<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DMANd Security &#187; PCI</title>
	<atom:link href="http://dmandsecurity.com/blog/category/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://dmandsecurity.com/blog</link>
	<description>Security Tips and Tools for Small &#38; Home Business</description>
	<lastBuildDate>Mon, 14 Jun 2010 19:37:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Best Weekend Reading From Around The Web</title>
		<link>http://dmandsecurity.com/blog/2009/03/weekend-reading-0327/</link>
		<comments>http://dmandsecurity.com/blog/2009/03/weekend-reading-0327/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 20:00:36 +0000</pubDate>
		<dc:creator>Joe Lofshult</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[browser vulnerabilities]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[weekend]]></category>

		<guid isPermaLink="false">http://dmandsecurity.com/blog/?p=346</guid>
		<description><![CDATA[
			
				
			
		
<p>The developers of the Firefox browser are rushing to develop a fix for a critical vulnerability just discovered that could let an attacker execute code on your system if you visit sites with the exploit on them. The vulnerability affects Firefox versions on Windows, Mac, and Linux.  NoScript, a plugin every Firefox user should have, can <span style="color:#777"> . . . &#8594; Read More: <a href="http://dmandsecurity.com/blog/2009/03/weekend-reading-0327/">Best Weekend Reading From Around The Web</a></span>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fweekend-reading-0327%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fweekend-reading-0327%2F&amp;style=normal&amp;service=TinyURL.com" height="61" width="50" /><br />
			</a>
		</div>
<p>The developers of the <a title="Firefox Browser" href="http://www.mozilla.com/en-US/firefox/personal.html?from=getfirefox" target="_blank">Firefox </a>browser are rushing to develop a fix for a <a title="Firefox exploit sends Mozilla developers into fire drill" href="http://www.theregister.co.uk/2009/03/26/new_firefox_exploit/" target="_blank">critical vulnerability</a> just discovered that could let an attacker execute code on your system if you visit sites with the exploit on them. The vulnerability affects Firefox versions on Windows, Mac, and Linux.  <a title="Noscript Plugin" href="http://noscript.net/" target="_blank">NoScript</a>, a <a title="Firefox Security Plugins" href="http://dmandsecurity.com/blog/2009/03/firefox-security-addons-0303/" target="_blank">plugin every Firefox user should have</a>, can protect against this vulnerability. A patch for the vulnerability should be ready in the new release scheduled for April 1.</p>
<p>Scary! Your personal information is even easier to get now, <a title="Web Fraud 2.0" href="http://voices.washingtonpost.com/securityfix/2009/03/web_fraud_20_data_search_tools.html?wprss=securityfix" target="_blank">Brian Krebs reports</a>.</p>
<blockquote><p>Data such as your Social Security number, mother&#8217;s maiden name and credit card balance are not as difficult for ID thieves to find as most people think. Security Fix spent the past week testing services offered by two Web sites that sell access to a wealth of information on consumers. For a payment of $3 each, I was able to find full Social Security numbers on four of the volunteers, as well as their most recent street addresses and birthdays.   Another set of three $3 payments allowed me to gather the mother&#8217;s maiden name (MMN) on half of the volunteers.</p></blockquote>
<p>With April 1st quickly approaching, there has been quite a bit of media coverage of the Conficker worm that is scheduled to do something on that date. According to <a title="Conficker Questions and Answers" href="http://www.f-secure.com/weblog/archives/00001636.html" target="_blank">F-Secure</a> you shouldn&#8217;t worry, too much, though.</p>
<blockquote><p><strong>Q:</strong> I heard something <strong>really bad</strong> is going to happen on the Internet on April 1st! Will it?<br />
<strong>A:</strong> No, not really.</p>
<p><strong>Q:</strong> Seriously, the <strong>Conficker worm</strong> is going to do something bad on April 1st, right?<br />
<strong>A:</strong> The Conficker aka <strong>Downadup</strong> worm is going to change it&#8217;s operation a bit, but that&#8217;s <strong>unlikely to cause anything visible on April 1st</strong>.</p>
<p><strong>Q:</strong> I just checked, and my Windows machine is clean. Is something going to happen to me on April 1st?<br />
<strong>A:</strong> No.</p>
<p><strong>Q:</strong> Now I&#8217;m worried. How do I know if I&#8217;m infected?<br />
<strong>A:</strong> Try to surf to www.f-secure.com. If you can&#8217;t reach our website you might be infected, as Downadup/Conficker blocks access to security vendor&#8217;s websites. Don&#8217;t tell anybody, but users who can&#8217;t access f-secure.com because of this can surf to www.fsecure.com instead.</p></blockquote>
<p>CNet News has  is another good <a title="Conficker Worm" href="http://news.cnet.com/8301-1009_3-10204590-83.html?tag=mncol;title" target="_blank">writeup on the Conficker worm</a>.</p>
<blockquote><p>There&#8217;s been lots of hype about the fact that the latest variant of the Conficker worm is set to start communicating with other computers on the Internet on April 1&#8211;like an April Fool&#8217;s Day time bomb with some mysterious payload. But security researchers say the reality is probably going to be more like what happened when the clocks on the world&#8217;s computers turned to January 1, 2000, after lots of dire predictions about the so-called <a title="Year 2000 arrives without disaster -- Saturday, Jan 1, 2000" href="http://news.cnet.com/Year-2000-arrives-without-disaster/2009-1091_3-235093.html">millennium bug</a>. That is, not much at all.</p></blockquote>
<p>If you accept or process credit cards, the Society of Payment Security Professionals has released a <a title="PCI DSS Wireless FAQ" href="https://www.paymentsecuritypros.com/labs/" target="_blank">Wireless FAQ</a> addressing some of PCI compliance and wireless networks. This FAQ is applicable even if you don&#8217;t use wireless networks, since you still have to scan for roque wireless access points on your network.</p>
<p><a title="Scareware" href="http://en.wikipedia.org/wiki/Scareware" target="_blank">Scareware</a>, malicious software that would pop up alarming messages scaring users into buying useless software, is now <a title="Scareware Morphs into Ransomware" href="http://www.darkreading.com/security/attacks/showArticle.jhtml;jsessionid=BCIGTI4UXUKWAQSNDLPSKH0CJUNN2JVN?articleID=216300413" target="_blank">changing into ransomware</a>. This new malware will encrypt files on your computer and will decrypt them for a &#8220;fee.&#8221;</p>
<blockquote><p><span class="smalltext">FireEye describes Vundo as a &#8220;generic Trojan&#8221; that sends a popup to Web users. In this case, however, Vundo is &#8220;pushing a piece of malware that encrypts various personal file types (.pdf, .doc, .jpg, etc.) on your system, and &#8216;coincidentally&#8217; pushes a program called FileFix Pro 2009, which would decrypt them &#8212; for a fee.&#8221; </span></p></blockquote>
<p>Defense against this type of malware is much the same as for any other. Keep your anti-virus software and operating system patches up-to-date, don&#8217;t surf suspicious web sites, and use <a title="Browser Security Plugins" href="http://dmandsecurity.com/blog/2009/03/firefox-security-addons-0303/" target="_blank">security plugins</a> in your browser to make your browsing experience safer.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fweekend-reading-0327%2F&amp;linkname=Best%20Weekend%20Reading%20From%20Around%20The%20Web"><img src="http://dmandsecurity.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dmandsecurity.com/blog/2009/03/weekend-reading-0327/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Weekend Reading</title>
		<link>http://dmandsecurity.com/blog/2009/03/best-weekend-reading-0306/</link>
		<comments>http://dmandsecurity.com/blog/2009/03/best-weekend-reading-0306/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 20:53:02 +0000</pubDate>
		<dc:creator>Joe Lofshult</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[weekend]]></category>

		<guid isPermaLink="false">http://dmandsecurity.com/blog/?p=260</guid>
		<description><![CDATA[
			
				
			
		
<p>Online criminals are posting ads for their services on YouTube. How interesting.</p>
<p>Bruce Schneier on the good and bad uses of incentives to improve security.</p>
<p>Twitter fixed a security hole this week that allowed people to post fake posts on other users&#8217; sites.</p>
<p>Study finds anti-virus software misses up to 15% of malware and nearly 5% of systems in <span style="color:#777"> . . . &#8594; Read More: <a href="http://dmandsecurity.com/blog/2009/03/best-weekend-reading-0306/">Best Weekend Reading</a></span>


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fbest-weekend-reading-0306%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fbest-weekend-reading-0306%2F&amp;style=normal&amp;service=TinyURL.com" height="61" width="50" /><br />
			</a>
		</div>
<p>Online criminals are <a title="Online Criminals Post Ads on Youtube" href="http://www.f-secure.com/weblog/archives/00001619.html" target="_blank">posting ads</a> for their services on YouTube. How interesting.</p>
<p>Bruce Schneier on the good and bad uses of <a title="Perverse Security Incentives" href="http://www.schneier.com/blog/archives/2009/03/perverse_securi.html" target="_blank">incentives to improve security</a>.</p>
<p><a title="Twitter Fixes Security Hole" href="http://voices.washingtonpost.com/securityfix/2009/03/twitter_security_h.html?wprss=securityfix" target="_blank">Twitter fixed a security hole</a> this week that allowed people to post fake posts on other users&#8217; sites.</p>
<p>Study finds <a title="Antivirus Software Misses Up to 15% of Malware" href="http://www.darkreading.com/security/antivirus/showArticle.jhtml;jsessionid=RYEASFPMQIBTOQSNDLPSKH0CJUNN2JVN?articleID=215600282" target="_blank">anti-virus software misses up to 15% of malware</a> and nearly 5% of systems in enterprises are infected with botnet software.</p>
<p>I wrote about <a title="Six Firefox Security Add-Ons" href="http://dmandsecurity.com/blog/2009/03/firefox-security-addons-0303/" target="_blank">six Firefox security add-ons</a> you should take a look at.</p>
<p>The PCI Security Standards Council released a new document, a<a title="Prioritized Approach to DSS 1.2" href="https://www.pcisecuritystandards.org/education/prioritized.shtml" target="_blank"> Prioritized Approach to DSS 1.2</a>, and the Treasury Institute had a good writeup on <a title="PCI DSS News: Prioritized Approach to DSS 1.2" href="http://treasuryinstitute.org/blog/index.php?itemid=236" target="_blank">what it actually means to businesses</a>.</p>
<p>Microsoft is planning on releasing <a title="Microsoft Plans Three Security Bulletins for Patch Tuesday" href="http://www.eweek.com/c/a/Security/Microsoft-Plans-Three-Security-Bulletins-for-Patch-Tuesday/" target="_blank">3 security bulletins for Patch Tuesday</a> next week. One of the patches resolves a critical issue, but there is no word yet on when a patch will be released for the <a title="Critical Microsoft Excel Vulnerability" href="http://www.microsoft.com/technet/security/advisory/968272.mspx" target="_blank">critical Excel flaw</a> announced in February.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fdmandsecurity.com%2Fblog%2F2009%2F03%2Fbest-weekend-reading-0306%2F&amp;linkname=Best%20Weekend%20Reading"><img src="http://dmandsecurity.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dmandsecurity.com/blog/2009/03/best-weekend-reading-0306/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
