<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>danielmiessler.com » Information Security</title>
	
	<link>http://danielmiessler.com</link>
	<description>grep understanding</description>
	<lastBuildDate>Fri, 03 Jul 2009 18:30:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/blog_informationsecurity" type="application/rss+xml" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">blog_informationsecurity</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Updated PGP Information</title>
		<link>http://danielmiessler.com/blog/updated-pgp-information</link>
		<comments>http://danielmiessler.com/blog/updated-pgp-information#comments</comments>
		<pubDate>Tue, 30 Jun 2009 04:35:22 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/updated-pgp-information</guid>
		<description><![CDATA[

I&#8217;ve updated my PGP information. 

Quick question: how many of you use PGP often? I hardly ever do, but I like having it available for those rare cases. ::
Related PostsFeeds UpdatedVulnerability Management Without Asset Management, Isn'tConsidering Using danielmiessler.com Instead of dmiessler.comWhos.amung.us for Real-time Site StatsA Great Picture of a Young Obama



	
	
	
	
	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="300" height="300" src="http://danielmiessler.com/wp-content/uploaded_content/2008/09/security-lock.jpg" alt="lock" /></p>

<p>I&#8217;ve updated my <a href="http://danielmiessler.com/pgp/">PGP</a> information. </p>

<p>Quick question: how many of you use PGP often? I hardly ever do, but I like having it available for those rare cases. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/feeds-updated" rel="bookmark">Feeds Updated</a></li><li><a href="http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt" rel="bookmark">Vulnerability Management Without Asset Management, Isn't</a></li><li><a href="http://danielmiessler.com/blog/considering-using-danielmiessler-com-instead-of-dmiessler-com" rel="bookmark">Considering Using danielmiessler.com Instead of dmiessler.com</a></li><li><a href="http://danielmiessler.com/blog/whos-amung-us-for-real-time-site-stats" rel="bookmark">Whos.amung.us for Real-time Site Stats</a></li><li><a href="http://danielmiessler.com/blog/a-great-picture-of-a-young-obama" rel="bookmark">A Great Picture of a Young Obama</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information&amp;bodytext=%0A%0AI%27ve%20updated%20my%20%5BPGP%5D%28http%3A%2F%2Fdanielmiessler.com%2Fpgp%2F%29%20information.%20%0A%0AQuick%20question%3A%20how%20many%20of%20you%20use%20PGP%20often%3F%20I%20hardly%20ever%20do%2C%20but%20I%20like%20having%20it%20available%20for%20those%20rare%20cases.%20%3A%3A" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information&amp;annotation=%0A%0AI%27ve%20updated%20my%20%5BPGP%5D%28http%3A%2F%2Fdanielmiessler.com%2Fpgp%2F%29%20information.%20%0A%0AQuick%20question%3A%20how%20many%20of%20you%20use%20PGP%20often%3F%20I%20hardly%20ever%20do%2C%20but%20I%20like%20having%20it%20available%20for%20those%20rare%20cases.%20%3A%3A" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information&amp;notes=%0A%0AI%27ve%20updated%20my%20%5BPGP%5D%28http%3A%2F%2Fdanielmiessler.com%2Fpgp%2F%29%20information.%20%0A%0AQuick%20question%3A%20how%20many%20of%20you%20use%20PGP%20often%3F%20I%20hardly%20ever%20do%2C%20but%20I%20like%20having%20it%20available%20for%20those%20rare%20cases.%20%3A%3A" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Updated%20PGP%20Information&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;t=Updated%20PGP%20Information" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Updated%20PGP%20Information%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;title=Updated%20PGP%20Information&amp;body=%0A%0AI%27ve%20updated%20my%20%5BPGP%5D%28http%3A%2F%2Fdanielmiessler.com%2Fpgp%2F%29%20information.%20%0A%0AQuick%20question%3A%20how%20many%20of%20you%20use%20PGP%20often%3F%20I%20hardly%20ever%20do%2C%20but%20I%20like%20having%20it%20available%20for%20those%20rare%20cases.%20%3A%3A" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Updated%20PGP%20Information&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fupdated-pgp-information" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/nLtVC7_vRsVItgZKgBmLNuhNlVU/0/da"><img src="http://feedads.g.doubleclick.net/~a/nLtVC7_vRsVItgZKgBmLNuhNlVU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/nLtVC7_vRsVItgZKgBmLNuhNlVU/1/da"><img src="http://feedads.g.doubleclick.net/~a/nLtVC7_vRsVItgZKgBmLNuhNlVU/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/updated-pgp-information/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Getting IP Location Information in Wireshark</title>
		<link>http://danielmiessler.com/blog/getting-ip-location-information-in-wireshark</link>
		<comments>http://danielmiessler.com/blog/getting-ip-location-information-in-wireshark#comments</comments>
		<pubDate>Sun, 28 Jun 2009 22:53:11 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/getting-ip-location-information-in-wireshark</guid>
		<description><![CDATA[

Laura Chappell just posted a great tutorial on getting GeoIP working with the new version of Wireshark (1.2). I set it up myself recently and it only took a couple of minutes.

Abridged Instructions


Download the GeoIP (Lite) database files for country, city, and ASN.
Decompress them to a permanent directory on your hard drive.
Go to Wireshark&#8217;s preferences [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="500" height="" src="http://danielmiessler.com/wp-content/uploads/2009/06/wireshark_location.png" alt="wireshark_location" /></p>

<p><a href="http://www.packet-level.com/" title="Home - Protocol Analysis Institute">Laura Chappell</a> just posted a great tutorial on getting <a href="http://www.maxmind.com/" title="Geolocation and Online Fraud Prevention from MaxMind">GeoIP</a> working with the new version of <a href="http://www.wireshark.org/" title="Wireshark: Go deep.">Wireshark</a> (1.2). I set it up myself recently and it only took a couple of minutes.</p>

<h2>Abridged Instructions</h2>

<ol>
<li>Download the GeoIP (Lite) database files for country, city, and ASN.</li>
<li>Decompress them to a permanent directory on your hard drive.</li>
<li>Go to Wireshark&#8217;s preferences and click on the Location menu.</li>
<li>Add the location you created in step 2.</li>
<li>Restart Wireshark if it&#8217;s already running.</li>
<li>Once you&#8217;re capturing, got to Statistics -> Endpoints -> IPv4</li>
<li>Become happy.</li>
</ol>

<p>Yes, extremely cool stuff. And <a href="http://www.securitytube.net/Setting-up-GeoIP-to-Track-IP-Address-Locations-in-Wireshark-video.aspx" title="Setting up GeoIP to Track IP Address Locations in Wireshark Tutorial">here&#8217;s Laura&#8217;s tutorial video</a>. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/a-simple-script-for-harvesting-dns-country-state-and-city-information-from-a-list-of-ip-addresses" rel="bookmark">A Simple Script for Harvesting DNS, Country, State, and City Information From a List of IP Addresses</a></li><li><a href="http://danielmiessler.com/blog/git-ignore-wordpress-cache-files-using-gitignore" rel="bookmark">Git: Ignore Wordpress Cache Files using .gitignore</a></li><li><a href="http://danielmiessler.com/blog/how-to-create-dynamic-diggredditdelicious-buttons-for-your-pages-includes-code" rel="bookmark">How To Create Dynamic Digg/Reddit/Del.icio.us Buttons For Your Pages (Includes Code)</a></li><li><a href="http://danielmiessler.com/blog/how-to-instantly-download-any-youtube-video-in-mp4-format" rel="bookmark">How to Instantly Download Any YouTube Video in .mp4 Format</a></li><li><a href="http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion" rel="bookmark">Installing the Latest Version of Nmap Using Subversion</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;bodytext=%0A%0A%5BLaura%20Chappell%5D%28http%3A%2F%2Fwww.packet-level.com%2F%20%22Home%20-%20Protocol%20Analysis%20Institute%22%29%20just%20posted%20a%20great%20tutorial%20on%20getting%20%5BGeoIP%5D%28http%3A%2F%2Fwww.maxmind.com%2F%20%22Geolocation%20and%20Online%20Fraud%20Prevention%20from%20MaxMind%22%29%20working%20with%20the%20new%20version%20of%20%5BWir" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;annotation=%0A%0A%5BLaura%20Chappell%5D%28http%3A%2F%2Fwww.packet-level.com%2F%20%22Home%20-%20Protocol%20Analysis%20Institute%22%29%20just%20posted%20a%20great%20tutorial%20on%20getting%20%5BGeoIP%5D%28http%3A%2F%2Fwww.maxmind.com%2F%20%22Geolocation%20and%20Online%20Fraud%20Prevention%20from%20MaxMind%22%29%20working%20with%20the%20new%20version%20of%20%5BWir" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;notes=%0A%0A%5BLaura%20Chappell%5D%28http%3A%2F%2Fwww.packet-level.com%2F%20%22Home%20-%20Protocol%20Analysis%20Institute%22%29%20just%20posted%20a%20great%20tutorial%20on%20getting%20%5BGeoIP%5D%28http%3A%2F%2Fwww.maxmind.com%2F%20%22Geolocation%20and%20Online%20Fraud%20Prevention%20from%20MaxMind%22%29%20working%20with%20the%20new%20version%20of%20%5BWir" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;t=Getting%20IP%20Location%20Information%20in%20Wireshark" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Getting%20IP%20Location%20Information%20in%20Wireshark%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;title=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;body=%0A%0A%5BLaura%20Chappell%5D%28http%3A%2F%2Fwww.packet-level.com%2F%20%22Home%20-%20Protocol%20Analysis%20Institute%22%29%20just%20posted%20a%20great%20tutorial%20on%20getting%20%5BGeoIP%5D%28http%3A%2F%2Fwww.maxmind.com%2F%20%22Geolocation%20and%20Online%20Fraud%20Prevention%20from%20MaxMind%22%29%20working%20with%20the%20new%20version%20of%20%5BWir" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Getting%20IP%20Location%20Information%20in%20Wireshark&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fgetting-ip-location-information-in-wireshark" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/F0ea-HadBd3PVS5J52R2gaV9XMU/0/da"><img src="http://feedads.g.doubleclick.net/~a/F0ea-HadBd3PVS5J52R2gaV9XMU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/F0ea-HadBd3PVS5J52R2gaV9XMU/1/da"><img src="http://feedads.g.doubleclick.net/~a/F0ea-HadBd3PVS5J52R2gaV9XMU/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/getting-ip-location-information-in-wireshark/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Installing the Latest Version of Nmap Using Subversion</title>
		<link>http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion</link>
		<comments>http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion#comments</comments>
		<pubDate>Sat, 27 Jun 2009 02:55:06 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Nmap]]></category>

		<guid isPermaLink="false">http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion</guid>
		<description><![CDATA[

As of the last year or so my preferred method for installing and updating nmap is to use subversion. It&#8217;s a good way to make sure you have the latest features available to you, and it&#8217;s easy to get up and running with. Here&#8217;s how:

[ I'm using OS X, but it's pretty much an identical [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="300" height="" src="http://danielmiessler.com/wp-content/uploads/2009/06/nmap_subversion.png" alt="nmap_subversion" /></p>

<p>As of the last year or so my preferred method for installing and updating <code><a href="http://nmap.org/" title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits.">nmap</a></code> is to use <a href="http://subversion.tigris.org/" title="subversion.tigris.org">subversion</a>. It&#8217;s a good way to make sure you have the latest features available to you, and it&#8217;s easy to get up and running with. Here&#8217;s how:</p>

<p class="post_note">[ I'm using OS X, but it's pretty much an identical process in Linux. And if you are using OS X be sure to install subversion first, which I use <code>macports</code> to do. ]</p>

<h2>1. Download the Software</h2>

<p>First move to a place on your filesystem that you want the new nmap directory to exist. Then it&#8217;s just one command to log in to the repository and pull the entire tree.</p>

<p><pre class="brush: bash"> svn co --username guest --password &quot;&quot; svn://svn.insecure.org/nmap/</pre></p>

<h2>2. Configure, Make, Make Install</h2>

<p>Move into the <code>nmap</code> directory that&#8217;s now there and run <code>configure<code>.</p>

<p><pre class="brush: bash">cd nmap
./configure</pre></p>

<p>Then <code>make</code>.</p>

<p><pre class="brush: bash">make</pre></p>

<p>Then install it.</p>

<p><pre class="brush: bash">sudo make install</pre></p>

<h2>3. Point to the New Version</h2>

<p>Then create an alias for <code>nmap</code> that points to the new location.</p>

<p><pre class="brush: bash">alias nmap=&quot;sudo /Users/daniel/Applications/nmap/nmap&quot;</pre></p>

<h2>4. Enjoy</h2>

<p>Reload your aliases file and you're all set to run the latest version of <code>nmap</code>.</p>

<p><pre class="brush: bash">cd
source .aliases
nmap --version</pre> </p>

<p>::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/an-nmap-command-worth-remembering" rel="bookmark">An Nmap Command Worth Remembering</a></li><li><a href="http://danielmiessler.com/blog/the-nmap-dshield-trick" rel="bookmark">The Nmap / DShield Trick</a></li><li><a href="http://danielmiessler.com/blog/an-nmap-scan-of-the-iphone-20-software" rel="bookmark">An Nmap Scan of the iPhone 2.0 Software</a></li><li><a href="http://danielmiessler.com/blog/git-ignore-wordpress-cache-files-using-gitignore" rel="bookmark">Git: Ignore Wordpress Cache Files using .gitignore</a></li><li><a href="http://danielmiessler.com/blog/the-coolest-thing-you-didnt-know-bash-could-do" rel="bookmark">The Coolest Thing You Didn't Know Bash Could Do</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;bodytext=%0A%0AAs%20of%20the%20last%20year%20or%20so%20my%20preferred%20method%20for%20installing%20and%20updating%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20is%20to%20use%20%5Bsubversion%5D%28http%3A%2F%2Fsubversion.tigris.org%2F%20%22subversion.tigris.org" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;annotation=%0A%0AAs%20of%20the%20last%20year%20or%20so%20my%20preferred%20method%20for%20installing%20and%20updating%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20is%20to%20use%20%5Bsubversion%5D%28http%3A%2F%2Fsubversion.tigris.org%2F%20%22subversion.tigris.org" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;notes=%0A%0AAs%20of%20the%20last%20year%20or%20so%20my%20preferred%20method%20for%20installing%20and%20updating%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20is%20to%20use%20%5Bsubversion%5D%28http%3A%2F%2Fsubversion.tigris.org%2F%20%22subversion.tigris.org" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;t=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;title=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;body=%0A%0AAs%20of%20the%20last%20year%20or%20so%20my%20preferred%20method%20for%20installing%20and%20updating%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20is%20to%20use%20%5Bsubversion%5D%28http%3A%2F%2Fsubversion.tigris.org%2F%20%22subversion.tigris.org" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Installing%20the%20Latest%20Version%20of%20Nmap%20Using%20Subversion&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finstalling-the-latest-version-of-nmap-using-subversion" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/49koaOVdm0hsEdva1VUr-d-a_60/0/da"><img src="http://feedads.g.doubleclick.net/~a/49koaOVdm0hsEdva1VUr-d-a_60/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/49koaOVdm0hsEdva1VUr-d-a_60/1/da"><img src="http://feedads.g.doubleclick.net/~a/49koaOVdm0hsEdva1VUr-d-a_60/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wireless: WPA2 Enterprise Integration With Active Directory 2008 Using NPS</title>
		<link>http://danielmiessler.com/blog/wireless-wpa2-enterprise-integration-with-active-directory-2008</link>
		<comments>http://danielmiessler.com/blog/wireless-wpa2-enterprise-integration-with-active-directory-2008#comments</comments>
		<pubDate>Mon, 15 Jun 2009 04:28:05 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/wireless-wpa2-enterprise-integration-with-active-directory-2008</guid>
		<description><![CDATA[

So I finally got my Wireless Access Point (an Apple AirPort) authenticating off of Active Directory-integrated LDAP in Server 2008 (which is called NPS now). So now I authenticate wireless users individually, through Active Directory, rather than using a shared secret. WPA2 Enterprise&#8230;it overfloweth with w00tn3ss.

Setup

So here are the basic steps, and I can provide [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://dmiessler.com/wp-content/uploaded_content/2008/09/security-lock.jpg" width="200" height="200" /></center></p>

<p>So I finally got my Wireless Access Point (an Apple AirPort) authenticating off of Active Directory-integrated LDAP in Server 2008 (which is called NPS now). So now I authenticate wireless users individually, through Active Directory, rather than using a shared secret. WPA2 Enterprise&#8230;it overfloweth with w00tn3ss.</p>

<h2>Setup</h2>

<p>So here are the basic steps, and I can provide more detail if you have questions in the comments.</p>

<h3>1. Install AD and Create Users</h3>

<p>First install Active Directory. Easy stuff.</p>

<p>Next, since the whole point of this is to have <em>unique user authentication</em>, you need to have&#8230;users. So create them as usual but be sure to add them to a new group like &#8220;RADIUS&#8221; or something, and ensure that they have dial-in access within their user account. I used &#8220;RADIUS Users&#8221; because I&#8217;m creative and eccentric.</p>

<h3>2. Enable Network Policy and Access Services in Server 2008</h3> 

<p>This is what replaces IAS in Server 2008. The install is pretty straight forward; it&#8217;s the policy that&#8217;s the trick.</p>

<p style="text-align:center"><img width="500" height="" src="http://dmiessler.com/wp-content/uploads/2009/06/nps2.png" alt="nps" /></p>

<p>I&#8217;m using PEAP right now, although I haven&#8217;t yet researched the ideal setup. Soon, though, and if you have any input (or good reading) on this let me know.</p>

<p>You also want to set the authentication rule to Windows Authentication within the policy, and then select your group out of Active Directory that you placed your users in.</p>

<p>Be sure to setup a RADIUS client within the NPS configuration, and enter the info for your access point rather than for your individual clients.</p>

<h3>3. Configure Your Wireless Access Point</h3> 

<p>Tell your wireless access point to use WPA2 Enterprise, and configure the RADIUS info to point to your domain controller that you just set up NPS on. Enter the shared secret you configured during the NPS piece.</p>

<h3>4. Configure Your Clients</h3>

<p>Connect to your AP as you normally would, and when prompted you will enter your Active Directory username and password. I&#8217;ve chosen PEAP as my authentication protocol pending more research on which is ideal:</p>

<p style="text-align:center"><img width="500" height="" src="http://dmiessler.com/wp-content/uploads/2009/06/peap3.png" alt="peap" /></p>

<h2>Fin</h2>

<p>And that&#8217;s about it. Connect to your AP and enter your credentials.</p>

<p>Now when your friends come over you simply make them an account in Active Directory and they have wireless access using their own username and password. And when they leave you disable their account until next time. This way you get all the added benefits of password expiration and stuff like that.</p>

<p>Oh, and if any part of this fails, check the NPS logs on your DC. Logs are much improved in 2008 vs. previous versions of Windows, and it&#8217;s pretty easy to troubleshoot. I saw a lot of errors with authentication types not being supported before I figured out which to use. </p>

<p class="post_note"><strong>Bonus:</strong> If you&#8217;re one of the cool kids you&#8217;ll have your AD and AP logs going into <a href="http://www.splunk.com/" title="Splunk IT Search Company | It's not just Log Management anymore">Splunk</a> so you can see (and alert on) attempts to access your wireless network from accounts and MAC addresses you don&#8217;t recognize. More on that later.</p>

<p>Anyway, enjoy, and hit me up with any questions. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server" rel="bookmark">HOWTO: Use Splunk as Your Remote Syslog Server</a></li><li><a href="http://danielmiessler.com/blog/biopassword" rel="bookmark">BioPassword: Two-Factor Authentication The Easy Way</a></li><li><a href="http://danielmiessler.com/blog/home-network-upgrades" rel="bookmark">Home Network Upgrades</a></li><li><a href="http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion" rel="bookmark">Installing the Latest Version of Nmap Using Subversion</a></li><li><a href="http://danielmiessler.com/blog/a-short-list-of-interesting-windows-server-2008-features" rel="bookmark">A Short List of Interesting Windows Server 2008 Features</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;bodytext=%0D%0A%0D%0ASo%20I%20finally%20got%20my%20Wireless%20Access%20Point%20%28an%20Apple%20AirPort%29%20authenticating%20off%20of%20Active%20Directory-integrated%20LDAP%20in%20Server%202008%20%28which%20is%20called%20NPS%20now%29.%20So%20now%20I%20authenticate%20wireless%20users%20individually%2C%20through%20Active%20Directory%2C%20rather%20than" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;annotation=%0D%0A%0D%0ASo%20I%20finally%20got%20my%20Wireless%20Access%20Point%20%28an%20Apple%20AirPort%29%20authenticating%20off%20of%20Active%20Directory-integrated%20LDAP%20in%20Server%202008%20%28which%20is%20called%20NPS%20now%29.%20So%20now%20I%20authenticate%20wireless%20users%20individually%2C%20through%20Active%20Directory%2C%20rather%20than" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;notes=%0D%0A%0D%0ASo%20I%20finally%20got%20my%20Wireless%20Access%20Point%20%28an%20Apple%20AirPort%29%20authenticating%20off%20of%20Active%20Directory-integrated%20LDAP%20in%20Server%202008%20%28which%20is%20called%20NPS%20now%29.%20So%20now%20I%20authenticate%20wireless%20users%20individually%2C%20through%20Active%20Directory%2C%20rather%20than" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;t=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;title=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;body=%0D%0A%0D%0ASo%20I%20finally%20got%20my%20Wireless%20Access%20Point%20%28an%20Apple%20AirPort%29%20authenticating%20off%20of%20Active%20Directory-integrated%20LDAP%20in%20Server%202008%20%28which%20is%20called%20NPS%20now%29.%20So%20now%20I%20authenticate%20wireless%20users%20individually%2C%20through%20Active%20Directory%2C%20rather%20than" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Wireless%3A%20WPA2%20Enterprise%20Integration%20With%20Active%20Directory%202008%20Using%20NPS&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fwireless-wpa2-enterprise-integration-with-active-directory-2008" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/GdWiMkVCsRj3ZH4tHrVd52Qdqz0/0/da"><img src="http://feedads.g.doubleclick.net/~a/GdWiMkVCsRj3ZH4tHrVd52Qdqz0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/GdWiMkVCsRj3ZH4tHrVd52Qdqz0/1/da"><img src="http://feedads.g.doubleclick.net/~a/GdWiMkVCsRj3ZH4tHrVd52Qdqz0/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/wireless-wpa2-enterprise-integration-with-active-directory-2008/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Encryption on the iPhone 3G[S]</title>
		<link>http://danielmiessler.com/blog/encryption-on-the-iphone-3gs</link>
		<comments>http://danielmiessler.com/blog/encryption-on-the-iphone-3gs#comments</comments>
		<pubDate>Sat, 13 Jun 2009 22:59:21 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[iPhone]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/encryption-on-the-iphone-3gs</guid>
		<description><![CDATA[My buddy Anthony just put up a piece on encryption on the new iPhone. Worth a read. ::

Links

[ The iPhone 3GS and Forensics: Encryption Changes the Game? ]
Related PostsVOIP SecurityHow to Downgrade an iPhone from 2.0 to 1.4 [Tutorial]Tap Tap RevengeUm...Next Gen iPhone on June 18th?Geocaching With the iPhone 3G



	
	
	
	
	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p>My buddy Anthony just put up a piece on encryption on the new iPhone. Worth a read. ::</p>

<h3>Links</h3>

<p>[ <a href="http://anthonyvance.com/blog/forensics/iphone_encryption/" title="The iPhone 3GS and Forensics: Encryption Changes the Game? | Anthony Vance">The iPhone 3GS and Forensics: Encryption Changes the Game?</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/voip-security" rel="bookmark">VOIP Security</a></li><li><a href="http://danielmiessler.com/blog/how-to-downgrade-an-iphone-from-20-to-14-tutorial" rel="bookmark">How to Downgrade an iPhone from 2.0 to 1.4 [Tutorial]</a></li><li><a href="http://danielmiessler.com/blog/tap-tap-revenge" rel="bookmark">Tap Tap Revenge</a></li><li><a href="http://danielmiessler.com/blog/umnext-gen-iphone-on-june-18th" rel="bookmark">Um...Next Gen iPhone on June 18th?</a></li><li><a href="http://danielmiessler.com/blog/geocaching-with-the-iphone-3g" rel="bookmark">Geocaching With the iPhone 3G</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;bodytext=My%20buddy%20Anthony%20just%20put%20up%20a%20piece%20on%20encryption%20on%20the%20new%20iPhone.%20Worth%20a%20read.%20%3A%3A%0A%0ALinks%0A%0A%5B%20%5BThe%20iPhone%203GS%20and%20Forensics%3A%20Encryption%20Changes%20the%20Game%3F%5D%28http%3A%2F%2Fanthonyvance.com%2Fblog%2Fforensics%2Fiphone_encryption%2F%20%22The%20iPhone%203GS%20and%20Forensics%3A%20Enc" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;annotation=My%20buddy%20Anthony%20just%20put%20up%20a%20piece%20on%20encryption%20on%20the%20new%20iPhone.%20Worth%20a%20read.%20%3A%3A%0A%0ALinks%0A%0A%5B%20%5BThe%20iPhone%203GS%20and%20Forensics%3A%20Encryption%20Changes%20the%20Game%3F%5D%28http%3A%2F%2Fanthonyvance.com%2Fblog%2Fforensics%2Fiphone_encryption%2F%20%22The%20iPhone%203GS%20and%20Forensics%3A%20Enc" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;notes=My%20buddy%20Anthony%20just%20put%20up%20a%20piece%20on%20encryption%20on%20the%20new%20iPhone.%20Worth%20a%20read.%20%3A%3A%0A%0ALinks%0A%0A%5B%20%5BThe%20iPhone%203GS%20and%20Forensics%3A%20Encryption%20Changes%20the%20Game%3F%5D%28http%3A%2F%2Fanthonyvance.com%2Fblog%2Fforensics%2Fiphone_encryption%2F%20%22The%20iPhone%203GS%20and%20Forensics%3A%20Enc" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;t=Encryption%20on%20the%20iPhone%203G%5BS%5D" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Encryption%20on%20the%20iPhone%203G%5BS%5D%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;title=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;body=My%20buddy%20Anthony%20just%20put%20up%20a%20piece%20on%20encryption%20on%20the%20new%20iPhone.%20Worth%20a%20read.%20%3A%3A%0A%0ALinks%0A%0A%5B%20%5BThe%20iPhone%203GS%20and%20Forensics%3A%20Encryption%20Changes%20the%20Game%3F%5D%28http%3A%2F%2Fanthonyvance.com%2Fblog%2Fforensics%2Fiphone_encryption%2F%20%22The%20iPhone%203GS%20and%20Forensics%3A%20Enc" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Encryption%20on%20the%20iPhone%203G%5BS%5D&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fencryption-on-the-iphone-3gs" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/N1axTqs4bANEP8Uzlp2cDDSLZYM/0/da"><img src="http://feedads.g.doubleclick.net/~a/N1axTqs4bANEP8Uzlp2cDDSLZYM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/N1axTqs4bANEP8Uzlp2cDDSLZYM/1/da"><img src="http://feedads.g.doubleclick.net/~a/N1axTqs4bANEP8Uzlp2cDDSLZYM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/encryption-on-the-iphone-3gs/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Discussion: Where’s the Best Place For Country Blocks?</title>
		<link>http://danielmiessler.com/blog/discussion-wheres-the-best-place-for-country-blocks</link>
		<comments>http://danielmiessler.com/blog/discussion-wheres-the-best-place-for-country-blocks#comments</comments>
		<pubDate>Fri, 12 Jun 2009 12:50:15 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=5799</guid>
		<description><![CDATA[

In a scenario where your SMB or enterprise gets constantly bombarded (portscans, brute force, spam, etc.) by Russia, China, Brazil, et al., and where you don&#8217;t do business in these countries, where&#8217;s the best place to block them?

Here are a few options (add as necessary):

    Border router ACL
    Firewall [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://news.zdnet.co.uk/i/z5/illo/nw/lead_graphics/security/184x138/184-cyberwar-1.jpg" alt="" width="184" height="138" /></center></p>

<p>In a scenario where your SMB or enterprise gets constantly bombarded (portscans, brute force, spam, etc.) by Russia, China, Brazil, et al., and where you don&#8217;t do business in these countries, where&#8217;s the best place to block them?</p>

<p>Here are a few options (add as necessary):
<ul>
    <li>Border router ACL</li>
    <li>Firewall ACL</li>
    <li>Separate, dedicated appliance</li>
    <li>Network IPS</li>
    <li>Border router routing (blackholing)</li>
</ul>
This is also assuming you can&#8217;t do a simple, tight <em>whitelist </em>ACL on the firewall&#8211;which would make the solution pretty easy&#8211;and instead have to specifically blacklist because there are a large number of legitimate foreign IP blocks.</p>

<p class="post_note">Related: Do you guys blacklist at a granular level (hundreds or thousands of networks), or do you do only the few primary /8&#8217;s?</p>

<p>What are your thoughts on the best method?</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/how-not-to-do-firewall-filtering" rel="bookmark">How *Not* To Do Firewall Filtering</a></li><li><a href="http://danielmiessler.com/blog/network-security-what-does-a-firewall-mean-to-you" rel="bookmark">Network Security: What Does A Firewall Mean To You?</a></li><li><a href="http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values" rel="bookmark">TTL Caging: How to Fight Malware Using Reduced TTL Values</a></li><li><a href="http://danielmiessler.com/blog/home-network-upgrades" rel="bookmark">Home Network Upgrades</a></li><li><a href="http://danielmiessler.com/blog/problems-with-check-point-nat-and-sip" rel="bookmark">Problems with Check Point, NAT, and SIP</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;bodytext=%0D%0A%0D%0AIn%20a%20scenario%20where%20your%20SMB%20or%20enterprise%20gets%20constantly%20bombarded%20%28portscans%2C%20brute%20force%2C%20spam%2C%20etc.%29%20by%20Russia%2C%20China%2C%20Brazil%2C%20et%20al.%2C%20and%20where%20you%20don%27t%20do%20business%20in%20these%20countries%2C%20where%27s%20the%20best%20place%20to%20block%20them%3F%0D%0A%0D%0AHere%20are%20a%20fe" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;annotation=%0D%0A%0D%0AIn%20a%20scenario%20where%20your%20SMB%20or%20enterprise%20gets%20constantly%20bombarded%20%28portscans%2C%20brute%20force%2C%20spam%2C%20etc.%29%20by%20Russia%2C%20China%2C%20Brazil%2C%20et%20al.%2C%20and%20where%20you%20don%27t%20do%20business%20in%20these%20countries%2C%20where%27s%20the%20best%20place%20to%20block%20them%3F%0D%0A%0D%0AHere%20are%20a%20fe" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;notes=%0D%0A%0D%0AIn%20a%20scenario%20where%20your%20SMB%20or%20enterprise%20gets%20constantly%20bombarded%20%28portscans%2C%20brute%20force%2C%20spam%2C%20etc.%29%20by%20Russia%2C%20China%2C%20Brazil%2C%20et%20al.%2C%20and%20where%20you%20don%27t%20do%20business%20in%20these%20countries%2C%20where%27s%20the%20best%20place%20to%20block%20them%3F%0D%0A%0D%0AHere%20are%20a%20fe" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;t=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;title=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;body=%0D%0A%0D%0AIn%20a%20scenario%20where%20your%20SMB%20or%20enterprise%20gets%20constantly%20bombarded%20%28portscans%2C%20brute%20force%2C%20spam%2C%20etc.%29%20by%20Russia%2C%20China%2C%20Brazil%2C%20et%20al.%2C%20and%20where%20you%20don%27t%20do%20business%20in%20these%20countries%2C%20where%27s%20the%20best%20place%20to%20block%20them%3F%0D%0A%0D%0AHere%20are%20a%20fe" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Discussion%3A%20Where%27s%20the%20Best%20Place%20For%20Country%20Blocks%3F&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdiscussion-wheres-the-best-place-for-country-blocks" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/CVnLpXdqzq9Xstqq9oKz8S3l3PM/0/da"><img src="http://feedads.g.doubleclick.net/~a/CVnLpXdqzq9Xstqq9oKz8S3l3PM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/CVnLpXdqzq9Xstqq9oKz8S3l3PM/1/da"><img src="http://feedads.g.doubleclick.net/~a/CVnLpXdqzq9Xstqq9oKz8S3l3PM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/discussion-wheres-the-best-place-for-country-blocks/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>HOWTO: Use Splunk as Your Remote Syslog Server</title>
		<link>http://danielmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server</link>
		<comments>http://danielmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server#comments</comments>
		<pubDate>Mon, 01 Jun 2009 11:50:47 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Sysadmin]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server</guid>
		<description><![CDATA[So I&#8217;ve been messing with Splunk> a bit recently, and as part of that I&#8217;ve been sending logs from iptables, snort, and apache&#8211;not to mention the other stuff that naturally lands within /var/log/messages.



As you can see, the reason I&#8217;m doing this is to get a brutally powerful data view in one interface. Here I&#8217;m showing [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;ve been messing with <a href="http://www.splunk.com/" title="Splunk IT Search Company | It's not just Log Management anymore">Splunk</a>> a bit recently, and as part of that I&#8217;ve been sending logs from <code>iptables</code>, <code>snort</code>, and <code>apache</code>&#8211;not to mention the other stuff that naturally lands within <code>/var/log/messages</code>.</p>

<p style="text-align:center"><img width="500" height="" src="http://dmiessler.com/wp-content/uploads/2009/06/get-requests.png" alt="get_requests" /></p>

<p>As you can see, the reason I&#8217;m doing this is to get a brutally powerful data view in one interface. Here I&#8217;m showing some GET requests within my Apache logs, but I currently have saved searches for all these various types of information:</p>

<ul>
<li>drops on my firewall</li>
<li>accepts on my firewall</li>
<li>successful SSH logins (password or key)</li>
<li>failed SSH logins (password or key)</li>
<li>associations to my wireless</li>
<li>incoming GET requests to Apache</li>
<li>user agents</li>
</ul>

<p>The key with Splunk> is the quickness in which you can search raw data, and create powerful visualizations of the results.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/06/dports.png" alt="dports" /><br /><span class="image_attribution">firewall drops by port within 3 hours</span></p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/06/dports2.png" alt="dports2" /></p>

<h2>Syslog Setup</h2>

<p>So this all requires that Splunk> see your log data; here&#8217;s how to set up <code>syslog-ng</code> to forward your various log types to an arbitrary destination.</p>

<h3><code>netfilter/iptables</code></h3>

<p>Log your desired traffic (this is my default-deny at the bottom of my ruleset)</p>

<p><pre class="brush: bash">/sbin/iptables -A INPUT -i eth0 -d $SENECA -j LOG --log-level 7 --log-prefix &quot;Firewall: Default Deny: &quot;</pre></p>

<p>This will automatically go to <code>syslog</code> on most systems.</p>

<h3><code>Apache</code></h3>

<p>You don&#8217;t do anything specific in Apache, other than make sure you&#8217;re logging the stuff you want. I prefer to get user-agent and such in my logs:</p>

<p><pre class="brush: bash">LogFormat &quot;%h %l %u %t \&quot;%r\&quot; %&gt;s %b \&quot;%{Referer}i\&quot; \&quot;%{User-Agent}i\&quot;&quot; combined
LogFormat &quot;%h %l %u %t \&quot;%r\&quot; %&gt;s %b&quot; common
LogFormat &quot;%{Referer}i -&gt; %U&quot; referer
LogFormat &quot;%{User-Agent}i&quot; agent
LogFormat &quot;%v %h %l %u %t \&quot;%r\&quot; %&gt;s %b %T&quot; script
LogFormat &quot;%v %h %l %u %t \&quot;%r\&quot; %&gt;s %b \&quot;%{Referer}i\&quot; \&quot;%{User-Agent}i\&quot; VLOG=%{VLOG}e&quot; vhost</pre></p>

<h3><code>syslog</code></h3>

<p>Then for the most important piece you have to:</p>

<ol>
<li>Tell <code>syslog-ng</code> to parse your Apache logs</li>
<li>Tell <code>syslog-ng</code> to send logs to your remote system (Splunk, in this case)</li>
</ol>

<p>First, here&#8217;s how you get arbitrary, quickly expanding logs into <cocde>syslog-ng</code>:</p>

<p><pre class="brush: bash">source access {
    file(&quot;/var/log/apache2/access&lt;em&gt;log&quot; &lt;em&gt;follow&lt;/em&gt;freq&lt;/em&gt;(1)
    flags(no-parse));
};</pre></p>

<p>This names a source <em>access</em> (for access<em>log) that will be harvested from a <em>file</em>. The file is my main Apache log. The important bit is the <em>follow</em>freq(1)</em>, as it keeps you from having to do crazy tail / pipe tricks to get access_log's input into <code>syslog-ng</code>. The 1 says to parse the file for new content every second.</p>

<p>Then you need to define a <em>destination</em> for your logs:</p>

<p><pre class="brush: bash">destination logserver { udp(&quot;your.remote.logserver.dns&quot; port(514)); };</pre></p>

<p>And then give the <code>log</code> command, which calls your custom source and your custom destination:</p>

<p><pre class="brush: bash">log { source(access); destination(logserver); };</pre></p>

<p class="post_note">[ ** Don't forget to also add log lines for your default syslog source as well. ]</p>

<p>And that's pretty much it. Configure Splunk to listen on UDP/514 and you will have some decent data to start playing with. ::</p>

<h3>Links</h3>

<p>[ <a href="http://www.splunk.com/base/Documentation/3.0/User/Search" title="Search">Splunk Search Syntax | splunk.com</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion" rel="bookmark">Installing the Latest Version of Nmap Using Subversion</a></li><li><a href="http://danielmiessler.com/blog/the-coolest-thing-you-didnt-know-bash-could-do" rel="bookmark">The Coolest Thing You Didn't Know Bash Could Do</a></li><li><a href="http://danielmiessler.com/blog/how-to-get-around-the-md5sum-carriage-return-issue" rel="bookmark">How to Get Around the md5sum Carriage Return Issue</a></li><li><a href="http://danielmiessler.com/blog/git-ignore-wordpress-cache-files-using-gitignore" rel="bookmark">Git: Ignore Wordpress Cache Files using .gitignore</a></li><li><a href="http://danielmiessler.com/blog/linux-xargs-vs-exec" rel="bookmark">Linux: <code>xargs</code> vs. <code>exec {}</code></a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;bodytext=So%20I%27ve%20been%20messing%20with%20%5BSplunk%5D%28http%3A%2F%2Fwww.splunk.com%2F%20%22Splunk%20IT%20Search%20Company%20%7C%20It%27s%20not%20just%20Log%20Management%20anymore%22%29%3E%20a%20bit%20recently%2C%20and%20as%20part%20of%20that%20I%27ve%20been%20sending%20logs%20from%20iptables%2C%20snort%2C%20and%20apache--not%20to%20mention%20the%20other%20stuff%20" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;annotation=So%20I%27ve%20been%20messing%20with%20%5BSplunk%5D%28http%3A%2F%2Fwww.splunk.com%2F%20%22Splunk%20IT%20Search%20Company%20%7C%20It%27s%20not%20just%20Log%20Management%20anymore%22%29%3E%20a%20bit%20recently%2C%20and%20as%20part%20of%20that%20I%27ve%20been%20sending%20logs%20from%20iptables%2C%20snort%2C%20and%20apache--not%20to%20mention%20the%20other%20stuff%20" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;notes=So%20I%27ve%20been%20messing%20with%20%5BSplunk%5D%28http%3A%2F%2Fwww.splunk.com%2F%20%22Splunk%20IT%20Search%20Company%20%7C%20It%27s%20not%20just%20Log%20Management%20anymore%22%29%3E%20a%20bit%20recently%2C%20and%20as%20part%20of%20that%20I%27ve%20been%20sending%20logs%20from%20iptables%2C%20snort%2C%20and%20apache--not%20to%20mention%20the%20other%20stuff%20" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;t=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;title=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;body=So%20I%27ve%20been%20messing%20with%20%5BSplunk%5D%28http%3A%2F%2Fwww.splunk.com%2F%20%22Splunk%20IT%20Search%20Company%20%7C%20It%27s%20not%20just%20Log%20Management%20anymore%22%29%3E%20a%20bit%20recently%2C%20and%20as%20part%20of%20that%20I%27ve%20been%20sending%20logs%20from%20iptables%2C%20snort%2C%20and%20apache--not%20to%20mention%20the%20other%20stuff%20" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=HOWTO%3A%20Use%20Splunk%20as%20Your%20Remote%20Syslog%20Server&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhowto-use-splunk-as-your-remote-syslog-server" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/yDQ9o8bMOAh-W9XGedPwSri7PoM/0/da"><img src="http://feedads.g.doubleclick.net/~a/yDQ9o8bMOAh-W9XGedPwSri7PoM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/yDQ9o8bMOAh-W9XGedPwSri7PoM/1/da"><img src="http://feedads.g.doubleclick.net/~a/yDQ9o8bMOAh-W9XGedPwSri7PoM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Connected Web: Why It’s Time For Strong Authentication</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication</link>
		<comments>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comments</comments>
		<pubDate>Wed, 20 May 2009 06:25:53 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication</guid>
		<description><![CDATA[

It&#8217;s getting exciting in the world of cross-network authentication. Let&#8217;s review. I can now:


sign into Digg using Facebook
sign into DISQUS using Facebook or Twitter
sign into Facebook automatically using OpenID (with two-factor authentication) or Google
sign into FriendFeed using Google, Twitter, or Facebook




We&#8217;re quickly approaching the point where we&#8217;re going to be able to log into one [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="200" height="" src="http://dmiessler.com/wp-content/uploads/2009/05/openid-logo.png" alt="openid_logo" /></p>

<p>It&#8217;s getting exciting in the world of cross-network authentication. Let&#8217;s review. I can now:</p>

<ul>
<li>sign into <a href="http://digg.com/">Digg</a> using <a href="http://facebook.com/">Facebook</a></li>
<li>sign into <a href="http://disqus.com/" title="DISQUS | Turn Blog Comments into a Webwide Discussion with a Powerful Comment System">DISQUS</a> using Facebook or <a href="http://twitter.com/" title="Twitter: What are you doing?">Twitter</a></li>
<li>sign into Facebook automatically using <a href="http://openid.net/" title="OpenID">OpenID</a> (<a href="http://dmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Verisign VIP for Two-Factor Authentication, and PIP for OpenID | dmiessler.com">with two-factor authentication</a>) or Google</li>
<li>sign into <a href="http://friendfeed.com/" title="FriendFeed">FriendFeed</a> using Google, Twitter, or Facebook</li>
</ul>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/05/social-connections.png" alt="social_connections" /></p>

<p class="offset strong">We&#8217;re quickly approaching the point where we&#8217;re going to be able to log into one major service (Google, Facebook, OpenID, etc,) and from there access all of our other services without authenticating.</p>

<p>As it stands now, I can already log into my OpenID provider, visit the Facebook homepage, and be transparently logged in. Today this works on Facebook. Soon something like it will work for your bank as well.</p>

<p>This is a good thing, but there&#8217;s a catch.</p>

<h2>Security</h2>

<p>While this is completely phenomenal from a functionality standpoint, we need to consider the fact that single-sign-on (SSO) raises a serious security concern: it significantly increases the impact of an account compromise.</p>

<p class="banner_ad">
<script type="text/javascript"><!--
google_ad_client = "pub-2677272500934866";
/* Blog_Content_468x60 */
google_ad_slot = "2329464279";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</p>

<p>If my OpenID account gets me into Facebook, and my Facebook gets me into Digg and DISQUS and FriendFeed (where I can post to Twitter, of course)&#8230;then a compromise of my OpenID account means a compromise of all those other accounts as well. Basically, once someone gets into your main service, your entire online identity can be hijacked.</p>

<h3>Authentication Strength: More Important Than Ever</h3>

<p style="text-align:center"><img width="200" height="" src="http://dmiessler.com/wp-content/uploads/2009/05/verisign-vip.png" alt="verisign_vip" /></p>

<p>As single-sign-on solutions get more popular (i.e. <em>now</em>) we are going to have to give significantly more attention to our authentication standards and processes. Traditionally this has meant having a strong password, and while that is an essential piece of it, it&#8217;s arguably no longer enough.</p>

<p>What we really need to do is move to a strong/multi-factor authentication system. This means combining at least two of:</p>

<ul>
<li>something you <strong>know</strong> (passwords, pins)</li>
<li>something you <strong>have</strong> (tokens, smartcards)</li>
<li>something you <strong>are</strong> (biometrics)</li>
</ul>

<p>So if someone guesses your password to my OpenID account, for example, they still can&#8217;t get into my account. They <em>know</em> my password, but they don&#8217;t <em>have</em> my mobile phone with my soft token on it. That&#8217;s multi-factor authentication, and it improves your security greatly when done right.</p>

<p>My current recommended way of doing this is by <a href="http://www.verisign.com/authentication/consumer-authentication/vip-authentication/" title="VIP Authentication Services - two-factor authentictation from VeriSign, Inc.">adding two-factor authentication</a> to OpenID, which can be done via <a href="https://pip.verisignlabs.com/">Verisign PIP</a> for free. <a href="http://www.verisign.com/authentication/consumer-authentication/vip-authentication" title="VIP Authentication Services - two-factor authentictation from VeriSign, Inc.">VIP</a> can be used to add two-factor auth to major sites like <a href="http://www.ebay.com/" title="eBay - New &amp; used electronics, cars, apparel, collectibles, sporting goods &amp; more at low prices">eBay</a> and <a href="http://paypal.com">PayPal</a> as well, and <a href="http://dmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Verisign VIP for Two-Factor Authentication, and PIP for OpenID | dmiessler.com">soft tokens are available for popular mobile phone platforms</a> if you don&#8217;t want to carry an actual token.</p>

<h3>Strong Authentication Alternatives</h3>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/05/vidoop-example.jpg" alt="vidoop_example" /></p>

<p>In addition to tokens a number of other innovative options are available for multifactor authentication. <a href="http://vidoop.com/" title="Vidoop - Strong Authentication for the Consumer Web">Vidoop</a> is an interesting system that combines OpenID functionality with a unique picture-based authentication system. It&#8217;s not technically multi-factor since it relies on something you know twice (password, then the images), but it&#8217;s still considered <em>strong</em> authentication.</p>

<p>Plus there are number of systems that use other things we commonly have with us to provide an additional factor of authentication, like sending a one-time password to your mobile phone via text message.</p>

<h2>Conclusion</h2>

<p>Social web service integration is upon us. Very soon, signing into websites using local credentials is going to be an indication of one of two things: 1) your single-sign-on system is broken, or 2) you&#8217;re using a website so ancient that you might want to consider an alternative.</p>

<p>This is progress, and it&#8217;s progress we should embrace, but we need to keep the risks in mind and take steps to mitigate them. So yes, enjoy the new powers given to you by single-sign-on, but do your best to protect yourself by looking for strong/two-factor authentication options within your favorite online services. ::</p>

<h3>Links</h3>

<p>[ <a href="http://en.wikipedia.org/wiki/Strong_authentication" title="Strong authentication - Wikipedia, the free encyclopedia">Strong Authentication | wikipedia.org</a> ]<br />
[ <a href="http://en.wikipedia.org/wiki/Two-factor_authentication" title="Two-factor authentication - Wikipedia, the free encyclopedia">Two-factor Authentication | wikipedia.org</a> ]<br />
[ <a href="http://en.wikipedia.org/wiki/Single_sign-on" title="Single sign-on - Wikipedia, the free encyclopedia">Single Sign On | wikipedia.org</a> ]<br />
[ <a href="http://en.wikipedia.org/wiki/Oath" title="Oath - Wikipedia, the free encyclopedia">OATH | openauthenticaton.org</a> ]<br />
[ <a href="http://developers.facebook.com/connect.php" title="Facebook Developers | Facebook Connect">Facebook Connect | facebook.com</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" rel="bookmark">Verisign VIP for Two-Factor Authentication, and PIP for OpenID</a></li><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/verisign-pip-openid-delegation-code" rel="bookmark">Verisign PIP OpenID Delegation Code</a></li><li><a href="http://danielmiessler.com/blog/biopassword" rel="bookmark">BioPassword: Two-Factor Authentication The Easy Way</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark">Implementing OpenID</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;bodytext=%0A%0AIt%27s%20getting%20exciting%20in%20the%20world%20of%20cross-network%20authentication.%20Let%27s%20review.%20I%20can%20now%3A%0A%0A%2A%20sign%20into%20Digg%20using%20Facebook%0A%2A%20sign%20into%20%5BDISQUS%5D%28http%3A%2F%2Fdisqus.com%2F%20%22DISQUS%20%7C%20Turn%20Blog%20Comments%20into%20a%20Webwide%20Discussion%20with%20a%20Powerful%20Comment%20Sys" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;annotation=%0A%0AIt%27s%20getting%20exciting%20in%20the%20world%20of%20cross-network%20authentication.%20Let%27s%20review.%20I%20can%20now%3A%0A%0A%2A%20sign%20into%20Digg%20using%20Facebook%0A%2A%20sign%20into%20%5BDISQUS%5D%28http%3A%2F%2Fdisqus.com%2F%20%22DISQUS%20%7C%20Turn%20Blog%20Comments%20into%20a%20Webwide%20Discussion%20with%20a%20Powerful%20Comment%20Sys" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;notes=%0A%0AIt%27s%20getting%20exciting%20in%20the%20world%20of%20cross-network%20authentication.%20Let%27s%20review.%20I%20can%20now%3A%0A%0A%2A%20sign%20into%20Digg%20using%20Facebook%0A%2A%20sign%20into%20%5BDISQUS%5D%28http%3A%2F%2Fdisqus.com%2F%20%22DISQUS%20%7C%20Turn%20Blog%20Comments%20into%20a%20Webwide%20Discussion%20with%20a%20Powerful%20Comment%20Sys" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;t=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;title=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;body=%0A%0AIt%27s%20getting%20exciting%20in%20the%20world%20of%20cross-network%20authentication.%20Let%27s%20review.%20I%20can%20now%3A%0A%0A%2A%20sign%20into%20Digg%20using%20Facebook%0A%2A%20sign%20into%20%5BDISQUS%5D%28http%3A%2F%2Fdisqus.com%2F%20%22DISQUS%20%7C%20Turn%20Blog%20Comments%20into%20a%20Webwide%20Discussion%20with%20a%20Powerful%20Comment%20Sys" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=The%20Connected%20Web%3A%20Why%20It%27s%20Time%20For%20Strong%20Authentication&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-connected-web-why-its-time-for-strong-authentication" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/dgBSW80L6NWeFASjQ4jQXikWay0/0/da"><img src="http://feedads.g.doubleclick.net/~a/dgBSW80L6NWeFASjQ4jQXikWay0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/dgBSW80L6NWeFASjQ4jQXikWay0/1/da"><img src="http://feedads.g.doubleclick.net/~a/dgBSW80L6NWeFASjQ4jQXikWay0/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Facebook Now Supports OpenID</title>
		<link>http://danielmiessler.com/blog/facebook-now-supports-openid</link>
		<comments>http://danielmiessler.com/blog/facebook-now-supports-openid#comments</comments>
		<pubDate>Tue, 19 May 2009 03:52:31 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OpenID]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/facebook-now-supports-openid</guid>
		<description><![CDATA[

Exciting stuff&#8211;Facebook is rolling out full support for OpenID. Once it&#8217;s done being pushed to all users, you&#8217;ll be able to log in seamlessly to Facebook if you&#8217;re already logged into your OpenID provider.

Combine this with two-factor authentication from PIP, and things are shaping up nicely.

Oh, and they&#8217;re supporting seamless logon from Google as well. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="200" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/vip.jpg" alt="pip" /></p>

<p>Exciting stuff&#8211;Facebook is rolling out full support for OpenID. Once it&#8217;s done being pushed to all users, you&#8217;ll be able to log in seamlessly to Facebook if you&#8217;re already logged into your OpenID provider.</p>

<p>Combine this with <a href="http://dmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Verisign VIP for Two-Factor Authentication, and PIP for OpenID | dmiessler.com">two-factor authentication from PIP</a>, and things are shaping up nicely.</p>

<p>Oh, and they&#8217;re supporting seamless logon from Google as well. Very cool stuff. ::</p>

<p class="post_update">[ 2009-05-19 : Confirmed--I just logged out of Facebook and re-visited the homepage while logged into my OpenID provider (with two-factor, mind you). It seamlessly logged me in. Totally sick. ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" rel="bookmark">Verisign VIP for Two-Factor Authentication, and PIP for OpenID</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark">The Connected Web: Why It's Time For Strong Authentication</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark">Implementing OpenID</a></li><li><a href="http://danielmiessler.com/blog/rsa-day-1" rel="bookmark">RSA: Day 1</a></li><li><a href="http://danielmiessler.com/blog/verisign-pip-openid-delegation-code" rel="bookmark">Verisign PIP OpenID Delegation Code</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID&amp;bodytext=%0A%0AExciting%20stuff--Facebook%20is%20rolling%20out%20full%20support%20for%20OpenID.%20Once%20it%27s%20done%20being%20pushed%20to%20all%20users%2C%20you%27ll%20be%20able%20to%20log%20in%20seamlessly%20to%20Facebook%20if%20you%27re%20already%20logged%20into%20your%20OpenID%20provider.%0A%0ACombine%20this%20with%20%5Btwo-factor%20authentica" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID&amp;annotation=%0A%0AExciting%20stuff--Facebook%20is%20rolling%20out%20full%20support%20for%20OpenID.%20Once%20it%27s%20done%20being%20pushed%20to%20all%20users%2C%20you%27ll%20be%20able%20to%20log%20in%20seamlessly%20to%20Facebook%20if%20you%27re%20already%20logged%20into%20your%20OpenID%20provider.%0A%0ACombine%20this%20with%20%5Btwo-factor%20authentica" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID&amp;notes=%0A%0AExciting%20stuff--Facebook%20is%20rolling%20out%20full%20support%20for%20OpenID.%20Once%20it%27s%20done%20being%20pushed%20to%20all%20users%2C%20you%27ll%20be%20able%20to%20log%20in%20seamlessly%20to%20Facebook%20if%20you%27re%20already%20logged%20into%20your%20OpenID%20provider.%0A%0ACombine%20this%20with%20%5Btwo-factor%20authentica" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Facebook%20Now%20Supports%20OpenID&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;t=Facebook%20Now%20Supports%20OpenID" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Facebook%20Now%20Supports%20OpenID%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;title=Facebook%20Now%20Supports%20OpenID&amp;body=%0A%0AExciting%20stuff--Facebook%20is%20rolling%20out%20full%20support%20for%20OpenID.%20Once%20it%27s%20done%20being%20pushed%20to%20all%20users%2C%20you%27ll%20be%20able%20to%20log%20in%20seamlessly%20to%20Facebook%20if%20you%27re%20already%20logged%20into%20your%20OpenID%20provider.%0A%0ACombine%20this%20with%20%5Btwo-factor%20authentica" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Facebook%20Now%20Supports%20OpenID&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Ffacebook-now-supports-openid" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/AvSZjwgJeLsCeLm7bVGnKyp62-8/0/da"><img src="http://feedads.g.doubleclick.net/~a/AvSZjwgJeLsCeLm7bVGnKyp62-8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/AvSZjwgJeLsCeLm7bVGnKyp62-8/1/da"><img src="http://feedads.g.doubleclick.net/~a/AvSZjwgJeLsCeLm7bVGnKyp62-8/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/facebook-now-supports-openid/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>10 Essential Firefox Plugins for the Infosec Professional</title>
		<link>http://danielmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional</link>
		<comments>http://danielmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional#comments</comments>
		<pubDate>Tue, 28 Apr 2009 04:31:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional</guid>
		<description><![CDATA[

I&#8217;ve moved to Chrome and Safari as my primary browsers, but nothing compares to Firefox when it comes to functionality and plugin support. Shown below are the information security related plugins I recommend any infosec professional (or enthusiast) install upon spinning up a new Firefox instance. 

XSS Me

This plugin discovers all the fields on the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/ff-plugins.png" alt="ff_plugins" /></p>

<p>I&#8217;ve moved to <a href="http://www.google.com/chrome" title="Google Chrome - Download a new browser">Chrome</a> and <a href="http://www.apple.com/safari/" title="Apple - Safari - Introducing Safari 4 - See the web in a whole new way">Safari</a> as my primary browsers, but nothing compares to <a href="http://www.mozilla.com/firefox/" title="Firefox web browser | Faster, more secure, &amp; customizable">Firefox</a> when it comes to functionality and plugin support. Shown below are the information security related plugins I recommend any infosec professional (or enthusiast) install upon spinning up a new Firefox instance. </p>

<h2>XSS Me</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/7598">This plugin</a> discovers all the fields on the current page, and gives you the option to launch targeted attacks on each field, or to launch all of its attacks against all fields.</p>

<p style="text-align:center"><img width="" height="400" src="http://dmiessler.com/wp-content/uploads/2009/04/xssme.png" alt="xssme" /></p>

<h2>SQL Inject Me</h2>

<p>From the same group as XSS Me, <a href="https://addons.mozilla.org/en-US/firefox/addon/7597">this plugin</a> finds all fields on the page you&#8217;re on and let&#8217;s you launch the most common SQL injection attacks against them.</p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/sqlinjectme.png" alt="sqlinjectme" /></p>

<h2>Live HTTP Headers</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/3829">See exactly what your browser is sending</a> and receiving in real-time.</p>

<p style="text-align:center"><img width="400" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/livehttpheaders.png" alt="livehttpheaders" /></p>

<h2>User Agent Switcher</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/59">Change your user-agent</a> on the fly. So, you can make it look like you&#8217;re coming from Lynx running on AIX, or like you&#8217;re the GoogleBot.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/useragentswitcher.png" alt="useragentswitcher" /></p>

<h2>Web Developer</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/60">Modify all sorts of options</a> related to the site you&#8217;re viewing. Disable scripting, modify forms, etc., etc. Trust me&#8211;good stuff.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/webdeveloper.png" alt="webdeveloper" /></p>

<h2>Tamper Data</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/966">Lets you view the data that&#8217;s being passed back and forth between you and the web server&#8230;and let&#8217;s you mess with it</a>. Think &#8220;WebScarab&#8221;, but far simpler, and as a Firefox plugin.</p>

<p style="text-align:center"><img width="400" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/tamperdata.png" alt="tamperdata" /></p>

<h2>ASnumber</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2072">Find the Autonomous System Number</a> (ASN) of the network that your current site is served from. Simple. Useful.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/asnumber.gif" alt="asnumber" /></p>

<h2>DT Whois</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2855">Do a domaintools.com lookup</a> of the site you&#8217;re currently visiting. If you haven&#8217;t used <a href="http://www.domaintools.com/" title="Domain Tools: Whois Lookup and Domain Suggestions">domaintools.com</a> yet, you&#8217;ll be even more impressed.</p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/domaintools1.gif" alt="domaintools" /></p>

<h2>Firebug</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1843">Gives you a developer&#8217;s view</a> into the page you&#8217;re viewing, showing exactly what scripts are running, what the stylesheet is, etc. Oh, and let&#8217;s you change them and see what the result would be. Not really a security thing, but strong enough to be included in a list of musts.</p>

<p style="text-align:center"><img width="400" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/firebug.gif" alt="firebug" /></p>

<h2>SwitchProxy Tool</h2>

<p><a href="https://addons.mozilla.org/en-US/firefox/addon/125">Allows you to quickly switch back and forth between multiple proxies</a>, or between using your main proxy and going straight out to the Internet. My configuration always includes at least one proxy: localhost:8008 for WebScarab.</p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/switchproxy.png" alt="switchproxy" /></p>

<h2>Hackbar</h2>

<p>This tool, added on Zach&#8217;s (@quine&#8217;s) request, is kind of interesting. It allows a lot of functionality from a very simple interface. Essentially, it presents you with the ability to modify the current URL in a number of interesting ways, including giving access to a number of simple tools for translating data formats. Worth adding to the list of essentials.</p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/hackbar.png" alt="hackbar" /></p>

<p>So there they are. If you have any I should add to this list of essentials, do let me know in the comments or via <a href="http://dmiessler.com/contact/">email</a>. ::</p>

<p><span class="attribution">(Thanks to those who helped me build this list including Johannes Ulrich and Steve Crapo)</span></p>

<h3>Related</h3>

<p>[ <a href="http://feeds.dmiessler.com/blog_informationsecurity" title="dmiessler.com » Information Security">Information Security Posts | dmiessler.com</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/a-firefox-theme" rel="bookmark">A Firefox Theme</a></li><li><a href="http://danielmiessler.com/blog/a-mandatory-firefox-extension" rel="bookmark">A Mandatory Firefox Extension</a></li><li><a href="http://danielmiessler.com/blog/firefox-universal" rel="bookmark">Firefox Universal</a></li><li><a href="http://danielmiessler.com/blog/on-my-site-firefox-rules" rel="bookmark">On My Site, Firefox Rules</a></li><li><a href="http://danielmiessler.com/blog/camino-rocks-but" rel="bookmark">Camino Rocks, But...</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;bodytext=%0A%0AI%27ve%20moved%20to%20%5BChrome%5D%28http%3A%2F%2Fwww.google.com%2Fchrome%20%22Google%20Chrome%20-%20Download%20a%20new%20browser%22%29%20and%20%5BSafari%5D%28http%3A%2F%2Fwww.apple.com%2Fsafari%2F%20%22Apple%20-%20Safari%20-%20Introducing%20Safari%204%20-%20See%20the%20web%20in%20a%20whole%20new%20way%22%29%20as%20my%20primary%20browsers%2C%20but%20nothing%20co" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;annotation=%0A%0AI%27ve%20moved%20to%20%5BChrome%5D%28http%3A%2F%2Fwww.google.com%2Fchrome%20%22Google%20Chrome%20-%20Download%20a%20new%20browser%22%29%20and%20%5BSafari%5D%28http%3A%2F%2Fwww.apple.com%2Fsafari%2F%20%22Apple%20-%20Safari%20-%20Introducing%20Safari%204%20-%20See%20the%20web%20in%20a%20whole%20new%20way%22%29%20as%20my%20primary%20browsers%2C%20but%20nothing%20co" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;notes=%0A%0AI%27ve%20moved%20to%20%5BChrome%5D%28http%3A%2F%2Fwww.google.com%2Fchrome%20%22Google%20Chrome%20-%20Download%20a%20new%20browser%22%29%20and%20%5BSafari%5D%28http%3A%2F%2Fwww.apple.com%2Fsafari%2F%20%22Apple%20-%20Safari%20-%20Introducing%20Safari%204%20-%20See%20the%20web%20in%20a%20whole%20new%20way%22%29%20as%20my%20primary%20browsers%2C%20but%20nothing%20co" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;t=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;title=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;body=%0A%0AI%27ve%20moved%20to%20%5BChrome%5D%28http%3A%2F%2Fwww.google.com%2Fchrome%20%22Google%20Chrome%20-%20Download%20a%20new%20browser%22%29%20and%20%5BSafari%5D%28http%3A%2F%2Fwww.apple.com%2Fsafari%2F%20%22Apple%20-%20Safari%20-%20Introducing%20Safari%204%20-%20See%20the%20web%20in%20a%20whole%20new%20way%22%29%20as%20my%20primary%20browsers%2C%20but%20nothing%20co" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=10%20Essential%20Firefox%20Plugins%20for%20the%20Infosec%20Professional&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2F10-essential-firefox-plugins-for-the-infosec-professional" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/w9xwegkGAKdicgL2JKZzN7uQSwM/0/da"><img src="http://feedads.g.doubleclick.net/~a/w9xwegkGAKdicgL2JKZzN7uQSwM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/w9xwegkGAKdicgL2JKZzN7uQSwM/1/da"><img src="http://feedads.g.doubleclick.net/~a/w9xwegkGAKdicgL2JKZzN7uQSwM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Verisign VIP for Two-Factor Authentication, and PIP for OpenID</title>
		<link>http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid</link>
		<comments>http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid#comments</comments>
		<pubDate>Sun, 26 Apr 2009 14:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid</guid>
		<description><![CDATA[I&#8217;ve been using Verisign VIP for a while now with a hard token like the one seen below. It allows you to add two-factor authentication to sites like Ebay and PayPal.



But at RSA 2009, which I just returned from, I found out Verisign has released a soft token as well, and it works for all [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been using <a href="http://www.verisign.com/authentication/consumer-authentication/vip-authentication/" title="VIP Authentication Services - two-factor authentictation from VeriSign, Inc.">Verisign VIP</a> for a while now with a hard token like the one seen below. It allows you to add two-factor authentication to sites like <a href="http://www.ebay.com/" title="eBay - New &amp; used electronics, cars, apparel, collectibles, sporting goods &amp; more at low prices">Ebay</a> and <a href="http://www.paypal.com/">PayPal</a>.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/vip-token.jpg" alt="vip_token" /></p>

<p>But at <a href="http://www.rsaconference.com/2009/us/index.htm" title="RSA Conference 2009: World's Largest Information Security Industry Conference and Expo">RSA 2009</a>, which I just returned from, I found out Verisign has released a soft token as well, and it works for all the main mobile platforms&#8211;including iPhone. The app is <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewSoftware?id=307658513&amp;mt=8" title="iTunes Store">free from the app store</a>, and here&#8217;s how it looks:</p>

<p style="text-align:center"><img width="" height="300" src="http://dmiessler.com/wp-content/uploads/2009/04/vip.jpg" alt="vip" /></p>

<p>So you&#8217;re probably asking what all this works with. Well, <a href="https://idprotect.verisign.com/wheretouse.v">here&#8217;s a list</a> of supported websites:</p>

<p style="text-align:center"><img width="300" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/vip-sites.png" alt="vip_sites" /></p>

<p>These sites directly support Verisign VIP, which is really just an OATH-based multi-factor authentication system.</p>

<p>This is cool, but the real reach of this system is that you can use your VIP credential as a second factor to <a href="https://pip.verisignlabs.com/">pip.verisignlabs.com</a>, which is Verisign&#8217;s <a href="http://openid.net/" title="OpenID">OpenID</a> implementation.</p>

<p>And that&#8217;s why I use Verisign for my OpenID system: it&#8217;s not only a solid OpenID implementation, but it also allows me to use a token for two-factor authentication. And now that they have a soft-token for the iPhone, it&#8217;s even better.</p>

<p>I suggest you check it out. ::</p>

<h3>Links</h3>

<p>[ <a href="http://www.verisign.com/authentication/consumer-authentication/vip-authentication/" title="VIP Authentication Services - two-factor authentictation from VeriSign, Inc.">Verisign VIP (Two-Factor Auth) | verisign.com</a> ]<br />
[ <a href="https://pip.verisignlabs.com/">Verisign PIP (OpenID) | verisignlabs.com</a> ]<br /></p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/facebook-now-supports-openid" rel="bookmark">Facebook Now Supports OpenID</a></li><li><a href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication" rel="bookmark">The Connected Web: Why It's Time For Strong Authentication</a></li><li><a href="http://danielmiessler.com/blog/verisign-pip-openid-delegation-code" rel="bookmark">Verisign PIP OpenID Delegation Code</a></li><li><a href="http://danielmiessler.com/blog/rsa-day-1" rel="bookmark">RSA: Day 1</a></li><li><a href="http://danielmiessler.com/blog/implementing-openid" rel="bookmark">Implementing OpenID</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;bodytext=I%27ve%20been%20using%20%5BVerisign%20VIP%5D%28http%3A%2F%2Fwww.verisign.com%2Fauthentication%2Fconsumer-authentication%2Fvip-authentication%2F%20%22VIP%20Authentication%20Services%20-%20two-factor%20authentictation%20from%20VeriSign%2C%20Inc.%22%29%20for%20a%20while%20now%20with%20a%20hard%20token%20like%20the%20one%20seen%20belo" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;annotation=I%27ve%20been%20using%20%5BVerisign%20VIP%5D%28http%3A%2F%2Fwww.verisign.com%2Fauthentication%2Fconsumer-authentication%2Fvip-authentication%2F%20%22VIP%20Authentication%20Services%20-%20two-factor%20authentictation%20from%20VeriSign%2C%20Inc.%22%29%20for%20a%20while%20now%20with%20a%20hard%20token%20like%20the%20one%20seen%20belo" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;notes=I%27ve%20been%20using%20%5BVerisign%20VIP%5D%28http%3A%2F%2Fwww.verisign.com%2Fauthentication%2Fconsumer-authentication%2Fvip-authentication%2F%20%22VIP%20Authentication%20Services%20-%20two-factor%20authentictation%20from%20VeriSign%2C%20Inc.%22%29%20for%20a%20while%20now%20with%20a%20hard%20token%20like%20the%20one%20seen%20belo" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;t=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;title=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;body=I%27ve%20been%20using%20%5BVerisign%20VIP%5D%28http%3A%2F%2Fwww.verisign.com%2Fauthentication%2Fconsumer-authentication%2Fvip-authentication%2F%20%22VIP%20Authentication%20Services%20-%20two-factor%20authentictation%20from%20VeriSign%2C%20Inc.%22%29%20for%20a%20while%20now%20with%20a%20hard%20token%20like%20the%20one%20seen%20belo" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Verisign%20VIP%20for%20Two-Factor%20Authentication%2C%20and%20PIP%20for%20OpenID&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fverisign-vip-for-two-factor-authentication-and-pip-for-openid" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/5ugmZ6Msw2LUDeKzegQrNOzy1q4/0/da"><img src="http://feedads.g.doubleclick.net/~a/5ugmZ6Msw2LUDeKzegQrNOzy1q4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/5ugmZ6Msw2LUDeKzegQrNOzy1q4/1/da"><img src="http://feedads.g.doubleclick.net/~a/5ugmZ6Msw2LUDeKzegQrNOzy1q4/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to Get Around the md5sum Carriage Return Issue</title>
		<link>http://danielmiessler.com/blog/how-to-get-around-the-md5sum-carriage-return-issue</link>
		<comments>http://danielmiessler.com/blog/how-to-get-around-the-md5sum-carriage-return-issue#comments</comments>
		<pubDate>Mon, 20 Apr 2009 21:03:26 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Sysadmin]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=5442</guid>
		<description><![CDATA[

There&#8217;s an issue with md5sum where it returns unexpected results due to the fact that appends a carriage return to what you&#8217;re trying to get a sum of.

So if you try and get a sum of &#8220;password&#8221; by summing a file with the word &#8220;password&#8221; as the only line in the file, you won&#8217;t actually [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://www.iusmentis.com/technology/hashfunctions/md5/md5operation.gif" /></center></p>

<p>There&#8217;s an issue with <code>md5sum</code> where it returns unexpected results due to the fact that appends a carriage return to what you&#8217;re trying to get a sum of.</p>

<p>So if you try and get a sum of &#8220;password&#8221; by summing a file with the word &#8220;password&#8221; as the only line in the file, you won&#8217;t actually be summing &#8220;password&#8221;, but rather &#8220;password[^M]&#8220;, which obviously won&#8217;t be the same.</p>

<h2>The Fix</h2>

<p>So a quick fix for this is to use <code>echo</code> to feed <code>md5sum</code> with the <code>-n</code> option, which removes the trailing carriage return:</p>

<p><pre class="brush: bash">echo -n &quot;password&quot; | md5sum</pre></p>

<p>::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion" rel="bookmark">Installing the Latest Version of Nmap Using Subversion</a></li><li><a href="http://danielmiessler.com/blog/linux-xargs-vs-exec" rel="bookmark">Linux: <code>xargs</code> vs. <code>exec {}</code></a></li><li><a href="http://danielmiessler.com/blog/learning-git" rel="bookmark">Learning git</a></li><li><a href="http://danielmiessler.com/blog/howto-use-splunk-as-your-remote-syslog-server" rel="bookmark">HOWTO: Use Splunk as Your Remote Syslog Server</a></li><li><a href="http://danielmiessler.com/blog/getting-with-git" rel="bookmark">Getting with Git</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;bodytext=%0D%0A%0D%0AThere%27s%20an%20issue%20with%20md5sum%20where%20it%20returns%20unexpected%20results%20due%20to%20the%20fact%20that%20appends%20a%20carriage%20return%20to%20what%20you%27re%20trying%20to%20get%20a%20sum%20of.%0D%0A%0D%0ASo%20if%20you%20try%20and%20get%20a%20sum%20of%20%22password%22%20by%20summing%20a%20file%20with%20the%20word%20%22password%22%20as%20the%20" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;annotation=%0D%0A%0D%0AThere%27s%20an%20issue%20with%20md5sum%20where%20it%20returns%20unexpected%20results%20due%20to%20the%20fact%20that%20appends%20a%20carriage%20return%20to%20what%20you%27re%20trying%20to%20get%20a%20sum%20of.%0D%0A%0D%0ASo%20if%20you%20try%20and%20get%20a%20sum%20of%20%22password%22%20by%20summing%20a%20file%20with%20the%20word%20%22password%22%20as%20the%20" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;notes=%0D%0A%0D%0AThere%27s%20an%20issue%20with%20md5sum%20where%20it%20returns%20unexpected%20results%20due%20to%20the%20fact%20that%20appends%20a%20carriage%20return%20to%20what%20you%27re%20trying%20to%20get%20a%20sum%20of.%0D%0A%0D%0ASo%20if%20you%20try%20and%20get%20a%20sum%20of%20%22password%22%20by%20summing%20a%20file%20with%20the%20word%20%22password%22%20as%20the%20" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;t=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;title=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;body=%0D%0A%0D%0AThere%27s%20an%20issue%20with%20md5sum%20where%20it%20returns%20unexpected%20results%20due%20to%20the%20fact%20that%20appends%20a%20carriage%20return%20to%20what%20you%27re%20trying%20to%20get%20a%20sum%20of.%0D%0A%0D%0ASo%20if%20you%20try%20and%20get%20a%20sum%20of%20%22password%22%20by%20summing%20a%20file%20with%20the%20word%20%22password%22%20as%20the%20" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=How%20to%20Get%20Around%20the%20md5sum%20Carriage%20Return%20Issue&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-get-around-the-md5sum-carriage-return-issue" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/NDxZm_RCAzJc59wZ38g_wKoqa3Q/0/da"><img src="http://feedads.g.doubleclick.net/~a/NDxZm_RCAzJc59wZ38g_wKoqa3Q/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/NDxZm_RCAzJc59wZ38g_wKoqa3Q/1/da"><img src="http://feedads.g.doubleclick.net/~a/NDxZm_RCAzJc59wZ38g_wKoqa3Q/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/how-to-get-around-the-md5sum-carriage-return-issue/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prominent Infosec Personalities That Use OS X</title>
		<link>http://danielmiessler.com/blog/prominent-infosec-personalities-that-use-os-x</link>
		<comments>http://danielmiessler.com/blog/prominent-infosec-personalities-that-use-os-x#comments</comments>
		<pubDate>Sun, 19 Apr 2009 22:55:50 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OS X]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=5432</guid>
		<description><![CDATA[

I often have to explain to other IT people (and even too many in infosec) why I prefer OS X as my primary operating system. If you lack the time to make a complete argument, one shortcut to giving strength to your position is to give a list of well-known security professionals that have made [...]]]></description>
			<content:encoded><![CDATA[<p><center><img class="alignnone" title="macsec" src="http://theos.in/wp-content/uploads/2008/04/apple-chains.jpg" alt="" width="320" height="250" /></center></p>

<p>I often have to explain to other IT people (and even too many in infosec) why I prefer OS X as my primary operating system. If you lack the time to make a complete argument, one shortcut to giving strength to your position is to give a list of well-known security professionals that have made the same decision.</p>

<p>So here&#8217;s the beginning of this list; if you want to add someone to it, you can do so in the following ways:
<ol>
    <li>In the comments below</li>
    <li>Email it to me at daniel@dmiessler.com</li>
    <li>Tweet it to me with #macsec appended</li>
</ol>
And here are the people I know of off the top of my head (no particular order):
<ul>
    <li>Martin Roesch</li>
    <li>Mike Poor</li>
    <li>Taylor Banks</li>
    <li>Johannes Ulrich</li>
    <li>Chris Hoff</li>
        <li>Rich Mogull</li>
    <li>Jeremiah Grossman?</li>
</ul>
I know there are a bunch of others I&#8217;ve known and can&#8217;t remember at the moment. That&#8217;s where you come in. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional" rel="bookmark">10 Essential Firefox Plugins for the Infosec Professional</a></li><li><a href="http://danielmiessler.com/blog/a-response-to-mac-elitism-and-snobbery" rel="bookmark">A Response to "Mac Elitism and Snobbery"</a></li><li><a href="http://danielmiessler.com/blog/im-invincible-the-wrong-reason-to-go-with-os-x" rel="bookmark">"I'm Invincible!" : The Wrong Reason To Go With OS X</a></li><li><a href="http://danielmiessler.com/blog/p90x-training-system" rel="bookmark">P90X Training System</a></li><li><a href="http://danielmiessler.com/blog/use-twitter-search-to-find-interesting-people-to-follow" rel="bookmark">Using Twitter Search to Find Interesting People to Follow</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;bodytext=%0D%0A%0D%0AI%20often%20have%20to%20explain%20to%20other%20IT%20people%20%28and%20even%20too%20many%20in%20infosec%29%20why%20I%20prefer%20OS%20X%20as%20my%20primary%20operating%20system.%20If%20you%20lack%20the%20time%20to%20make%20a%20complete%20argument%2C%20one%20shortcut%20to%20giving%20strength%20to%20your%20position%20is%20to%20give%20a%20list%20of%20we" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;annotation=%0D%0A%0D%0AI%20often%20have%20to%20explain%20to%20other%20IT%20people%20%28and%20even%20too%20many%20in%20infosec%29%20why%20I%20prefer%20OS%20X%20as%20my%20primary%20operating%20system.%20If%20you%20lack%20the%20time%20to%20make%20a%20complete%20argument%2C%20one%20shortcut%20to%20giving%20strength%20to%20your%20position%20is%20to%20give%20a%20list%20of%20we" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;notes=%0D%0A%0D%0AI%20often%20have%20to%20explain%20to%20other%20IT%20people%20%28and%20even%20too%20many%20in%20infosec%29%20why%20I%20prefer%20OS%20X%20as%20my%20primary%20operating%20system.%20If%20you%20lack%20the%20time%20to%20make%20a%20complete%20argument%2C%20one%20shortcut%20to%20giving%20strength%20to%20your%20position%20is%20to%20give%20a%20list%20of%20we" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;t=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;title=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;body=%0D%0A%0D%0AI%20often%20have%20to%20explain%20to%20other%20IT%20people%20%28and%20even%20too%20many%20in%20infosec%29%20why%20I%20prefer%20OS%20X%20as%20my%20primary%20operating%20system.%20If%20you%20lack%20the%20time%20to%20make%20a%20complete%20argument%2C%20one%20shortcut%20to%20giving%20strength%20to%20your%20position%20is%20to%20give%20a%20list%20of%20we" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Prominent%20Infosec%20Personalities%20That%20Use%20OS%20X&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fprominent-infosec-personalities-that-use-os-x" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/SKdVZFERaV7aqeHvzMyXgZ8Pdxk/0/da"><img src="http://feedads.g.doubleclick.net/~a/SKdVZFERaV7aqeHvzMyXgZ8Pdxk/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/SKdVZFERaV7aqeHvzMyXgZ8Pdxk/1/da"><img src="http://feedads.g.doubleclick.net/~a/SKdVZFERaV7aqeHvzMyXgZ8Pdxk/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/prominent-infosec-personalities-that-use-os-x/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Monitoring and Controlling Outbound Network Connections on OS X using Little Snitch</title>
		<link>http://danielmiessler.com/blog/monitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch</link>
		<comments>http://danielmiessler.com/blog/monitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch#comments</comments>
		<pubDate>Fri, 03 Apr 2009 05:31:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OS X]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/monitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch</guid>
		<description><![CDATA[

Being in Information Security, I understand that knowing what&#8217;s going on is the first step to being secure. The way this translates to networked computers is knowing who they&#8217;re talking to.

And for this task I use Little Snitch to both monitor and control what applications are able to reach out from my OS X system.



In [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/lsteaser.jpg" alt="lsteaser" /></p>

<p>Being in Information Security, I understand that knowing what&#8217;s going on is the first step to being secure. The way this translates to networked computers is knowing who they&#8217;re talking to.</p>

<p>And for this task I use <a href="http://www.obdev.at/products/littlesnitch/index.html" title="Little Snitch">Little Snitch</a> to both monitor and control what applications are able to reach out from my OS X system.</p>

<p style="text-align:center"><img width="350" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/littlesnitch2.png" alt="littlesnitch2" /></p>

<p class="strong">In addition to being able to control what apps can do what (rule manager seen above), what I most like about this application is being able to roll over the menubar icon to see what apps are currently sending or receiving on the network.</p>

<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/04/littlesnitch.png" alt="littlesnitch" /></p>

<p>So imagine you&#8217;re just writing something locally on your system, and you see that your Little Snitch menu bar icon is lit up (meaning something&#8217;s talking on the network). </p>

<p>You simply touch the menubar icon with your mouse and the window seen above appears to show you <em>exactly</em> what application is talking on the network.</p>

<p>This is invaluable. Nothing is more annoying to a good security person, or even a good sysadmin, than not knowing what on your system is putting packets on the wire. Little Snitch gives you this visibility, and if you&#8217;re running OS X I&#8217;d highly suggest you check it out. ::</p>

<p>[ <a href="http://www.obdev.at/products/littlesnitch/index.html" title="Little Snitch">Little Snitch | obdev.at</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/security-how-to-monitor-your-network-connections" rel="bookmark">Security: How To Monitor Your Network Connections</a></li><li><a href="http://danielmiessler.com/blog/verisign-vip-for-two-factor-authentication-and-pip-for-openid" rel="bookmark">Verisign VIP for Two-Factor Authentication, and PIP for OpenID</a></li><li><a href="http://danielmiessler.com/blog/how-to-display-content-from-other-services-within-facebook-automatically" rel="bookmark">How to Display Content From Other Services Within Facebook Automatically</a></li><li><a href="http://danielmiessler.com/blog/feed-updates" rel="bookmark">Feed Updates</a></li><li><a href="http://danielmiessler.com/blog/10-essential-firefox-plugins-for-the-infosec-professional" rel="bookmark">10 Essential Firefox Plugins for the Infosec Professional</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;bodytext=%0A%0ABeing%20in%20Information%20Security%2C%20I%20understand%20that%20knowing%20what%27s%20going%20on%20is%20the%20first%20step%20to%20being%20secure.%20The%20way%20this%20translates%20to%20networked%20computers%20is%20knowing%20who%20they%27re%20talking%20to.%0A%0AAnd%20for%20this%20task%20I%20use%20%5BLittle%20Snitch%5D%28http%3A%2F%2Fwww.obdev." title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;annotation=%0A%0ABeing%20in%20Information%20Security%2C%20I%20understand%20that%20knowing%20what%27s%20going%20on%20is%20the%20first%20step%20to%20being%20secure.%20The%20way%20this%20translates%20to%20networked%20computers%20is%20knowing%20who%20they%27re%20talking%20to.%0A%0AAnd%20for%20this%20task%20I%20use%20%5BLittle%20Snitch%5D%28http%3A%2F%2Fwww.obdev." title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;notes=%0A%0ABeing%20in%20Information%20Security%2C%20I%20understand%20that%20knowing%20what%27s%20going%20on%20is%20the%20first%20step%20to%20being%20secure.%20The%20way%20this%20translates%20to%20networked%20computers%20is%20knowing%20who%20they%27re%20talking%20to.%0A%0AAnd%20for%20this%20task%20I%20use%20%5BLittle%20Snitch%5D%28http%3A%2F%2Fwww.obdev." title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;t=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;title=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;body=%0A%0ABeing%20in%20Information%20Security%2C%20I%20understand%20that%20knowing%20what%27s%20going%20on%20is%20the%20first%20step%20to%20being%20secure.%20The%20way%20this%20translates%20to%20networked%20computers%20is%20knowing%20who%20they%27re%20talking%20to.%0A%0AAnd%20for%20this%20task%20I%20use%20%5BLittle%20Snitch%5D%28http%3A%2F%2Fwww.obdev." title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Monitoring%20and%20Controlling%20Outbound%20Network%20Connections%20on%20OS%20X%20using%20Little%20Snitch&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fmonitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/nj81RRvC53puma4hum31ksBTogI/0/da"><img src="http://feedads.g.doubleclick.net/~a/nj81RRvC53puma4hum31ksBTogI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/nj81RRvC53puma4hum31ksBTogI/1/da"><img src="http://feedads.g.doubleclick.net/~a/nj81RRvC53puma4hum31ksBTogI/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/monitoring-and-controlling-outbound-network-connections-on-os-x-using-little-snitch/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Security Twits Information Security Group</title>
		<link>http://danielmiessler.com/blog/sectwits</link>
		<comments>http://danielmiessler.com/blog/sectwits#comments</comments>
		<pubDate>Thu, 02 Apr 2009 02:42:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/sectwits</guid>
		<description><![CDATA[

If you&#8217;re into Information Security, and you use Twitter, you probably want to be following @securitytwits. 

It&#8217;s a group of security professionals and enthusiasts that use Twitter to share ideas. The group is herded by Zach Lanier (@quine), and the list of members can be found here online.

For a decent introduction to the ideas behind [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="" height="" src="http://www.security-twits.com/wp-content/nsectwits-c.jpg" alt="securitytwits" /></p>

<p>If you&#8217;re into Information Security, and you use <a href="http://twitter.com/" title="Twitter: What are you doing?">Twitter</a>, you probably want to be following <a href="http://twitter.com/securitytwits">@securitytwits</a>. </p>

<p>It&#8217;s a group of security professionals and enthusiasts that use Twitter to share ideas. The group is herded by Zach Lanier (<a href="http://twitter.com/quine">@quine</a>), and the list of members can be found <a href="http://www.security-twits.com/" title="Security Twits">here</a> online.</p>

<p>For a decent introduction to the ideas behind the group, here&#8217;s a short podcast of Bill Brenner (<a href="http://twitter.com/billbrenner70">@billbrenner70</a>) interviewing Zach on the topic of Twitter itself as well as the Security Twits list.</p>

<p>[ <a href="http://a1448.g.akamai.net/7/1448/25138/v0001/compworld.download.akamai.com/25137/cso/podcasts/security_perspectives/CSO_PodcastSecTwits_03_31_09.mp3" title="">Bill Brenner / Zach Lanier | csopodcasts</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/getting-more-out-of-twitter-kenswaincom" rel="bookmark">Getting More Out of Twitter | kenswain.com</a></li><li><a href="http://danielmiessler.com/blog/use-twitter-search-to-find-interesting-people-to-follow" rel="bookmark">Using Twitter Search to Find Interesting People to Follow</a></li><li><a href="http://danielmiessler.com/blog/calling-attention-to-twitter-micro-blogging-in-my-sidebar" rel="bookmark">Calling Attention to Twitter Micro-Blogging in my Sidebar</a></li><li><a href="http://danielmiessler.com/blog/is-twitter-just-a-personal-branding-tool" rel="bookmark">Is Twitter Just a Personal Branding Tool?</a></li><li><a href="http://danielmiessler.com/blog/php-security-about-to-get-worse" rel="bookmark">PHP Security About To Get Worse?</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group&amp;bodytext=%0A%0AIf%20you%27re%20into%20Information%20Security%2C%20and%20you%20use%20%5BTwitter%5D%28http%3A%2F%2Ftwitter.com%2F%20%22Twitter%3A%20What%20are%20you%20doing%3F%22%29%2C%20you%20probably%20want%20to%20be%20following%20%40securitytwits.%20%0A%0AIt%27s%20a%20group%20of%20security%20professionals%20and%20enthusiasts%20that%20use%20Twitter%20to%20share%20ide" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group&amp;annotation=%0A%0AIf%20you%27re%20into%20Information%20Security%2C%20and%20you%20use%20%5BTwitter%5D%28http%3A%2F%2Ftwitter.com%2F%20%22Twitter%3A%20What%20are%20you%20doing%3F%22%29%2C%20you%20probably%20want%20to%20be%20following%20%40securitytwits.%20%0A%0AIt%27s%20a%20group%20of%20security%20professionals%20and%20enthusiasts%20that%20use%20Twitter%20to%20share%20ide" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group&amp;notes=%0A%0AIf%20you%27re%20into%20Information%20Security%2C%20and%20you%20use%20%5BTwitter%5D%28http%3A%2F%2Ftwitter.com%2F%20%22Twitter%3A%20What%20are%20you%20doing%3F%22%29%2C%20you%20probably%20want%20to%20be%20following%20%40securitytwits.%20%0A%0AIt%27s%20a%20group%20of%20security%20professionals%20and%20enthusiasts%20that%20use%20Twitter%20to%20share%20ide" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=The%20Security%20Twits%20Information%20Security%20Group&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;t=The%20Security%20Twits%20Information%20Security%20Group" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=The%20Security%20Twits%20Information%20Security%20Group%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;title=The%20Security%20Twits%20Information%20Security%20Group&amp;body=%0A%0AIf%20you%27re%20into%20Information%20Security%2C%20and%20you%20use%20%5BTwitter%5D%28http%3A%2F%2Ftwitter.com%2F%20%22Twitter%3A%20What%20are%20you%20doing%3F%22%29%2C%20you%20probably%20want%20to%20be%20following%20%40securitytwits.%20%0A%0AIt%27s%20a%20group%20of%20security%20professionals%20and%20enthusiasts%20that%20use%20Twitter%20to%20share%20ide" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=The%20Security%20Twits%20Information%20Security%20Group&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fsectwits" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/TjyTL8nLke6gBU7Je_H5hs2A4zY/0/da"><img src="http://feedads.g.doubleclick.net/~a/TjyTL8nLke6gBU7Je_H5hs2A4zY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/TjyTL8nLke6gBU7Je_H5hs2A4zY/1/da"><img src="http://feedads.g.doubleclick.net/~a/TjyTL8nLke6gBU7Je_H5hs2A4zY/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/sectwits/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://a1448.g.akamai.net/7/1448/25138/v0001/compworld.download.akamai.com/25137/cso/podcasts/security_perspectives/CSO_PodcastSecTwits_03_31_09.mp3" length="14083448" type="audio/mpeg" />
		</item>
		<item>
		<title>The Problem With Selling Information Security as a “Business Enabler”</title>
		<link>http://danielmiessler.com/blog/the-problem-with-selling-information-security-as-a-business-enabler</link>
		<comments>http://danielmiessler.com/blog/the-problem-with-selling-information-security-as-a-business-enabler#comments</comments>
		<pubDate>Thu, 26 Mar 2009 19:02:08 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=5144</guid>
		<description><![CDATA[

A random, innocent tweet by Gunnar Peterson (@oneraindrop) got me emoting about whether or not Information Security should be viewed/pitched as a business enabler.  This is the tweet that got me going:
Please remember that security is a business enabler kthxbye
And I disagree(d).
Security isn&#8217;t an &#8220;enabler&#8221;; that line can hurt us. Security is about NOT [...]]]></description>
			<content:encoded><![CDATA[<p><img title="plumbing" src="http://dmiessler.com/wp-content/uploads/2009/03/plumbing1.jpg" alt="plumbing" width="375" height="314" /></p>

<p>A random, innocent tweet by Gunnar Peterson (<a href="http://twitter.com/oneraindrop">@oneraindrop</a>) got me emoting about whether or not Information Security should be viewed/pitched as a business enabler.  <a href="http://twitter.com/oneraindrop/status/1388111729">This</a> is the tweet that got me going:
<blockquote>Please remember that security is a business enabler kthxbye</blockquote>
And I disagree(d).
<blockquote>Security isn&#8217;t an &#8220;enabler&#8221;; that line can hurt us. Security is about NOT doing things wrong, as part of overall quality. To &#8220;enable&#8221; business is to add value above and beyond simply not sucking. So if security is an enabler then so is an oven mit.</blockquote>
At that point my friend Ken (<a href="http://twitter.com/kenotic">@kenotic</a>) got involved and said that the oven mit WAS an enabler because without it you&#8217;d hurt yourself and not be able to cook. He essentially argued that security is necessary for business, and it enables business to take place, so it (by definition) IS a business enabler. That&#8217;s hard to argue from a technical standpoint; I mean the word is right there in the definition.</p>

<p>My problem with that approach is that it widens the definition so much as to make it useless. If a word means everything then it means nothing. And if everything a company does, including having fire extinguishers and a parking lot, is going to be called a &#8220;business enabler&#8221;, then there&#8217;s no point in pitching infosec as one as well.</p>

<p>But let&#8217;s not get too caught up with definitions. Business &#8220;enabler&#8221; might mean different things to different people, and I agree that it CAN mean everything including free coffee and hand sanitizer. But that&#8217;s not what matters. What matters is what it means to those we&#8217;re selling it to, i.e. the business. So if you say to a business person, in an attempt to promote information security, that information security &#8220;enables&#8221; business, I think you should have a more direct link in your claim than one to general supporting infrastructure.</p>

<p>And that&#8217;s where Gunnar added to the conversation again with a simple yet powerful quote:
<blockquote>&#8220;Because we have brakes in our cars we can drive fast.&#8221; &#8211; Robert Garigue</blockquote>
The beauty of the brakes-to-speed analogy is that it transfers nicely to business. So a company could be agile in that they are able to forge new partnerships quickly (speed), but they could be bad at securing their assets when doing so (no brakes), which makes them more likely to crash. As a result, the business will be less likely to move quickly (speed/agility) because they don&#8217;t have the brakes (security) to do so safely.</p>

<p>I&#8217;ve always liked this analogy, and I&#8217;ve used it before when flirting with the whole concept of &#8220;business enabling&#8221; and &#8220;security ROI&#8221; in the past. But I no longer believe in such things.</p>

<p>The reason this analogy fails is that it is looking at the speed of the car WITHOUT brakes as a comparison to the speed of the car WITH brakes. This is wrong. The speed of the car is the speed WITH brakes, and improvements to the brakes are improvements to the car. The car as a whole is all that matters. It&#8217;s infrastructure. It&#8217;s plumbing.</p>

<p>In a CEO&#8217;s big picture, there&#8217;s no difference between a web application firewall and a fire alarm and sprinkler system. Ultimately they both reduce to one thing: <strong>an </strong><strong>operating expense</strong>. I think IT in general <em>can </em>be an enabler, say through a new VPN system that lets a CEO quickly spin up a workforce, but even then it&#8217;s not likely to be perceived, by the business, as the same type of &#8220;enabler&#8221; as an ad campaign, for example.</p>

<p>I have more to say on this, but the ideas are still brewing. I&#8217;d love to hear thoughts in the interim. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/time-to-switch-from-debit-to-credit-when-paying-for-things" rel="bookmark">Time to Switch From Debit to Credit When Paying for Things?</a></li><li><a href="http://danielmiessler.com/blog/a-three-sentence-description-of-solid-foreign-security-policy-aka-how-non-interventionism-increases-security" rel="bookmark">A Three Sentence Description of Solid Foreign Security Policy: AKA "How Non Interventionism Increases Security"</a></li><li><a href="http://danielmiessler.com/blog/is-information-security-education-failing" rel="bookmark">Is Information Security Education Failing?</a></li><li><a href="http://danielmiessler.com/blog/what-are-atheists-so-upset-about" rel="bookmark">What Are Atheists So Upset About?</a></li><li><a href="http://danielmiessler.com/blog/this-might-be-my-next-certification" rel="bookmark">This Might Be My Next Certification</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;bodytext=%0D%0A%0D%0AA%20random%2C%20innocent%20tweet%20by%20Gunnar%20Peterson%20%28%40oneraindrop%29%20got%20me%20emoting%20about%20whether%20or%20not%20Information%20Security%20should%20be%20viewed%2Fpitched%20as%20a%20business%20enabler.%20%20This%20is%20the%20tweet%20that%20got%20me%20going%3A%0D%0APlease%20remember%20that%20security%20is%20a%20business" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;annotation=%0D%0A%0D%0AA%20random%2C%20innocent%20tweet%20by%20Gunnar%20Peterson%20%28%40oneraindrop%29%20got%20me%20emoting%20about%20whether%20or%20not%20Information%20Security%20should%20be%20viewed%2Fpitched%20as%20a%20business%20enabler.%20%20This%20is%20the%20tweet%20that%20got%20me%20going%3A%0D%0APlease%20remember%20that%20security%20is%20a%20business" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;notes=%0D%0A%0D%0AA%20random%2C%20innocent%20tweet%20by%20Gunnar%20Peterson%20%28%40oneraindrop%29%20got%20me%20emoting%20about%20whether%20or%20not%20Information%20Security%20should%20be%20viewed%2Fpitched%20as%20a%20business%20enabler.%20%20This%20is%20the%20tweet%20that%20got%20me%20going%3A%0D%0APlease%20remember%20that%20security%20is%20a%20business" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;t=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;title=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;body=%0D%0A%0D%0AA%20random%2C%20innocent%20tweet%20by%20Gunnar%20Peterson%20%28%40oneraindrop%29%20got%20me%20emoting%20about%20whether%20or%20not%20Information%20Security%20should%20be%20viewed%2Fpitched%20as%20a%20business%20enabler.%20%20This%20is%20the%20tweet%20that%20got%20me%20going%3A%0D%0APlease%20remember%20that%20security%20is%20a%20business" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=The%20Problem%20With%20Selling%20Information%20Security%20as%20a%20%22Business%20Enabler%22&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-problem-with-selling-information-security-as-a-business-enabler" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/Nb0LmGf-Y3Y_53ZDrsGVYuzGlVo/0/da"><img src="http://feedads.g.doubleclick.net/~a/Nb0LmGf-Y3Y_53ZDrsGVYuzGlVo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Nb0LmGf-Y3Y_53ZDrsGVYuzGlVo/1/da"><img src="http://feedads.g.doubleclick.net/~a/Nb0LmGf-Y3Y_53ZDrsGVYuzGlVo/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/the-problem-with-selling-information-security-as-a-business-enabler/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Dilbert Does Risk Management</title>
		<link>http://danielmiessler.com/blog/dilbert-does-risk-management</link>
		<comments>http://danielmiessler.com/blog/dilbert-does-risk-management#comments</comments>
		<pubDate>Mon, 23 Mar 2009 16:00:12 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=5119</guid>
		<description><![CDATA[
Related PostsA GTD Approach to Organizing and Reading Your FeedsA Three-Dimensional Approach to Organizing Feeds in Google Reader [v2]A Three-Dimensional Approach to Organizing Your Feeds Using Google ReaderWhy Scott Adams is Wrong about AtheismAn Idea For Making Public Policy



	
	
	
	
	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p><a href="http://dilbert.com/strips/comic/2009-03-17/" title="Dilbert.com"><img width="500" src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/40000/5000/200/45279/45279.strip.gif" border="0" alt="Dilbert.com" /></a></p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/a-gtd-approach-to-organizing-and-reading-your-feeds" rel="bookmark">A GTD Approach to Organizing and Reading Your Feeds</a></li><li><a href="http://danielmiessler.com/blog/a-three-dimensional-approach-to-organizing-feeds-in-google-reader-v2" rel="bookmark">A Three-Dimensional Approach to Organizing Feeds in Google Reader [v2]</a></li><li><a href="http://danielmiessler.com/blog/a-three-dimensional-approach-to-organizing-your-feeds-using-google-reader" rel="bookmark">A Three-Dimensional Approach to Organizing Your Feeds Using Google Reader</a></li><li><a href="http://danielmiessler.com/blog/why-scott-adams-is-wrong-about-atheism" rel="bookmark">Why Scott Adams is Wrong about Atheism</a></li><li><a href="http://danielmiessler.com/blog/an-idea-for-making-public-policy" rel="bookmark">An Idea For Making Public Policy</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management&amp;bodytext=" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management&amp;annotation=" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management&amp;notes=" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Dilbert%20Does%20Risk%20Management&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;t=Dilbert%20Does%20Risk%20Management" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Dilbert%20Does%20Risk%20Management%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;title=Dilbert%20Does%20Risk%20Management&amp;body=" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Dilbert%20Does%20Risk%20Management&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fdilbert-does-risk-management" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/m8nmJJYgfmLU8oKFmAmyVGxH48g/0/da"><img src="http://feedads.g.doubleclick.net/~a/m8nmJJYgfmLU8oKFmAmyVGxH48g/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/m8nmJJYgfmLU8oKFmAmyVGxH48g/1/da"><img src="http://feedads.g.doubleclick.net/~a/m8nmJJYgfmLU8oKFmAmyVGxH48g/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/dilbert-does-risk-management/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>On the Cisco / Brock Lesnar Analogy</title>
		<link>http://danielmiessler.com/blog/on-the-cisco-brock-lesnar-analogy</link>
		<comments>http://danielmiessler.com/blog/on-the-cisco-brock-lesnar-analogy#comments</comments>
		<pubDate>Fri, 20 Mar 2009 04:20:44 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/on-the-cisco-brock-lesnar-analogy</guid>
		<description><![CDATA[

So a fellow infosec buddy of mine, Hoff, wrote a great piece about how Brock Lesnar is like Cisco. His main points seemed to be that 1) Cisco/Brock is really good in an area other than infosec/mma, and 2) people are mistakenly dismissing them because of this.

Those are solid points, and I agree with his [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/03/brockjpg.jpeg" alt="brock" /></p>

<p>So a fellow infosec buddy of mine, <a href="http://www.rationalsurvivability.com/blog/?page_id=2" title="Rational Survivability &raquo; About">Hoff</a>, wrote a great piece about how <a href="http://www.rationalsurvivability.com/blog/?p=546" title="Rational Survivability &raquo; The UFC and UCS: Cisco Is Brock Lesnar">Brock Lesnar is like Cisco</a>. His main points seemed to be that 1) Cisco/Brock is really good in an area other than infosec/mma, and 2) people are mistakenly dismissing them because of this.</p>

<p>Those are solid points, and I agree with his analysis, i.e. they&#8217;re foolish to underestimate them&#8211;but I have another angle which is where I thought Hoff was going with the analogy when I first saw the title.</p>

<p class="offset">To me the more interesting observation is that &#8220;when skill levels are close to equal, <em>size and strength matter.</em> <b>A lot</b>.</p>

<p>So when Brock fights most people it&#8217;s almost like an adult fighting a young teenager. It&#8217;s almost unfair to the point of brutality. Sure, the teenager <strong>can</strong> win, but the skill difference between him and Brock would have to be extraordinary. And the better Brock gets the lower the chances <em>anyone</em> can be that much better than him.</p>

<p><span style="float: right; margin: 5px 5px 5px 5px;"><script type="text/javascript"><!--
google_ad_client = "pub-2677272500934866";
/* Blog_Content_125x125 */
google_ad_slot = "7181740217";
google_ad_width = 125;
google_ad_height = 125;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</span>It&#8217;s the same with Cisco. They&#8217;re already in your network. They have the routers, they have the switches, they have the VPNs. That&#8217;s the size/power difference between them and <code>$foobrand</code>. It&#8217;s true that many companies have some functionality (technique) that Cisco doesn&#8217;t have, but Cisco is good at being good at things. They can buy a gym and pay someone else to work out for them.</p>

<p>In the end, the Brocks and Ciscos of the world will crush the competition. Not because the competition <em>can&#8217;t</em> win any given battle, but because the more times they fight, and the more time the big guys get to train, the less difference there will be in technique and functionality.</p>

<p>And at that point it&#8217;ll just be a man against a boy. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/what-did-ron-paul-spend-our-money-on" rel="bookmark">What Did Ron Paul Spend Our Money On?</a></li><li><a href="http://danielmiessler.com/blog/mccain-and-clinton-youve-got-to-be-kidding-me" rel="bookmark">McCain and Clinton? You've Got to Be F**king Kidding Me</a></li><li><a href="http://danielmiessler.com/blog/google-why-cant-i-bookmark-a-site-from-google-reader" rel="bookmark">Google: Why Can't I Bookmark a Site From Google Reader?</a></li><li><a href="http://danielmiessler.com/blog/ive-only-seen-this-once-and-it-came-from-a-cisco-security-device" rel="bookmark">I've Only Seen This Once, And It Came From A Cisco Security Device</a></li><li><a href="http://danielmiessler.com/blog/why-twitter-works" rel="bookmark">Why Twitter Works</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;bodytext=%0A%0ASo%20a%20fellow%20infosec%20buddy%20of%20mine%2C%20%5BHoff%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fpage_id%3D2%20%22Rational%20Survivability%20%26raquo%3B%20About%22%29%2C%20wrote%20a%20great%20piece%20about%20how%20%5BBrock%20Lesnar%20is%20like%20Cisco%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fp%3D546%20%22Rat" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;annotation=%0A%0ASo%20a%20fellow%20infosec%20buddy%20of%20mine%2C%20%5BHoff%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fpage_id%3D2%20%22Rational%20Survivability%20%26raquo%3B%20About%22%29%2C%20wrote%20a%20great%20piece%20about%20how%20%5BBrock%20Lesnar%20is%20like%20Cisco%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fp%3D546%20%22Rat" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;notes=%0A%0ASo%20a%20fellow%20infosec%20buddy%20of%20mine%2C%20%5BHoff%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fpage_id%3D2%20%22Rational%20Survivability%20%26raquo%3B%20About%22%29%2C%20wrote%20a%20great%20piece%20about%20how%20%5BBrock%20Lesnar%20is%20like%20Cisco%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fp%3D546%20%22Rat" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;t=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;title=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;body=%0A%0ASo%20a%20fellow%20infosec%20buddy%20of%20mine%2C%20%5BHoff%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fpage_id%3D2%20%22Rational%20Survivability%20%26raquo%3B%20About%22%29%2C%20wrote%20a%20great%20piece%20about%20how%20%5BBrock%20Lesnar%20is%20like%20Cisco%5D%28http%3A%2F%2Fwww.rationalsurvivability.com%2Fblog%2F%3Fp%3D546%20%22Rat" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=On%20the%20Cisco%20%2F%20Brock%20Lesnar%20Analogy&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fon-the-cisco-brock-lesnar-analogy" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/GhzQU_xdlV4N7aqKIbGoKtXXDv8/0/da"><img src="http://feedads.g.doubleclick.net/~a/GhzQU_xdlV4N7aqKIbGoKtXXDv8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/GhzQU_xdlV4N7aqKIbGoKtXXDv8/1/da"><img src="http://feedads.g.doubleclick.net/~a/GhzQU_xdlV4N7aqKIbGoKtXXDv8/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/on-the-cisco-brock-lesnar-analogy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The VIA Model of Security Filtering Technologies</title>
		<link>http://danielmiessler.com/blog/the-via-model-of-security-filtering-technologies</link>
		<comments>http://danielmiessler.com/blog/the-via-model-of-security-filtering-technologies#comments</comments>
		<pubDate>Tue, 10 Mar 2009 17:42:49 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/the-via-model-of-security-filtering-technologies</guid>
		<description><![CDATA[

I inwardly smile when I hear the term &#8220;Unified Threat Management&#8221;. It means different things to different people, but to me it means consolidating the different &#8220;types&#8221; of security filtering, e.g.:


ACLs
Firewalling
Stateful Inspection
Deep Packet Inspection (whatever that is)
Network Intrusion Detection
Network Intrusion Prevention
Application Security Filtering (Web, Database, etc.)


&#8230;onto a single device.

This isn&#8217;t really all that special. The [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align:center"><img width="500" height="500" src="http://dmiessler.com/wp-content/uploads/2009/03/via-model.png" alt="via_model" /></p>

<p>I inwardly smile when I hear the term &#8220;Unified Threat Management&#8221;. It means different things to different people, but to me it means consolidating the different &#8220;types&#8221; of security filtering, e.g.:</p>

<ul>
<li>ACLs</li>
<li>Firewalling</li>
<li>Stateful Inspection</li>
<li>Deep Packet Inspection (whatever that is)</li>
<li>Network Intrusion Detection</li>
<li>Network Intrusion Prevention</li>
<li>Application Security Filtering (Web, Database, etc.)</li>
</ul>

<p>&#8230;onto a single device.</p>

<p>This isn&#8217;t really all that special. The only reason things didn&#8217;t start out this way in the first place is because the technology wasn&#8217;t there yet. We didn&#8217;t have the horsepower on the devices nor the various types of inspection to leverage. </p>

<p>So now the technology is finally catching up, and the marketing folks evidently decided not to go with, &#8220;UTM: The Way Things Were Supposed to Be Originally!&#8221; as their slogan.</p>

<h2>The VIA Model</h2>

<p>The reason combining these various pieces is brutally obvious is because they&#8217;re all doing the same thing. There is, fundamentally, very little difference between a router ACL and a Web Application Firewall. Once distilled there are basically three components to any security filter:</p>

<ol>
<li><strong>Visibility</strong>: what portion of the input does the system inspect?</li>
<li><strong>Identification</strong>: what types of knowledge and/or intelligence can be used evaluate on?</li>
<li><strong>Action</strong>: what can be done once something is found?</li>
</ol>

<p>So what&#8217;s the difference between an IDS and an IPS? In the action phase you get an extra option to drop. Awesome. What&#8217;s the difference between an IPS and a WAF? WAFs understand HTTP better (the identification phase); they both see through layer 7 and can drop stuff they don&#8217;t like. Looking at it this way, even a router ACL and a WAF aren&#8217;t that far apart; the WAF simply beats it in all three VIA categories.</p>

<p>So no matter how cool the name of your filtering system is, it&#8217;s only doing a combination of those three things. It could be &#8220;Deep Packet Inspection&#8221;, or it could be, &#8220;Bob&#8217;s Packet Looker Thingy&#8221;&#8211;either way you have to a) see packets, b) find stuff in them, and c) do something when you do.</p>

<p>That&#8217;s why the future of security filtering is for every trust boundary and every endpoint to be running all of these simultaneously. You see the traffic once, run it through all your various identification pieces, and then you take whatever actions based on your policy.</p>

<p>The fact that we&#8217;re getting to that point doesn&#8217;t constitute evolution; it just means we&#8217;re finally getting to where we should have been all along. ::</p>

<p class="post_note">Hat tip to Markus Ranum for pointing me in this direction back in 2003 with a talk on the difference (or lack thereof) between IDS and IPS.</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/network-security-what-does-a-firewall-mean-to-you" rel="bookmark">Network Security: What Does A Firewall Mean To You?</a></li><li><a href="http://danielmiessler.com/blog/how-not-to-do-firewall-filtering" rel="bookmark">How *Not* To Do Firewall Filtering</a></li><li><a href="http://danielmiessler.com/blog/security-and-obscurity-its-not-what-you-think" rel="bookmark">Security And Obscurity: It's Not What You Think</a></li><li><a href="http://danielmiessler.com/blog/home-network-upgrades" rel="bookmark">Home Network Upgrades</a></li><li><a href="http://danielmiessler.com/blog/security-identification-authentication-and-authorization" rel="bookmark">Security: Identification, Authentication, and Authorization</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;bodytext=%0D%0A%0D%0AI%20inwardly%20smile%20when%20I%20hear%20the%20term%20%22Unified%20Threat%20Management%22.%20It%20means%20different%20things%20to%20different%20people%2C%20but%20to%20me%20it%20means%20consolidating%20the%20different%20%22types%22%20of%20security%20filtering%2C%20e.g.%3A%0D%0A%0D%0A%2A%20ACLs%0D%0A%2A%20Firewalling%0D%0A%2A%20Stateful%20Inspection%0D" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;annotation=%0D%0A%0D%0AI%20inwardly%20smile%20when%20I%20hear%20the%20term%20%22Unified%20Threat%20Management%22.%20It%20means%20different%20things%20to%20different%20people%2C%20but%20to%20me%20it%20means%20consolidating%20the%20different%20%22types%22%20of%20security%20filtering%2C%20e.g.%3A%0D%0A%0D%0A%2A%20ACLs%0D%0A%2A%20Firewalling%0D%0A%2A%20Stateful%20Inspection%0D" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;notes=%0D%0A%0D%0AI%20inwardly%20smile%20when%20I%20hear%20the%20term%20%22Unified%20Threat%20Management%22.%20It%20means%20different%20things%20to%20different%20people%2C%20but%20to%20me%20it%20means%20consolidating%20the%20different%20%22types%22%20of%20security%20filtering%2C%20e.g.%3A%0D%0A%0D%0A%2A%20ACLs%0D%0A%2A%20Firewalling%0D%0A%2A%20Stateful%20Inspection%0D" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;t=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;title=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;body=%0D%0A%0D%0AI%20inwardly%20smile%20when%20I%20hear%20the%20term%20%22Unified%20Threat%20Management%22.%20It%20means%20different%20things%20to%20different%20people%2C%20but%20to%20me%20it%20means%20consolidating%20the%20different%20%22types%22%20of%20security%20filtering%2C%20e.g.%3A%0D%0A%0D%0A%2A%20ACLs%0D%0A%2A%20Firewalling%0D%0A%2A%20Stateful%20Inspection%0D" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=The%20VIA%20Model%20of%20Security%20Filtering%20Technologies&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fthe-via-model-of-security-filtering-technologies" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/dAcYRAaCnaQgOhZ3HMknJL77_hc/0/da"><img src="http://feedads.g.doubleclick.net/~a/dAcYRAaCnaQgOhZ3HMknJL77_hc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/dAcYRAaCnaQgOhZ3HMknJL77_hc/1/da"><img src="http://feedads.g.doubleclick.net/~a/dAcYRAaCnaQgOhZ3HMknJL77_hc/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/the-via-model-of-security-filtering-technologies/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to View Your Otherwise Invisible Flash Cookies</title>
		<link>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies</link>
		<comments>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies#comments</comments>
		<pubDate>Sat, 14 Feb 2009 07:44:42 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies</guid>
		<description><![CDATA[If you have any basic computer knowledge and value your privacy you probably know how to clear your browser&#8217;s cookies and cache. It&#8217;s Internet 101. But newer web technologies like Adobe Flash, Adobe Air, and Microsoft Silverlight complicate things. Deleting &#8220;cookies&#8221; from these technologies isn&#8217;t necessarily done through your browser. 

As an example, if you [...]]]></description>
			<content:encoded><![CDATA[<p>If you have any basic computer knowledge and value your privacy you probably know how to clear your browser&#8217;s cookies and cache. It&#8217;s Internet 101. But newer web technologies like <a href="http://www.adobe.com/products/flashplayer/" title="Adobe Flash Player">Adobe Flash</a>, <a href="http://www.adobe.com/products/air/" title="Adobe - Adobe AIR">Adobe Air</a>, and <a href="http://www.microsoft.com/SILVERLIGHT/">Microsoft Silverlight</a> complicate things. Deleting &#8220;cookies&#8221; from these technologies isn&#8217;t necessarily done through your browser. </p>

<p>As an example, if you use Flash in a standard way you are often sending websites information about the other Flash sites you&#8217;ve been to&#8211;even if you&#8217;ve done the standard browser privacy stuff. So you can <em>think</em> you&#8217;ve covered your tracks, but in fact still be blabbing about where you&#8217;ve been to any site you visit running Flash.</p>

<p><a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html"><p style="text-align:center"><img width="" height="" src="http://dmiessler.com/wp-content/uploads/2009/02/flash-manager.png" alt="flash_manager" /></p></a></p>

<p>Using <a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html" title="Adobe - Flash Player : Settings Manager - Website Storage Settings panel">this application</a> shown above, you can actually see this invisible content. From there you can manage not only the Flash artifacts you currently have, but also apply settings for handling them in the future.</p>

<p>Pass it on. ::</p>

<h3>Links</h3>

<p>[ <a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html" title="Adobe - Flash Player : Settings Manager - Website Storage Settings panel">Flash Cookie Manager | adobe.com</a> ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/adobe-buying-macromedia" rel="bookmark">Adobe Buying Macromedia</a></li><li><a href="http://danielmiessler.com/blog/adobe-reader-updates-evil-same-thing" rel="bookmark">Adobe Reader Updates, Evil -- Same Thing</a></li><li><a href="http://danielmiessler.com/blog/searching-for-a-new-font-color-palette" rel="bookmark">Searching For a New Font Color Palette</a></li><li><a href="http://danielmiessler.com/blog/adobe-buys-macromedia" rel="bookmark">Adobe Buys Macromedia</a></li><li><a href="http://danielmiessler.com/blog/privacy-the-tor-project" rel="bookmark">Privacy: The Tor Project</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;bodytext=If%20you%20have%20any%20basic%20computer%20knowledge%20and%20value%20your%20privacy%20you%20probably%20know%20how%20to%20clear%20your%20browser%27s%20cookies%20and%20cache.%20It%27s%20Internet%20101.%20But%20newer%20web%20technologies%20like%20%5BAdobe%20Flash%5D%28http%3A%2F%2Fwww.adobe.com%2Fproducts%2Fflashplayer%2F%20%22Adobe%20Flash%20" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;annotation=If%20you%20have%20any%20basic%20computer%20knowledge%20and%20value%20your%20privacy%20you%20probably%20know%20how%20to%20clear%20your%20browser%27s%20cookies%20and%20cache.%20It%27s%20Internet%20101.%20But%20newer%20web%20technologies%20like%20%5BAdobe%20Flash%5D%28http%3A%2F%2Fwww.adobe.com%2Fproducts%2Fflashplayer%2F%20%22Adobe%20Flash%20" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;notes=If%20you%20have%20any%20basic%20computer%20knowledge%20and%20value%20your%20privacy%20you%20probably%20know%20how%20to%20clear%20your%20browser%27s%20cookies%20and%20cache.%20It%27s%20Internet%20101.%20But%20newer%20web%20technologies%20like%20%5BAdobe%20Flash%5D%28http%3A%2F%2Fwww.adobe.com%2Fproducts%2Fflashplayer%2F%20%22Adobe%20Flash%20" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;t=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;title=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;body=If%20you%20have%20any%20basic%20computer%20knowledge%20and%20value%20your%20privacy%20you%20probably%20know%20how%20to%20clear%20your%20browser%27s%20cookies%20and%20cache.%20It%27s%20Internet%20101.%20But%20newer%20web%20technologies%20like%20%5BAdobe%20Flash%5D%28http%3A%2F%2Fwww.adobe.com%2Fproducts%2Fflashplayer%2F%20%22Adobe%20Flash%20" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=How%20to%20View%20Your%20Otherwise%20Invisible%20Flash%20Cookies&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fhow-to-view-your-otherwise-invisible-flash-cookies" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/sfRqmEA7MBaJGmtBOyogtbaaGoc/0/da"><img src="http://feedads.g.doubleclick.net/~a/sfRqmEA7MBaJGmtBOyogtbaaGoc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/sfRqmEA7MBaJGmtBOyogtbaaGoc/1/da"><img src="http://feedads.g.doubleclick.net/~a/sfRqmEA7MBaJGmtBOyogtbaaGoc/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/how-to-view-your-otherwise-invisible-flash-cookies/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Learn Binary in 60 Seconds [Video]</title>
		<link>http://danielmiessler.com/blog/learn-binary-in-60-seconds-video</link>
		<comments>http://danielmiessler.com/blog/learn-binary-in-60-seconds-video#comments</comments>
		<pubDate>Fri, 13 Feb 2009 15:24:23 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=4850</guid>
		<description><![CDATA[
Related PostsBolivian Salt FlatsRethinking the Fireplace Fire: The Upside Down FireExtraordinary Video TechniqueGiving People Faith in Humanity is a True Path to MeaningJobs Debuts the Macintosh



	
	
	
	
	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/qdFmSlFojIw&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/qdFmSlFojIw&#038;color1=0xb1b1b1&#038;color2=0xcfcfcf&#038;hl=en&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/bolivian-salt-flats" rel="bookmark">Bolivian Salt Flats</a></li><li><a href="http://danielmiessler.com/blog/rethinking-the-fireplace-fire-the-upside-down-fire" rel="bookmark">Rethinking the Fireplace Fire: The Upside Down Fire</a></li><li><a href="http://danielmiessler.com/blog/extraordinary-video-technique" rel="bookmark">Extraordinary Video Technique</a></li><li><a href="http://danielmiessler.com/blog/giving-people-faith-in-humanity-is-a-true-path-to-meaning" rel="bookmark">Giving People Faith in Humanity is a True Path to Meaning</a></li><li><a href="http://danielmiessler.com/blog/jobs-debuts-the-macintosh" rel="bookmark">Jobs Debuts the Macintosh</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;bodytext=" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;annotation=" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;notes=" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;t=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;title=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;body=" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Learn%20Binary%20in%2060%20Seconds%20%5BVideo%5D&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Flearn-binary-in-60-seconds-video" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/18H-6SIEq6psbad4KE8M7HGrVgQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/18H-6SIEq6psbad4KE8M7HGrVgQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/18H-6SIEq6psbad4KE8M7HGrVgQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/18H-6SIEq6psbad4KE8M7HGrVgQ/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/learn-binary-in-60-seconds-video/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Security Thought Leaders</title>
		<link>http://danielmiessler.com/blog/information-security-thought-leaders</link>
		<comments>http://danielmiessler.com/blog/information-security-thought-leaders#comments</comments>
		<pubDate>Thu, 12 Feb 2009 16:24:51 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/?p=4845</guid>
		<description><![CDATA[I like to maintain a list of people who innovate in particular fields so that I can be sure to follow their work. Here&#8217;s my current list for the field of Information Security:
The Current List

    Bob Blakely
    Dan Geer
    Craig Wright
    Bruce Schneier
 [...]]]></description>
			<content:encoded><![CDATA[<p>I like to maintain a list of people who innovate in particular fields so that I can be sure to follow their work. Here&#8217;s my current list for the field of Information Security:
<h2>The Current List</h2>
<ul>
    <li>Bob Blakely</li>
    <li>Dan Geer</li>
    <li>Craig Wright</li>
    <li>Bruce Schneier</li>
    <li>Marcus Ranum</li>
    <li>Tom Van Vleck</li>
    <li>Richard Bejtlich</li>
    <li>Gene Spafford</li>
</ul>
Who would you add to this list (or remove), and why?</p>

<p class="post_update">[ Lots of good input received; list of potential adds below ]</p>

<h2>Potential Adds</h2>

<p><ul>
    <li>Hal Pomeranz</li>
    <li>Gene Kim</li>
    <li>Kevin Behr</li>
    <li>Dorothy Denning</li>
    <li>Alec Yasinac</li>
    <li>Christopher Hoff</li>
</ul></p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/a-crazy-idea-regarding-the-obama-administration-and-security" rel="bookmark">A Crazy Idea Regarding the Obama Administration and Security</a></li><li><a href="http://danielmiessler.com/blog/information-security-certifications" rel="bookmark">Information Security Certifications</a></li><li><a href="http://danielmiessler.com/blog/sectwits" rel="bookmark">The Security Twits Information Security Group</a></li><li><a href="http://danielmiessler.com/blog/a-browser-security-idea" rel="bookmark">A Browser Security Idea</a></li><li><a href="http://danielmiessler.com/blog/iphone-source-addresses" rel="bookmark">iPhone Source Addresses</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders&amp;bodytext=I%20like%20to%20maintain%20a%20list%20of%20people%20who%20innovate%20in%20particular%20fields%20so%20that%20I%20can%20be%20sure%20to%20follow%20their%20work.%20Here%27s%20my%20current%20list%20for%20the%20field%20of%20Information%20Security%3A%0D%0AThe%20Current%20List%0D%0A%0D%0A%09Bob%20Blakely%0D%0A%09Dan%20Geer%0D%0A%09Craig%20Wright%0D%0A%09Bruce%20Schnei" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders&amp;annotation=I%20like%20to%20maintain%20a%20list%20of%20people%20who%20innovate%20in%20particular%20fields%20so%20that%20I%20can%20be%20sure%20to%20follow%20their%20work.%20Here%27s%20my%20current%20list%20for%20the%20field%20of%20Information%20Security%3A%0D%0AThe%20Current%20List%0D%0A%0D%0A%09Bob%20Blakely%0D%0A%09Dan%20Geer%0D%0A%09Craig%20Wright%0D%0A%09Bruce%20Schnei" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders&amp;notes=I%20like%20to%20maintain%20a%20list%20of%20people%20who%20innovate%20in%20particular%20fields%20so%20that%20I%20can%20be%20sure%20to%20follow%20their%20work.%20Here%27s%20my%20current%20list%20for%20the%20field%20of%20Information%20Security%3A%0D%0AThe%20Current%20List%0D%0A%0D%0A%09Bob%20Blakely%0D%0A%09Dan%20Geer%0D%0A%09Craig%20Wright%0D%0A%09Bruce%20Schnei" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Information%20Security%20Thought%20Leaders&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;t=Information%20Security%20Thought%20Leaders" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Information%20Security%20Thought%20Leaders%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;title=Information%20Security%20Thought%20Leaders&amp;body=I%20like%20to%20maintain%20a%20list%20of%20people%20who%20innovate%20in%20particular%20fields%20so%20that%20I%20can%20be%20sure%20to%20follow%20their%20work.%20Here%27s%20my%20current%20list%20for%20the%20field%20of%20Information%20Security%3A%0D%0AThe%20Current%20List%0D%0A%0D%0A%09Bob%20Blakely%0D%0A%09Dan%20Geer%0D%0A%09Craig%20Wright%0D%0A%09Bruce%20Schnei" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Information%20Security%20Thought%20Leaders&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Finformation-security-thought-leaders" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/rmkzEkN6idV9oKc2zSGK2fD6XGs/0/da"><img src="http://feedads.g.doubleclick.net/~a/rmkzEkN6idV9oKc2zSGK2fD6XGs/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rmkzEkN6idV9oKc2zSGK2fD6XGs/1/da"><img src="http://feedads.g.doubleclick.net/~a/rmkzEkN6idV9oKc2zSGK2fD6XGs/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/information-security-thought-leaders/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>A Google Talk Botnet?</title>
		<link>http://danielmiessler.com/blog/a-google-talk-botnet</link>
		<comments>http://danielmiessler.com/blog/a-google-talk-botnet#comments</comments>
		<pubDate>Thu, 05 Feb 2009 05:20:05 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/a-google-talk-botnet</guid>
		<description><![CDATA[An enlightening post over at Elastic Vapor on Google&#8217;s XMPP-based, Open Communication network. Very cool stuff.

[ Cloud Control with Google Talk &#124; elasticvapor.com  ]
Related PostsThe Cloud: Reducing Security To Way Above Where It Is TodayTaking A Peek At Google Talk AuthenticationEntering the "Cloud Security" FrayGoogle Talk Contact List ProblemsSpotify: How We Will Consume Music [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.elasticvapor.com/2009/02/cloud-control-with-google-talk-botnets.html" title="ElasticVapor :: Life in the Cloud: Cloud Control with Google Talk (Botnets)">An enlightening post</a> over at <a href="http://www.elasticvapor.com/" title="ElasticVapor :: Life in the Cloud">Elastic Vapor</a> on Google&#8217;s <a href="http://en.wikipedia.org/wiki/Extensible_Messaging_and_Presence_Protocol" title="Extensible Messaging and Presence Protocol - Wikipedia, the free encyclopedia">XMPP</a>-based, Open Communication network. Very cool stuff.</p>

<p>[ <a href="http://www.elasticvapor.com/2009/02/cloud-control-with-google-talk-botnets.html" title="ElasticVapor :: Life in the Cloud">Cloud Control with Google Talk | elasticvapor.com</a>  ]</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/the-cloud-reducing-security-to-way-above-where-it-is-today" rel="bookmark">The Cloud: Reducing Security To Way Above Where It Is Today</a></li><li><a href="http://danielmiessler.com/blog/taking-a-peek-at-google-talk-authentication" rel="bookmark">Taking A Peek At Google Talk Authentication</a></li><li><a href="http://danielmiessler.com/blog/entering-the-cloud-security-fray" rel="bookmark">Entering the "Cloud Security" Fray</a></li><li><a href="http://danielmiessler.com/blog/google-talk-contact-list-problems" rel="bookmark">Google Talk Contact List Problems</a></li><li><a href="http://danielmiessler.com/blog/spotify-how-we-will-consume-music-in-the-future" rel="bookmark">Spotify: How We Will Consume Music in the Future</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F&amp;bodytext=%5BAn%20enlightening%20post%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F2009%2F02%2Fcloud-control-with-google-talk-botnets.html%20%22ElasticVapor%20%3A%3A%20Life%20in%20the%20Cloud%3A%20Cloud%20Control%20with%20Google%20Talk%20%28Botnets%29%22%29%20over%20at%20%5BElastic%20Vapor%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F%20%22ElasticVapor%20%3A" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F&amp;annotation=%5BAn%20enlightening%20post%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F2009%2F02%2Fcloud-control-with-google-talk-botnets.html%20%22ElasticVapor%20%3A%3A%20Life%20in%20the%20Cloud%3A%20Cloud%20Control%20with%20Google%20Talk%20%28Botnets%29%22%29%20over%20at%20%5BElastic%20Vapor%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F%20%22ElasticVapor%20%3A" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F&amp;notes=%5BAn%20enlightening%20post%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F2009%2F02%2Fcloud-control-with-google-talk-botnets.html%20%22ElasticVapor%20%3A%3A%20Life%20in%20the%20Cloud%3A%20Cloud%20Control%20with%20Google%20Talk%20%28Botnets%29%22%29%20over%20at%20%5BElastic%20Vapor%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F%20%22ElasticVapor%20%3A" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=A%20Google%20Talk%20Botnet%3F&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;t=A%20Google%20Talk%20Botnet%3F" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=A%20Google%20Talk%20Botnet%3F%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;title=A%20Google%20Talk%20Botnet%3F&amp;body=%5BAn%20enlightening%20post%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F2009%2F02%2Fcloud-control-with-google-talk-botnets.html%20%22ElasticVapor%20%3A%3A%20Life%20in%20the%20Cloud%3A%20Cloud%20Control%20with%20Google%20Talk%20%28Botnets%29%22%29%20over%20at%20%5BElastic%20Vapor%5D%28http%3A%2F%2Fwww.elasticvapor.com%2F%20%22ElasticVapor%20%3A" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=A%20Google%20Talk%20Botnet%3F&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fa-google-talk-botnet" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/uTGWT9HS9odCxRQpcKqqZ7ZIM_Q/0/da"><img src="http://feedads.g.doubleclick.net/~a/uTGWT9HS9odCxRQpcKqqZ7ZIM_Q/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/uTGWT9HS9odCxRQpcKqqZ7ZIM_Q/1/da"><img src="http://feedads.g.doubleclick.net/~a/uTGWT9HS9odCxRQpcKqqZ7ZIM_Q/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/a-google-talk-botnet/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>An Nmap Command Worth Remembering</title>
		<link>http://danielmiessler.com/blog/an-nmap-command-worth-remembering</link>
		<comments>http://danielmiessler.com/blog/an-nmap-command-worth-remembering#comments</comments>
		<pubDate>Thu, 29 Jan 2009 03:27:56 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/an-nmap-command-worth-remembering</guid>
		<description><![CDATA[This nmap command will verbosely scan all 65,535 ports, both tcp and udp, using service probing and operating system detection, and output the results to nmap, greppable, and xml formats.

nmap -vv -p0- -sSUV -O -oA $outputfile $target

Links

[ My Nmap Page &#124; dmiessler.com ]

::
Related PostsInstalling the Latest Version of Nmap Using SubversionThe Nmap / DShield TrickHow [...]]]></description>
			<content:encoded><![CDATA[<p>This <code><a href="http://nmap.org/" title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits.">nmap</a></code> command will verbosely scan all 65,535 ports, both tcp and udp, using service probing and operating system detection, and output the results to nmap, greppable, and xml formats.</p>

<p><pre class="brush: bash">nmap -vv -p0- -sSUV -O -oA $outputfile $target</pre></p>

<h3>Links</h3>

<p>[ <a href="http://dmiessler.com/study/nmap/">My Nmap Page | dmiessler.com</a> ]</p>

<p>::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/installing-the-latest-version-of-nmap-using-subversion" rel="bookmark">Installing the Latest Version of Nmap Using Subversion</a></li><li><a href="http://danielmiessler.com/blog/the-nmap-dshield-trick" rel="bookmark">The Nmap / DShield Trick</a></li><li><a href="http://danielmiessler.com/blog/how-a-default-iphone-113-looks-to-nmap-350" rel="bookmark">How a Default iPhone 1.1.3 Looks to Nmap 3.50</a></li><li><a href="http://danielmiessler.com/blog/an-nmap-scan-of-the-iphone-20-software" rel="bookmark">An Nmap Scan of the iPhone 2.0 Software</a></li><li><a href="http://danielmiessler.com/blog/an-nmap-primer" rel="bookmark">An Nmap Primer</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering&amp;bodytext=This%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20command%20will%20verbosely%20scan%20all%2065%2C535%20ports%2C%20both%20tcp%20and%20udp%2C%20using%20service%20probing%20and%20operating%20system%20detection%2C%20and%20output%20the%20results%20to%20nm" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering&amp;annotation=This%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20command%20will%20verbosely%20scan%20all%2065%2C535%20ports%2C%20both%20tcp%20and%20udp%2C%20using%20service%20probing%20and%20operating%20system%20detection%2C%20and%20output%20the%20results%20to%20nm" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering&amp;notes=This%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20command%20will%20verbosely%20scan%20all%2065%2C535%20ports%2C%20both%20tcp%20and%20udp%2C%20using%20service%20probing%20and%20operating%20system%20detection%2C%20and%20output%20the%20results%20to%20nm" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=An%20Nmap%20Command%20Worth%20Remembering&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;t=An%20Nmap%20Command%20Worth%20Remembering" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=An%20Nmap%20Command%20Worth%20Remembering%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;title=An%20Nmap%20Command%20Worth%20Remembering&amp;body=This%20%5Bnmap%5D%28http%3A%2F%2Fnmap.org%2F%20%22Nmap%20-%20Free%20Security%20Scanner%20For%20Network%20Exploration%20%26%20Security%20Audits.%22%29%20command%20will%20verbosely%20scan%20all%2065%2C535%20ports%2C%20both%20tcp%20and%20udp%2C%20using%20service%20probing%20and%20operating%20system%20detection%2C%20and%20output%20the%20results%20to%20nm" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=An%20Nmap%20Command%20Worth%20Remembering&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fan-nmap-command-worth-remembering" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/rUA59C7Ngd62FRk3FL_rUI4tJMU/0/da"><img src="http://feedads.g.doubleclick.net/~a/rUA59C7Ngd62FRk3FL_rUI4tJMU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rUA59C7Ngd62FRk3FL_rUI4tJMU/1/da"><img src="http://feedads.g.doubleclick.net/~a/rUA59C7Ngd62FRk3FL_rUI4tJMU/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/an-nmap-command-worth-remembering/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can Twitter Push OAuth into the Mainstream?</title>
		<link>http://danielmiessler.com/blog/can-twitter-push-oauth-into-the-mainstream</link>
		<comments>http://danielmiessler.com/blog/can-twitter-push-oauth-into-the-mainstream#comments</comments>
		<pubDate>Sun, 25 Jan 2009 00:55:48 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blog/can-twitter-push-oauth-into-the-mainstream</guid>
		<description><![CDATA[


I really hope Twitter&#8217;s pushing of OAuth is successful. ::
Related PostsGoogle Hires Delicious FounderTwitter Explained in Three ParagraphsHow to Display Content From Other Services Within Facebook AutomaticallyThe Power of Twitter SearchWhere Twitter Fits



	
	
	
	
	
	
	
	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://dmiessler.com/wp-content/uploads/2009/01/oauth.png" alt="OAuth" />
</center></p>

<p>I really hope <a href="http://www.readwriteweb.com/archives/why_twitters_new_oauth_matters.php" title="Why Twitter's New Security Solution Could Pave the Way to a Future Web of Mashups - ReadWriteWeb">Twitter&#8217;s pushing of OAuth</a> is successful. ::</p>
<div id="crp_related"><h3>Related Posts</h3><ul><li><a href="http://danielmiessler.com/blog/google-hires-delicious-founder" rel="bookmark">Google Hires Delicious Founder</a></li><li><a href="http://danielmiessler.com/blog/twitter-explained-in-three-paragraphs" rel="bookmark">Twitter Explained in Three Paragraphs</a></li><li><a href="http://danielmiessler.com/blog/how-to-display-content-from-other-services-within-facebook-automatically" rel="bookmark">How to Display Content From Other Services Within Facebook Automatically</a></li><li><a href="http://danielmiessler.com/blog/the-power-of-twitter-search" rel="bookmark">The Power of Twitter Search</a></li><li><a href="http://danielmiessler.com/blog/where-twitter-fits" rel="bookmark">Where Twitter Fits</a></li></ul></div>



	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;bodytext=%21%5BOAuth%5D%28http%3A%2F%2Fdmiessler.com%2Fwp-content%2Fuploads%2F2009%2F01%2Foauth.png%29%0A%0A%0AI%20really%20hope%20%5BTwitter%27s%20pushing%20of%20OAuth%5D%28http%3A%2F%2Fwww.readwriteweb.com%2Farchives%2Fwhy_twitters_new_oauth_matters.php%20%22Why%20Twitter%27s%20New%20Security%20Solution%20Could%20Pave%20the%20Way%20to%20a%20Futu" title="Digg"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F" title="Reddit"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F" title="StumbleUpon"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.dzone.com/links/add.html?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F" title="DZone"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/dzone.png" title="DZone" alt="DZone" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;annotation=%21%5BOAuth%5D%28http%3A%2F%2Fdmiessler.com%2Fwp-content%2Fuploads%2F2009%2F01%2Foauth.png%29%0A%0A%0AI%20really%20hope%20%5BTwitter%27s%20pushing%20of%20OAuth%5D%28http%3A%2F%2Fwww.readwriteweb.com%2Farchives%2Fwhy_twitters_new_oauth_matters.php%20%22Why%20Twitter%27s%20New%20Security%20Solution%20Could%20Pave%20the%20Way%20to%20a%20Futu" title="Google Bookmarks"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://delicious.com/post?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;notes=%21%5BOAuth%5D%28http%3A%2F%2Fdmiessler.com%2Fwp-content%2Fuploads%2F2009%2F01%2Foauth.png%29%0A%0A%0AI%20really%20hope%20%5BTwitter%27s%20pushing%20of%20OAuth%5D%28http%3A%2F%2Fwww.readwriteweb.com%2Farchives%2Fwhy_twitters_new_oauth_matters.php%20%22Why%20Twitter%27s%20New%20Security%20Solution%20Could%20Pave%20the%20Way%20to%20a%20Futu" title="del.icio.us"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.friendfeed.com/share?title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream" title="FriendFeed"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/friendfeed.png" title="FriendFeed" alt="FriendFeed" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;t=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F" title="Facebook"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://twitter.com/home?status=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F%20-%20http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream" title="Twitter"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://ping.fm/ref/?link=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;title=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;body=%21%5BOAuth%5D%28http%3A%2F%2Fdmiessler.com%2Fwp-content%2Fuploads%2F2009%2F01%2Foauth.png%29%0A%0A%0AI%20really%20hope%20%5BTwitter%27s%20pushing%20of%20OAuth%5D%28http%3A%2F%2Fwww.readwriteweb.com%2Farchives%2Fwhy_twitters_new_oauth_matters.php%20%22Why%20Twitter%27s%20New%20Security%20Solution%20Could%20Pave%20the%20Way%20to%20a%20Futu" title="Ping.fm"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream&amp;partner=sociable" title="Print this article!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/printfriendly.png" title="Print this article!" alt="Print this article!" class="sociable-hovers" /></a>
	<a rel="nofollow" href="mailto:?subject=Can%20Twitter%20Push%20OAuth%20into%20the%20Mainstream%3F&amp;body=http%3A%2F%2Fdanielmiessler.com%2Fblog%2Fcan-twitter-push-oauth-into-the-mainstream" title="E-mail this story to a friend!"><img src="http://danielmiessler.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>
<p><a href="http://feedads.g.doubleclick.net/~a/u6sD2nuCDQ8beMXCgtvMn1PqiRE/0/da"><img src="http://feedads.g.doubleclick.net/~a/u6sD2nuCDQ8beMXCgtvMn1PqiRE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/u6sD2nuCDQ8beMXCgtvMn1PqiRE/1/da"><img src="http://feedads.g.doubleclick.net/~a/u6sD2nuCDQ8beMXCgtvMn1PqiRE/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/can-twitter-push-oauth-into-the-mainstream/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss><!-- Dynamic page generated in 7.444 seconds. --><!-- Cached page generated by WP-Super-Cache on 2009-07-04 05:31:05 --><!-- Compression = gzip -->
