<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/index.html" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.html" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.html" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.html" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.html" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.html" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.html" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.html">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.html">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.html">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">October, 2004 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>The Apache software foundation recently <a href="http://apache.org/foundation/docs/sender-id-position.html">declined to
		implement Sender ID</a> because it requires a Microsoft license incompatible with
		open source licenses.  A recent study showed that <a href="http://www.infoworld.com/article/04/08/31/HNspammerstudy_1.html">spammers use
		anti-spam sender authentication</a> even more than the rest of us.</text></p></li><li>
			<p><text>@stake is <a href="http://www.atstake.com/research/advisories/2004/a091304-1.txt">reporting</a>
		that they can easily read data from &quot;protected&quot; areas of the Lexar JumpDrive
		USB drive.  The encryption password can be read directly from the device.  Not
		to pick on Lexar, but this is an example of how hard it is for companies to
		create proprietary security schemes that can actually keep out an experienced
		hacker.</text></p></li><li>
			<p><text>Even USA Today is <a href="http://www.usatoday.com/tech/news/computersecurity/2004-09-08-zombieuser_x.htm">picking
		up</a> on the prevalence of &quot;zombie&quot; computers among home users.
		Cyber-criminals methodically search the Internet for vulnerable machines,
		surreptitiously take them over, and then re-sell usage of these machines to
		illegal spammers, porn distributors, and other criminals.  Use of a computer
		can be <a href="http://www.usatoday.com/tech/news/computersecurity/2004-09-08-zombieprice_x.htm">purchased
		for as little as $0.10</a>.  If you're a home user, use a firewall, anti-virus,
		and keep your system up-to-date!</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>This month, serious vulnerabilities were found in <a href="http://www.us-cert.gov/cas/techalerts/TA04-245A.html">Kerberos</a>.  Make sure
		to get your software up-to-date!</text></p></li><li>
			<p><text>Cryptologists have found &quot;collisions&quot; in the <a href="http://www.rtfm.com/movabletype/archives/2004_08.html#001059">sha-0 and
		popular md5 hash functions</a>.  A collision indicates that two separate documents
		(e.g. an original signed contract and a altered forged contract) can have the same
		hash fingerprint.  Though these aren't yet exploitable vulnerabilities in any
		current systems (md5 or sha-1), they do indicate that vulnerabilities will be found,
		and cryptographers need to organize around a next generation hash function.</text></p></li></ul><h3 xmlns=""><hint>Hints</hint></h3>
		<ul xmlns="">
		<li>
			<p><text>One of our clients was recently having problems with spam being sent to their
		public email addresses.  Spammers use special email address harvesters that
		automatically scan the web for addresses they can add to their databases for sending
		out spam.  It is possible to specially encode email links on your website so that
		they are not readable by most spammer's address harvesters, and therefore won't get
		as much spam.  I recommend using a <a href="http://www.uea.ac.uk/~l003/linkencoder.html">&quot;character entity&quot;
		translator</a>.  The mailto links on your website will still work for visitors, but
		will be skipped by most address harvesters.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/index.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.html" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>