- +
Your World. . . Hacked 02/10/2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network - +
Toxic Mix or Bit of a Mixed Blessing? 31/12/2007 10:36:30
“Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . ” The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare’s Macbeth, but even so it makes “for a charm of powerful trouble”"Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . " The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare's Macbeth, but even so it makes "for a charm of powerful trouble" - +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Read up on the latest ideas and technologies from companies that sell hardware, software and services. You Deserve Better than Spreadsheets
Application Modernization: Preserving Your Organization’s DNA
Realizing the Value of Unified Communications
ALM in Geographically Distributed Development Environments
Network Aware Service Management
The Next CIO is You
EMC Data Profiling for File System and Exchange Server Environments
Business Mashups: The 10 Commandments
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
The beef over news of a worm targeting Macs, and the identity of the researcher who claimed to have created the malware, took an even stranger turn Wednesday as death threats were allegedly posted to his or her blog, which was then reportedly hacked.
In return, the researcher leveled charges at a security expert known for taking on Apple.
The hubbub started earlier this week, when a researcher responsible for the Information Security Sell Out (InfoSec) blog announced a proof-of-concept worm that exploited a Mac OS X vulnerability which Apple missed in a May round of patches. The vulnerability exploited by the worm was in mDNSResponder, a component of Apple's Bonjour automatic network configuring service, InfoSec said then.
Criticism from Mac users and other security researchers was almost immediate, with the former focusing on crude insults and the latter concentrating on InfoSec's refusal to identify himself or herself, or prove that the worm existed.
The latter group questioned InfoSec's motives and the veracity of his or her claims. "Let's see this worm deliver a destructive payload in the wild and then we can talk again," said a user identified as Ted Wood. "Until then, you're just hot air."
"If you are a legitimate researcher, you have an obligation to publish your findings so they can be tested," said Stephen, another user on the same comment list. "Any good researcher would do this."
According to InfoSec, some of the comments left earlier included death threats. In a posting -- since deleted, more on that below -- from Tuesday, InfoSec listed comments he refused to allow to be posted to the blog. Among them:
- "You are lucky you are anonymous or I would put a bullet in your head for this!" -- Anonymous
- "Nice try with the FUD [fear, uncertainty and doubt]. You are full of **** there is no such thing as an Apple Worm." -- Jeff
- "I dare you to demonstrate this at Defcon you ***** Microsoftie. We will drag you out, put a bullet in you, and bury your body so deep it will take a nuclear blast to find your body." -- Anonymous
Tuesday night, the InfoSec blog's title changed to "Security Information..." and all former postings, which began in January, had been deleted. When asked via e-mail Wednesday to explain the changes, InfoSec answered: "Blog was hijacked somehow. Also the blog stating I am associated with PHC on another Blog is false and a myth created by Dave Maynor who is involved in the hijacking of the Blog."
InfoSec was likely referring to a posting on a blog dubbed "Security Ripcord" at a site run by a Texas-based security consultancy called Cutaway. In a long entry posted this morning, Don Weber, a.k.a. Cutaway, said an informant had told him that that InfoSec is actually "LMH," a researcher best known for having co-authored January's Month of Apple Bugs (MoAB) campaign. The source also claimed, said Weber, that LMH was part of a group that calls itself "Phrack High Council," or PHC, a self-described group of "black hat" hackers.
No way, said InfoSec.
"The claim that we are LMH or MoAB or PHC are all wrong," InfoSec wrote in a second e-mail Wednesday. "These came from Maynor assuming that we are all one and the same because we have all attacked his creditability."
Dave Maynor, a researcher who last year was involved in a very public spat with Apple over a wireless hack demonstration he and a colleague gave at the Black Hat security conference, refused to be drawn into the argument with InfoSec. "I am not even going to comment on that stupidity," Maynor wrote in an e-mail responding to an offer to rebut or comment on InfoSec's allegations.
Prior to this, Maynor was most recently in the news as one of several researchers who found vulnerabilities in the Windows beta of Apple's Safari 3.0 within hours of the browser's release.
Kevin Finisterre, who partnered with LMH for MoAB, said he doubted that InfoSec and LMH were one and the same. "From what I am aware of it's not the same guy," Finisterre said in an e-mail.
"I can certainly say that the underground is always abuzz about mDNS bugs," Finisterre added. "If you have ever looked at the source code you would see it is clearly a large target surface. mDNS is a nasty beast."
Apple has been largely forgotten in the heated back-and-forth between InfoSec on one side, Mac users and other researchers on the other. The only response the Cupertino, Calif. computer maker has offered up on the issue, and alleged unpatched vulnerability, was made by a spokesman Tuesday. "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users," said Anuj Nayar Tuesday.
Computerworld Member Login
Beyond Virtualisation - The Roadmap to 2012
CIO Breakfast Briefing
8:30am - 10:30am
Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt
Attend and discover:
- What happens after virtualisation
- The benefits automation drives
- When automated infrastructures will emerge
- What the roadmap to 2012 looks like
- How to deliver an automated architecture
- How to maximise your investment in virtualisation
- +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years.
Ballarat Grammar Improves Student Access to Computer Based Learning with HP ProCurve 2008-07-04 16:49:00+10
Media release: 40 Per Cent of Australian Businesses Do Not Validate Their Data 2008-07-04 10:29:00+10
Kaseya helps turbo charge BlueFire’s service delivery model 2008-07-03 17:23:00+10
Computershare Selects Symantec for Data Loss Prevention Globally 2008-07-03 14:52:00+10
DST International moves to new Shanghai office 2008-07-03 13:21:00+10
Top Tips for Email Security in 2008
E-mail security remains a difficult issue for IT managers, who are now faced with more malicious threats than ever before. So what’s new in e-mail security in 2008? And what will work best for your business? Read on to discover & create your 2008 e-mail security goals.








