<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4981981113585921735</id><updated>2012-02-26T10:01:57.110+01:00</updated><category term='GC-SEC'/><category term='Youtube'/><category term='SQL Injection'/><category term='malware'/><category term='Guide di Sicurezza'/><category term='privacy'/><category term='adobe'/><category term='Cloud security'/><category term='McAfee'/><category term='MessageLabs'/><category term='RSA'/><category term='Thorwed'/><category term='Security Summit'/><category term='MELANI'/><category term='fake AV'/><category term='OWASP'/><category term='hacktivism'/><category term='Diginotar'/><category term='spam'/><category term='conferenza'/><category term='Web application security'/><category term='cyberterrorism'/><category term='defacement'/><category term='CloudSIRT'/><category term='responsible disclosure'/><category term='full disclosure'/><category term='strategia difensiva'/><category term='Secunia'/><category term='patch'/><category term='Coreflood'/><category term='FBI'/><category term='shopping online'/><category term='smartphone'/><category term='NSTIC'/><category term='IE 6'/><category term='tweetviewer'/><category term='Incident Response'/><category term='worm'/><category term='Trojan'/><category term='XSS'/><category term='Best of the Week'/><category term='cybersecurity'/><category term='Twitter'/><category term='0day'/><category term='attacchi ai siti'/><category term='CERT-EU'/><category term='Rustock'/><category term='Voci Amiche'/><category term='svizzera'/><category term='advanced persistent threats'/><category term='criminalità informatica'/><category term='vulnerabilità'/><category term='hacking'/><category term='VBMania'/><category term='cyberlaudering'/><category term='MUMBLE'/><category term='Garante'/><category term='NATO'/><category term='IE 7'/><category term='PDF-X-RAY'/><category term='BEAST'/><category term='US-CERT'/><category term='sicurezza informatica'/><category term='skipfish'/><category term='Bredolab'/><category term='honeypot'/><category term='Android'/><category term='ENISA'/><category term='DNS Exfiltration'/><category term='social network'/><category term='CIE'/><category term='CNAIPIC'/><category term='DNSSEC'/><category term='m28sx'/><category term='social engineering'/><category term='workaround'/><category term='rapporto'/><category term='attacchi'/><category term='peer to peer'/><category term='Cyber War'/><category term='riflessioni sicurezza'/><category term='Java'/><category term='Google'/><category term='botnet'/><category term='Data breach'/><category term='phishing'/><category term='consigli di lettura'/><category term='antivirus'/><category term='Tequila'/><category term='wireless'/><category term='Zeus'/><category term='AET'/><category term='microsoft'/><category term='Verizon'/><category term='DAT'/><category term='file sharing'/><category term='Jarlsberg'/><category term='P2P'/><category term='Digital Agenda Assembly'/><category term='password'/><title type='text'>Punto 1</title><subtitle type='html'>Conversazioni sulla sicurezza informatica con Matteo Cavallini</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default?start-index=101&amp;max-results=100'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>247</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7094658820106173901</id><published>2012-02-26T10:01:00.003+01:00</published><updated>2012-02-26T10:01:57.127+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 26 Febbraio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;As always, security is one of the most hot topic in the press. Here's my list of the best security articles of this week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;The Rusi Journal &lt;a href="http://zite.to/yxxOhb" target="_blank"&gt;http://zite.to/yxxOhb&lt;/a&gt; - A very interesting article on "Cyber-Weapons"&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@e_kaspersky" target="_blank"&gt;@e_kaspersky&lt;/a&gt; Canadian Police: “We consume money. The bad guys make money. We’ll always be at a disadvantage” &lt;a href="http://bit.ly/wo67Of" target="_blank"&gt;bit.ly/wo67Of&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; UK Government Cyber-Crime Report Shows That Technical Solutions Alone Are Not Enough &lt;a href="http://flpbd.it/icmLn" target="_blank"&gt;flpbd.it/icmLn&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@jkouns" target="_blank"&gt;@jkouns&lt;/a&gt; Breach of Nortel could give hackers "a persistent presence in the telecommunications network" &lt;a href="http://is.gd/zeM6x4" target="_blank"&gt;is.gd/zeM6x4&lt;/a&gt; &amp;amp; &lt;a href="http://is.gd/LPS40v" target="_blank"&gt;is.gd/LPS40v&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@Jason_Healey" target="_blank"&gt;@Jason_Healey Holding&lt;/a&gt; nations responsible for nations from their cyber soil: &lt;a href="http://goo.gl/ecZzK" target="_blank"&gt;goo.gl/ecZzK&lt;/a&gt; including a 10-point scale of state responsibility&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@publicintel" target="_blank"&gt;@publicintel&lt;/a&gt; U.S. Strategic Command Workshop Report: Deterring Violent Non-State Actors in Cyberspace &lt;a href="http://bit.ly/xXoAjD" target="_blank"&gt;bit.ly/xXoAjD&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@moxie" target="_blank"&gt;@moxie&lt;/a&gt; CloudCracker now supports a phone numbers dictionary for WPA jobs (&lt;a href="https://t.co/Uyu2XLHG" target="_blank"&gt;cloudcracker.com/dictionaries.h…&lt;/a&gt;), which includes all phone numbers in US and Canada&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7094658820106173901?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7094658820106173901/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-26-febbraio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7094658820106173901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7094658820106173901'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-26-febbraio-2012.html' title='Best of the week - 26 Febbraio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2202328155640675363</id><published>2012-02-19T09:53:00.001+01:00</published><updated>2012-02-19T09:53:36.310+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 19 febbraio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here we are with another best of the week post. My list of the best security articles of this week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it!&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;a href="https://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; interview with TeaMp0isoN's "TriCk". Seriously, you ought to read this one...&amp;nbsp;&lt;a href="http://bit.ly/wcf1Pg" target="_blank"&gt;http://bit.ly/wcf1Pg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@jeremiahg" target="_blank"&gt;@jeremiahg&lt;/a&gt; If you're into Advanced (Oracle) SQL Injection, this post is required reading: &lt;a href="http://bit.ly/wyTUMb" target="_blank"&gt;bit.ly/wyTUMb&lt;/a&gt; &amp;lt;&lt;a href="https://twitter.com/@WhiteHatSec" target="_blank"&gt;@WhiteHatSec&lt;/a&gt; TRC hard at work&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@ProfWoodward" target="_blank"&gt;@ProfWoodward&lt;/a&gt; My feature piece this week on BBC:&lt;a href="http://t.co/FZAtct9a" target="_blank"&gt; bbc.co.uk/news/technolog…&lt;/a&gt; Many thanks to &lt;a href="https://tweitter.com/@neirajones" target="_blank"&gt;@neirajones&lt;/a&gt; for her comments - much appreciated.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@assolini" target="_blank"&gt;@assolini&lt;/a&gt; Have you uninstalled Java yet? Here are 14 new reasons... &lt;a href="http://zd.net/zcbLvR" target="_blank"&gt;zd.net/zcbLvR&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@mbenlakhoua" target="_blank"&gt;@mbenlakhoua&lt;/a&gt; RT &lt;a href="https://twitter.com/@sectechno" target="_blank"&gt;@sectechno&lt;/a&gt;: The Secunia Yearly Report 2011 Released &lt;a href="http://bit.ly/Ac0opk" target="_blank"&gt;bit.ly/Ac0opk&lt;/a&gt; #security #infosec&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@elie" target="_blank"&gt;@elie&lt;/a&gt; Attacking the Phishers: An Autopsy on Compromised Phishing Websites - &lt;a href="http://ow.ly/93qwq" target="_blank"&gt;ow.ly/93qwq&lt;/a&gt; #security #infosec&lt;br /&gt;&lt;br /&gt;And now, just to end this post with some humour... two gems coming from the net:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@KevinScanlan" target="_blank"&gt;@KevinScanlan&lt;/a&gt; "Rupert Murdoch is said to be deeply touched by the messages from family and friends left on whitney houston's phone."&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; Email spammers resort to extreme measures in order to bypass spam filters: &lt;a href="http://twitpic.com/8kdig6" target="_blank"&gt;twitpic.com/8kdig6&lt;/a&gt; /screenshot by &lt;a href="https://twitter.com/@ossij" target="_blank"&gt;@ossij&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5YgFn7XPm0U/T0C3wtMICLI/AAAAAAAAAXI/OVgQRrZXU2g/s1600/Spammers-image.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://1.bp.blogspot.com/-5YgFn7XPm0U/T0C3wtMICLI/AAAAAAAAAXI/OVgQRrZXU2g/s320/Spammers-image.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2202328155640675363?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2202328155640675363/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-19-febbraio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2202328155640675363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2202328155640675363'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-19-febbraio-2012.html' title='Best of the week - 19 febbraio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1992650878402793663</id><published>2012-02-12T12:22:00.001+01:00</published><updated>2012-02-12T12:24:34.056+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 12 febbraio 2012</title><content type='html'>&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here in Rome, snow came for the second time in a week. A big branch fell on the telephone line near my house so today I am completely isolated.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;There's only one solution... publish my list of the best security articles of the week, being away.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope you enjoy it!&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@candolin2" target="_blank"&gt;@candolin2&lt;/a&gt; Social Media to Be Included in 2012 Cyber Exercise - SIGNAL Magazine &lt;a href="http://shar.es/flaEH" target="_blank"&gt;shar.es/flaEH&lt;/a&gt; #cyber #exercise&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@websense" target="_blank"&gt;@websense&lt;/a&gt; Attackers using fake google analytics code to redirect users to black hole exploit kit &lt;a href="http://ow.ly/8XdXo" target="_blank"&gt;ow.ly/8XdXo&lt;/a&gt; &lt;a href="https://twitter.com/@threatpost" target="_blank"&gt;@threatpost&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@jeremiahg" target="_blank"&gt;@jeremiahg&lt;/a&gt; "Creating Backdoors Using SQL Injection" &lt;a href="http://bit.ly/ygWN34" target="_blank"&gt;bit.ly/ygWN34&lt;/a&gt; &amp;lt; pen-testers should like this one.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@metalabasia" target="_blank"&gt;@metalabasia&lt;/a&gt; Can Hackers Destroy The Internet? - Forbes &lt;a href="http://onforb.es/yUeEjx" target="_blank"&gt;onforb.es/yUeEjx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@arstechnica" target="_blank"&gt;@arstechnica&lt;/a&gt; A Valentine's Day present for SCADA companies: new exploit tools: &lt;a href="http://t.co/H20bIFca" target="_blank"&gt;arstechnica.com/business/news/…&lt;/a&gt; by &lt;a href="https://twitter.com/@thepacketrat" target="_blank"&gt;@thepacketrat&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@e_kaspersky" target="_blank"&gt;@e_kaspersky&lt;/a&gt; Comodo, Diginotar, Verisign, now Trustwave. The debates around trust in digital certificates heats up &lt;a href="http://bit.ly/ydIBbH" target="_blank"&gt;bit.ly/ydIBbH&lt;/a&gt; by &lt;a href="https://twitter.com/@k_sec" target="_blank"&gt;@k_sec&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1992650878402793663?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1992650878402793663/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-12-febbraio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1992650878402793663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1992650878402793663'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-12-febbraio-2012.html' title='Best of the week - 12 febbraio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8849457540188906900</id><published>2012-02-05T09:11:00.001+01:00</published><updated>2012-02-05T10:25:37.251+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 5 febbraio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Italy is frozen, in Rome the snow lays thick on the ground... but bad guys are relentless so, we need to stay informed.&lt;br /&gt;&lt;br /&gt;Which are the best security news of the week?&amp;nbsp;Here you can find my answer.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it!&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@candolin2" target="_blank"&gt;@candolin2&lt;/a&gt; FAQ about the VeriSign data breaches | Computerworld New Zealand &lt;a href="http://t.co/SGT1fUk1" target="_blank"&gt;computerworld.co.nz/news.nsf/secur…&lt;/a&gt; via &lt;a href="https://twitter.com/@computerworldnz" target="_blank"&gt;@computerworldnz&lt;/a&gt; #verisign&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@CiscoGGSG" target="_blank"&gt;@CiscoGGSG&lt;/a&gt; VeriSign hack: Reactions from the security community &lt;a href="http://fb.me/1kSufkczk"&gt;fb.me/1kSufkczk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@ProfWoodward" target="_blank"&gt;@ProfWoodward&lt;/a&gt; &amp;nbsp;New computer incident handling guidelines drafted for comment by NIST in the US: &lt;a href="http://t.co/W7x6wLtJ" target="_blank"&gt;csrc.nist.gov/publications/d…&lt;/a&gt; See what you think.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@metalabasia" target="_blank"&gt;@metalabasia&lt;/a&gt; Rare interview with Gulshan Rai, head of CERT-In &lt;a href="http://t.co/WElbNq0g" target="_blank"&gt;livemint.com/2012/01/312300…&lt;/a&gt; via &lt;a href="https://twitter.com/@livemint" target="_blank"&gt;@livemint&lt;/a&gt; #india #malware&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@CERTXMCO" target="_blank"&gt;@CERTXMCO&lt;/a&gt; [Blog XMCO] La cybercriminalité made in France --&amp;gt; &lt;a href="https://t.co/kfAR7jxp" target="_blank"&gt;cert.xmco.fr/blog/index.php…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@cuoretoro" target="_blank"&gt;@cuoretoro&lt;/a&gt; US spy agencies look to cloud computing &lt;a href="http://lnkd.in/vK22iS"&gt;lnkd.in/vK22iS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This week, the last report is not a news but a very interesting initiative. A good friend, "&lt;a href="http://blogger.quasidot.com/" target="_blank"&gt;Francesco Armando&lt;/a&gt;", has collected a lot of blogs devoted to security and created a page named "&lt;a href="http://www.blist.quasidot.com/b-opml/" target="_blank"&gt;The security (B)log list&lt;/a&gt;", in which he put together all the links. Since I think this initiative could be of some help to have a complete view on the security scenario, if you like it, please, spread the link.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8849457540188906900?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8849457540188906900/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-5-febbraio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8849457540188906900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8849457540188906900'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/02/best-of-week-5-febbraio-2012.html' title='Best of the week - 5 febbraio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4091625553804295272</id><published>2012-02-02T11:45:00.001+01:00</published><updated>2012-02-02T11:46:11.169+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberterrorism'/><title type='text'>La minaccia cyber supererà il terrorismo</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-hSeDZBMtErM/Typi1u9JQoI/AAAAAAAAAXA/X5Y3igr965s/s1600/Robert-Mueller-James-Clapper.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="225" src="http://3.bp.blogspot.com/-hSeDZBMtErM/Typi1u9JQoI/AAAAAAAAAXA/X5Y3igr965s/s320/Robert-Mueller-James-Clapper.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small; text-align: justify;"&gt;(AP Photo/Jacquelyn Martin)&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt;Parola del direttore dell'FBI!!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il 31 gennaio scorso, Robert Mueller ha testimoniato davanti al Comitato senatoriale sull'intelligence e, in estrema sintesi, ha dichiarato che la minaccia terroristica è in declino mentre le minacce cyber sono ascesa e quindi nel medio periodo è probabile che l'importanza di queste ultime diventi prevalente su tutte le altre.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Rispetto all'usuale &lt;a href="http://it.wikipedia.org/wiki/Fear,_uncertainty_and_doubt" target="_blank"&gt;FUD&lt;/a&gt; (Paura, Incertezza e Dubbio) che viene normalmente speso a piene mani su questi temi da parte di amministrazioni pubbliche alla ricerca di finanziamenti, questa volta le notizie che sono trapelate mi sembrano frutto di ragionamenti condivisibili, ma vediamo più da vicino cosa è stato detto dal Direttore dell'FBI.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ecco &lt;a href="http://abcnews.go.com/blogs/politics/2012/01/fbi-director-says-cyberthreat-will-surpass-threat-from-terrorists/" target="_blank"&gt;alcuni stralci&lt;/a&gt; presi da questa audizione.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;"Non penso che le minacce di cyber-espionage, computer crime e di attacchi cyber alle infrastrutture critiche siano al momento le minacce numero uno, ma lo saranno domani. Ad oggi, la priorità numero uno dell'FBI è l'antiterrorismo. Nel prossimo futuro le minacce cyber, che impattano tutti i programmi dell'FBI, diventeranno la minaccia numero uno per il paese"&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"La minaccia cyber è una delle più complesse con cui ci confrontiamo. Russia e Cina, tra gli attori statuali, sono quelli che ci preoccupano maggiormente in quanto conducono intrusioni nelle nostre reti al fine di rubare dati. Anche il crescente ruolo degli attori non-statuali è un grande esempio della facilità di accesso a tecnologie distruttive e potenzialmente letali da parte di questi gruppi."&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"Posso dirvi che siamo eccezionalmente preoccupati da queste minacce"&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"In modo analogo a come abbiamo cambiato la lotta al terrorismo dobbiamo cambiare la lotta al cybercrime. Dobbiamo costruire uno sforzo collettivo e globale per combattere questa minaccia nello stesso modo in cui abbiamo operato in conseguenza dell'11 settembre."&amp;nbsp;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bisogna&amp;nbsp;anche&amp;nbsp;ricordare che quest'audizione si pone nel mezzo del dibattito che porterà, nel prossimo mese, ad una decisione in merito a nuove competenze da affidare al Department of Homeland Security in materia di protezione delle reti collegate ad infrastrutture critiche.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il mio pensiero, a questo punto, torna quindi all'Italia e alla grande mole di lavoro che ci aspetta. In questo mondo che cambia alla velocità della luce le lentezze del nostro paese rischiano proprio di lasciarci in un mare di guai.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Buona giornata a tutti.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4091625553804295272?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4091625553804295272/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/02/la-minaccia-cyber-superera-il.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4091625553804295272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4091625553804295272'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/02/la-minaccia-cyber-superera-il.html' title='La minaccia cyber supererà il terrorismo'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-hSeDZBMtErM/Typi1u9JQoI/AAAAAAAAAXA/X5Y3igr965s/s72-c/Robert-Mueller-James-Clapper.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5864233437740321997</id><published>2012-01-29T09:27:00.001+01:00</published><updated>2012-01-29T09:27:43.082+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 29 gennaio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here you can find my list of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;First of all, the cloud section...&lt;br /&gt;&lt;a href="https://twitter.com/@cuoretoro" target="_blank"&gt;@cuoretoro&lt;/a&gt; US spy agencies look to cloud computing &lt;a href="http://lnkd.in/vK22iS" target="_blank"&gt;lnkd.in/vK22iS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@georgevhulme" target="_blank"&gt;@georgevhulme&lt;/a&gt;&amp;nbsp;The transition to cloud - an opportunity to get application security right:&amp;nbsp;&lt;a href="http://bit.ly/zprtEo" target="_blank"&gt;bit.ly/zprtEo&lt;/a&gt;&amp;nbsp;#infosec&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@slashdot" target="_blank"&gt;@slashdot&lt;/a&gt; New Privacy Laws Could Boost EU Cloud Industry &lt;a href="http://bit.ly/zlQaM1" target="_blank"&gt;bit.ly/zlQaM1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;secondly, the general security section..&lt;br /&gt;&lt;a href="https://twitter.com/@DarkReading" target="_blank"&gt;@DarkReading&lt;/a&gt; Zappos, Amazon sued over data breach: &lt;a href="http://ow.ly/8Ewm4" target="_blank"&gt;ow.ly/8Ewm4&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@dsancho66" target="_blank"&gt;@dsancho66&lt;/a&gt; Cyberpower index: &lt;a href="http://is.gd/pcjwr3" target="_blank"&gt;is.gd/pcjwr3&lt;/a&gt; &amp;lt;- Spain is not even in the list&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@KimZetter" target="_blank"&gt;@KimZetter&lt;/a&gt; Mapping Tool Shows 10,000 Reasons to Worry about Critical Infrastructure - &lt;a href="http://bit.ly/wNJciI" target="_blank"&gt;bit.ly/wNJciI&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;and to finish, the laughs section...&lt;br /&gt;&lt;a href="https://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; Only four more years to go until EU Copyright expires for 'Happy Birthday to You' and then we can all sing it for free! &lt;a href="http://t.co/QRj0qx3V" target="_blank"&gt;en.wikipedia.org/wiki/Happy_Bir…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5864233437740321997?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5864233437740321997/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-29-gennaio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5864233437740321997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5864233437740321997'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-29-gennaio-2012.html' title='Best of the week - 29 gennaio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4186211476249588929</id><published>2012-01-22T08:45:00.001+01:00</published><updated>2012-01-22T08:49:43.908+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 22 gennaio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;A new week is just around the corner and a lot of security news are ready to be published, but which are the best security news of this week? Here you can find the answer!&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@RealSecurity" target="_blank"&gt;@RealSecurity&lt;/a&gt; Anonymous Changes DDoS Tactics in Megaupload Retaliation &lt;a href="http://bit.ly/ypGYWB" target="_blank"&gt;bit.ly/ypGYWB&lt;/a&gt; via &lt;a href="https://twitter.com/@threatpost" target="_blank"&gt;@threatpost&lt;/a&gt; #security&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@assolini" target="_blank"&gt;@assolini&lt;/a&gt; Brazilian cybercriminals’ daily earnings – more than you’ll ever earn in a year! | Securelist &lt;a href="http://bit.ly/xv85jy" target="_blank"&gt;bit.ly/xv85jy&lt;/a&gt; (by &lt;a href="https://twitter.com/@dimitribest" target="_blank"&gt;@dimitribest&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@InfosecNewsBot" target="_blank"&gt;@InfosecNewsBot&lt;/a&gt; 74% believe mobile devices increase security incidents: The number of personal mobile devices connectin... &lt;a href="http://bit.ly/x1uJX5" target="_blank"&gt;bit.ly/x1uJX5&lt;/a&gt; #infosec&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@metalabasia" target="_blank"&gt;@metalabasia&lt;/a&gt; Brian White, managing director of the Chertoff Group, Discusses Cyber Attack Against Amazon's Zappos &lt;a href="http://t.co/I1bTE3ff" target="_blank"&gt;washingtonpost.com/business/white…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; Sophos blogs about phishing sites hosted on Google Docs: &lt;a href="http://t.co/B4QCQxR0" target="_blank"&gt;nakedsecurity.sophos.com/2012/01/16/goo…&lt;/a&gt; Our take on this, from last May:&amp;nbsp;&lt;a href="http://t.co/LehDwjnU" target="_blank"&gt;f-secure.com/weblog/archive…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@SecureEB" target="_blank"&gt;@SecureEB&lt;/a&gt; #security Mourad: Google services for Handling and Cleaning Infected Websites &lt;a href="http://dlvr.it/15jDkQ" target="_blank"&gt;dlvr.it/15jDkQ&lt;/a&gt; #infosec&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4186211476249588929?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4186211476249588929/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-22-gennaio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4186211476249588929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4186211476249588929'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-22-gennaio-2012.html' title='Best of the week - 22 gennaio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-9042784397533435941</id><published>2012-01-15T09:34:00.001+01:00</published><updated>2012-01-15T09:34:35.229+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 15 gennaio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;This week I found a lot of interesting readings and here is the list of the best security resources.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@eEye" target="_blank"&gt;@eEye&lt;/a&gt; RT &lt;a href="https://twitter.com/@hugsec" target="_blank"&gt;@hugsec&lt;/a&gt;: Trends in Security &lt;a href="http://dlvr.it/159FtY" target="_blank"&gt;dlvr.it/159FtY&lt;/a&gt; #InfoSec #security #vulnerability&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@CND_Ltd" target="_blank"&gt;@CND_Ltd&lt;/a&gt; Microsoft Readying Real Time Hosted Threat Intelligence Feed &lt;a href="http://bit.ly/wHQVIf" target="_blank"&gt;bit.ly/wHQVIf&lt;/a&gt; via &lt;a href="https://twitter.com/@threatpost" target="_blank"&gt;@threatpost&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@dsancho66" target="_blank"&gt;@dsancho66&lt;/a&gt; Why Internet crime goes unpunished: &lt;a href="http://is.gd/SrQXRT" target="_blank"&gt;is.gd/SrQXRT&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@RonGula" target="_blank"&gt;@RonGula&lt;/a&gt; Very cool youtube video from Stratfor CEO about their recent attacks and compromises : &lt;a href="http://youtu.be/ItreEs03A2k" target="_blank"&gt;youtu.be/ItreEs03A2k&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://https.//twitter.com/@DrInfoSec" target="_blank"&gt;@DrInfoSec&lt;/a&gt; A Practical Guide to Implementing SEC Guidance on Disclosure of Cybersecurity Risks &lt;a href="http://t.co/fQ7P4gfU" target="_blank"&gt;jdsupra.com/post/documentV…&lt;/a&gt; [PDF is worth the quick read]&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; 4TB+ of rainbowtables to download &lt;a href="http://freerainbowtables.com/en/tables2/" target="_blank"&gt;freerainbowtables.com/en/tables2/&lt;/a&gt; &amp;lt;= Distributed Rainbow Tables Project.. - (4TB??? It's a huge amount of data!!!!)&lt;br /&gt;&lt;br /&gt;&lt;a href="https://twitter.com/@e_kaspersky" target="_blank"&gt;@e_kaspersky&lt;/a&gt; There is no winning party in #cyberwarfare. It's a boomerang as much as nuclear weapons. Great reading: &lt;a href="http://bit.ly/wRSqIo" target="_blank"&gt;bit.ly/wRSqIo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-9042784397533435941?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/9042784397533435941/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-15-gennaio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/9042784397533435941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/9042784397533435941'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-15-gennaio-2012.html' title='Best of the week - 15 gennaio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-272740756883830677</id><published>2012-01-11T16:46:00.002+01:00</published><updated>2012-01-12T10:37:15.165+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><title type='text'>Cloud Incident Response: Detection and Declaration</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-UMnIs7Nyedc/Tw2s-7ktMeI/AAAAAAAAAW4/hNSlpR1RV9I/s1600/Cloud-Incident-Detection.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="187" src="http://2.bp.blogspot.com/-UMnIs7Nyedc/Tw2s-7ktMeI/AAAAAAAAAW4/hNSlpR1RV9I/s200/Cloud-Incident-Detection.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Modified from the&amp;nbsp;original&amp;nbsp;Wired's image&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;Here's another part of the &lt;a href="http://www.matteocavallini.com/p/cloud-incident-response.html" target="_blank"&gt;series devoted to cloud incident response&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;This time we will talk about incident detection and incident declaration. These topics are closely linked and well developed in classical environments but are still immature in cloud services, so let's begin to explore them.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;&lt;b&gt;Phase 1 - Incident Detection&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;This phase is common to every security incident and, in non-cloud environments, can be performed either by a final user who sees something strange in his/her service or by an operational team that becomes aware of the problem. In the first case, the user can warn the security that performs some checks with the operational teams in order to clear the exact nature of the reported event. In the second case, the activation of the security team is internal and, usually, the investigations will start almost immediately.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;This approach is a little bit different in cloud services because the roles of the final user and the operational team are tailored in a different manner and, in some cases, the Cloud Service Provider (CSP) could have only a portion of the essential data. So, taking a closer look at the possibilities, we become&amp;nbsp; immediately aware that the erogation models of the cloud services change the operational scenario. Infact, also in the simplest situation in which the service is erogated directly by only one CSP, the state changes radically if the service is a Software as a Service (saaS), or a Platform as a Service (PaaS), or an Infrastructure as a Service (IaaS).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;In the SaaS case, the user has only access to some personal activity log without any access to system information. In this scenario, the CSP has to conduct all the incident detection activities and the Cloud Service Consumer (CSC) is totally dependent on the information items shared by the CSP. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;IaaS represents the complementary situation; in this erogation model the CSP directly manages only the network security layer, on the contrary all the information regarding the inner layer, from the OS to the application, are a CSC matter.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;PaaS is in the middle between the previous cases with a different involvement of the CSC varying the implementation.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;The above reasons imply that, in order to have the right instruments to respond to incidents in cloud environments, the information sharing between CSP and CSC is essential. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;Since clauses regulate every aspect of the cloud services, also these matters have to be clearly defined in the contract. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;These clauses have to set at least the following features:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;- the expected pieces of information that have to be exchanged&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;- the triggers for the information sharing&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;- the temporal SLA for the exchange of information&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;- the confidentiality level of any information shared.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;&lt;b&gt;Phase 2 - Declaration&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;In this phase, after the detection, someone has to declare the incident. T&lt;/span&gt;his moment is crucial for the effective response of an incident; a bad move in this phase&amp;nbsp;might affect all the following activities, compromising the final outcome.&amp;nbsp;But, who is in charge of this activity? And, which is the best way to approach this critical phase? And finally, which cases have to go public?&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;These questions are pertaining to every CSP and it's nearly impossible to give indications or best practices... &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;except this one: "Every CSP has to be well prepared!"&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;A plan has to be prearranged, officially issued and shared between the operational teams.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;Moreover, after every incident a review has to be performed to verify the effectiveness of the plan.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;In conclusion, every CSC, while approaching a CSP, should verify the presence and the effectiveness of such a plan checking the compliance of this document with law, regulations and his requirements.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span lang="EN-US"&gt;Well, for this post it is enough, in the following parts I'll share with you other thoughts on the Cloud Incident Response, so... stay tuned!&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-272740756883830677?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/272740756883830677/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/cloud-incident-response-detection-and.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/272740756883830677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/272740756883830677'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/cloud-incident-response-detection-and.html' title='Cloud Incident Response: Detection and Declaration'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-UMnIs7Nyedc/Tw2s-7ktMeI/AAAAAAAAAW4/hNSlpR1RV9I/s72-c/Cloud-Incident-Detection.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8122194230721333763</id><published>2012-01-08T09:22:00.001+01:00</published><updated>2012-01-08T09:26:17.233+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 8 gennaio 2012</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Regular publications of the series "Best of the Week" are started again and here you can find my new selection of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RIPE_NCC" target="_blank"&gt;@RIPE_NCC&lt;/a&gt; Vint Cerf: Internet Access is Not a Human Right &lt;a href="http://nyti.ms/AmPQp1" target="_blank"&gt;nyti.ms/AmPQp1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CERT_Polska_en" target="_blank"&gt;@CERT_Polska_en&lt;/a&gt; Results of our long term analysis of the #ZeuS P2P+DGA trojan published, including the mapping out of it's network: &lt;a href="http://t.co/8UvPB70w" target="_blank"&gt;cert.pl/news/4711/lang…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mthorbruegge" target="_blank"&gt;@mthorbruegge&lt;/a&gt; RT &lt;a href="http://twitter.com/@ProjectHoneynet" target="_blank"&gt;@ProjectHoneynet:&lt;/a&gt; There's a great series of malware analysis tutorials starting here: &lt;a href="http://t.co/SxMzxdBc" target="_blank"&gt;fumalwareanalysis.blogspot.com/2011/08/malwar…&lt;/a&gt; #malware&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@VJirasek" target="_blank"&gt;@VJirasek&lt;/a&gt; RT &lt;a href="http://twitter.com/@PeterWoodx" target="_blank"&gt;@PeterWoodx&lt;/a&gt;: Cracking 14 Character Complex Passwords in 5 Seconds &lt;a href="http://bit.ly/yczo3q"&gt;bit.ly/yczo3q&lt;/a&gt; &amp;lt;- &lt;a href="http://twitter.com/@miketmclaughlin" target="_blank"&gt;@miketmclaughlin&lt;/a&gt;&amp;nbsp;&lt;time away="" from="" move="" p="" pwds&lt;="" to=""&gt;&lt;/time&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CiscoGGSG" target="_blank"&gt;@CiscoGGSG&lt;/a&gt; 2012 Cybersecurity Trends to Watch in Government&amp;nbsp;&lt;a href="http://fb.me/1Bt5v0mpc" target="_blank"&gt;http://fb.me/1Bt5v0mpc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; Allocating Security Resources to Protect Critical Infrastructure &lt;a href="http://flpbd.it/QsLv" target="_blank"&gt;flpbd.it/QsLv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@kakroo" target="_blank"&gt;@kakroo&lt;/a&gt; Cloud SWAT teams - Cloud computing poses unique security challenges. Here's how cloud-specific 'security incident-re... &lt;a href="http://ht.ly/1gvAjT" target="_blank"&gt;ht.ly/1gvAjT&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8122194230721333763?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8122194230721333763/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-8-gennaio-2012.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8122194230721333763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8122194230721333763'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-8-gennaio-2012.html' title='Best of the Week - 8 gennaio 2012'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2225376269721378902</id><published>2012-01-05T21:20:00.000+01:00</published><updated>2012-01-13T18:08:29.306+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='responsible disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='Thorwed'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Thorwed: a conversation with the hacker</title><content type='html'>&lt;div style="text-align: justify;"&gt;Some days ago, I &lt;a href="http://www.matteocavallini.com/2011/12/bucato-un-sito-del-ministero.html" target="_blank"&gt;found&lt;/a&gt; that a governmental Italian site (&lt;a href="http://qualitapa.gov.it/" target="_blank"&gt;qualitapa.gov.it&lt;/a&gt;) was hacked by an hacker named Thorwed. Thorwed owned the DB and then published all the usernames and passwords of the site (more than 9000 entries) on Pastebin. Since I work for a governmental CERT, I warned the people in charge of the security of this site and then, with the essential help of some friends, we sent an email to all the involved users asking them to change their passwords.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;After few days, other &lt;a href="http://www.matteocavallini.com/2011/12/joint-research-center-hacked-rainews24.html" target="_blank"&gt;two "events"&lt;/a&gt; occurred, the &lt;a href="http://mahb.jrc.it/" target="_blank"&gt;Joint Research Centre&lt;/a&gt; and the &lt;a href="http://www.rainews24.rai.it/" target="_blank"&gt;Rainews24&lt;/a&gt; sites were hacked and, again, all data (usernames, passwords and emails) were published by Thorwed on Pastebin.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Same situation, same response.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The day after all has finished, but I was very intrigued by the actions of this hacker so I decided to leave a message on Pastebin, asking Thorwed to contact me.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-a-dqnRsQZyY/TwXvrpXoyDI/AAAAAAAAAWk/729p_WtsNic/s1600/To-Thorwed.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://2.bp.blogspot.com/-a-dqnRsQZyY/TwXvrpXoyDI/AAAAAAAAAWk/729p_WtsNic/s400/To-Thorwed.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This evening I found on my blog and on &lt;a href="http://pastebin.com/F1VUczh2" target="_blank"&gt;Pastebin&lt;/a&gt; this message left by Thorwed:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;"# Thorwed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;# I apologize in advance http://translate.google.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;# http://pastebin.com/F1VUczh2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Hi Matteo, I am Thorwed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Let me explain about: (&lt;a href="http://pastebin.com/uBMFL4R3" target="_blank"&gt;http://pastebin.com/uBMFL4R3&lt;/a&gt;).&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;The first laid the basis of (qualitapa.gov.it), which contained (login; pass; mail) a day later it was modified,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;where I wrote the reasons for their actions:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;"... I am very sad to look at the large site with such childish errors that are fixed for a few minutes.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;This is especially true of government websites. In December, an error that could be eliminated within a few minutes was the diversion of 9000 + data.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;I think you ask why I showed the entire database? but if I showed only a mistake nobody would have noticed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;When I put a base on pastebin.com it turns out there was already an analogy only it contained the names of the tables.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;(&lt;a href="http://pastebin.com/XLZ0iLZy" target="_blank"&gt;http://pastebin.com/XLZ0iLZy&lt;/a&gt;) on October 10, ridiculous is not it? Nobody paid any attention to even and did not close the error."&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;I think the reasons for these large and important sites such as Rainews24 and others are not worth explaining.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;I just want to add, in a world very vulnerable state sites.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Oh yeah I forgot to say that I stopped and I was left with a list of vulnerable sites of domain zones (. Gov.uk,. Gov.vi and others), but they will not leak.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Goodbye. Yours faithfully. Thorwed ..."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;First of all, I want to thank Thorwed to have accepted my invitation.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Secondly, I want write a public answer to the Thorwed's message:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"Thorwed, I remember that you had a Twitter account in which you wrote "Con la esperanza de hacerlo mejor...".&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-WsXMqW6HLVA/TwXylaCLTgI/AAAAAAAAAWw/drGsoVWgT8s/s1600/Thorwed-Twitter-account.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: justify;"&gt;&lt;img border="0" height="93" src="http://4.bp.blogspot.com/-WsXMqW6HLVA/TwXylaCLTgI/AAAAAAAAAWw/drGsoVWgT8s/s320/Thorwed-Twitter-account.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Well, you do have the possibility to make it better... and this possibility is called "&lt;a href="http://www.google.it/url?sa=t&amp;amp;rct=j&amp;amp;q=%22responsible%20disclosure%22%20wikipedia&amp;amp;source=web&amp;amp;cd=1&amp;amp;ved=0CCQQFjAA&amp;amp;url=http%3A%2F%2Fen.wikipedia.org%2Fwiki%2FResponsible_disclosure&amp;amp;ei=XQUGT5DrBOrj4QSNgvmVDA&amp;amp;usg=AFQjCNFmNeOlwsoL6jMdL8q3Q1iKtaLgdA" target="_blank"&gt;Responsible disclosure&lt;/a&gt;".&amp;nbsp;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;I don't want to bother you giving a definition of what responsible disclosure&amp;nbsp;is&amp;nbsp;or highlighting the importance of a such approach.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I just want to say that, if your goal is the improvement of the&amp;nbsp;websites&amp;nbsp;security, particularly the governmental ones, just send me your findings privately,&amp;nbsp;I can forward them to the right people and then publish your discovery on my blog.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This way, you can&amp;nbsp;achieve your goals and&amp;nbsp;obtain the deserved visibility without harming anyone.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Think about it.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This makes the difference between an offence and a meritorious action.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Write me, this is my email address&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/-MpuYVmz9gbk/TCSiiD8b6rI/AAAAAAAAAGo/ezdK7VNg2wU/s1600/Indirizzo_di_posta.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="28" src="http://1.bp.blogspot.com/-MpuYVmz9gbk/TCSiiD8b6rI/AAAAAAAAAGo/ezdK7VNg2wU/s200/Indirizzo_di_posta.PNG" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bye,&lt;br /&gt;Matteo&lt;br /&gt;-----------------------------------------------------------------------------------&lt;br /&gt;Update to the post (January 13, 2012)&lt;br /&gt;&lt;br /&gt;Some days ago Thorwed contacted me privately to submit some information regarding a couple of vulnerabilites found on many Italian sites. Most of these sites are registered by private citizens and companies but some of them are school websites within the "gov.it" domain.&lt;br /&gt;&lt;br /&gt;In association with a friend, I performed some checks to verify the quality of these warnings then I sent a report to some of the owners of the vulnerable sites.&lt;br /&gt;&lt;br /&gt;I want to publicly thank Thorwed for accepting my invitation to disclose this kind of &amp;nbsp;information more responsibly.&lt;br /&gt;&lt;br /&gt;In the next few days I will verify, if at least the gov.it domain will be fixed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2225376269721378902?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2225376269721378902/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/thorwed-conversation-with-hacker.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2225376269721378902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2225376269721378902'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/thorwed-conversation-with-hacker.html' title='Thorwed: a conversation with the hacker'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-a-dqnRsQZyY/TwXvrpXoyDI/AAAAAAAAAWk/729p_WtsNic/s72-c/To-Thorwed.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4799249357424249675</id><published>2012-01-04T10:35:00.001+01:00</published><updated>2012-01-04T11:18:59.737+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacktivism'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberterrorism'/><title type='text'>Tra Hacktivism e Cyberterrorism</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-rvdDdKS8ZkY/TwQbyubQ3RI/AAAAAAAAAWY/Xs94kIUOYnI/s1600/Wahhabi-Hacker.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-rvdDdKS8ZkY/TwQbyubQ3RI/AAAAAAAAAWY/Xs94kIUOYnI/s200/Wahhabi-Hacker.jpg" width="193" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il nuovo anno ha portato agli Israeliani un'amara sorpresa!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;0xOmar del gruppo "group-xp", il più grande gruppo di hacker Wahabiti dell'Arabia Saudita, legato anche al movimento Anonymous, ha pubblicato su &lt;a href="http://pastebin.com/WaSDNbsE" target="_blank"&gt;Pastebin&lt;/a&gt; e su &lt;a href="http://pastebay.com/148920" target="_blank"&gt;Pastebay&lt;/a&gt; un comunicato in cui annuncia di aver reso disponibili i dati di 400.000 carte di credito appartenenti appunto a cittadini israeliani.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questo gesto viene spiegato con una finalità che sta a metà tra la protesta e il "terrorismo", infatti viene chiaramente detto che questo è il primo passo di un'operazione che ha come obiettivo finale la compromissione di 1 milione di carte con i relativi dati di identità. In un paese come Israele che detiene complessivamente tra i 6 e i 7 milioni di carte, questa compromissione rappresenterebbe una quota decisamente rilevante. Se ciò si dovesse avverare comporterebbe &amp;nbsp; certamente grandi problemi nel paese. Problemi che vengono anticipati nel comunicato stesso da parte degli hacker arabi:&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;What's fun for us?&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;- Watching&lt;/span&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="nu0" style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;400&lt;/span&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;,&lt;/span&gt;&lt;span class="nu0" style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;000&lt;/span&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;people gathered in front of Israeli credit card companies and banks, complaining about cards and that they are stolen&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;- Watching Israeli banks shredding&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="nu0" style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;400&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;,&lt;/span&gt;&lt;span class="nu0" style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;000&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;credit cards and re-generate new cards&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="br0" style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;(&lt;/span&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;so costly, huh?&lt;/span&gt;&lt;span class="br0" style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;)&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;- Watching people purchasing stuff for theirself using the cards and making Israeli credit cards untrustable in the world, like Nigerian credit cards&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;- and much more..."&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="background-color: #f8f8f8; color: #333333; font-family: 'Courier New', Courier, monospace; font-size: 12px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Al di là dei numeri, che &lt;a href="http://borsaitaliana.it.reuters.com/article/foreignNews/idITL6E8C30S720120103" target="_blank"&gt;un comunicato di Isracard&lt;/a&gt; ridemensiona moltissimo, la cosa che trovo più rilevante in questa operazione è il cambio di strategia che vi è sotteso. Un cambio che punta alla creazione del caos attraverso l'utilizzo di informazioni e procedure che, di norma, sono appannaggio dei cybercriminali e che ora, invece, vengono usate con scopi di cyberprotesta al limite del cyberterrorismo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Credo che questo tipo di evoluzione sia solo l'anticipazione di quanto potrà avvenire nel corso dell'anno appena iniziato.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E' infatti veramente troppo facile portare a termine questo tipo di operazioni e creare scompiglio senza dover affrontare i grandi rischi che un gruppo di terroristi che opera in maniera tradizionale è costretto a &amp;nbsp;correre.&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4799249357424249675?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4799249357424249675/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/tra-hacktivism-e-cyberterrorism.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4799249357424249675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4799249357424249675'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/tra-hacktivism-e-cyberterrorism.html' title='Tra Hacktivism e Cyberterrorism'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-rvdDdKS8ZkY/TwQbyubQ3RI/AAAAAAAAAWY/Xs94kIUOYnI/s72-c/Wahhabi-Hacker.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5971022144277975533</id><published>2012-01-01T10:44:00.001+01:00</published><updated>2012-01-04T10:57:36.922+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - New Year Edition</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-dQIXHgU81oY/TwApowLDIII/AAAAAAAAAWM/BTmVtL_RMc8/s1600/Best-of-the-week-new-year.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="241" src="http://2.bp.blogspot.com/-dQIXHgU81oY/TwApowLDIII/AAAAAAAAAWM/BTmVtL_RMc8/s320/Best-of-the-week-new-year.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;Well, a new year has come and, starting from today, we&amp;nbsp;will be able to&amp;nbsp;verify all the security prediction made these days.  &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Meanwhile, here you can find the best security resources of the last week of the year.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope you enjoy it.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Happy new year to all of you!!&lt;/div&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@QatarCERT" target="_blank"&gt;@QatarCERT&lt;/a&gt;: Q-CERT Weekly Newsletter,01 January,2012 - &lt;a href="http://eepurl.com/h_CWQ" target="_blank"&gt;http://eepurl.com/h_CWQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Security_FAQs" target="_blank"&gt;@Security_FAQs&lt;/a&gt; Why Is Sand Boxing A Most Wanted Security Feature? &lt;a href="http://bit.ly/vubIzd" target="_blank"&gt;http://bit.ly/vubIzd&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@dimitribest" target="_blank"&gt;@dimitribest&lt;/a&gt; Know the story about Stuxnet? For sure you didn't. This is the new story with the new malware platform “Tilded” &lt;a href="https://www.securelist.com/en/analysis/..." target="_blank"&gt;https://www.securelist.com/en/analysis/...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; Ideas about China’s Cyber Command - Council on Foreign Relations - &lt;a href="http://on.cfr.org/v9amPv" target="_blank"&gt;http://on.cfr.org/v9amPv&lt;/a&gt; (cc: &lt;a href="http://twitter.com/@taosecurity" target="_blank"&gt;@taosecurity&lt;/a&gt; &lt;a href="http://twitter.com/@jeffreycarr" target="_blank"&gt;@jeffreycarr&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@hdmoore" target="_blank"&gt;@hdmoore&lt;/a&gt; RT &lt;a href="http://twitter.com/@effffn" target="_blank"&gt;@effffn&lt;/a&gt;: are you also missing 28c3? watch the talks online &lt;a href="http://bit.ly/vpwUec" target="_blank"&gt;http://bit.ly/vpwUec&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="justify"&gt;﻿&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5971022144277975533?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5971022144277975533/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-new-year-edition.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5971022144277975533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5971022144277975533'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2012/01/best-of-week-new-year-edition.html' title='Best of the week - New Year Edition'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-dQIXHgU81oY/TwApowLDIII/AAAAAAAAAWM/BTmVtL_RMc8/s72-c/Best-of-the-week-new-year.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1582543187296207663</id><published>2011-12-30T22:59:00.000+01:00</published><updated>2011-12-31T13:20:39.676+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web application security'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='Thorwed'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Joint Research Centre hacked - Rainews24 hacked</title><content type='html'>Ebbene si. Volevo evitare di scrivere sul blog fino al nuovo anno, ma non è stato possibile.&lt;br /&gt;&lt;br /&gt;Oggi è stato tutto un susseguirsi di mail e telefonate e, tra veri e presunti attacchi, è uscito fuori un bel quadro.&lt;br /&gt;&lt;br /&gt;Vi riporto solo gli incidenti più importanti... che, oltretutto sono legati allo stesso autore: il già noto Thorwed autore dell'&lt;a href="http://www.matteocavallini.com/2011/12/bucato-un-sito-del-ministero.html" target="_blank"&gt;attacco al sito qualitapa.gov.it&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Vediamo cosa ha combinato oggi...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-gdLNLV7jxmc/Tv4zJQ6oUiI/AAAAAAAAAVc/18UYB_iH4_0/s1600/Mahb-JRC.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="50" src="http://1.bp.blogspot.com/-gdLNLV7jxmc/Tv4zJQ6oUiI/AAAAAAAAAVc/18UYB_iH4_0/s320/Mahb-JRC.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Attacco 1&lt;/b&gt; - un sito del Joint Research Centre, in particolare il sito del "&lt;a href="http://mahb.jrc.it/" target="_blank"&gt;Major Accident Hazards Bureau&lt;/a&gt;", un sito della Commissione Europea dedicato alla gestione delle politiche di controllo dei pericoli derivanti dallo stoccaggio di sostanze tossiche. Il solito Thorwed ha preso il DB degli amministratori e degli utenti registrati e lo ha pubblicato su &lt;a href="http://pastebin.com/E19sVGH5" target="_blank"&gt;Pastebin&lt;/a&gt;. La cosa che mi è saltata all'occhio è l'utente amministrativo "test"... chi vuole provare ad indovinare la password può postare nei commenti la sua proposta. Quando io l'ho provato dopo circa una ventina di ore dall'attacco era ancora tutto perfettamente funzionante, una vera meraviglia!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ovviamente ho segnalato il tutto a chi di dovere, anche se so per certo che erano&amp;nbsp;già&amp;nbsp;stati informati tramite canali ufficiali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Q02VWRDiZOM/Tv4zT-zexWI/AAAAAAAAAVo/w0k6Lqzcaxo/s1600/rainews24.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: justify;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Q02VWRDiZOM/Tv4zT-zexWI/AAAAAAAAAVo/w0k6Lqzcaxo/s1600/rainews24.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Attacco 2&lt;/b&gt; -&lt;a href="http://www.rainews24.rai.it/" target="_blank"&gt; Rainews24&lt;/a&gt; stessa cosa. DB utenti e un secondo DB (probabilmente dedicato ai contributori di notizie "User Generated Content") pubblicati su &lt;a href="http://pastebin.com/h8bA3P0Q" target="_blank"&gt;Pastebin&lt;/a&gt;. La cosa divertente (si fa per dire) è che gli utenti in questo caso sono tutti i redattori e la struttura di rainews24. Anche qui una vera meraviglia.&lt;/div&gt;&lt;br /&gt;Ah dimenticavo... buon anno a tutti!&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------------------------------------&lt;br /&gt;Aggiornamento del 31 dicembre 2011 ore 12.&lt;br /&gt;&lt;br /&gt;Sono stato appena informato che i gestori del sito del JRC hanno reso irragiungibile la pagina di amministrazione e che stanno gestendo l'incidente. Meno male.&lt;br /&gt;&lt;br /&gt;ore 13&lt;br /&gt;Al momento è stato messo off-line tutto il sito. Una misura un po' drastica ma probabilmente legata alla risoluzione della vulnerabilità sfruttata per l'attacco. Se volete vedere come si presentava il sito potete utilizzare la copia cache di Google.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1582543187296207663?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1582543187296207663/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/joint-research-center-hacked-rainews24.html#comment-form' title='5 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1582543187296207663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1582543187296207663'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/joint-research-center-hacked-rainews24.html' title='Joint Research Centre hacked - Rainews24 hacked'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-gdLNLV7jxmc/Tv4zJQ6oUiI/AAAAAAAAAVc/18UYB_iH4_0/s72-c/Mahb-JRC.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2623055063630018792</id><published>2011-12-29T16:33:00.000+01:00</published><updated>2011-12-29T16:33:05.616+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>MUMBLE - Diginotar: l'attacco che cambiò Internet</title><content type='html'>&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JMJhx380xqA/TvyH09GlzxI/AAAAAAAAAVQ/o7qwQu82ops/s1600/Cyber-crime-n5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-JMJhx380xqA/TvyH09GlzxI/AAAAAAAAAVQ/o7qwQu82ops/s320/Cyber-crime-n5.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;Questo articolo è stato pubblicato sull'ultimo numero di Cybercrime ed è la mia riflessione di fine anno.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'appuntamento per il prossimo post è per il 2012 (se non succede niente di eclatante...).&amp;nbsp;Tanti auguri a tutti!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nel corso di quest'anno, quasi ogni giorno abbiamo letto di criminali che hanno violato database di grandi aziende, di spie che sono entrate nelle reti di agenzie governative di tutto il mondo, di segreti industriali che sono stati rubati da agenti prezzolati e di pubblicazioni di materiale riservato trafugato da sedicenti attivisti di varia natura.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il 2011, probabilmente, passerà alla storia come uno degli anni più neri per la sicurezza su Internet.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per importanza e ripercussioni, però, un evento si discosta da tutti gli altri: l'attacco alla certification authority (CA) olandese Diginotar.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Prima di tutto, per capire la reale portata di questo attacco, conviene partire dallo scenario.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Una CA emette i certificati digitali utilizzati per garantire l'identità di un soggetto in rete, sia esso un privato che un sito Internet, consentendo nel contempo la cifratura del traffico tra l'utente e il sito stesso. In questo modo sono stati sviluppati tutti i servizi a valore aggiunto basati sull'utilizzo di reti pubbliche, dall'home banking alle VPN SSL. Diginotar, recentemente acquistata da una multinazionale di sicurezza, era una CA riconosciuta a livello internazionale i cui certificati venivano verificati e dichiarati affidabili direttamente all'interno dei browser web. Qualsiasi utente, con qualsiasi browser, nel collegarsi ad un sito che presentava un certificato emesso da Diginotar, avrebbe visto comparire una notifica sul browser a sancire la sicurezza del collegamento stesso.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Diginotar erogava due tipologie di servizi di certificazione: una destinata ai privati ed una ad uso del governo olandese per l'emissione di certificati a valenza legale.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questo è lo scenario in cui è maturato l'attacco, ma cosa è successo esattamente a Diginotar?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il 29 Agosto è stato reso noto che un attacco aveva compromesso la CA, evento preoccupante ma &amp;nbsp;già successo qualche mese prima anche alla CA Comodo. In quel caso, però, l'attacco si era risolto con poche e marginali conseguenze. Con il passare delle ore si viene a sapere che, in seguito all'attacco, era stato creato almeno un falso certificato digitale, a nome di google.com. Chiaramente questo fatto ha cominciato ad allarmare gli esperti e l'interesse per questa notizia si è innalzato notevolmente.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Anche il governo olandese è intervenuto, preoccupato del fatto che i propri certificati digitali fossero emessi proprio da un soggetto che era stato “bucato”.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La domanda che, a questo punto, ci si comincia a porre è: quanto è esteso e grave questo attacco?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dopo pochi giorni arriva la risposta, ed è una risposta che lascia tutti gli osservatori basiti e angosciati: oltre 530 certificati falsi sono stati emessi a nome di soggetti che spaziano dai social network (FaceBook e Twitter) ai maggiori fornitori di software e servizi su Internet (Microsoft, Mozilla, Tor, Skype, LogMeIn, Wordpress e AOL), dai principali motori di ricerca (Google, Yahoo!) alle maggiori agenzie di spionaggio occidentali (Mossad, CIA e MI6).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La notizia è talmente grave che il governo olandese è stato costretto a intervenire direttamente comunicando di aver avocato la gestione della CA e di aver affidato ad una società indipendente l'analisi dell'accaduto. Il ministro degli interni ha dovuto indire in tutta fretta una conferenza stampa televisiva per dare conto delle misure intraprese. Il CERT governativo olandese infine ha cominciato ad emette una serie di bollettini ufficiali per informare degli sviluppi e delle decisioni adottate.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ciò che emerge dalle indagini è che Diginotar aveva avuto delle indicazioni di attività malevole fin dalla metà di luglio e che aveva cercato di arginare la situazione senza successo ma che, soprattutto, aveva maldestramente cercato di coprire l'accaduto per evitare ripercussioni negative al proprio business e alla propria immagine. Emerge inoltre che il presunto hacker dietro all'attacco è lo stesso iraniano che qualche mese prima aveva attaccato Comodo, con risultati, però, decisamente più modesti. Infine, Trend Micro ed altri operatori internazionali di sicurezza pubblicano alcune ricerche che mostrano che il vero movente dell'attacco sia stata la volontà di monitorare i collegamenti Internet effettuati da cittadini iraniani verso siti considerati “sensibili” ai fini del contenimento della attività di protesta dei dissidenti.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Un vero disastro, che culmina a fine settembre con la presentazione di una formale istanza di fallimento.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La sciagurata avventura di Diginotar finisce così.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tra le tante riflessioni che nascono da questo evento vale la pena di puntualizzarne alcune.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'assenza di adeguate misure di sicurezza può cancellare anche una società affermata&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per la prima volta appare chiaro che nella mappa dei rischi che devono essere considerati in ambito aziendale si deve mettere in conto anche la cancellazione del proprio business a causa di un attacco informatico. Sino ad ora, gli attacchi informatici erano confinati tra quelli che potevano portare danni diretti (la cui entità poteva essere valutata in termini monetari) e danni indiretti, di natura principalmente legata alla perdita di immagine. Il caso Sony e, ancor più, il caso Diginotar, hanno mostrato che le conseguenze di attacchi informatici, in assenza di adeguate misure di sicurezza e di gestione degli stessi, possono portare conseguenze impreviste ed imprevedibili danni economici.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La sottovalutazione di questa tipologia di rischi non è più accettabile&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se ci si mette nei panni dei manager di Diginotar, vedremo che le scelte che li hanno portati a sottovalutare l'importanza dell'implementazione di un serio sistema di gestione della sicurezza delle informazioni sembravano pagare. Fino a luglio Diginotar, aveva un fiorente business, con costi di gestione ridotti. L'assenza di sicurezza probabilmente era percepita come un risparmio e non aveva dato particolari conseguenze negative. Peccato che, nel giro di qualche giorno, avrebbe condotto al fallimento. C'è sicuramente di che meditare, anche nell’ottica delle scelte che sta operando il nostro sistema paese.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'incapacità nella gestione degli incidenti di sicurezza moltiplica gli effetti negativi&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questa vicenda mette in risalto come, nella società digitale, la capacità di difendere gli stakeholder dagli eventi relativi ad attacchi informatici sia data per acquisita. Mostrare di non essere in grado di gestire adeguatamente questo tipo di situazioni crea immediatamente un intorno di sospetto e di sfiducia che complica ulteriormente lo scenario dell'attacco. La reale capacità di reazione data dalla presenza ed efficienza di un team esperto, dedicato alla gestione degli incidenti, è un prerequisito essenziale per il contenimento delle conseguenze di un attacco.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La fiducia è un bene prezioso che deve essere tutelato adeguatamente&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tutti noi, soggetti individuali, società private e istituzioni pubbliche, abbiamo compiuto il grande passo della virtualizzazione dei rapporti. Questo passo si fonda sull'esperienza comune che, in questo modo, è possibile conseguire grandi vantaggi a fronte di rischi tutto sommato comparabili a quelli che si corrono nei rapporti “in person”. La fiducia però è un bene molto labile che deve essere costantemente difeso e tutelato. L'attacco a Diginotar ha mostrato in modo inequivocabile che la perdita di fiducia può rappresentare un moltiplicatore delle conseguenze negative di un attacco.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La domande da porsi a questo punto sono:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;“Quante possibili Diginotar ci sono?” e, soprattutto, “Quante Diginotar ci saranno?”&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2623055063630018792?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2623055063630018792/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/mumble-diginotar-lattacco-che-cambio_29.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2623055063630018792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2623055063630018792'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/mumble-diginotar-lattacco-che-cambio_29.html' title='MUMBLE - Diginotar: l&apos;attacco che cambiò Internet'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-JMJhx380xqA/TvyH09GlzxI/AAAAAAAAAVQ/o7qwQu82ops/s72-c/Cyber-crime-n5.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-827259764502441970</id><published>2011-12-25T12:42:00.000+01:00</published><updated>2012-01-04T10:57:57.483+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - XMas Edition</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3-19W2BFmAM/TvcFD_4GoVI/AAAAAAAAAVE/g8P7xTlOYDw/s1600/Santa-with-Vespa.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="151" src="http://3.bp.blogspot.com/-3-19W2BFmAM/TvcFD_4GoVI/AAAAAAAAAVE/g8P7xTlOYDw/s200/Santa-with-Vespa.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;It's Christmas time and everybody wants to celebrate it. Also the bad guys...?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@jeromesegura" target="_blank"&gt;@jeromesegura&lt;/a&gt; Malware Fighters’ Dream Team &lt;a href="http://bit.ly/t7YfJ3" target="_blank"&gt;bit.ly/t7YfJ3&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@TrendLabs" target="_blank"&gt;@TrendLabs&lt;/a&gt; What botnets got taken down in 2011? Read the details at &lt;a href="http://bit.ly/vny7UQ" target="_blank"&gt;bit.ly/vny7UQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@QatarCERT" target="_blank"&gt;@QatarCERT&lt;/a&gt; Q-CERT Weekly Newsletter,25 December,2011 - &lt;a href="http://eepurl.com/h4-l2" target="_blank"&gt;eepurl.com/h4-l2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@George_Kurtz" target="_blank"&gt;@George_Kurtz&lt;/a&gt; Stolen Credit Cards Go for $3.50 at Amazon-like Online Bazaar. &lt;a href="http://buswk.co/uMxVOI" target="_blank"&gt;buswk.co/uMxVOI&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@bobmcmillan" target="_blank"&gt;@bobmcmillan&lt;/a&gt; US IPs are #1 source of electronic crimes in China, says Verizon; hacktivists &amp;amp; data breaches... &lt;a href="http://bit.ly/skBBEX" target="_blank"&gt;bit.ly/skBBEX&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; Video: "Stuxnet 3.0 possible features and Hiding rootkits" &lt;a href="http://bit.ly/sZkGMg" target="_blank"&gt;bit.ly/sZkGMg &lt;/a&gt;By &lt;a href="http://twitter.com/@nima_bagheri" target="_blank"&gt;@nima_bagheri&lt;/a&gt; from Tehran, Iran.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And finally...&lt;br /&gt;&lt;a href="http://twitter.com/@e_kaspersky" target="_blank"&gt;@e_kaspersky&lt;/a&gt; Our cyberthreat forecast for 2012 &lt;a href="http://bit.ly/w3cZUG" target="_blank"&gt;bit.ly/w3cZUG&lt;/a&gt; targeted attacks, hacktivism, mobile malware and cyber warfare&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;.... so, a happy new year to all of you!!! ;-))&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-827259764502441970?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/827259764502441970/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-xmas-edition.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/827259764502441970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/827259764502441970'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-xmas-edition.html' title='Best of the Week - XMas Edition'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-3-19W2BFmAM/TvcFD_4GoVI/AAAAAAAAAVE/g8P7xTlOYDw/s72-c/Santa-with-Vespa.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8730488645150788315</id><published>2011-12-19T17:14:00.005+01:00</published><updated>2011-12-20T09:17:29.085+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Voci Amiche'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilità'/><category scheme='http://www.blogger.com/atom/ns#' term='PDF-X-RAY'/><category scheme='http://www.blogger.com/atom/ns#' term='adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><title type='text'>Brandon Dixon - CVE-2011-2462 exploitation: a real case</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mmDFvNefK-o/TvBAbqzREaI/AAAAAAAAAUs/e2-khLYFsRY/s1600/brandon-dixon.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-mmDFvNefK-o/TvBAbqzREaI/AAAAAAAAAUs/e2-khLYFsRY/s200/brandon-dixon.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;This summer I saw an interesting news item about a new online security tool: &lt;a href="https://www.pdfxray.com/" target="_blank"&gt;PDF X-RAY&lt;/a&gt;. This tool seemed to me so important that immediately I decided to write &lt;a href="http://www.matteocavallini.com/2011/08/pdf-x-ray-un-utile-strumento-per-la.html" target="_blank"&gt;a post&lt;/a&gt; to describe its potentiality and use. I was also interested about the author of the tool, Brandon Dixon, a researcher from George Washington University, so I decided to write him an email.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here, another nice find. Brandon is very helpful and informal. A guy with whom is a pleasure to interact.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Inviting him to write a guest post for "Punto 1" was the next step so Brandon and I agreed that whenever an occasion turns up he would write a post for my blog.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Then,&amp;nbsp;two week ago I read that Brandon has published an analysis of the new 0day vulnerability of Adobe Reader I knew that the right time had arrived. Last Friday, Adobe released a &lt;a href="http://www.adobe.com/support/security/bulletins/apsb11-30.html" target="_blank"&gt;patch&lt;/a&gt; for this vulnerability and knowing the reasons why it is important to organize the complex deployment of this piece of software is fundamental.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Brandon, thank you very much to accept my invitation. This is the moment to present your work to the "Punto 1" readers.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: center;"&gt;&lt;iframe allowfullscreen="" frameborder="0" height="146" src="http://www.youtube.com/embed/6cFLwjWuNdQ" width="260"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;On December 7th, 2011 a suspicious file was uploaded to PDF X-RAY containing references to U3D content. Normally this would not constitute more analysis, but Adobe had released an advisory documenting a new vulnerability within U3D content that was actively being exploited.&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Using PDF X-RAY, I was able to identify both the trigger U3D object (located in object 10) and the heap spray (located in object 15). Reading through the specification revealed how the 3D content would be executed and what actions would be performed.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;After the initial static analysis, the PDF was ran on a Windows XP SP3 machine running Adobe Reader 9.4.6 to identify any dropped files or command and control servers. Upon running the PDF file, Adobe Reader crashed and opened up a clean document that appeared to target employees of the defense contractor Mantech.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Not only was a clean file dropped, but there was also an executable named “pretty.exe” created and ran on the system. VirusTotal identified this file with generic signatures and a reference to “sykipot”. This Trojan had been analyzed before and public data revealed how it would operate. Knowing these details, Internet Explorer was started and the system was set to wait until data was sent back to the command and control server.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Sykipot injected a process into Internet Explorer and made a request to “https://prettylikeher.com” to get what appeared to be a key for encryption/decryption purposes. Matthew Wollenweber analyzed the Trojan using a debugger and disassembler to identify any other process injections and the commands used for the control servers.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;After identifying the trojan being dropped and the command and control servers, focused was placed on the generation of the malicious file. Several strings within the generated document matched a proof-of-concept exploit from back in 2009. This proof-of-concept written by Felipe Manzano appeared to be the main generator used to create the malicious documents.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Shortly after the advisory was released, another variant of the exploit was seen being used in targeted attacks. These documents were encrypted with AESV3 and appeared to be generated using Adobe Lifecycle. While these documents exploited the same vulnerability, they were more successful in bypassing anti-virus because of the AESV3 encryption.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Performing analysis on the encrypted document also revealed a different Trojan being dropped on the system. Virustotal was not able to identify a particular trojan family associated with this executable, but HTTPS connections could be seen being made to 69.197.132.130. It is unclear what, if anything was sent to this command and control server, but it did appear offline.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It should be noted that the encrypted documents appeared to target defense contractor Lockheed Martin and farming company Monsanto. Given the extreme differences in document structure and trojan dropper, it is likely two different groups were involved in the use of these zero day exploits. Several signs point back to China as the creator of these documents, but this can not be confirmed.&lt;br /&gt;---------------------------------------------------------------------------------------------&lt;br /&gt;Bio&lt;br /&gt;&lt;br /&gt;Beside being the Founder and CEO of 9b+, the company that owns PDF X-RAY, Brandon Dixon is also "Computer Forensics and Security Engineer with George Washington University". Moreover he is contributing to Hakin9 as Tester, Writer and Promoter.&lt;br /&gt;&lt;br /&gt;Here you can find his &lt;a href="http://www.linkedin.com/in/brandonsdixon" target="_blank"&gt;LinkedIn profile&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8730488645150788315?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8730488645150788315/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/brandon-dixon-cve-2011-2462.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8730488645150788315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8730488645150788315'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/brandon-dixon-cve-2011-2462.html' title='Brandon Dixon - CVE-2011-2462 exploitation: a real case'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mmDFvNefK-o/TvBAbqzREaI/AAAAAAAAAUs/e2-khLYFsRY/s72-c/brandon-dixon.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2894889390830623992</id><published>2011-12-18T21:36:00.000+01:00</published><updated>2011-12-31T12:32:30.964+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web application security'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='Thorwed'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Bucato un sito del Ministero dell'Innovazione</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1H0ivA308GI/Tu5M48NkvZI/AAAAAAAAAUc/yX56e4kUmXY/s1600/qualitapa-gov-it.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="71" src="http://4.bp.blogspot.com/-1H0ivA308GI/Tu5M48NkvZI/AAAAAAAAAUc/yX56e4kUmXY/s320/qualitapa-gov-it.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;Oggi, un certo &lt;a href="http://twitter.com/@thorwed" target="_blank"&gt;Thorwed&lt;/a&gt; ha pubblicato su &lt;a href="http://pastebin.com/wVSq1Ujb" target="_blank"&gt;pastebin &lt;/a&gt;una copia del DB utenti del sito &lt;a href="http://qualitapa.gov.it/" target="_blank"&gt;qualitapa.gov.it&lt;/a&gt; appartenente al Ministero per la Pubblica Amministrazione e l'Innovazione.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Sulla pagina di pastebin si possono leggere userid, password e email dei circa 9000 utenti registrati del sito. Ho chiaramente fatto una delle solite "telefonatine" e mi hanno assicurato che la notizia era arrivata da circa un'ora attraverso una segnalazione internazionale.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questo evento non è particolarmente diverso da altri che avvengono ogni giorno in molti siti istituzionali e privati in ogni parte del mondo. Ciò che lo rende diverso da molti altri, però, è la nostra situazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come i lettori di Punto 1 sanno bene, l'Italia non si è ancora dotata di un CERT nazionale, ovvero di una struttura che si faccia carico delle attività di contenimento degli incidenti, che dia una direzione ufficiale e un coordinamento alle risorse che operativamente si faranno carico di "rimettere le cose a posto".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Quindi, ad esempio, ora sarebbe altamente necessario che gli ignari utenti i cui indirizzi mail e password sono stati pubblicati, vengano avvisati immediatamente per cercare di minimizzare il danno e dare modo a tutti loro di cambiare le password (soprattutto se hanno utilizzato la stessa anche in altri contesti).&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ebbene in questo momento nessuno sa chi ha il ruolo per farlo. E' un'attività che non è allocabile in nessuna struttura ufficiale ad oggi esistente.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per cui con qualche amico stiamo ragionando su una iniziativa "volontaristica".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma un gran pasticcio.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Speriamo che questa situazione serva a ribadire (se ancora ce ne fosse bisogno) che l'Italia ha bisogno di un CERT Nazionale.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2894889390830623992?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2894889390830623992/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/bucato-un-sito-del-ministero.html#comment-form' title='9 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2894889390830623992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2894889390830623992'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/bucato-un-sito-del-ministero.html' title='Bucato un sito del Ministero dell&apos;Innovazione'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-1H0ivA308GI/Tu5M48NkvZI/AAAAAAAAAUc/yX56e4kUmXY/s72-c/qualitapa-gov-it.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3751759505516473735</id><published>2011-12-18T10:21:00.001+01:00</published><updated>2011-12-18T10:21:41.585+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 18 Dicembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;This time I'm starting my list of the best security resources of the week with an "off topic" news item, but I'm sure it's really worth it!&amp;nbsp;&lt;a href="http://twitter.com/@Vendima" target="_blank"&gt;@Vendima&lt;/a&gt; Check this video out -- ONE OF THE GREATEST POSTS ON YOUTUBE SO FAR! &lt;a href="http://t.co/tD3PIEGv" target="_blank"&gt;youtube.com/watch?v=M8C-qI…&lt;/a&gt; via &lt;a href="http://twitter.com/@MarcoBavazzano" target="_blank"&gt;@MarcoBavazzano&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;And now it's the time of the "official" list...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope you enjoy it!&lt;/div&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@e_kaspersky" target="_blank"&gt;@e_kaspersky&lt;/a&gt; FAA allows airlines to replace paper books/charts with iPads&amp;nbsp;&lt;a href="http://zd.net/scpNhs" target="_blank"&gt;zd.net/scpNhs&lt;/a&gt; &amp;lt;- one day we may regret our dependence on digital stuff&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; video of 'Yash's' (Red Force Labs) MITM POC attack against Citibank India &lt;a href="http://bit.ly/vjhZWl" target="_blank"&gt;bit.ly/vjhZWl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Fortify" target="_blank"&gt;@Fortify&lt;/a&gt; Great blog post from Raf Los on the Ponemon study released yesterday--worth a read @ &lt;a href="http://bit.ly/uBrXsa" target="_blank"&gt;bit.ly/uBrXsa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@candolin2" target="_blank"&gt;@candolin2&lt;/a&gt; Cybersecurity and Cyberpower: Concepts, Conditions and Capabilities for Action within the EU: &lt;a href="http://www.oiip.ac.at/home/home-detail/article//cybersecurity-and-cyberpower-concepts-conditions-and-capabilities-for-action-within-the-eu.html" target="_blank"&gt;oiip.ac.at/home/home-deta…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@FSecure" target="_blank"&gt;@FSecure&lt;/a&gt; “Social media isn’t a choice anymore; it’s a business transformation tool.” &lt;a href="http://bit.ly/uRwYHm" target="_blank"&gt;bit.ly/uRwYHm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@elie" target="_blank"&gt;@elie&lt;/a&gt; Google Docs Used in a Spam Campaign - &lt;a href="http://bit.ly/sqsElC" target="_blank"&gt;bit.ly/sqsElC&lt;/a&gt; #security&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3751759505516473735?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3751759505516473735/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-18-dicembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3751759505516473735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3751759505516473735'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-18-dicembre-2011.html' title='Best of the Week - 18 Dicembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-854091278999009614</id><published>2011-12-11T08:55:00.001+01:00</published><updated>2011-12-11T09:11:58.036+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 11 Dicembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;This is my selection of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@VivianeRedingEU" target="_blank"&gt;@VivianeRedingEU&lt;/a&gt; &lt;a href="http://twitter.com/@mobileworldlive" target="_blank"&gt;@mobileworldlive&lt;/a&gt; My speech on #privacy in the cloud – how to ensure #dataprotection in the #EU &lt;a href="http://bit.ly/tcszlg" target="_blank"&gt;bit.ly/tcszlg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@jakeludington" target="_blank"&gt;@jakeludington&lt;/a&gt; Great discussion with &lt;a href="http://twitter.com/@Wh1t3Rabbit" target="_blank"&gt;@Wh1t3Rabbit&lt;/a&gt; about how cloud computing is forcing us to rethink security &lt;a href="http://ow.ly/1BvN56" target="_blank"&gt;ow.ly/1BvN56&lt;/a&gt; #HPDiscover #cloud&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mthorbruegge" target="_blank"&gt;@mthorbruegge&lt;/a&gt; Cyber Security: ENISA’s view on the way forward, new paper &lt;a href="http://j.mp/svDult" target="_blank"&gt;j.mp/svDult&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@sansforensics" target="_blank"&gt;@sansforensics&lt;/a&gt; Quick Malware Notes, Incident Response, and 00-outs - A while back after dealing with some heavily malware-infect... &lt;a href="http://bit.ly/vRSFKa" target="_blank"&gt;bit.ly/vRSFKa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; The Most Notorious Cyber Crooks of 2011 – And How They Got Caught &lt;a href="http://bit.ly/vT8iht" target="_blank"&gt;bit.ly/vT8iht&lt;/a&gt; #hacking #infosec&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SCADAhacker" target="_blank"&gt;@SCADAhacker&lt;/a&gt; After seeing &lt;a href="http://twitter.com/@SecurityTube" target="_blank"&gt;@SecurityTube&lt;/a&gt;, decided to add new Video Feeds section to How-To section of Resources - SCADAhacker - &lt;a href="http://bit.ly/uZv6WE" target="_blank"&gt;bit.ly/uZv6WE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-854091278999009614?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/854091278999009614/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-11-dicembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/854091278999009614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/854091278999009614'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-11-dicembre-2011.html' title='Best of the Week - 11 Dicembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5967553496003947004</id><published>2011-12-09T19:41:00.001+01:00</published><updated>2011-12-10T09:34:29.391+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social network'/><category scheme='http://www.blogger.com/atom/ns#' term='Voci Amiche'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='strategia difensiva'/><title type='text'>Andrea Zapparoli Manzoni - Social Business Security &amp; Risk Management Strategies</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s1600/Andrea-Zapparoli-Manzoni.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s1600/Andrea-Zapparoli-Manzoni.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As promised, Andrea is back with the second part of his contribution to Punto 1 and now it's the turn of the threats of "Computer aided social networking".&lt;br /&gt;&lt;br /&gt;Those who have missed the Andrea's previous post can find it &lt;a href="http://www.matteocavallini.com/2011/10/andrea-zapparoli-manzoni-2011-infosecs.html" target="_blank"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As introduction to this post, &amp;nbsp;I can say that sometimes I found a guest post that I feel very close to my vision and my approach to security... in this case I have a complete synthony with the Andrea's post.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Thank you again Andrea!&lt;br /&gt;&lt;br /&gt;Punto 1 will be always open for your posts.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;"Social Networking" is not new at all, in fact it is something that humans do since a half million years or so.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;But "Computer Aided Social Networking" is *very* new, and it has so many far reaching consequences that even the terms of the problem are hard to define.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As of today, there are no laws, no institutions, no existing socio-economical nor philosophical tools that we can apply to this subject without a distinct feeling of inappropriateness. So, before we talk about risk management and security countermeasures of any kind, let me briefly introduce a couple of key concepts.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;First (and hardest) concept: we are entering the uncharted waters of a new age, where computer &amp;amp; internet aided (some would say "augmented") human interactions become *prevalent*, both at the one-to-one and at the one-to-many level, re-shaping any other aspect of everybody's life.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This is why Social Business isn't something we already know but "with a different name", it's something completely new (like people developing all at once a new "sense", i.e. becoming able to see a different part of the spectrum, etc).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It is interesting to note here that those who do not directly participate in this new form of human interaction will be strongly affected by its consequences too, much like the invention of language did (I believe this is a much better metaphor than, for example, comparing SM to the invention of the press), since Computer Aided Social Networking is reshaping people's brains, perceptions, priorities and values, everywhere.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The second concept is also quite hard to grasp: while the Internet was mainly a technological breakthrough which generated some interesting socio-economic byproducts, Computer Aided Social Networking represents a geopolitical, socio-economical and, above all, mental phase-change for the human kind. We are going to become "Semantic Cyborgs", and because of this fact both individuals and societies will evolve in previously undreamed of directions.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This said, when talking about adopting Social Business, organizations must first realize the magnitude of the consequences, make a true intellectual effort in order to metabolize them, and change accordingly in order to survive. Reacting to these changes without a vision, on a day-by-day basis, only when and if problems arise, will most likely *not* work.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Today a company entering the Social Business arena is immediately exposing itself to a wide range of serious risks in terms of brand and reputation management, of responsibilities and liabilities towards users, customers and partners, and of open source intelligence on the part of competitors.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Of course, given that Social Media is an excellent vector for hacktivists' attacks, and cybercriminals preferred playground, its adoption will also seriously increase the probability for an organization of being damaged by having its computer systems breached, its most sensitive information / intellectual property stolen, etc...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As we described in our previous post, there are further threats that are becoming increasingly worrisome (terrorism, cyber-warfare activities, sabotage) but here let's just concentrate on the simplest and more diffuse ones. The following suggestions won't protect a company from targeted hostile cyber-warfare activities, but will certainly add resilience and protection against the most common threats.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;What is required is a serious commitment from stakeholders and top management, and a continuous effort undertaken by a multidisciplinary team of highly skilled people in order to monitor, understand and anticipate trends so that it becomes possible to define, apply and enforce appropriate rules and policies dynamically, remembering that these phenomena evolve daily, almost in real time.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This is not something that the Marketing Department can handle alone, nor the IT, and not even the Security Team nor the HR or the Legal Department: all these otherwise perfectly capable professionals will fail if given the task of managing an organization's Social Business Strategy outside a multidisciplinary and truly integrated approach.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The marketing people will see all and only the advantages and the marvels of social networking, ignoring any other consideration; the IT will only see an increase in bandwidth usage and help desk calls, the Security guys will scream that shutting down the perimeter defenses would be less dangerous than opening access to SM sites to all employees (as Marketing demands), HR will only try to recruit the best resources with the lowest effort, end users themselves will happily find ways to bypass any policy and restriction, and so on. With Social Business, this is THE recipe for disaster.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;There are also several main obstacles that work against the implementation of an effective Social Business Risk Management Strategy and that must be taken into account:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Awareness of the problems is still very low at all levels (if non-existent);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- A growing number of threats is realized at the semantic level, impossible to monitor and manage with traditional security tools;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Consumerization of Enterprise IT / BYOD are putting security workflows at risk (sometimes beyond any remedy);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- For various reasons, it is "forbidden to forbid" (especially in Italy);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Legislation protects the privacy and freedoms of employees and users (and rightly so), complicating monitoring activities;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Mitigation technologies are not yet up to date with the issues (nonetheless they're evolving at great speed);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Policies and virtuous behaviors are always lagging years behind the technology (nowadays first we invent something, then we find how to make a profit out of it, then we see if there are contraindications);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In addition, recent researches showed that companies do not have adequate tools to monitor and measure data loss &amp;amp; leakage through Social Media, and that the phenomenon is simply out of control in 98% of cases.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, let's go back to countermeasures. In order to find solutions applicable in the real world we must take into account strategic, educational, economic, organizational, technological and legal issues.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In a comprehensive Social Business Risk Management Strategy, there are seven areas to be simultaneously pursued:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Create a Social Business Officer position, with a staff capable of managing risk across (at least) 5 different domains: Marketing, Legal, IT Security, HR and IT. These organizational changes are mandatory: without such a team, the organization will be blind, deaf and incapable of reacting quickly and appropriately in case of an incident or of an attack. And no, your Advertising Agency cannot supply you a Social Business Officer.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Remedy the lack of standard procedures, organizational tools, plans and corporate culture in general by implementing continuous risk and security awareness programs, explaining and enforcing the new Social Business rules and policies to all parties involved (achieving understanding, acceptance and participation);&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Implement effective multi-layer technical tools to monitor and control in real time all the different kind of threats that flow within the Social conversation (from semantic threats to suspicious URLs to malware), whereas firewalls, proxies and antiviruses are becoming almost useless, being transparent for most of today's threats;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Empower and responsibilize all users and corporate structures involved, for whatever reason, in the use of Social Media, and make them accountable for managing their own share of risks. Social Business is not just another IT problem and it's not only a "marketing thing". Since Social Network owners are not willing to do it, enforce strict identity and access management processes on your side;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Reduce unnecessary risky behaviors and choose wisely the way you manage your IT Security: do not allow the marketing sirens of the Bring Your Own Device, or of Cloud based Whatever-as-a-service fool you. If somebody fries or steals your database, no cool marketing concept will bring it back;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Measure your KSIs and your KPIs and monitor closely both progresses and failures. Ideally your security trend graph should have daily control points. If you are using more than one Social Network, measure and monitor them all, each one with its distinctive tools and parameters.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Finally, increase your reaction speed. Nowadays the lag between the birth and growth of a risky trend and its impact on organizations has become merely weeks, not years or months like it used to be. Stay ahead of the pack and set up preventive measures, including education at all levels, an effective early warning system and contingency plans for handling incidents while they are happening, in real time, before they get out of control.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Social Business related problems are much more complex than they seem at first and there are no magic wands: the variables involved are so many, and the issues to be addressed have non-linear consequences at so many (apparently) unrelated levels, that we have no one-size-fits-all solutions yet... but we are learning fast.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I personally find it all extremely fascinating: let's talk about it!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;Bio&lt;br /&gt;Andrea Zapparoli Manzoni was born in Milan in 1968.&lt;br /&gt;With a multidisciplinary background both in political science and in computer science, since 1997 he developed an active interest in ICT security, with particular reference to GRC (Governance, Risk and Compliance), cybercrime and cyber warfare issues.&lt;br /&gt;Over the years he worked in the IDM, IAM, DLP, Anti Fraud, Security Intelligence, Forensics, Vulnerability Assessment &amp;amp; Management fields in Enterprise, Industrial, Central PA and Gov-Mil environments.&lt;br /&gt;He writes articles and essays on InfoSec topics and follows very closely all developments in Cybersecurity, working as a trusted advisor with national and international organizations.&lt;br /&gt;He partecipates to the activities of CLUSIT (Italian Association for Information Security) speaking at conferences, contributing papers (two ROSI patterns about IAM and DLP, seminars about SCADA Security and Social Media Security) and spreading the culture of IT Security in Italy.&lt;br /&gt;In addition to collaborating with numerous Italian and foreign companies, he is the founder and CEO of iDialoghi, a consulting firm specializing in the design and implementation of advanced information security solutions, including the Social Business Security field.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5967553496003947004?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5967553496003947004/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/andrea-zapparoli-manzoni-social.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5967553496003947004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5967553496003947004'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/andrea-zapparoli-manzoni-social.html' title='Andrea Zapparoli Manzoni - Social Business Security &amp; Risk Management Strategies'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s72-c/Andrea-Zapparoli-Manzoni.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7833796340776183697</id><published>2011-12-06T11:47:00.001+01:00</published><updated>2011-12-06T12:27:49.713+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><title type='text'>Cloud Incident Response: a tangled scenario</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iXmncfgluAE/Tt32eHYzANI/AAAAAAAAAUU/U0mTjI-fLSA/s1600/Tangled-cloud.jpg" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" dda="true" src="http://3.bp.blogspot.com/-iXmncfgluAE/Tt32eHYzANI/AAAAAAAAAUU/U0mTjI-fLSA/s1600/Tangled-cloud.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;A detail from Constable's "Landscape with clouds"&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;﻿﻿﻿﻿﻿﻿﻿﻿This is the second post of the “&lt;a href="http://www.matteocavallini.com/p/cloud-incident-response.html" target="_blank"&gt;Cloud Incident Response&lt;/a&gt;” series and, after the announcement of the &lt;a href="http://www.matteocavallini.com/2011/11/cloudsirt-project_21.html" target="_blank"&gt;CloudSIRT project&lt;/a&gt;, I want to begin our journey through this matter starting from the base... the scenario. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infact, we need to investigate in detail the way in which the services are delivered in the cloud to better comprehend the reasons behind the necessity of a new and efficient approach to the Incident Response process.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Well, the majority of people think the world of cloud services is made by Consumers and Providers, but the reality is much more complicated. At the moment, mature cloud services are not a matter of you and&amp;nbsp;your provider, instead, as the NIST highlights, at least three other major actors are involved in this business. These new actors (for a full definition of these roles see the “&lt;a href="http://collaborate.nist.gov/twiki-cloud-computing/pub/CloudComputing/ReferenceArchitectureTaxonomy/NIST_SP_500-292_-_090611.pdf" target="_blank"&gt;NIST Cloud Computing Reference Architecture&lt;/a&gt;”) are the following:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Cloud Broker (the entity that manages the final services and the relationships between providers and consumers)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Cloud Carrier (the intermediary that provides connectivity and transport of cloud services)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Cloud Auditor (the independent examiner of cloud service controls to verify compliance).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;To complicate matters further, a cloud provider can use subcontractors to deliver some specific features of his services (e.g. storage, computational resources, network, etc.).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, in the real market, a consumer finds offerings for services that involve a combination of many players and each of these can contribute to the final service with a different weight and role. Finally, a consumer would not be completely aware of all the interactions amongst the providers of the service because, usually, he signs a contract with a front-end provider that, in some cases, could have an interest to hide the complexity behind the proposed service.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You can easily imagine that each of these players have to face general and specific threats (an interesting document on the cloud threats is the “&lt;a href="https://cloudsecurityalliance.org/topthreats/csathreats.v1.0.pdf" target="_blank"&gt;Top Threats to Cloud Computing&lt;/a&gt;“ by &lt;a href="https://cloudsecurityalliance.org/" target="_blank"&gt;Cloud Security Alliance&lt;/a&gt;) and security risks. The complex supply scenario multiply these threats and security risks combining them in various ways. As result, a security incident in the cloud involves many layers of the service with multiple mutual interactions and each layer involved could be managed by a different actor. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In one word, a mess!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, incident response in the cloud is an activity that relies mostly on communication and information sharing among the various actors involved. A wise cloud consumer wants to be part of the incident response process but, often, a cautious cloud provider needs to maintain the whole process in his hands. Moreover, the provider has specific needs not to disclose some pieces of information belonging to other customers uninvolved by the incident. So, despite all the difficulties, the solution is to achieve a good balance between these diverging requirements and the only tools that can be used to regulate these information interchanges are contractual clauses and Service Level Agreements (SLA). &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hence, the first step&amp;nbsp;in addressing an efficient incident response process is to set up specific contractual clauses regulating the information flows regarding incidents. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;To achieve a good balance of these different needs, these clauses have to set, at least:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;a clear definition of an incident&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;the incident declaration procedure&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;the needs of cooperation between consumer and provider&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;the expected information flows to/from the consumer&amp;nbsp;in every phase of incident response&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;the perimeter in which the incident related data can be used and shared&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;the procedures and triggers to involve the law enforcement agencies&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;all the involved parties along with their roles&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In my opinion, this is the only way to lay the foundation stone for an effective incident response process within the cloud. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In the next parts I will focus on the ways to exchange data related to incidents and on the phases of the incident response process in the cloud… so, stay tuned! &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7833796340776183697?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7833796340776183697/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/cloud-incident-response-tangled.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7833796340776183697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7833796340776183697'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/cloud-incident-response-tangled.html' title='Cloud Incident Response: a tangled scenario'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-iXmncfgluAE/Tt32eHYzANI/AAAAAAAAAUU/U0mTjI-fLSA/s72-c/Tangled-cloud.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-935356028695705384</id><published>2011-12-04T08:47:00.001+01:00</published><updated>2011-12-04T09:15:43.087+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 4 Dicembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;This week, beside the articles, I found some interesting security reports.&amp;nbsp;Here you can read my list of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you can enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RSA_Fraud" target="_blank"&gt;@RSA_Fraud&lt;/a&gt; Are you Smarter than a Fraudster? &lt;a href="http://yfrog.com/ocb1clbj" target="_blank"&gt;yfrog.com/ocb1clbj&lt;/a&gt; Take our quiz to see!&amp;nbsp;&lt;a href="http://rsa.im/tOiGQi" target="_blank"&gt;rsa.im/tOiGQi&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@fpietrosanti" target="_blank"&gt;@fpietrosanti&lt;/a&gt; National Counterintelligence 2011 Executive Report to US Congress &lt;a href="http://t.co/oGt85Krh" target="_blank"&gt;ncix.gov/publications/r…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nientenomi" target="_blank"&gt;@nientenomi&lt;/a&gt; Utility Cyber Security Report. Seven key smart grid security trends to watch in 2012 and beyond &lt;a href="http://zite.to/t1iW27" target="_blank"&gt;zite.to/t1iW27&lt;/a&gt; by PikeResearch&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CiscoGGSG" target="_blank"&gt;@CiscoGGSG&lt;/a&gt; Military crypto modernization leads to applications like smartphones, tablet computers on the battle &lt;a href="http://fb.me/V1GIDK5v" target="_blank"&gt;fb.me/V1GIDK5v&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="htpp://twitter.com/@cedricpernet" target="_blank"&gt;@cedricpernet&lt;/a&gt; A new #IRM ( #incidentresponse Methodology) is out, this time about #scam #fraud - on CERT SG's website: &lt;a href="http://bit.ly/mxb82p" target="_blank"&gt;bit.ly/mxb82p&lt;/a&gt;&amp;nbsp;- &lt;a href="http://twitter.com/@nientenomi" target="_blank"&gt;@nientenomi&lt;/a&gt; I suggest also these information security policy templates&amp;nbsp;&lt;a href="http://www.sans.org/security-resources/policies/" target="_blank"&gt;http://www.sans.org/security-resources/policies/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SecureTheHuman" target="_blank"&gt;@SecureTheHuman&lt;/a&gt; Top ten tricks for successful security awareness presentations. How to engage and present with impact by &lt;a href="http://twitter.com/@lspitzner" target="_blank"&gt;@lspitzner&lt;/a&gt;. &lt;a href="http://bit.ly/tp2aWv" target="_blank"&gt;bit.ly/tp2aWv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-935356028695705384?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/935356028695705384/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-4-dicembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/935356028695705384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/935356028695705384'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/12/best-of-week-4-dicembre-2011.html' title='Best of the Week - 4 Dicembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2223103358036958781</id><published>2011-11-27T08:30:00.001+01:00</published><updated>2011-11-27T08:55:41.790+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 27 Novembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It's Sunday which means it's time for another "Best of the Week" post.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here you can find the list of my favourite security resources of the week.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope you enojoy it.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@RealSecurity" target="_blank"&gt;@RealSecurity&lt;/a&gt; Best Practices for Keeping Your Home Network Secure - NSA [PDF] &lt;a href="http://t.co/V5ZE7r7E" target="_blank"&gt;nsa.gov/ia/_files/fact…&lt;/a&gt; #security&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@gcluley" target="_blank"&gt;@gcluley&lt;/a&gt; Graham RT &lt;a href="http://twitter.com/@nakedsecurity" target="_blank"&gt;@NakedSecurity&lt;/a&gt;: The Conficker worm, three years and counting &lt;a href="http://bit.ly/sVG9kW" target="_blank"&gt;bit.ly/sVG9kW&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@RealSecurity" target="_blank"&gt;@RealSecurity&lt;/a&gt; DNS Cache Poisoning (excellent read) &lt;a href="http://realsecurity%20brian%20%20dns%20cache%20poisoning%20%28excellent%20read%29%20resources.infosecinstitute.com/dns-cache-pois%E2%80%A6%20#security" target="_blank"&gt;resources.infosecinstitute.com/dns-cache-pois…&lt;/a&gt; #security&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@assolini" target="_blank"&gt;@assolini&lt;/a&gt; now is time to Brazilian crooks to invite customers of local Banks to "update" their RSA tokens &lt;a href="http://twitpic.com/7i0a8q" target="_blank"&gt;twitpic.com/7i0a8q&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@CERTXMCO" target="_blank"&gt;@CERTXMCO&lt;/a&gt; U.S. confirms it will use military force in response to cyber attacks &lt;a href="http://t.co/zLZn3Jq4" target="_blank"&gt;thetechherald.com/article.php/20…&lt;/a&gt; via &lt;a href="http://twitter.com/@thetechherald" target="_blank"&gt;@thetechherald&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@DoDRecruiterDC" target="_blank"&gt;@DoDRecruiterDC&lt;/a&gt; Top 7 cybersecurity predictions for 2012 &lt;a href="http://bit.ly/sUI8tM" target="_blank"&gt;bit.ly/sUI8tM&lt;/a&gt; #infosec #cybersecurity via &lt;a href="http://twitter.com/@kanguru_news" target="_blank"&gt;@kanguru_news&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://twitter.com/@cyberwar" target="_blank"&gt;@cyberwar&lt;/a&gt; Assessing India's Cyber Preparedness. &lt;a href="http://t.co/iiKBH3G7" target="_blank"&gt;scribd.com/doc/69726906/J…&lt;/a&gt; &amp;lt;== excellent article!&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2223103358036958781?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2223103358036958781/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-27-novembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2223103358036958781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2223103358036958781'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-27-novembre-2011.html' title='Best of the Week - 27 Novembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7843626745307921918</id><published>2011-11-24T09:56:00.001+01:00</published><updated>2011-11-24T11:50:41.310+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><category scheme='http://www.blogger.com/atom/ns#' term='US-CERT'/><title type='text'>MUMBLE - A cosa serve un CERT Nazionale</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-osLZUd63cS4/Ts4W4CLx1mI/AAAAAAAAAUE/J2Oc4MAiTJ0/s1600/CERT-nazionale.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://4.bp.blogspot.com/-osLZUd63cS4/Ts4W4CLx1mI/AAAAAAAAAUE/J2Oc4MAiTJ0/s200/CERT-nazionale.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Negli scorsi giorni una notizia ha dominato il mondo della cybersecurity: negli Stati Uniti, un ignoto hacker ha avuto accesso a un sistema di gestione dell'acqua potabile e, tramite l'invio di una serie di comandi, ha provocato la rottura di una pompa.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La notizia è molto più articolata di così ma, per il mio obiettivo odierno, possiamo fermarci qui (se invece volete altri dettagli, potete agevolmente trovarli in &lt;a href="http://www.google.it/search?hl=it&amp;amp;safe=off&amp;amp;q=hacker+disrupt+a+water+pump&amp;amp;oq=hacker+disrupt+a+water+pump&amp;amp;aq=f&amp;amp;aqi=&amp;amp;aql=&amp;amp;gs_sm=e&amp;amp;gs_upl=1320959l1330544l0l1331271l31l31l2l18l18l0l188l1335l1.8l9l0" target="_blank"&gt;rete&lt;/a&gt;).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Chiaramente questa notizia è estremamente preoccupante, se l'ignoto hacker è stato realmente in grado di rompere una pompa avrebbe anche potuto alterare dei parametri di funzionamento rendendo l'acqua imbevibile, oppure avrebbe potuto rompere tutte le pompe e mandare in tilt l'intero sistema. E se invece avesse preso di mira un fornitore di energia, o un impianto chimico? Insomma si aprono scenari da vera e propria cyberwar.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bene, appena si è diffusa la notizia, sono&amp;nbsp;immediatamente&lt;span class="Apple-style-span" style="text-align: -webkit-auto;"&gt;&amp;nbsp;&lt;/span&gt;partite le indagini (che, al momento, &lt;a href="http://www.us-cert.gov/control_systems/pdf/ICSB-11-327-01.pdf" target="_blank"&gt;tendono a minimizzare l'evento&lt;/a&gt;) dell'FBI e &lt;b&gt;dello US-CERT&lt;/b&gt;. E proprio di questo voglio parlare oggi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A cosa serve un CERT Nazionale? Ho avuto modo di fare una chiacchierata "tra amici" qualche giorno fa, e ho avuto conferma che, purtroppo, a differenza dei tecnici, i livelli decisionali italiani non hanno ancora messo a fuoco correttamente la missione di un CERT nazionale. Che sia questo il motivo del nostro immobilismo su questa delicatissima materia?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Proviamo a fare chiarezza con un esempio tratto, appunto, dalla recente cronaca.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Oggi, giovedì 24 novembre 2011, un ignoto hacker mette fuori uso le pompe di depurazione dell'acqua dell'ACEA (non me vogliano gli amici di ACEA, è solo un esempio). A Roma si diffonde il panico, l'acqua sarà ancora potabile? La magistratura apre un fascicolo contro ignoti e la Polizia delle Comunicazioni inizia le indagini. E, fino a qui ci siamo...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma chi supporta ACEA nelle proprie indagini interne? Chi supporta la gestione dell'incidente, garantendo che siano fatti gli interessi pubblici e non solo quelli dell'operatore coinvolto? Chi determina le contromisure che devono essere realizzate affinché un incidente di questa dimensione non succeda nuovamente? Chi contribuisce a diffondere le notizie ufficiali agli altri operatori di settore in modo che tutti mettano in atto le necessarie misure preventive? Chi si coordina con le altre strutture internazionali per avere un quadro più generale della situazione? Chi distribuisce informazioni ufficiali al pubblico tramite rapporti con i media garantendo che sia privilegiato l'interesse pubblico rispetto all'interesse privato dell'operatore?&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La risposta è semplice...&amp;nbsp;&lt;b&gt;NESSUNO!&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In Italia, nel 2011, queste attività vitali non sono di competenza di nessuno.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ogni operatore deve cavarsela da&amp;nbsp;sé&amp;nbsp;e la Polizia, giustamente, si attiva solamente al fine di individuare i responsabili dell'eventuale atto criminoso (se dietro a tutto ci fosse un malware, come ad esempio Conficker, non succederebbe quasi niente) ed assicurarli alla giustizia.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come sa chi è già un lettore di questo blog, ritengo che questa sia una situazione indegna di un paese evoluto &amp;nbsp;che, come il nostro, basa la propria vita sociale e finanziaria su infrastrutture informatiche.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questa situazione deve essere sanata quanto prima.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma ora sono stanco, vado a bere un bel bicchiere di acqua fresca... finché posso!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7843626745307921918?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7843626745307921918/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/mumble-cosa-serve-un-cert-nazionale.html#comment-form' title='4 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7843626745307921918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7843626745307921918'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/mumble-cosa-serve-un-cert-nazionale.html' title='MUMBLE - A cosa serve un CERT Nazionale'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-osLZUd63cS4/Ts4W4CLx1mI/AAAAAAAAAUE/J2Oc4MAiTJ0/s72-c/CERT-nazionale.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4767775444224685745</id><published>2011-11-21T09:27:00.001+01:00</published><updated>2011-11-24T11:48:10.662+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Response'/><category scheme='http://www.blogger.com/atom/ns#' term='CloudSIRT'/><title type='text'>The CloudSIRT project</title><content type='html'>&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://1.bp.blogspot.com/-Algh2HyukLg/TsaIF8kKGvI/AAAAAAAAAT8/S2pQMTnSTnM/s1600/Cloud-SIRT-logo.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Algh2HyukLg/TsaIF8kKGvI/AAAAAAAAAT8/S2pQMTnSTnM/s1600/Cloud-SIRT-logo.jpg" /&gt;&lt;/a&gt;The&amp;nbsp;&lt;a href="https://cloudsecurityalliance.org/" target="_blank"&gt;Cloud Security Alliance&lt;/a&gt;&amp;nbsp;Congress is just finished and many interesting news has been released, such as:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;&lt;a href="https://cloudsecurityalliance.org/research/initiatives/security-guidance/" target="_blank"&gt;Security Guidance 3.0&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- CloudSIRT project&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In the next days I will write a post to describe the major changes in the Security Guidance but today I'm going to write about CloudSIRT, a project in which I am participating. The big news is that the evaluation of the membership applications will start by the end of November; organizations that will join by February 20th will become Charter Members and will enjoy additional membership benefits.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;CloudSIRT (or better, CloudCERT*, the real name of the initiative), as the name suggest, &amp;nbsp;is a project aimed to the development of Incident Response best practices and information sharing within cloud environments. In fact, the mission of this project is to "&lt;b&gt;Enhance the capability of the cloud community to prepare for and respond to vulnerabilities, threats, and incidents in order to preserve trust in cloud computing&lt;/b&gt;"... and this is a very ambitious mission.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In the last months, in order to create a framework to achieve the mission, our working group (led by John Howie and Jim Reavis), has stated the following principles:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- foster an open and collaborative environment among members that supports the goal of safe and secure cloud computing;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- seek to fill gaps in knowledge and capabilities specific to cloud computing security, while avoiding duplication of effort and conflict of ownership;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- be a responsible and responsive partner to governments, law enforcement and security organizations;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- provide real value with demonstrable positive effect in achieving our mission and goals;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- strive to build trust with constituent members, third-party security organizations, and cloud community at large so that information will flow freely to CloudSIRT;&lt;br /&gt;- behave professionally and ethically within the membership and with any external contacts.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This project is an official CSA initiative that was conceived of at the same time as the CSA but was formally announced only one year ago. During this year, among other activities, we have been working on a bylaw that regulates the organization, relationships, memberships and activities of CloudSIRT.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;First of all, we established that no cost will be requested to join CloudSIRT and eligible members will be limited to qualified organizations in the following categories:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Cloud Providers;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Telecommunications providers;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- CERTs, CSIRTs and ISACs (and similar).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;However, upon approval of a two-thirds majority of the Board, other organizations will be able to join CloudSIRT.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More specifically, for Cloud Providers we intend organizations owning and managing the infrastructure used to provide service that offer Public, Private or Community clouds (with one or more of IaaS, PaaS or SaaS), maintaining a permanent, dedicated Incident Response team and holding a direct relationship with their customers.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The eligible Telco Providers must have a carrier-class backbone and/or long-haul network connections over which public IP traffic is routed, must have established peering relationships with other telecommunications provider and maintain a permanent, dedicated Incident Response team.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Finally, eligible CERTs CSIRTs and ISACs must be established by statute or regulation, or designated as a national or regional CERT/CSIRT by the national or regional government with jurisdiction or must be recognized by a national or regional CERT/CSIRT as an industry CERT or ISAC.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Within CloudSIRT, the member organizations will share information regarding operational threats such as:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- attacks against infrastructure;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- malicious activity detected;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- evidence of compromise of another member;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- source of attacks, signatures and patterns, account names, etc.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Since these pieces of information are critical and may contain sensitive data (Personal data/PII, financial information, etc.), all members are requested to sign a multi-party NDA that protects the confidentiality of the information. We are also working on agreements, procedures and operational guides to ensure a legal handling and sharing of this data.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;CloudSIRT will share information within three communication perimeters:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- among member organizations as part of routine operations;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- with the CSA and its Working Groups to enable further research;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- externally to the public, to governments, and to industry.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Actually, not all the information will be shared in all ways, nor simultaneously so, in order to regulate these flows of information, we decided to use a so called "&lt;a href="http://en.wikipedia.org/wiki/Traffic_Light_Protocol" target="_blank"&gt;Traffic Light Protocol&lt;/a&gt;" that puts in relation the information and the communication perimeters.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;CloudSIRT will publish all public information through its official communication channels (website, twitter account and mailing list)&amp;nbsp;that soon will be set up.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Finally, as all the Cloud Security Alliance initiatives, CloudSIRT has a focus on research and will contribute to CSA WGs, in particular those linked to the Guidance “Domain 9: Incident Response” and “Domain 3: Legal and Electronic Discovery”. Moreover, CloudSIRT will contribute to external research specific to its focus and consistent with its Charter.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In the next days, I will publish other posts regarding &lt;a href="http://www.matteocavallini.com/p/cloud-incident-response.html"&gt;Cloud Incident Response&lt;/a&gt; and CloudSIRT in particular so, if you are interested in these subjects... stay tuned!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;*In the US and other countries, Carnegie-Mellon University owns the right to the name ‘CERT’ so, we&amp;nbsp;have begun the process of licensing CloudCERT with CMU and, at the moment, we have an agreement in principle to use CloudCERT but we are using the name CloudSIRT until we have ratified this formal agreement.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4767775444224685745?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4767775444224685745/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/cloudsirt-project_21.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4767775444224685745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4767775444224685745'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/cloudsirt-project_21.html' title='The CloudSIRT project'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Algh2HyukLg/TsaIF8kKGvI/AAAAAAAAAT8/S2pQMTnSTnM/s72-c/Cloud-SIRT-logo.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1316450530707089652</id><published>2011-11-20T08:38:00.001+01:00</published><updated>2011-11-20T09:12:18.464+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 20 novembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This week, many worrying details were published about water utilities and chemical industries as targets of sofisticated cyber attacks. I have selected the most interesting security articles of the week and now, as every weekend, I'm presenting you my "Best of the Week".&lt;/div&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Cephurs" target="_blank"&gt;@Cephurs&lt;/a&gt; RT&lt;a href="http://twitter.com/@CNETNews" target="_blank"&gt;@CNETNews&lt;/a&gt;: Hacker "pr0f" hacked into Houston water plant to demonstrate utility vulnerability to cyberattack &lt;a href="http://cnet.co/txOByF" target="_blank"&gt;cnet.co/txOByF&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@sambowne" target="_blank"&gt;@sambowne&lt;/a&gt; Second water utility reportedly hit by hack attack &lt;a href="http://bit.ly/ugFTuk" target="_blank"&gt;bit.ly/ugFTuk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CompuSecure" target="_blank"&gt;@CompuSecure&lt;/a&gt; Hackers attack Norway's oil, gas and defence businesses &lt;a href="http://sns.mx/BVgXy5" target="_blank"&gt;sns.mx/BVgXy5&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@peterkruse" target="_blank"&gt;@peterkruse&lt;/a&gt;&amp;nbsp;More on the "Fawkes" virus. A video on Youtube (just uploaded) claims that Anonymous have unleased Fawkes on Facebook,&amp;nbsp;&lt;a href="http://www.youtube.com/watch?v=-fhF0tArUUQ" target="_blank"&gt;youtube.com/watch?v=-fhF0t…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ryanaraine" target="_blank"&gt;@ryanaraine&lt;/a&gt; Our Duqu FAQ has been updated with information on multiple easter eggs in the malware code &lt;a href="http://www.securelist.com/en/blog/blog?weblogid=208193178" target="_blank"&gt;securelist.com/en/blog/blog?w…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; Hackers hacking hackers. German carder forums featured in e-zine "Owned and Exposed": &lt;a href="http://bit.ly/sw0IbX" target="_blank"&gt;bit.ly/sw0IbX&lt;/a&gt; #CC&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1316450530707089652?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1316450530707089652/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-20-novembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1316450530707089652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1316450530707089652'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-20-novembre-2011.html' title='Best of the Week - 20 novembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-620809968126276246</id><published>2011-11-13T19:05:00.001+01:00</published><updated>2011-11-14T09:33:31.748+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Guide di Sicurezza'/><category scheme='http://www.blogger.com/atom/ns#' term='CERT-EU'/><title type='text'>La guida del CERT-EU sul malware</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-pyqh1mcg6pg/TsAKpcdyhLI/AAAAAAAAAT0/Cid_FaFX570/s1600/CERT-EU-Security-WP-2011-003.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-pyqh1mcg6pg/TsAKpcdyhLI/AAAAAAAAAT0/Cid_FaFX570/s1600/CERT-EU-Security-WP-2011-003.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Partiamo dall'inizio, da qualche tempo è stato attivato il Computer Emergency Response Team Europeo, il &lt;a href="http://www.cert.europa.eu/" target="_blank"&gt;CERT-EU&lt;/a&gt; appunto. Un'iniziativa di grande valore e spessore per tutta l'Unione Europea che ci pone finalmente al livello degli americani che, con lo &lt;a href="http://www.uscert.gov/" target="_blank"&gt;US-CERT&lt;/a&gt;, hanno proposto al mondo uno dei modelli più importanti per le strutture nazionali dedicate alla prevenzione e gestione degli incidenti.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il neonato CERT-EU sta iniziando a popolare il proprio sito di informazioni utili e di guide per gli utenti.&amp;nbsp;Da qualche giorno è stato pubblicato un documento dal titolo "&lt;a href="http://cert.europa.eu/static/WhitePapers/CERT-EU-SWP_11_003_v1_1.pdf" target="_blank"&gt;Security White Paper 2011-003&lt;/a&gt; - Windows Malware Detection (Incident Response Methodology)".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Prima di entrare nel vivo della descrizione di questo documento&amp;nbsp;devo sottolineare,&amp;nbsp;come mio solito, quanto sia grave la mancanza per l'Italia di un CERT nazionale e quanto questo metta tutti i cittadini e le imprese italiane in posizione di svantaggio rispetto ai nostri partner internazionali (in un momento di grave crisi economica un handicap ancora più sentito), distanziandoci sempre più dall'Unione Europea nel campo della tecnologia e dell'utilizzo del cyberspace.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bene, ora veniamo alla guida.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tra gli indizi che il CERT-EU indica come riferibili ad una possibile infezione ci sono:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- un comportamento anomalo dell'Antivirus (un allarme, l'impossibilità di aggiornarmento il DB delle firme, il fermo di uno o più servizi o l'impossibilità di eseguire scansioni anche se lanciate manualmente)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- un comportamento anomalo del disco rigido (il disco rigido "frulla" a lungo senza apparente legame con le attività correnti)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- un comportamento anomalo del computer (improvviso rallentamento, riavvi senza motivo, crash senza apparente motivo di alcune applicazioni o pop-up che si aprono in modo decontestualizzato rispetto all'uso)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- un comportamento anomalo della rete (connessione a Internet molto lenta per la maggior parte del tempo di navigazione (si vede che sono europei e non italiani... loro hanno la banda larga, noi il digitale terrestre, dove si riesce a vedere...))&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- l'inserimento in una black-list del proprio indirizzo IP statico (per chi ce l'ha)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- un comportamento anomalo dei sistemi di comunicazione (email, IM, ecc).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Saltando tutti i passaggi intermedi, che potete leggere direttamente sulla guida, si giunge alle indicazioni per il ripristino:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- fare il reboot da un live CD e fare il backup, su un disco esterno, di tutti i file importanti&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- rimuovere i binari del malware e tutte le configurazioni di registro (fare riferimento alle best-practice dei vendor antivirus)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- avviare una scansione antivirus online&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- lanciare BartPE live CD con degli strumenti antivirus (in alternativa avviare un live CD prodotto da un vendor AV)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- se possibile reinstallare il Sistema operativo e le applicazioni e fare il restore dei dati da un backup affidabile&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- recuperare i file eventualmente danneggiati dal malware, soprattutto se sono file di sistema&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- fare il reboot della macchina e verificare se il sistema funziona correttamente e riavviare una scansione completa.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Relativamente ai passaggi di bonifica, vi ricordo che su Punto 1 potete trovare &lt;a href="http://www.matteocavallini.com/2010/05/guide-di-sicurezza-il-malware.html" target="_blank"&gt;la guida dedicata al malware &lt;/a&gt;con molti link a risorse e procedure esterne.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Voglio chiudere questa breve analisi del white paper guida del CERT-EU ricordando che tra le azioni indicate a valle del contenimento viene suggerito di fare una valutazione dei costi dell'incidente. Questa attività renderà più semplice fare le giuste valutazioni per le allocazioni del budget da destinare alle contromisure per il malware.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Mi permetto di aggiungere, però, un ulteriore passaggio alla guida del CERT-EU e suggerisco&amp;nbsp;di effettuare, a valle della bonifica, una scansione con&amp;nbsp;&lt;a href="http://secunia.com/vulnerability_scanning/online/" target="_blank"&gt;Secunia On-line scanner&lt;/a&gt; per verificare gli aggiornamenti dei programmi installati. Questo permette di eliminare le eventuali vulnerabilità che sono state sfruttate per l'installazione del malware.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-620809968126276246?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/620809968126276246/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/la-guida-contro-il-malware-del-cert-eu.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/620809968126276246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/620809968126276246'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/la-guida-contro-il-malware-del-cert-eu.html' title='La guida del CERT-EU sul malware'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-pyqh1mcg6pg/TsAKpcdyhLI/AAAAAAAAAT0/Cid_FaFX570/s72-c/CERT-EU-Security-WP-2011-003.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-6895237542276400664</id><published>2011-11-13T08:42:00.001+01:00</published><updated>2011-11-13T09:05:01.607+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 13 novembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Many interesting news this week. This is my selection of the best security resources of the week.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Hope you enjoy it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@mthorbruegge" target="_blank"&gt;@mthorbruegge&lt;/a&gt;&amp;nbsp;#CERT-EU is now #TI listed&lt;a href="http://t.co/B1lULmwY" target="_blank"&gt; trusted-introducer.org/teams/teams-c.…&lt;/a&gt; #fb&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@DebbieMahler" target="_blank"&gt;@DebbieMahler&lt;/a&gt; Best Cloud Computing Security &amp;amp; Best Computer Forensics Tool: Throughout the day, SC Magazine will be announcing... &lt;a href="http://bit.ly/vCYqka" target="_blank"&gt;bit.ly/vCYqka&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@CND_Ltd" target="_blank"&gt;@CND_Ltd&lt;/a&gt; Duqu Created to Spy Iranian Nuclear Program &lt;a href="http://goo.gl/bA0Pt" target="_blank"&gt;goo.gl/bA0Pt&lt;/a&gt; via &lt;a href="http://twitter.com/@softpedia" target="_blank"&gt;@softpedia&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@RSAConference" target="_blank"&gt;@RSAConference&lt;/a&gt; &lt;a href="http://twitter.com/@MishaGlenny" target="_blank"&gt;@MishaGlenny&lt;/a&gt; writes about why you can’t trust the cyber crime stats. Do you agree? &lt;a href="http://bit.ly/vBbNVs" target="_blank"&gt;bit.ly/vBbNVs&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@SCADAhacker" target="_blank"&gt;@SCADAhacker&lt;/a&gt; NSS Labs releases Duqu Analysis &amp;amp; Detection Tool - &lt;a href="http://bit.ly/sIgLNA" target="_blank"&gt;bit.ly/sIgLNA&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;a href="http://twitter.com/@RealSecurity" target="_blank"&gt;@RealSecurity&lt;/a&gt; Blogging Cybersecurity: Looking Back at the Best, Worst and Most Surprising &lt;a href="http://shar.es/onols" target="_blank"&gt;shar.es/onols&lt;/a&gt; #security #cyber&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-6895237542276400664?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/6895237542276400664/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-13-novembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6895237542276400664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6895237542276400664'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-13-novembre-2011.html' title='Best of the Week - 13 novembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4123227584973007984</id><published>2011-11-06T08:47:00.001+01:00</published><updated>2011-11-06T08:47:24.532+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 6 Novembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here's my selection of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; A collection of whitepapers and presentations on Russian cybercrime and online attacks 2000-2010: &lt;a href="http://bit.ly/rTvbrz" target="_blank"&gt;bit.ly/rTvbrz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ArMyZ" target="_blank"&gt;@ArMyZ&lt;/a&gt; Read, keep and save it -The Immutable Laws of Security &lt;a href="http://zite.to/sGhKG8" target="_blank"&gt;zite.to/sGhKG8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@cyberwar" target="_blank"&gt;@cyberwar&lt;/a&gt; Interesting if corroborated.Cyber attack on key Nuclear facility in Mysore? &lt;a href="http://t.co/dDqgvbX3" target="_blank"&gt;asianage.com/india/cyber-at…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikko" target="_blank"&gt;@mikko&lt;/a&gt; F-Secure's Questions &amp;amp; Answers on Duqu: &lt;a href="http://bit.ly/DuquQA" target="_blank"&gt;bit.ly/DuquQA&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@stiennon" target="_blank"&gt;@stiennon&lt;/a&gt; There is no cyber war the same way there is no nuclear war - Forbes &lt;a href="http://onforb.es/tckxW1" target="_blank"&gt;onforb.es/tckxW1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@DrInfoSec" target="_blank"&gt;@DrInfoSec&lt;/a&gt; E&amp;amp;Y: "An executive should know their CISO well and be in constant contact." &lt;a href="http://t.co/JleH5gqc" target="_blank"&gt;banktech.com/risk-managemen…&lt;/a&gt; &amp;lt;- QOTD!!!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@danchodanchev" target="_blank"&gt;@danchodanchev&lt;/a&gt; "Soon we will be facing cyber terrorism" &lt;a href="http://is.gd/kUXG6z" target="_blank"&gt;is.gd/kUXG6z&lt;/a&gt; not at all, as cyber jihad is currently threat number one &lt;a href="http://is.gd/sRjaSI" target="_blank"&gt;is.gd/sRjaSI&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4123227584973007984?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4123227584973007984/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-6-novembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4123227584973007984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4123227584973007984'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/best-of-week-6-novembre-2011.html' title='Best of the Week - 6 Novembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3480851616846236281</id><published>2011-11-02T14:01:00.003+01:00</published><updated>2011-11-03T09:23:52.484+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><title type='text'>Information Warfare Conference Rome 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-hTfwI8wT4ew/TrEeS1L2d8I/AAAAAAAAATc/h7xs8m-gUEI/s1600/Infowar-2011.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" ida="true" src="http://4.bp.blogspot.com/-hTfwI8wT4ew/TrEeS1L2d8I/AAAAAAAAATc/h7xs8m-gUEI/s1600/Infowar-2011.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il 27 ottobre scorso si è tenuta la &lt;a href="http://www.infowar.it/"&gt;seconda edizione&lt;/a&gt; della Information Warfare Conference di Roma organizzata anche quest'anno da &lt;a href="http://www.google.it/url?sa=t&amp;amp;rct=j&amp;amp;q=maglan&amp;amp;source=web&amp;amp;cd=1&amp;amp;ved=0CC8QFjAA&amp;amp;url=http%3A%2F%2Fwww.maglangroup.com%2F&amp;amp;ei=40CxTqGQMob4sgb8qe1T&amp;amp;usg=AFQjCNH2iRjPBAeSjlPUNdciYgTzx2QjrA"&gt;Maglan&lt;/a&gt; e promossa da &lt;a href="http://www.cssi.unifi.it/mdswitch.html"&gt;CSSI&lt;/a&gt;, &lt;a href="http://www.unilink.it/"&gt;Link Campus University&lt;/a&gt;, &lt;a href="http://www.ispri.org/"&gt;ISPRI&lt;/a&gt; e dal Centro studi Gino Germani. Tra le novità di quest'anno, oltre ai numerosi patrocini da parte di enti pubblici, c'è stata l'assegnazione della "Medaglia del Presidente della Repubblica" a sottolineare l'importanza di questo evento nel panorama nazionale.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il tema della conferenza era "&lt;strong&gt;La sfida della cyber-intelligence al sistema Italia&lt;/strong&gt;" e, come lo&amp;nbsp;scorso anno, l'agenda era particolarmente ricca di interventi.&amp;nbsp;Riporterò quindi solo alcuni estratti delle numerose notizie ed analisi interessanti che sono state presentate nel corso della mattinata.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La Conferenza è stata aperta da &lt;strong&gt;Paolo Lezzi&lt;/strong&gt; (CEO Maglan Europe) che&amp;nbsp;ha presentato l'evento e ha quindi lasciato la parola al &lt;strong&gt;prof. Umberto&amp;nbsp;Gori&lt;/strong&gt; che&amp;nbsp;ha sottolineato l'importanza del cyber-space per tutto il mondo dell'intelligence e della counter-intelligence. Tramite il cyebr-space, infatti si aprono scenari fino a pochi anni fa del tutto inaspettati e, entro certi limiti, ancora poco compresi (basti pensare alla facilità con cui&amp;nbsp;Bradley Manning ha copiato le 250.000 pagine di cablo poi pubblicati di WikiLeaks. Se avesse dovuto fare delle copie fisiche,&amp;nbsp;la situazione sarebbe stata ben diversa. NdA). L'intervento è proseguito poi:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;sottolineando la necessità di avvalersi delle&amp;nbsp;PPP (Public-Private Partnership) per indirizzare correttamente queste nuove problematiche caratterizzate da elevate complessità multi-dimensionali&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- invocando una concertazione internazionale per una gestione globale di queste problematiche&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- sottolineando la necessità&amp;nbsp;di definire&amp;nbsp;metriche effettive per la misura degli impatti causati da incidenti informatici. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, il professor Gori ha chiuso il suo intervento con una nota polemica sulle scelte effettuate dall'Italia nel campo della protezione delle infrastrutture critiche, che sono state tardive e non sempre improntate all'efficacia e tempestività che questi temi richiederebbero.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'&lt;strong&gt;on. Vincenzo Scotti&lt;/strong&gt; ha poi ripreso alcuni concetti mettendo in evidenza come il tema dell'intelligence, soprattutto di tipo economico, sia vitale per la difesa delle imprese in tempi di crisi come quelli che stiamo affrontando.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il &lt;strong&gt;prof. Luigi Germani&lt;/strong&gt; ha invece analizzato le varie tipologie di intelligence e di utilizzo del cyber-space&amp;nbsp;come campo di confronto tra entità statuali e non. In particolare ha sottolineato come l'efficacia delle&amp;nbsp;attività di influenza, ingerenza&amp;nbsp;e&amp;nbsp;disinformazione strategica sia moltiplicata dall'utilizzo dei media che si basano sui social network e sui nuovi mezzi di comunicazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il &lt;strong&gt;Dott. Paolo Scotto di Castelbianco&lt;/strong&gt; ha invece puntato sulle difficoltà create ai paesi maggiormente evoluti dalle vulnerabilità intrinseche al cyber-space, sia dal punto di vista delle possibili minacce statuali, sia dal punto di vista di minacce meno canoniche come quelle rappresentate dagli hacktivist. Questi ultimi, in particolare, seguendo motivazioni sempre più liquide e cangianti e creando una sfiducia diffusa nella sicurezza della rete, hanno un ruolo particolarmente rilevante&amp;nbsp;nel panorama internazionale delle minacce.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il &lt;strong&gt;C.F. Danilo Murciano&lt;/strong&gt; ha individuato, nell'anonimato garantito dalla rete e dalla forte asimmetria tra chi attacca e chi si difende, i temi dominanti della intelligence nell'era cyber-space. Ha inoltre posto il dominio legato al cyber-space come trasversale agli altri domini (acqua, aria, terra e spazio), sottolineando quindi le interdipendenze che si vengono a creare tra le operazioni militari canoniche e quelle cyber e la conseguente crescente importanza della "Information Superiority" come obiettivo strategico. L'intervento si è chiuso con una riflessione sul bisogno di dotarsi&amp;nbsp;di regole chiare in questo nuovo dominio, ad esempio per determinare quando un attacco cyber possa essere considerato un atto bellico, con tutte le conseguenze del caso.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;strong&gt;Shai Blitzblau&lt;/strong&gt;, citando gli "air-gap", ossia le separazioni tra le reti dedicate a sistemi critici e le reti connesse ad Internet, si è soffermato sull'inefficacia di queste tecniche&amp;nbsp;di sicurezza, soffermandosi invece sull'importanza dell'approccio complessivo alla sicurezza e della costante attenzione ai fenomeni e ai segnali deboli. Dal punto di vista dell'intelligence ha poi citato due fenomeni "collaterali" all'utilizzo del&amp;nbsp;cyber-space per questi fini:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- le difficoltà di mantenere la segretezza delle&amp;nbsp;attività di preparazione di una&amp;nbsp;operazione di intelligence dato che, a differenza ad esempio&amp;nbsp;di una telecamera,&amp;nbsp;i mezzi che devono essere sviluppati per fare sorveglianza di un bersaglio cyber sono molto specifici per&amp;nbsp;ogni dato&amp;nbsp;target&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- la necessità di disporre di un ampio arsenale di cyber-weapon perché queste armi sono caratterizzate da una grande efficacia che però si&amp;nbsp;viene a depauperare completamente&amp;nbsp;a seguito del primo utilizzo, rendendole quindi inadatte a utilizzi successivi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;strong&gt;Andrea Rigoni&lt;/strong&gt;, ha esordito con una provocazione dicendo che siamo già all'11 settembre della cyber security solo che non ce ne siamo ancora accorti. Il suo intervento è poi proseguito citando le varie problematiche del DNS che il &lt;a href="http://www.gc-sec.org/"&gt;GC-SEC&lt;/a&gt; sta contribuendo a mettere in luce.&amp;nbsp;Il DNS, infatti, è una&amp;nbsp;componente fondamentale delle reti che però è stata concepita&amp;nbsp;nel '93 senza che, ovviamente,&amp;nbsp;fosse possibile intuire le enormi evoluzioni&amp;nbsp;negli utilizzi&amp;nbsp;che sarebbero seguiti.&amp;nbsp;Oggi il DNS soffre di una mancanza di sicurezza intrinseca e indotta, la prima è dovuta appunto alla sua vetustà, la secoda invece dipende&amp;nbsp;dalla mancanza di una vera governance che ne possa indirizzare le evoluzioni.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come avrete letto, quindi, questa conferenza è stata&amp;nbsp;un evento molto interessante e, in un'Italia sempre più avvitata sui propri problemi e senza&amp;nbsp;grandi slanci&amp;nbsp;verso il futuro,&amp;nbsp;svolge un ruolo&amp;nbsp;importante&amp;nbsp;nel mantenere alta l'attenzione su questi temi.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3480851616846236281?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3480851616846236281/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/information-warfare-conference-rome.html#comment-form' title='3 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3480851616846236281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3480851616846236281'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/information-warfare-conference-rome.html' title='Information Warfare Conference Rome 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-hTfwI8wT4ew/TrEeS1L2d8I/AAAAAAAAATc/h7xs8m-gUEI/s72-c/Infowar-2011.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3189274139206588426</id><published>2011-11-01T21:48:00.000+01:00</published><updated>2011-11-01T21:48:05.535+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MELANI'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='svizzera'/><category scheme='http://www.blogger.com/atom/ns#' term='rapporto'/><title type='text'>MELANI: il nuovo report del CERT svizzero</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XxCdehnN3Ko/TNRjoI3xb0I/AAAAAAAAAMM/VWEbx6_mMrE/s1600/Cover_rapporto_semestrale_MELANI.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://4.bp.blogspot.com/-XxCdehnN3Ko/TNRjoI3xb0I/AAAAAAAAAMM/VWEbx6_mMrE/s320/Cover_rapporto_semestrale_MELANI.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ieri, MELANI, il CERT svizzero, &lt;a href="http://www.melani.admin.ch/dokumentation/00123/00124/01128/index.html?lang=en&amp;amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ad1IZn4Z2qZpnO2Yuq2Z6gpJCDdIF8fmym162epYbg2c_JjKbNoKSn6A--"&gt;ha rilasciato&lt;/a&gt; il nuovo rapporto sullo stato della sicurezza informatica in Svizzera e nel resto del mondo.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come sempre, gli esperti svizzeri hanno fatto un eccellente lavoro, riunendo in unico documento tutti i fatti ed i fenomeni salienti dei primi sei mesi del 2011.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Scorrendo il documento potrete trovare, ad esempio, alcuni&amp;nbsp;dati relativi:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- all'aumento del fenomeno dello "skimming" (la clonazione di carte di pagamento) in Svizzera,&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- agli attacchi degli Anonymous e di Lulzsec,&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- all'aumento degli attacchi con finalità spionistiche&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- agli attacchi contro Sony e RSA.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In particolare, voglio però ricordare qui 3 argomenti che mi hanno colpito particolarmente e che riporto brevemente.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il primo riguarda l'approccio cauto delle banche svizzere verso lo sviluppo di applicazioni mobili per l'home banking. Nel rapporto si ricorda che, a parte qualche rara eccezione, le "apps" distribuite dalle banche svizzere sono finalizzate più alla diffusione di notizie utili sull'andamento dei mercati che alle transazioni bancarie vere e proprie. A questo proposito, viene analizzata la difficoltà di impostazione di un corretto approccio all'autenticazione forte in contesti come quelli degli smartphone. In questi device, infatti, l'invio di sms con credenziali di accesso di tipo one-time (mTAN) è una misura debole, visto che risiede sullo stesso apparato che ospita anche l'applicazione e gli altri tipi di distribuzione di credenziali (chiavette, token e tabelle) sono poco consoni all'uso mobile.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il secondo punto che voglio riportare è l'impatto degli attacchi con finalità spionistiche nella vita quotidiana delle aziende svizzere ed internazionali. MELANI, infatti, ha voluto sottolineare la diffusione degli attacchi ad aziende, governi e istituzioni finanziarie finalizzati alla sottrazione di dati riservati. Nel rapporto viene analizzata una delle tecniche maggiormente utilizzate che è messa in atto attraverso l'invio di mail contenenti malware&amp;nbsp;verso dipendenti dell'ente target. MELANI conclude questa riflessione con l'invito alla propria constituency ad attrezzarsi per fronteggiare un possibile attacco di questo genere perché la probabilità di accadimento è ormai piuttosto alta.&lt;br /&gt;&lt;br /&gt;Il terzo ed ultimo aspetto su cui volevo soffermarmi è l'annuncio che il governo elvetico è in procinto di varare la propria strategia per la cyber security. La Svizzera sarà così annoverata tra i paesi europei ed occidentali che hanno già varato questo fondamentale strumento a garanzia della sicurezza delle proprie infrastrutture. Il rapporto ci ricorda che, tra gli altri, USA, Inghilterra, Germania, Olanda Francia, Repubblica Ceca e Spagna sono già dotate di una strategia di sicurezza e che altri paesi &amp;nbsp;si stanno aggiungendo.&lt;br /&gt;&lt;br /&gt;Questa notizia mi fa sentire ancora più forte la mancanza in Italia di una struttura che svolga le funzioni di un CERT nazionale. Il nostro paese, infatti, sta ormai rimanendo sempre più isolato in Europa e nei consessi internazionali non avendo né un CERT nazionale né, tantomeno, una strategia che detti le priorità di intervento. Tanto per dire, l'Europa ha disposto che entro il prossimo anno tutti i paesi membri siano dotati di un CERT nazionale e anche paesi meno tecnologici e dipendenti dalla rete come ad esempio il &lt;a href="http://cert-africa.org/node/91"&gt;Ghana&lt;/a&gt; si sono dotati di un CERT.&lt;br /&gt;&lt;br /&gt;Che dire di più... complimenti a MELANI per l'ottimo lavoro.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3189274139206588426?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3189274139206588426/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/11/melani-il-nuovo-report-del-cert.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3189274139206588426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3189274139206588426'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/11/melani-il-nuovo-report-del-cert.html' title='MELANI: il nuovo report del CERT svizzero'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-XxCdehnN3Ko/TNRjoI3xb0I/AAAAAAAAAMM/VWEbx6_mMrE/s72-c/Cover_rapporto_semestrale_MELANI.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8018913276089112758</id><published>2011-10-30T08:36:00.000+01:00</published><updated>2011-10-30T08:36:22.525+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 30 ottobre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;That's the new post of the "Best of Week" series, in which you can find my personal selection of the best security resources of this week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@computersandlaw" target="_blank"&gt;@computersandlaw&lt;/a&gt; Cloud Legal Project have a recording of Dr Ian Walden's talk on law enforcement access to cloud data available at &lt;a href="http://bit.ly/nqaChB" target="_blank"&gt;bit.ly/nqaChB&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@FSecure" target="_blank"&gt;@FSecure&lt;/a&gt; How to Create a Fake Identity and (Try to) Stay Anonymous Online &lt;a href="http://lifehac.kr/rULTcC" target="_blank"&gt;lifehac.kr/rULTcC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ciscosecurity/" target="_blank"&gt;@CiscoSecurity&lt;/a&gt; Security Quiz - easier than the one we had at BlackHat, have you tried it yet? &lt;a href="http://bit.ly/vsvQ3V" target="_blank"&gt;bit.ly/vsvQ3V&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; Using Pastebin Sites For Pen Testing Reconnaissance &lt;a href="http://bit.ly/rddagj" target="_blank"&gt;bit.ly/rddagj&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@andreglenzer" target="_blank"&gt;@andreglenzer&lt;/a&gt; Further evidence of Certificate Authority break-ins: &lt;a href="http://goo.gl/9SVtK" target="_blank"&gt;http://goo.gl/9SVtK&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@paulsparrows" target="_blank"&gt;@paulsparrows&lt;/a&gt; XML Encryption Cracked! &lt;a href="http://bit.ly/rd0RFU" target="_blank"&gt;bit.ly/rd0RFU&lt;/a&gt; #Infosec&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8018913276089112758?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8018913276089112758/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-30-ottobre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8018913276089112758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8018913276089112758'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-30-ottobre-2011.html' title='Best of the Week - 30 ottobre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5346206714227535738</id><published>2011-10-25T17:00:00.000+02:00</published><updated>2011-10-25T20:05:35.214+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social network'/><category scheme='http://www.blogger.com/atom/ns#' term='Voci Amiche'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><title type='text'>Andrea Zapparoli Manzoni - 2011, InfoSec’s “Annus Horribilis”</title><content type='html'>&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s1600/Andrea-Zapparoli-Manzoni.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: justify;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s1600/Andrea-Zapparoli-Manzoni.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The "Voci Amiche" section of Punto 1 starts again hosting contribution from other security experts.&lt;br /&gt;&lt;br /&gt;I'm very happy to announce that we are beginning with a good friend of mine and a very capable expert: Andrea Zapparoli Manzoni.&lt;br /&gt;&lt;br /&gt;His experience and passion in his work in the field of social media security make him a prominent figure among the Italian security experts.&lt;br /&gt;&lt;br /&gt;I agreed with Andrea that his post will be divided in two parts so... stay tuned!!&lt;br /&gt;&lt;br /&gt;Andrea, the floor is yours!&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Social Business Insecurity: Espionage, Cyberwar and Trans-national Cybercrime&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A 2008 report of the Center for Strategic and International Studies (CSIS) Commission on Cybersecurity for the 44th Presidency noted: ‘we began with one central finding: The United States must treat cybersecurity as one of most important national security challenges it faces’ (CSIS 2008).&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Let's admit it: three years later things didn’t get any better, on the contrary, they seriously worsened. Without fear of being dubbed as scaremongers, we can say that 2011 was a real "annus horribilis" for InfoSec, probably the worst ever, and that, at least until now, both industry self-regulation and law enforcement oversight have almost completely failed in the cyber security space.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The same foundations of e-commerce, home banking and of any other sensitive online activity (including expressing dissent) have been shaken by the recent attacks on the Certification Authorities infrastructure (Comodo, DigiNotar and even RSA, in a sense), leaving us wondering whether we should completely rethink the trust model that is one of the cornerstones of the Internet today. &amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The prevailing compliance-focused security model is showing all its shortcomings too, and has clearly become obsolete when compared to the evolution of threats: not only diffuse cyber-hacktivism has fully demonstrated its potential with LulzSec and Anonymous (ask Sony!), but high tech skills are now available for rent on a global scale to a variety of customers, including nation states, corporations and other interest groups (i.e. criminal cartels and terrorists), changing the security game forever.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We're also witnessing the birth of trans-national cyber mercenary units and the unregulated proliferation of shadowy private contractors (the HBGary scandal being just a glimpse of what is brewing in the cyber-underworld, well beyond the reach of public scrutiny).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The feeling is that the situation is getting out of control, and that all the advantages that the new digital domain has brought to our everyday's lives are now at risk of being seriously hindered by the stupendous growth of cyber threats and of their intensity, if this trend isn’t somehow reversed.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Social Business Insecurity&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;While Social Business is touted as the new frontier of economic activity, attracting huge investments and creating a lot of expectations, associated risks are completely underestimated.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The marketing hype surrounding the steep rise of Social Networks adoption has masked the reality of a corresponding growth in espionage, cyber crime and cybewarfare activities performed through them.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The potential consequences of organized cybercrime, cyber-espionage and cyberwarfare activities coupled with Social Media platforms are, as of today, not well understood and mostly ignored.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;With an estimated billion logged users per day, Social Media are the “place” where everything happens nowadays, almost in real time and without any serious monitoring capability in place. It is extremely hard, both economically and technically, to react to Social Media delivered threats in a timely and organized manner, which can then be amplified and spread to a world-wide audience in a few minutes.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Furthermore, it seems that the owners of Social Media platforms have no interest, or at least are not paying enough effort, into making their digital environments less prone to misuse.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cyber-espionage (expecially from the far east) has reached never seen before levels of sophistication and is now the world's primary cause of intellectual property theft, becoming more aggressive by the day, while some analyst are already stating that we just entered a new “Cold Cyberwar” age.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;With regards to cyberwar, many developed countries are loudly declaring that they are defining ad-hoc cyberwarfare doctrines and building up both offensive and defensive cyber capabilities, establishing military commands and special hybrid groups (military and civilian) for the purpose, while at the same time they are getting every day more vulnerable and susceptible to devastating cyber-attacks on their digital infrastructures, caught in a self fulfilling prophecy.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Meanwhile trans-national cybercrime is growing exponentially (+250% in 2011 compared to 2010), having reached an overall estimated 2011 turnover of 7Bn $ while inducing worldwide direct and indirect losses for 388Bn $ (a 55:1 ratio!), an amount of lost wealth that is bigger than Denmark’s GDP.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;For their very nature, Social Media are not only affected by the usual Internet threats (frauds, scams, spam, phishing, whaling, identity theft, malvertising and infections hit tens of millions of users every year), but are also becoming the new tool of choice for OSInt and enemy groups infiltration, social engineering and PsyOps, unfair competition, surveillance and target acquisition (as was recently demonstrated in Lybia and during the “Arab Springs”). Social Media have now become not only the Arcadia of digital social interactions, but also the equivalent of a world-wide, free C4SIR for any antagonist group, a perfect cyberweapons delivery system and, of course, cybercrime’s preferred playground.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In this scenario it is clear how Social Media platforms themselves have become not only a major infection vector but at the same time a weapon, a battlefield and (therefore) a primary target, which makes them quite a dangerous environment for establishing large scale business operations.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Also, due to the fact that Social Media Security awareness is completely lacking, not only within the general population but also among law-makers and top managers, laws, policies and safe behaviours are also lagging years behind the adoption of the technology, in all environments.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This creates a huge, nearly untractable problem for nowadays security teams, because of the sheer number of users involved, and because&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;1)&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;SN are intrinsically based upon a (mostly false) sense of trust between their members,&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;2)&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;SN authentication methods are weak to say the least and identity is not verifiable (nor verified),&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;3)&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;attacks are mostly performed at the semantic level, well above firewalls and antimalware defenses, and&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;4)&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;mobile devices and the “consumerization” of Enterprise IT (which is spreading also among the military!) are making traditional defenses unworkable.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;There are specific countermeasures that we can apply in order to mitigate Social Business related risks, but they require huge investments, a strong committment, diffuse education at all levels, organizational and technological radical changes, and the hard work of many skilled people (not only in the InfoSec field) in order to be effective. We’ll discuss them in the next article, stay tuned.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bio&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;Andrea Zapparoli Manzoni was born in Milan in 1968.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;With a multidisciplinary background both in political science and in computer science, since 1997 he developed an active interest in ICT security, with particular reference to GRC (Governance, Risk and Compliance), cybercrime and cyber warfare issues.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Over the years he worked in the IDM, IAM, DLP, Anti Fraud, Security Intelligence, Forensics, Vulnerability Assessment &amp;amp; Management fields in Enterprise, Industrial, Central PA and Gov-Mil environments.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;He writes articles and essays on InfoSec topics and follows very closely all developments in Cybersecurity, working as a trusted advisor with national and international organizations.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;He partecipates to the activities of CLUSIT (Italian Association for Information Security) speaking at conferences, contributing papers (two ROSI patterns about IAM and DLP, seminars about SCADA Security and Social Media Security) and spreading the culture of IT Security in Italy.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In addition to collaborating with numerous Italian and foreign companies, he is the founder and CEO of iDialoghi, a consulting firm specializing in the design and implementation of advanced information security solutions, including the Social Business Security field.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5346206714227535738?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5346206714227535738/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/andrea-zapparoli-manzoni-2011-infosecs.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5346206714227535738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5346206714227535738'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/andrea-zapparoli-manzoni-2011-infosecs.html' title='Andrea Zapparoli Manzoni - 2011, InfoSec’s “Annus Horribilis”'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-eOEeDDKFUAo/TqU5vwFEVXI/AAAAAAAAATM/Y7TxbYN7eoQ/s72-c/Andrea-Zapparoli-Manzoni.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8557630555189889834</id><published>2011-10-23T09:50:00.000+02:00</published><updated>2011-10-23T09:50:07.970+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 23 ottobre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span id="goog_1617302091"&gt;&lt;/span&gt;Duqu, &lt;a href="http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet" target="_blank"&gt;the son of Stuxnet&lt;/a&gt;, has attracted many attentions this week. I has my own opinion on this topic and I'm trying to obtain some confirmations. Next week, probably, I will publish something on this subject.&lt;br /&gt;&lt;br /&gt;Here's my list of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@marcomorana" target="_blank"&gt;@marcomorana&lt;/a&gt; "&lt;a href="http://twitter.com/@WebSecurityNews" target="_blank"&gt;@WebSecurityNews&lt;/a&gt;: Hackers Spied on Board Directors After Nasdaq Breach - Enterprise Security Today &lt;a href="http://ow.ly/1fgaFv" target="_blank"&gt;ow.ly/1fgaFv&lt;/a&gt;"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@AdobeSecurity" target="_blank"&gt;@AdobeSecurity&lt;/a&gt; Note: The next quarterly #AdobeReader, #Adobe #Acrobat #security updates have been rescheduled for Jan 10, 2012. &lt;a href="http://adobe.ly/oAyZ0u" target="_blank"&gt;adobe.ly/oAyZ0u&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@josephmenn" target="_blank"&gt;@josephmenn&lt;/a&gt; FBI official says secure, alternate Internet is needed to protect critical systems - &lt;a href="http://wapo.st/qqRWk3" target="_blank"&gt;wapo.st/qqRWk3&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@marcoriccardi" target="_blank"&gt;@marcoriccardi&lt;/a&gt; The Biggest Security Breaches Of All Time &lt;a href="http://bit.ly/oNvZF7" target="_blank"&gt;bit.ly/oNvZF7&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@FSecure" target="_blank"&gt;@FSecure&lt;/a&gt; Who gets your Internet passwords when you die? &lt;a href="http://on.msnbc.com/nJIWlX" target="_blank"&gt;on.msnbc.com/nJIWlX&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; Using Pastebin Sites For Pen Testing Reconnaissance &lt;a href="http://bit.ly/rddagj" target="_blank"&gt;bit.ly/rddagj&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8557630555189889834?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8557630555189889834/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-23-ottobre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8557630555189889834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8557630555189889834'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-23-ottobre-2011.html' title='Best of the week - 23 ottobre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5273743804006160230</id><published>2011-10-16T09:38:00.001+02:00</published><updated>2011-10-16T09:38:11.276+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 16 ottobre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here's my list of the best security &amp;nbsp;resources of this week.&lt;br /&gt;&lt;br /&gt;And this week we serve... many videos!&lt;br /&gt;&lt;br /&gt;Hope you enjoy!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mthorbruegge" target="_blank"&gt;@mthorbruegge&lt;/a&gt; Cyber Security: Thousands of video lectures from the world's top scholars &lt;a href="http://j.mp/npsKK9" target="_blank"&gt;j.mp/npsKK9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@jduck1337" target="_blank"&gt;@jduck1337&lt;/a&gt; Check out &lt;a href="http://twitter.com/@0xcharlie" target="_blank"&gt;@0xcharlie&lt;/a&gt; 's &lt;a href="http://twitter.com/@PaulDotCom" target="_blank"&gt;@PaulDotCom&lt;/a&gt; interview on Pwn2Own and more -&amp;nbsp;&lt;a href="http://t.co/mwK6MCo6" target="_blank"&gt;ustream.tv/recorded/17719…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@taosecurity" target="_blank"&gt;@taosecurity&lt;/a&gt; Honker Union of China reorganizing for defense, plans to avoid cybercrime &lt;a href="http://on.wsj.com/o2wYaI" target="_blank"&gt;on.wsj.com/o2wYaI&lt;/a&gt; Probably true; want to make less risky money?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@gianlucaSB" target="_blank"&gt;@gianlucaSB&lt;/a&gt; Public/Private Collaboration to Fight Botnet Plague &lt;a href="http://ow.ly/6U0mL" target="_blank"&gt;ow.ly/6U0mL&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@josephmenn" target="_blank"&gt;@josephmenn&lt;/a&gt; Where are countries most vulnerable to cyber attacks? Do we need an "Internet 2"? More stories are up at &lt;a href="http://t.co/8bjEymY8" target="_blank"&gt;ft.com/intl/indepth/c…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@DoDRecruiterDC" target="_blank"&gt;@DoDRecruiterDC&lt;/a&gt; How to Secure Federal Data in the #Cloud &lt;a href="http://soc.li/WZ53M9E" target="_blank"&gt;soc.li/WZ53M9E&lt;/a&gt; #bigdata #infosec #cybersecurity via &lt;a href="http://twitter.com/@spinzo" target="_blank"&gt;@spinzo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@0xcharlie" target="_blank"&gt;@0xcharlie&lt;/a&gt; Why you shouldn't report bugs (&lt;a href="http://t.co/I83FtZOF" target="_blank"&gt;i.haymarket.net.au/News/201110140…&lt;/a&gt;) Especially web bugs!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5273743804006160230?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5273743804006160230/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-16-ottobre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5273743804006160230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5273743804006160230'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-16-ottobre-2011.html' title='Best of the Week - 16 ottobre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4132274335169429856</id><published>2011-10-14T14:29:00.000+02:00</published><updated>2011-10-14T17:30:03.147+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><title type='text'>MUMBLE - Di droni, malware e SCADA</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-l6gS8x1esMs/Tpf5I4qb1VI/AAAAAAAAATE/mwSuhzJ40A4/s1600/Telnet-747-Boeing.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" oda="true" src="http://3.bp.blogspot.com/-l6gS8x1esMs/Tpf5I4qb1VI/AAAAAAAAATE/mwSuhzJ40A4/s1600/Telnet-747-Boeing.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questa riflessione nasce da una serie di notizie che hanno catturato l'attenzione dei media in questi giorni. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La prima è sicuramente la più nota: &lt;a href="http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet/" target="_blank"&gt;è stata scoperta&lt;/a&gt; un'infezione, causata da un malware, sui sistemi di controllo degli aerei senza pilota americani (i droni appunto) che vengono utilizzati per le missioni di eliminazione mirata dei militanti di Al-Qaeda in Pakistan. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E qui sorge la prima serie di riflessioni e domande. Ma&amp;nbsp;è possibile che questi sistemi, così &lt;a href="http://www.economist.com/node/21531433" target="_blank"&gt;critici da un punto di vista tattico e strategico&lt;/a&gt;, in grado di lanciare attacchi cinetici che causano la morte di esseri&amp;nbsp;umani,&amp;nbsp;siano così poco protetti da cadere vittime di un malware qualunque?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se la risposta è si, vuol dire che gli americani sono tutto fumo e niente arrosto. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se la risposta è no, allora vuol dire che non è proprio un malware qualunque quello che li ha infettati. E quindi, se si prosegue su questa linea di pensiero, ci dobbiamo chiedere: "Ma come si infetta un sistema d'arma come quello?". Non credo che ci siano allegati da aprire o link malevoli da cliccare.&amp;nbsp;Restano quindi:&amp;nbsp;l'accesso fisico alle macchine (tipo chiavetta USB o dischi vari), gli accessi diretti via rete o, peggio ancora, le "logic bomb" installate su qualche componente software o hardware. Insomma scenari che prevedono un pesante impegno di intelligence, risorse professionali&amp;nbsp;e tecnologie d'avanguardia. In ogni caso scenari da brividi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Non bastasse questo, la seconda notizia è che i tecnici che hanno scoperto il malware hanno cercato di bonificare le macchine infette &lt;a href="http://www.wired.com/dangerroom/2011/10/drone-virus-kept-quiet/" target="_blank"&gt;senza coinvolgere i gruppi&lt;/a&gt; che si occupano di cybersecurity per l'aviazione americana. Come dire... "Do it yourself". Un fatto gravissimo se fosse vero.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La terza notizia è che un &lt;a href="http://www.wired.com/images_blogs/dangerroom/2011/10/11-10-01-RPA-Malware-Release-FINAL-SAF_PA-approved.docx" target="_blank"&gt;comunicato ufficiale&lt;/a&gt; minimizza l'accaduto e asserisce che si è trattato di un banale keylogger destinato a rubare credenziali di giochi on line ad infettare il sistema. Il vettore d'infezione? Un disco USB infetto. Tutto fumo e niente arrosto dunque? Non ci giurerei.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il mio commento a questo punto è: Stavolta è andata bene ma se qualcuno decidesse di organizzare un attacco, vista la situazione, potrebbe certamente fare dei gran bei danni, senza dover necessariamente ricorrere a scenari da "Mission Impossible". Come Stuxnet ha d'altronde insegnato a tutto il mondo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'ultima notizia che mi ha colpito è che i sistemi di funzionamento dei motori dei 747, anche quando sono&amp;nbsp;in volo, &lt;a href="https://www.infosecisland.com/blogview/16696-FACT-CHECK-SCADA-Systems-Are-Online-Now.html" target="_blank"&gt;possono essere acceduti da remoto&lt;/a&gt; dai tecnici dalle compagnie aeree per modificarne la configurazione dei parametri. E che la sicurezza&amp;nbsp;non è certamente il punto forte dell'operazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Fermatevi un attimo. Respiro. E adesso rileggete la frase. Se non vi siete spaventati vuol davvero dire che avete un'incrollabile&amp;nbsp;fiducia nel prossimo e nella tecnologia.&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Io no. Io sono spaventato da queste notizie.&amp;nbsp;Se provate a unire tutte queste notizie la sensazione&amp;nbsp;è che ci siano in giro&amp;nbsp;degli apprendisti stregoni che mettono tutti quanti a rischio con scelte che non garantiscono un pieno controllo della situazione. E credo quindi che un ripensamento nell'uso di questo tipo di tecnologie sia necessario.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Auspicabilmente&amp;nbsp;prima che qualche evento&amp;nbsp;ci metta tutti davanti all'evidenza dei fatti.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4132274335169429856?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4132274335169429856/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/mumble-di-droni-malware-e-scada.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4132274335169429856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4132274335169429856'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/mumble-di-droni-malware-e-scada.html' title='MUMBLE - Di droni, malware e SCADA'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-l6gS8x1esMs/Tpf5I4qb1VI/AAAAAAAAATE/mwSuhzJ40A4/s72-c/Telnet-747-Boeing.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8964855777767121204</id><published>2011-10-09T15:09:00.000+02:00</published><updated>2011-10-09T15:09:22.702+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 9 ottobre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;This is the week in which Steve Jobs has passed away. My thoughts are for his family and his friends. I'm convinced that the world is a poorer place without him.&lt;br /&gt;&lt;br /&gt;Here my list of best security news of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@GovInfoSecurity" target=" _blank"&gt;@GovInfoSecurity&lt;/a&gt; #NIST Issues Continuous Monitoring Guidance. &lt;a href="http://bit.ly/mS5YMQ" target=" _blank"&gt;bit.ly/mS5YMQ&lt;/a&gt; #infosec #ITsecurity #cybersecurity&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@jduck1337" target=" _blank"&gt;@jduck1337&lt;/a&gt; Check out &lt;a href="http://twitter.com/@0xcharlie" target=" _blank"&gt;@0xcharlie&lt;/a&gt; 's &lt;a href="http://twitter.com/@PaulDotCom" target=" _blank"&gt;@PaulDotCom&lt;/a&gt; interview on Pwn2Own and more - &lt;a href="http://t.co/mwK6MCo6" target=" _blank"&gt;ustream.tv/recorded/17719…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@lastknight" target=" _blank"&gt;@lastknight&lt;/a&gt; Online Penetration Testing Tools &lt;a href="http://bit.ly/pYW0pg" target=" _blank"&gt;bit.ly/pYW0pg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CompuSecure" target=" _blank"&gt;@CompuSecure&lt;/a&gt; Chrome extension enables remote computer control &lt;a href="http://sns.mx/Bzfuy6" target=" _blank"&gt;sns.mx/Bzfuy6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CERT_Polska_en" target=" _blank"&gt;@CERT_Polska_en&lt;/a&gt; #Malware (probably a #keylogger) hits Predator and Reaper US military drones! Security specialists can't remove it... &lt;a href="http://t.co/AKeexuUx" target=" _blank"&gt;wired.com/dangerroom/201…&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nicfab" target=" _blank"&gt;@nicfab&lt;/a&gt; Disegno di legge canadese sull'obbligatorietà della data breach notification &lt;a href="http://bit.ly/osXESA" target=" _blank"&gt;bit.ly/osXESA&lt;/a&gt;&amp;nbsp;(The proposal for a Canadian data breach notification law)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RealSecurity" target=" _blank"&gt;@RealSecurity&lt;/a&gt; [Updated] Malware Removal Guide for Windows - added #malware symptoms &lt;a href="http://www.selectrealsecurity.com/malware-removal-guide" target=" _blank"&gt;selectrealsecurity.com/malware-remova…&lt;/a&gt; #security #virus&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8964855777767121204?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8964855777767121204/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-9-ottobre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8964855777767121204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8964855777767121204'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-9-ottobre-2011.html' title='Best of the Week - 9 ottobre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4736949554233069089</id><published>2011-10-04T12:56:00.001+02:00</published><updated>2011-10-04T12:56:42.595+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='strategia difensiva'/><category scheme='http://www.blogger.com/atom/ns#' term='riflessioni sicurezza'/><title type='text'>Ottobre 2011: il mese della...</title><content type='html'>&lt;div style="text-align: justify;"&gt;Non ho resistito. L'occasione era troppo ghiotta. Due iniziative che occupano il mese di ottobre, due Stati alle prese con problemi diversi e sensibilità diverse, due modi di interpretare il futuro e la tanto agognata crescita, due modi di coinvolgere i cittadini in un'iniziativa pubblica con risvolti sociali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;Ma quali paesi? E quali iniziative?&lt;br /&gt;&lt;br /&gt;1 - Stati Uniti - Ottobre 2011 &lt;a href="http://www.staysafeonline.org/ncsam"&gt;il mese della cybersecurity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-JbhAYFwvB1I/Toq0V0eW2nI/AAAAAAAAAS8/0u2CeYHJnbc/s1600/NCSAM.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="255" src="http://3.bp.blogspot.com/-JbhAYFwvB1I/Toq0V0eW2nI/AAAAAAAAAS8/0u2CeYHJnbc/s400/NCSAM.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;2 - Italia - Ottobre 2011 &lt;a href="http://www.raccolta10piu.it/index.html"&gt;il mese del riciclo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TZTBBxP9sXY/Toq0tAkv5VI/AAAAAAAAATA/m9zCBJv1oqI/s1600/Raccolta-10-pi%25C3%25B9.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://4.bp.blogspot.com/-TZTBBxP9sXY/Toq0tAkv5VI/AAAAAAAAATA/m9zCBJv1oqI/s400/Raccolta-10-pi%25C3%25B9.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Fermi! Non banalizziamo, non lasciamoci subito andare a grida di dolore. Superiamo il momento di tristezza immediata e proviamo a ragionare.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Sarà solo la nostra miopia a farci occupare di "monnezza" invece che di cybersecurity? Probabilmente no, probabilmente queste differenti scelte nascono da differenti visioni del proprio futuro come paese e da differenti contingenze nei problemi percepiti dalla popolazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Entrambe le iniziative partono dalla constatazione che la consapevolezza e l'educazione sono componenti essenziali per riuscire a modificare i comportamenti dei cittadini. E' però certo che se&amp;nbsp;oggi&amp;nbsp;si lanciasse in Italia&amp;nbsp;un'iniziativa&amp;nbsp;come quella statunitense, visto che non c'è una sensibilità diffusa su questo tema, sicuramente qualcuno storcerebbe il naso e penserebbe che l'iniziativa nasce per far "contento" qualcuno.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Abbiamo sicuramente ancora tanta strada da fare... speriamo almeno che non sia invasa da cumuli di "monnezza"&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4736949554233069089?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4736949554233069089/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/ottobre-2011-il-mese-della.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4736949554233069089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4736949554233069089'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/ottobre-2011-il-mese-della.html' title='Ottobre 2011: il mese della...'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-JbhAYFwvB1I/Toq0V0eW2nI/AAAAAAAAAS8/0u2CeYHJnbc/s72-c/NCSAM.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5894187850705953784</id><published>2011-10-02T09:30:00.001+02:00</published><updated>2011-10-02T09:31:00.351+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 1 ottobre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Many interesting things have happened this week: a dangerous botnet was neutralized and an interesting report was released.&lt;br /&gt;&lt;br /&gt;Here you can find my list of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; Microsoft Neutralizes Kelihos Botnet, Names Defendant in Case &lt;a href="http://bit.ly/pD5rEx" target="_blank"&gt;bit.ly/pD5rEx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CiscoSecurity" target="_blank"&gt;@CiscoSecurity&lt;/a&gt; Cisco SIO: Preparing for DNSSEC- Best Practices, Recommendations, Tips and Traps &lt;a href="http://bit.ly/nPltXg" target="_blank"&gt;bit.ly/nPltXg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@FSecure" target="_blank"&gt;@FSecure&lt;/a&gt; The dangers of online crime: Q&amp;amp;A with Mikko Hypponen &lt;a href="http://bit.ly/qwaf7q" target="_blank"&gt;bit.ly/qwaf7q&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SCADAhacker" target="_blank"&gt;@SCADAhacker&lt;/a&gt; October is Cyber Security Awareness Month: DHS Eval Tool - &lt;a href="http://bit.ly/qNLNJl" target="_blank"&gt;bit.ly/qNLNJl&lt;/a&gt; SH: Make your #ics community aware of your security policy.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@stefan_frei" target="_blank"&gt;@stefan_frei&lt;/a&gt; RT @dsancho66: Infographic: If You Get Hacked, What Do You Stand to Lose?: &lt;a href="http://bit.ly/oH5fwA" target="_blank"&gt;bit.ly/oH5fwA&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ibmxforce" target="_blank"&gt;@ibmxforce&lt;/a&gt; We just published our 2011 Mid-Year Trend and Risk Report: &lt;a href="http://ow.ly/6I66W" target="_blank"&gt;http://ow.ly/6I66W&lt;/a&gt; #security #ibm&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5894187850705953784?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5894187850705953784/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-1-ottobre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5894187850705953784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5894187850705953784'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/10/best-of-week-1-ottobre-2011.html' title='Best of the Week - 1 ottobre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3600908007632438240</id><published>2011-09-30T17:17:00.000+02:00</published><updated>2011-09-30T17:17:59.913+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='consigli di lettura'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Un consiglio di lettura: Ghost in the Wires</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GjOCK0adyY4/ToXZwjKZtwI/AAAAAAAAAS4/sH2FqxBs1J4/s1600/Ghost-in-the-Wires.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://1.bp.blogspot.com/-GjOCK0adyY4/ToXZwjKZtwI/AAAAAAAAAS4/sH2FqxBs1J4/s320/Ghost-in-the-Wires.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cosa non ti aspetteresti mai da un autore famoso per aver scritto un libro dal titolo "The Art of Deception"?&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La sincerità.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ebbene, la sensazione che ho avuto leggendo questo libro è che sia un libro sincero, al limite del candore in alcuni punti. E questa è una dote molto rara e apprezzata, almeno da me.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma veniamo ai motivi per i quali ho scelto di consigliare questo libro.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;1 E' un libro davvero godibilissimo, si legge come un romanzo e quasi si è tentati di dimenticare che la trama ci è nota. Si arriva fino al punto di sperare che Kevin non venga arrestato, che riesca a far perdere le proprie tracce...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;2 Fondamentalmente Kevin Mitnick ha deciso di mettersi a nudo in questa autobiografia che approfondisce diversi aspetti della sua personalità e del suo carattere. A questo proposito ho trovato molto interessante il rapporto che ha sviluppato nel tempo con le attività di hacking. Un rapporto quasi di dipendenza, tanto che scrive: "&lt;i&gt;Hacking was my entertainment. You could almost say it was a way of escaping to an alternate reality - like playnig a video game. But to play my of choice, you had to stay alert at all times. One lapse in attention or sloppy mistake, and the Feds could show up at your door. Not the simulated G-men, not the black wizards of Dungeons and Dragons, but the real, honest-to-God, lock-you-up-and-throw-away-the-key Feds.&lt;/i&gt;". Molto intrigante è anche la descrizione del rapporto che ha con la madre e la nonna e con le altre persone importanti della sua vita (la sua ex moglie Bonnie ad esempio), che riflette un affetto profondo e una condizione di dipendenza dovuta principalmente alla sua debolezza psicologica e materiale connessa alla sua condizione di ricercato o indagato. Infine mi ha colpito molto anche il suo rapporto con gli amici e i suoi compagni di avventura, descritti senza mai insistere troppo sui loro lati negativi e con una naturale propensione al perdono per tutti coloro che, così di frequente, lo hanno tradito o messo in difficoltà.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;3 La spiegazione delle sue motivazioni per l'hacking, così ben descritta, vale il libro. L'Hacking visto come ricerca, come sfida intellettuale spinta dalla pura sete di conoscenza e non da motivazioni normalmente più comprensibili, come il denaro o il potere. Questo atteggiamento mentale, che come ho detto in precedenza in alcuni punti sfiora il candore, è veramente molto interessante soprattutto in un momento storico come il nostro in cui il cyberspazio e&amp;nbsp;la società stessa&amp;nbsp;sono dominati da biechi interessi materiali. La sua sincerità nel sottolineare l'importanza del disinteresse verso i potenziali benefici materiali che avrebbe potuto ottenere mettendo "a frutto" le sue conquiste, è sottolineata anche dall'apprezzamento intellettuale che esprime verso figure che lo hanno affascinato (Poulsen e Shimomura ad esempio) a prescindere da ciò che è derivato dal loro rapporto con Kevin.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;4 Le sue "magie" sono sempre un valore aggiunto, mai banali, a volte al confine con l'arte per il loro senso estetico intrinseco.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma il libro mi è davvero piaciuto e l'ho divorato in pochi giorni.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Complimenti!!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3600908007632438240?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3600908007632438240/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/un-consiglio-di-lettura-ghost-in-wires.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3600908007632438240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3600908007632438240'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/un-consiglio-di-lettura-ghost-in-wires.html' title='Un consiglio di lettura: Ghost in the Wires'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-GjOCK0adyY4/ToXZwjKZtwI/AAAAAAAAAS4/sH2FqxBs1J4/s72-c/Ghost-in-the-Wires.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7716805024847918744</id><published>2011-09-26T15:43:00.001+02:00</published><updated>2011-09-26T15:43:48.557+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilità'/><category scheme='http://www.blogger.com/atom/ns#' term='strategia difensiva'/><category scheme='http://www.blogger.com/atom/ns#' term='BEAST'/><title type='text'>BEAST: un attacco contro SSL</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--ZR8q6g0-yU/ToB6DOuIYXI/AAAAAAAAASw/TUYliqJ1_S8/s1600/BEAST-attack-SSL.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/--ZR8q6g0-yU/ToB6DOuIYXI/AAAAAAAAASw/TUYliqJ1_S8/s320/BEAST-attack-SSL.jpg" width="254" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Durante una recente &lt;a href="http://ekoparty.org/index.php"&gt;conferenza&lt;/a&gt; sulla sicurezza che si è tenuta a Buenos Aires, è stata&amp;nbsp;&lt;a href="http://ekoparty.org/2011/juliano-rizzo.php"&gt;presentata una ricerca&lt;/a&gt;&amp;nbsp;portata avanti da&amp;nbsp;due ricercatori (Rizzo e Duong) su un'innovativa modalità di sfruttamento di una vulnerabilità negli algoritmi di cifratura utilizzati nei protocolli di sicurezza SSL e TLS 1.0.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Allora vediamo un po' di capirci qualcosa...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Innanzitutto il nome BEAST è un acronimo per&amp;nbsp;Browser Exploit Against SSL/TLS.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Poi bisogna capire che, anche se come tutti sanno il protocollo SSL serve a proteggere le comunicazioni a valore aggiunto su Internet, questa ricerca non significa che da oggi non sia possibile effettuare collegamenti sicuri usando questi protocolli.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se volete avere un'idea di come funzioni l'attacco e di quali impatti ci siano potete fare riferimento agli ottimi contributi pubblicati sui blog di &lt;a href="http://paulsparrows.wordpress.com/2011/09/25/the-beauty-rc4-and-the-beast-tls/"&gt;Paul Sparrows&lt;/a&gt; o del &lt;a href="https://blog.torproject.org/blog/tor-and-beast-ssl-attack"&gt;progetto TOR&lt;/a&gt;.&amp;nbsp;&amp;nbsp;Ciò che interessa di più a me invece è fare qualche piccola riflessione a margine di questa notizia.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Innanzitutto è da notare come siano sempre più frequenti le notizie che mettono in evidenza come Internet sia stato concepito per assolvere a dei compiti molto diversi da quelli che abbiamo via via costruito e che soprattutto l'"ambiente" sia diventato molto diverso da quello iniziale. E' infatti utile ricordare che Internet è nato per collegare istituti di ricerca e governativi in un contesto in cui la banda e le capacità elaborative erano assolutamente scarsissime. Adesso, invece, abbiamo le cloud che forniscono capacità elaborative e di banda pressoché illimitate, siamo oltre 3 miliardi di utenti (di cui molti attraverso dispositivi mobili), facciamo "girare" fiumi di denaro e di business sulla rete e dobbiamo quotidianamente fare i conti con un sempre più incombente "dark side" (cybercrime, cyberwar e quant'altro).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per riuscire a transitare dal contesto iniziale allo scenario attuale sono stati sviluppati nuovi "pezzi" (autenticazione forte, cifratura, solo per citarne alcuni) e sono state sviluppate "pezze" per alcuni elementi chiave (IPv6, DNSSEC, ecc.).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ciò che sta succedendo sembra però indicare che le "debolezze strutturali" siano tali da richiedere un approccio innovativo che riparta proprio dalle fondamenta di Internet e che fornisca un "ambiente" qualitativamente e quantitativamente adeguato agli usi odierni della rete.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Un sogno? Forse, però pensare di riuscire a garantire lo sviluppo della società moderna per il tramite di mezzi tecnologici che con cadenza quotidiana mostrano la loro inadeguatezza è un azzardo che, a mio parere, non si può ulteriormente scegliere di correre.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7716805024847918744?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7716805024847918744/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/beast-un-attacco-contro-ssl.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7716805024847918744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7716805024847918744'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/beast-un-attacco-contro-ssl.html' title='BEAST: un attacco contro SSL'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/--ZR8q6g0-yU/ToB6DOuIYXI/AAAAAAAAASw/TUYliqJ1_S8/s72-c/BEAST-attack-SSL.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2736755092403608706</id><published>2011-09-25T10:35:00.000+02:00</published><updated>2011-09-25T10:47:41.425+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 25 settembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Did you miss some security news? Here's&amp;nbsp;the list of my favourite security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@cyberwar" target="_blank"&gt;@cyberwar&lt;/a&gt; Voice of Russia: Russia seeks equal cybersecurity for all &lt;a href="http://english.ruvr.ru/2011/09/23/56634644.html" target="_blank"&gt;http://english.ruvr.ru/2011/09/23/56634644.html&lt;/a&gt; &amp;lt;===Ya think? Really?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SecurityWeek" target="_blank"&gt;@SecurityWeek&lt;/a&gt; If You Missed It &amp;gt; The Evolution of Malware &lt;a href="http://bit.ly/oN09jY" target="_blank"&gt;http://bit.ly/oN09jY&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@quasidot" target="_blank"&gt;@quasidot&lt;/a&gt; 5 secrets to building a great security team - Computerworld &lt;a href="http://tumblr.com/x8d4sndumu" target="_blank"&gt;http://tumblr.com/x8d4sndumu&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; Position Paper: Why are there so many vulnerabilities in web applications? (pdf) &lt;a href="http://bit.ly/qwEdXu" target="_blank"&gt;http://bit.ly/qwEdXu&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; On-line tools to test your DNS setup &lt;a href="http://bit.ly/oNpoX7" target="_blank"&gt;http://bit.ly/oNpoX7&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mtrojnar" target="_blank"&gt;@mtrojnar&lt;/a&gt; OWADE is an interesting tool to decrypt data encrypted with Syskey/DPAPI: &lt;a href="http://t.co/ixpjMers" target="_blank"&gt;http://t.co/ixpjMers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2736755092403608706?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2736755092403608706/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-25-settembre-2011.html#comment-form' title='1 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2736755092403608706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2736755092403608706'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-25-settembre-2011.html' title='Best of the Week - 25 settembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2670085713235002753</id><published>2011-09-22T11:47:00.001+02:00</published><updated>2011-09-22T14:06:13.108+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='Diginotar'/><title type='text'>MUMBLE - Il fallimento di Diginotar cambierà Internet?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GI9mjL7R4es/Tnrpq-pQz9I/AAAAAAAAASo/mc99cu1DHjY/s1600/Diginotar-bankruptcy.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="173" src="http://2.bp.blogspot.com/-GI9mjL7R4es/Tnrpq-pQz9I/AAAAAAAAASo/mc99cu1DHjY/s320/Diginotar-bankruptcy.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La notizia è grossa, Diginotar, la certification authority olandese &lt;a href="http://www.matteocavallini.com/2011/09/diginotar-un-nuovo-passo-verso-la.html"&gt;attaccata&lt;/a&gt; a fine estate, &lt;a href="http://www.vasco.com/company/press_room/news_archive/2011/news_vasco_announces_bankruptcy_filing_by_diginotar_bv.aspx"&gt;ha dichiarato fallimento&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Anzi l'ha fatto Vasco, la società che recentemente aveva comprato Diginotar per cercare di estendere il proprio mercato e le proprie potenzialità nel campo dei sistemi di autenticazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questa notizia mi ha fatto sorgere molti pensieri e quindi ho deciso di condividerne alcuni con voi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Innanzitutto mi viene in mente un&amp;nbsp;vecchio proverbio che si adatta bene alla situazione attuale:&amp;nbsp;"&lt;b&gt;Tanto tuonò che piovve&lt;/b&gt;".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infatti, dopo un lungo periodo in cui si sono susseguiti attacchi &amp;nbsp;sempre più eclatanti a vari soggetti, civili e militari, si è giunti al punto che la vittima di un attacco ha dovuto fronteggiare una situazione talmente grave da trovarsi nell'impossibilità di proseguire il proprio business.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E tutto questo potrebbe portare alla...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Sindrome da paese pericoloso&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Sul sito del Dipartimento di Stato americano c'è una sezione dedicata alla &lt;a href="http://travel.state.gov/travel/cis_pa_tw/tw/tw_1764.html"&gt;lista dei paesi considerati pericolosi &lt;/a&gt;nei quali si sconsiglia di viaggiare. Ecco ciò che viene detto a proposito dei criteri per la composizione di questa lista: "Il Dipartimento di Stato è portato a raccomandare ai cittadini americani di evitare o di considerare il rischio di un viaggio quando in un paese si riscontrano condizioni&amp;nbsp;protratte e&amp;nbsp;a lungo termine che rendono un paese pericoloso o instabile" (la traduzione è un po' libera ma altrimenti era complicato rendere il concetto).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se Internet fosse un paese fisico, cosa ne direbbe il Dipartimento di Stato americano ora che oltretutto c'è anche scappato il "morto"? Sono sicuro che la lista verrebbe aggiornata così:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-2QERSWI0Y4Q/TnrvrnnEcBI/AAAAAAAAASs/8Jnyql1kN2w/s1600/Current-travel-warnings.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://3.bp.blogspot.com/-2QERSWI0Y4Q/TnrvrnnEcBI/AAAAAAAAASs/8Jnyql1kN2w/s320/Current-travel-warnings.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E in un paese pericoloso cosa succede? Crollano gli investimenti, i traffici di beni e persone tendono a rallentare e soprattutto gli altri paesi si cautelano facendo due cose:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- avvisano i propri cittadini di stare alla larga&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- predispongono delle cosiddette "Unità di crisi" che possano aiutare chi si trova nei guai.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E chi nonostante tutto si trova a dover viaggiare in quei posti cosa fa?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- stipula una polizza che lo copra da tutti i possibili rischi&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- si fa accompagnare da una scorta armata&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- cerca (direttamente o indirettamente) di ottenere dei salvacondotti&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se ci pensate è proprio quello che sta avvenendo su Internet, la maggior parte degli Stati (noi purtroppo facciamo parte della minoranza) hanno avviato programmi di "awareness" nei confronti dei cittadini e si è dotata di CERT nazionali in grado di fronteggiare le emergenze. I privati invece stanno cercando di trasferire parte dei rischi &lt;a href="http://www.lloyds.com/News-and-Insight/News-and-Features/Market-news/Industry-News-2011/Rising-claims-reflect-cyber-concerns-of-multi-nationals"&gt;stipulando sempre più polizze assicurative&lt;/a&gt; e cercano soluzioni di sicurezza che li mettano almeno parzialmente al riparo dagli attacchi. Per quanto riguarda infine la ricerca di salvacondotti non posso citare casi specifici ma la situazione che si sta creando, ormai da tempo, è simile al pagamento del "pizzo", la formazione di accordi con gruppi malavitosi al fine di evitare spiacevoli "incidenti".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dato che su Internet quasi tutto si basa sulla fiducia, i tempi non sono certo brillanti.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2670085713235002753?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2670085713235002753/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/mumble-il-fallimento-di-diginotar.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2670085713235002753'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2670085713235002753'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/mumble-il-fallimento-di-diginotar.html' title='MUMBLE - Il fallimento di Diginotar cambierà Internet?'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-GI9mjL7R4es/Tnrpq-pQz9I/AAAAAAAAASo/mc99cu1DHjY/s72-c/Diginotar-bankruptcy.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2590379737773115695</id><published>2011-09-18T10:03:00.000+02:00</published><updated>2011-09-18T10:03:51.890+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 18 settembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here is my new list of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@chagall12" target="_blank"&gt;@chagall12&lt;/a&gt; Privacy day &lt;a href="http://on.fb.me/mYJYO2" target="_blank"&gt;on.fb.me/mYJYO2&lt;/a&gt; #privacy&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@eEye" target="_blank"&gt;@eEye&lt;/a&gt; U.S., AUS to add cyber realm to defense pact &lt;a href="http://dlvr.it/ldk8L" target="_blank"&gt;dlvr.it/ldk8L&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RSAConference" target="_blank"&gt;@RSAConference&lt;/a&gt; RT &lt;a href="http://twitter.com/@PwC_LLP" target="_blank"&gt;@PwC_LLP&lt;/a&gt; 43% of companies think they have an effective #info security strategy in place but few are security leaders &lt;a href="http://pwc.to/q0zVpH" target="_blank"&gt;pwc.to/q0zVpH&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@cloudsa" target="_blank"&gt;@cloudsa&lt;/a&gt; Seeking Safety in Clouds: CSA's Jim Reavis in the WSJ on benefits of cloud for SMBs &lt;a href="http://me.lt/5g2se" target="_blank"&gt;http://me.lt/5g2se&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SecMash" target="_blank"&gt;@SecMash&lt;/a&gt; 10 Things CIOs Don't Know About Cyber Security - CIO Insight &lt;a href="http://dlvr.it/lCbTS" target="_blank"&gt;dlvr.it/lCbTS&lt;/a&gt; #InfoSec&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@HP_AppSecurity" target="_blank"&gt;@HP_AppSecurity&lt;/a&gt; Are your web apps vulnerable? New risks report is an #EnterpriseSecurity must-read. &lt;a href="http://bit.ly/p0g8Jm" target="_blank"&gt;bit.ly/p0g8Jm&lt;/a&gt; #infosec #HP&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2590379737773115695?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2590379737773115695/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-18-settembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2590379737773115695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2590379737773115695'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-18-settembre-2011.html' title='Best of the Week - 18 settembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1606601640735015260</id><published>2011-09-11T12:19:00.001+02:00</published><updated>2011-09-11T12:20:00.909+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 11 settembre 2011</title><content type='html'>&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Today it's a very special day, it's the tenth anniversary of the 9/11. My thoughts are for that tragedy and for all the people that lost their lives that day. I have been struck &lt;a href="http://www.nytimes.com/interactive/us/sept-11-reckoning/comments-the-decade.html" target="_blank"&gt;by a comment&lt;/a&gt; on the New York Times: "The #1 lesson was that our government failed; their #1 job is to protect us".&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;My hope (and my work) is that this comment will never be written after a cyber attack.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It's now the time to list the best security resources of the week.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope you enjoy it.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; Did The September 11th Attacks Blind Us To A Digital Pearl Harbor? &lt;a href="http://flpbd.it/kgaw" target="_blank"&gt;flpbd.it/kgaw&lt;/a&gt; &amp;lt; good piece by &lt;a href="http://twitter.com/@threatpost" target="_blank"&gt;@threatpost&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://twitter.com/@teamcymru" target="_blank"&gt;@teamcymru&lt;/a&gt; UK newspaper interview with Turkish Turkguvenligi high profile DNS #hackers &lt;a href="http://bit.ly/pjOsdi" target="_blank"&gt;bit.ly/pjOsdi&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://twitter.com/@danchodanchev" target="_blank"&gt;@danchodanchev&lt;/a&gt; Reading: Hacktivism: a Theoretical and Empirical Exploration of China’s Cyber Warriors - &lt;a href="http://bit.ly/oJ6tyn" target="_blank"&gt;bit.ly/oJ6tyn&lt;/a&gt; [pdf] #cyberwar #China&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; Cybercrime Attribution: An Eastern European Case Study &lt;a href="http://bit.ly/onmcRh" target="_blank"&gt;bit.ly/onmcRh&lt;/a&gt; Russian Hacking News &lt;a href="http://linkd.in/kHEVhx" target="_blank"&gt;linkd.in/kHEVhx&lt;/a&gt; #hacking #russia&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a _blank""="" href="http://twitter.com/@paulsparrows%20target="&gt;@paulsparrows&lt;/a&gt; The latest cyberattacks reinforce the need to adopt #DNSSEC &lt;a href="http://bit.ly/otdq1V" target="_blank"&gt;bit.ly/otdq1V&lt;/a&gt; #Infosec #Security&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://twitter.com/@cyberwar" target="_blank"&gt;@cyberwar&lt;/a&gt; Ross Anderson on UK cyber spend. Too much offense, not enough defense.&amp;nbsp;&lt;a href="http://t.co/vTO73up" target="_blank"&gt;http://t.co/vTO73up&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1606601640735015260?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1606601640735015260/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-11-settembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1606601640735015260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1606601640735015260'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-11-settembre-2011.html' title='Best of the Week - 11 settembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3947390939022861249</id><published>2011-09-05T16:56:00.002+02:00</published><updated>2011-09-05T17:58:35.680+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Diginotar'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber War'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><title type='text'>Diginotar: un nuovo passo verso la cyberwar</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Uk5ELpEKiW0/TmTgfMtFlfI/AAAAAAAAASg/Nh8ViKPCEM8/s1600/Bomba.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Uk5ELpEKiW0/TmTgfMtFlfI/AAAAAAAAASg/Nh8ViKPCEM8/s1600/Bomba.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Un po' forte come titolo ma vediamo quali sono le ragioni che mi portano a questa riflessione.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Prima di tutto il punto della situazione. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nei giorni scorsi si è scoperto che una certification authority olandese, Diginotar, era stata "bucata" e che era stato prodotto almeno un&amp;nbsp; certificato falso intestato a Google.com. Poi, pian piano, sono emersi altri particolari e si è capito che i certifcati erano senz'altro più di uno. Microsoft ha rilasciato un bolletino speciale e ha ritirato Diginotar dalla lista dei certificatori presenti in IE. Stessa cosa hanno fatto Google con Chrome e Mozilla con Firefox (aggiungendo che&amp;nbsp; Diginotar era bandita per sempre dai loro browser) ma non ancora, incredibilmente,&amp;nbsp;Apple con Safari.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ieri si è avuta la &lt;a href="https://blog.torproject.org/blog/diginotar-damage-disclosure"&gt;lista completa&lt;/a&gt; dei certificati falsi generati con l'utilizzo di della CA Diginotar. Leggendola vengono i brividi...&amp;nbsp;una&amp;nbsp;lista di oltre 530 certificati&amp;nbsp;falsi&amp;nbsp;che comprende di tutto: Facebook, Google, Microsoft, Yahoo!, Tor, Skype, Mossad, CIA, MI6, LogMeIn, Twitter, Mozilla, AOL&amp;nbsp;e WordPress,&amp;nbsp;solo per citarne alcuni dei più importanti.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Un disastro. Tanto che si è mosso addirittura&amp;nbsp;il ministro olandese degli interni con una conferenza stampa&amp;nbsp;in cui&amp;nbsp;ha annunciato la revoca ufficiale della fiducia&amp;nbsp;verso Diginotar come CA governativa.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infatti, una delle due linee di servizi di Diginotar ("PKIoverheid") era focalizzata sui servizi di e-gov&amp;nbsp;e le evidenze hanno mostrato che non si poteva più ritenere ancora affidabile questa CA.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ieri sera quindi&amp;nbsp;un &lt;a href="http://www.securelist.com/en/blog/208193111/Why_Diginotar_may_turn_out_more_important_than_Stuxnet"&gt;interessantissimo post&lt;/a&gt; di Securelist metteva in evidenza&amp;nbsp;questo episodio&amp;nbsp;come&amp;nbsp;più importante e grave di quanto&amp;nbsp;non sia stato Stuxnet.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma perchè tutto questo clamore? Fondamentalmente perchè con questi certificati si possono effettuare attacchi del tipo "man in the middle" e ingannare gli utenti facendoli collegare a finti siti o intercettandone le comunicazioni&amp;nbsp;senza che ne abbiano alcun sentore. Data la lista dei certificati falsi, che includono social network, software house e&amp;nbsp;varie agenzie di intelligence la cosa diventa oltremodo preoccupante.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Oggi, dopo una serie di speculazioni, è arrivata una &lt;a href="http://blog.trendmicro.com/diginotar-iranians-the-real-target/"&gt;presa di posizione ufficiale&lt;/a&gt; di Trend Micro che, tramite l'analisi della propria rete di sensori, è arrivata a stabilire&amp;nbsp;che il fine di questo attacco sia il monitoraggio delle attività Internet&amp;nbsp;dei cittadini iraniani&amp;nbsp;aggirando i sistemi&amp;nbsp;anticensura che permettono ai dissidenti di collegarsi all'estero con relativa sicurezza.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tenendo presente che i certificati falsi, oltre a consentire di ingannare i browser, potevano anche consentire di installare software malevolo&amp;nbsp;con firme digitali apparentemente validate, il livello di attenzione per questo attacco è veramente altissimo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ecco perchè,&amp;nbsp;dopo Stuxnet e la dimostrazione patente che&amp;nbsp;con un codice informatico si poteva mettere fuori uso una infrastruttura&amp;nbsp;critica altrimenti&amp;nbsp;difficilmente attaccabile, questo nuovo attacco dimostra come sia possibile compromettere la sicurezza delle comunicazioni e degli approcci di e-gov basati sui certificati digitali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Speriamo che questa rapida scalata verso le dimostrazioni di fattibilità degli&amp;nbsp;attacchi militari&amp;nbsp;nel cyber spazio&amp;nbsp;abbia una pausa che permetta a chi di dovere di studiare il modo di gestire queste situazioni senza&amp;nbsp;sfociare in un vero e proprio conflitto&amp;nbsp;armato.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3947390939022861249?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3947390939022861249/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/diginotar-un-nuovo-passo-verso-la.html#comment-form' title='4 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3947390939022861249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3947390939022861249'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/diginotar-un-nuovo-passo-verso-la.html' title='Diginotar: un nuovo passo verso la cyberwar'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Uk5ELpEKiW0/TmTgfMtFlfI/AAAAAAAAASg/Nh8ViKPCEM8/s72-c/Bomba.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5433442309768259508</id><published>2011-09-04T10:20:00.000+02:00</published><updated>2011-09-04T10:20:29.982+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 4 settembre 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here we are at the usual publication of the "Best of the week" post. My personal list of the best security resources of the week is at your disposal.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@Shadowserver" target="_blank"&gt;@Shadowserver&lt;/a&gt; Shadowserver releases new AV Test Suite Results: &lt;a href="http://bit.ly/nbA3Az" target="_blank"&gt;http://bit.ly/nbA3Az&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@Raj_SamaniRaj" target="_blank"&gt;@Raj_SamaniRaj&lt;/a&gt; Neelie Kroes, #cloud computing needs trust and security in the system for the technology to flourish: &lt;a href="http://bit.ly/oSlHB9" target="_blank"&gt;http://bit.ly/oSlHB9&lt;/a&gt; #CAMM&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@INFOSECSchool" target="_blank"&gt;@INFOSECSchool&lt;/a&gt; Vivek Kundra Makes the Case for Government Cloud @InfosecIsland &lt;a href="http://goo.gl/DeYbZ" target="_blank"&gt;http://goo.gl/DeYbZ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@DarkReading" target="_blank"&gt;@DarkReading&lt;/a&gt; 1/3 of security pros aren't practicing what they preach &amp;amp; most not making changes in light of hi-profile attacks: &lt;a href="http://tinyurl.com/3fkdta9" target="_blank"&gt;http://tinyurl.com/3fkdta9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@BrianHonan" target="_blank"&gt;@BrianHonan&lt;/a&gt; France Introduces Data Security Breach Notification Requirement for Electronic Communication Service Providers &lt;a href="http://bit.ly/rihfWk" target="_blank"&gt;http://bit.ly/rihfWk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.twitter.com/@SecurityTube" target="_blank"&gt;@SecurityTube&lt;/a&gt; [Video] How to not get hired for a security job &lt;a href="http://securitytube.net/video/2156" target="_blank"&gt;http://securitytube.net/video/2156&lt;/a&gt; by J4vv4D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5433442309768259508?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5433442309768259508/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-4-settembre-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5433442309768259508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5433442309768259508'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/09/best-of-week-4-settembre-2011.html' title='Best of the week - 4 settembre 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-6368362621757394764</id><published>2011-08-30T15:30:00.000+02:00</published><updated>2011-08-30T15:30:22.437+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='PDF-X-RAY'/><category scheme='http://www.blogger.com/atom/ns#' term='adobe'/><title type='text'>PDF X-RAY: un utile strumento per la sicurezza</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6RLbcLGKQ50/Tlzcz7ODN0I/AAAAAAAAASc/9Ri5lyKpdUM/s1600/PDF-X-RAY.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://2.bp.blogspot.com/-6RLbcLGKQ50/Tlzcz7ODN0I/AAAAAAAAASc/9Ri5lyKpdUM/s320/PDF-X-RAY.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ho pensato molto al modo migliore per riprendere la pubblicazione dei post dopo la pausa estiva e, alla fine, ho deciso che avrei ricominciato con una buona notizia... compito arduo di questi tempi!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Alla fine ho deciso di parlare di &lt;a href="http://www.pdfxray.com/"&gt;PDF X-RAY&lt;/a&gt;, uno strumento rilasciato ad inizio ad agosto in concomitanza del BlackHat e del DEFCON; il momento migliore &lt;a href="http://blog.9bplus.com/pdf-x-ray-is-open"&gt;a detta&lt;/a&gt;&amp;nbsp;di&amp;nbsp;&lt;a href="http://www.linkedin.com/in/brandonsdixon"&gt;Brandon Dixon&lt;/a&gt;, autore del tool.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma veniamo al sodo, cos'è PDF X-RAY?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E' uno strumento molto efficace e di semplice utilizzo per aiutare a determinare se un file PDF sia o meno vettore di un possibile attacco. PDF X-RAY, in combinazione con altri strumenti quali gli strumenti di analisi che ognuno di noi ha sul proprio computer o con altre risorse disponibili in rete (come ad esempio &lt;a href="http://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt;)&amp;nbsp;può condurre all'effettuazione di analisi molto affidabili.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'utilizzo è veramente molto semplice, si procede con il caricamento del file sospetto attraverso un'interfaccia Web (sono disponibili anche delle API) e quindi si ottiene un report davvero molto completo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il PDF inviato viene infatti ad essere confrontato con migliaia di altri PDF noti per contenere malware cercandone eventuali affinità. Viene inoltre svolta un'approfondita analisi degli eventuali oggetti contenuti all'interno del file evidenziandone la natura, la dimensione e il potenziale sfruttamento di vulnerabilità note.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Sulla destra del report viene proposta un'immagine della prima pagina del file che, spesso, può essere di aiuto nella determinazione della natura malevola del file (e qui un piccolo appunto devo però farlo... nel database dei report, pubblicamente consultabile, è contenuta anche questa informazione. Quindi, se fate l'upload di un documento legittimo aspettatevi che la prima pagina diventi automaticamente pubblica con tutte le possibili implicazioni del caso. Per questioni di privacy, si potrebbe limitare la pubblicazione dell'immagine ai soli PDF individuati come malevoli).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine è possibile generare un report molto completo che consente di effettuare molti tipi di "drill-down" sui dati generati.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se a questo punto siete diventati curiosi e volete avere altre informazioni, potete andare sulla &lt;a href="http://www.pdfxray.com/"&gt;home&lt;/a&gt; del sito dedicato dove è pubblicato un video esplicativo molto chiaro.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma, un'ottima idea che ha dato vita ad un bello strumento di analisi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Complimenti!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-6368362621757394764?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/6368362621757394764/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/08/pdf-x-ray-un-utile-strumento-per-la.html#comment-form' title='1 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6368362621757394764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6368362621757394764'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/08/pdf-x-ray-un-utile-strumento-per-la.html' title='PDF X-RAY: un utile strumento per la sicurezza'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6RLbcLGKQ50/Tlzcz7ODN0I/AAAAAAAAASc/9Ri5lyKpdUM/s72-c/PDF-X-RAY.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5801886198666166917</id><published>2011-08-28T10:47:00.000+02:00</published><updated>2011-08-28T10:47:17.036+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 28 agosto 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;My summer vacations are ending, so next week the blog publication will start again at usual rate. Also the "Voci Amiche" blog posts will resume in September with an important contribution by a very well known security expert.&lt;br /&gt;&lt;br /&gt;But, at the moment, it's time for the list of best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@cyberwar" target="_blank"&gt;@cyberwar&lt;/a&gt; The Next New Cyberdefense Strategy: Monitor Everything - Laura Mather &lt;a href="http://twitter.com/@SilverTailSyst" target="_blank"&gt;@SilverTailSyst&lt;/a&gt; &lt;a href="http://t.co/R9ouJUC" target="_blank"&gt;http://t.co/R9ouJUC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@josephmenn" target="_blank"&gt;@josephmenn&lt;/a&gt; -- &lt;a href="http://twitter.com/@MishaGlenny" target="_blank"&gt;@MishaGlenny&lt;/a&gt; recommends 5 #cybersecurity books via &lt;a href="http://twitter.com/@TheBrowser" target="_blank"&gt;@TheBrowser&lt;/a&gt;, including Fatal System Error: &lt;a href="http://bit.ly/r1z0PY" target="_blank"&gt;bit.ly/r1z0PY&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@marcomorana" target="_blank"&gt;@marcomorana&lt;/a&gt; OWASP Application Security Guide For CISO, updated &lt;a href="http://tinyurl.com/43xhskr" target="_blank"&gt;tinyurl.com/43xhskr&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; When botnets try to break in, do you know which doors should be locked? &lt;a href="http://bit.ly/oqTxuN" target="_blank"&gt;bit.ly/oqTxuN&lt;/a&gt; #botnet #infosec #malware&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RiaHyman" target="_blank"&gt;@RiaHyman&lt;/a&gt; RT &lt;a href="http://twitter.com/@ibmcloud" target="_blank"&gt;@ibmcloud&lt;/a&gt;: Crafting a #cloud security policy &lt;a href="http://ibm.co/qe0M2O" target="_blank"&gt;ibm.co/qe0M2O&lt;/a&gt; #IBMcloud&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/Bruce_Schneier" target="_blank"&gt;@Bruce_Schneier&lt;/a&gt; How Microsoft Develops Security Patches &lt;a href="http://to.ly/aZMv" target="_blank"&gt;http://to.ly/aZMv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/stefan_frei" target="_blank"&gt;@stefan_frei&lt;/a&gt; Aus DOD: "Strategies to Mitigate Cyber Intrusions": Top 4 strategies would have prevented 85% of intrusions in 2010 &lt;a href="http://bit.ly/r0nUGa" target="_blank"&gt;bit.ly/r0nUGa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5801886198666166917?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5801886198666166917/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-28-agosto-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5801886198666166917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5801886198666166917'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-28-agosto-2011.html' title='Best of the week - 28 agosto 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7967538142245735912</id><published>2011-08-21T14:43:00.000+02:00</published><updated>2011-08-21T14:43:11.843+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 21 Agosto 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;In this hot Italian summer, here are some refreshing security resources... my "Best of the week" listing!&lt;br /&gt;&lt;br /&gt;Hope you enjoy it!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; Sailing the Sea of OSINT in the Information Age (Studies in Intelligence) &lt;a href="http://t.co/ZYoGt7Q" target="_blank"&gt;1.usa.gov/cweng6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt;&amp;nbsp;Who Should Handle Serious Internal Investigations? (Infosec Island) &lt;a href="http://bit.ly/olKLzO" target="_blank"&gt;bit.ly/olKLzO&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ibmxforce" target="_blank"&gt;@ibmxforce&lt;/a&gt; New #ibmxforce blog: Our Presentation on Secure Open Wireless Networking &lt;a href="http://bit.ly/rscCBr" target="_blank"&gt;bit.ly/rscCBr&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@HenkvanRoest" target="_blank"&gt;@HenkvanRoest&lt;/a&gt; Samsung Hires Android Hacker, Steve "Cyanogen" Kondick &lt;a href="http://bit.ly/rnrwWa" target="_blank"&gt;bit.ly/rnrwWa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@markrussinovich" target="_blank"&gt;@markrussinovich&lt;/a&gt; More scary cybersecurity news: GAO finds that FDIC cybersecurity is lacking. Wonder what other departments look like. &lt;a href="http://bit.ly/nMURSb" target="_blank"&gt;bit.ly/nMURSb&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@paulcsfi" target="_blank"&gt;@paulcsfi&lt;/a&gt; Alarm Sounded as Cyber Attacks on U.S. Defense Base Multiply &lt;a href="http://lnkd.in/_gVxTc" target="_blank"&gt;lnkd.in/_gVxTc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7967538142245735912?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7967538142245735912/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-21-agosto-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7967538142245735912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7967538142245735912'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-21-agosto-2011.html' title='Best of the Week - 21 Agosto 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-2545017766626985591</id><published>2011-08-14T16:38:00.000+02:00</published><updated>2011-08-14T16:38:32.099+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 14 agosto 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It's August and it's time for vacation... but for me a Sunday is not a Sunday &amp;nbsp;without my listing of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@0xcharlie" target="_blank"&gt;@0xcharlie&lt;/a&gt; One of my kids not practicing good password security. Like father like son.&amp;nbsp;&lt;a href="http://t.co/Ald4eDe" target="_blank"&gt;http://t.co/Ald4eDe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; NIST Computer Security Division: Special Publications &lt;a href="http://1.usa.gov/8Lc6GL" target="_blank"&gt;http://1.usa.gov/8Lc6GL&lt;/a&gt;&amp;nbsp;SANS Information Security Reading Room &lt;a href="http://bit.ly/aePxP" target="_blank"&gt;http://bit.ly/aePxP&lt;/a&gt; Checklists and Step-by-Step Guides &lt;a href="http://bit.ly/or4p0Q" target="_blank"&gt;http://bit.ly/or4p0Q&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@xme" target="_blank"&gt;@xme&lt;/a&gt; Don't forget your MS patches! "IE, Windows server bugs likely to be exploited soon" (source: &lt;a href="http://bit.ly/opMknk" target="_blank"&gt;http://bit.ly/opMknk&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; Man-In-The-Middle Attacks &lt;a href="http://flpbd.it/N34" target="_blank"&gt;http://flpbd.it/N34&lt;/a&gt;Z &amp;lt; great overview..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@pauldotcom" target="_blank"&gt;@pauldotcom&lt;/a&gt; Top 10 Things I Learned at #Blackhat 2011 #Defcon 19 &amp;amp; Ten Reasons You Know You've Been In Vegas Too Long &lt;a href="http://bit.ly/rfm5bY" target="_blank"&gt;http://bit.ly/rfm5bY&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RonGula" target="_blank"&gt;@RonGula&lt;/a&gt; More Cyber-War Rhetoric from Marcus Ranum via IANS : &lt;a href="http://bit.ly/rracx2" target="_blank"&gt;http://bit.ly/rracx2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-2545017766626985591?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/2545017766626985591/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-14-agosto-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2545017766626985591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/2545017766626985591'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-14-agosto-2011.html' title='Best of the week - 14 agosto 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5253235609115710322</id><published>2011-08-07T12:04:00.000+02:00</published><updated>2011-08-07T12:04:58.547+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 7 agosto 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here is my weekly listing of the best security resources.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikkohypponen" target="_blank"&gt;@mikkohypponen&lt;/a&gt; Fake Flash player malware for Mac OS X changes your Google search results on the fly: &lt;a href="http://bit.ly/pd4S2Q" target="_blank"&gt;http://bit.ly/pd4S2Q&lt;/a&gt; from F-Secure blog&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@markrussinovich" target="_blank"&gt;@markrussinovich&lt;/a&gt; This is leadership? US cybersecurity is a revolving door of exiting officials &lt;a href="http://t.co/V0LgAk3" target="_blank"&gt;http://t.co/V0LgAk3&lt;/a&gt; via &lt;a href="http://twitter.com/@BetaNews" target="_blank"&gt;@BetaNews&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@helpnetsecurity" target="_blank"&gt;@helpnetsecurity&lt;/a&gt; Testing the cloud -&amp;nbsp;&lt;a href="http://bit.ly/pYAyZH" target="_blank"&gt;http://bit.ly/pYAyZH&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@JANETCSIRT" target="_blank"&gt;@JANETCSIRT&lt;/a&gt; Using Google as a security incident detector&lt;a href="http://bit.ly/rgvEtj" target="_blank"&gt;http://bit.ly/rgvEtj&lt;/a&gt; harness the search power of Google to identify security breaches -- A very interesting approach!!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SecMash" target="_blank"&gt;@SecMash&lt;/a&gt; Study: Cybercrime costs on the rise from last year &lt;a href="http://dlvr.it/dZrqt" target="_blank"&gt;http://dlvr.it/dZrqt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@McAfeeNews" target="_blank"&gt;@McAfeeNews&lt;/a&gt; Blog: Revealed: Operation Shady RAT: Download the PDF version of Operation Shady RAT report For the last few yea... &lt;a href="http://bit.ly/qOCSGP" target="_blank"&gt;http://bit.ly/qOCSGP&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5253235609115710322?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5253235609115710322/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-7-agosto-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5253235609115710322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5253235609115710322'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/08/best-of-week-7-agosto-2011.html' title='Best of the week - 7 agosto 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4936098799812702323</id><published>2011-07-31T10:24:00.001+02:00</published><updated>2011-07-31T10:26:01.528+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 31 luglio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear:left; float:left;margin-right:1em; margin-bottom:1em"&gt;&lt;img border="0" height="172" width="170" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;It's Sunday morning and it's time for a new "Best of the week" post!&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@klightowler" target="_blank"&gt;@klightowler&lt;/a&gt;: FBI shares lessons of Zeus botnet ring takedown &lt;a href="http://bit.ly/qvDOlG" target="_blank"&gt;http://bit.ly/qvDOlG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ChetWisniewski" target="_blank"&gt;@ChetWisniewski&lt;/a&gt;: Obama outlines strategy to combat transnational cybercrime &lt;a href="http://bit.ly/pGJRoQ" target="_blank"&gt;http://bit.ly/pGJRoQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@regsecurity" target="_blank"&gt;@regsecurity&lt;/a&gt;: Crypto shocker: 'Perfect cipher' dates back to telegraphs &lt;a href="http://bit.ly/mYo2Lj" target="_blank"&gt;http://bit.ly/mYo2Lj&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@msftmmpc" target="_blank"&gt;@msftmmpc&lt;/a&gt;: Announcing the newest MMPC Research and Response Lab: &lt;a href="http://t.co/ORvb9YY" target="_blank"&gt;http://t.co/ORvb9YY&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Canaudit" target="_blank"&gt;@Canaudit&lt;/a&gt;: "The cost of cybercrime" - &lt;a href="http://t.co/HUv1o2Z" target="_blank"&gt;http://t.co/HUv1o2Z&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@0xcharlie" target="_blank"&gt;@0xcharlie&lt;/a&gt;: That italian song in the pwnies is pretty good!  &lt;a href="http://www.youtube.com/watch?v=aTwMZR1Vjg4" target="_blank"&gt;http://www.youtube.com/watch?v=aTwMZR1Vjg4&lt;/a&gt; (with subtitles)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@securityshell" target="_blank"&gt;@securityshell&lt;/a&gt;: Open Web Application Security Project: Application Security Tutorial Videos &lt;a href="http://t.co/5RFyMQu" target="_blank"&gt;http://t.co/5RFyMQu&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4936098799812702323?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4936098799812702323/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-31-luglio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4936098799812702323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4936098799812702323'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-31-luglio-2011.html' title='Best of the week - 31 luglio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3769545104561877591</id><published>2011-07-25T15:44:00.005+02:00</published><updated>2011-07-26T10:42:22.825+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CNAIPIC'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='Data breach'/><title type='text'>Hanno bucato il CNAIPIC</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-sFZJksbGM2E/Ti1zkSI3lEI/AAAAAAAAASY/JUjxVmFu_3I/s1600/anonymouSabu.jpg" imageanchor="1" style="clear: left; cssfloat: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="97" src="http://4.bp.blogspot.com/-sFZJksbGM2E/Ti1zkSI3lEI/AAAAAAAAASY/JUjxVmFu_3I/s320/anonymouSabu.jpg" t$="true" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Il primo tweet con cui è stata diffusa la notizia&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;﻿﻿﻿C'era da aspettarselo, era questione di tempo, prima o poi qualcuno avrebbe raccolto le minacce che da tempo circolavano contro il CNAIPIC (Centro Nazionale Anticrimine Informatico per la Protezione delle Infrastrutture Critiche). &lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La notizia è, nella sua essenza, abbastanza banale, il CNAIPIC, fiore all'occhiello della Polizia Postale Italiana, è stato bucato da hacker legati al movimento Anonymous e LulzSec e sono stati trafugati circa 8 GB di dati. Alcuni di questi file trafugati sono stati pubblicati su diversi siti e si può trovare anche un &lt;a href="http://pastebin.com/UZZpDGWE"&gt;comunicato "ufficiale"&lt;/a&gt; relativo a questa azione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Perchè dico che c'era da aspettarselo? Bhe, per prima cosa per "ritorsione", per gli arresti effettuati alcuni giorni fa; inoltre, nella chat di AnonItaly se ne parlava da tempo, legando l'ipotetico attacco alla commemorazione per il decennale&amp;nbsp;morte di Carlo Giuliani. Il secondo motivo l'ho illustrato qualche giorno fa in una riflessione intitolata "&lt;a href="http://www.matteocavallini.com/2011/07/mumble-san-sebastiano-e-la.html"&gt;MUMBLE - San Sebastiano e la cybersecurity&lt;/a&gt;", nella quale sostanzialmente sostengo che, in questo momento storico non c'è nessuno che possa sperare di essere al sicuro, perchè violare i sistemi non è mai stato così semplice. Infine sempre in una recente riflessione (&lt;a href="http://www.matteocavallini.com/2011/06/mumble-data-breach-ecco-perche-andra.html"&gt;MUMBLE - Data Breach ecco perché andrà sempre peggio&lt;/a&gt;) avevo individuato in alcuni fattori, tra cui la grande notorietà che si riserva a questi episodi,&amp;nbsp;la molla che spinge la situazione&amp;nbsp;verso un futuro sempre più preoccupante.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cosa succederà adesso?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Probabilmente dipende dalla strategia che adotteranno gli attaccanti. Se adotteranno una strategia "responsabile" (ma non sembra proprio che siano di quest'avviso) e non divulgheranno notizie riservate (come è stato fatto per il recente attacco alle infrastrutture informatiche della NATO) probabilmente dopo un po' di polverone le cose si acqueteranno. Altrimenti, ci sarà uno stillicidio di informazioni che terrà alta l'attenzione dei media per qualche giorno in più. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Almeno fino alla prossima notizia di questo genere.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Sul fronte dell'analisi degli eventi voglio solo far notare che, il &lt;a href="http://pastebin.com/r21cExeP"&gt;primo annuncio dell'attacco&lt;/a&gt; come si può vedere dalla figura ad inizio del post è stato dato attarverso l'account di "The Real Sabu" e cioè del supposto leader del gruppo LulzSec.&lt;br /&gt;&lt;br /&gt;C'è da pensare...&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3769545104561877591?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3769545104561877591/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/hanno-bucato-il-cnaipic.html#comment-form' title='5 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3769545104561877591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3769545104561877591'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/hanno-bucato-il-cnaipic.html' title='Hanno bucato il CNAIPIC'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-sFZJksbGM2E/Ti1zkSI3lEI/AAAAAAAAASY/JUjxVmFu_3I/s72-c/anonymouSabu.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7287035530657098851</id><published>2011-07-24T10:20:00.000+02:00</published><updated>2011-07-24T10:20:05.387+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 24 luglio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear:left; float:left;margin-right:1em; margin-bottom:1em"&gt;&lt;img border="0" height="172" width="170" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;It's Sunday morning and it's time for a new listing of the best security resources the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CommonAssurance" target="_blank"&gt;@CommonAssurance&lt;/a&gt;: Business Assurance for the 21st Century &lt;a href="http://ht.ly/5Glsi" target="_blank"&gt;http://ht.ly/5Glsi&lt;/a&gt; #CAMM&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@policeledintel" target="_blank"&gt;@policeledintel&lt;/a&gt;: OSINT, Search Tools &amp; Search Tip Roundup &lt;a href="http://wp.me/p1mWTe-gv" target="_blank"&gt;http://wp.me/p1mWTe-gv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@rsasecurity" target="_blank"&gt;@rsasecurity&lt;/a&gt;: Securing the Cloud: Cloud Computer Security Techniques and Tactics &lt;br /&gt;&lt;a href="http://rsa.im/mS7yZl" target="_blank"&gt;http://rsa.im/mS7yZl&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CiscoSecurity" target="_blank"&gt;@CiscoSecurity&lt;/a&gt;: Malicious PDF attack targets defense &lt;a href="http://t.co/R7HI2C2" target="_blank"&gt;http://t.co/R7HI2C2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Fortinet" target="_blank"&gt;@Fortinet&lt;/a&gt;: Check out Fortinet's newest whitepaper "“The Need for Secure Communications in a Distributed Environment” &lt;a href="http://t.co/pnOmRYZ" target="_blank"&gt;http://t.co/pnOmRYZ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@DarkReading" target="_blank"&gt;@DarkReading&lt;/a&gt;: How to respond to a distributed denial-of-service (DDoS) attack: &lt;a href="http://tinyurl.com/3jf2fel" target="_blank"&gt;http://tinyurl.com/3jf2fel&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7287035530657098851?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7287035530657098851/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-24-luglio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7287035530657098851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7287035530657098851'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-24-luglio-2011.html' title='Best of the week - 24 luglio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7195033366221481632</id><published>2011-07-22T15:27:00.004+02:00</published><updated>2011-10-09T15:24:17.671+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='attacchi'/><category scheme='http://www.blogger.com/atom/ns#' term='strategia difensiva'/><category scheme='http://www.blogger.com/atom/ns#' term='Guide di Sicurezza'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='US-CERT'/><title type='text'>Guide di sicurezza: evitare le intrusioni</title><content type='html'>&lt;div style="text-align: justify;"&gt;Il NIST tre giorni fa ha rilasciato una interessante&amp;nbsp;&lt;a href="http://www.us-cert.gov/cas/techalerts/TA11-200A.html" target="_blank"&gt;guida "tecnica"&lt;/a&gt;&amp;nbsp;sulle contromisure che devono essere adottate per cercare di ridurre la superficie d'attacco offerta a possibili intrusioni. Il valore aggiunto di questa guida è fondamentalmente nell'ufficialità della fonte (grazie &lt;a href="http://it.linkedin.com/in/domenicofumarola" target="_blank"&gt;Domenico&lt;/a&gt; per la riflessione); non ci sono infatti indicazioni "rivoluzionarie" o particolarmente profonde, sono tutte indicazioni di buon senso che chi si occupa di sicurezza conosce da tempo. Provate però a chiedervi quante di queste pur essendo pienamente condivisibili sono correttamente implementate nella vostra realtà...&lt;br /&gt;&lt;br /&gt;Ho quindi pensato che fosse importante riprendere i contenuti della guida, riorganizzarli per argomento, arricchirli di alcune informazioni aggiuntive, togliere alcune informazioni che considero un po' obsolete e soprattutto offrirli in italiano. Ovviamente questa iniziativa si inserisce nella serie delle "&lt;a href="http://www.matteocavallini.com/p/le-guide-di-sicurezza.html" target="_blank"&gt;Guide di Sicurezza&lt;/a&gt;" di Punto 1.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma veniamo ai contenuti, ecco cosa ci suggerisce lo US-CERT (ribadisco che i contenuti sono un po' rivisti e corretti, chi preferisce la guida originale può seguire il link proposto all'inizio del post)&lt;/div&gt;&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&lt;b&gt;Policy di sicurezza&lt;/b&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;- Emettere una "Acceptable Use Policy" che contenga elementi atti a limitare e regolamentare:&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- L'utilizzo di strumenti personali per l'accesso o l'elaborazione di dati&amp;nbsp;o sistemi &amp;nbsp;ufficiali (ad esempio, tele-lavoro o utilizzo di dispositivi personali in ufficio)&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - L'utilizzo di tutti i dispositivi rimovibili, salvo che non vi sia una ben documentata necessità aziendale (in questo caso devono essere emesse anche delle specifiche linee guida)&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- L'uso dei servizi di social networking&amp;nbsp;(Facebook, Twitter,&amp;nbsp;applicazioni di&amp;nbsp;instant messaging,&amp;nbsp;ecc, ed anche&amp;nbsp;la posta elettronica personale)&amp;nbsp;sul posto di lavoro, salvo che non vi sia una necessità aziendale formalmente individuata&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;-&amp;nbsp;Realizzare programmi di formazione degli utenti sull'Acceptable Use Policy e sui pericoli connessi all'uso della posta elettronica&amp;nbsp;e della navigazione Web&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;- Emettere policy per la sicurezza degli accessi che prevedano l'uso di:&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Sistemi di autenticazione forte per gli account con privilegi di root&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Password di almeno 15 caratteri per gli account amministratore&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Password di almeno 8 caratteri per gli utenti standard&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Password a complessità elevata con caratteri alfanumerici e simboli&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Strumenti che limitino il riutilizzo di password precedenti&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Strumenti che &amp;nbsp;limitino l'uso di informazioni personali come password&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Strumenti che richiedano il cambio password almeno ogni 60-90 giorni&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: justify;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Strumenti per la memorizzazione cifrata delle password&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Emettere una policy che preveda che in caso di compromissione di un account di amministratore si debba&amp;nbsp;&amp;nbsp;immediatamente&amp;nbsp;cambiare la password (da sistemi verificati e liberi da malware)&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;-&amp;nbsp;&lt;/b&gt;Adottare le best practice per la sicurezza delle reti (info su CERT-CC &lt;a href="http://www.cert.org/governance/" target="_blank"&gt;Governing for Enterprise Security&lt;/a&gt;)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Web Server e applicazioni Web&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Utilizzare un proxy applicativo (o meglio un Web Application Firewall) di fronte ai server web per filtrare le richieste dannose&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"&gt;- Assicurarsi che la configurazione "&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: 12px;"&gt;&lt;a href="http://it.php.net/manual/en/filesystem.configuration.php#ini.allow-url-fopen" target="_blank"&gt;allow URL_fopen&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;" sia disattivata per cercare di limitare gli attacchi di tipo "remote file inclusion"&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Limitare l'uso di codice SQL dinamico attraverso l'uso di "&lt;span class="Apple-style-span" style="font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;a href="http://sci138.sci.unich.it/amato/teaching/labdati10/lezioni/php-interazione/php-interazione.php" target="_blank"&gt;prepared statements&lt;/a&gt;"&lt;/span&gt;, query con parametri o stored procedure (info sugli attacchi di tipo SQL Injection sono disponibili sul sito dello &lt;a href="http://www.us-cert.gov/reading_room/sql200901.pdf" target="_blank"&gt;US-CERT&lt;/a&gt; o sul sito dell'&lt;a href="https://www.owasp.org/index.php/SQL_Injection" target="_blank"&gt;OWASP&lt;/a&gt;)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Seguire le best practice per la codifica sicura e validazione dell'input (info su &lt;a href="https://www.owasp.org/index.php/Top_10_2010" target="_blank"&gt;OWASP Top 10&lt;/a&gt; &amp;nbsp;e &lt;a href="https://buildsecurityin.us-cert.gov/bsi/articles%20/%20knowledge/coding/305-BSI.html" target="_blank"&gt;Build Security In&lt;/a&gt;)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Postazioni di lavoro e server&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Distribuire un sistema Host Intrusion Detection (&lt;a href="http://it.wikipedia.org/wiki/Host-based_intrusion_detection_system" target="_blank"&gt;HIDS&lt;/a&gt;) per bloccare e identificare gli attacchi comuni&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Garantire che tutti i sistemi siano aggiornati con patch provenienti da fonti attendibili&lt;br /&gt;&lt;br /&gt;Mi sembra importante integrare questa breve guida con l'indicazione dei &lt;a href="http://www.sans.org/security-resources/top5_logreports.pdf" target="_blank"&gt;5 tipi di log essenziali&lt;/a&gt; che devono essere implementati sui sistemi (la fonte in questo caso è il SANS Institute) che sono:&lt;br /&gt;&lt;br /&gt;1) log dei tentativi di accesso tramite account esistenti&lt;br /&gt;2) log dei tentativi non riusciti di accesso a file o a risorse&lt;br /&gt;3) log delle modifiche non autorizzate ad utenti, gruppi e servizi&lt;br /&gt;4) log dei sistemi più vulnerabili (per mancanza di aggiornamenti)&lt;br /&gt;5) log dei pattern&amp;nbsp;sospetti o&amp;nbsp;non autorizzati&amp;nbsp;del traffico di rete&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, per quanto riguarda le policy da emettere per garantire che i propri utenti mantengano dei comportamenti adeguati dal punto di vista della sicurezza, bisogna ricordarsi che normalmente queste iniziative tendono a proibire o a limitare molto alcuni comportamenti che gli utenti considerano legittimi, per cui è da preferire un approccio graduale e volto all'illustrazione della logica sottesa alle scelte. E' quindi preferibile adottare strumenti innovativi e divertenti per la formazione e la successiva verifica degli esiti della stessa.&lt;br /&gt;&lt;br /&gt;Un esempio potrebbe essere questo simpatico giochino (in inglese) tratto da &lt;a href="http://www.onguardonline.gov/default.aspx" target="_blank"&gt;Onguardonline&lt;/a&gt; che permette di verificare la propria conoscenza di &amp;nbsp;alcune problematiche di base sulla sicurezza informatica.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;          &lt;object width='640' height='480'&gt;&lt;param name='movie' value='http://www.onguardonline.gov/flash/7practices_loader.swf'&gt;&lt;/param&gt;&lt;param name='wmode' value='transparent'&gt;&lt;/param&gt;&lt;embed src='http://www.onguardonline.gov/flash/7practices_loader.swf' type='application/x-shockwave-flash' wmode='transparent' width='400' height='300'&gt;&lt;/embed&gt;&lt;/object&gt;          &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7195033366221481632?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7195033366221481632/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/guide-di-sicurezza-evitare-le.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7195033366221481632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7195033366221481632'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/guide-di-sicurezza-evitare-le.html' title='Guide di sicurezza: evitare le intrusioni'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4554708119037243894</id><published>2011-07-18T08:58:00.001+02:00</published><updated>2011-07-18T09:01:29.130+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Voci Amiche'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='riflessioni sicurezza'/><title type='text'>Matthew Holt - Earthquake vs. Data Breach: Which can hurt you more?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_fd0trfGxlA/Th_rSkuMY6I/AAAAAAAAASI/mtiGwm_Hf_0/s1600/Matthew-Holt.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-_fd0trfGxlA/Th_rSkuMY6I/AAAAAAAAASI/mtiGwm_Hf_0/s200/Matthew-Holt.JPG" width="155" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I met Matthew some months ago and immediately recognized his exceptional analysing capabilities. He is brilliant, with a deep knowledge of the risk analisys and solid international experience. As Senior Associate with Booz &amp;amp; Co based in Rome, he leads the firm’s Cyber Security &amp;amp; ICT Resilience service offering, so he has a privileged point of view that allows him to view, process and analyse issues and concerns of big players in the market.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;With him, some months ago, I had&amp;nbsp;one of the most interesting conversation on cybersecurity topics I ever had. During this conversation he asked me this very intriguing question: "If you had to present three cybersecurity topics at a G8 meeting in 15 minutes, which subjects would you choose? And why?". After thinking about it for a while I gave my answer.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;And, if Matthew had asked you this question what answer would you have given him?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now it's a pleasure to me to leave the floor to&amp;nbsp;Matthew.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Digital transformation can have a profoundly negative impact on a company when its risks are not managed properly. Consider the PlayStation Network (PSN) data breach disclosed by Sony Corporation in April 2011, and the events that have unfolded since. Described in the press as a “debacle,” “fiasco,” and “humiliation,” the breach clearly inflicted serious damage on Sony, especially in combination with the generally poor economic conditions globally and the other major crisis already under way in Japan at the time of the breach, resulting from the earthquake of March 11, 2011.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;That earthquake was the most powerful ever to hit Japan, and the fourth most powerful in the world since modern record keeping began in 1900. The overall cost is estimated to exceed US$200 billion, making it the most expensive natural disaster on record.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Just over a month later, on April 20, 2011, a 14-year-old boy returned to his Chicago home after school expecting to join three friends online and play Might &amp;amp; Magic: Clash of Heroes (a fantasy adventure in which young people from different cultures band together to stop demons from taking over the world) on his Sony PlayStation 3. But the PSN service was down. Several days later, Sony explained that it had taken the network offline on purpose because of a massive data breach that eventually involved more than 100 million customer accounts.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Though the Japanese earthquake and Sony’s data breach are certainly not comparable in terms of societal impact and suffering, they do provide a useful lesson in risk management and mitigation for companies with major positions in digital services and valuable information assets.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In late April, Sony announced that the 10th and final plant affected by the earthquake would resume production by the end of May. The cost of the earthquake, according to Sony, was $475 million in fiscal 2011 and will approach $1.8 billion in fiscal 2012.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In contrast, Sony has not yet been able to calculate the full cost of the data breach. The company initially estimated the cost at $171 million in fiscal 2012, including lost business and response costs such as identifying and repairing the breach and notifying subscribers. But Sony hastened to add that this figure did not account for costs related to class action lawsuits by customers (at least two of which are already under way), customer identity theft, and credit card theft. External estimates, which include these potential future costs and losses in market capitalization, are much higher. For example, the most widely recognized industry standard for evaluating such events, the Ponemon Institute’s annual “Cost of a Data Breach” report, estimates that the PSN breach could eventually cost Sony as much as $24.5 billion. The actual cost will likely lie somewhere between the two estimates.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another way to effectively measure and compare the potential impacts of these two crises is to analyze their effects on Sony’s share price on the Tokyo Stock Exchange (see Exhibit 1).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-7JG9RLVKS5E/Th_qJzXX6tI/AAAAAAAAASA/i7AAm6YASlc/s1600/Data-Breach-vs-Earthquake.JPG" target="_blank" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="276" src="http://4.bp.blogspot.com/-7JG9RLVKS5E/Th_qJzXX6tI/AAAAAAAAASA/i7AAm6YASlc/s400/Data-Breach-vs-Earthquake.JPG" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Exhibit 1&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This analysis reveals a significant difference in the impacts of the two crises on the company’s market valuation. The immediate impact of the earthquake on Sony’s share price (-19 percent) was generally perceived by capital markets to be about the same as the impact to the general economy (-18 percent), but both recovered about 50 percent of the loss by March 27. After that, Sony’s share price slowly dropped in comparison to the Nikkei index, probably due to the actual impact of the earthquake on its operations. The data breach, on the other hand, caused a sustained 12 percent loss in Sony’s share price—the equivalent of $3.6 billion in market capitalization. And recent events suggest that this could worsen, because more security weaknesses have been revealed as Sony has restored service, and the recovery phase is not yet fully complete.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Evaluating events based on share price is admittedly imperfect, but the key message is clear: The PSN data breach knocked Sony off the post-tsunami economic recovery path in Japan.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This raises a critical question: Could risk management have prevented or mitigated Sony’s back-to-back crises?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In a crisis of the magnitude and consequence of the Japanese earthquake, the answer is probably not. It was clearly a Black Swan—an event with extremely low probability and devastating impact. A risk manager who predicted that an earthquake such as this would occur, and requested the budget necessary to protect the company against it, would most likely have been ignored.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The PSN data breach, however, is another story. According to Shinji Hasejima, Sony’s CIO, the breach occurred in PSN’s Web application service platform. “The vulnerability was a known vulnerability,” he said during a press conference on May 1, 2011. Further, in the current threat environment, IT security and risk managers feel that it is almost certain that adversaries will try to access their information.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If you had asked Sony’s senior leaders a year ago to identify 10 events that could potentially erase 12 percent of their market capitalization in a matter of days, “unauthorized access to a list of online gamers” probably would not have made the list. If you had asked the same executives after the earthquake to identify 10 events that might keep Sony from recovering at the same rate as the overall economy in Japan, the result would likely have been the same. Yet that is exactly what happened.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;No one held Sony’s management responsible for failing to predict an unimaginable natural catastrophe, but the PSN data breach is sure to be a different story. Sony will recover from the earthquake at a substantially slower rate than other Japanese companies because an as-yet-unidentified culprit (probably Anonymous) exploited a known software vulnerability. Why that happened is something Sony management is having a hard time explaining &amp;nbsp;to its board of directors, to judges and juries in class action lawsuits, and, most important, to its customers and shareholders.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Profile:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://it.linkedin.com/pub/matthew-holt/5/40a/a35" target="_blank"&gt;Matthew W. Holt&lt;/a&gt;, MBA, CISSP, CISM, is a Senior Associate with Booz &amp;amp; Co based in Rome, Italy, and he leads the firm’s Cyber Security &amp;amp; ICT Resilience service offering. &amp;nbsp;This includes development of national / corporate policy and governance models, risk management, integrated security, incident management, and business continuity planning. &amp;nbsp;Mr. Holt’s background encompasses 22 years of international experience for both government and private sector clients including the United States Department of Defense and multiple Fortune 500 companies.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4554708119037243894?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4554708119037243894/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/matthew-holt-earthquake-vs-data-breach.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4554708119037243894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4554708119037243894'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/matthew-holt-earthquake-vs-data-breach.html' title='Matthew Holt - Earthquake vs. Data Breach: Which can hurt you more?'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-_fd0trfGxlA/Th_rSkuMY6I/AAAAAAAAASI/mtiGwm_Hf_0/s72-c/Matthew-Holt.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1643185550519767002</id><published>2011-07-17T10:09:00.000+02:00</published><updated>2011-07-17T10:09:30.708+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 17 luglio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear:left; float:left;margin-right:1em; margin-bottom:1em"&gt;&lt;img border="0" height="172" width="170" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As every Sunday morning here is my listing of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@fpietrosanti" target="_blank"&gt;@fpietrosanti&lt;/a&gt;: Very well writen, non Technical, article How Hackers Stole 24000 Files From The Pentagon  &lt;a href="http://t.co/f2PSqiS" target="_blank"&gt;http://t.co/f2PSqiS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@rmack" target="_blank"&gt;@rmack&lt;/a&gt;: Corrected link: Academic paper on re-establishment of borders in cyberspace &lt;a href="http://1.usa.gov/pGDrZ7" target="_blank"&gt;http://1.usa.gov/pGDrZ7&lt;/a&gt; (pdf)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt;: A Futures Market for Computer Security - MIT Technology Review &lt;a href="http://flpbd.it/jDdY" target="_blank"&gt;http://flpbd.it/jDdY&lt;/a&gt; by &lt;a href="http://twitter.com/@briankrebs" target="_blank"&gt;@briankrebs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@TheHackersNews" target="_blank"&gt;@TheHackersNews&lt;/a&gt;: Chrome Extensions for #Security Professionals &lt;a href="http://t.co/tp9bpmX" target="_blank"&gt;http://t.co/tp9bpmX&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@BrianHonan" target="_blank"&gt;@BrianHonan&lt;/a&gt;: Does your org comply with the Data Protection Act?  This free self assessment checklist from the DPC is a good start &lt;a href="http://bit.ly/qIP6op" target="_blank"&gt;http://bit.ly/qIP6op&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@eduinfosec" target="_blank"&gt;@eduinfosec&lt;/a&gt;: Use discretion when installing smartphone apps. Once again, malicious apps found in Android Market. &lt;a href="http://bit.ly/q1NJpC" target="_blank"&gt;http://bit.ly/q1NJpC&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1643185550519767002?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1643185550519767002/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-17-luglio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1643185550519767002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1643185550519767002'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-17-luglio-2011.html' title='Best of the week - 17 luglio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-8918114364686368297</id><published>2011-07-15T12:37:00.002+02:00</published><updated>2011-07-15T15:03:34.533+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='Data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='riflessioni sicurezza'/><title type='text'>MUMBLE - San Sebastiano e la cybersecurity</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SkK96dybC_4/TiALDxgJ-8I/AAAAAAAAASM/03L6Tiq4KEQ/s1600/San-Sebastiano.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-SkK96dybC_4/TiALDxgJ-8I/AAAAAAAAASM/03L6Tiq4KEQ/s320/San-Sebastiano.jpg" width="194" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Luca Signorelli - 1498&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt;Ma che c'entra San Sebastiano con la cybersecurity?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Purtroppo c'entra eccome.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come vedete in questo bellissimo olio su legno di fine Quattrocento, San Sebastiano fu martirizzato con le frecce. Nel dipinto è possibile vedere una moltitudine di individui armati di balestre lanciare dardi all'indirizzo di un inerme Sebastiano legato ad un palo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E' da un po' di tempo che penso a questo quadro come a una ottima metafora per descrivere l'attuale situazione della sicurezza su Internet. Siamo infatti diventati tutti dei Sebastiano; alla&amp;nbsp;mercé&amp;nbsp;di aggressori, più o meno motivati e più o meno efficaci, che portano continuamente attacchi alle infrastrutture informatiche di tutte le organizzazioni del mondo.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Se si sommano le varie notizie di attacchi andati a buon fine, in una prima e sommaria analisi,&amp;nbsp;negli ultimi&amp;nbsp;12 mesi otteniamo:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- attacchi di tipo statuale con finalità spionistiche e/o di immagine&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- furti di dati con finalità economiche dirette e/o indirette&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- furti di dati con finalità di protesta o di immagine&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- attacchi di DDoS con finalità di protesta&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- furti di dati con finalità spionistiche&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma, ciò che emerge è che la minaccia sta cambiando rapidamente (se volete approfondire ho fatto &lt;a href="http://prezi.com/4njg9olad2xn/present/?auth_key=94oolyb&amp;amp;follow=nientenomi@live.it"&gt;una presentazione&lt;/a&gt; su questo argomento, usare i tasti freccia per cambiare slide) e che l'asserzione che "avendo a disposizione tempo, risorse e skill in quantità adeguata si riesce a compromettere la sicurezza di qualunque sistema" non è mai stata così vera come in questa fase storica. Non si sta salvando nessuno. Perché nessuno è attualmente in grado di salvarsi, almeno con una buona dose di certezza.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ciò che si riesce a fare (e non è cosa da poco) è limitare i danni. Il che non significa assolutamente che non bisogna fare il possibile per ridurre la superficie d'attacco e rendere il più possibile la vita difficile agli attaccanti. Semplicemente non ci si può aspettare che questo sia sufficiente a fermare tutti i possibili attacchi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Volendo citare un grande della sicurezza informatica, Bruce Schneier, "You can't defend.&amp;nbsp;You can't prevent.&amp;nbsp;The only thing you can do is&amp;nbsp;DETECT and RESPOND.".&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E' molto importante imparare questa lezione perché in questo modo è possibile cominciare a ragionare in maniera proattiva orientando i propri investimenti e le proprie priorità in modo da privilegiare le capacità davvero utili. Inoltre, proprio per riuscire a migliorare le proprie capacità di "rilevazione e risposta" bisogna imparare a conoscere bene la propria realtà: le proprie vulnerabilità, i propri nemici e propri punti di forza.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E, purtroppo in Italia questi aspetti sono sempre stati abbastanza sottovalutati.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma, dovremo abituarci a sentire sempre più spesso parlare di data breach.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Senza che questo ci condizioni più di tanto.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Perché sono convinto che la notizia di un data breach, di per sè, non dia un metro di giudizio sulla sicurezza di una realtà, ciò che davvero fa la differenza sono i tempi e le capacità di reazione e di gestione dell'incidente.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-8918114364686368297?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/8918114364686368297/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/mumble-san-sebastiano-e-la.html#comment-form' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8918114364686368297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/8918114364686368297'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/mumble-san-sebastiano-e-la.html' title='MUMBLE - San Sebastiano e la cybersecurity'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-SkK96dybC_4/TiALDxgJ-8I/AAAAAAAAASM/03L6Tiq4KEQ/s72-c/San-Sebastiano.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3167040397055135588</id><published>2011-07-10T15:13:00.000+02:00</published><updated>2011-07-10T15:13:44.245+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 10 Luglio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here is my weekly listing of the best security resources.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="tweet-text tweet-text-large"&gt;     &lt;a class="tweet-user-block-screen-name user-profile-link" data-user-id="177493320" href="http://twitter.com/#%21/eraserhw" title="Marco Giuliani"&gt;@eraserhw&lt;/a&gt;&amp;nbsp;&lt;span class="tweet-user-block-full-name"&gt;&lt;/span&gt;ZeroAccess updated now kills security software &lt;a class="twitter-timeline-link" data-expanded-url="http://goo.gl/8YpcP" href="http://t.co/w2KK2Pe" rel="nofollow" target="_blank" title="http://goo.gl/8YpcP"&gt;goo.gl/8YpcP&lt;/a&gt; Technical paper updated at this link: &lt;a class="twitter-timeline-link" data-expanded-url="http://goo.gl/fVesZ" href="http://t.co/7akEvbb" rel="nofollow" target="_blank" title="http://goo.gl/fVesZ"&gt;goo.gl/fVesZ&lt;/a&gt;&lt;/div&gt;&lt;div class="tweet-text tweet-text-large"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="tweet-text tweet-text-large"&gt;&lt;div class="tweet-row"&gt;               &lt;span class="tweet-user-name"&gt;   &lt;a class="tweet-screen-name user-profile-link" data-user-id="111379552" href="http://twitter.com/#%21/Nientenomi" title="Matteo Cavallini"&gt;@Nientenomi&lt;/a&gt;&amp;nbsp;&lt;span class="tweet-full-name"&gt;&lt;/span&gt;&lt;/span&gt;                       Clickjacking Attacks Unresolved &lt;a class="twitter-timeline-link" data-expanded-url="https://docs.google.com/document/pub/?id=1hVcxPeCidZrM5acFH9ZoTYzg1D0VjkG3BDW_oUdn5qc&amp;amp;pli=1" href="http://zite.to/pSi7Gs" rel="nofollow" target="_blank" title="https://docs.google.com/document/pub/?id=1hVcxPeCidZrM5acFH9ZoTYzg1D0VjkG3BDW_oUdn5qc&amp;amp;pli=1"&gt;http://zite.to/pSi7Gs&lt;/a&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="tweet-row"&gt;&lt;div class="tweet-row"&gt;               &lt;span class="tweet-user-name"&gt;   &lt;a class="tweet-screen-name user-profile-link" data-user-id="92149105" href="http://twitter.com/#%21/nigroeneveld" title="N. Groeneveld"&gt;@nigroeneveld&lt;/a&gt; &lt;span class="tweet-full-name"&gt;&lt;/span&gt;&lt;/span&gt;780 Online Documentaries &lt;a class="twitter-timeline-link" data-expanded-url="http://www.slideshare.net/jopiter/780-online-documentaries/" href="http://slidesha.re/bds4sj" rel="nofollow" target="_blank" title="http://www.slideshare.net/jopiter/780-online-documentaries/"&gt;http://slidesha.re/bds4sj&lt;/a&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;&lt;a class="  twitter-hashtag" href="http://twitter.com/#%21/search?q=%23documentary" rel="nofollow" title="#documentary"&gt;&lt;span class="hash"&gt;&lt;/span&gt;&lt;span class="hash-text"&gt;&lt;/span&gt;&lt;/a&gt;&lt;a class="  twitter-hashtag" href="http://twitter.com/#%21/search?q=%23video" rel="nofollow" title="#video"&gt;&lt;span class="hash"&gt;&lt;/span&gt;&lt;span class="hash-text"&gt;&lt;/span&gt;&lt;/a&gt;&lt;div class="tweet-corner"&gt;&lt;div class="tweet-meta"&gt;&lt;span class="icons"&gt;   &lt;/span&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;            &lt;/div&gt;&amp;nbsp;&lt;div class="tweet-corner"&gt;&lt;div class="tweet-meta"&gt;&lt;span class="icons"&gt;   &lt;/span&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;            &lt;/div&gt;&amp;nbsp;&lt;span class="tweet-user-name"&gt;&lt;a class="tweet-screen-name user-profile-link" data-user-id="20525891" href="http://twitter.com/#%21/SecurityTube" title="Security Tube"&gt;@SecurityTube&lt;/a&gt; &lt;span class="tweet-full-name"&gt;&lt;/span&gt;&lt;/span&gt;[Video] Hacking NZ Government SQL Injection -Nerv&amp;nbsp; &lt;a class="twitter-timeline-link" data-expanded-url="http://www.securitytube.net/video/2012/" href="http://securitytube.net/video/2012" rel="nofollow" target="_blank" title="http://www.securitytube.net/video/2012/"&gt;http://securitytube.net/video/2012&lt;/a&gt;&amp;nbsp; &lt;a class="twitter-timeline-link" data-expanded-url="http://www.securitytube.net/video/2014/" href="http://securitytube.net/video/2014" rel="nofollow" target="_blank" title="http://www.securitytube.net/video/2014/"&gt;http://securitytube.net/video/2014&lt;/a&gt; by Nerv&lt;/div&gt;&lt;div class="tweet-text tweet-text-large"&gt;&lt;div class="tweet-row"&gt;&lt;div class="tweet-corner"&gt;&lt;div class="tweet-meta"&gt;&lt;span class="icons"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="tweet-meta"&gt;&lt;div class="tweet-text pretty-link"&gt;               &lt;span class="tweet-user-name"&gt;   &lt;a class="tweet-screen-name user-profile-link" data-user-id="94331772" href="http://twitter.com/#%21/ccdcoe" title="CCD COE"&gt;@ccdcoe&lt;/a&gt;&amp;nbsp;&lt;span class="tweet-full-name"&gt;&lt;/span&gt;&lt;/span&gt;Why are the bad guys winning the InfoSec war? To find out watch &lt;a class="  twitter-atreply" data-screen-name="0xcharlie" href="http://twitter.com/0xcharlie" rel="nofollow"&gt;&lt;span class="at"&gt;@&lt;/span&gt;&lt;span class="at-text"&gt;0xcharlie&lt;/span&gt;&lt;/a&gt; keynote at &lt;a class="  twitter-hashtag" href="http://twitter.com/#%21/search?q=%233iccc" rel="nofollow" title="#3iccc"&gt;&lt;span class="hash"&gt;#&lt;/span&gt;&lt;span class="hash-text"&gt;3iccc&lt;/span&gt;&lt;/a&gt;: &lt;a class="twitter-timeline-link" data-expanded-url="http://www.ccdcoe.org/282.html/" href="http://t.co/bCF96Ei" rel="nofollow" target="_blank" title="http://www.ccdcoe.org/282.html/"&gt;ccdcoe.org/282.html&lt;/a&gt;&lt;/div&gt;&lt;div class="tweet-text pretty-link"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="tweet-text pretty-link"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="tweet-row"&gt;     &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;            &lt;/div&gt;&lt;/div&gt;&lt;div class="tweet-row"&gt;   &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3167040397055135588?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3167040397055135588/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-10-luglio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3167040397055135588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3167040397055135588'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-10-luglio-2011.html' title='Best of the week - 10 Luglio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7756711456704286876</id><published>2011-07-08T19:24:00.003+02:00</published><updated>2011-07-20T15:36:25.440+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='rapporto'/><title type='text'>Cloud Security: una sfida per il futuro</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-bE2vC8bRx6U/Thc5gok8H6I/AAAAAAAAAR8/r5UcSGrU-qA/s1600/Cloud-Security-una-sfida-per-il-futuro.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" m$="true" src="http://2.bp.blogspot.com/-bE2vC8bRx6U/Thc5gok8H6I/AAAAAAAAAR8/r5UcSGrU-qA/s320/Cloud-Security-una-sfida-per-il-futuro.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E' con piacere e con un pizzico di orgoglio che scrivo questo post. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dopo un lungo lavoro di scrittura è stato pubblicato il Quaderno Consip "Cloud Security: una sfida per il futuro" e, finalmente,&amp;nbsp;il 6 luglio scorso in Consip, si è tenuto&amp;nbsp;il workshop dedicato alla presentazione del Quaderno. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Consip, per evitare spiacevoli esclusioni nella distribuzione degli&amp;nbsp;inviti, ha ritenuto di invitare solamente persone provenienti dalla PA; nonostante questa limitazione l'evento ha visto la partecipazione di oltre 90 persone. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'agenda prevedeva:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Apertura dei lavori a cura di &lt;a href="http://www.consip.it/on-line/Home/Chisiamo/Organisocietariestruttura/OrganiSocietari/ConsigliodiAmministrazione.html#casalino"&gt;Domenico Casalino&lt;/a&gt; (AD Consip)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-&amp;nbsp;Introduzione di Gaetano Santucci (Resp. Competence Center Consip)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;e, a seguire, gli interventi:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Cloud Security: una sfida per il futuro di &lt;a href="http://it.linkedin.com/in/cavallinimatteo"&gt;Matteo Cavallini&lt;/a&gt; (Resp. SO Unità Locale Sicurezza MEF/Consip)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Governance e Cloud Security di &lt;a href="http://it.linkedin.com/pub/igor-nai-fovino/1/824/905"&gt;Igor Nai Fovino&lt;/a&gt; (Dir. Scientifico GCSEC)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Analisi legale di rischi, criticità e opportunità relative al cloud computing di &lt;a href="http://www.paolobalboni.eu./"&gt;Paolo Balboni&lt;/a&gt; (Dir. Esecutivo European Privacy Association)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- L’iniziativa cloud del Dipartimento del Tesoro di &lt;a href="http://www.dt.tesoro.it/it/dipartimento/organigramma/ucid_coordinamento_informatico.html"&gt;Francesco Castanò&lt;/a&gt; (Resp. Sistemi Informativi Dip. del Tesoro, MEF)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Il cloud computing nella visione del Ministero della Giustizia di &lt;a href="http://www.giustizia.it/giustizia/it/mg_6_8_1_1.wp;jsessionid=735EC781E501462FFABF30E164263D39.ajpAL01?contentId=NVA99641&amp;amp;previsiousPage=mg_6_8"&gt;Stefano Aprile&lt;/a&gt; (Resp. Sistemi Informativi Ministero della Giustizia)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il Quaderno è &lt;a href="http://www.consip.it/on-line/Home/Pressroom/QuaderniConsip/QuaderniConsip2011/documento6416.html"&gt;liberamente scaricabile&lt;/a&gt; dal sito Consip. Le slide degli interventi sono state pubblicate al &lt;a href="http://www.consip.it/on-line/Home/Newsedeventi/articolo3222.html"&gt;seguente link&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Prima di chiudere il post voglio ringraziare di cuore le persone che hanno contribuito alla stesura di questo Quaderno, oltre ai miei colleghi (che trovate citati nei ringraziamenti), voglio citare Paolo Balboni e &lt;a href="http://gr.linkedin.com/in/danielecatteddu"&gt;Daniele Catteddu&lt;/a&gt; che hanno dato un contributo decisivo alla maturazione dei concetti espressi nel Quaderno.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Grazie, grazie, grazie.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tutti i commenti sono benvenuti e graditi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7756711456704286876?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7756711456704286876/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/cloud-security-una-sfida-per-il-futuro.html#comment-form' title='4 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7756711456704286876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7756711456704286876'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/cloud-security-una-sfida-per-il-futuro.html' title='Cloud Security: una sfida per il futuro'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-bE2vC8bRx6U/Thc5gok8H6I/AAAAAAAAAR8/r5UcSGrU-qA/s72-c/Cloud-Security-una-sfida-per-il-futuro.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-176936066722600261</id><published>2011-07-03T14:20:00.000+02:00</published><updated>2011-07-03T14:20:55.976+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 3 luglio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here is the new listing of best security resources of the week.&lt;br /&gt;&lt;br /&gt;Enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikkohypponen"&gt;@mikkohypponen&lt;/a&gt; This is why you should enable two-factor authentication on your GMail account: &lt;a href="http://bit.ly/l6F86n"&gt;http://bit.ly/l6F86n&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mgeist"&gt;@mgeist&lt;/a&gt; OECD Internet Policy Principles could create incentives to delete or block content, adopt 3 strikes &lt;a href="http://is.gd/TKWoI6"&gt;http://is.gd/TKWoI6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@BullGuard"&gt;@BullGuard&lt;/a&gt; DNS cache poisoning: still works and still makes lots of damage, (Mon, Jun 27th) &lt;a href="http://ow.ly/5rLXM"&gt;http://ow.ly/5rLXM&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@InfosecurityMag"&gt;@InfosecurityMag&lt;/a&gt; Symantec: Google Android has a number of security strengths &lt;a href="http://bit.ly/k9br6C"&gt;http://bit.ly/k9br6C&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ToolsWatch"&gt;@ToolsWatch&lt;/a&gt; The #OpNewblood Super Secret Security Handbook: Guys from #OpNewblood has spread out a good guidelines showing... &lt;a href="http://twurl.nl/1md7d8"&gt;http://twurl.nl/1md7d8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikkohypponen"&gt;@mikkohypponen&lt;/a&gt; Kenneth Geers of NATO CCD COE in Estonia has published a book called "Strategic Cyber Security". Free, 169 Pages: &lt;a href="http://bit.ly/j6IevS"&gt;http://bit.ly/j6IevS&lt;/a&gt; [PDF]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-176936066722600261?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/176936066722600261/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-3-luglio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/176936066722600261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/176936066722600261'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/07/best-of-week-3-luglio-2011.html' title='Best of the Week - 3 luglio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-413088606046705213</id><published>2011-06-30T12:23:00.007+02:00</published><updated>2011-08-01T22:17:38.692+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><title type='text'>MUMBLE - Le cloud incontrano il Cybercrime</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-24zli-BD3_w/TgxNoWn8OcI/AAAAAAAAAR0/TwwNcZLMGgA/s1600/Cyber-Crime-2.JPG" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" i$="true" src="http://2.bp.blogspot.com/-24zli-BD3_w/TgxNoWn8OcI/AAAAAAAAAR0/TwwNcZLMGgA/s320/Cyber-Crime-2.JPG" width="223" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ho scritto questo articolo quanche tempo fa e ora posso finalmente renderlo pubblico anche su Punto 1 poichè è stato&amp;nbsp;pubblicato nella seconda uscita della rivista &lt;a href="http://www.tecnaeditrice.com/cybercrime_presentazione.php" target="_blank"&gt;CyberCrime magazine&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;----------------------------------------------&lt;br /&gt;Le Cloud sono il futuro dell’ICT e stano aprendo nuovi scenari e nuove opportunità di crescita in tutto il mondo. Negli Stati Uniti, ad esempio, Vivek Kundra, Chief Information Officer (CIO) dell'amministrazione pubblica statunitense, ha prodotto la “&lt;a href="http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf" target="_blank"&gt;Federal Cloud Strategy&lt;/a&gt;” in cui, tra le altre cose, viene ribadito che le nuove iniziative IT federali dovranno prendere in esame le soluzioni cloud based in via prioritaria rispetto ad ogni altra opzione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In questo contesto così florido e ricco di investimenti, i criminali non stanno certo a guardare e hanno cominciato a sviluppare le proprie strategie su questo specifico tema. Al momento stiamo assistendo ad un inizio di interesse da parte dei cyber criminali verso le grandi cloud pubbliche secondo tre direttrici principali:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;• come bersagli di valore&lt;/div&gt;&lt;div style="text-align: justify;"&gt;• come fonte di nuovi strumenti&lt;/div&gt;&lt;div style="text-align: justify;"&gt;• come modelli di business da emulare &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Prendendo in esame il caso in cui le cloud fungono da bersaglio dei cyber criminali è facile capire che, data la natura di grandi accentratori di dati provenienti da molti clienti diversi, le cloud sono percepite come uno dei bersagli più appetibili per attacchi di tipo “massivo” che puntano al furto o alla compromissione di grandi quantità di dati. Inoltre, le cloud pubbliche presentano caratteristiche infrastrutturali per le quali una singola vulnerabilità o un singolo errore di configurazione possono comportare una grande superficie d’attacco. I cyber criminali hanno poi l’invidiabile possibilità di ripetere un identico attacco sui molti clienti di una stessa cloud.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, i cyber criminali sono attratti dalle cloud poiché i rischi connessi con questo tipo di attacchi sono attualmente molto bassi, in quanto:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;1. le indagini delle forze dell’ordine sono tecnicamente molto complesse&lt;/div&gt;&lt;div style="text-align: justify;"&gt;2. la natura transnazionale delle cloud pubbliche complica ulteriormente la scena del crimine&lt;/div&gt;&lt;div style="text-align: justify;"&gt;3. in caso di giudizio non ci sono ancora precedenti consolidati sulla presentazione delle prove a carico&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tutto ciò contribuisce alla creazione di un substrato particolarmente favorevole all’azione dei criminali che inizia a dare qualche preoccupazione al mercato, come peraltro dimostrato da alcuni recenti casi di cronaca quali, ad esempio, il “data breach” di Epsilon, un fornitore cloud di servizi marketing per grandi marchi dell’industria mondiale. In questo caso, infatti, milioni di indirizzi email, nomi ed altre informazioni di valore sono direttamente passati dal cloud provider alle poco raccomandabili mani dei criminali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Passando poi al caso in cui le cloud fungono da strumento per realizzare crimini, la riflessione può partire dalla considerazione che una comune modalità di misura della robustezza di molti meccanismi di sicurezza è data dal tempo necessario per comprometterne il corretto funzionamento con i normali strumenti messi a disposizione dal mercato. Molti meccanismi di sicurezza sono dunque considerati sufficientemente robusti perché garantiscono di resistere a tentativi di compromissione per un tempo considerato adeguato. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il cloud computing sta mettendo seriamente in discussione questo approccio poiché, con estrema facilità e velocità, i criminali hanno la possibilità di rendere operative infrastrutture ICT capaci di grandi performance computazionali. Da notare, inoltre, che queste infrastrutture possono essere dismesse con altrettanta semplicità complicando quindi la successiva attività investigativa. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A dimostrazione delle reali potenzialità di questo tipo di approccio può essere preso in esame un sito che offre a “penetration tester and network auditors” la possibilità di sfruttare un servizio cloud per l’ottimizzazione della procedura di individuazione delle password di reti WiFi protette con algoritmo WPA. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come si può leggere nel testo proposto nella home page del sito, il tempo di calcolo richiesto per questa operazione passa da circa 5 giorni a 20 minuti ad un costo di soli 17 dollari.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, come precedentemente anticipato, l’ultimo punto riguarda invece l’aspetto emulativo del cyber crime verso l’approccio cloud. E’ sempre più evidente che i criminali si stanno organizzando per commercializzare i loro “business” in modalità “as a Service”. Exploit pack, spam, attacchi DDoS, phishing, frodi bancarie e quant’altro sia nella mente dei cyber criminali viene messo sul mercato sotto forma di servizi. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Si stanno quindi formando gruppi specializzati nell’erogazione di servizi malevoli ad altri gruppi criminali che quindi usufruiscono degli stessi benefici di economicità e flessibilità riservati ai normali utenti delle cloud. A questo proposito è interessante notare che le botnet, le reti di computer infetti che vengono controllati remotamente da criminali, stanno diventando delle vere e proprie cloud pubbliche in grado di erogare varie tipologie di servizi. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma, dopo IaaS, PaaS e SaaS si sta consolidando anche il MaaS, il Malware as a Service.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E’ necessario quindi affrontare ed indirizzare il rapporto tra cloud computing e cyber crime con decisione, prima che le cloud siano utilizzate a livello globale nell’erogazione di servizi essenziali. Tra le varie indicazioni che possono essere date c’è la predisposizione di seri standard di sicurezza collegati a schemi di certificazione ufficialmente riconosciuti. Questi standard, tenendo conto delle peculiarità delle cloud, contribuiranno a limitare gli “effetti collaterali” della natura condivisa di questi ambienti. Inoltre dovrà essere fatto un grande sforzo a livello di standardizzazione delle procedure e degli strumenti di “forensic” nel mondo cloud in modo che le forze dell’ordine abbiano la possibilità di acquisire in modo efficiente, certo e affidabile le prove di quanto eventualmente accaduto. Infine dovranno essere elaborati dei codici di comportamento per i provider di servizi in modo che gli utilizzi consentiti per le cloud siano strettamente limitati e sottoposti ad adeguati controlli. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; text-align: justify;"&gt;Un piccolo aggiornamento&amp;nbsp;che risale a&amp;nbsp;qualche giorno dopo l'invio di questo articolo alla rivista. Kaspersky ha messo in evidenza un caso in cui l'infrastruttura di Amazon è stata utilizzata per servire malware agli utenti... la giostra è cominciata!!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Ez3wpOPwvkk/TgxOjxTyIpI/AAAAAAAAAR4/enruVxkMwpc/s1600/Amazon-malware.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="247" i$="true" src="http://1.bp.blogspot.com/-Ez3wpOPwvkk/TgxOjxTyIpI/AAAAAAAAAR4/enruVxkMwpc/s320/Amazon-malware.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-413088606046705213?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/413088606046705213/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/mumble-le-cloud-incontrano-il.html#comment-form' title='3 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/413088606046705213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/413088606046705213'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/mumble-le-cloud-incontrano-il.html' title='MUMBLE - Le cloud incontrano il Cybercrime'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-24zli-BD3_w/TgxNoWn8OcI/AAAAAAAAAR0/TwwNcZLMGgA/s72-c/Cyber-Crime-2.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-6993124734293364067</id><published>2011-06-28T14:35:00.005+02:00</published><updated>2011-06-29T11:27:04.570+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Voci Amiche'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='AET'/><title type='text'>Olli-Pekka Niemi - Dealing with evasions</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-EhnNXMSIQCg/TgmAXl4QKQI/AAAAAAAAARw/Af8aqX5QjP0/s1600/Olli-Pekka-Niemi.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" i$="true" src="http://1.bp.blogspot.com/-EhnNXMSIQCg/TgmAXl4QKQI/AAAAAAAAARw/Af8aqX5QjP0/s1600/Olli-Pekka-Niemi.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It's time for a new contribution to "&lt;a href="http://www.matteocavallini.com/p/voci-amiche.html" target="_blank"&gt;Voci Amiche&lt;/a&gt;" section of the blog and I'm very happy to introduce &lt;a href="http://fi.linkedin.com/pub/olli-pekka-niemi/5/994/363" target="_blank"&gt;Olli-Pekka Niemi&lt;/a&gt;, an expert on a very hot topic: the Advanced Evasion Techniques (AETs).&lt;br /&gt;&lt;br /&gt;I met Olli during a &lt;a href="http://www.stonesoft.com/it/press_and_media/releases/italiano/2011/07042011.html?uri=/it/press_and_media/releases/italiano/index.html" target="_blank"&gt;workshop&lt;/a&gt; organized by Stonesoft and I admired his ability to explain hard concepts in a simple way. He is brilliant and has an amazing&amp;nbsp;knowledge of network security topics.&lt;br /&gt;&lt;br /&gt;As Head of the Stonesoft Vulnerability Analysis Goup (VAG) he delved into multiple evasion methods to bypass the detection of Intrusion Prevention Systems and break into the remote system. So, at the moment, his knowledge of AETs is pretty unique and I'm very proud that the "Punto 1" readers can approach this "advanced" topic through his contribution.&lt;br /&gt;&lt;br /&gt;Thank you very much Olli, I hope that we will have other occasions to collaborate, now the floor is yours... &lt;br /&gt;---------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The role of a network security device such as IPS/NGFW/UTM is to analyze and&amp;nbsp; pass through data that is allowed according to Security Policies, while&amp;nbsp;preventing threatening data such as remote exploits against vulnerable clients and servers. Exploits can apply multiple evasion methods to bypass the detection and protection capabilities of the network security device and break into the remote host. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;What's evasion?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;TCP/IP implementations will follow a general principle of robustness: Be conservative in what you do, be liberal in what you accept from others. There are always multiple ways to do things, i.e. to encode and transmit data. The multitude of data encoding and transmission possibilities provide ample opportunity for the malicious to discover and apply evasions. Simply put, an evasion is just a method of transmitting data in a way that is not expected or understood properly by the network security device. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This also means that many of the evasion methods that can be applied to hide malicious data like exploits are not actually threatening or malicious by themselves. Only the payload is. An evasion happens when the security device misclassifies the transmitted data as legitimate, even though it is in fact malicious. Evasions are not just some protocol anomalies or violations, or malicious data that can be dropped by the security device, but simply alternative ways of encoding data.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Evasion research, nothing new under the sun? &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Evasions have been researched before. A lot. One of the first comprehensive description of evasions is a research paper "Insertion, Evasion, and Denial of&amp;nbsp; Service: Eluding Network Intrusion Detection" written by Ptacek and Newsham in January 1998. This paper is kind of the founding stone of evasions, and in fact&amp;nbsp;most of evasions are somewhat based on the research done. In 1998, an article in the Phrack Magazine also describes ways to bypass network intrusion detection. In 1999 http related evasions were studied in "Whisker evasion tactics" by Rain Forest Puppy. Later on Handley and Paxson suggested evasion prevention via normalization in 2001, Gorton and Champion suggested combinations of evasions in&amp;nbsp;2004, and finally Moore and Caswell discussed MSPRC evasions at Black Hat 2006.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;At Stonesoft we have followed the research of evasions ever since we started our own security gateway development over a decade ago, and started our own research into the topic back in 2007. In the summer of 2010 we announced the concept of Advanced Evasions Techniques (AET). In our release we combined evasion techniques to form new evasions. However, AETs are not just a single release of evasion techniques, but a new paradigm, where Network Security Devices are systematically tested with all possible ways of transmitting data between hosts.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Why do evasions still work?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Why do evasions still work, after all these years? Some vendors are actually saying that they do not. But they are mistaken: while their products may offer protection against some specific evasions, the claim that all evasions are handled properly is simply untrue. The problem is that evasion are not a single concept or item or technique, but the general inability to correctly understand the data being transmitted and analyzed. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Evasions work because many of the network security devices are too much throughput oriented by design, sacrificing the security analysis capabilities for performance. The security devices are lacking proper understanding and analysis of the networking protocols. Evasions work because implementing middle box TCP/IP stack and protocol normalization is difficult. Anomaly based evasion preventions lead to false&amp;nbsp;positives. Simple and throughput-wise effective packet based pattern matching will miss attacks deploying evasions. Proper TCP/IP reassembly that is invulnerable to TCP evasions requires a lot of memory. And finally, testing evasions is difficult. It requires tools, but most of the tools available contain only a few evasions. Network security devices tend to detect some of those evasions that are required for certifications or can be tested in publicly available tools but they often miss attacks that contain evasions that are not&amp;nbsp;implemented in available testing tools.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dealing with evasions&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Properly dealing with evasions requires a thorough understanding of the network protocols. For example, some Network Security Devices could be fooled by splitting a TCP stream into small segments. Some vendors protect themselves against this by having their product block small segments. However, small&amp;nbsp;segments are a perfectly legitimate feature of TCP, and they risk blocking legitimate traffic.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;To deal with TCP segmentation properly requires understanding that TCP is essentially a method of transmitting a data stream, so it is the data stream that should be investigated, not individual segments.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;To properly deal with evasions and inspect the traffic, the Network Security Device must understand it thoroughly. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;There is no substitute for an in-depth understanding of the networking protocols used. That understanding must not be limited to proper usage of the protocols, but must encompass also the behavior of typical endpoint systems when subjected to improper protocol usage. That understanding must also be dynamic and&amp;nbsp;adaptable. The Internet is in a never-ending change process. Even though there are things that at least seem static, there are continuous changes even in the basic building blocks of the Net. The pace of change requires a lot of flexibility and updatability from the network security devices. Network security devices cannot be static appliances but they must be updated regularly and effortlessly.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-----------------------------------------------------------------------------------------------&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Bio&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Olli-Pekka Niemi has been working in the area of Internet security since 1996. Since 2000, he has worked at Stonesoft’s R&amp;amp;D department, developing Stonesoft's StoneGate network security solutions. His main areas of responsibility include the analysis of network based attacks and attack methods as well as the research of new detection and analysis methods that could be implemented into StoneGate network security solutions. Mr. Niemi is also the Head of the Stonesoft Vulnerability Analysis Goup (VAG). Before joining Stonesoft Mr. Niemi worked at KPMG Information Risk Management, where he mainly focused on penetration testing and security audits. He has also worked as a system administrator at the Helsinki University of Technology.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-6993124734293364067?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/6993124734293364067/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/olli-pekka-niemi-dealing-with-evasions.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6993124734293364067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/6993124734293364067'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/olli-pekka-niemi-dealing-with-evasions.html' title='Olli-Pekka Niemi - Dealing with evasions'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-EhnNXMSIQCg/TgmAXl4QKQI/AAAAAAAAARw/Af8aqX5QjP0/s72-c/Olli-Pekka-Niemi.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-3606807484307291051</id><published>2011-06-26T13:09:00.000+02:00</published><updated>2011-06-26T13:09:55.057+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 26 Giugno 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Here is my new listing of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Enjoy it&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/CcureIT"&gt;@CcureIT&lt;/a&gt; Cyber police stymied by hackers &lt;a href="http://dlvr.it/WwtVd"&gt;http://dlvr.it/WwtVd&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/secuobsrevueus"&gt;@secuobsrevueus&lt;/a&gt; Attack Simulation and Threat Analysis of Banking Malware-Based Attacks &amp;nbsp;&lt;a href="http://bit.ly/k3IOtA"&gt;http://bit.ly/k3IOtA&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/nigroeneveld"&gt;@nigroeneveld&lt;/a&gt; Turning The iPad Into A Weapon &lt;a href="http://bit.ly/iCLOwS"&gt;http://bit.ly/iCLOwS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/regsecurity"&gt;@regsecurity&lt;/a&gt; Google Chrome extension detects dangerous websites &lt;a href="http://bit.ly/m3irqb"&gt;http://bit.ly/m3irqb&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/europeanprivacy"&gt;@europeanprivacy&lt;/a&gt; USA Today article discussing U.S. consumers and the cloud: &lt;a href="http://usat.ly/kDI21H"&gt;http://usat.ly/kDI21H&lt;/a&gt; &lt;a href="http://fb.me/BHtfGi0p"&gt;http://fb.me/BHtfGi0p&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/mikkohypponen"&gt;@mikkohypponen&lt;/a&gt; So, why on earth do people write malware? Well, here's 74 million reasons why: &lt;a href="http://1.usa.gov/lnKnCB"&gt;http://1.usa.gov/lnKnCB&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-3606807484307291051?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/3606807484307291051/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-26-giugno-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3606807484307291051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/3606807484307291051'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-26-giugno-2011.html' title='Best of the Week - 26 Giugno 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-552845970868234440</id><published>2011-06-19T10:53:00.000+02:00</published><updated>2011-06-19T10:53:35.196+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the Week - 19 Giugno 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;After my coming back home from Brussels (I partecipated in the "&lt;a href="http://ec.europa.eu/information_society/digital-agenda/daa/programme/index_en.htm" target="_blank"&gt;First Digital Agenda Assembly&lt;/a&gt;" as you can read in my &lt;a href="http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-1.html" target="_blank"&gt;recent posts&lt;/a&gt;), I can publish the weekly listing of my favorite security resources.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@zmcki001" target="_blank"&gt;@zmcki001&lt;/a&gt;: Good article and video from &lt;a href="http://twitter.com/@CiscoSecurity" target="_blank"&gt;@CiscoSecurity&lt;/a&gt; on Social Engineering. &lt;a href="http://goo.gl/h8AZm" target="_blank"&gt;goo.gl/h8AZm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@nigroeneveld" target="_blank"&gt;@nigroeneveld&lt;/a&gt; Swiss: Defence minister ponders cyber-security &lt;a href="http://bit.ly/jgNRDF" target="_blank"&gt;http://bit.ly/jgNRDF&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CertSG" target="_blank"&gt;@CertSG&lt;/a&gt; Happy to announce the release of our 8th IRM (Incident Response Methodology) &lt;a href="http://bit.ly/mxb82p" target="_blank"&gt;http://bit.ly/mxb82p&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@marcoriccardi" target="_blank"&gt;@marcoriccardi&lt;/a&gt; Italian honeynet chapter report for 2010 just published &lt;a href="http://lnkd.in/WgYc_M" target="_blank"&gt;http://lnkd.in/WgYc_M&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@iseclaborg" target="_blank"&gt;@iseclaborg&lt;/a&gt; Blog posting on Botmagnifier for locating Spambots: iSecLab blog: &lt;a href="http://wp.me/p17xdu-7B" target="_blank"&gt;http://wp.me/p17xdu-7B&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@_x4o" target="_blank"&gt;@_x4o&lt;/a&gt; Syria Uses Cyber Warfare to Attack Pro-Democracy Supporters - FoxNews.com &lt;a href="http://ow.ly/5gY4p" target="_blank"&gt;http://ow.ly/5gY4p&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-552845970868234440?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/552845970868234440/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-19-giugno-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/552845970868234440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/552845970868234440'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-19-giugno-2011.html' title='Best of the Week - 19 Giugno 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-1555776791648395029</id><published>2011-06-17T15:19:00.000+02:00</published><updated>2011-06-17T15:19:30.904+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Agenda Assembly'/><title type='text'>Digital Agenda Assembly - Day 2</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6nhyro6YDWc/TftSRNzl0kI/AAAAAAAAARo/H9GTvoXYINU/s1600/Digital-Agenda-Assembly-1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-6nhyro6YDWc/TftSRNzl0kI/AAAAAAAAARo/H9GTvoXYINU/s1600/Digital-Agenda-Assembly-1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Eccoci arrivati al secondo giorno della Digital Agenda Assembly. &lt;a href="http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-1.html"&gt;Come ieri&lt;/a&gt; la mattina è stata gestita con workshop paralleli e il pomeriggio con una sessione plenaria. Io ho partecipato, questa volta come semplice uditore, al workshop dal titolo "&lt;a href="http://ec.europa.eu/information_society/events/cf/daa11/item-display.cfm?id=5999"&gt;Towards a Cloud Computing strategy for Europe: Matching supply and demand&lt;/a&gt;". Nel seguito trovate alcuni messaggi estratti dagli interventi che mi hanno colpito maggiormente.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Pilar del Castillo Vera&lt;/b&gt; (MEP, Member of the Commitee on Industry, Research and Energy)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La riflessione politica inizia con la presa di coscienza che, al momento, il cloud è dominato dalle sole forze economiche del mercato e quindi deve&amp;nbsp;essere valutato un riequilibrio che preveda anche il contributo della visione strategica della politica. La sicurezza pone i maggiori problemi per una generale adozione delle cloud. I clienti devono avere ampie assicurazioni che i loro dati siano gestiti in maniera sicura. La mancanza di standard e la mancanza di interoperabilità sono dei limiti sui quali si dovrà lavorare molto per superare gli attuali limiti. Nella visione proposta da del Castillo Vera, i governi e la commissione devono avere la possibilità di regolare il mercato nel campo della Data Protection allo scopo di rendere maggiormente competitivo il mercato e per creare le condizioni per le quali sia possibile accedere a questi servizi in maniera ampia e sicura.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Thomas Endres&lt;/b&gt; (Senior VP Corporate Information Management and CIO Deutsche Lufthansa AG)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tutti i benefici delle cloud, che sono stati ormai ben disegnati, sono raggiungibili solo se i rischi e i relativi controlli&amp;nbsp;sono stati preventivamente e adeguatamente valutati. Solo poche grandi società europee sfruttano servizi cloud &amp;nbsp;a causa della&amp;nbsp;mancanza di standard e di best practice. Deve essere costruita una fiducia maggiore su questi servizi. Servirebbe una&amp;nbsp;legislazione simile a quella che regola gli spostamenti delle merci via mare che dia garanzia a clienti e fornitori sui&amp;nbsp;rispettivi diritti e doveri. La presenza di subforniture dovrebbe essere resa esplicita e i clienti dovrebbero poter dare la&amp;nbsp;propria approvazione su queste scelte.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Moises Navarro Martin&lt;/b&gt; (Director, Cloud Strategy &amp;amp; Services, Telefonica)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La grande importanza delle cloud è nei risparmi che possono essere realizzati. La seconda ragione per la quale può essere&amp;nbsp;importante adottare servizi cloud è l'innovazione. Innovare attraverso l'utilizzo delle cloud è molto più semplice e diretto&amp;nbsp;soprattutto per le piccole e medie imprese che possono così compensare la loro mancanza di strumenti IT. Anche il mondo&amp;nbsp;accademico può godere di grandi benefici nel campo dell'innovazione attraverso l'utilizzo delle cloud. Una raccomandazione&amp;nbsp;per l'Europa nell'approccio alle cloud: pragmatismo. I trend per il futuro prevedeono : elasticità, federazione e&amp;nbsp;interoperabilità delle cloud e lo sviluppo di servizi di personal cloud (e Steve Jobs se la ride...)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Silvana Koch-Mehrin&lt;/b&gt; (MEP)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come politico, inizia chiedendosi quale possa essere il ruolo della politica in un settore tecnologico dominato da&amp;nbsp;dinamiche economiche. La risposta è nelle potenzialità nel campo dell'innovazione devono essere indirizzate e sfruttate al massimo delle loro possibilità con uno specifico ruolo per il legislatore e per la politica in generale proprio in questo campo. Da questo punto di vista le risposte che possono essere messe in campo dalla politica sono:&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- una generale semplificazione per l'acccesso e la fruizione dei servizi&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- lo stanziamento di fondi per le migliori idee e gli approcci più innovativi.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Daniele Catteddu&lt;/b&gt; (esperto di sicurezza e resilienza di ENISA... e buon amico)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Il corso delle cloud sarà come quello degli altri fenomeni che hanno caratterizzato l'IT in questi anni. Il periodo in cui&amp;nbsp;daranno il massimo dei benefici sarà di circa 10-15 anni, quindi non possiamo aspettare molto per avere dei risultati è tempo&amp;nbsp;di agire. L'interoperabilità è centrale per lo sviluppo delle cloud a livello di:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- policy&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- tecnologie&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- gestione delle identità&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- sicurezza&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- conformità legale e normativa.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La mancanza di interoperibilità si riflette in una serie di rischi che spaziano dalle problematiche di disponibilità dei&amp;nbsp;servizi, al cosiddetto "lock-in".&amp;nbsp;Da questo punto di vista, FedRAMP è un buon esempio per come realizzare un approccio agile ed efficace.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Cosa si può fare?&amp;nbsp;Standardizzare, standardizzare, standardizzare. Le interfacce, i formati&amp;nbsp;dei log e degli audit, la gestione delle chiavi e i sistemi di gestione delle identità.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ci sono stati vari momenti di dibattito con il pubblico in cui sono emersi temi interessanti tra cui:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- una domanda importante a cui deve essere data una risposta è come sia possibile creare le conidizioni per le quali dati provenienti da tutto il mondo siano gestiti da cloud europee e non solo creare le condizioni perché i dati europei possano essere gestiti in cloud internazionali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- al momento, l'Europa non è in grado di dare risposte legislative rapide che siano adottatate da tutti i paesi membri. Questa situazione rende molto difficile per le istituzioni europee dare un vero indirizzo nei temi tecnologici che invece sono caratterizzati da un'estrema rapidità di adozione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- è importante stabilire se in futuro si procederà verso un'integrazione dei sistemi di gestione delle identità o se invece sarà adottato un sistema di gestione delle identità terzo rispetto ai Cloud Service Provider.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come commento finale vorrei aggiungere che il Workshop è stato &amp;nbsp;un buon successo e che ho sentito molte cose interessanti anche se in generale ho trovato un tasso di&amp;nbsp;messaggi orientati al marketing superiore a quello che mi sarei aspettato.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Se nella sessione plenaria di oggi pomeriggio emergeranno argomenti interessanti dal punto di vista della sicurezza li troverete in un aggiornamento nei prossimi giorni.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-1555776791648395029?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/1555776791648395029/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-2.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1555776791648395029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/1555776791648395029'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-2.html' title='Digital Agenda Assembly - Day 2'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-6nhyro6YDWc/TftSRNzl0kI/AAAAAAAAARo/H9GTvoXYINU/s72-c/Digital-Agenda-Assembly-1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4962802104969698979</id><published>2011-06-16T21:52:00.002+02:00</published><updated>2011-06-19T10:19:32.041+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Agenda Assembly'/><title type='text'>Digital Agenda Assembly - Day 1</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-L2LcLFicoYk/TfpdKF9qh9I/AAAAAAAAARk/1q5aaZ0VTD4/s1600/Digital-Agenda-Assembly.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="212" src="http://3.bp.blogspot.com/-L2LcLFicoYk/TfpdKF9qh9I/AAAAAAAAARk/1q5aaZ0VTD4/s320/Digital-Agenda-Assembly.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Riassunto grafico della conferenza disegnato durante la Plenaria&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Oggi ho avuto il piacere e l'onore di partecipare alla prima Conferenza dedicata alla strategia digitale europea.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;L'organizzazione della conferenza prevedeva una serie di workshop paralleli nel corso della mattinata e poi una sessione&amp;nbsp;plenaria nel pomeriggio.&lt;br /&gt;&lt;br /&gt;Alla mattina ho partecipato al Workshop dedicato al tema "&lt;a href="http://ec.europa.eu/information_society/events/cf/daa11/item-display.cfm?id=5985"&gt;Cybersecurity: barriers and incentives&lt;/a&gt;"&amp;nbsp;che era moderato da Eneken Tikk, Head of Legal and Policy Branch del CCDCOE (Cooperative Cyber Defence Centre of Exellence di Tallin). Il workshop prevedeva una prima sessione con tre presentazioni e una tavola rotonda dopo il coffee break.&lt;br /&gt;&lt;br /&gt;Io ho&amp;nbsp;aperto la sessione delle presentazioni con un intervento dal titolo: "Cybersecurity: State of the Art and Future Trends in&amp;nbsp;Italy" che ha tratteggiato le varie iniziative che sono state avviate in Italia (se date un'occhiata alle slide appena le pubblicano, avrete delle&amp;nbsp;piacevoli sorprese...). E, come è successo al Security Summit di Roma, il pubblico ha riservato una grande attenzione alla&amp;nbsp;proposta di realizzazione di un AntiBotnet Center Italiano. A seguire è stata la volta di Karim Antonio Lesina, Executive&amp;nbsp;Director EMEA Government Affairs di AT&amp;amp;T, che ha fatto una presentazione molto interessante ponendo una grande attenzione ai temi della collaborazione internazionale, della lotta alle botnet (abbiamo poi avuto&amp;nbsp;un'amabile chiacchierata in proposito) e ell'evoluzione dell'approccio verso la cybersecurity. Fantastica la foto della loro&amp;nbsp;sala operativa di sicurezza negli Stati Uniti (Global NOC); penso che neanche nei sogni più felici uno possa immaginare un&amp;nbsp;posto così. Lavorare in un ambiente del genere deve essere davvero spettacolare!&amp;nbsp;L'ultima presentazione è stata di Michel J.G. van Eeten, della&amp;nbsp;&amp;nbsp;Delft University of Technology. In questa presentazione si è approcciato al tema della&amp;nbsp;responsabilità nella sicurezza che hanno gli Internet Service Provider. L'analisi era basata su dati quantitativi e mostrava,&amp;nbsp;tra l'altro che, anche normalizzando i dati per tenere conto della dimensione dei provider, la lista dei Top 50 ISP che&amp;nbsp;contribuiscono maggiormente allo spam mondiale è quasi immutata da 4 anni. Infatti nei Top 50, ben 32 ISP sono stabilmente&amp;nbsp;presenti ogni anno.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I temi che invece sono emersi nella Tavola Rotonda (i panelist erano: Kurt Erik Lindqvist, CEO di Netnod un provider svedese, Mika Lauhde di Nokia e Michel J.G. van Eeten della Delft University of Technology) sono stati:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- la cybersecurity non è solo una questione tecnologica ma passa attraverso le agende dei politici e anche delle persone del&amp;nbsp;marketing&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- le interdipendenze tra diversi settori e tra Stati sono sempre più significative&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- è necessario una approccio internazionale alla lotta al cybercrime&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- dal punto di vista nazionale non è strettamente necessaria l'adozione di nuove leggi ma bisognerebbe riuscire a proseguire&amp;nbsp;con gli sforzi messi in campo sinora&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- le Public-Private Partneships sono il futuro della cybersecurity&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- il tema dell'Information Sharing è essenziale&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- tutti devono sentirsi coinvolti perchè il tema della sicurezza in un mondo globale non può che avere un approccio globale.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, la riunione plenaria. La Vice Presidente della Commissione Europea Neelie Kroes ha fatto un grande discorso, citando&amp;nbsp;molti temi importanti e centrali per crescita digitale dell'Europa. La visione strategica che ha saputo rappresentare mi è&amp;nbsp;sembrata molto vicina a quella espressa dal Presidente Obama in molti suoi discorsi sul tema della tecnologia. Inoltre ho&amp;nbsp;avuto il piacere di verificare che una figura di così alto livello ha una sensibilità verso i temi della sicurezza davvero&amp;nbsp;ammirevole. Nella visione della Kroes infatti la sicurezza è vista come un tema centrale per lo sviluppo armonico e&amp;nbsp;strategico dell'economia digitale in Europa.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Domani il resoconto del &lt;a href="http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-2.html"&gt;giorno 2&lt;/a&gt; (se non svengo prima per la stanchezza...)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;PS una piccola nota di colore... nel corso della riunione plenaria c'era un servizio di traduzione per i non udenti con due&amp;nbsp;bravissimi interpreti che, in tempo reale, trasformavano le parole pronunciate dagli speaker in altrettanti gesti ed&amp;nbsp;espressioni. Ebbene, uno dei due era la copia di Umberto Bossi (forse un po' più giovane) e aveva però una mimica facciale e&amp;nbsp;una gestualità degna del miglior Dario Fo. Non so se sono riuscito a rendere l'effetto, ma vi assicuro che per un italiano&amp;nbsp;era veramente esilarante...&amp;nbsp;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4962802104969698979?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4962802104969698979/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-1.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4962802104969698979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4962802104969698979'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/digital-agenda-assembly-day-1.html' title='Digital Agenda Assembly - Day 1'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-L2LcLFicoYk/TfpdKF9qh9I/AAAAAAAAARk/1q5aaZ0VTD4/s72-c/Digital-Agenda-Assembly.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5325836453839482880</id><published>2011-06-12T15:36:00.000+02:00</published><updated>2011-06-12T15:36:49.044+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 12 giugno 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" width="170" /&gt;&lt;/a&gt;&lt;/div&gt;Another week is gone and now it's time to propose my listing of the  best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enojoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@klightowler"&gt;@klightowler&lt;/a&gt; Pentagon Has Secret List of Cyberweapons - FoxNews.com &lt;a href="http://fxn.ws/kGGFMt"&gt;http://fxn.ws/kGGFMt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@stefan_frei"&gt;@stefan_frei&lt;/a&gt; Six ways sensitive data finds its way to personal email accounts &amp;lt;- good list &lt;a href="http://bit.ly/iIUwwh"&gt;http://bit.ly/iIUwwh&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/#!/suffert"&gt;@suffert&lt;/a&gt; Powerful forensic tool for Android devices released &lt;a href="http://flpbd.it/qM5m"&gt;http://flpbd.it/qM5m&lt;/a&gt; by &lt;a href="http://twitter.com/@viaforensics"&gt;@viaforensics&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@DarkReading"&gt;@DarkReading&lt;/a&gt; RSA breach "a direct contributing factor" in Lockheed's breach, but the devil's in the details: &lt;a href="http://tinyurl.com/3ekdp7s"&gt;http://tinyurl.com/3ekdp7s&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@regsecurity"&gt;@regsecurity&lt;/a&gt; Microsoft goes botherder hunting in streets of Russia &lt;a href="http://bit.ly/mAuefD"&gt;http://bit.ly/mAuefD&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@StopBlackMarket"&gt;@StopBlackMarket&lt;/a&gt; Bitcoin, la moneta degli hacker che spaventa Cia e banche &lt;a href="http://bit.ly/ko7k2V"&gt;http://bit.ly/ko7k2V&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5325836453839482880?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5325836453839482880/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-12-giugno-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5325836453839482880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5325836453839482880'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-12-giugno-2011.html' title='Best of the week - 12 giugno 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-34909800656943673</id><published>2011-06-10T17:17:00.002+02:00</published><updated>2011-06-10T17:21:27.604+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Summit'/><title type='text'>Security Summit 2011 - Day 2</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s1600/SecuritySummit.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s1600/SecuritySummit.jpg" t8="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Eccoci arrivati al resoconto della seconda giornata del Security Summit 2011 di Roma.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La mia seconda giornata al Summit è iniziata molto bene... ho partecipato ad un interessantissimo talk di &lt;a href="http://it.linkedin.com/pub/gabriele-faggioli/0/432/5b1" target="_blank"&gt;Gabriele Faggioli&lt;/a&gt;&amp;nbsp; dal titolo: "I servizi “cloud”: problemi legali e contrattuali". Faggioli è partito con una puntuale analisi dei contratti tipici delle forniture IT classiche per poi passare in rassegna gli aspetti più rilevanti dei contratti di outsourcing e arrivare infine ai contratti tipici del mondo cloud.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Tra le notazioni che mi hanno più colpito c'è il riferimento all'utilizzo del&amp;nbsp;contratto di licenza d'uso in alcuni contratti per servizi cloud che (giustamente) Faggioli inquadra come non adatto. Secondo Faggioli, la tipologia che si adatta meglio ai&amp;nbsp;servizi cloud (ovviamente dal punto di vista&amp;nbsp;del Cloud Service Consumer) è quella relativa ai contratti d'appalto di servizi con obbligazione di risultato.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'intervento di Faggioli si è concluso con una lista di verifiche che dovrebbero essere sempre effettuate prima di accettare un contratto di servizi cloud:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Qual'è la qualifica del fornitore (Responsabile privacy)?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Quali tipologie di dati vengono trasferite "on the cloud"?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Quali sono gli eventuali subfornitori?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Dove sono le infrastrutture?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Quali misure di sicurezza hanno i provider e i loro subfornitori?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Come si effettua la nomina del provider e dei suoi subfornitori?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Quali sono le previsioni contrattuali?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Quali sistemi di controllo devo prevedere?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Ci sono impatti in termini di 231/01?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dopo questo intervento mi sono incontrato con &lt;a href="http://nl.linkedin.com/in/cguarnieri" target="_blank"&gt;Claudio Guarnieri&lt;/a&gt; e &lt;a href="http://it.linkedin.com/in/felicianointini" target="_blank"&gt;Feliciano Intini&lt;/a&gt; e abbiamo concordato la nostra presentazione pomeridiana dedicata alla lotta alle botnet. Non ho potuto quindi seguire altri interventi. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nel primo pomeriggio, invece sono riuscito a vedere una parte del seminario di &lt;a href="http://www.linkedin.com/in/go4it/it" target="_blank"&gt;Marco Morana&lt;/a&gt; (altra guest star di questa edizione del Summit) e oltre alla gioia&amp;nbsp;di rincontrarlo (avevo avuto il piacere di ospitarlo nella prima edizione dell'&lt;a href="https://www.owasp.org/index.php/Italy_OWASP_Day_E-Gov_09#tab=Introduction" target="_blank"&gt;OWASP Day per la PA&lt;/a&gt;), ho avuto modo di avere alcuni flash sulla nuova metodologia per la simulazione degli attacchi e per l’analisi delle minacce che si chiama PASTA (Process for Attack Simulation e Threat Analysis). Molto interessante!!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Infine, in un auditorium che poteva essere più ricco di presenze... (abbiamo iniziato con poco meno di trenta persone) Feliciano, Claudio ed io abbiamo presentato il workshop dal titolo "Botnet Delenda Est" dedicato agli iscritti al gruppo linkedin "Italian Security Professional".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ho personalemente trovato i lavori di Claudio e Feliciano estremamente interessanti. Claudio ha presentato un lavoro di investigazione su KoobFace (&lt;a href="http://twitter.com/@drego85" target="_blank"&gt;@drego85&lt;/a&gt; ecco la tua risposta! ;-)) ), veramente aggiornato e completo. Nella migliore tradizione dei lavori di questo tipo c'erano una serie di slide che non saranno pubblicate perchè il contenuto è, diciamo così, "sensibile".&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Feliciano, dal canto suo, ha portato una serie di informazioni che venivano direttamente dalla Microsoft Digital Crime Unit, sui take down di Rustock e Coreflood. Avevo visto una precedente versione di questa presentazione (in un consesso chiuso e altamente qualificato) e, in tutta onestà, posso affermare che Felicaino è riuscito a valorizzarla&amp;nbsp;con dati e informazioni nuove facendola diventare ancor più interessante e ricca.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per quanto mi riguarda, ho fatto un inquadramento generale del tema botnet esponendo i motivi per i quali siamo convinti che&amp;nbsp;questi strumenti&amp;nbsp;in mano ai&amp;nbsp;cybercriminali debbano essere "distrutti",&amp;nbsp;per poi&amp;nbsp;concludere parlando della situazione italiana e presentare la proposta della creazione di un AntiBotnet Center Italiano (ABC-I). Il prezi della mia presentazione è già &lt;a href="http://prezi.com/lkvcf2iakfau/botnet-delenda-est/" target="_blank"&gt;online&lt;/a&gt;, per le altre presentazioni dovrete attendere la pubblicazione degli atti del convegno.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ancora grazie agli organizzatori e... ci vediamo il prossimo anno!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;﻿&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-34909800656943673?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/34909800656943673/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/security-summit-2011-day-2.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/34909800656943673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/34909800656943673'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/security-summit-2011-day-2.html' title='Security Summit 2011 - Day 2'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s72-c/SecuritySummit.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7956689400635345598</id><published>2011-06-09T13:36:00.001+02:00</published><updated>2011-06-10T11:31:44.543+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conferenza'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Summit'/><title type='text'>Security Summit 2011 - Day 1</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s1600/SecuritySummit.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s1600/SecuritySummit.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Anche quest'anno siamo arrivati al fatidico appuntamento con il Security Summit di Roma che si conferma come una delle iniziative più interessanti nel campo della security in Italia. &lt;a href="https://www.securitysummit.it/eventi/giorno/8" target="_blank"&gt;Il programma&lt;/a&gt; ha proposto un ventaglio di talk di alto livello che hanno coperto le maggiori problematiche di sicurezza. Inoltre la valenza di quest'evento per fare network e rivedere o conoscere persone che si occupano di sicurezza è davvero impagabile.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ma veniamo al racconto delle giornate, che quest'anno sarà parziale perché, avendo una presentazione da fare, non potuto seguire tutti gli interventi che avrei voluto.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Convegno di apertura - Tavola rotonda "Le nuove frontiere dell'ICT Security"&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come già successo nelle precedenti edizioni la tavola rotonda è stata moderata dal'effervescente Gigi Tagliapietra che ha messo subito in chiaro quanto senta limitante per lui il ruolo di moderatore al quale certamente preferisce quello di "provocatore". Questa attitudine, oltre alla sua consueta capacità di analisi, ha fatto salire il livello generale della tavola rotonda che è così stata sempre stimolante e divertente.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La "guest star" di&amp;nbsp;questa&amp;nbsp;edizione era &lt;a href="http://www.enisa.europa.eu/about-enisa/structure-organization/executive-director" target="_blank"&gt;Udo Helmbrecht&lt;/a&gt;, Direttore esecutivo di &lt;a href="http://www.enisa.europa.eu/" target="_blank"&gt;ENISA&lt;/a&gt;, l'agenzia europea &amp;nbsp;per la sicurezza delle reti. Assieme a Helmbrecht erano presenti &lt;a href="http://www.isticom.it/index.php/direttore" target="_blank"&gt;Rita Forsi&lt;/a&gt;, direttore generale dell'Istituto Superiore delle Comunicazioni, J.P. Ballerini di IBM, Alessandro Vallega di Oracle e Gastone Nencini di TrendMicro.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Helmbrecht, ha presentato ENISA e le attività che ha svolto in questi anni evidenziando gli attuali limiti entro i quali ENISA opera, lavorando per progetti che vengono decisi su base annuale e non potendo sovrapporsi al ruolo dei "decision maker" nazionali. In particolare è stato evidenziato come in Europa manchi un ente che abbia invece un ruolo operativo sulla security e come ENISA stia collaborando con la Commissione per riuscire a sanare questa situazione, tenendo conto degli ambiziosi progetti che sono legati alla visione europea per il futuro (nel 2020 il punto di arrivo è Every European Digital).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Helmbrecht ha poi ricordato le iniziative di ENISA nel campo della cybersecurity, del cloud computing, dei social network e della mobile security. In generale è stato un intervento ricco di spunti e di riflessioni sul futuro che ci attende e sulla reali capacità di inserire "correttivi" in tecnologie o contesti dove il driver del mercato &amp;nbsp;è fortissimo. Un esempio per tutti: la mancanza di regole per la portabilità dei dati e l'interoperabilità nel cloud computing o, peggio ancora, nei social network.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nella successiva discussione i relatori hanno trovato modo di approfondire e dare un taglio personale ai vari argomenti, arricchendo con sfumature interessanti i vari aspetti che Gigi Tagliapietra, di volta in volta, sottolineava o proponeva. Tra i temi che sono emersi con maggior forza ci sono:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Internet è un elemento in&amp;nbsp;grado&amp;nbsp;di cambiare i comportamenti umani con maggiore incisività rispetto a leggi e regolamenti;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- le Public-Private Partnership rappresentano il futuro della sicurezza perché consentono di affrontare ostacoli altrimenti insuperabili;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- nessun soggetto pubblico o privato è in grado di affrontare con efficacia le maggiori problematiche di sicurezza attraverso un approccio "solitario";&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- la cultura della sicurezza deve crescere raggiungendo i cittadini.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A proposito di quest'ultimo punto, Rita Forsi ha ribadito che l'Italia, anche per rispondere alle sempre più&amp;nbsp;pressanti&amp;nbsp;richieste provenienti dalla Unione Europea, sta lavorando per dotarsi di un CERT governativo/nazionale che dovrebbe vedere la luce nei prossimi mesi. Notizia che già da sola vale la partecipazione a quest'evento.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nel pomeriggio ho poi visto la presentazione di Alessio Pennasilico e Gastone Nencini sulla protezione delle infrastrutture virtuali. Come al solito gli standard di presentazione di Alessio sono molto alti e ci sono stati numerosi spunti per un corretto approccio alla sicurezza nella predisposizione di un ambiente virtuale. Sono stati inoltre messi in evidenza gli errori più frequenti e le più tipiche sottovalutazioni che vengono purtroppo fatte quando si passa da una infrastruttura composta da elementi reali a una invece basata sulla virtualizzazione.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'ultimo talk della giornata è stato... il mio. E visto che è impossibile parlare di se stessi con un minimo di obiettività... non lo farò! Vi dico solo che ho affrontato il tema della Cloud Security e che nel corso della presentazione ho annunciato di aver scritto un whitepaper sull'argomento che sarà pubblicato a breve come &lt;a href="http://www.consip.it/on-line/Home/Pressroom/QuaderniConsip.html" target="_blank"&gt;Quaderno Consip&lt;/a&gt;. Il Quaderno dal titolo "Cloud Security: una sfida per il futuro" sarà presentato ufficialmente nel corso di un evento che si terrà il prossimo 6 luglio in Consip. Nei prossimi giorni, scriverò più diffusamente di questo evento e vi darò maggiori dettagli.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Le altre sessioni della giornata erano dedicate al ROSI Return On Security Investement), alla gestione federata delle identità nel cloud, al rischio informatico nelle piccole imprese e alla Data Leakage Prevention.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Nel prossimo post il resoconto del Day 2.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A presto!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7956689400635345598?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7956689400635345598/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/security-summit-2011-day-1.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7956689400635345598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7956689400635345598'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/security-summit-2011-day-1.html' title='Security Summit 2011 - Day 1'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-RLF3ivRlYXc/TfCcQnh1mdI/AAAAAAAAARg/q5t1aIgtNZA/s72-c/SecuritySummit.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-5311133212339862423</id><published>2011-06-05T09:03:00.001+02:00</published><updated>2011-06-05T09:32:46.782+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='sicurezza informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 5 giugno 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" width="170" /&gt;&lt;/a&gt;&lt;/div&gt;Another week is passed so it's time to propose my listing of the best security resources of the week.&lt;br /&gt;&lt;br /&gt;Hope you enjoy it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@tofinosecurity" target="_blank"&gt;@tofinosecurity&lt;/a&gt; "Son of #Stuxnet" - Coming Soon to a #SCADA or PLC System Near You? - &lt;a href="http://bit.ly/jFzbI3" target="_blank"&gt;http://bit.ly/jFzbI3&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ECIOForum" target="_blank"&gt;@ECIOForum&lt;/a&gt; Surviving Security Breaches, the Bleak Outlook, and Hope &lt;a href="http://ow.ly/54GUd" target="_blank"&gt;http://ow.ly/54GUd&lt;/a&gt; #enterprisesecurity&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SCADAhacker" target="_blank"&gt;@SCADAhacker&lt;/a&gt; Pesca 0.75 Local Stealer - Download ! &lt;a href="http://goo.gl/fb/bSXte" target="_blank"&gt;http://goo.gl/fb/bSXte&lt;/a&gt; RT @TheHackersNews SH: great add to your security &lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@RKHilbertSpace" target="_blank"&gt;@RKHilbertSpace&lt;/a&gt;: Chinese hackers use the same backdoor required by US law to eavesdrop on Gmail accts. &lt;a href="http://j.mp/m98tYR" target="_blank"&gt;http://j.mp/m98tYR&lt;/a&gt; U.S. enables Chinese hacking of Google&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@stefan_frei" target="_blank"&gt;@stefan_frei&lt;/a&gt;: Video of my SwissCyberStorm talk and malware demo online &lt;a href="http://bit.ly/lVlhY0" target="_blank"&gt;http://bit.ly/lVlhY0&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@mikkohypponen" target="_blank"&gt;@mikkohypponen&lt;/a&gt; Sean from our Labs recommends using Bing for image searches. Here's why: &lt;a href="http://bit.ly/j73hXl" target="_blank"&gt;http://bit.ly/j73hXl&lt;/a&gt; [youtube, 7 mins]&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Imperva" target="_blank"&gt;@Imperva&lt;/a&gt; Anatomy of PDF Attack &lt;a href="http://bit.ly/mq3EFx" target="_blank"&gt;http://bit.ly/mq3EFx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-5311133212339862423?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/5311133212339862423/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-5-giugno-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5311133212339862423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/5311133212339862423'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/best-of-week-5-giugno-2011.html' title='Best of the week - 5 giugno 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-7429843490767450536</id><published>2011-06-04T18:16:00.000+02:00</published><updated>2011-06-04T18:16:27.429+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='MUMBLE'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='attacchi ai siti'/><category scheme='http://www.blogger.com/atom/ns#' term='riflessioni sicurezza'/><title type='text'>MUMBLE - Data Breach ecco perché andrà sempre peggio</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-JOnc56V2pdM/TepSDC9PijI/AAAAAAAAARc/FrZplS8b8gg/s1600/Data-Breach-sempre-peggio.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="165" src="http://4.bp.blogspot.com/-JOnc56V2pdM/TepSDC9PijI/AAAAAAAAARc/FrZplS8b8gg/s200/Data-Breach-sempre-peggio.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Ciao a tutti, oggi torno alla serie delle riflessioni sui temi della sicurezza con un argomento che arriva direttamente dalla cronaca di questi ultimi tempi: i data breach. Come avrete certamente avuto modo di notare, in questi ultimi due o tre mesi si sono concentrati una serie di episodi di una certa gravità (alcuni molto gravi per la verità) di violazioni di servizi Web che hanno portato al furto di una mole impressionante di dati personali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Come mai questa concentrazione? E cosa succederà nei prossimi tempi?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per chi non ha la voglia o il tempo di leggere il resto del post la mia conclusione è nel titolo... "andrà sempre peggio". Come sono arrivato a questa conclusione? Seguitemi e ve lo spiegherò.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'analisi che faccio parte da considerazioni tecniche per arrivare a conclusioni di tipo "sociale".&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Partiamo dalle considerazioni tecniche. Come abbiamo più volte sottolineato su Punto 1, il Web è pieno di siti che non hanno in alcuna considerazione le tematiche di sicurezza. Molto spesso, questi siti pieni di vulnerabilità sono anche molto popolari e, a volte, hanno anche delle transazioni a valore aggiunto (monetario e non) su grandi basi dati di utenti.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Questa situazione rappresenta il perfetto "humus" sul quale prolifera la mala pianta del cybercrime e delle pratiche affini. &lt;b&gt;Abbiamo quindi il primo pezzo per la nostra indagine "l'occasione".&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Rimaniamo nel campo della tecnica. Trovare script e tool per portare attacchi è ormai quasi più semplice che trovare un antivirus gratuito. Questi mezzi non presuppongono nessuna conoscenza tecnica reale e quindi consentono praticamente a chiunque di portare attacchi di grande impatto su siti vulnerabili (cioè quasi tutti i siti). &lt;b&gt;Ed ecco che qui si profila il secondo pezzo del nostro puzzle il "mezzo".&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Possiamo ora passare alla parte più "sociale"... i media stanno dando una grande copertura a questi eventi. Proprio ieri, parlando con una amica che non ha nessun interesse nella cybersecurity, mi veniva fatto notare come negli ultimi tempi questi temi siano saliti alla ribalta della stampa generalista di tutto il mondo e abbiano dunque acquisito una notorietà prima sconosciuta al grande pubblico. Inoltre, sui tempi brevi, è molto raro che le forze dell'ordine abbiano modo di concludere un'indagine. Si ha così una generale impressione di totale impunità legata ad una grande notorietà. Se poi passiamo alla copertura e al taglio&amp;nbsp;che molti giornali hanno riservato ad esempio alle notizie relative alle imprese degli "Anonymous" arriviamo alla costruzione di un'immagine da vero e proprio moderno "Robin Hood". Tutto ciò contribuisce a creare una fortissima voglia di emulazione che spinge molti a tentare la sorte per trovare il proprio quarto d'ora di notorietà. I reiterati episodi di hacking sui siti della Sony sono un esempio di questo fenomeno (e anche un esempio di come non si dovrebbero gestire i servizi Web di una grande corporation ;-)) ). &lt;b&gt;E finalmente siamo arrivati a raccogliere il terzo e ultimo pezzo della nostra indagine... il "movente".&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Non bisogna certo essere Ellery Queen per sapere che quando ci sono l'occasione, il mezzo e soprattutto il movente siamo nelle condizioni ideali per la commissione di un reato.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Quindi, andrà sempre peggio.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Fino a quando non si interromperà questa catena in qualche punto, ma per farlo bisogna che tutti quelli che si occupano a vario titolo di sicurezza lavorino duramente per cambiare uno scenario che, al momento, resta davvero fosco.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Buona domenica a tutti.&amp;nbsp;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-7429843490767450536?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/7429843490767450536/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/06/mumble-data-breach-ecco-perche-andra.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7429843490767450536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/7429843490767450536'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/06/mumble-data-breach-ecco-perche-andra.html' title='MUMBLE - Data Breach ecco perché andrà sempre peggio'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-JOnc56V2pdM/TepSDC9PijI/AAAAAAAAARc/FrZplS8b8gg/s72-c/Data-Breach-sempre-peggio.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4176106086910833784</id><published>2011-05-29T09:07:00.000+02:00</published><updated>2011-05-29T09:07:41.771+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='Best of the Week'/><title type='text'>Best of the week - 29 maggio 2011</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" imageanchor="1" style="clear:left; float:left;margin-right:1em; margin-bottom:1em"&gt;&lt;img border="0" height="172" width="170" src="http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s1600/Best-of-the-Week.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hi all, that's my listing of the Best Security resources of this week. &lt;br /&gt;&lt;br /&gt;Enjoy it!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@SophosLabs" target="_blank"&gt;@SophosLabs&lt;/a&gt;: Free tech paper: What is Zeus? Notorious malware under the microscope &lt;a href="http://bit.ly/lpyj4l" target="_blank"&gt;http://bit.ly/lpyj4l&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@CloudSOC" target="_blank"&gt;@CloudSOC&lt;/a&gt;: Cyber war on hearts and minds - &lt;a href="http://cloudsoc.net/1X" target="_blank"&gt;http://cloudsoc.net/1X&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@ChetWisniewski" target="_blank"&gt;@ChetWisniewski&lt;/a&gt;: Apple continues policy of refusing to help infected customers, ZDNet estimates 60,000 or more &lt;a href="http://bit.ly/kHeW2P" target="_blank"&gt;http://bit.ly/kHeW2P&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@TrendLabs" target="_blank"&gt;@TrendLabs&lt;/a&gt;: The objectives of highly targeted attacks can range from financial theft to corporate espionage &lt;a href="http://bit.ly/mPNaGc" target="_blank"&gt;http://bit.ly/mPNaGc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@Cenzic" target="_blank"&gt;@Cenzic&lt;/a&gt;: Bank of America breach - a big, scary story &lt;a href="http://fb.me/YNvPfmS6" target="_blank"&gt;http://fb.me/YNvPfmS6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@suffert" target="_blank"&gt;@suffert&lt;/a&gt; Hardening OS X Using The NSA Guidelines &lt;a href="http://flpbd.it/XghR" target="_blank"&gt;http://flpbd.it/XghR&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/@InfosecurityMag" target="_blank"&gt;@InfosecurityMag&lt;/a&gt;: New England works to coordinate government-industry response to cyber attacks &lt;a href="http://bit.ly/j4kZuG" target="_blank"&gt;http://bit.ly/j4kZuG&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4981981113585921735-4176106086910833784?l=www.matteocavallini.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.matteocavallini.com/feeds/4176106086910833784/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.matteocavallini.com/2011/05/best-of-week-29-maggio-2011.html#comment-form' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4176106086910833784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4981981113585921735/posts/default/4176106086910833784'/><link rel='alternate' type='text/html' href='http://www.matteocavallini.com/2011/05/best-of-week-29-maggio-2011.html' title='Best of the week - 29 maggio 2011'/><author><name>Matteo Cavallini</name><uri>http://www.blogger.com/profile/14424950254783229133</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://2.bp.blogspot.com/_Q63lRxU9Ezw/S-XCrd6NZEI/AAAAAAAAADE/8tOVsyLeojk/S220/Matteo-Cavallini.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-P94Qr11fdzY/TU1l4FWKl1I/AAAAAAAAAPA/3mx-J_mNZjA/s72-c/Best-of-the-Week.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4981981113585921735.post-4318023128586042117</id><published>2011-05-26T18:19:00.001+02:00</published><updated>2011-05-26T18:21:20.212+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='criminalità informatica'/><category scheme='http://www.blogger.com/atom/ns#' term='Youtube'/><title type='text'>Un nuovo "scam" per YouTube</title><content type='html'>&lt;div style="text-align: justify;"&gt;I cattivi hanno una fantasia davvero sconfinata. Ecco uno&amp;nbsp;&lt;a href="http://it.wikipedia.org/wiki/Scam"&gt;scam&lt;/a&gt;&amp;nbsp;che fa leva su una serie di pulsioni molto forti dell'animo umano: la curiosità e la vanità. Da una breve ricerca su google sembra che questo scam sia relativamente nuovo e in rapida espansione in Europa. Sul forum di YouTube &lt;a href="http://your%20video%20on%20the%20top%20of%20youtube/"&gt;è stata segnalato&lt;/a&gt;,&amp;nbsp;con alcune varianti minori nel testo, dal 24 maggio.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ax04qmloCsI/Td52nYK9hwI/AAAAAAAAARY/EWBWMlIa2ps/s1600/YouTube-scam.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="140" src="http://1.bp.blogspot.com/-ax04qmloCsI/Td52nYK9hwI/AAAAAAAAARY/EWBWMlIa2ps/s400/YouTube-scam.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Io ricevuto questa mail pochi minuti fa e devo dire che è molto ben realizzata nella sua semplicità. La mail fa leva su due&amp;nbsp;umanissimi&amp;nbsp;sentimenti per indurre l'utente a cliccare sulla URL proposta. Infatti, la tentazione di cliccare sul link è forte di fronte alla frase "&lt;b&gt;Your video on the TOP of YouTube&lt;/b&gt;".&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Moltissime persone hanno un canale su YouTube e la prima pulsione che si avverte è legata alla &lt;b&gt;curiosità&lt;/b&gt;:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- ma davvero un mio video ha avuto successo?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- e che video è?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Clic. Fregati.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;La seconda pulsione è invece legata alla &lt;b&gt;vanità&lt;/b&gt;:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- lo sapevo che prima o poi ci sarei riuscito...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- in effetti quel video che ho postato l'altro giorno era proprio fico...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Clic. Fregati.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Purtroppo l'appuntamento con i propri 15 minuti di notorietà deve essere rimandato, il reale link che era presente nella mia mail rimanda al solito sito che propone Viagra e affini. Se non serve anche malware vario. L'URL a cui era collegata la mia mail
