<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Worms are an effective weapon in cyber warfare</title>
	<atom:link href="http://mcwresearch.com/archives/647/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com/archives/647</link>
	<description>Things I think I've thought about</description>
	<lastBuildDate>Thu, 16 Feb 2012 16:52:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: mcwresearch.com &#187; Conficker Hits French MoD</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5049</link>
		<dc:creator>mcwresearch.com &#187; Conficker Hits French MoD</dc:creator>
		<pubDate>Tue, 10 Feb 2009 12:57:52 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5049</guid>
		<description>[...] the recent compromise of the British MoD, the compromise of the French MoD appears to have been isolated to the [...]</description>
		<content:encoded><![CDATA[<p>[...] the recent compromise of the British MoD, the compromise of the French MoD appears to have been isolated to the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; An Information Security Place Podcast - Episode 14</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5047</link>
		<dc:creator>&#187; An Information Security Place Podcast - Episode 14</dc:creator>
		<pubDate>Thu, 29 Jan 2009 09:02:16 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5047</guid>
		<description>[...] up - Same worm variant is also attacking the UK MOD - Michael at [...]</description>
		<content:encoded><![CDATA[<p>[...] up &#8211; Same worm variant is also attacking the UK MOD &#8211; Michael at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim&#8217;s Bloggyness &#187; Post Topic &#187; An Information Security Place Podcast - Episode #14</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5046</link>
		<dc:creator>Jim&#8217;s Bloggyness &#187; Post Topic &#187; An Information Security Place Podcast - Episode #14</dc:creator>
		<pubDate>Thu, 29 Jan 2009 05:08:29 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5046</guid>
		<description>[...] Confiker Worm Takes Down UK Hospitals and the MOD - Link Here / Link Here [...]</description>
		<content:encoded><![CDATA[<p>[...] Confiker Worm Takes Down UK Hospitals and the MOD &#8211; Link Here / Link Here [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5041</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 21 Jan 2009 15:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5041</guid>
		<description>In the network security podcast linked twice above, they talk about this incident at 17:49 into the podcast.

They don&#039;t really go into the worm as a weapon in cyber warfare but instead focus on the intermingling of networks.  One of the points they don&#039;t mention is that even if the networks don&#039;t mingle and operational/navigational networks aren&#039;t directly at risk, this threat still saps resources from those networks as IT staff scramble to regain control of the administration networks.

There is also the sneakernet to be considered.  USB drives (which conficker leverages) can travel from one network to the other and deliver worms through that vector.  Usually in classified networks USB drives are forbidden but if you miss restricting them on even one machine, the users will find it and exploit it, not necessarily intending to be malicious but for convenience.  

Granted, this worm attack wouldn&#039;t be a tactical win if it were a part of cyber warfare but it would certainly serve a purpose in propaganda, by demonstrating that even an aircraft carrier&#039;s network and more importantly the Ministry of Defense network has weaknesses to be easily exploited.</description>
		<content:encoded><![CDATA[<p>In the network security podcast linked twice above, they talk about this incident at 17:49 into the podcast.</p>
<p>They don&#8217;t really go into the worm as a weapon in cyber warfare but instead focus on the intermingling of networks.  One of the points they don&#8217;t mention is that even if the networks don&#8217;t mingle and operational/navigational networks aren&#8217;t directly at risk, this threat still saps resources from those networks as IT staff scramble to regain control of the administration networks.</p>
<p>There is also the sneakernet to be considered.  USB drives (which conficker leverages) can travel from one network to the other and deliver worms through that vector.  Usually in classified networks USB drives are forbidden but if you miss restricting them on even one machine, the users will find it and exploit it, not necessarily intending to be malicious but for convenience.  </p>
<p>Granted, this worm attack wouldn&#8217;t be a tactical win if it were a part of cyber warfare but it would certainly serve a purpose in propaganda, by demonstrating that even an aircraft carrier&#8217;s network and more importantly the Ministry of Defense network has weaknesses to be easily exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Network Security Podcast, Episode 135</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5040</link>
		<dc:creator>Network Security Blog &#187; Network Security Podcast, Episode 135</dc:creator>
		<pubDate>Wed, 21 Jan 2009 00:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5040</guid>
		<description>[...] Worms run rampant through UK Ministry of Defense systems. [...]</description>
		<content:encoded><![CDATA[<p>[...] Worms run rampant through UK Ministry of Defense systems. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Podcast &#187; Blog Archive &#187; Network Security Podcast, Episode 135</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5039</link>
		<dc:creator>Network Security Podcast &#187; Blog Archive &#187; Network Security Podcast, Episode 135</dc:creator>
		<pubDate>Wed, 21 Jan 2009 00:47:56 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5039</guid>
		<description>[...] Worms run rampant through UK Ministry of Defense systems. [...]</description>
		<content:encoded><![CDATA[<p>[...] Worms run rampant through UK Ministry of Defense systems. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://mcwresearch.com/archives/647/comment-page-1#comment-5038</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Tue, 20 Jan 2009 21:50:38 +0000</pubDate>
		<guid isPermaLink="false">http://mcwresearch.com/?p=647#comment-5038</guid>
		<description>More than likely, someone just doesn&#039;t know what they&#039;re saying and are mixing rumors or separate incidents, in regards to the sending of email to Russia.

Either way, obviously there is a level of incompetence somewhere in there.</description>
		<content:encoded><![CDATA[<p>More than likely, someone just doesn&#8217;t know what they&#8217;re saying and are mixing rumors or separate incidents, in regards to the sending of email to Russia.</p>
<p>Either way, obviously there is a level of incompetence somewhere in there.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

