<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>mcwresearch.com</title>
	<link>http://mcwresearch.com</link>
	<description>Things I think I've thought about</description>
	<pubDate>Mon, 31 Mar 2008 17:16:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>MS Exchange Spam Filtering</title>
		<link>http://mcwresearch.com/archives/625</link>
		<comments>http://mcwresearch.com/archives/625#comments</comments>
		<pubDate>Mon, 31 Mar 2008 17:05:58 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Exchange]]></category>

		<category><![CDATA[SCL]]></category>

		<category><![CDATA[Smartscreen]]></category>

		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/625</guid>
		<description><![CDATA[I&#8217;m no Microsoft Exchange guru, by any stretch of the imagination, but I&#8217;ve been working with our email provider for the past three weeks trying to get our spam filtering disabled on Exchange 2007 because we use a third party anti-spam service and wish to simplify the whole solution.  
There seems to be some [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/625/feed</wfw:commentRss>
		</item>
		<item>
		<title>Electric Sheep and Bittorrent</title>
		<link>http://mcwresearch.com/archives/624</link>
		<comments>http://mcwresearch.com/archives/624#comments</comments>
		<pubDate>Fri, 28 Mar 2008 13:07:53 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[BitTorrent]]></category>

		<category><![CDATA[Electric Sheep]]></category>

		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/624</guid>
		<description><![CDATA[Earlier this week I observed one of my laptops running World of Warcraft, which was accessing a *.torrent file.  Today, I found another application, this time a screen saver called Electric Sheep is using it.
Electric Sheep is a similar concept to SETI@home; network several machines together to utilize processing cycles once the machine goes [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/624/feed</wfw:commentRss>
		</item>
		<item>
		<title>Interesting Bittorrent client</title>
		<link>http://mcwresearch.com/archives/623</link>
		<comments>http://mcwresearch.com/archives/623#comments</comments>
		<pubDate>Mon, 24 Mar 2008 16:27:10 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Intrusion Detection/Prevention]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[BitTorrent]]></category>

		<category><![CDATA[World Of Warcraft]]></category>

		<category><![CDATA[WoW]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/623</guid>
		<description><![CDATA[One of my HIPS rules specifically blocks any access to a *.torrent file, for obvious reasons.  Going through my HIPS logs today, I see the following event:
The process &#8216;C:\World of Warcraft\BackgroundDownloader.exe&#8217; (as user [SNIP]) attempted to access &#8216;C:\Documents and Settings\[SNIP]\Local Settings\Temporary Internet Files\Content.IE5\Y7YR4USA\WoW-2.3.3.7799-x86-Win-enUS-BKGND[1].torrent&#8217;. The attempted access was a write (operation = WRITE). The operation [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/623/feed</wfw:commentRss>
		</item>
		<item>
		<title>DOH!</title>
		<link>http://mcwresearch.com/archives/622</link>
		<comments>http://mcwresearch.com/archives/622#comments</comments>
		<pubDate>Sun, 23 Mar 2008 14:52:31 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/622</guid>
		<description><![CDATA[I used to use Boxtrapper to control who could send email to an uber-secret email account, that Wordpress would check and post any email in that account.  
For some reason my hosting service removed Boxtrapper and of course the spam found my inbox and was subsequently posted here on my blog.  
To replace [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/622/feed</wfw:commentRss>
		</item>
		<item>
		<title>Thanks</title>
		<link>http://mcwresearch.com/archives/621</link>
		<comments>http://mcwresearch.com/archives/621#comments</comments>
		<pubDate>Sat, 22 Mar 2008 17:56:45 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/621</guid>
		<description><![CDATA[Thanks to everyone who let me know about the blog spam.  I believe it is coming in through the post-from-email feature.  I don&#8217;t have time right now to dig into it, I&#8217;m off to get belay certified, but I&#8217;ve disabled that feature.  Hopefully that puts an end to it.  
Thanks again.
	]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/621/feed</wfw:commentRss>
		</item>
		<item>
		<title>AV stats</title>
		<link>http://mcwresearch.com/archives/605</link>
		<comments>http://mcwresearch.com/archives/605#comments</comments>
		<pubDate>Mon, 18 Feb 2008 23:30:14 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[AV sucks]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/605</guid>
		<description><![CDATA[Take &#8216;em for what their worth; this is a collection of events logged from 277 hosts located in 12 different office locations with five unique, central AV servers managed by five different IT departments.  
The statistics have been collected over 11 days:


Number of alerts regarding a failure to open a file:
1253*


Number of alerts regarding [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/605/feed</wfw:commentRss>
		</item>
		<item>
		<title>The Future of AV?</title>
		<link>http://mcwresearch.com/archives/604</link>
		<comments>http://mcwresearch.com/archives/604#comments</comments>
		<pubDate>Mon, 11 Feb 2008 20:56:20 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[AV sucks]]></category>

		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/604</guid>
		<description><![CDATA[Last week I struck a cord with a few people when I (once again) complained publicly about the short-comings of AV.  I&#8217;ve gone on record claiming the current model is broken, so what do I think will help fix it?  Below are some of the ideas I&#8217;ve had for the future of AV. [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/604/feed</wfw:commentRss>
		</item>
		<item>
		<title>AV must innovate or die</title>
		<link>http://mcwresearch.com/archives/603</link>
		<comments>http://mcwresearch.com/archives/603#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:40:35 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[AV sucks]]></category>

		<category><![CDATA[Rant]]></category>

		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/603</guid>
		<description><![CDATA[One of the things I&#8217;ve been doing with my HIPS software is take a closer look at my AV protection, or lack thereof.  I have HIPS on roughly 300 hosts on my network, which is a slice of about 1/5th of my entire host population.  I have the HIPS software pulling selected events [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/603/feed</wfw:commentRss>
		</item>
		<item>
		<title>The conquerer of AV?</title>
		<link>http://mcwresearch.com/archives/602</link>
		<comments>http://mcwresearch.com/archives/602#comments</comments>
		<pubDate>Thu, 07 Feb 2008 21:54:05 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[AV sucks]]></category>

		<category><![CDATA[Intrusion Detection/Prevention]]></category>

		<category><![CDATA[A1000]]></category>

		<category><![CDATA[Antivirus]]></category>

		<category><![CDATA[Nemean]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/602</guid>
		<description><![CDATA[CSOonline.com has a good article about some emergent technology (the A1000) designed to create rules dynamically to detect malware.  
There isn&#8217;t a lot of information on the technology yet but it seems that it does have strong roots in IDS tech, which is exactly what I&#8217;ve been hoping will happen to AV.  
It [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/602/feed</wfw:commentRss>
		</item>
		<item>
		<title>MS08-001</title>
		<link>http://mcwresearch.com/archives/600</link>
		<comments>http://mcwresearch.com/archives/600#comments</comments>
		<pubDate>Fri, 01 Feb 2008 16:33:26 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
		
		<category><![CDATA[Patch-Tuesday]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[MS08-001]]></category>

		<category><![CDATA[Remote Kernel Attack]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/600</guid>
		<description><![CDATA[Am I being Chicken Little in thinking that remote kernel attacks such as one leveraging the MS08-001 vulnerability will be the next chapter in the arms race between hackers and network defenders?
Alex Wheeler, one of the two responsible for discovering and researching the vulnerability said this; &#8220;This is a severe vulnerability across the board. I [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/600/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
