<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-35072070</id><updated>2011-04-21T15:08:20.786-05:00</updated><category term='FDCC'/><category term='Common Access Card'/><category term='HSPD-12'/><category term='CAC'/><category term='DNS'/><category term='Nessus'/><category term='NIST 800-53'/><category term='Cache Poisoning'/><category term='FISMA'/><category term='OWASP Altiris BMC Rational Web Application Security Metric Framework'/><category term='Smart Card'/><category term='Dan Kaminsky'/><category term='Compliance Check'/><category term='Audit'/><title type='text'>Blogissimo De Ronaldo</title><subtitle type='html'>Differences in opinion lead to similarities in frustration.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://roncharette.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://roncharette.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Ron</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-35072070.post-6506580957429016109</id><published>2009-03-26T07:12:00.015-05:00</published><updated>2009-03-27T00:23:43.856-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP Altiris BMC Rational Web Application Security Metric Framework'/><title type='text'></title><content type='html'>&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Proposal of Web Application Security Metric Framework to Compliance/Configuration Management Vendors (Altiris, BMC, Rational, et al)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Ron Charette, CISSP&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;&lt;br /&gt;In March 2009, OWASP took a survey of 50 companies and found 61% of those surveyed had an independent third-party security review of software code to find flaws before web applications were used live&lt;/span&gt;&lt;a href="http://www.owasp.org/images/b/b2/OWASP_SSB_Project_Report_March_2009.pdf"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;[1]&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;.  This was a new kind of a survey, which attempted to derive benchmarks from software development and how it is associated with spending.  Earlier in the month, &lt;/span&gt;&lt;a href="http://jeremiahgrossman.blogspot.com/2009/03/website-security-needs-strategy.html"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Jeremiah Grossman&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt; of WhiteHat Security Inc. put a call out for metrics on twitter: "Impossible to know what works without outcome based metrics. Limited data on what happened, less on how, and neither is tied&lt;/span&gt;&lt;a href="http://twitter.com/jeremiahg/statuses/1263037965"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;[3]&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;."  Grossman is on a tear, and we the security community (and ironically also the user community), support him. &lt;br /&gt;&lt;br /&gt;It is for the above reasons that this methodology and schema are proposed, which may be built on and used to capture metrics (at this point I'd call them estimates, but it is a beginning) for quantifying costs against the effect of the software cycle.  Dare I call it "cost and effect?"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;*Which Beans are we Counting?*&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;In order to capture vital data used to tie back through the software development and security testing cycles, metrics need to be captured, which involve the following phases:&lt;br /&gt;     - Baseline (optional at this time)&lt;br /&gt;     - Configuration Changes&lt;br /&gt;     - Vulnerabilities Found&lt;br /&gt;     - Remediation&lt;br /&gt;     - Mitigation&lt;br /&gt;     - Incident Response&lt;br /&gt;     - Budgeting&lt;br /&gt;&lt;br /&gt;Within the above phases, it would then be necessary to capture the following attributes (more to follow):&lt;br /&gt;     - Type/Category&lt;br /&gt;     - Date Completed&lt;br /&gt;     - Severity (phase specific)&lt;br /&gt;     - Rationale (phase specific)&lt;br /&gt;     - Itemized Cost&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;*What problems does having this data solve?*&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;Through the collection of the above, it is felt that a historical record will be conceived to provide the information holder with strongly typed information, which then may be transformed into reports or decision points for future budgetary, software, and security-based concerns.&lt;br /&gt;&lt;br /&gt;In its present form, thinking a little more data can be captured to add much more value cannot be helped.  The benefit of this methodology is that it can be used to scale to virtually any organization or data set.  The complement would be to design a schema with the flexibility to use multiple revisions (interoperability) on a technology able to fully harness the information, such as a web service (accessibility).  Having this data readily available and interoperable in a universal form could potentially provide a very powerful platform.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;*Factoring Budget Considerations*&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;The most important function of this exercise is also one of the most complex.  In the development of software, acquisition cycles are often specialized, and as a result intrinsically laden with processes that do not lend well to providing a single itemized cost.  For this reason, a schema is provided to address these accounting functions and to (hopefully) assist in assignment of cost to the metric model. &lt;br /&gt;&lt;br /&gt;Worthy of note, the Budgeting schema is not for the already itemized costs placed within the phases, but a roll-up of the organizational or programmatic costs.  The intent is to capture these costs and distribute them over the remaining phases once they are sufficiently known and isolated.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;*In Support of an XML Schema*&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;After considering the above, it is then naturally deduced by the author that the typing and scalabilty of XML lend well to the type of data collected and harnessed in this manner.  Exact schema to follow.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;*Bibliography*&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;&lt;br /&gt;[1] http://www.owasp.org/images/b/b2/OWASP_SSB_Project_Report_March_2009.pdf&lt;br /&gt;[2] http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1351731,00.html?track=sy160&lt;br /&gt;[3] http://twitter.com/jeremiahg/statuses/1263037965&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Acknowledgment to &lt;/span&gt;&lt;a href="http://www.blackhat.org/"&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt;Jason Oliver&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: arial;"&gt; for providing the fire to work this through.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="color: rgb(51, 51, 51);   font-family:'trebuchet ms';font-size:13px;"&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 10px/normal Monaco; min-height: 14px; "&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192); "&gt;&lt;a rel="license" href="http://creativecommons.org/licenses/by-sa/3.0/us/"&gt;&lt;img alt="Creative Commons License" style="border-width:0" src="http://i.creativecommons.org/l/by-sa/3.0/us/88x31.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 10px/normal Monaco; "&gt;&lt;span class="Apple-style-span" style=""&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192);"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 51, 51); "&gt;&lt;span dc="http://purl.org/dc/elements/1.1/" href="http://purl.org/dc/dcmitype/Text" property="dc:title" rel="dc:type"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192); "&gt;Proposal of Web Application Security Metric Framework to Compliance/Configuration Management Vendors (Altiris, BMC, Rational, et al)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192); "&gt; by &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 153); "&gt;&lt;a href="http://roncharette.blogspot.com/2009/03/proposal-of-web-application-security_26.html"&gt;Ron Charette&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192); "&gt; is licensed under a &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192); "&gt;&lt;a href="http://creativecommons.org/licenses/by-sa/3.0/us/"&gt;Creative Commons Attribution-Share Alike 3.0 United States License&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: rgb(192, 192, 192);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35072070-6506580957429016109?l=roncharette.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://roncharette.blogspot.com/feeds/6506580957429016109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35072070&amp;postID=6506580957429016109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/6506580957429016109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/6506580957429016109'/><link rel='alternate' type='text/html' href='http://roncharette.blogspot.com/2009/03/proposal-of-web-application-security_26.html' title=''/><author><name>Ron</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35072070.post-6185788540638642411</id><published>2008-07-25T15:00:00.009-05:00</published><updated>2008-07-27T10:52:49.558-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CAC'/><category scheme='http://www.blogger.com/atom/ns#' term='Smart Card'/><category scheme='http://www.blogger.com/atom/ns#' term='HSPD-12'/><category scheme='http://www.blogger.com/atom/ns#' term='Common Access Card'/><title type='text'></title><content type='html'>&lt;span class="Apple-style-span"  style="font-size:x-large;"&gt;Smart Cards, Common Access Card (CAC), HSPD-12 and you...&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I was searching the Internets for a sensible article, post, anything on the practical application of smart cards and came up with a lot of technical jargon and solutions but not much practical information for the everyday Joe security guy or admin.  Why should I care?  Well, as logical and physical security technologies evolve, the use of a smart card (and a RFID or GPS one at that) seems quite useful as an access replacement to current technologies.  It would only follow that governments and big business will be soon to follow suit in implementing this technology... so why not start making it simple to understand?  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;What are smart cards?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.doi.gov/nbc/eps/seiwg.pdf"&gt;http://www.doi.gov/nbc/eps/seiwg.pdf&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;OS Insecurity:  How does your favorite OS deal with these scenarios when CAC authentication is enabled?&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Remote administration&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Non-Kerberos or non-PKI authentication&lt;/li&gt;&lt;li&gt;Services running as users instead of system&lt;/li&gt;&lt;li&gt;Emergency root-level access&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Microsoft Windows and Smart Cards&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;A user receives an "Unable to log you on because it is required that you use a smart card" message when the user tries to log on to your Windows XP-based computer by using Remote Assistance&lt;br /&gt;http://support.microsoft.com/kb/893226&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;How to access a network resource that requires username and password authentication when your user account requires a smart card for interactive logon&lt;br /&gt;http://support.microsoft.com/kb/834432&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;After you use a smart card to unlock a Windows XP-based computer, you are prompted for authentication when you access resources that require NTLM authentication&lt;br /&gt;http://support.microsoft.com/kb/939850&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;"Local Policy of This System Requires You to Logon Using a Smart Card" Message Appears When You Try to Log On to the Server&lt;br /&gt;http://support.microsoft.com/kb/832026&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;A scheduled task that is running under a specific account cannot access a shared network resource in Windows XP&lt;br /&gt;http://support.microsoft.com/kb/887572&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Services and scheduled tasks cannot log on if a smart card is not present in Windows Server 2003&lt;br /&gt;http://support.microsoft.com/kb/889505&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Dell Identity Management Solutions&lt;br /&gt;http://www.dell.com/downloads/global/power/ps4q06-20070155-IdentiPHI.pdf&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;These are some initial thoughts... more to follow...&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35072070-6185788540638642411?l=roncharette.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://roncharette.blogspot.com/feeds/6185788540638642411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35072070&amp;postID=6185788540638642411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/6185788540638642411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/6185788540638642411'/><link rel='alternate' type='text/html' href='http://roncharette.blogspot.com/2008/07/common-access-card-cac-hspd-12-and-you.html' title=''/><author><name>Ron</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35072070.post-836537975641007864</id><published>2008-07-25T13:21:00.009-05:00</published><updated>2008-07-27T10:20:50.902-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Cache Poisoning'/><category scheme='http://www.blogger.com/atom/ns#' term='Dan Kaminsky'/><title type='text'></title><content type='html'>&lt;span class="Apple-style-span"  style="font-size:x-large;"&gt;Dan Kaminsky's DNS In-Bailiwick Spoofing Vulnerability Find&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First off, good on Dan for finding yet another way to break DNS.  By combining previously known loopholes with a new twist, a truly lethal and rather trivial exploit has been found to attack the soft underbelly of recursive DNS servers.  More information on the find below:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dan's Black Hat Talk (Archived)&lt;/div&gt;&lt;div&gt;&lt;a href="https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;amp;eventid=114268"&gt;https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;amp;eventid=114268&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;US-CERT - Multiple DNS implementations vulnerable to cache poisoning&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.us-cert.gov/cas/techalerts/TA08-190B.html"&gt;http://www.us-cert.gov/cas/techalerts/TA08-190B.html&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Workaround:&lt;/div&gt;&lt;div&gt;There really isn't one.  Non-Internet facing DNS servers talking to non-recursive (authoritative) DNS servers is the closest thing you got to being anywhere near a safe situation.  In simple terms... you are screwed if you use a large ISP to connect to the Internet from home; if you are at a small company that has sharp administrators you might have a fighting chance.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Problem:&lt;/div&gt;&lt;div&gt;Sure cache poisoning is bad.  However, I'm more interested in what can be done with this exploit... I mean what really can be done.  If I was going to change a DNS server entry, the last thing I would do would be direct www.Google.com to my own website saying, "PWN'T!"  If I were really evil, I would take a DNS entry for a bank and proxy the traffic through a botnet.  In other words, real-world information gathering (and subsequent use) would be my main goal.  Actually, if I were pure evil, this exploit would be used to ends having to do more with the Estonian hack than for my own purposes.  Whatever the case, these scenarios are something I think is fundamental to the problem (improper browser use, email insecurity, and shabby OS and application configuration holes so large you could drive a truck through).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Fix:&lt;/div&gt;&lt;div&gt;There is a fine line between full-disclosure and stomping on a story.  Here again I would commend Dan.  He kept the problem under wraps so the fix could get organized.  In the end, the cat got out anyway (some say it was 6 months, some say 13 days).  Regardless, this exploit is fundamental to the function of DNS and any suggested fix to the problem only leads to slowing down an attack (days instead of seconds) and does not actually stop it.  To date the only true fix proposed has been DNSSEC.  If I know anything about the Internet, implementing a new protocol only takes... (cough: IPv6) forever.  Anyway, hell if I know what that DNSSEC does.  Sadly, I just know the name... and there in lies my final point.  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35072070-836537975641007864?l=roncharette.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://roncharette.blogspot.com/feeds/836537975641007864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35072070&amp;postID=836537975641007864' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/836537975641007864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/836537975641007864'/><link rel='alternate' type='text/html' href='http://roncharette.blogspot.com/2008/07/dan-kaminskys-dns-in-bailiwick-spoofing.html' title=''/><author><name>Ron</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35072070.post-8693665951087711261</id><published>2008-05-22T20:58:00.008-05:00</published><updated>2008-07-27T10:23:08.704-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Compliance Check'/><category scheme='http://www.blogger.com/atom/ns#' term='FISMA'/><category scheme='http://www.blogger.com/atom/ns#' term='Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='FDCC'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST 800-53'/><title type='text'></title><content type='html'>&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:x-large;"&gt;FDCC XP Nessus Compliance Check AUDIT File&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you are interested in performing Nessus compliance checks that produce an 800-53 report for NIST's FDCC XP Baseline; you've come to the right spot... &lt;a href="http://www.roncharette.com-a.googlepages.com/SCAP-800-53-FDCC-XP-v1.audit"&gt;Download Here&lt;/a&gt;.  If you don't have any clue what I just said, might as well save your sanity and enjoy &lt;a href="http://www.roseandisabel.com/"&gt;this&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35072070-8693665951087711261?l=roncharette.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://roncharette.blogspot.com/feeds/8693665951087711261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35072070&amp;postID=8693665951087711261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/8693665951087711261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35072070/posts/default/8693665951087711261'/><link rel='alternate' type='text/html' href='http://roncharette.blogspot.com/2008/05/if-you-are-interested-in-nessus.html' title=''/><author><name>Ron</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
