<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Security Top Headlines &#187; case studies</title>
	<atom:link href="http://www.pinolobu.com/security/category/case-studies/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pinolobu.com/security</link>
	<description>interesting news and opinions about IT security</description>
	<lastBuildDate>Wed, 30 Sep 2009 09:05:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Beware of facebook phishing site: faecibook.com</title>
		<link>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/</link>
		<comments>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 02:56:51 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[faecibook]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=105</guid>
		<description><![CDATA[First post I&#8217;ve seen is dated 7th August 2009.
If you see a comment that goes something like this, DO NOT CLICK ON IT:
seen this really bad blog about you? http://www.jdsense.com/search/redirect.php?f=http://blogs.faecibook.com/sessionid?nglnbskuf

Apparently China based, it will bring you to an authentic-looking FAKE Facebook page that tells you Your Session Has Expired and will require you to login [...]]]></description>
			<content:encoded><![CDATA[<p>First post I&#8217;ve seen is dated 7th August 2009.</p>
<p>If you see a comment that goes something like this, DO NOT CLICK ON IT:</p>
<blockquote><p>seen this really bad blog about you? http://www.jdsense.com/search/redirect.php?f=http://blogs.faecibook.com/sessionid?nglnbskuf
</p></blockquote>
<p>Apparently China based, it will bring you to an authentic-looking FAKE Facebook page that tells you Your Session Has Expired and will require you to login with your email and password. </p>
<p>Its only purpose is to harvest your email address and facebook password, and the creators are writing comments on strangers&#8217; statuses. </p>
<p>So far, the comments have been either &#8220;seen this really bad blog about you?&#8221; or &#8220;I have a 13 year old daughter who is in LOVE with you.&#8221; </p>
<p>Apparently, in a few minutes, the message will be deleted.</p>
<p>If you happen to experience this, CHANGE YOUR PASSWORD NOW!!!</p>
<p>Technical info:</p>
<p>It seems the domain was set up on 6th August 2009 under the name Li Wang, registered in Shanghai with email lixing688@gmail.com, and phone/fax no: 86-021-51697771</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Subsidised liquid fuel detected via nanotags</title>
		<link>http://www.pinolobu.com/security/2007/07/15/subsidised-liquid-fuel-detected-via-nanotags/</link>
		<comments>http://www.pinolobu.com/security/2007/07/15/subsidised-liquid-fuel-detected-via-nanotags/#comments</comments>
		<pubDate>Sun, 15 Jul 2007 04:44:30 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2007/07/15/subsidised-liquid-fuel-subsidised-via-nanotags/</guid>
		<description><![CDATA[The Borneo Post reported on 31 May 2007 that the Sarawak State goverment hopes to save RM750 million this year as more companies in illegal possession of subsidised diesel are caught via nanotag detection system.
But what is it and how does it work?
Developed in the US, a chemical marker that is added to diesel consignments [...]]]></description>
			<content:encoded><![CDATA[<p>The Borneo Post reported on 31 May 2007 that the Sarawak State goverment hopes to save RM750 million this year as more companies in illegal possession of subsidised diesel are caught via nanotag detection system.</p>
<p>But what is it and how does it work?</p>
<p>Developed in the US, a chemical marker that is added to diesel consignments before leaving oil terminals. Every 8,000 litres of subsidised diesel is doped with a 25ml vial of the chemical. Doped diesel cannot be differentiated by visible means. Its low concentration level is akin to one second in 15 years. No amount of mixing subsidised diesel with those that are not ‘tagged’ will affect the results.</p>
<p>To detect the presence of nanotags in a diesel sample, another chemical is used. It is drawn into a syringe containing the diesel sample &#8211; the presence of nanotags would turn the diesel sample either white or pink in colour.</p>
<p>Normal diesel stored in tanks, which have previously contained nanotag doped diesel, would not be tested positive, because the sensitivity of the chemical has been adjusted to ensure that containers used to store both ‘tagged’ and ‘non-tagged’ diesel will not give contradicting results.</p>
<p>It seems to be very effective. According to the newsreport, since its implementation in Sept 2006, more than 60 per cent of industrial sites have tested positive for illegal possession of subsidised diesel. That&#8217;s more than half!<br />
As an indication of the size of the matter: in Malaysia there are 4,000 approved fuel distributors, and there are a total of 10,000 factories.</p>
<p>Apparently nanotag techology are also applied in this way in India, Brazil and of course the US.</p>
<p><a href="http://www.theborneopost.com/?p=18870">source</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2007/07/15/subsidised-liquid-fuel-detected-via-nanotags/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCTVs are getting smarter: beware shoplifters</title>
		<link>http://www.pinolobu.com/security/2006/11/03/cctvs-are-getting-smarter-beware-shoplifters/</link>
		<comments>http://www.pinolobu.com/security/2006/11/03/cctvs-are-getting-smarter-beware-shoplifters/#comments</comments>
		<pubDate>Thu, 02 Nov 2006 21:52:01 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2006/10/31/cctvs-are-getting-smarter-beware-shoplifters/</guid>
		<description><![CDATA[As reported by Business Week  in September:
Some Macy&#8217;s, CVS, and Babies &#8216;R&#8217; Us stores have installed a system called the Video Investigator, whose advanced surveillance software can compare a shopper&#8217;s movements between video images and recognize unusual activity. Remove 10 items from a shelf at once, for instance, or open a case that&#8217;s normally [...]]]></description>
			<content:encoded><![CDATA[<p>As reported by Business Week  in September:</p>
<blockquote><p><span class="text" style="font-family: arial,helvetica,univers">Some Macy&#8217;s, CVS, and Babies &#8216;R&#8217; Us stores have installed a system called the Video Investigator, whose advanced surveillance software can compare a shopper&#8217;s movements between video images and recognize unusual activity. Remove 10 items from a shelf at once, for instance, or open a case that&#8217;s normally kept closed and locked, and the system alerts guards sitting in a back room &#8212; or pacing the sales floor &#8212; with a chime or flashing screen. The system can predict where a shoplifter is likely to hide (at the ends of aisles, behind floor displays). A search function spots sudden movement that might indicate a large spill, prompting workers to clean up before it leads to a slip-and-fall accident and a costly lawsuit. And if someone opens a back door at 2 a.m., the system will record who sneaked in and link it with snapshots of the previous and next persons to use the door. Alerts, complete with images, can be sent to handheld devices, keeping retailers informed 24/7, says Jumbi Edulbehram, vice-president for strategic marketing at IntelliVid Corp., a Cambridge (Mass.) firm that makes the Video Investigator system.</span></p></blockquote>
<p><a href="http://www.businessweek.com/magazine/content/06_37/b4000401.htm?chan=tc&#038;campaign_id=bier_tcst0">source</a></p>
<p><small>Tags: <a rel="tag" href="http://technorati.com/tag/CCTV">CCTV</a>, <a rel="tag" href="http://technorati.com/tag/security">security</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2006/11/03/cctvs-are-getting-smarter-beware-shoplifters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ATM machines *are* connected to the internet</title>
		<link>http://www.pinolobu.com/security/2006/07/13/atm-machines-are-connected-to-the-internet/</link>
		<comments>http://www.pinolobu.com/security/2006/07/13/atm-machines-are-connected-to-the-internet/#comments</comments>
		<pubDate>Wed, 12 Jul 2006 18:08:51 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2006/07/13/atm-machines-are-connected-to-the-internet/</guid>
		<description><![CDATA[Who said ATM machines are not connected to the internet, and hence safe from online theft?
Maybe not all are wired to the net, but at least some are.
Malaysian banks &#8211; anybody know their status?
http://www.windowsfordevices.com/news/NS6438545389.html
Tags: ATM+machines, internet, security
]]></description>
			<content:encoded><![CDATA[<p>Who said ATM machines are not connected to the internet, and hence safe from online theft?</p>
<p>Maybe not all are wired to the net, but at least some are.</p>
<p>Malaysian banks &#8211; anybody know their status?</p>
<p>http://www.windowsfordevices.com/news/NS6438545389.html</p>
<p><small>Tags: <a rel="tag" href="http://technorati.com/tag/ATM%2Bmachines">ATM+machines</a>, <a rel="tag" href="http://technorati.com/tag/internet">internet</a>, <a rel="tag" href="http://technorati.com/tag/security">security</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2006/07/13/atm-machines-are-connected-to-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University server was controlled by hackers for a year</title>
		<link>http://www.pinolobu.com/security/2006/07/03/university-server-was-controlled-by-hackers-for-a-year/</link>
		<comments>http://www.pinolobu.com/security/2006/07/03/university-server-was-controlled-by-hackers-for-a-year/#comments</comments>
		<pubDate>Mon, 03 Jul 2006 14:46:07 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2006/07/03/university-server-was-controlled-by-hackers-for-a-year/</guid>
		<description><![CDATA[&#8230;before anyone found out at Ohio University.
And it&#8217;s not a small matter:

they had likely hundreds of servers, at least 3 were compromised
at least one of the servers compromised contained Social Security numbers of more than 130,000 people
the other 2 servers had health records belonging to students treated at the university&#8217;s health center stolen, as well [...]]]></description>
			<content:encoded><![CDATA[<p>&#8230;before anyone<a href="http://news.com.com/University+server+in+hackers+hands+for+a+year/2100-7349_3-6074739.html?tag=nefd.top"> found out</a> at Ohio University.</p>
<p>And it&#8217;s not a small matter:</p>
<ul>
<li>they had likely hundreds of servers, at least 3 were compromised</li>
<li>at least one of the servers compromised contained Social Security numbers of more than 130,000 people</li>
<li>the other 2 servers had health records belonging to students treated at the university&#8217;s health center stolen, as well as more Social Security numbers.</li>
<li>penetrated by both US and overseas hackers</li>
</ul>
<p>The Uni only came to know about it after the FBI discovered someone had remotely taken control of one of the school&#8217;s servers. What if they didn&#8217;t? </p>
<p>Universities are popular targets for hackers because:</p>
<ul>
<li>due to the fact that they store Social Security numbers and other data useful for committing identity thefts </li>
<li>they don&#8217;t take security seriously enough.</li>
<li>they have to keep information free flowing (maintain delicate balance in flexibility and security), unlike corporations which can issue immediate lockdown</li>
</ul>
<p>Bill Sams, the school&#8217;s CIO said: &quot;We need someone somewhere to come up with a set of best practices for schools.&quot;</p>
<p>How hackers managed to get in, according to Sams:</p>
<blockquote>
<p>A server supporting the alumni relations department was supposed to be offline. The people responsible for shutting it down thought they had done so. The server continued to be connected to the Internet but didn&#8217;t receive security updates. It was the equivalent of leaving a backdoor open for thieves to walk in and seize what they wanted.</p>
</blockquote>
<p>The following is a sobering statement for all of us:</p>
<blockquote>
<p>&quot;We had a failure of both policies and procedures,&quot; Sams said. Asked why, when so many schools were succumbing to computer attacks, Ohio University wasn&#8217;t quicker to order a security audit, Sams replied: &quot;Should we have? Yes. Did we? No.&quot;</p>
</blockquote>
<blockquote>
</p>
</blockquote>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2006/07/03/university-server-was-controlled-by-hackers-for-a-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
