706786</id><published>2009-02-24T06:29:00.005-05:00</published><updated>2009-02-24T06:45:20.368-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='Mdropper'/><category scheme='http://www.blogger.com/atom/ns#' term='excel. security'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day Mircrosoft'/><title type='text'>Symantec and ZDNet report a new Excel 0-day</title><content type='html'>ZDNet reported yesterday that Symantec has  discovered &lt;a href="http://www.securityfocus.com/bid/33870/discuss"&gt;a remote code-execution vulnerability in Excel 2007 and Excel 2007 SP1&lt;/a&gt;.  It looks like it is being &lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99&amp;amp;tabid=1"&gt;actively exploited in the wild by a variant of the Mdropper trojan&lt;/a&gt;. Attackers can exploit this issue by tricking victims into opening a maliciously crafted Excel file.&lt;br /&gt;&lt;br /&gt;The only defense at this point is not to open Excel files unless you trust the source.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2152145919831706786?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2152145919831706786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2152145919831706786' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2152145919831706786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2152145919831706786'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/symantec-and-zdnet-report-new-excel-0.html' title='Symantec and ZDNet report a new Excel 0-day'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1161814611069351816</id><published>2009-02-23T08:46:00.013-05:00</published><updated>2009-02-23T19:32:04.370-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virut virux security'/><title type='text'>CA says the souce of Virut for some infections might have been MySpace</title><content type='html'>The CA Security Advisor Research Blog &lt;a href="http://community.ca.com/blogs/securityadvisor/archive/2009/02/09/infectious-virut-on-the-loose.aspx"&gt;says&lt;/a&gt; a new infectious version of Virut might have come from MySpace. &lt;a href="http://community.ca.com/blogs/securityadvisor/archive/2009/02/09/infectious-virut-on-the-loose.aspx"&gt;This blog post&lt;/a&gt; is the best technical analysis of Virut, also &lt;a href="http://blog.trendmicro.com/virux-cases-escalate/"&gt;called&lt;/a&gt; Virux by Trend Micro, I've seen. I've posted a number of other bookmarks for information on Virut/Virux on &lt;a href="http://delicious.com/oncee"&gt;delicious&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;There really should be a common naming scheme for viruses and worms. Virux has a number of different names depending on the antivirus vendor: Symantec call it W32.Virut.CF, McAfee calls it W32/Virut.n, Sophos calls it W32/Scribble-A, Microsoft calls it Virus:Win32/Virut.BM, and Trend Mirco calls it Virux. Could this be any more confusing for IT folks and IT security professionals, not to mention non-technical managers?&lt;br /&gt;&lt;br /&gt;By the way, it should be noted that &lt;a href="http://distrowatch.com/table.php?distribution=virux"&gt;Virux is also a Linux distro.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1161814611069351816?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1161814611069351816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1161814611069351816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1161814611069351816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1161814611069351816'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/ca-says-souce-of-virut-for-some.html' title='CA says the souce of Virut for some infections might have been MySpace'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-428944658561708449</id><published>2009-02-23T03:52:00.007-05:00</published><updated>2009-02-23T20:48:55.629-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='zero-day'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='PaulDotCom'/><title type='text'>Adobe Zero-Day, Symantec says they've got it covered</title><content type='html'>SANS Internet Storm Center and Shadowserver &lt;a href="http://isc.sans.org/diary.html?storyid=5902&amp;amp;rss"&gt;report&lt;/a&gt; Adobe Arobat 0-day in the wild. Our friends over at &lt;span class="source"&gt;Symantec say &lt;a href="http://www.securityfocus.com/blogs/1700"&gt;they've got our back&lt;/a&gt;. Estimated time for Adobe to patch is a couple of weeks.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="post-footers"&gt;Larry Pesce over at &lt;a href="http://pauldotcom.com/"&gt;PaulDotCom&lt;/a&gt;&lt;/span&gt; has an &lt;a href="http://pauldotcom.com/2009/02/adobe-0day-and-captain-metadat.html"&gt;interesting post&lt;/a&gt; on how to use metadata as a tool for secuity for auditing this zero-day exploit. He also points out that this problem affects not only Adobe Reader, but also Adobe Standard, Abode Pro, and Adobe Pro Extended releases of versions 7, 8, and 9.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-428944658561708449?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/428944658561708449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=428944658561708449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/428944658561708449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/428944658561708449'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/02/adobe-zero-day-symantect-says-theyve.html' title='Adobe Zero-Day, Symantec says they&apos;ve got it covered'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2233686579640818587</id><published>2009-01-10T16:09:00.007-05:00</published><updated>2009-01-12T00:01:24.649-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='WV State Police. Antivirus2009'/><category scheme='http://www.blogger.com/atom/ns#' term='Fail'/><title type='text'>New WV State Police site infested with malware</title><content type='html'>The Charleston Gazette-Mail &lt;a href="http://www.wvgazette.com/News/200901090709"&gt;reported this morning&lt;/a&gt;  that the WV State Police is in the process of launching a new site to report crime.&lt;br /&gt;&lt;blockquote&gt;CHARLESTON, W.Va. -- It won't replace calls to 911, but the West Virginia State Police soon will launch a Web site that it hopes will make reporting crimes easier.&lt;br /&gt;&lt;br /&gt;The Web site, www.wvcrime.com, will allow the members of the public to submit an anonymous tip or a full-blown crime report, said State Police Sgt. Christopher Casto.&lt;br /&gt;&lt;br /&gt;The site will be ready "in the next few weeks," he said. "It's in the finals stages of testing and setting up."&lt;br /&gt;&lt;br /&gt;The site will cut down on phone calls to the State Police and will allow people to make complaints without talking directly to a trooper, Casto said.&lt;br /&gt;&lt;br /&gt;"We're hoping that people will be more comfortable reporting crimes if they can do it anonymously through their computer," he said.&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://www.wvgazette.com/comments?build=yes&amp;amp;ContID=200901090709"&gt;Readers repor&lt;/a&gt;t when they visit the site that get a message, "Your computer might be infected and to click OK to install Antivirus2009." Hackers have inserted javascript that links to the site that holds the actual malware.&lt;br /&gt;&lt;br /&gt;Antivirus2009 is a &lt;a href="http://www.pcthreat.com/parasitebyid-6947en.html"&gt;very bad piece&lt;/a&gt; of &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-082521-2037-99"&gt;malware&lt;/a&gt; that affects computers running Windows.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I was able to load the site in OS X and Linux earlier this afternoon, but now Google is on the case. When I visit the site now I get a &lt;a href="http://google.com/safebrowsing/diagnostic?tpl=safari&amp;amp;site=e.fissare.net&amp;amp;hl=en-us"&gt;Google Safe Browsing warring&lt;/a&gt; that the site is infected with malware.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Back in September the &lt;a href="http://www.charlestondailymail.com/News/200809100161"&gt;WV State Bar site was blacklisted&lt;/a&gt; for containing malware.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Update&lt;/span&gt;: The malicious java script redirected to a blank page for about a day. It's now redirecting to the malware again. Thanks to my buddy, and former law firm IT director, Paul McNeely who has kept his eye on this and has provided updates.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2233686579640818587?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2233686579640818587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2233686579640818587' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2233686579640818587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2233686579640818587'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/01/new-wv-state-police-site-infested-with.html' title='New WV State Police site infested with malware'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5051601171888983755</id><published>2009-01-10T13:04:00.000-05:00</published><updated>2009-01-10T13:04:57.920-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Weak Passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Dictionary Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><title type='text'>Secure your social networking passwords</title><content type='html'>It amazes me that an 18-year-old hacker can break into a Twitter admin account and start &lt;a href="http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html"&gt;changing the passwords of famous users&lt;/a&gt; with a dictionary attack script. Creating complex passwords is Security 101. Some, including Michael Arrington of TechCrunch, say this breach is proof that &lt;a href="http://www.techcrunch.com/2009/01/05/twitter-gets-hacked-badly/"&gt;Twitter isn't ready for prime time&lt;/a&gt;. I disagree. It's not a Twitter problem. It's a problem of not having a strong password policy and users not picking strong passwords.&lt;br /&gt;&lt;br /&gt;In general strong passwords:&lt;br /&gt;&lt;ul&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;should be&lt;/span&gt; at least seven characters long&lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;should not&lt;/span&gt; contain your user name, real name, or company name&lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;should not&lt;/span&gt; contain a word you can find in the dictionary&lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;should contain&lt;/span&gt; a combination of uppercase and lowercase letters, as well as numeral and symbols&lt;/li&gt;&lt;/ul&gt;Also when changing a password, the new password should be significantly different from the pervious password. Passwords that increment (Password1, Password2, Password3...) are not strong. And passphrases are more secure than passwords. A passphrase is a sequence of words rather than just one password.&lt;br /&gt;&lt;br /&gt;If strong passwords aren't required by the service in question, weak passwords are a user problem and are probably just as much of a problem on other social media sites. One way to address this is to require users to use secure passwords. LiveJournal is an example of a service that now &lt;a href="http://www.livejournal.com/support/faqbrowse.bml?faqid=71&amp;amp;view=full"&gt;requires strong passwords&lt;/a&gt;. In fact, LiveJournal has a stronger password policy than my bank.&lt;br /&gt;&lt;br /&gt;Facebook, on the other hand, &lt;a href="http://www.facebook.com/policy.php"&gt;doesn't appear to have any sort of strong password policy at all&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The other way to address this problem is education. The press that the Twitter data breach have generated will hopefully let the general public know that weak passwords dangerous.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5051601171888983755?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5051601171888983755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5051601171888983755' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5051601171888983755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5051601171888983755'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/01/secure-your-social-networking-passwords.html' title='Secure your social networking passwords'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6549607227671202521</id><published>2009-01-03T14:36:00.003-05:00</published><updated>2009-01-03T14:59:12.446-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mac at 25'/><category scheme='http://www.blogger.com/atom/ns#' term='Macintosh'/><category scheme='http://www.blogger.com/atom/ns#' term='Steve Jobs'/><title type='text'>The Mac turns 25</title><content type='html'>As Dave Winer points out, &lt;a href="http://www.scripting.com/stories/2009/01/03/macAt25.html"&gt;we are nearing &lt;/a&gt;the 25th anniversary of the introduction of the Macintosh. In 1984 I was a undergraduate at Marshall University and I spent hours typing papers on electric typewriters and going through gallons of &lt;a href="http://en.wikipedia.org/wiki/Liquid_Paper"&gt;Liquid Paper Correction Fluid&lt;/a&gt;. When I first got to use a Mac when I entered graduate school in 1990 it was truly a life changing event.&lt;br /&gt;&lt;br /&gt;At the time we were using the Mac Plus to write and edit our college newspaper. If I remember correctly there where 13 of them in the newsroom, including the one at the news editor's desk. When I became managing editor I got to inherit the powerful Mac SE 30 which also had an external hard drive. The Mac Plus booted from a floppy and all your work had to be saved to yet another floppy.&lt;br /&gt;&lt;br /&gt;My first law firm IT job in 1999 was working at a firm who used only Macs. The machines where mainly iMacs and PowerBooks. This was in the days before OS X. OS 9 was a simple system to administer, but not without it's faults.&lt;br /&gt;&lt;br /&gt;Below is a young Steve Jobs introducing the Macintosh on January 24th 1984.&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/LiFb4QC_RWQ&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/LiFb4QC_RWQ&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6549607227671202521?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6549607227671202521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6549607227671202521' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6549607227671202521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6549607227671202521'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/01/mac-turns-25.html' title='The Mac turns 25'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-809028492983954430</id><published>2009-01-03T10:33:00.009-05:00</published><updated>2009-01-03T11:11:16.497-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='disgruntled ex-employee'/><category scheme='http://www.blogger.com/atom/ns#' term='disaster recovery'/><category scheme='http://www.blogger.com/atom/ns#' term='business continuituy'/><category scheme='http://www.blogger.com/atom/ns#' term='disgruntled employee'/><category scheme='http://www.blogger.com/atom/ns#' term='backups'/><category scheme='http://www.blogger.com/atom/ns#' term='insider threat'/><title type='text'>Disgruntled ex-employee takes JournalSpace offline for good</title><content type='html'>There are posts from &lt;a href="http://www.techcrunch.com/2009/01/03/journalspace-drama-all-data-lost-without-backup-company-deadpooled/"&gt;TechCrunch&lt;/a&gt; and &lt;a href="http://hardware.slashdot.org/article.pl?sid=09%2F01%2F02%2F1546214&amp;amp;from=rss"&gt;Slashdot&lt;/a&gt; this morning about the blogging service JournalSpace being completely taken offline as a result of a malicious act from a disgruntled ex-employee. According to the &lt;a href="http://journalspace.com/blog/"&gt;JournalSpace blog&lt;/a&gt; the employee in question decided to depend on RAID as the only backup of the SQL database of users posts. As pointed out the the Slashdot headline, &lt;a href="http://hardware.slashdot.org/article.pl?sid=09%2F01%2F02%2F1546214&amp;amp;from=rss"&gt;Mirroring is Not a Backup Solution&lt;/a&gt;, and any IT employee worth their salt should know this.&lt;br /&gt;&lt;br /&gt;The Slashdot story says: &lt;blockquote&gt;The site had been in business since 2002 and had an &lt;a href="http://www.alexa.com/data/details/main/journalspace.com"&gt;Alexa page rank&lt;/a&gt; of 106,881. Quantcast said they had &lt;a href="http://www.quantcast.com/journalspace.com"&gt;14,000 monthly visitors&lt;/a&gt; recently. No word on how many thousands of bloggers' entire output has evaporated.&lt;/blockquote&gt;According to the &lt;a href="http://journalspace.com/blog/"&gt;JournalSpace blog&lt;/a&gt; and also reported by TechCrunch: &lt;blockquote&gt;It was the guy handling the IT (and, yes, the same guy who I caught stealing from the company, and who did a slash-and-burn on some servers on his way out) who made the choice to rely on RAID as the only backup mechanism for the SQL server. He had set up automated backups for the HTTP server which contains the PHP code, but, inscrutibly, had no backup system in place for the SQL data. The ironic thing here is that one of his hobbies was telling everybody how smart he was.&lt;/blockquote&gt;This story should be a reminder that every organization should have a backup, disaster recovery and business continuity plan. It is also important to have a plan to deal with insiders threats and not let one person make all the decisions about backup, disaster recovery, and business continuity.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-809028492983954430?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/809028492983954430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=809028492983954430' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/809028492983954430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/809028492983954430'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2009/01/disgruntled-ex-employee-takes.html' title='Disgruntled ex-employee takes JournalSpace offline for good'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6426281666781752530</id><published>2008-12-10T00:42:00.004-05:00</published><updated>2008-12-10T00:58:35.655-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Network Scan'/><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='iPhone App'/><category scheme='http://www.blogger.com/atom/ns#' term='Sys Admin'/><title type='text'>Snap: iPhone app that will scan your wireless network for hosts</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Obekm8R9tIc/ST9W5lJAOzI/AAAAAAAAAFk/x9Jnt1A8x8g/s1600-h/icon100x100.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 100px; height: 100px;" src="http://4.bp.blogspot.com/_Obekm8R9tIc/ST9W5lJAOzI/AAAAAAAAAFk/x9Jnt1A8x8g/s320/icon100x100.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5278032835523918642" /&gt;&lt;/a&gt;Ever wondered if someone has cracked your WEP key and is using your wireless network? Ever wondered if who else is using the free wireless at the local coffee shop? Snap is an iPhone app that will scan a wireless network and tell you who else is using the wireless access point, which can be very useful for network administrators. &lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Below are some screenshots of my home wireless network.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Scanning Wireless Area Network&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/oncee/3097334592/" title="photo.jpg by oncee, on Flickr"&gt;&lt;img src="http://farm4.static.flickr.com/3238/3097334592_9fa385d10b_o.jpg" width="320" height="480" alt="photo.jpg" /&gt;&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Host List/Scan Results&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/oncee/3097335658/" title="photo.jpg by oncee, on Flickr"&gt;&lt;img src="http://farm4.static.flickr.com/3178/3097335658_e5ca5327a1_o.jpg" width="320" height="480" alt="photo.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Host Information&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/oncee/3097336610/" title="photo.jpg by oncee, on Flickr"&gt;&lt;img src="http://farm4.static.flickr.com/3242/3097336610_be6281ac7f_o.jpg" width="320" height="480" alt="photo.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Host Services&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/oncee/3096497921/" title="photo.jpg by oncee, on Flickr"&gt;&lt;img src="http://farm4.static.flickr.com/3239/3096497921_3baec48519_o.jpg" width="320" height="480" alt="photo.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Snap is $1.99 for the iTunes App Store&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6426281666781752530?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6426281666781752530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6426281666781752530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6426281666781752530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6426281666781752530'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/12/snap-iphone-app-that-will-scan-your.html' title='Snap: iPhone app that will scan your wireless network for hosts'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Obekm8R9tIc/ST9W5lJAOzI/AAAAAAAAAFk/x9Jnt1A8x8g/s72-c/icon100x100.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6966185759781753208</id><published>2008-12-09T19:39:00.003-05:00</published><updated>2008-12-09T19:46:16.914-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Update Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Tuesday'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Update'/><category scheme='http://www.blogger.com/atom/ns#' term='WSUS'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>December Black Tuesday Overview</title><content type='html'>SANS has issued its &lt;a href="http://isc.sans.org/diary.html?storyid=5449&amp;amp;rss"&gt;December Black Tuesday Overview&lt;/a&gt;. Microsoft is will be hosting a webcast to address customer questions on these bulletins on December 10, 2008, at 11:00 AM Pacific Time. Click &lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;amp;EventID=1032374647"&gt;here&lt;/a&gt; to register for the December Security Bulletin Webcast&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6966185759781753208?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6966185759781753208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6966185759781753208' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6966185759781753208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6966185759781753208'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/12/december-black-tuesday-overview.html' title='December Black Tuesday Overview'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7239589374172739408</id><published>2008-10-07T22:31:00.001-04:00</published><updated>2008-10-07T22:34:48.671-04:00</updated><title type='text'>West Virginia e-Discovery Conference</title><content type='html'>&lt;span style=""&gt;The West Virginia e-Discovery Conference is on the campus of the Marshall University Forensics Science Center in Huntington, WV on Oct. 28 from 8:30 a.m. to 4:30 p.m. &lt;/span&gt;&lt;span style=""&gt;Second Creek Technologies LLC and Marshall University are offering a full day of training focusing on electronic discovery and forensics topics. &lt;/span&gt;&lt;br /&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=""&gt;John Sammons, CEO of Second Creek, says, &lt;/span&gt;&lt;span style=""&gt;"This is the first of an annual event that we plan to put on every year. We plan to bring in experts and practitioners from around the state to help keep the legal community -- and their clients -- up to speed on the growing field of electronic discovery and computer forensics. We also view this as an opportunity for academia as well. Students and professors can also benefit.&lt;br /&gt;&lt;br /&gt;"This event will provide a bridge for the students and faculty to the front lines of electronic discovery and computer forensics. They will get to hear, first hand, from practitioners in the field about the current challenges they face and how they are conquering them."&lt;br /&gt;&lt;br /&gt;The cost of the event is $180 per person. Lunch and a ticket to the Thundering Herd's football game against Houston later that day are also included.&lt;br /&gt;&lt;br /&gt;Topics include:&lt;br /&gt;&lt;br /&gt;* E-Discovery Response Teams - Brian M. Peterson Esq., Bowles, Rice, McDavid, Graff &amp;amp; Love LLP&lt;br /&gt;&lt;br /&gt;* An Introduction to Internet Evidence - Sammons and David Irvin, COO, Second Creek Technologies LLC&lt;br /&gt;&lt;br /&gt;* E-Discovery Costs - Mathew Nelson, Esq., Jackson Kelly PLLC&lt;br /&gt;&lt;br /&gt;* Ethical Duties of Attorneys in e-Discovery - Jill McIntyre, Esq., and Erin Stankewicz, Esq., Jackson Kelly PLLC&lt;br /&gt;&lt;br /&gt;* E-Discovery Case Law Update - Ray Shepard, Esq., Corporate Counsel, Second Creek Technologies LLC&lt;br /&gt;&lt;br /&gt;* Digital Evidence Collection, Transport and Storage: Getting It Right - Dr. Terry Fenger, Director, Marshall University Forensic Science Center&lt;br /&gt;&lt;br /&gt;* Getting the e-Stuff: Using the Rules in e-Discovery - David Duffield, Esq., Duffield &amp;amp; Lovejoy PLLC&lt;br /&gt;&lt;br /&gt;The West Virginia CLE credit is pending for this training.&lt;br /&gt;&lt;br /&gt;For more information or to register for this conference, call (304) 736-5454 or (877) 523-3253 or go to &lt;a href="http://mail.fsblaw.com/exchweb/bin/redir.asp?URL=http://www.2ndcreek.net/discovery/ediscoveryconf.html" target="_blank"&gt;&lt;span style=""&gt;www.2ndcreek.net/discovery/ediscoveryconf.html&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7239589374172739408?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7239589374172739408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7239589374172739408' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7239589374172739408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7239589374172739408'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/10/west-virginia-e-discovery-conference.html' title='West Virginia e-Discovery Conference'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8105014388088585941</id><published>2008-10-02T09:47:00.000-04:00</published><updated>2008-10-02T09:49:10.346-04:00</updated><title type='text'>Help Wanted -Application Support Specialist</title><content type='html'>Flaherty, Sensabaugh &amp;amp; Bonasso, PLLC, a law firm with offices in West Virginia is seeking a service-oriented individual to fill the position of Application Support Specialist in our Charleston, WV office.&lt;br /&gt;&lt;br /&gt;The position will provide software training and support to lawyers and staff, and will work closely with other IT positions to troubleshoot and resolve problems. The successful candidate will be a friendly self-starter who enjoys supporting users of various skill levels in a busy work environment.&lt;br /&gt;&lt;br /&gt;A high level of proficiency with the MS Office Suite and Windows XP, and the ability to quickly learn and support other legal applications, including document management, case management and litigation support software is required for this position.&lt;br /&gt;&lt;br /&gt;Please respond by submitting a cover letter, resume and salary history to Human Resources, P.O. Box 3843, Charleston, WV 25338 or via email to rdayfield@fsblaw.com.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8105014388088585941?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8105014388088585941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8105014388088585941' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8105014388088585941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8105014388088585941'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/09/help-wanted.html' title='Help Wanted -Application Support Specialist'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-946094092699521891</id><published>2008-08-14T15:31:00.003-04:00</published><updated>2008-08-14T15:56:50.182-04:00</updated><title type='text'>General Policy  - Virtualization of Elite Products</title><content type='html'>Thomson Elite has released an official policy regarding &lt;a href="http://www.elite.com/supportservices/elite/VirtualizationEliteServers.htm"&gt; - Virtualization of Elite Products&lt;/a&gt; including Prolaw.&lt;br /&gt;&lt;blockquote&gt;1.1 General Policy&lt;br /&gt;Thomson Elite generally recommends against using virtualization environments (e.g., Virtual Machines from VMware or Microsoft Virtual Server) for primary production servers hosting Thomson Elite products.&lt;br /&gt;&lt;br /&gt;Thomson Elite makes no performance warranties in relation to Thomson Elite applications hosted on Virtual Machines.&lt;br /&gt;&lt;br /&gt;The use of Virtual Machines for test and disaster recovery (DR) environments may be appropriate, provided customers understand and accept sole responsibility for any performance issues related to virtualization.&lt;br /&gt;&lt;br /&gt;1.2 Behind the Policy&lt;br /&gt;While use of Virtual Machines can be an excellent way to consolidate server functions onto fewer boxes and reduce the time hardware is idle, the effectiveness of such consolidation relies, in part, on the functions consolidated either not requiring full CPU utilization or requiring it at different times. Since many Thomson Elite applications tend to share the same peak load times (e.g., month-end accounting), it is difficult to capitalize on the strengths of Virtual Machines without at least as much hardware as is recommend by Thomson Elite.&lt;br /&gt;&lt;br /&gt;1.3 Production Use Against Recommendation&lt;br /&gt;Customers running virtual environments for primary production use, against Thomson Elite’s recommendations, and who require support for performance issues related to using Virtual Machines, will be charged at standard support rates.&lt;br /&gt;&lt;br /&gt;Thomson Elite will not be responsible for the performance of products running on Virtual Machines, since they fail to meet the requirements established by Thomson Elite.&lt;br /&gt;&lt;br /&gt;1.4 Virtualization Performance Concerns&lt;br /&gt;&lt;br /&gt;1.4.1 Processor Performance&lt;br /&gt;In addition to the hardware that Thomson Elite recommends for an appropriate level of performance, software which allows the use of Virtual Machines imposes an additional overhead which can reduce performance by 15-20 percent or more in some cases.&lt;br /&gt;&lt;br /&gt;1.4.2 Disk I/O Performance&lt;br /&gt;In addition to processor cycles that may be consumed as overhead by the use of Virtual Machines, Disk I/O performance is also impacted by the added layer of virtualization. As a point of reference, using Microsoft’s SQLIO tool, limited testing on directly attached storage consisting of a six (6) spindle RAID 10 array, revealed the following:&lt;br /&gt;&lt;br /&gt;  * VMware ESX Server 2.5.2 imposed approximately a 15% sequential read performance penalty using a virtual SCSI disk.&lt;br /&gt;  * VMware GSX Server 3.2 imposed approximately a 20% sequential read performance penalty using a direct connection to the physical array.&lt;br /&gt;  * Microsoft Virtual Server 2005 imposed over a 30% sequential read performance penalty using a virtual SCSI disk.&lt;br /&gt;  * Microsoft Virtual Server 2005 imposed nearly a 70% read performance penalty using a virtual IDE disk.&lt;br /&gt;&lt;br /&gt;1.5 Virtualization Products&lt;br /&gt;While Thomson Elite recommends against Virtual Machines in primary production use, those customers who choose to proceed with virtual environments where “Not Recommended,, may find the following virtualization products more suitable than desktop versions, such as VMware Workstation or Microsoft Virtual PC: VMware GSX Server 3.2 (or VMware Server, the free successor to GSX Server expected in Q2 2006)&lt;br /&gt;&lt;br /&gt;  * VMware ESX Server 2.5&lt;br /&gt;  * Virtual Server 2005 Standard Edition&lt;br /&gt;  * Virtual Server 2005 Enterprise Edition&lt;br /&gt;&lt;br /&gt;1.6 Future of Virtualization&lt;br /&gt;Thomson Elite is aware of the growing popularity of virtualized solutions and will continue to evaluate it as the market, technology, supporting hardware and underlying platforms mature. &lt;/blockquote&gt;&lt;br /&gt;I've been told by other users that if you go ahead and run Prolaw on a virtual platform and have any sort of performance problem, the first thing Prolaw support will do is tell you to move the server from the virtual platform back to a physical server.&lt;br /&gt;&lt;br /&gt;Does anyone have any experience running Prolaw in a virtualized environment?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-946094092699521891?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/946094092699521891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=946094092699521891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/946094092699521891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/946094092699521891'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/08/general-policy-virtualization-of-elite.html' title='General Policy  - Virtualization of Elite Products'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4256398503140395044</id><published>2008-07-25T12:15:00.000-04:00</published><updated>2008-07-25T12:15:55.305-04:00</updated><title type='text'>System Administrator Appreciation Day</title><content type='html'>Happy &lt;a href="http://www.sysadminday.com/"&gt;System Administrator Appreciation Day&lt;/a&gt; to all you law firm IT and other IT folks out there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4256398503140395044?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.sysadminday.com/' title='System Administrator Appreciation Day'/><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4256398503140395044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4256398503140395044' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4256398503140395044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4256398503140395044'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/system-administrator-appreciation-day.html' title='System Administrator Appreciation Day'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3738024308088563175</id><published>2008-07-24T08:31:00.001-04:00</published><updated>2008-07-24T08:31:40.415-04:00</updated><title type='text'>Check you DNS server</title><content type='html'>Is the DNS server you use safe?&lt;br /&gt;&lt;blockquote&gt;Recently, a significant threat to DNS, the system that translates names you can remember (such as www.doxpara.com) to numbers the Internet can route (66.240.226.139) was discovered, that would allow malicious people to impersonate almost any website on the Internet. Software companies across the industry have quietly collaborated to simultaneously release fixes for all affected name servers.&lt;/blockquote&gt;&lt;br /&gt;You can run a check at &lt;a href="http://www.doxpara.com/"&gt;on this page&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3738024308088563175?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3738024308088563175/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3738024308088563175' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3738024308088563175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3738024308088563175'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/check-you-dns-server.html' title='Check you DNS server'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8087614288723319723</id><published>2008-07-22T15:24:00.000-04:00</published><updated>2008-07-22T15:24:12.622-04:00</updated><title type='text'>ISP operator need to patch their recursive DNS servers now</title><content type='html'>SANS&lt;a href="http://isc.sans.org/diary.html?storyid=4765&amp;amp;rss"&gt; reports&lt;/a&gt; information about the DNS bug discovered by security researcher Dan Kaminsky is now public knowledge and recursive DNS server should be patched immediately.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8087614288723319723?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isc.sans.org/diary.html?storyid=4765&amp;rss' title='ISP operator need to patch their recursive DNS servers now'/><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8087614288723319723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8087614288723319723' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8087614288723319723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8087614288723319723'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/isp-operator-need-to-patch-their.html' title='ISP operator need to patch their recursive DNS servers now'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8359784717530546923</id><published>2008-07-15T11:53:00.005-04:00</published><updated>2008-07-16T11:06:11.657-04:00</updated><title type='text'>Internal Threats: the Disgruntled Employee</title><content type='html'>The strong passwords and other security measure will not keep out the most danger threat to network security will not keep out the most dangerous threat: disgruntled employees.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;SFGate&lt;/i&gt;, the web home of the &lt;i&gt;San Francisco Chronicle&lt;/i&gt; &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL"&gt;has the scary story&lt;/a&gt; of how a disgruntled city computer consultant has taking over San Francisco's new  multimillion-dollar computer network by changing the admin passwords and refusing to had over the new passwords.&lt;br /&gt;&lt;blockquote&gt;(07-14) 19:23 PDT SAN FRANCISCO -- A disgruntled city computer engineer has virtually commandeered San Francisco's new multimillion-dollar computer network, altering it to deny access to top administrators even as he sits in jail on $5 million bail, authorities said Monday.&lt;br /&gt;&lt;br /&gt;Terry Childs, a 43-year-old computer network administrator who lives in Pittsburg, has been charged with four counts of computer tampering and is scheduled to be arraigned today.&lt;br /&gt;&lt;br /&gt;Prosecutors say Childs, who works in the Department of Technology at a base salary of just over $126,000, tampered with the city's new FiberWAN (Wide Area Network), where records such as officials' e-mails, city payroll files, confidential law enforcement documents and jail inmates' bookings are stored.&lt;br /&gt;&lt;br /&gt;Childs created a password that granted him exclusive access to the system, authorities said. He initially gave pass codes to police, but they didn't work. When pressed, Childs refused to divulge the real code even when threatened with arrest, they said.&lt;br /&gt;&lt;br /&gt;He was taken into custody Sunday. City officials said late Monday that they had made some headway into cracking his pass codes and regaining access to the system.&lt;/blockquote&gt;&lt;br /&gt;&lt;strike&gt;I though it was interesting that the guy actually lives in Pittsburgh. I'm sure that make this incident, as bad as it already is, a federal crime as well.&lt;/strike&gt; Oops wrong Pittsburg, as pointed out in the comments, "Pittsburg (no "h") is a town about 40 miles east-northeast of San Francisco."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8359784717530546923?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8359784717530546923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8359784717530546923' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8359784717530546923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8359784717530546923'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/internal-threats-disgruntled-employee.html' title='Internal Threats: the Disgruntled Employee'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1841530468087998518</id><published>2008-07-09T15:58:00.002-04:00</published><updated>2008-07-09T18:27:35.834-04:00</updated><title type='text'>Legal IT vs. Corporate IT</title><content type='html'>&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Here's a very interesting post from Prism Legal that explores the difference between &lt;a href="http://prismlegal.com/wordpress/index.php?m=200807#post-818"&gt;Legal IT versus Corporate IT&lt;/a&gt;. The content is the result of a panel discussion at the &lt;a href="http://www.legalweek.com/events/details.aspx?liEventID=1082460"&gt;Strategic Technology Forum in Lisbon, hosted by LegalWeek&lt;/a&gt; last month.&lt;br /&gt;&lt;br /&gt;Here's the panelist list of differences:&lt;br /&gt;&lt;blockquote&gt;* In legal it’s about words; in corporate it’s about numbers. This makes a big difference in how CIOs present business cases to management.&lt;br /&gt;* Lawyers resist change, industry embraces it.&lt;br /&gt;* Corporate management asks “what’s the business case?” Law firm management asks “what are other firms doing?”&lt;br /&gt;* Legal market software suppliers are few; corporate many. A corollary: legal software vendors are less innovative.&lt;br /&gt;* Corporations do zero-based budgeting, meaning CIOs have to justify items each year. In law firms, budgeting is a continuous and incremental process without the need to justify each year.&lt;br /&gt;* “There is no PowerPoint in law firms.”&lt;/blockquote&gt;&lt;br /&gt;The panelists were David Coates, IT Director of Bond Pearce and formerly of UBS; Jason Haines, Director of IT, Allen &amp;amp; Overy LLP and formerly of PricewaterhouseCoopers (PWC); and Malcolm Simms, IT Director, Eversheds LLP and formerly of Disney/ABC Television Group.&lt;br /&gt;&lt;br /&gt;I think they did a great job of pointing out the differences, but I didn't understand "There is no PowerPoint in law firms."&lt;br /&gt;&lt;br /&gt;The Prism Legal, Ron, goes on to say:&lt;br /&gt;&lt;blockquote&gt;All of these resonated with me. One comment on “no PPT in law firms.” I think this difference has a deeper meaning than many may think. Presentations are not just about content; they are about guiding or controlling a conversation. When I started as a manager in a large law firm, I met frequently with the management committee to discuss tech projects. Discussions wandered and were, as a consequence, often unproductive. So I decided to use a presentation as a way to help guide the discussion. The resistance to my doing so was palpable. I wish I had had a chance to pose this hypothesis to the panelists for confirmation or rejection.&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1841530468087998518?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1841530468087998518/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1841530468087998518' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1841530468087998518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1841530468087998518'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/legal-it-vs-corporate-it.html' title='Legal IT vs. Corporate IT'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2987979049801057240</id><published>2008-07-07T11:29:00.001-04:00</published><updated>2008-07-07T11:29:43.766-04:00</updated><title type='text'>Testing Sazell</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;For more information see &lt;a href='http://www.techcrunch.com/2008/07/07/sazell-lets-you-snap-the-web/'&gt;this TechCrunch story&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;div class='youtube-video'&gt;&lt;object height='160' align='middle' width='370' id='Snapshot'&gt;&lt;param value='sameDomain' name='allowScriptAccess'&gt; &lt;/param&gt;&lt;param value='false' name='allowFullScreen'&gt; &lt;/param&gt;&lt;param value='http://sazell.com/Flash/Snapshot.swf' name='movie'&gt; &lt;/param&gt;&lt;param value='high' name='quality'&gt; &lt;/param&gt;&lt;param value='#333333' name='bgcolor'&gt; &lt;/param&gt;&lt;param value='sid=231' name='flashvars'&gt; &lt;/param&gt;&lt;embed height='160' align='middle' width='370' type='application/x-shockwave-flash' allowfullscreen='false' allowscriptaccess='sameDomain' flashvars='sid=231' name='Snapshot' bgcolor='#333333' quality='high' src='http://sazell.com/Flash/Snapshot.swf'&gt; &lt;/embed&gt;  &lt;/object&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2987979049801057240?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2987979049801057240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2987979049801057240' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2987979049801057240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2987979049801057240'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/testing-sazell.html' title='Testing Sazell'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1919514417071311496</id><published>2008-07-03T13:47:00.001-04:00</published><updated>2008-07-06T14:42:39.105-04:00</updated><title type='text'>Social Media in Law Firms</title><content type='html'>&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Why are there no large law firms listed on &lt;a href="http://www.web-strategist.com/blog/2008/06/20/list-of-social-computing-strategists-and-community-managers-for-large-corporations-2008/"&gt;this list&lt;/a&gt;? Are large law firm's engaged in social medial beyond blogging?&lt;br /&gt;&lt;br /&gt;Jeremiah Owyang of Forrester writes:&lt;br /&gt;&lt;blockquote&gt;Understanding how companies staff, organize, and prepare for social media/computing is one of my top interests personally and professionally. Having been a former Online Community Manager at Hitachi Data Systems, I want to make sure companies do it right. I’m often asked which companies have one of the two emerging roles, (companies love to benchmark against their peers) so I’ve decided to start a list.&lt;br /&gt;&lt;br /&gt;The first role is the Social Computing Strategist, the second is the Community Manager, although the titles vary, and sometimes it’s a part-time function, there’s clearly a trend as corporations staff.&lt;br /&gt;&lt;br /&gt;It’s important to note, that in the end, these skills (the ability to communicate online) will disperse and grow to many employees. Generation Y comes to us with these abilities built it as a “digital natives”– yet the need to organize will still occur, it’s a knee jerk reaction to every corporation.&lt;/blockquote&gt;&lt;br /&gt;Is there room for social media in law firms, both large and small?&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1919514417071311496?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1919514417071311496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1919514417071311496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1919514417071311496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1919514417071311496'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/social-media-in-law-firms.html' title='Social Media in Law Firms'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4815405537068859759</id><published>2008-07-01T20:37:00.001-04:00</published><updated>2008-07-01T20:37:26.661-04:00</updated><title type='text'>Microsoft Remote Desktop Connection 2 is now out of beta</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;The Unofficial Apple Weblog &lt;a href='http://www.tuaw.com/2008/07/01/microsoft-remote-desktop-connection-2-now-available/'&gt;reports&lt;/a&gt; Microsoft Remote Desktop Connection 2 is now out of beta.&lt;br/&gt;&lt;blockquote&gt;This is news that is certain to make Mac based Windows Admins (of which I am one) very happy: &lt;a href='http://www.microsoft.com/mac/products/remote-desktop/default.mspx'&gt;Microsoft Remote Desktop Connection 2&lt;/a&gt; is finally out of beta. The final release includes all the new features that Microsoft added, some of the highlights include:&lt;br/&gt;&lt;br/&gt;    * The ability to open multiple instances of Remote Desktop without resorting to a hack (though I do believe that each connection spawns a new instance of the app itself).&lt;br/&gt;    * Redesigned UI&lt;br/&gt;    * Support for Network Level Authentication (which makes connections more secure)&lt;br/&gt;&lt;br/&gt;You can get more info about this release from the MacBU &lt;a href='http://www.officeformac.com/blog/RDC-2-is-out-of-beta-and-available-today'&gt;blog post&lt;/a&gt;.&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4815405537068859759?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4815405537068859759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4815405537068859759' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4815405537068859759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4815405537068859759'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/07/microsoft-remote-desktop-connection-2.html' title='Microsoft Remote Desktop Connection 2 is now out of beta'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4159466641822631642</id><published>2008-06-26T13:13:00.003-04:00</published><updated>2008-06-26T13:51:41.601-04:00</updated><title type='text'>Practice Management goes Web 2.0</title><content type='html'>Practice Management moves into the &lt;a href="http://en.wikipedia.org/wiki/Cloud_computing"&gt;cloud&lt;/a&gt; with a product called &lt;a href="http://goclio.com/"&gt;clio&lt;/a&gt;. The service is currently in private beta. Depending on the level of service you &lt;a href="http://goclio.com/signup.html"&gt;sign up&lt;/a&gt; for, clio offers client and file management, timesheet and activity tracking time reporting and exporting, performance analysis and reporting, calendaring and reminders, multi-user access, SSL encryption and secured data storage, client billing and invoice generation, and document management.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4159466641822631642?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4159466641822631642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4159466641822631642' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4159466641822631642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4159466641822631642'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/practice-management-goes-web-20.html' title='Practice Management goes Web 2.0'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7153188034867304382</id><published>2008-06-22T18:00:00.001-04:00</published><updated>2008-06-22T18:00:29.143-04:00</updated><title type='text'>LEXBLOG soft launches LexMonitor</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;a href='http://www.lexblog.com/'&gt;LEXBLOG&lt;/a&gt; has soft launched &lt;a href='http://www.lexmonitor.com/'&gt;LexMonitor&lt;/a&gt;, a US blawg portal, according LEXBLOG chief Kevin O'Keefe on&lt;a href='http://kevin.lexblog.com/2008/06/articles/lexblog/lexmonitor-is-live/'&gt; Real Lawyers Have Blogs&lt;/a&gt;. &lt;br/&gt;&lt;blockquote&gt;Pulling from nearly 2,000 sources and 5,000 authors, LexMonitor will hopefully shine a light on the ongoing conversation among thought leaders in the law for the benefit of the legal profession and the public at large.&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7153188034867304382?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7153188034867304382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7153188034867304382' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7153188034867304382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7153188034867304382'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/lexblog-soft-launches-lexmonitor.html' title='LEXBLOG soft launches LexMonitor'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6598777831000247810</id><published>2008-06-13T23:51:00.001-04:00</published><updated>2008-06-13T23:51:46.622-04:00</updated><title type='text'>SolarWinds Free Exchange Monitor</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;I've downloaded and installed &lt;a href='http://www.solarwinds.com/register/index.aspx?Program=825&amp;amp;c=70150000000DkHy&amp;amp;CMP=LEC-Exch-Mon-LockerG'&gt;SolarWinds Exchange Monitor&lt;/a&gt; yesterday. It works great. Is anyone else using any of the SolarWind products?&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6598777831000247810?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6598777831000247810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6598777831000247810' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6598777831000247810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6598777831000247810'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/solarwinds-free-exchange-monitor.html' title='SolarWinds Free Exchange Monitor'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-508792211849092685</id><published>2008-06-10T21:28:00.001-04:00</published><updated>2008-06-10T21:28:13.273-04:00</updated><title type='text'>iPhone 3G: What we didn't get</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;This &lt;a href='http://crave.cnet.com/8301-1_105-9963760-1.html?tag=bubbl_1'&gt;piece&lt;/a&gt; is more about the consumer end of things that the enterprise. I still would like copy and paste. I'm sure we would all find it useful. The lack of MMS really doesn't bother me. I think developers might be able to fill some of these gaps.&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-508792211849092685?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/508792211849092685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=508792211849092685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/508792211849092685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/508792211849092685'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/iphone-3g-what-we-didn-get.html' title='iPhone 3G: What we didn&amp;#39;t get'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3703927084790092359</id><published>2008-06-09T22:53:00.001-04:00</published><updated>2008-06-09T22:53:28.189-04:00</updated><title type='text'>Apple iPhone Enterprise Integration</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;Apple has &lt;a href='http://www.apple.com/iphone/enterprise/integration.html'&gt;posted&lt;/a&gt; a page that details enterprise integration. Included is a &lt;a href='http://images.apple.com/iphone/enterprise/docs/MS_Exchange_fs.pdf'&gt;pdf&lt;/a&gt; that details step by step directions on how to implement Exchange ActiveSync Setup. ActiveSync for the iPhone is supported on Exchange 2003 and 2007.  We will all have to wait for the iPhone 2.0 software to be released before we can begin testing.&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3703927084790092359?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3703927084790092359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3703927084790092359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3703927084790092359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3703927084790092359'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/apple-iphone-enterprise-integration.html' title='Apple iPhone Enterprise Integration'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-198023595062890967</id><published>2008-06-09T18:02:00.001-04:00</published><updated>2008-06-09T18:02:10.298-04:00</updated><title type='text'>Yes there is a $200 iPhone but...</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;TechCrunch &lt;a href='http://www.techcrunch.com/2008/06/09/199-iphone-sure-with-a-2-year-contract/'&gt;reports&lt;/a&gt;, "Unlimited data plans for iPhone 3G customers will be $30/month while business users will have to pony up $45/month." &lt;br/&gt;&lt;br/&gt;This is in line with the current Blackberry data plans. It is also unclear if you need the new iPhone 3G to use the business plan, or if you can use it on edge what the cost will be.&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-198023595062890967?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/198023595062890967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=198023595062890967' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/198023595062890967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/198023595062890967'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/yes-there-is-200-iphone-but.html' title='Yes there is a $200 iPhone but...'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-1818801727049972748</id><published>2008-06-07T16:17:00.001-04:00</published><updated>2008-06-07T16:17:21.535-04:00</updated><title type='text'>Apple said to release enterprise iPhone software on Monday</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;It has been &lt;a href='http://news.google.com/news?q=iphone+enterprise+features&amp;amp;ie=UTF-8&amp;amp;amp;oe=UTF-8&amp;amp;amp;rls=org.mozilla:en-US:official&amp;amp;amp;client=firefox-a&amp;amp;amp;um=1&amp;amp;amp;sa=N&amp;amp;amp;tab=wn&amp;amp;amp;oi=property_suggestions&amp;amp;amp;resnum=0&amp;amp;amp;ct=property-revision&amp;amp;amp;cd=1'&gt;reported in various places&lt;/a&gt; that Apple will release &lt;a href='http://lawfirmit.blogspot.com/2008/03/iphone-enterprise-features-comming-in.html'&gt;the enterprise software&lt;/a&gt; that will let the iPhone &lt;a href='http://techland.blogs.fortune.cnn.com/2008/06/06/new-iphone-cool-corporate-tool/'&gt;work with Exchange&lt;/a&gt; in the same way that Blackberry BES does now. With that said IT departments should expect a flood of questions who currently own or plan to buy iPhones. &lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-1818801727049972748?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/1818801727049972748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=1818801727049972748' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1818801727049972748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/1818801727049972748'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/apple-said-to-release-enterprise-iphone.html' title='Apple said to release enterprise iPhone software on Monday'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-308469529393694160</id><published>2008-06-07T16:08:00.001-04:00</published><updated>2008-06-07T16:08:29.608-04:00</updated><title type='text'>Windows XP SP3 breaks some routers</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;Broadband modem/router maker &lt;a href='http://apcmag.com/router_crashes_blamed_on_windows_xp_sp3.htm'&gt;Billion says XP SP3&lt;/a&gt; causes it's BiPAC 5200-series of routers to constantly crash and reboot.&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-308469529393694160?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/308469529393694160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=308469529393694160' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/308469529393694160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/308469529393694160'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/windows-xp-sp3-breaks-some-routers.html' title='Windows XP SP3 breaks some routers'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4894047237145735773</id><published>2008-06-01T21:12:00.000-04:00</published><updated>2008-06-01T21:12:00.607-04:00</updated><title type='text'>A graph of where spam, viruses and worms come from</title><content type='html'>They come from &lt;span style="text-decoration: underline;"&gt; &lt;/span&gt;&lt;a href="http://www.technologyreview.com/Infotech/20579/?a=f"&gt;these countries&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4894047237145735773?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.technologyreview.com/Infotech/20579/?a=f' title='A graph of where spam, viruses and worms come from'/><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4894047237145735773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4894047237145735773' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4894047237145735773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4894047237145735773'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/06/graph-of-where-spam-viruses-and-worms.html' title='A graph of where spam, viruses and worms come from'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-866406759730831331</id><published>2008-05-27T21:57:00.001-04:00</published><updated>2008-05-27T21:58:54.472-04:00</updated><title type='text'>Live from D: Gates and Ballmer preview Windows 7</title><content type='html'>&lt;a href="http://www.engadget.com/2008/05/27/live-from-d-gates-and-ballmer-debut-windows-7/"&gt;Live from D: Gates and Ballmer debut Windows 7 - Engadget&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'm not sure if they will tell us anything, but it will be interesting to watch.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-866406759730831331?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/866406759730831331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=866406759730831331' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/866406759730831331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/866406759730831331'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/live-from-d-gates-and-ballmer-debut.html' title='Live from D: Gates and Ballmer preview Windows 7'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7556480725938602124</id><published>2008-05-27T19:04:00.000-04:00</published><updated>2008-05-27T19:04:01.125-04:00</updated><title type='text'>Leaked Screen Shots of Windows 7</title><content type='html'>This &lt;a href="http://www.techcrunch.com/2008/05/27/leaked-screen-shots-of-windows-7-hit-crunchgears-inbox/"&gt;leaked screen shots of Windows 7&lt;/a&gt; concerns me. For those of us that skipped Vista in hopes that Microsoft would deliver a usable OS in Windows 7, there seems to be too much eye candy with superfluous processes, like a weather report, running in the task bar.&lt;br /&gt;&lt;br /&gt;I still hold some hope that will deliver an OS close to the simple, usable design of Server 2008, which has been my favorite version of Windows Server so far, and not more crap like Vista.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7556480725938602124?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.techcrunch.com/2008/05/27/leaked-screen-shots-of-windows-7-hit-crunchgears-inbox/' title='Leaked Screen Shots of Windows 7'/><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7556480725938602124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7556480725938602124' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7556480725938602124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7556480725938602124'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/leaked-screen-shots-of-windows-7.html' title='Leaked Screen Shots of Windows 7'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2040805755791605293</id><published>2008-05-01T20:16:00.002-04:00</published><updated>2008-05-01T20:22:20.247-04:00</updated><title type='text'>More on the $199 iPhone</title><content type='html'>$199 iPhone is cool, but possibly imaginary. &lt;a href="http://www.macworld.com/article/133237/2008/04/199iphone.html"&gt;MacWorld&lt;/a&gt; weighs in.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2040805755791605293?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2040805755791605293/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2040805755791605293' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2040805755791605293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2040805755791605293'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/broiled-salmon-with-ramps.html' title='More on the $199 iPhone'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3526031379811194084</id><published>2008-05-01T07:27:00.000-04:00</published><updated>2008-05-01T08:23:31.022-04:00</updated><title type='text'>Hope for XP extension?</title><content type='html'>&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9080218&amp;amp;taxonomyId=14&amp;amp;intsrc=kc_top"&gt;Ballmer offers glimmer of hope for XP extension&lt;/a&gt; but, "Later on Thursday, however, a U.S.-based spokeswoman for the company said that Microsoft's plans remain 'unchanged.'"&lt;br /&gt;&lt;br /&gt;I think there is a lot of wishful thinking going on from consumers. If MS does give an extension, they won't announce it until the last minute.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3526031379811194084?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3526031379811194084/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3526031379811194084' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3526031379811194084'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3526031379811194084'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/hope-for-xp-extension.html' title='Hope for XP extension?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3736196255541229254</id><published>2008-05-01T07:10:00.001-04:00</published><updated>2008-05-01T08:22:38.149-04:00</updated><title type='text'>$199 iPhones?</title><content type='html'>Fortune &lt;a href="http://techland.blogs.fortune.cnn.com/2008/04/29/att-to-cut-the-price-of-apples-new-iphone/"&gt;reports&lt;/a&gt; AT&amp;amp;T plans to reduce the cost by chipping in $200.00 on each iPhone sold.&lt;br /&gt;&lt;blockquote&gt;When the 3G iPhone is introduced this summer, AT&amp;amp;T, the exclusive U.S. iPhone sales partner with Apple, will cut the price by as much as $200, according to a person familiar with the strategy.&lt;br /&gt;&lt;br /&gt;AT&amp;amp;T is preparing to subsidize $200 of the cost of a new iPhone, bringing the price down to $199 for customers who sign two-year contracts, the source says. Apple is expected to have two versions of the new iPhone, an 8-gigabyte-memory and a 16-gigabyte-memory model with price tags widely expected to be $399 and $499.&lt;br /&gt;&lt;br /&gt;AT&amp;amp;T and Apple declined to comment.&lt;/blockquote&gt;&lt;br /&gt;It would be nice, but AT&amp;amp;T is already losing money on the iPhone. I guess we will find out in June.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3736196255541229254?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3736196255541229254/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3736196255541229254' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3736196255541229254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3736196255541229254'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/199-iphones.html' title='$199 iPhones?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6783524367979908218</id><published>2008-05-01T06:33:00.000-04:00</published><updated>2008-05-01T06:33:04.362-04:00</updated><title type='text'>Your help desk career: Dead end or launching pad?</title><content type='html'>&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9080699"&gt; Help Desk: Dead end or launching pad?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In my opinion every admin should have experience working with end users.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6783524367979908218?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6783524367979908218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6783524367979908218' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6783524367979908218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6783524367979908218'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/05/your-help-desk-career-dead-end-or.html' title='Your help desk career: Dead end or launching pad?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5446596018684565649</id><published>2008-03-10T22:22:00.001-04:00</published><updated>2008-03-10T22:24:58.538-04:00</updated><title type='text'>Because Tuesday is Black Tuesday</title><content type='html'>&lt;a href=http://www.microsoft.com/technet/security/bulletin/ms08-mar.mspx&gt;Microsoft Security Bulletin Advance Notification for March 2008&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5446596018684565649?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5446596018684565649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5446596018684565649' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5446596018684565649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5446596018684565649'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/03/because-tuesday-is-black-tuesday.html' title='Because Tuesday is Black Tuesday'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2452139620630929984</id><published>2008-03-08T03:19:00.004-05:00</published><updated>2008-03-08T04:12:25.001-05:00</updated><title type='text'>US Daylight Savings Time starts this weekend</title><content type='html'>Just a reminder this is the weekend that Daylight Savings Time starts in the US at 02:00 local time Sunday morning. This is the time change where we set our clocks one hour ahead, and we lose an hour.&lt;br /&gt;&lt;br /&gt;On August 8, 2005, President George W. Bush signed the Energy Policy Act of 2005. This Act changed the time change dates for Daylight Saving Time in the U.S. Beginning in 2007, DST will begin on the second Sunday in March and end the first Sunday in November. Under the old system DST would have started this weekend. Next week we gain an additional week of DST under Energy Policy Act of 2005.&lt;br /&gt;&lt;br /&gt;Microsoft and other software vendors recommend you pay close attention to your calendar doing this extending DST period. Problems with other nonrecurring events might still happen.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2452139620630929984?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2452139620630929984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2452139620630929984' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2452139620630929984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2452139620630929984'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/03/us-daylight-savings-time-starts-this.html' title='US Daylight Savings Time starts this weekend'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3421033869303461170</id><published>2008-03-06T15:31:00.002-05:00</published><updated>2008-03-06T15:33:57.662-05:00</updated><title type='text'>iPhone Enterprise Features Comming in June</title><content type='html'>The new features include:&lt;br /&gt;&lt;br /&gt;- Push email&lt;br /&gt;- Push calendar&lt;br /&gt;- Push contacts&lt;br /&gt;- Global address list&lt;br /&gt;- Certificates and Identities&lt;br /&gt;- WPA2 / 802.1x&lt;br /&gt;- Enforced security policies&lt;br /&gt;- Device configuration&lt;br /&gt;- Remote wipe&lt;br /&gt;- Active Sync and Microsoft Exchange support&lt;br /&gt;&lt;br /&gt;There is a beta program, but you must apply and meet the requirements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3421033869303461170?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3421033869303461170/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3421033869303461170' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3421033869303461170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3421033869303461170'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/03/iphone-enterprise-features-comming-in.html' title='iPhone Enterprise Features Comming in June'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-2077182939150424967</id><published>2008-02-27T20:48:00.003-05:00</published><updated>2008-02-27T20:57:05.916-05:00</updated><title type='text'>“iPhone Software Roadmap” Event March 6th</title><content type='html'>Date Apple has set March 6th for the “iPhone Software Roadmap” event. Along with a peek at the iPhone SDK, Apple promises “new enterprise features”. &lt;br /&gt;&lt;br /&gt;I hope they announce full Microsoft Exchange support. Many attorneys I talk to say they would dump their Blackberrys for iPhones, if the iPhone has email push and would sync with their Exchange calendars and contacts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-2077182939150424967?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/2077182939150424967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=2077182939150424967' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2077182939150424967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/2077182939150424967'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/02/iphone-software-roadmap-event-march-6th.html' title='“iPhone Software Roadmap” Event March 6th'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-774319027165936042</id><published>2008-02-27T20:37:00.002-05:00</published><updated>2008-02-27T20:43:46.228-05:00</updated><title type='text'>Windows Server 2008</title><content type='html'>Windows Server 2008 was &lt;a href=http://arstechnica.com/news.ars/post/20080227-windows-server-2008-arrives-with-high-hopes-great-fanfare.html&gt;officially launched today.&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;Whether IT admins follow along with Microsoft's reasoning is, of course, another matter. But Server 2008 certainly contains desirable features in its own right. Server Core is a new installation option that enables Windows Server 2008 to be deployed in a cut-down mode to serve one of eight specific server roles: file, print, DNS, DHCP, Active Directory, LDAP, virtualization, and web (IIS); there is also a ninth streaming media server role that is an optional download.&lt;br /&gt;&lt;br /&gt;Server Core mode omits much of the GUI and interactive parts of the OS, as well as those services not essential to the chosen role. Management of Server Core systems will be remote, typically through MMC. In this first version of the functionality, some of those roles may be a little too cut-down; the web server mode lacks .NET (and hence ASP.NET), and since ASP.NET is one of IIS's major features, its omission may prove a little hard to stomach. The other options are more appealing, and they should be very welcome for administrators looking to streamline resource usage and cut down attack surface area.&lt;br /&gt;&lt;br /&gt;Hyper-V, the new virtualization platform, isn't actually finished yet; it's still in beta, with a final release expected within 180 days. It's also an optional feature; you can save about $28 from the license fee by opting to eschew it, and it'll be available to purchase—for about $28—if you wish to add it to a non-Hyper-V version later on. Hyper-V uses the virtualization features on Intel and AMD processors (64-bit only) to, in principle, provide high-performance reliable virtualization.&lt;/blockquote&gt;&lt;br /&gt;The &lt;a href=http://www.microsoft.com/events/series/windowsserver2008.aspx?tab=virtuallabs&gt;version&lt;/a&gt; of Windows 2008 server I played with looks very promising.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-774319027165936042?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/774319027165936042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=774319027165936042' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/774319027165936042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/774319027165936042'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/02/windows-server-2008.html' title='Windows Server 2008'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3794688384960831521</id><published>2008-02-12T08:21:00.000-05:00</published><updated>2008-02-12T08:30:28.236-05:00</updated><title type='text'>What's the deal RIM?</title><content type='html'>While the Great Blackberry Outage of 2008&lt;sup&gt;TM&lt;/sup&gt; is over, most people are left to wonder what the problem is at RIM. Bloomberg reports:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt; "Research In Motion Ltd. said that a disruption in its Blackberry e-mail service in North America was ``fully and quickly'' restored and no messages were lost.&lt;br /&gt;&lt;br /&gt;``It was pretty focused and isolated and we recovered well,'' Co-Chief Executive Officer James Balsillie said in an interview at the Mobile World Congress in Barcelona today. ``We apologize for any inconvenience.''&lt;/blockquote&gt;&lt;br /&gt;My first question is where are these emails that news outlet keep taking about. I've never gotten one, and my firm is a BES customer. &lt;br /&gt;&lt;br /&gt;My second question is how much can we trust RIM to provide key services when we have seen outages time after time. I just glad that my iPhone can do IMAP to my firm's Exchange server.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3794688384960831521?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3794688384960831521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3794688384960831521' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3794688384960831521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3794688384960831521'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/02/whats-deal-rim.html' title='What&apos;s the deal RIM?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-4607066690115395079</id><published>2008-02-09T20:31:00.000-05:00</published><updated>2008-02-09T20:37:59.927-05:00</updated><title type='text'>Microsoft is set to push IE 7 out via WSUS on Tuesday</title><content type='html'>From a technet update email&lt;br /&gt;&lt;br /&gt;Volume 10, Issue 3: February 6, 2008&lt;br /&gt;&lt;br /&gt;   &lt;blockquote&gt;"On February 12, 2008 Microsoft will release the Windows Internet Explorer 7 Installation and Availability update to Windows Server Update Services (WSUS). Windows Internet Explorer 7 Installation and Availability Update is a complete installation package that will upgrade machines running Internet Explorer 6 to Windows Internet Explorer 7. Customers who have configured WSUS to "auto-approve" Update Rollup packages will automatically upgrade machines running Internet Explorer 6 to Windows Internet Explorer 7 after February 12, 2008 and consequently, may want to read &lt;a href="http://support.microsoft.com/kb/946202/en-us"&gt;Knowledge Base article 946202&lt;/a&gt; to manage how and when this update is installed. For more on the Windows Internet Explorer 7 Installation and Availability Update, read &lt;a href="http://support.microsoft.com/kb/940767/"&gt;Knowledge Base article 940767&lt;/a&gt;."&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-4607066690115395079?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/4607066690115395079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=4607066690115395079' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4607066690115395079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/4607066690115395079'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/02/microsoft-is-set-to-push-ie-7-out-via.html' title='Microsoft is set to push IE 7 out via WSUS on Tuesday'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-5232652574244339467</id><published>2008-02-08T10:22:00.000-05:00</published><updated>2008-02-08T10:29:22.049-05:00</updated><title type='text'>Microsoft Security Bulletin Advance Notification for February 2008</title><content type='html'>&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-feb.mspx"&gt;Microsoft Security Bulletin Advance Notification for February 2008&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Microsoft has listed seven critical updates, and five important updates that will be released next Tuesday.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-5232652574244339467?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/5232652574244339467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=5232652574244339467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5232652574244339467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/5232652574244339467'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2008/02/microsoft-security-bulletin-advance.html' title='Microsoft Security Bulletin Advance Notification for February 2008'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-3083928584412934911</id><published>2007-11-22T07:35:00.000-05:00</published><updated>2007-11-22T07:38:54.358-05:00</updated><title type='text'>Disable or turn off UAC in Windows Vista</title><content type='html'>How to &lt;a href="http://www.online-tech-tips.com/windows-vista/tweak-disable-or-turn-off-uac-user-account-control-in-windows-vista/"&gt;disable or turn off UAC in Windows Vista&lt;/a&gt;.&lt;br /&gt;&lt;blockquote&gt;The feature was put in to place to prevent unwanted applications, such as viruses and spyware, from self-installing onto the operating system. That’s great, but does one really need to enter a password or click OK every time they want to open a Control Panel applet? That’s a bit annoying, especially if you like to customize and configure your computer the way you want.&lt;br /&gt;&lt;br /&gt;However, disabling UAC altogether is not the best idea in the world. It’s amazing how many times spyware installs itself when you are browsing the Internet or when you insert a floppy disk or USB stick into your computer. So how does one not getting annoyed all the time, but still protect their computers?&lt;br /&gt;&lt;br /&gt;TweakUAC is a freeware application that you can run on Windows Vista to control how User Account Control (UAC) works. You can set it to Turn Off UAC, Turn On UAC, or put UAC into Quiet mode.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;You will need to disable UAC to run ProLaw in Vista.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-3083928584412934911?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/3083928584412934911/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=3083928584412934911' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3083928584412934911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/3083928584412934911'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2007/11/disable-or-turn-off-uac-in-windows.html' title='Disable or turn off UAC in Windows Vista'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-6664691455959682935</id><published>2007-07-09T11:45:00.000-04:00</published><updated>2007-07-09T11:46:27.085-04:00</updated><title type='text'>Fun with Darknets</title><content type='html'>&lt;a href="http://isc.sans.org/diary.html?storyid=3111"&gt;Fun with Darknets&lt;/a&gt; is an interesting read from them team over that the SANS Internet Storm Center.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-6664691455959682935?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/6664691455959682935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=6664691455959682935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6664691455959682935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/6664691455959682935'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2007/07/fun-with-darknets.html' title='Fun with Darknets'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-8197610222054200957</id><published>2007-07-09T11:41:00.000-04:00</published><updated>2007-07-09T11:43:57.122-04:00</updated><title type='text'>Google to acqure Postini</title><content type='html'>Google &lt;a href="http://googleblog.blogspot.com/2007/07/welcome-postini-team.html"&gt;announced today&lt;/a&gt; that they have greed to acquire &lt;a href="http://www.postini.com/index.php"&gt;Postini&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-8197610222054200957?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/8197610222054200957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=8197610222054200957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8197610222054200957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/8197610222054200957'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2007/07/google-to-acqure-postini.html' title='Google to acqure Postini'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15182237.post-7988925100580431033</id><published>2007-03-21T20:19:00.001-04:00</published><updated>2007-03-21T20:19:26.509-04:00</updated><title type='text'>Too much information?</title><content type='html'>Mike Mcbride asks &lt;a href="http://www.mikemcbrideonline.com/2007/03/how-much-is-too-much.html"&gt;How much is too much?&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;One was this whole DST mess. If there was one constant in all the things we did it was this. Every communication we sent to users in the hope of limiting some help desk calls by supplying information ahead of time, only resulted in more help desk calls. Instead of people reading the email, following the directions and going about their lives without the need to involve tech support folks, they called to ask questions about the email. Even people who didn't actually need to do anything different from what they always have been, called to make sure they didn't need to do anything. It seemed like the more we tried to educate people about the issue, and what to expect, the more it just confused them. A handful of people literally just took to ignoring any emails that came from the IS department, figuring we'd fix whatever needed to be fixed later for them.&lt;br /&gt;&lt;br /&gt;Here was a case where our attempts at sharing information backfired completely. It illustrates to me that when it comes to technical information, there is a saturation point where users simply tune you out.&lt;/blockquote&gt;&lt;br /&gt;&lt;!-- Technorati Tags Start --&gt;&lt;br /&gt;&lt;p&gt;Technorati Tags:&lt;br /&gt;&lt;a href="http://technorati.com/tag/law%20firm%20IT" rel="tag"&gt;law firm IT&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;!-- Technorati Tags End --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15182237-7988925100580431033?l=lawfirmit.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://lawfirmit.blogspot.com/feeds/7988925100580431033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15182237&amp;postID=7988925100580431033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7988925100580431033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15182237/posts/default/7988925100580431033'/><link rel='alternate' type='text/html' href='http://lawfirmit.blogspot.com/2007/03/too-much-information.html' title='Too much information?'/><author><name>oncee</name><uri>http://www.blogger.com/profile/15277332209680865565</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://photos1.blogger.com/blogger/2411/988/1600/cab3-4.jpg'/></author><thr:total>0</thr:total></entry></feed>
