<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" version="2.0">
  <channel>
    <title>SecureDeveloper.com</title>
    <link>http://www.securedeveloper.com/</link>
    <description>Code is COMBAT !</description>
    <language>en-us</language>
    <copyright>Joe Stagner</copyright>
    <lastBuildDate>Tue, 07 Oct 2008 18:32:24 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 1.9.7174.0</generator>
    <managingEditor>Joe.Stagner@Microsoft.com</managingEditor>
    <webMaster>Joe.Stagner@Microsoft.com</webMaster>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=03e1f3fa-3db5-455f-b29c-a201ca7c35eb</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,03e1f3fa-3db5-455f-b29c-a201ca7c35eb.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,03e1f3fa-3db5-455f-b29c-a201ca7c35eb.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=03e1f3fa-3db5-455f-b29c-a201ca7c35eb</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
I've been working hard to get more security related work back into my schedule. 
</p>
        <p>
And so..... I'm starting a new "season" of the Digital Blackbelt webcast series. 
</p>
        <p>
If we get enough interest I'll do some give-a-ways and such !
</p>
        <p>
SIGN UP NOW !!!! Here are the first 3 dates !
</p>
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheDigitalBlackbeltWebcastSeriesisBACK_CC63/3240226_thb_2.jpg">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="244" alt="3240226_thb" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheDigitalBlackbeltWebcastSeriesisBACK_CC63/3240226_thb_thumb.jpg" width="244" border="0" />
          </a>
        </p>
        <p>
          <strong>11/3/2008; 11:00 AM (PST)</strong>
          <br />
Convincing Management: The Business Case for Adding Security to the Development Life
Cycle<br />
[ <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391402&amp;Culture=en-US" target="_blank">Click
HERE to Register</a> ]
</p>
        <p>
          <strong>11/10/2008; 11:00 AM (PST)</strong>
          <br />
Security Development Lifecycle: Building an Intentionally Secure Development Process<br />
[ <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391402&amp;Culture=en-US" target="_blank">Click
HERE to Register</a> ]
</p>
        <p>
          <strong>11/24/2008; 11:00 AM (PST)</strong>
          <br />
Threat Modeling for Software Developers<br />
[ <a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391882&amp;Culture=en-US" target="_blank">Click
HERE to Register</a> ]
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=03e1f3fa-3db5-455f-b29c-a201ca7c35eb" />
      </body>
      <title>The Digital Blackbelt Webcast Series is BACK !</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,03e1f3fa-3db5-455f-b29c-a201ca7c35eb.aspx</guid>
      <link>http://www.securedeveloper.com/TheDigitalBlackbeltWebcastSeriesIsBACK.aspx</link>
      <pubDate>Tue, 07 Oct 2008 18:32:24 GMT</pubDate>
      <description>&lt;p&gt;
I've been working hard to get more security related work back into my schedule. 
&lt;/p&gt;
&lt;p&gt;
And so..... I'm starting a new "season" of the Digital Blackbelt webcast series. 
&lt;/p&gt;
&lt;p&gt;
If we get enough interest I'll do some give-a-ways and such !
&lt;/p&gt;
&lt;p&gt;
SIGN UP NOW !!!! Here are the first 3 dates !
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheDigitalBlackbeltWebcastSeriesisBACK_CC63/3240226_thb_2.jpg"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="244" alt="3240226_thb" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheDigitalBlackbeltWebcastSeriesisBACK_CC63/3240226_thb_thumb.jpg" width="244" border="0"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;11/3/2008; 11:00 AM (PST)&lt;/strong&gt;
&lt;br&gt;
Convincing Management: The Business Case for Adding Security to the Development Life
Cycle&lt;br&gt;
[ &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391402&amp;amp;Culture=en-US" target="_blank"&gt;Click
HERE to Register&lt;/a&gt; ]
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;11/10/2008; 11:00 AM (PST)&lt;/strong&gt;
&lt;br&gt;
Security Development Lifecycle: Building an Intentionally Secure Development Process&lt;br&gt;
[ &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391402&amp;amp;Culture=en-US" target="_blank"&gt;Click
HERE to Register&lt;/a&gt; ]
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;11/24/2008; 11:00 AM (PST)&lt;/strong&gt;
&lt;br&gt;
Threat Modeling for Software Developers&lt;br&gt;
[ &lt;a href="http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032391882&amp;amp;Culture=en-US" target="_blank"&gt;Click
HERE to Register&lt;/a&gt; ]
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=03e1f3fa-3db5-455f-b29c-a201ca7c35eb" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,03e1f3fa-3db5-455f-b29c-a201ca7c35eb.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=bb8b463c-df12-4362-8fa1-f6f54aa6a5f7</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,bb8b463c-df12-4362-8fa1-f6f54aa6a5f7.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,bb8b463c-df12-4362-8fa1-f6f54aa6a5f7.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=bb8b463c-df12-4362-8fa1-f6f54aa6a5f7</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.nostarch.com/idapro.htm" target="_blank">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="idaPro_big" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheIDAProBookbyChrisEagle_E2C6/idaPro_big_3.jpg" width="186" height="244" />
          </a>
        </p>
        <p>
This book is OFF THE HOOK !
</p>
        <p>
Wanna REALLY dissect a running application ?
</p>
        <p>
IDA Pro is THE tool of choice for disassembly and the crackers choice because of it's
raw power. 
</p>
        <p>
Whether you need to solve a tough runtime defect or examine your application security
from teh inside out IDA Pro is a great tool and this book is THE guide for coming
up to speed. 
</p>
        <p>
From the book description ....
</p>
        <li>
Identify known library routines, so you can focus your analysis on other areas of
the code 
</li>
        <li>
Extend IDA to support new processors and filetypes, making disassembly possible for
new or obscure architectures 
</li>
        <li>
Explore popular plug-ins that make writing IDA scripts easier, allow collaborative
reverse engineering, and much more 
</li>
        <li>
Utilize IDA’s built-in debugger to tackle obfuscated code that would defeat a stand-alone
disassembler 
<p>
 
</p><p><a href="http://www.tinker.tv/download/idaPro_ch12.pdf">Download Chapter 12: "Library
Recognition Using FLIRT Signatures"</a></p><p><a title="http://www.nostarch.com/idapro.htm" href="http://www.nostarch.com/idapro.htm">http://www.nostarch.com/idapro.htm</a></p></li>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=bb8b463c-df12-4362-8fa1-f6f54aa6a5f7" />
      </body>
      <title>The IDA Pro Book by Chris Eagle</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,bb8b463c-df12-4362-8fa1-f6f54aa6a5f7.aspx</guid>
      <link>http://www.securedeveloper.com/TheIDAProBookByChrisEagle.aspx</link>
      <pubDate>Wed, 24 Sep 2008 20:08:14 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.nostarch.com/idapro.htm" target="_blank"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="idaPro_big" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TheIDAProBookbyChrisEagle_E2C6/idaPro_big_3.jpg" width="186" height="244"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
This book is OFF THE HOOK !
&lt;/p&gt;
&lt;p&gt;
Wanna REALLY dissect a running application ?
&lt;/p&gt;
&lt;p&gt;
IDA Pro is THE tool of choice for disassembly and the crackers choice because of it's
raw power. 
&lt;/p&gt;
&lt;p&gt;
Whether you need to solve a tough runtime defect or examine your application security
from teh inside out IDA Pro is a great tool and this book is THE guide for coming
up to speed. 
&lt;/p&gt;
&lt;p&gt;
From the book description ....
&lt;/p&gt;
&lt;li&gt;
Identify known library routines, so you can focus your analysis on other areas of
the code 
&lt;li&gt;
Extend IDA to support new processors and filetypes, making disassembly possible for
new or obscure architectures 
&lt;li&gt;
Explore popular plug-ins that make writing IDA scripts easier, allow collaborative
reverse engineering, and much more 
&lt;li&gt;
Utilize IDA’s built-in debugger to tackle obfuscated code that would defeat a stand-alone
disassembler 
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.tinker.tv/download/idaPro_ch12.pdf"&gt;Download Chapter 12: "Library
Recognition Using FLIRT Signatures"&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://www.nostarch.com/idapro.htm" href="http://www.nostarch.com/idapro.htm"&gt;http://www.nostarch.com/idapro.htm&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=bb8b463c-df12-4362-8fa1-f6f54aa6a5f7" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,bb8b463c-df12-4362-8fa1-f6f54aa6a5f7.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=af465414-2d58-4a34-be3d-91d61071af74</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,af465414-2d58-4a34-be3d-91d61071af74.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,af465414-2d58-4a34-be3d-91d61071af74.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=af465414-2d58-4a34-be3d-91d61071af74</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ThePCDecrapifier_C10D/decraplogo_2.png">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="decraplogo" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ThePCDecrapifier_C10D/decraplogo_thumb.png" width="132" height="132" />
          </a>
        </p>
        <p>
I haven't tried it yet, but what a great idea !!
</p>
        <p>
          <a title="http://pcdecrapifier.com/" href="http://pcdecrapifier.com/">http://pcdecrapifier.com/</a>
        </p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=af465414-2d58-4a34-be3d-91d61071af74" />
      </body>
      <title>The PC Decrapifier</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,af465414-2d58-4a34-be3d-91d61071af74.aspx</guid>
      <link>http://www.securedeveloper.com/ThePCDecrapifier.aspx</link>
      <pubDate>Wed, 24 Sep 2008 17:44:26 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ThePCDecrapifier_C10D/decraplogo_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="decraplogo" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ThePCDecrapifier_C10D/decraplogo_thumb.png" width="132" height="132"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
I haven't tried it yet, but what a great idea !!
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://pcdecrapifier.com/" href="http://pcdecrapifier.com/"&gt;http://pcdecrapifier.com/&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=af465414-2d58-4a34-be3d-91d61071af74" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,af465414-2d58-4a34-be3d-91d61071af74.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=822d02fd-cb9e-402b-8abe-3c669e0bb20b</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,822d02fd-cb9e-402b-8abe-3c669e0bb20b.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,822d02fd-cb9e-402b-8abe-3c669e0bb20b.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=822d02fd-cb9e-402b-8abe-3c669e0bb20b</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Application Development Trends reports on Google Chrome Security Issues 
</p>
        <p>
          <img src="http://www.siliconrepublic.com/fs/img/news/200809/378x/chromecolour3.jpg" width="100" height="100" />
        </p>
        <p>
Read the complete story here - <a title="http://adtmag.com/article.aspx?id=23205" href="http://adtmag.com/article.aspx?id=23205">http://adtmag.com/article.aspx?id=23205</a></p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=822d02fd-cb9e-402b-8abe-3c669e0bb20b" />
      </body>
      <title>Security Exploits to Google Chrome Browser Emerge</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,822d02fd-cb9e-402b-8abe-3c669e0bb20b.aspx</guid>
      <link>http://www.securedeveloper.com/SecurityExploitsToGoogleChromeBrowserEmerge.aspx</link>
      <pubDate>Tue, 09 Sep 2008 12:40:47 GMT</pubDate>
      <description>&lt;p&gt;
Application Development Trends reports on Google Chrome Security Issues 
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.siliconrepublic.com/fs/img/news/200809/378x/chromecolour3.jpg" width="100" height="100"&gt;
&lt;/p&gt;
&lt;p&gt;
Read the complete story here - &lt;a title="http://adtmag.com/article.aspx?id=23205" href="http://adtmag.com/article.aspx?id=23205"&gt;http://adtmag.com/article.aspx?id=23205&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=822d02fd-cb9e-402b-8abe-3c669e0bb20b" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,822d02fd-cb9e-402b-8abe-3c669e0bb20b.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=4ed2c278-4da5-497f-a12f-e2e5a9ab6291</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,4ed2c278-4da5-497f-a12f-e2e5a9ab6291.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,4ed2c278-4da5-497f-a12f-e2e5a9ab6291.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=4ed2c278-4da5-497f-a12f-e2e5a9ab6291</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ImDeepFriedItslivetoday_7AB2/dfb-header_2.png">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="dfb-header" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ImDeepFriedItslivetoday_7AB2/dfb-header_thumb.png" width="644" height="129" />
          </a>
        </p>
        <p>
The <a href="http://deepfriedbytes.com/" target="_blank">Deep Fried Bytes</a> guys
caught  up with me at <a href="http://www.devlink.net/" target="_blank">DevLink</a> and
we had a talk about developer security needs, mistakes, activities, etc !
</p>
        <p>
Listen Here <a title="http://deepfriedbytes.com/" href="http://deepfriedbytes.com/">http://deepfriedbytes.com/</a></p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=4ed2c278-4da5-497f-a12f-e2e5a9ab6291" />
      </body>
      <title>I'm Deep Fried - It's live today !</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,4ed2c278-4da5-497f-a12f-e2e5a9ab6291.aspx</guid>
      <link>http://www.securedeveloper.com/ImDeepFriedItsLiveToday.aspx</link>
      <pubDate>Tue, 02 Sep 2008 17:04:23 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ImDeepFriedItslivetoday_7AB2/dfb-header_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="dfb-header" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/ImDeepFriedItslivetoday_7AB2/dfb-header_thumb.png" width="644" height="129"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The &lt;a href="http://deepfriedbytes.com/" target="_blank"&gt;Deep Fried Bytes&lt;/a&gt; guys
caught&amp;nbsp; up with me at &lt;a href="http://www.devlink.net/" target="_blank"&gt;DevLink&lt;/a&gt; and
we had a talk about developer security needs, mistakes, activities, etc !
&lt;/p&gt;
&lt;p&gt;
Listen Here &lt;a title="http://deepfriedbytes.com/" href="http://deepfriedbytes.com/"&gt;http://deepfriedbytes.com/&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=4ed2c278-4da5-497f-a12f-e2e5a9ab6291" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,4ed2c278-4da5-497f-a12f-e2e5a9ab6291.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=ea6ea66d-e11c-4936-9e12-9609dd3cc91e</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,ea6ea66d-e11c-4936-9e12-9609dd3cc91e.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,ea6ea66d-e11c-4936-9e12-9609dd3cc91e.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=ea6ea66d-e11c-4936-9e12-9609dd3cc91e</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
ZDNEt Reports ..... 
</p>
        <p>
  
</p>
        <p>
          <img border="0" hspace="15" alt="Compromised SSH keys leads to rootkit" align="left" src="http://blogs.zdnet.com/security/images/kill_bill_tee.jpg" />The
U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls
“active attacks” against Linux-based computing infrastructures using compromised SSH
keys. 
</p>
        <p>
The attack appears to initially use stolen SSH keys to gain access to a system, and
then uses local kernel exploits to gain root access. Once root access has been obtained,
a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current
activity site. 
</p>
        <p>
From the advisory: 
</p>
        <ul>
          <ul>
            <ul>
              <ul>
                <li>
                  <a>
                  </a>
                  <em>Phalanx2 appears to be a derivative of an older rootkit named “phalanx”.
Phalanx2 and the support scripts within the rootkit, are configured to systematically
steal SSH keys from the compromised system. These SSH keys are sent to the attackers,
who then use them to try to compromise other sites and other systems of interest at
the attacked site.</em>
                </li>
              </ul>
            </ul>
          </ul>
        </ul>
        <p>
[ <a href="http://blogs.zdnet.com/security/?p=1803&amp;tag=nl.e550" target="_blank">Read
the article on ZDNet</a> ]
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=ea6ea66d-e11c-4936-9e12-9609dd3cc91e" />
      </body>
      <title>Linux under attack: Compromised SSH keys lead to rootkit</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,ea6ea66d-e11c-4936-9e12-9609dd3cc91e.aspx</guid>
      <link>http://www.securedeveloper.com/LinuxUnderAttackCompromisedSSHKeysLeadToRootkit.aspx</link>
      <pubDate>Fri, 29 Aug 2008 11:59:29 GMT</pubDate>
      <description>&lt;p&gt;
ZDNEt Reports ..... 
&lt;p&gt;
&amp;nbsp; 
&lt;p&gt;
&lt;img border="0" hspace="15" alt="Compromised SSH keys leads to rootkit" align="left" src="http://blogs.zdnet.com/security/images/kill_bill_tee.jpg"&gt;The
U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls
“active attacks” against Linux-based computing infrastructures using compromised SSH
keys. 
&lt;p&gt;
The attack appears to initially use stolen SSH keys to gain access to a system, and
then uses local kernel exploits to gain root access. Once root access has been obtained,
a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current
activity site. 
&lt;p&gt;
From the advisory: 
&lt;ul&gt;
&lt;ul&gt;
&lt;ul&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a&gt;&lt;/a&gt;&lt;em&gt;Phalanx2 appears to be a derivative of an older rootkit named “phalanx”.
Phalanx2 and the support scripts within the rootkit, are configured to systematically
steal SSH keys from the compromised system. These SSH keys are sent to the attackers,
who then use them to try to compromise other sites and other systems of interest at
the attacked site.&lt;/em&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;p&gt;
[ &lt;a href="http://blogs.zdnet.com/security/?p=1803&amp;amp;tag=nl.e550" target="_blank"&gt;Read
the article on ZDNet&lt;/a&gt; ]
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=ea6ea66d-e11c-4936-9e12-9609dd3cc91e" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,ea6ea66d-e11c-4936-9e12-9609dd3cc91e.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=b60ef650-ba7b-44d9-86f1-ce4a89536c9b</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,b60ef650-ba7b-44d9-86f1-ce4a89536c9b.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,b60ef650-ba7b-44d9-86f1-ce4a89536c9b.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=b60ef650-ba7b-44d9-86f1-ce4a89536c9b</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RedHatbelatedlyconfirmssecuritybreach_6F1B/red_hat_logo_big_2.jpg">
            <img style="border-right: 0px; border-top: 0px; margin: 0px 25px 0px 0px; border-left: 0px; border-bottom: 0px" border="0" alt="red_hat_logo_big" align="left" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RedHatbelatedlyconfirmssecuritybreach_6F1B/red_hat_logo_big_thumb.jpg" width="222" height="244" />
          </a>
        </p>
        <p>
More than a week after a cryptic note <a href="http://blogs.zdnet.com/security/?p=1725">hinted
at a security breach at Fedora</a>, the open-source group has finally fessed up to
two separate server intrusions that compromised the security of Red Hat’s OpenSSH
packages. 
</p>
        <p>
  
</p>
        <p>
The confirmation follows eight days of <a href="http://www.heise-online.co.uk/news/Fedora-servers-may-have-been-breached--/111345">media
speculation</a> and <a href="http://lists.immunitysec.com/pipermail/dailydave/2008-August/005280.html">conjecture</a> over
a brief e-mail that simply mentioned “an issue in the infrastructure systems” and
calls into question Red Hat’s ability to promptly — and accurately — disclose security
breaches. 
</p>
        <p>
  
</p>
        <p>
[ <a href="http://blogs.zdnet.com/security/?p=1784&amp;tag=nl.e550" target="_blank">Read
the full article HERE at ZDNet</a> ]
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=b60ef650-ba7b-44d9-86f1-ce4a89536c9b" />
      </body>
      <title>Red Hat (belatedly) confirms security breach</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,b60ef650-ba7b-44d9-86f1-ce4a89536c9b.aspx</guid>
      <link>http://www.securedeveloper.com/RedHatBelatedlyConfirmsSecurityBreach.aspx</link>
      <pubDate>Fri, 29 Aug 2008 11:54:14 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RedHatbelatedlyconfirmssecuritybreach_6F1B/red_hat_logo_big_2.jpg"&gt;&lt;img style="border-right: 0px; border-top: 0px; margin: 0px 25px 0px 0px; border-left: 0px; border-bottom: 0px" border="0" alt="red_hat_logo_big" align="left" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RedHatbelatedlyconfirmssecuritybreach_6F1B/red_hat_logo_big_thumb.jpg" width="222" height="244"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
More than a week after a cryptic note &lt;a href="http://blogs.zdnet.com/security/?p=1725"&gt;hinted
at a security breach at Fedora&lt;/a&gt;, the open-source group has finally fessed up to
two separate server intrusions that compromised the security of Red Hat’s OpenSSH
packages. 
&lt;p&gt;
&amp;nbsp; 
&lt;p&gt;
The confirmation follows eight days of &lt;a href="http://www.heise-online.co.uk/news/Fedora-servers-may-have-been-breached--/111345"&gt;media
speculation&lt;/a&gt; and &lt;a href="http://lists.immunitysec.com/pipermail/dailydave/2008-August/005280.html"&gt;conjecture&lt;/a&gt; over
a brief e-mail that simply mentioned “an issue in the infrastructure systems” and
calls into question Red Hat’s ability to promptly — and accurately — disclose security
breaches. 
&lt;p&gt;
&amp;nbsp; 
&lt;p&gt;
[ &lt;a href="http://blogs.zdnet.com/security/?p=1784&amp;amp;tag=nl.e550" target="_blank"&gt;Read
the full article HERE at ZDNet&lt;/a&gt; ]
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=b60ef650-ba7b-44d9-86f1-ce4a89536c9b" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,b60ef650-ba7b-44d9-86f1-ce4a89536c9b.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=02c53ca1-3ad1-4cee-a65b-e78a976d8bee</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,02c53ca1-3ad1-4cee-a65b-e78a976d8bee.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,02c53ca1-3ad1-4cee-a65b-e78a976d8bee.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=02c53ca1-3ad1-4cee-a65b-e78a976d8bee</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/FreeDataStructuresandAlgorithmsBookfromt_90BB/dsa_2.png">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="dsa" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/FreeDataStructuresandAlgorithmsBookfromt_90BB/dsa_thumb.png" width="172" height="244" />
          </a>
        </p>
        <h4>Data Structures and Algorithms: Annotated Reference with Examples
</h4>
        <p>
This book written by <a href="http://msmvps.com/blogs/gbarnett/">Granville Barnett</a> and <a href="http://blogs.ugidotnet.org/wetblog/Default.aspx">Luca
Del Tongo</a> is part of an effort to provide all <a href="http://dotnetslackers.com/#">developers</a> with
a core understanding of algorithms that operate on various common, and uncommon <a href="http://dotnetslackers.com/#">data</a> structures. 
</p>
        <p>
Data Structures and Algorithms: Annotated Reference with Examples is completely free! 
</p>
        <p>
[ <a href="http://dotnetslackers.com/projects/Data-Structures-And-Algorithms/" target="_blank">CILICK
HERE</a> ] 
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=02c53ca1-3ad1-4cee-a65b-e78a976d8bee" />
      </body>
      <title>Free Data Structures and Algorithms Book from the Slackers</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,02c53ca1-3ad1-4cee-a65b-e78a976d8bee.aspx</guid>
      <link>http://www.securedeveloper.com/FreeDataStructuresAndAlgorithmsBookFromTheSlackers.aspx</link>
      <pubDate>Thu, 28 Aug 2008 14:17:37 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/FreeDataStructuresandAlgorithmsBookfromt_90BB/dsa_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="dsa" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/FreeDataStructuresandAlgorithmsBookfromt_90BB/dsa_thumb.png" width="172" height="244"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;h4&gt;Data Structures and Algorithms: Annotated Reference with Examples
&lt;/h4&gt;
&lt;p&gt;
This book written by &lt;a href="http://msmvps.com/blogs/gbarnett/"&gt;Granville Barnett&lt;/a&gt; and &lt;a href="http://blogs.ugidotnet.org/wetblog/Default.aspx"&gt;Luca
Del Tongo&lt;/a&gt; is part of an effort to provide all &lt;a href="http://dotnetslackers.com/#"&gt;developers&lt;/a&gt; with
a core understanding of algorithms that operate on various common, and uncommon &lt;a href="http://dotnetslackers.com/#"&gt;data&lt;/a&gt; structures. 
&lt;p&gt;
Data Structures and Algorithms: Annotated Reference with Examples is completely free! 
&lt;p&gt;
[ &lt;a href="http://dotnetslackers.com/projects/Data-Structures-And-Algorithms/" target="_blank"&gt;CILICK
HERE&lt;/a&gt; ] 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=02c53ca1-3ad1-4cee-a65b-e78a976d8bee" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,02c53ca1-3ad1-4cee-a65b-e78a976d8bee.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=58303f3b-3f85-471e-bbc6-c3d957763dac</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,58303f3b-3f85-471e-bbc6-c3d957763dac.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,58303f3b-3f85-471e-bbc6-c3d957763dac.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=58303f3b-3f85-471e-bbc6-c3d957763dac</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.asp.net/video-387.aspx">
            <img alt="" src="http://static.asp.net/asp.net/images/videos/video-350.png" />
          </a>
        </p>
        <p>
          <strong>#8 | </strong>Changing Membership Settings in the Default Membership Schema
</p>
        <p>
          <a href="http://www.asp.net/video-388.aspx">
            <img alt="" src="http://static.asp.net/asp.net/images/videos/video-349.png" />
          </a>
        </p>
        <p>
          <strong>#9 | </strong>Configuring SQL To Work with Membership Schemas
</p>
        <p>
          <a href="http://www.asp.net/video-389.aspx">
            <img alt="" src="http://static.asp.net/asp.net/images/videos/video-348.png" />
          </a>
        </p>
        <p>
          <strong>#10 | </strong>Understanding ASP.NET Memberships
</p>
        <p>
[ <a href="http://www.asp.net/learn/security-videos/" target="_blank">Get them here</a> ]
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=58303f3b-3f85-471e-bbc6-c3d957763dac" />
      </body>
      <title>3 New Security Videos Published !</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,58303f3b-3f85-471e-bbc6-c3d957763dac.aspx</guid>
      <link>http://www.securedeveloper.com/3NewSecurityVideosPublished.aspx</link>
      <pubDate>Sun, 10 Aug 2008 18:10:42 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.asp.net/video-387.aspx"&gt;&lt;img alt="" src="http://static.asp.net/asp.net/images/videos/video-350.png"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;#8 | &lt;/strong&gt;Changing Membership Settings in the Default Membership Schema
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.asp.net/video-388.aspx"&gt;&lt;img alt="" src="http://static.asp.net/asp.net/images/videos/video-349.png"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;#9 | &lt;/strong&gt;Configuring SQL To Work with Membership Schemas
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.asp.net/video-389.aspx"&gt;&lt;img alt="" src="http://static.asp.net/asp.net/images/videos/video-348.png"&gt;&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;#10 | &lt;/strong&gt;Understanding ASP.NET Memberships
&lt;/p&gt;
&lt;p&gt;
[ &lt;a href="http://www.asp.net/learn/security-videos/" target="_blank"&gt;Get them here&lt;/a&gt; ]
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=58303f3b-3f85-471e-bbc6-c3d957763dac" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,58303f3b-3f85-471e-bbc6-c3d957763dac.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=26e3de1e-ff35-4224-a9bb-3ee3a28f066b</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,26e3de1e-ff35-4224-a9bb-3ee3a28f066b.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,26e3de1e-ff35-4224-a9bb-3ee3a28f066b.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=26e3de1e-ff35-4224-a9bb-3ee3a28f066b</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/WhatisyoudontwannashareyourPHPcode_A330/nucoder_190_3_2.png">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="nucoder_190_3" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/WhatisyoudontwannashareyourPHPcode_A330/nucoder_190_3_thumb.png" width="194" height="137" />
          </a>
        </p>
        <p>
Lots, even MOST PHP applications are Open Souce but what if you want to distribute
your application but don't want to distribute your PHP Source Code ?
</p>
        <p>
Check out Nu-Coder from NuSphere. 
</p>
        <p>
  
</p>
        <p>
Nu-Coder converts the source code of PHP Script into compiled PHP bytecodes for both
accelerated runtime performance and maximum security. 
</p>
        <p>
  
</p>
        <p>
          <a title="http://www.nusphere.com/products/nucoder.htm" href="http://www.nusphere.com/products/nucoder.htm">http://www.nusphere.com/products/nucoder.htm</a>
        </p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=26e3de1e-ff35-4224-a9bb-3ee3a28f066b" />
      </body>
      <title>What is you don't wanna share your PHP code ?</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,26e3de1e-ff35-4224-a9bb-3ee3a28f066b.aspx</guid>
      <link>http://www.securedeveloper.com/WhatIsYouDontWannaShareYourPHPCode.aspx</link>
      <pubDate>Fri, 01 Aug 2008 15:36:26 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/WhatisyoudontwannashareyourPHPcode_A330/nucoder_190_3_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="nucoder_190_3" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/WhatisyoudontwannashareyourPHPcode_A330/nucoder_190_3_thumb.png" width="194" height="137"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Lots, even MOST PHP applications are Open Souce but what if you want to distribute
your application but don't want to distribute your PHP Source Code ?
&lt;/p&gt;
&lt;p&gt;
Check out Nu-Coder from NuSphere. 
&lt;p&gt;
&amp;nbsp; 
&lt;p&gt;
Nu-Coder converts the source code of PHP Script into compiled PHP bytecodes for both
accelerated runtime performance and maximum security. 
&lt;p&gt;
&amp;nbsp; 
&lt;p&gt;
&lt;a title="http://www.nusphere.com/products/nucoder.htm" href="http://www.nusphere.com/products/nucoder.htm"&gt;http://www.nusphere.com/products/nucoder.htm&lt;/a&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=26e3de1e-ff35-4224-a9bb-3ee3a28f066b" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,26e3de1e-ff35-4224-a9bb-3ee3a28f066b.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=9b08f822-abbc-4f6d-8de6-89c8def1be21</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,9b08f822-abbc-4f6d-8de6-89c8def1be21.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,9b08f822-abbc-4f6d-8de6-89c8def1be21.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=9b08f822-abbc-4f6d-8de6-89c8def1be21</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Dolores Labs posted recently "<a href="http://blog.doloreslabs.com/2008/07/amazons-s3-web-service-our-1-cause-of-failure/">Amazon’s
S3 Web Service, our #1 cause of failure</a>" [ <a href="http://blog.doloreslabs.com/2008/07/amazons-s3-web-service-our-1-cause-of-failure/" target="_blank">Click
HERE to READ</a> ] 
</p>
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RiskswithCloudComputing_93C7/100014192753__V46777512__2.gif">
            <img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" border="0" alt="100014192753__V46777512_" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RiskswithCloudComputing_93C7/100014192753__V46777512__thumb.gif" width="174" height="73" />
          </a>
        </p>
        <p>
Amazon.com is a great company and a early innovator in the Web Services Community.
(God knows I send them ALOT of money.) 
</p>
        <p>
So this is not an indictment of Amazon as a technology provider. In fact, it is because
a Amazon is a great company with a solid infrastructure that this is significant. 
</p>
        <p>
As Geeks, we tend to get all jazzed about the latest buzz - and cloud computing is
certainly one of them. But, I think it's important to remember, while services in
the cloud can be very cost effective. You can't control the cloud. 
</p>
        <p>
When you build it and own it you always have options when you're not getting the service
level you need. In the cloud, you're held hostage by 3rd party service levels....
ad as we all know, stuff happens. 
</p>
        <p>
When you're using a cloud hosted service, remember to build support for graceful degradation
your application. You application need not fail completely because you can't fetch
images, ads, etc.
</p>
        <p>
Not only is this good design practice, but it mitigates a DOS security threat. If
I wanna bring your web application down and you haven't built resilience into your
site, all I need to to is successfully attack any one service your application depends
on and your application is down !! 
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=9b08f822-abbc-4f6d-8de6-89c8def1be21" />
      </body>
      <title>Risks with Cloud Computing.</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,9b08f822-abbc-4f6d-8de6-89c8def1be21.aspx</guid>
      <link>http://www.securedeveloper.com/RisksWithCloudComputing.aspx</link>
      <pubDate>Mon, 21 Jul 2008 14:31:23 GMT</pubDate>
      <description>&lt;p&gt;
Dolores Labs posted recently "&lt;a href="http://blog.doloreslabs.com/2008/07/amazons-s3-web-service-our-1-cause-of-failure/"&gt;Amazon’s
S3 Web Service, our #1 cause of failure&lt;/a&gt;" [ &lt;a href="http://blog.doloreslabs.com/2008/07/amazons-s3-web-service-our-1-cause-of-failure/" target="_blank"&gt;Click
HERE to READ&lt;/a&gt; ] 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RiskswithCloudComputing_93C7/100014192753__V46777512__2.gif"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" border="0" alt="100014192753__V46777512_" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/RiskswithCloudComputing_93C7/100014192753__V46777512__thumb.gif" width="174" height="73"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Amazon.com is a great company and a early innovator in the Web Services Community.
(God knows I send them ALOT of money.) 
&lt;/p&gt;
&lt;p&gt;
So this is not an indictment of Amazon as a technology provider. In fact, it is because
a Amazon is a great company with a solid infrastructure that this is significant. 
&lt;/p&gt;
&lt;p&gt;
As Geeks, we tend to get all jazzed about the latest buzz - and cloud computing is
certainly one of them. But, I think it's important to remember, while services in
the cloud can be very cost effective. You can't control the cloud. 
&lt;/p&gt;
&lt;p&gt;
When you build it and own it you always have options when you're not getting the service
level you need. In the cloud, you're held hostage by 3rd party service levels....
ad as we all know, stuff happens. 
&lt;/p&gt;
&lt;p&gt;
When you're using a cloud hosted service, remember to build support for graceful degradation
your application. You application need not fail completely because you can't fetch
images, ads, etc.
&lt;/p&gt;
&lt;p&gt;
Not only is this good design practice, but it mitigates a DOS security threat. If
I wanna bring your web application down and you haven't built resilience into your
site, all I need to to is successfully attack any one service your application depends
on and your application is down !! 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=9b08f822-abbc-4f6d-8de6-89c8def1be21" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,9b08f822-abbc-4f6d-8de6-89c8def1be21.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=f518d9fa-1062-490a-ab73-c33d72701514</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,f518d9fa-1062-490a-ab73-c33d72701514.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,f518d9fa-1062-490a-ab73-c33d72701514.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=f518d9fa-1062-490a-ab73-c33d72701514</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TweakUAC_F72E/TweakUAC_2.png">
            <img style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-RIGHT-WIDTH: 0px" height="327" alt="TweakUAC" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TweakUAC_F72E/TweakUAC_thumb.png" width="454" border="0" />
          </a>
        </p>
        <p>
Dies UAC give you a rash ?
</p>
        <p>
It does me !!!
</p>
        <p>
It's not that it isn't a good idea - it is. But I really wish I could train it or
over ride it. 
</p>
        <p>
Maybe in a future Windows version - in the mean time, I'm trying Tweak UAC which provides
a "Quiet Mode" for UAC.
</p>
        <p>
[ <a href="http://www.tweak-uac.com" target="_blank">Click HERE to get Tweak UAC</a> ]
</p>
        <p>
Note: UAC is a Security feature. Strictly speaking "Quiet Mode"  reduces your
system's security.
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=f518d9fa-1062-490a-ab73-c33d72701514" />
      </body>
      <title>Tweak UAC</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,f518d9fa-1062-490a-ab73-c33d72701514.aspx</guid>
      <link>http://www.securedeveloper.com/TweakUAC.aspx</link>
      <pubDate>Fri, 18 Jul 2008 15:34:41 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TweakUAC_F72E/TweakUAC_2.png"&gt;&lt;img style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-RIGHT-WIDTH: 0px" height=327 alt=TweakUAC src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/TweakUAC_F72E/TweakUAC_thumb.png" width=454 border=0&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Dies UAC give you a rash ?
&lt;/p&gt;
&lt;p&gt;
It does me !!!
&lt;/p&gt;
&lt;p&gt;
It's not that it isn't a good idea - it is. But I really wish I could train it or
over ride it. 
&lt;/p&gt;
&lt;p&gt;
Maybe in a future Windows version - in the mean time, I'm trying Tweak UAC which provides
a "Quiet Mode" for UAC.
&lt;/p&gt;
&lt;p&gt;
[ &lt;a href="http://www.tweak-uac.com" target=_blank&gt;Click HERE to get Tweak UAC&lt;/a&gt; ]
&lt;/p&gt;
&lt;p&gt;
Note: UAC is a Security feature. Strictly speaking "Quiet Mode"&amp;nbsp; reduces your
system's security.
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=f518d9fa-1062-490a-ab73-c33d72701514" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,f518d9fa-1062-490a-ab73-c33d72701514.aspx</comments>
    </item>
    <item>
      <trackback:ping>http://www.securedeveloper.com/Trackback.aspx?guid=bb6d32e6-f6f5-40b2-b642-8080f238c655</trackback:ping>
      <pingback:server>http://www.securedeveloper.com/pingback.aspx</pingback:server>
      <pingback:target>http://www.securedeveloper.com/PermaLink,guid,bb6d32e6-f6f5-40b2-b642-8080f238c655.aspx</pingback:target>
      <dc:creator>JoeStagner</dc:creator>
      <wfw:comment>http://www.securedeveloper.com/CommentView,guid,bb6d32e6-f6f5-40b2-b642-8080f238c655.aspx</wfw:comment>
      <wfw:commentRss>http://www.securedeveloper.com/SyndicationService.asmx/GetEntryCommentsRss?guid=bb6d32e6-f6f5-40b2-b642-8080f238c655</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/NewSecurityVideoSeriesLaunched_7881/video-343_2.png">
            <img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="video-343" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/NewSecurityVideoSeriesLaunched_7881/video-343_thumb.png" width="154" height="114" />
          </a>
        </p>
        <p>
Please checkout the first videos in my new Web Developer's Security Video Series.
</p>
        <p>
          <a title="http://www.asp.net/learn/security-videos/" href="http://www.asp.net/learn/security-videos/">http://www.asp.net/learn/security-videos/</a>
        </p>
        <p>
I'm hoping to do 100 Videos this year !
</p>
        <p>
PLEASE SEND YOUR REQUESTS !!!
</p>
        <img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=bb6d32e6-f6f5-40b2-b642-8080f238c655" />
      </body>
      <title>New Security Video Series Launched</title>
      <guid isPermaLink="false">http://www.securedeveloper.com/PermaLink,guid,bb6d32e6-f6f5-40b2-b642-8080f238c655.aspx</guid>
      <link>http://www.securedeveloper.com/NewSecurityVideoSeriesLaunched.aspx</link>
      <pubDate>Fri, 18 Jul 2008 12:34:41 GMT</pubDate>
      <description>&lt;p&gt;
&lt;a href="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/NewSecurityVideoSeriesLaunched_7881/video-343_2.png"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" border="0" alt="video-343" src="http://www.securedeveloper.com/content/binary/WindowsLiveWriter/NewSecurityVideoSeriesLaunched_7881/video-343_thumb.png" width="154" height="114"&gt;&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
Please checkout the first videos in my new Web Developer's Security Video Series.
&lt;/p&gt;
&lt;p&gt;
&lt;a title="http://www.asp.net/learn/security-videos/" href="http://www.asp.net/learn/security-videos/"&gt;http://www.asp.net/learn/security-videos/&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I'm hoping to do 100 Videos this year !
&lt;/p&gt;
&lt;p&gt;
PLEASE SEND YOUR REQUESTS !!!
&lt;/p&gt;
&lt;img width="0" height="0" src="http://www.securedeveloper.com/aggbug.ashx?id=bb6d32e6-f6f5-40b2-b642-8080f238c655" /&gt;</description>
      <comments>http://www.securedeveloper.com/CommentView,guid,bb6d32e6-f6f5-40b2-b642-8080f238c655.aspx</comments>
    </item>
  </channel>
</rss>