<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" > <channel><title>Comments on: More Cyber War Gouge</title> <atom:link href="http://defensetech.org/2008/01/19/more-cyber-war-gouge/feed/" rel="self" type="application/rss+xml" /><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/</link> <description>The Future of the Military, Law Enforcement and National Security</description> <lastBuildDate>Fri, 10 Feb 2012 05:05:24 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: steve</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173597</link> <dc:creator>steve</dc:creator> <pubDate>Mon, 21 Jan 2008 22:09:05 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173597</guid> <description>See the difference, stealing data, attacking databases, Chinese, shutting down networks, extortion, criminals, typically Eastern European. No need for diagrams, a lazy IT worker hooks up to the internet for an update, classic. No, no, don&#039;t download the update, check for viriii, burn to CD and deploy, just take down all security, it&#039;s easier. </description> <content:encoded><![CDATA[<p>See the difference, stealing data, attacking databases, Chinese, shutting down networks, extortion, criminals, typically Eastern European. No need for diagrams, a lazy IT worker hooks up to the internet for an update, classic. No, no, don’t download the update, check for viriii, burn to CD and deploy, just take down all security, it’s easier.</p> ]]></content:encoded> </item> <item><title>By: Kevin</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-68236</link> <dc:creator>Kevin</dc:creator> <pubDate>Sun, 20 Jan 2008 23:52:00 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-68236</guid> <description>I wish I could draw you a diagram of the incident I uncovered at one company it would be easier to explain how the grid control systems got cross connected to computers with internet connections.  But since I don&#039;t let me give you the text versions. 1.  A vendor software packages needed on the control system for the company had a maintenance application that used the internet. 2. On individual whose PC was on the internal control network put a wireless hub on his PC so he could connect to the internet. 3. A back-up server for load balancing that could be assigned to support both internal control networks and non-control networks thus providing a bridge between the two. Those are the three that I have seen.  I bet the other readers can come up with other possibilities. </description> <content:encoded><![CDATA[<p>I wish I could draw you a diagram of the incident I uncovered at one company it would be easier to explain how the grid control systems got cross connected to computers with internet connections.  But since I don’t let me give you the text versions.<br /> 1.  A vendor software packages needed on the control system for the company had a maintenance application that used the internet.<br /> 2. On individual whose PC was on the internal control network put a wireless hub on his PC so he could connect to the internet.<br /> 3. A back-up server for load balancing that could be assigned to support both internal control networks and non-control networks thus providing a bridge between the two.<br /> Those are the three that I have seen.  I bet the other readers can come up with other possibilities.</p> ]]></content:encoded> </item> <item><title>By: Chris</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173595</link> <dc:creator>Chris</dc:creator> <pubDate>Sun, 20 Jan 2008 23:43:18 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173595</guid> <description>Those of us in the pen test business have been telling customers for years that they need to improve internal security and audit capabilities. They never do...until something happens. On a side note.  Kevin is right on in his assessment of the professional state of the IT and engineering careers in the US.  Far too many corporations look to other countries for cheap (notice I didn&#039;t say inexpensive).  I once listened to Sam Palmisano (CEO of IBM) tell over a hundred engineers at one of its US development centers that they executives were NOT looking to the US for future talent. We&#039;re fighting a losing battle.  As one of the most technologically advanced countries in the world, we&#039;re dependent on an infrastructure we can&#039;t even defend. </description> <content:encoded><![CDATA[<p>Those of us in the pen test business have been telling customers for years that they need to improve internal security and audit capabilities.<br /> They never do…until something happens.<br /> On a side note.  Kevin is right on in his assessment of the professional state of the IT and engineering careers in the US.  Far too many corporations look to other countries for cheap (notice I didn’t say inexpensive).  I once listened to Sam Palmisano (CEO of IBM) tell over a hundred engineers at one of its US development centers that they executives were NOT looking to the US for future talent.<br /> We’re fighting a losing battle.  As one of the most technologically advanced countries in the world, we’re dependent on an infrastructure we can’t even defend.</p> ]]></content:encoded> </item> <item><title>By: Arthur</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173594</link> <dc:creator>Arthur</dc:creator> <pubDate>Sun, 20 Jan 2008 23:41:07 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173594</guid> <description>Kevin, can you please explain to me how it&#039;s even possible to attack a utility&#039;s network? I mean, why in the world would the utilities have their networks exposed to the Internet? If they do, then they must have complete retards working there. I know for a fact that all the nuclear power stations here in Ontario have absolutely no access to the Internet. If they aren&#039;t connected to the Internet, then there shouldn&#039;t be any way to hack in. Also, the tremendous drop in Computer Science and IT enrollment has to do with the dot com crash. Now applicants are only people who are interested in the field, not random people off the street who think they can get rich quick if they go into the tech field. </description> <content:encoded><![CDATA[<p>Kevin, can you please explain to me how it’s even possible to attack a utility’s network? I mean, why in the world would the utilities have their networks exposed to the Internet? If they do, then they must have complete retards working there. I know for a fact that all the nuclear power stations here in Ontario have absolutely no access to the Internet. If they aren’t connected to the Internet, then there shouldn’t be any way to hack in.<br /> Also, the tremendous drop in Computer Science and IT enrollment has to do with the dot com crash. Now applicants are only people who are interested in the field, not random people off the street who think they can get rich quick if they go into the tech field.</p> ]]></content:encoded> </item> <item><title>By: steve</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173593</link> <dc:creator>steve</dc:creator> <pubDate>Sun, 20 Jan 2008 20:16:47 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173593</guid> <description>China? Hah, hardly the MO. If there was extortion demands after the cyber attack I would bet the farm that it was Russian or other Eastern European criminals. You can&#039;t assume every attack is politically based, you should never forget the basic human condition of simple greed. As a side note, if you have your grid set up so someone can get inside the controls from the internet, you have failed as a IT professional. </description> <content:encoded><![CDATA[<p>China? Hah, hardly the MO. If there was extortion demands after the cyber attack I would bet the farm that it was Russian or other Eastern European criminals. You can’t assume every attack is politically based, you should never forget the basic human condition of simple greed. As a side note, if you have your grid set up so someone can get inside the controls from the internet, you have failed as a IT professional.</p> ]]></content:encoded> </item> <item><title>By: Kevin</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173592</link> <dc:creator>Kevin</dc:creator> <pubDate>Sun, 20 Jan 2008 15:38:59 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173592</guid> <description>Given the three cities/regions were outside the US, they were in a monitoring and support role to our International friends.  At this point no one can say if China played a role and if their supporters provided insider information.  Investigating these types of attacks is a long drawn out effort and very complex.  Few people are highly skilled at computer forensics.  In a cyber war, smarts is the raw material of weapons.  That being said the US has seen double digit decreases in students deciding to get computer and information science degrees in the lase several years.  We are in a dangerous situation that even if we act right now will take years to change! </description> <content:encoded><![CDATA[<p>Given the three cities/regions were outside the US, they were in a monitoring and support role to our International friends.  At this point no one can say if China played a role and if their supporters provided insider information.  Investigating these types of attacks is a long drawn out effort and very complex.  Few people are highly skilled at computer forensics.  In a cyber war, smarts is the raw material of weapons.  That being said the US has seen double digit decreases in students deciding to get computer and information science degrees in the lase several years.  We are in a dangerous situation that even if we act right now will take years to change!</p> ]]></content:encoded> </item> <item><title>By: pedestrian</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-68231</link> <dc:creator>pedestrian</dc:creator> <pubDate>Sun, 20 Jan 2008 05:02:20 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-68231</guid> <description>Why was CIA on its move? Was China involved? Were Chinese Americans providing support to the Chicoms to test internal assisted cyber attacks? </description> <content:encoded><![CDATA[<p>Why was CIA on its move? Was China involved? Were Chinese Americans providing support to the Chicoms to test internal assisted cyber attacks?</p> ]]></content:encoded> </item> <item><title>By: SPyGuy</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-68229</link> <dc:creator>SPyGuy</dc:creator> <pubDate>Sun, 20 Jan 2008 01:08:55 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-68229</guid> <description>What is the old saying Art imitates reality or is that now reality imitates art? </description> <content:encoded><![CDATA[<p>What is the old saying Art imitates reality or is that now reality imitates art?</p> ]]></content:encoded> </item> <item><title>By: Patron Vectras</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-173591</link> <dc:creator>Patron Vectras</dc:creator> <pubDate>Sun, 20 Jan 2008 01:00:52 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-173591</guid> <description>Glad someone beat me to saying that. If I was the owner, I would be extremely mad to learn that it was done from the inside. </description> <content:encoded><![CDATA[<p>Glad someone beat me to saying that.<br /> If I was the owner, I would be extremely mad to learn that it was done from the inside.</p> ]]></content:encoded> </item> <item><title>By: RJB1012</title><link>http://defensetech.org/2008/01/19/more-cyber-war-gouge/#comment-68227</link> <dc:creator>RJB1012</dc:creator> <pubDate>Sat, 19 Jan 2008 22:38:23 +0000</pubDate> <guid isPermaLink="false">http://deftech.usmilblog.com/?p=3800#comment-68227</guid> <description>Sounds just like the latest Die Hard movie </description> <content:encoded><![CDATA[<p>Sounds just like the latest Die Hard movie</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc
Page Caching using apc (User agent is rejected)
Database Caching 1/7 queries in 0.004 seconds using apc
Object Caching 743/747 objects using apc
Content Delivery Network via images.defensetech.org

Served from: defensetech.org @ 2012-02-10 00:19:17 -->
