<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/Home.xhtml" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.xhtml" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.xhtml" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.xhtml" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.xhtml" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.xhtml" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.xhtml" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.xhtml">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.xhtml">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.xhtml">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">August, 2005 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>Microsoft has introduced &quot;Windows Genuine
	Advantage&quot; -- a feature of Windows Update that checks for pirated
	versions of Windows before allowing online updates.  This feature has
	apparently been <a href="http://www.boingboing.net/2005/07/28/microsoft_genuine_ad.html">cracked within 24 hours</a> of release, and can be quickly disabled by
	changing a &quot;WGA&quot; flag to &quot;false&quot; in your browser's javascript.  This is
	a good example of why applications need professional security testing
	before release.</text></p></li><li>
			<p><text>The New York Times reports on <a href="http://nytimes.com/2005/07/26/business/26card.html">rampant
	theft of credit card data</a> from Miami retailers via unsecured
	wireless access points.  Companies should audit themselves for
	unauthorized or improperly secured wireless networks.</text></p></li><li>
			<p><text>The going rate for stolen identities is about 4
	British Pounds Sterling each.  According to the Sun, a reporter was
	able to <a href="http://www.theregister.co.uk/2005/06/23/indian_call_centre_fraud_probe/">purchase identities from an Indian call center</a>, including credit
	card numbers and banking account passwords.  All companies should work
	carefully with their partners to ensure security and privacy of
	customer data.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>A former ISS security research has delivered a
	<a href="http://www.wired.com/news/privacy/0,1848,68328,00.html">presentation at the Black Hat conference</a> in which he demonstrated
	a vulnerability that allows attackers to gain complete control of Cisco
	routers.  The researcher claims the disclosure is to protect national
	critical infrastructure.  He is now being sued by Cisco and his former
	employer.  The latest firmware update from Cisco should fix this
	flaw.</text></p></li><li>
			<p><text>The US CERT center has released <a href="http://www.cert.org">several security alerts</a> about
	vulnerabilities in Oracle, Windows, and Internet Explorer.  They also
	warn about increasing risks from targetted Trojan email attacks (also
	reported on <a href="http://securityfocus.com/news/11222">Security
	Focus</a>, where an attacker creates a custom piece of code to comprise
	a specific corporation.  Additional user eductation is recommended,
	since automatic anti-virus systems have limited effectiveness against
	custom attacks.</text></p></li></ul><h3 xmlns=""><news>News</news></h3>
		<ul xmlns="">
		<li>
			<p><text>We have recently posted some <a href="/slides/">presentations by Montebello Partners' Ames Cornish</a> on Payment Card
	Industry data security standards and anti-Spam
	techniques.</text></p></li></ul><h3 xmlns=""><event>Upcoming Events</event></h3>
		<ul xmlns="">
		<li>
			<p><text>The next <a href="http://www.sfbay-infragard.org/">Infragard chapter meeting</a>,
	on August 18th at Google headquarters in Mountain View, will cover
	physical security, including bay area bridges, BART, and California
	state terrorism assessments.</text></p></li><li>
			<p><text>The next <a href="http://www.sdforum.org/sigs/security">Internet Security SIG</a>,
	Thursday, August 25th, in Palo Alto, will cover Gerhard Eschelbeck's
	&quot;Laws of Vulnerabilities&quot;.  Gerhard is the CTO of Qualys, a leading
	vulnerability management vendor.  </text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/Home.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>
