<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; Web Security &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/tag/web-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Lessons learned from a hacked Twitter account</title>
		<link>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 07:09:12 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[direct message spam]]></category>
		<category><![CDATA[DM]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[tweets]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[URL shortening]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=878</guid>
		<description><![CDATA[If you follow @WebSpy on Twitter, you would have received a very strange Direct Message (DM) from us yesterday. Something along the lines of "rofl this you?" or "you're on this vid!" or "I found you on here!"

Unfortunately, the WebSpy Twitter account fell victim to a phishing scam, and as a result sent phishing spam to all our Twitter followers. We are embarrassed by the incident and we apologize to all of our followers, especially the ones that clicked the link in the DM and were caught by the phishing scam themselves.

Here's a rundown of the event in the hope that it will help others know what to look out for.]]></description>
			<content:encoded><![CDATA[<p>If you follow @WebSpy on Twitter, you would have received a very strange Direct Message (DM) from us yesterday. Something along the lines of &#8220;rofl this you?&#8221; or &#8220;you&#8217;re on this vid!&#8221; or &#8220;I found you on here!&#8221;</p>
<p>Unfortunately, the WebSpy Twitter account fell victim to a phishing scam, and as a result sent phishing spam to all our Twitter followers. We are embarrassed by the incident and we apologize to all of our followers, especially the ones that clicked the link in the DM and were caught by the phishing scam themselves.</p>
<p>Here&#8217;s a rundown of the event in the hope that it will help others know what to look out for.<span id="more-878"></span></p>
<h2>What Happened?</h2>
<p>The phishing scam works like this:</p>
<ol>
<li>You receive a strange yet intriguing Direct Message from someone you follow and likely trust. <strong>This is the key element to the scams success</strong>.</li>
<li>The DM contains a link using a shortened URL such as dwarfurl.com/blah. In our case, most of them were using dwarfurl.com, wapurl.co.uk, and 3.ly</li>
<li>You click the link and get taken to what appears to be the Twitter login page. But if you look at the URL it is actually something like blogs.videos.dsfasdc.com or  videos.twitter.dsfasdc.com. <strong>Checking the URL is the key to making sure the scam doesn&#8217;t get you too!</strong></li>
<li>You enter your Twitter login details. Reports of what happens after this login page vary. You may see the Twitter fail whale, or a blank page, or a random blog.</li>
<li>Now that the phishing site has your login details, the same Direct Messages is sent to all your Twitter contacts.</li>
<li>You eventually discover what happened. You feel like a violated idiot and start scrambling to fix everything.</li>
</ol>
<h2>What to do if it happens to you</h2>
<p>If the above sounds familiar, you need to login to Twitter right now and change your password to make sure the phishing site can no longer access your account. You also need to go to the Connections tab and disable any third party applications that look suspicious. You&#8217;ll then need to update the credentials in all the twitter clients, website/blog plug-ins, and anything else that may be using your old Twitter credentials.</p>
<p>Fortunately, we were still able to login to our Twitter account and change our password and disable third party connections. Thankfully there were not any new suspicious connections that we needed to worry about.</p>
<h2>Lessons Learned</h2>
<p>Now that we&#8217;ve fixed everything and regained control of our Twitter account, it&#8217;s good to sit back and reflect on what just happened and how to avoid it in the future.</p>
<p>You&#8217;ve probably heard all of this before. We had too. But it takes an incident like this to <em>really </em>think about and address any shortfalls in your own organization. Some of our followers were also caught out by the scam and these are people that are in the tech industry and generally know about these sorts of scams. We were definitely surprised that we fell for it!  So take a moment of your time to imagine your own Twitter account was compromised in the same way, then imagine all the possible ways it could have happened. Now go and take every precaution to ensure it doesn&#8217;t happen.</p>
<p>Having now been through it, here are some tips to help you avoid the same fate in the future.</p>
<ol>
<li>Just because a Direct Message comes from someone you trust, does not mean it is trustworthy. Always use caution!</li>
<li>Educate your employees &#8211; especially those that know your company&#8217;s Twitter credentials. The main goal you want to achieve here is getting your employees into the habit of glancing at the URL in the address bar of their browser before entering ANY login details. We used our own log analysis software (Vantage) to find out who ended up on the websites in question, and then spoke to them directly to ensure they understood what to look out for.</li>
<li>Use a Twitter application that can display the actual URL behind a shortened URL before clicking on the link. For TweetDeck users, go to Settings | General, and check &#8216;Show preview information for short URLs&#8217;. Please note, however that this function only works for a few specific URL shortening services.</li>
<li>If you&#8217;re using the Twitter web page directly, use a browser and plug-in that can expand shortened URLs such as Mozilla Firefox with <a href="https://addons.mozilla.org/en-US/firefox/addon/9549" target="_blank">Long URL Please</a>.</li>
<li>Use a browser with integrated anti-phishing security (such as Firefox or Google Chrome) and keep it up to date, or ensure you have good third party anti-phishing / anti-malware software installed.</li>
<li>As always, keep your security software and OS up to date.</li>
</ol>
<p>Our friends at Sophos also have some good information about the scam that you may like to read: <a title="Phish... it's what's for dinner" href="http://www.sophos.com/blogs/sophoslabs/?p=7366" target="_blank">http://www.sophos.com/blogs/sophoslabs/?p=7366</a></p>
<h2>Sorry!</h2>
<p>An event like this makes you realize how important Twitter is to the overall public perception of a company. Our followers trust us to deliver relevant and useful content about our key areas of expertise &#8211; log file analysis and reporting. We spend a large amount of effort researching and writing content to ensure our tweets provide our followers with a good source of information. Having a breach like this certainly degrades this public perception that we work so hard at trying to maintain.</p>
<p>I would therefore like to thank all our followers who have kept with us and not clicked the &#8216;Unfollow&#8217; button. Now that everything is under control again we will continue to bring you the best content we can provide about the log analysis and surrounding industries.</p>
<p>Once again, many many apologies to all of our followers, especially those that were affected.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft to announce Beta 3 for Threat Management Gateway (the new ISA Server)</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/#comments</comments>
		<pubDate>Mon, 18 May 2009 15:51:32 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Beta 3]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Intrusion Prevention]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Network Inspection System]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[SQL Express Log Files]]></category>
		<category><![CDATA[Threat Management Gateway Reporting]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[TMG Log Files]]></category>
		<category><![CDATA[TMG Reprting]]></category>
		<category><![CDATA[URL Filtering]]></category>
		<category><![CDATA[W3C Log Files]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=201</guid>
		<description><![CDATA[It sounds like Threat Management Gateway (TMG), the new re-branded version of ISA Server, has been a popular topic at this years TechEd event in the US. 

According to the <a href="http://blogs.technet.com/isablog/archive/2009/05/16/teched-2009-post-show-feedback.aspx">latest blog from TMG's Product Unit Manager</a>, David B. Cross, Beta 3 will be released in the next couple of weeks. As for the full release, David says that they are still on track for Q4 this calendar year. ]]></description>
			<content:encoded><![CDATA[<p>It sounds like Threat Management Gateway (TMG), the new re-branded version of ISA Server, has been a popular topic at this years TechEd event in the US. </p>
<p>According to the <a href="http://blogs.technet.com/isablog/archive/2009/05/16/teched-2009-post-show-feedback.aspx">latest blog from TMG&#8217;s Product Unit Manager</a>, David B. Cross, Beta 3 will be released in the next couple of weeks. As for the full release, David says that they are still on track for Q4 this calendar year. <span id="more-201"></span></p>
<p>Beta 3 will introduce URL filtering that is &#8216;fully integrated&#8217; with TMG&#8217;s web policy rules, and also utilizes Microsoft Reputation Services. </p>
<p>Microsoft are also introducing Intrusion Prevention and Detection (IPS/IDS) capabilities in TMG. These systems will utilize a technology they&#8217;re calling Network Inspection System (NIS) that detects attacks using signatures of known vulnerabilities, downloaded from the Microsoft Malware Protection Center. For more information on NIS see <a href="http://blogs.technet.com/isablog/archive/2009/04/12/exercising-nis-with-test-signature.aspx">http://blogs.technet.com/isablog/archive/2009/04/12/exercising-nis-with-test-signature.aspx</a></p>
<p>If you&#8217;re currently using ISA 2004 or 2006, upgrading to TMG will consist of exporting rules and settings from ISA, then importing them into a clean installation of TMG. TMG will also only run on Windows Server 2008.</p>
<p>Improving the on-box reporting has not been a focus for the TMG development team, so analyzing TMG’s web proxy and firewall logs is still the best way to go for in depth reporting. </p>
<p>If you’re interested in reporting on your TMG log files stay tuned! We’re currently implementing support for the SQL Express, W3C and Native text logs. WebSpy Vantage is likely to be the first application to include the feature, with Analyzer and Live soon to follow. </p>
<p>All going well, you can expect to see TMG support in your favourite WebSpy app within the next month or so. If you want to be notified once we’ve added support, just leave a comment below.</p>
<p>Cheers!<br />
Scott.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

