<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>NP-Incomplete</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/" />
   <link rel="self" type="application/atom+xml" href="http://np-incomplete.com/atom.xml" />
   <id>tag:np-incomplete.com,2008://1</id>
   <updated>2008-05-05T04:50:41Z</updated>
   <subtitle>adam j. o&apos;donnell&apos;s blog.</subtitle>
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.33</generator>

<entry>
   <title>BaySec Wednesday, May 7th</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/05/baysec_wednesday_may_7th.html" />
   <id>tag:np-incomplete.com,2008://1.104</id>
   
   <published>2008-05-05T04:50:33Z</published>
   <updated>2008-05-05T04:50:41Z</updated>
   
   <summary> Girls drinking a beer Originally uploaded by surfstyle BaySec is this Wednesday, May 7th at Pete&apos;s Tavern. As usual, you can find us by looking for the crowd of socially inept nerds to the left side of the bar....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<div style="float: right; margin-left: 10px; margin-bottom: 10px;">
 <a href="http://www.flickr.com/photos/surfstyle/319891486/" title="photo sharing"><img src="http://farm1.static.flickr.com/135/319891486_90a9bda303_m.jpg" alt="" style="border: solid 2px #000000;" /></a>
 <br />
 <span style="font-size: 0.9em; margin-top: 0px;">
  <a href="http://www.flickr.com/photos/surfstyle/319891486/">Girls drinking a beer</a>
  <br />
  Originally uploaded by <a href="http://www.flickr.com/people/surfstyle/">surfstyle</a>
 </span>
</div>
<A HREF="http://sockpuppet.org/baysec/">BaySec</A> is this Wednesday, May 7th at <A HREF="http://maps.google.com/maps?client=safari&ie=UTF8&oe=UTF-8&q=pete's+tavern,&near=San+Francisco,+CA&fb=1&cid=0,0,16253685649888729666&ll=37.78045,-122.391129&spn=0.007869,0.017509&t=h&z=16&iwloc=A">Pete's Tavern</A>.  As usual, you can find us by looking for the crowd of socially inept nerds to the left side of the bar.
<br clear="all" />]]>
      
   </content>
</entry>
<entry>
   <title>Spam is now 30.</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/05/spam_is_now_30.html" />
   <id>tag:np-incomplete.com,2008://1.103</id>
   
   <published>2008-05-04T06:17:32Z</published>
   <updated>2008-05-04T06:20:48Z</updated>
   
   <summary>Spam is now 30. Frankly, if spam still bothers you after all this time, buy a better filter....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<a href="http://aspamaday.blogspot.com/2008/05/happy-birthday-spam.html">Spam</a> is <a href="http://tech.yahoo.com/blogs/patterson/18084/spam-turning-30-this-month-no-gifts-please/">now</a> <a href="http://technology.newscientist.com/article/dn13777-happy-spamiversary-spam-reaches-30.html">30</a>.  Frankly, if spam still bothers you after all this time, <a href="http://www.cloudmark.com/">buy a better filter</a>.]]>
      
   </content>
</entry>
<entry>
   <title>Kraken Reveng</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/kraken_reveng.html" />
   <id>tag:np-incomplete.com,2008://1.102</id>
   
   <published>2008-04-29T18:13:25Z</published>
   <updated>2008-04-29T18:16:05Z</updated>
   
   <summary>There is a solid writeup by Pedram Amini @ TippingPoint on the Kraken RevEng here and here. Thanks to Richard Soderberg for the heads up....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[There is a solid writeup by Pedram Amini @ TippingPoint on the Kraken RevEng <a href="http://dvlabs.tippingpoint.com/blog/2008/04/28/kraken-botnet-infiltration">here</a> and <a href="http://dvlabs.tippingpoint.com/blog/2008/04/28/owning-kraken-zombies">here</a>.  Thanks to Richard Soderberg for the heads up.]]>
      
   </content>
</entry>
<entry>
   <title>Show me yours...</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/show_me_yours.html" />
   <id>tag:np-incomplete.com,2008://1.101</id>
   
   <published>2008-04-29T06:25:15Z</published>
   <updated>2008-04-29T06:25:19Z</updated>
   
   <summary> Bay to Breakers Bib Originally uploaded by Adam J. O&apos;Donnell My bay to breakers bib arrived....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<div style="float: right; margin-left: 10px; margin-bottom: 10px;">
 <a href="http://www.flickr.com/photos/adamjodonnell/2450593809/" title="photo sharing"><img src="http://farm4.static.flickr.com/3082/2450593809_8e75b43072_m.jpg" alt="" style="border: solid 2px #000000;" /></a>
 <br />
 <span style="font-size: 0.9em; margin-top: 0px;">
  <a href="http://www.flickr.com/photos/adamjodonnell/2450593809/">Bay to Breakers Bib</a>
  <br />
  Originally uploaded by <a href="http://www.flickr.com/people/adamjodonnell/">Adam J. O'Donnell</a>
 </span>
</div>
My bay to breakers bib arrived.
<br clear="all" />]]>
      
   </content>
</entry>
<entry>
   <title>Storm Defeated?</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/storm_defeated.html" />
   <id>tag:np-incomplete.com,2008://1.100</id>
   
   <published>2008-04-23T21:16:41Z</published>
   <updated>2008-04-23T21:19:30Z</updated>
   
   <summary>Apparently if you have kernel-level and below control of every Windows PC out there, you can pull out a botnet infestation. Let&apos;s see how long it takes for either the botters to be caught or for a new infection to...</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[Apparently if you have kernel-level and below control of every Windows PC out there, you can pull out a <a href="http://www.infoworld.com/article/08/04/22/Microsoft-We-took-out-Storm-botnet_1.html">botnet infestation</a>.  Let's see how long it takes for either the botters to be caught or for a new infection to come out that disables Windows Update.  Thanks go to <a href="http://www.mirrorshades.org/overflow/">Bryan</a> and <a href="http://monkey.org/~jose/">Jose</a> for the heads up.]]>
      
   </content>
</entry>
<entry>
   <title>How Storm Communicates</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/how_storm_communicates.html" />
   <id>tag:np-incomplete.com,2008://1.99</id>
   
   <published>2008-04-18T06:42:46Z</published>
   <updated>2008-04-18T06:46:38Z</updated>
   
   <summary>Thorsten Holz and team put together a fantastic paper on how the Storm Worm communicates and how it can be infiltrated. Thanks go to Jose Nazario for the heads up....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<a href="http://honeyblog.org/">Thorsten Holz</a> and team put together a <a href="http://honeyblog.org/junkyard/paper/storm-leet08.pdf">fantastic paper</a> on how the Storm Worm communicates and how it can be infiltrated.  Thanks go to <a href="http://monkey.org/~jose/">Jose Nazario</a> for the heads up.]]>
      
   </content>
</entry>
<entry>
   <title>Security Blogger&apos;s Meetup 2008</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/security_bloggers_meetup_2008.html" />
   <id>tag:np-incomplete.com,2008://1.98</id>
   
   <published>2008-04-16T07:18:29Z</published>
   <updated>2008-04-16T07:18:34Z</updated>
   
   <summary> Security Blogger&apos;s Meetup 2008 Originally uploaded by Adam J. O&apos;Donnell As you can see from the picture, I was very tired by the time the Security Blogger&apos;s Meetup rolled around at RSA. TechDulla, Alan Schimel, Jennifer Leggio and many...</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<div style="float: right; margin-left: 10px; margin-bottom: 10px;">
 <a href="http://www.flickr.com/photos/adamjodonnell/2414854563/" title="photo sharing"><img src="http://farm3.static.flickr.com/2307/2414854563_44eece0e8b_m.jpg" alt="" style="border: solid 2px #000000;" /></a>
 <br />
 <span style="font-size: 0.9em; margin-top: 0px;">
  <a href="http://www.flickr.com/photos/adamjodonnell/2414854563/">Security Blogger's Meetup 2008</a>
  <br />
  Originally uploaded by <a href="http://www.flickr.com/people/adamjodonnell/">Adam J. O'Donnell</a>
 </span>
</div>
As you can see from the picture, I was very tired by the time the <A HREF="http://www.rsaconference.com/security_topics/developing_with_security/Blog_Security_Bloggers_Meet_up_2008.aspx">Security Blogger's Meetup</A> rolled around at RSA.  <A HREF="http://techdulla.wordpress.com/2008/04/12/review-of-the-security-bloggers-meet-up-at-rsa/">TechDulla</A>, <A HREF="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/link-for-the-se.html">Alan Schimel</A>, <A HREF="http://mediaphyter.wordpress.com/2008/04/15/security-bloggers-meet-up-no-helmet-required/">Jennifer Leggio</A> and many others have provided writeups  (<A HREF="http://www.mckeay.net/2008/04/10/security-bloggers-meetup/">Martin McKeay has video</A>) of the event, and I really can't add too much to what has been said.<br />
<br /><br />
Long story short: Good time, and hats off to <A HREF="http://mediaphyter.wordpress.com/">Jennifer</A> for pulling off a fantastic event.
<br clear="all" />]]>
      
   </content>
</entry>
<entry>
   <title>What the hell have I been doing? Part $e^{j\pi}$</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/what_the_hell_have_i_been_doin_4.html" />
   <id>tag:np-incomplete.com,2008://1.97</id>
   
   <published>2008-04-14T22:53:20Z</published>
   <updated>2008-04-14T22:59:54Z</updated>
   
   <summary>I just submitted an article for IEEE Security and Privacy and spent the past week attending RSA. I did do a podcast for Schwartz PR during their RSA party that is available here....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[I just submitted an article for <a href="http://www.computer.org/portal/site/security">IEEE Security and Privacy</a> and spent the past week attending RSA.  I did do a podcast for <a href="http://www.schwartz-pr.com/">Schwartz PR</a> during their RSA party that is available <a href="http://feeds.feedburner.com/~r/SchwartzPodcasts/~3/267912379/Cloudmark.mp3">here</a>.]]>
      
   </content>
</entry>
<entry>
   <title>Stupid web 2.0 grumble grumble...</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/stupid_web_20_grumble_grumble.html" />
   <id>tag:np-incomplete.com,2008://1.96</id>
   
   <published>2008-04-14T22:52:03Z</published>
   <updated>2008-04-14T22:52:45Z</updated>
   
   <summary>Yet another means of promoting this site: Technorati Profile....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Personal" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[Yet another means of promoting this site: <a href="http://technorati.com/claim/jcxyf5fmre" rel="me">Technorati Profile</a>.]]>
      
   </content>
</entry>
<entry>
   <title>Malware shifts and value chains.</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/malware_shifts_and_value_chain.html" />
   <id>tag:np-incomplete.com,2008://1.95</id>
   
   <published>2008-04-12T01:33:02Z</published>
   <updated>2008-04-12T01:46:08Z</updated>
   
   <summary>Amrit Williams is calling me on predicting malware emergence. His assertion is that by the time AV improves enough to push attackers onto Macs at their current market share, then attackers will shift to another layer altogether and abandon the...</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<a href="http://techbuddha.wordpress.com/">Amrit Williams</a> is calling me on predicting malware emergence.  His assertion is that by the time AV improves enough to push attackers onto Macs at their current market share, then attackers will shift to another layer altogether and abandon the idea of monetized malware.  I had always assumed that the value chain established by attackers would be largely preserved, but he may be right: there could be a point where AV is so good that attackers will just move to popping webmail accounts and routers rather than attacking client systems.  Now wouldn't that be nice.]]>
      
   </content>
</entry>
<entry>
   <title>Why Google is Brilliant; Case Study: Google App Engine</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/why_google_is_brilliant_case_s.html" />
   <id>tag:np-incomplete.com,2008://1.94</id>
   
   <published>2008-04-10T16:43:48Z</published>
   <updated>2008-04-10T16:48:06Z</updated>
   
   <summary>Let&apos;s say you are a startup and you choose to use the Google App Engine for your infrastructure. If Google buys you out, they don&apos;t have to port the code. They directly quantify your company&apos;s technology opex and revenue, since...</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[Let's say you are a startup and you choose to use the <a href="http://code.google.com/appengine/">Google App Engine</a> for your infrastructure.  If Google buys you out, they don't have to port the code.  They directly quantify your company's <a href="http://en.wikipedia.org/wiki/Operating_expense">technology opex</a> and revenue, since they see both the CPU overhead and the eyeball count via Google Analytics.  Brilliant.]]>
      
   </content>
</entry>
<entry>
   <title>RSA still hates the Irish.</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/rsa_still_hates_the_irish.html" />
   <id>tag:np-incomplete.com,2008://1.93</id>
   
   <published>2008-04-10T16:41:55Z</published>
   <updated>2008-04-10T16:43:44Z</updated>
   
   <summary>Nokia, the phone company that doesn&apos;t do security but does OEM SourceFire and CheckPoint technology, brought in the fake Bono....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[Nokia, the phone company that doesn't do security but does OEM SourceFire and CheckPoint technology, <a href="http://np-incomplete.com/2008/04/maybe_rsa_doesnt_hate_the_iris.html">brought in the fake Bono</a>.]]>
      
   </content>
</entry>
<entry>
   <title>Maybe RSA doesn&apos;t hate the Irish.</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/maybe_rsa_doesnt_hate_the_iris.html" />
   <id>tag:np-incomplete.com,2008://1.92</id>
   
   <published>2008-04-08T17:06:33Z</published>
   <updated>2008-04-08T17:10:20Z</updated>
   
   <summary>Bono was walking the RSA floor last night. He was there for Nokia, which rocks security apparently. I guess RSA doesn&apos;t hate the Irish too much....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<a href="http://en.wikipedia.org/wiki/Bono">Bono</a> was walking the <a href="http://www.rsaconference.com/">RSA floor</a> last night.  He was there for <a href="http://www.nokia.com/">Nokia</a>, which rocks security apparently.  I guess <a href="http://np-incomplete.com/2008/04/rsa_hates_the_irish.html">RSA doesn't hate the Irish too much</a>.]]>
      
   </content>
</entry>
<entry>
   <title>RSA hates the Irish</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/rsa_hates_the_irish.html" />
   <id>tag:np-incomplete.com,2008://1.91</id>
   
   <published>2008-04-07T17:09:09Z</published>
   <updated>2008-04-07T17:18:43Z</updated>
   
   <summary>Because I have an apostrophe in my last name, I attempt a SQL injection attack every time I fill out a form. The RSA conference is aware of this, and requires everyone who has an apostrophe in their last name...</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      Because I have an apostrophe in my last name, I attempt a SQL injection attack every time I fill out a form.  The RSA conference is aware of this, and requires everyone who has an apostrophe in their last name to stand in a separate line.  Apparently they have not yet learned that it is possible to secure a webapp against the dreaded &apos; without blacklisting the content.

I find this to be equivalent to segregation against those of us who have apostrophes in our name, and by the principle of transitivity, RSA is attempting to segregate out the Irish without posting an &quot;Irish Need Not Apply&quot; sign.  Mark my words, first they will come for our crypto keys, and then they will come for our potatoes.
      
   </content>
</entry>
<entry>
   <title>BusinessWeek covers Apple Security</title>
   <link rel="alternate" type="text/html" href="http://np-incomplete.com/2008/04/businessweek_covers_apple_secu.html" />
   <id>tag:np-incomplete.com,2008://1.90</id>
   
   <published>2008-04-06T03:15:01Z</published>
   <updated>2008-04-06T03:16:30Z</updated>
   
   <summary>This article on the potential emergence of Macintosh malware appears with auspicious timing....</summary>
   <author>
      <name>Adam J. O&apos;Donnell</name>
      <uri>http://philtered.net/~adam</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://np-incomplete.com/">
      <![CDATA[<a href="http://www.businessweek.com/technology/content/mar2008/tc20080317_287032.htm">This article</a> on the potential emergence of Macintosh malware appears with <a href="http://np-incomplete.com/2008/03/newsflash_its_an_issue_of_mark.html">auspicious timing</a>.]]>
      
   </content>
</entry>

</feed>
