<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Alik Levin's : Information Gathering</title><link>http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx</link><description>Tags: Information Gathering</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Calculate Security Breach Cost Yourself</title><link>http://blogs.msdn.com/alikl/archive/2007/04/19/calculate-security-breach-cost-yourself.aspx</link><pubDate>Fri, 20 Apr 2007 00:35:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2197599</guid><dc:creator>alikl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alikl/comments/2197599.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alikl/commentrss.aspx?PostID=2197599</wfw:commentRss><wfw:comment>http://blogs.msdn.com/alikl/rsscomments.aspx?PostID=2197599</wfw:comment><description>&lt;P&gt;That is both amazing and amusing (I will leave "why" to myself....) but now CxO does not have to think twice&amp;nbsp;whether security services are too expensive. Check out this Security Breach Cost Calculator.&lt;/P&gt;
&lt;P&gt;via &lt;A title=http://news.com.com/2061-10789_3-6176074.html?part=rss&amp;amp;tag=2063-10789_3-0&amp;amp;subj=news href="http://news.com.com/2061-10789_3-6176074.html?part=rss&amp;amp;tag=2063-10789_3-0&amp;amp;subj=news" mce_href="http://news.com.com/2061-10789_3-6176074.html?part=rss&amp;amp;tag=2063-10789_3-0&amp;amp;subj=news"&gt;http://news.com.com/2061-10789_3-6176074.html?part=rss&amp;amp;tag=2063-10789_3-0&amp;amp;subj=news&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For example, if MS corp network gets penetrated, having at hand it has &lt;A href="http://en.wikipedia.org/wiki/Microsoft" target=_blank mce_href="http://en.wikipedia.org/wiki/Microsoft"&gt;71,172 employees&lt;/A&gt;&amp;nbsp;the resulting cost would be about $10M. And that is just in short run, the losses caused by damaged reputation would be much higher. Fortunately, leading analysts and professionals&amp;nbsp;think we are doing good in that space (touch wood and&amp;nbsp;hooray to&amp;nbsp;&lt;A href="http://msdn2.microsoft.com/en-us/library/ms995349.aspx" target=_blank mce_href="http://msdn2.microsoft.com/en-us/library/ms995349.aspx"&gt;SDL&lt;/A&gt;!!):&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;"...we actually consider Microsoft to be leading the software [industry] now in improvements in their security&lt;U&gt; &lt;/U&gt;development life cycle and in how they handle vulnerabilities and release patches..&lt;BR&gt;&lt;STRONG&gt;John Pescatore, vice president at Gartner&lt;/STRONG&gt;", read full story &lt;A href="http://www.crn.com/sections/coverstory/coverstory.jhtml;jsessionid=VV1Q351RM5A1YQSNDBOCKH0CJUMEKJVN?articleId=179103240" target=_blank mce_href="http://www.crn.com/sections/coverstory/coverstory.jhtml;jsessionid=VV1Q351RM5A1YQSNDBOCKH0CJUMEKJVN?articleId=179103240"&gt;here&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"What the smart banks are doing about this is they’re building security into their development lifecycles, and that’s exactly what Microsoft has done," he [Mark Curphey] said.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="http://securitybuddha.com/" target=_blank mce_href="http://securitybuddha.com/"&gt;Mark Curphey&lt;/A&gt;, vice president of professional services at McAfee’s Foundstone division&lt;/STRONG&gt;,&amp;nbsp; read full story &lt;A href="http://www.cio.com/article/24914" target=_blank mce_href="http://www.cio.com/article/24914"&gt;here&lt;/A&gt;. Mark is founder of &lt;A href="http://owasp.org/" target=_blank mce_href="http://OWASP.org"&gt;OWASP.org&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image014.png" atomicselection="true" mce_href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image014.png"&gt;&lt;IMG height=400 src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image0_thumb10.png" width=536 mce_src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image0_thumb10.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or graphically:&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image013.png" atomicselection="true" mce_href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image013.png"&gt;&lt;IMG height=342 src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image0_thumb9.png" width=419 mce_src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CalculateSecurityBreachCoastAndCallMe_B6B4/image0_thumb9.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Direct link is here &lt;A title=http://www.tech-404.com/calculator.html href="http://www.tech-404.com/calculator.html" mce_href="http://www.tech-404.com/calculator.html"&gt;http://www.tech-404.com/calculator.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Have fun calculating your losses. Or just start proactively implementing &lt;A href="http://msdn.com/SecurityEngineering" mce_href="http://msdn.com/SecurityEngineering"&gt;Security Engineering&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Need help? - try this &lt;A class="" href="http://msdn2.microsoft.com/en-us/security/aa570410.aspx" target=_blank mce_href="http://msdn2.microsoft.com/en-us/security/aa570410.aspx"&gt;Security Developer Center: Security Development Lifecycle for IT &lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enjoy&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2197599" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alikl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx">Information Gathering</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Inception+Phase/default.aspx">Inception Phase</category></item><item><title>Code Inspection - First Look For What To Look For</title><link>http://blogs.msdn.com/alikl/archive/2007/03/20/code-inspection-first-look-for-what-to-look-for.aspx</link><pubDate>Wed, 21 Mar 2007 00:13:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1921458</guid><dc:creator>alikl</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.msdn.com/alikl/comments/1921458.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alikl/commentrss.aspx?PostID=1921458</wfw:commentRss><wfw:comment>http://blogs.msdn.com/alikl/rsscomments.aspx?PostID=1921458</wfw:comment><description>&lt;p&gt;Reposted from &lt;a href="http://blogs.microsoft.co.il/blogs/alikl/archive/2007/01/03/Code-Inspection-_2D00_-First-Look-For-What-To-Look-For.aspx"&gt;Security Code Inspection - First Look For What To Look For&lt;/a&gt;&amp;nbsp;for further reuse on this blog.&lt;/p&gt; &lt;p&gt;I found it extremely productive to first look for strings in the code. But what strings to look for? And how to look for the strings? Looking into the source files?&lt;/p&gt; &lt;p&gt;My good friend &lt;a href="http://blogs.microsoft.co.il/blogs/alikl/archive/2006/12/29/How-They-Will-Discover-Secrets-You-Hide.aspx" target="_blank"&gt;FindStr&lt;/a&gt; is of great help here:&lt;/p&gt; &lt;p&gt;So first let's find what to look for:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/THCMCh21.asp"&gt;Ildasm.exe secureapp.dll /text | findstr ldstr&lt;/a&gt;&lt;/p&gt; &lt;p&gt;This is what I've got using it:&lt;/p&gt; &lt;p&gt;Wouldn't it trigger you think of authorization data doing roundtrip thus vulnerable to tampering and elevation of privileges?&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image020.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="55" src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image0_thumb10.png" width="568" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Wouldn't it trigger you think there is some custom authentication mechanism that potentially could be vulnerable thus enabling identity spoofing?&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image021.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="128" src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image0_thumb11.png" width="325" border="0"&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Wouldn't it trigger you think.....&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;a href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image022.png" atomicselection="true"&gt;&lt;img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="101" src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/CodeInspectionFirstLookForWhatToLookFor_C01E/image0_thumb12.png" width="576" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;So once you have these strings you use same FindStr to find actual files to inspect:&lt;/p&gt; &lt;p&gt;findstr /S /M /I /d:c:\projects\yourweb "StringOfInterestGoesHere" *.cs &lt;/p&gt; &lt;p&gt;Cheers&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1921458" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alikl/archive/tags/Test+Phase/default.aspx">Test Phase</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx">Information Gathering</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Sensitive+Data/default.aspx">Sensitive Data</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Tools/default.aspx">Tools</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Code+Inspection/default.aspx">Code Inspection</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Development+Phase/default.aspx">Development Phase</category></item><item><title>I Invite You To Rob Me</title><link>http://blogs.msdn.com/alikl/archive/2007/03/09/i-invite-you-to-rob-me.aspx</link><pubDate>Fri, 09 Mar 2007 19:26:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1845698</guid><dc:creator>alikl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alikl/comments/1845698.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alikl/commentrss.aspx?PostID=1845698</wfw:commentRss><wfw:comment>http://blogs.msdn.com/alikl/rsscomments.aspx?PostID=1845698</wfw:comment><description>&lt;p&gt;Is not it usual OOF message we put?&lt;/p&gt; &lt;p&gt;"OOF until &amp;lt;&amp;lt;here comes date&amp;gt;&amp;gt; visiting customers in &amp;lt;&amp;lt;12 hours flight from home&amp;gt;&amp;gt;"&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;In other words, until the date you are invited to break into my office, house, and car.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Here are some guidelines from here &lt;a title="http://download.microsoft.com/download/5/1/0/51025bef-21e0-445d-b1e2-b07137414572/OutOfOffice_GS_2003_E.ppt" href="http://download.microsoft.com/download/5/1/0/51025bef-21e0-445d-b1e2-b07137414572/OutOfOffice_GS_2003_E.ppt"&gt;http://download.microsoft.com/download/5/1/0/51025bef-21e0-445d-b1e2-b07137414572/OutOfOffice_GS_2003_E.ppt&lt;/a&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/IInviteYouToRobMe_FFA7/image%7B0%7D%5B2%5D.png" atomicselection="true"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="263" src="http://blogs.msdn.com/blogfiles/alikl/WindowsLiveWriter/IInviteYouToRobMe_FFA7/image%7B0%7D_thumb.png" width="461" border="0"&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Enjoy&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1845698" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alikl/archive/tags/Test+Phase/default.aspx">Test Phase</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx">Information Gathering</category><category domain="http://blogs.msdn.com/alikl/archive/tags/End+User/default.aspx">End User</category></item><item><title>Google Hacking</title><link>http://blogs.msdn.com/alikl/archive/2007/03/06/google-hacking.aspx</link><pubDate>Tue, 06 Mar 2007 10:33:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1815126</guid><dc:creator>alikl</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/alikl/comments/1815126.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alikl/commentrss.aspx?PostID=1815126</wfw:commentRss><wfw:comment>http://blogs.msdn.com/alikl/rsscomments.aspx?PostID=1815126</wfw:comment><description>&lt;p&gt;&lt;a href="http://en.wikipedia.org/wiki/Google_Hacking"&gt;It is not hacking Google but using Google to hack others&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Got practical guide? - Sure:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.amazon.com/Google-Hacking-Penetration-Testers-Johnny/dp/1931836361/sr=8-1/qid=1166898469/ref=pd_bbs_sr_1/103-8306865-4097434?ie=UTF8&amp;amp;s=books" atomicselection="true"&gt;&lt;img id="prodImage" height="240" alt="Google Hacking for Penetration Testers" src="http://ec1.images-amazon.com/images/P/1931836361.01._AA240_SCLZZZZZZZ_.jpg" width="240" border="0"&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Got some tooling? - Sure:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&amp;amp;subcontent=/resources/proddesc/sitedigger.htm"&gt;SiteDigger™&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Can I do it with Live Search? - Sure:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/alikl/archive/2006/12/23/This-is-How-They-will-Hack-Your-Web-Site.aspx"&gt;This is How They will Hack Your Web Site&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;What do I do to get protected????!&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://msdn2.microsoft.com/en-us/library/ms998404.aspx"&gt;Proactive Security Engineering&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Got some Guidance Tooling? Of Course!!&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a href="http://www.codeplex.com/guidanceExplorer"&gt;Guidance Explorer&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=59888078-9daf-4e96-b7d1-944703479451&amp;amp;displaylang=en"&gt;Microsoft Threat Analysis &amp;amp; Modeling&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;a href="http://blogs.msdn.com/threatmodeling/default.aspx"&gt;Microsoft Application Threat Modeling Blog&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Enjoy&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1815126" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alikl/archive/tags/Test+Phase/default.aspx">Test Phase</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx">Information Gathering</category></item><item><title>Google Code Search - Different Perspective</title><link>http://blogs.msdn.com/alikl/archive/2007/03/05/google-code-search-different-perspective.aspx</link><pubDate>Mon, 05 Mar 2007 23:56:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1812158</guid><dc:creator>alikl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/alikl/comments/1812158.aspx</comments><wfw:commentRss>http://blogs.msdn.com/alikl/commentrss.aspx?PostID=1812158</wfw:commentRss><wfw:comment>http://blogs.msdn.com/alikl/rsscomments.aspx?PostID=1812158</wfw:comment><description>&lt;p&gt;&lt;a href="http://blogs.msdn.com/bwong_ms/archive/2006/10/05/Google-launches-a-special-treat-just-for-developers.aspx"&gt;Google launches a special treat just for developers&lt;/a&gt;&amp;nbsp;...&lt;/p&gt; &lt;p&gt;&amp;nbsp;I'd like to present it&amp;nbsp;from some different perspective.&lt;/p&gt; &lt;p&gt;Imagine you provide search criteria as follows:&lt;/p&gt; &lt;p&gt;"&lt;a href="http://www.google.com/codesearch?q=%22initial+catalog%22&amp;amp;hl=en"&gt;Initial Catalog&lt;/a&gt;" - try it. What do you see?&lt;/p&gt; &lt;p&gt;More like these &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2006/10/06/Fun-With-Google-Code-Search.aspx"&gt;here&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Doesn't it make you want to write more &lt;a href="http://msdn.com/securityengineering"&gt;secure code&lt;/a&gt;... :) ?&lt;/p&gt; &lt;p&gt;Enjoy&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=1812158" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/alikl/archive/tags/Test+Phase/default.aspx">Test Phase</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Information+Gathering/default.aspx">Information Gathering</category><category domain="http://blogs.msdn.com/alikl/archive/tags/Sensitive+Data/default.aspx">Sensitive Data</category></item></channel></rss>