<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Beast Or Buddha</title>
	<atom:link href="http://beastorbuddha.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://beastorbuddha.com</link>
	<description>The ramblings in here are predominantly focused around IT Security topics. They are just my own takes on the industry and comments from industry peers. I don't profess to being able to solve the world's problems but happy to open myself up to criticisms and debate.</description>
	<lastBuildDate>Fri, 12 Mar 2010 23:02:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Securus Global Roles</title>
		<link>http://beastorbuddha.com/2010/03/12/securus-global-roles/</link>
		<comments>http://beastorbuddha.com/2010/03/12/securus-global-roles/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 07:22:37 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[IT Security Jobs]]></category>
		<category><![CDATA[Penetration Testers]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2243</guid>
		<description><![CDATA[We&#8217;re looking for people again. Check out the role advertisement. If you think you fit the role description and want to join one of the region&#8217;s best and fastest growing security companies, give us a yell.
Just a note: while we are open to overseas people applying, and we have recruited OS before, having a work [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re looking for people again. Check out the <a href="http://beastorbuddha.com/bhj/2010/03/12/security-consultantsecuritytestingpenetration-testing-melbourne-new/" target="_blank">role advertisement</a>. If you think you fit the role description and want to join one of the region&#8217;s best and fastest growing security companies, give us a yell.</p>
<p>Just a note: while we are open to overseas people applying, and we have recruited OS before, having a work visa or the like for Australia is preferred.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/12/securus-global-roles/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Why is &#8220;Commander&#8221; still allowed to do business?</title>
		<link>http://beastorbuddha.com/2010/03/09/why-is-commander-still-allowed-to-do-business/</link>
		<comments>http://beastorbuddha.com/2010/03/09/why-is-commander-still-allowed-to-do-business/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 11:56:02 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Bad Stuff]]></category>
		<category><![CDATA[WTF]]></category>
		<category><![CDATA[Commander]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2238</guid>
		<description><![CDATA[This is a dodgy operation who went bankrupt and did not pay their bills but somehow still exist under the same name?
http://www.commander.com/
Stay away from them. Weird they exist.
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.
]]></description>
			<content:encoded><![CDATA[<p>This is a dodgy operation who went bankrupt and did not pay their bills but somehow still exist under the same name?</p>
<p><a href="http://www.commander.com/" target="_blank">http://www.commander.com/</a></p>
<p>Stay away from them. Weird they exist.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/09/why-is-commander-still-allowed-to-do-business/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Consortium Watch&#8230;..</title>
		<link>http://beastorbuddha.com/2010/03/09/security-consortium-watch/</link>
		<comments>http://beastorbuddha.com/2010/03/09/security-consortium-watch/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 05:42:33 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Bad Stuff]]></category>
		<category><![CDATA[Dumb Security]]></category>
		<category><![CDATA[WTF]]></category>
		<category><![CDATA[Cloud Security Alliance]]></category>
		<category><![CDATA[ICASI]]></category>
		<category><![CDATA[SAFECode]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2235</guid>
		<description><![CDATA[I&#8217;m not going to go back over all the old posts to try to remember who all these mobs were, but is there a consortium still doing anything? eg; ICASI and SAFECode. etc etc&#8230;..
Some previous posts mentioning them: http://beastorbuddha.com/?s=consortium
Not much more to add that I haven&#8217;t already said in the link above and links within [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not going to go back over all the old posts to try to remember who all these mobs were, but is there a consortium still doing anything? eg; <a href="http://www.icasi.org/companies.htm" target="_blank">ICASI</a> and <a href="http://www.safecode.org/" target="_blank">SAFECode</a>. etc etc&#8230;..</p>
<p>Some previous posts mentioning them: <a href="http://beastorbuddha.com/?s=consortium" target="_self">http://beastorbuddha.com/?s=consortium</a></p>
<p>Not much more to add that I haven&#8217;t already said in the link above and links within the posts.</p>
<p>Is there a Cloud one also? Sure there is. <img src='http://beastorbuddha.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/09/security-consortium-watch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;Emerging Threats&#8221; &#8211; Most &#8220;emerged&#8221; a long time ago&#8230;.Emerging Responses?</title>
		<link>http://beastorbuddha.com/2010/03/08/emerging-threats-most-emerged-a-long-time-ago-emerging-responses/</link>
		<comments>http://beastorbuddha.com/2010/03/08/emerging-threats-most-emerged-a-long-time-ago-emerging-responses/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 03:10:32 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Bad Stuff]]></category>
		<category><![CDATA[Dumb Security]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[Emerging Responses]]></category>
		<category><![CDATA[Emerging Threats]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2230</guid>
		<description><![CDATA[A bit quiet lately. Sometimes I wonder if there&#8217;s more to say that I haven&#8217;t covered in the 500+ posts in Beast or Buddha. (The really interesting stuff, you can&#8217;t write about for obvious reasons). What do you do? Continue to rehash the old stuff? Sometimes!&#8230;.which brings me to an interesting discussion.
We were asked to [...]]]></description>
			<content:encoded><![CDATA[<p>A bit quiet lately. Sometimes I wonder if there&#8217;s more to say that I haven&#8217;t covered in the 500+ posts in Beast or Buddha. (The really interesting stuff, you can&#8217;t write about for <a href="http://beastorbuddha.securusglobal.com/2009/07/05/journalising-journalism-and-bloggingrestrictions-on-posting/" target="_self">obvious reasons</a>). What do you do? Continue to rehash the old stuff? Sometimes!&#8230;.which brings me to an interesting discussion.</p>
<p>We were asked to do a presentation recently on &#8220;emerging threats&#8221; at a business forum for IT Security and Risk Management professionals. Seems straightforward enough but when looking back over previous such presentations we&#8217;ve been doing over the years, nothing much was changing &#8211; in particular our recommendations on how organisations should be dealing with &#8220;emerging threats&#8221;. We could have almost just pulled out &#8220;Emerging Threats&#8221; presentation, (circa 2002) and done it word for word, (with only a few very minor wording and definition changes, eg; &#8220;Cloud&#8221;, &#8220;APT&#8221; etc <img src='http://beastorbuddha.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ).</p>
<p>Should we be calling these presentations; &#8220;Emerging Responses&#8221;? It&#8217;s the response part that is in most cases yet to &#8220;emerge&#8221; effectively! The &#8220;threats&#8221; (most of them), emerged a long time ago. In many cases, we just call them different things now because we&#8217;ve failed to deal with them properly at the time, so it&#8217;s easier to rename something &#8211; makes it all seem that little bit new, and covers up to a degree for failures in the past.</p>
<p>Am I being unfair? Keen on your thoughts.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/08/emerging-threats-most-emerged-a-long-time-ago-emerging-responses/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Recruiters&#8230;.please don&#8217;t purport to represent Securus Global</title>
		<link>http://beastorbuddha.com/2010/03/03/recruiters-please-dont-purport-to-represent-securus-global/</link>
		<comments>http://beastorbuddha.com/2010/03/03/recruiters-please-dont-purport-to-represent-securus-global/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 00:20:09 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2224</guid>
		<description><![CDATA[Dear Recruiters,
Unless we officially approach you to work with us, ie; approve you to go out and look for candidates, please don&#8217;t go out and approach people who you think we might like to fullfill roles that we advertise. This doesn&#8217;t look good upon you. We don&#8217;t support random headhunting of people.
Securus Global Team
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
Securus Global: [...]]]></description>
			<content:encoded><![CDATA[<p>Dear Recruiters,</p>
<p>Unless we officially approach you to work with us, ie; approve you to go out and look for candidates, please don&#8217;t go out and approach people who you think we might like to fullfill roles that we <a href="http://beastorbuddha.com/bhj/2010/02/16/security-consultant-penetration-tester-securus-global-new/" target="_blank">advertise</a>. This doesn&#8217;t look good upon you. We don&#8217;t support random headhunting of people.</p>
<p>Securus Global Team</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/03/recruiters-please-dont-purport-to-represent-securus-global/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>What&#8217;s your &#8220;checklist of choice&#8221; for an Enterprise State of Security review?</title>
		<link>http://beastorbuddha.com/2010/03/02/whats-your-checklist-of-choice-for-an-enterprise-state-of-security-review/</link>
		<comments>http://beastorbuddha.com/2010/03/02/whats-your-checklist-of-choice-for-an-enterprise-state-of-security-review/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 08:56:48 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[Enterprise Security]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2222</guid>
		<description><![CDATA[Just wondering how some people would and/or do approach an Enterprise State of Security assessment? Obviously given the plethora of standards, regulatory &#8220;guidelines&#8221; etc, there&#8217;s no right answers. (Including size and scope of such an exercise&#8230;assume it is possible of course!). Do you see it as something impossible? Would you use something like PCI DSS? [...]]]></description>
			<content:encoded><![CDATA[<p>Just wondering how some people would and/or do approach an Enterprise State of Security assessment? Obviously given the plethora of standards, regulatory &#8220;guidelines&#8221; etc, there&#8217;s no right answers. (Including size and scope of such an exercise&#8230;assume it is possible of course!). Do you see it as something impossible? Would you use something like PCI DSS? Do you have your own framework/methodology? Keen to hear people&#8217;s thoughts.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/03/02/whats-your-checklist-of-choice-for-an-enterprise-state-of-security-review/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Advanced Persistent Threat&#8230;APT&#8230;WTF!?</title>
		<link>http://beastorbuddha.com/2010/02/28/advanced-persistent-threat-apt-wtf/</link>
		<comments>http://beastorbuddha.com/2010/02/28/advanced-persistent-threat-apt-wtf/#comments</comments>
		<pubDate>Sat, 27 Feb 2010 14:59:21 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Bad Stuff]]></category>
		<category><![CDATA[Disclosure Laws]]></category>
		<category><![CDATA[WTF]]></category>
		<category><![CDATA[Advanced Persistent THREAT]]></category>
		<category><![CDATA[APT]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2216</guid>
		<description><![CDATA[I know it has taken me a while to catch up, but I relegated it low priority when I first heard of this &#8220;APT&#8221; business. Bad of me? Who made this stuff up? This is something you&#8217;d only make up for a laugh. But, all of the sudden, my industry is talking about it. FFS. [...]]]></description>
			<content:encoded><![CDATA[<p>I know it has taken me a while to catch up, but I relegated it low priority when I first heard of this &#8220;APT&#8221; business. Bad of me? Who made this stuff up? This is something you&#8217;d only make up for a laugh. But, all of the sudden, my industry is talking about it. FFS. Is this an American thing?</p>
<p> <img src='http://beastorbuddha.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  &#8230;.if I had to mention that to a client. &#8220;Stand back&#8230;..you have an APT!!!&#8221;&#8230;&#8230; &#8220;Thanks Draz&#8230;awesome we hired you to save us!&#8221;</p>
<p>I have nothing! If this makes Wikipedia, (which it may have by now (Ed: yeah, I know it&#8217;s there), I&#8217;d love to chat (Ed: modified to not scare people), with that genius  who invented the term, (for our industry).</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/02/28/advanced-persistent-threat-apt-wtf/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>(Off Topic) Web 2.0 Case Study: How it can work &#8211; Jerrys Plains and Coal Mining.</title>
		<link>http://beastorbuddha.com/2010/02/25/off-topic-web-2-0-case-study-how-it-can-work-jerrys-plains-and-coal-mining/</link>
		<comments>http://beastorbuddha.com/2010/02/25/off-topic-web-2-0-case-study-how-it-can-work-jerrys-plains-and-coal-mining/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 11:46:46 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2208</guid>
		<description><![CDATA[In my day to day, I read blog after blog and most of the ones that I have bookmarked are all I need to keep up with the latest in IT Security news. I rarely now ever read an IT news site unless it&#8217;s linked from a blog I read (or to be fair&#8230;..Twitter). This [...]]]></description>
			<content:encoded><![CDATA[<p>In my day to day, I read blog after blog and most of the ones that I have bookmarked are all I need to keep up with the latest in IT Security news. I rarely now ever read an IT news site unless it&#8217;s linked from a blog I read (or to be fair&#8230;..Twitter). This Web 2.0 business has substance. I hate the term but love the delivery. (FFS most IT news sites are not worth it anymore (not that many were before), when the bloggers and twitters provide the news quicker!). Anyway, back to the off topic:</p>
<p>The <a href="http://www.jerrysplains.blogspot.com/" target="_blank">Protect Jerrys Plains</a> blog is one of the best examples of Web 2.0 in action I have come across. Yes, it is run by a friend, Big Galoot, Craig Chapman, and yes, probably the <strong>only</strong> reason I know about it. But, it&#8217;s a gem!</p>
<p>I highly recommend the read. There&#8217;s not many entries but if you want to see Australia&#8217;s version of Erin Brockovich in action, this is it. It is a soap opera of big business and NSW government games at their best. Read how some make millions from nothing and how a community is spun on the concept of &#8220;supporting&#8221; individuals and big business making squillions. It reads like a daytime drama, but it is what a community and NSW taxpayers are copping while at the same time being convinced they&#8217;re getting something! It&#8217;s still going on&#8230;..keep reading&#8230;.logic tells you that someone will someday soon get into trouble!</p>
<p>Web 2.0 &#8211; If the Jerrys Plains community did not have this, you have to wonder where they may be?! It still may end bad but at least there will be a record of how it got there and one day, someone may decide to make the players accountable. Go Big Galoot!</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/02/25/off-topic-web-2-0-case-study-how-it-can-work-jerrys-plains-and-coal-mining/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Symantec Customers Immune to Rising Security Threats! (Late Update: Maybe Not!)</title>
		<link>http://beastorbuddha.com/2010/02/23/symantec-customers-immune-to-rising-security-threats-late-update-maybe-not/</link>
		<comments>http://beastorbuddha.com/2010/02/23/symantec-customers-immune-to-rising-security-threats-late-update-maybe-not/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 23:10:26 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Bad Stuff]]></category>
		<category><![CDATA[Dumb Security]]></category>
		<category><![CDATA[Too cool]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[WTF]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Symantec 2010 State of Enterprise Security]]></category>
		<category><![CDATA[Symantec Bullshit Marketing]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2201</guid>
		<description><![CDATA[Symantec Press Release 22 February, 2010: Symantec 2010 State of Enterprise Security Study&#8230;&#8230;
(Time to pump out another piece of marketing to get people thinking about buying Symantec. Here&#8217;s the report if you are interested in wasting a few minutes).
Just reading this now&#8230;&#8230;.wooo&#8230;..hang on&#8230;&#8230;what I don&#8217;t see anywhere in this report is a proud statement that [...]]]></description>
			<content:encoded><![CDATA[<p>Symantec Press Release 22 February, 2010: <a href="http://www.symantec.com/about/news/release/article.jsp?prid=20100221_01" target="_blank">Symantec 2010 State of Enterprise Security Study&#8230;&#8230;</a></p>
<p>(Time to pump out another piece of marketing to get people thinking about buying Symantec. Here&#8217;s the <a href="http://www.symantec.com/about/news/resources/press_kits/detail.jsp?pkid=sesreport2010&amp;om_ext_cid=biz_socmed_twitter_2010Feb_ESRreport" target="_blank">report</a> if you are interested in wasting a few minutes).</p>
<p>Just reading this now&#8230;&#8230;.wooo&#8230;..hang on&#8230;&#8230;what I don&#8217;t see anywhere in this report is a proud statement that Symantec customers are the lucky few that are safe from malicious attacks that other businesses are facing.</p>
<p>Why is this not in there Symantec? Surely you should be beating your own drums given you so proudly told us all some time ago that your product(s), and I quote; will provide “…proactive protection against unknown and zero-day threats”. It&#8217;s the <a href="http://beastorbuddha.com/2008/02/27/symantec-will-save-us-allproactive-protection-against-unknown-and-zero-day-threats/" target="_self">Symantec Guarantee</a>!</p>
<p>As such, surely Symantec customers do not have the same concerns as those poor businesses you mention in your study. Let us know if this was just an error on your part, or Symantec just not wanting to show off here because, surely you would not use bullshit marketing in the past?! <img src='http://beastorbuddha.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/02/23/symantec-customers-immune-to-rising-security-threats-late-update-maybe-not/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Door to Door Spam Chaser Style</title>
		<link>http://beastorbuddha.com/2010/02/21/door-to-door-spam-chaser-style/</link>
		<comments>http://beastorbuddha.com/2010/02/21/door-to-door-spam-chaser-style/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 08:35:56 +0000</pubDate>
		<dc:creator>Drazen Drazic</dc:creator>
				<category><![CDATA[Too cool]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[Door to door spam]]></category>
		<category><![CDATA[Spam Email]]></category>

		<guid isPermaLink="false">http://beastorbuddha.com/?p=2198</guid>
		<description><![CDATA[Classic Chaser work:

&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-
Securus Global: IT Security, Penetration Testing, Security Assessments, PCI Compliance, Product Assurance, QualysGuard, Security Strategy, Vulnerability Assessment.
]]></description>
			<content:encoded><![CDATA[<p>Classic Chaser work:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="380" height="260" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/Cj5wBOhn3Q0&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="380" height="260" src="http://www.youtube.com/v/Cj5wBOhn3Q0&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Securus Global: <a href="http://www.securusglobal.com/" target="_blank">IT Security</a>, <a href="http://www.securusglobal.com/services/pentesting.html" target="_blank">Penetration Testing</a>, <a href="http://www.securusglobal.com/services/securityassessments.html" target="_blank">Security Assessments</a>, <a href="http://www.securusglobal.com/services/pcicompliance.html" target="_blank">PCI Compliance</a>, <a href="http://www.securusglobal.com/services/producttesting.html" target="_blank">Product Assurance</a>, <a href="http://www.securusglobal.com/products/qualys.html" target="_blank">QualysGuard</a>, <a href="http://www.securusglobal.com/services/managementconsulting.html" target="_blank">Security Strategy</a>, <a href="http://www.securusglobal.com/services/managedva.html" target="_blank">Vulnerability Assessment</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://beastorbuddha.com/2010/02/21/door-to-door-spam-chaser-style/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
