<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.5" -->
<rss version="0.92">
<channel>
	<title>Digital Bond</title>
	<link>http://www.digitalbond.com</link>
	<description>This Month in Control System Security</description>
	<lastBuildDate>Wed, 07 May 2008 17:58:08 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Just surfing the web</title>
		<description>Typing scada as the search key in a Google news search http://news.google.com reveals that as a whole the industry (vendors, asset owners, and security players) still needs to raise the bar on security awareness and must change its mindset in a couple of key areas.

While I don't want to become ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/07/just-surfing-the-web/</link>
			</item>
	<item>
		<title>IT and Operations Unite!</title>
		<description>No, this is not what you think it is. In fact, it is almost the opposite.

Control system applications and components are increasingly being used to monitor critical IT Data Centers. We heard quite a bit about this at the PI Developers Conference, especially related to monitoring the power, environmental and ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/07/it-and-operations-unite/</link>
			</item>
	<item>
		<title>Wonderware SuiteLink Denial of Service Vulnerability (part 2)</title>
		<description>I couldn’t let the Wonderware Suitelink vulnerability go by without commenting on it, and even Jason commenting on it below won’t steal my thunder.

First, lets talk about the vulnerability from a technical perspective.  It appears that this is a fairly classic example of the program allocating an amount of ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/06/wonderware-suitelink-denial-of-service-vulnerability-part-2/</link>
			</item>
	<item>
		<title>Wonderware SuiteLink Denial of Service Vulnerability</title>
		<description>Sebastian Muniz from Core Security Technologies discovered a denial  of service vulnerability in the Wonderware SuiteLink service that was made public today. Here are some links:

Core Security Advisory

National Vulnerability Database

Wonderware Tech Alert (login required)

This SuiteLink vulnerability affects the same version of Wonderware InTouch that had the NetDDE problem. When ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/06/wonderware-suitelink-denial-of-service-vulnerability/</link>
			</item>
	<item>
		<title>Major DNSSEC Deployments on the Horizon?</title>
		<description>It looks like the DNS service for a few top level domains will be more secure in the future.  Announcements, by way of Dark Reading, have been made that the .org, .uk, and .arpa will soon be turning on DNSSEC and joining .swe (Sweden), .br (Brazil), and .bg (Bulgaria ).  ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/05/major-dnssec-deployments-on-the-horizon/</link>
			</item>
	<item>
		<title>Control Systems Security Standards Efforts ROI</title>
		<description>I've been involved to varying degrees with security standards efforts for way too long now - - almost twenty years. Most recently with the ISA 99 Part 4 effort. For a while I was actively involved in that effort in support of a contract with Wurldtech. When Bryan Singer joined ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/05/control-systems-security-standards-efforts-roi/</link>
			</item>
	<item>
		<title>HITBSecConf2008-Dubai &#8220;Penetration Testing SCADA&#8221; Presentation</title>
		<description>I mentioned this back in March -- Another hacker conference SCADA presentation. The presentation is now available for download. A quick review doesn't show anything too groundbreaking but it was interesting to learn about an Italian project called CrISTAL (Critical Infrastructures Security Testing and Analysis Lab). From the website:
CrISTAL aims ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/04/hitbsecconf2008-dubai-penetration-testing-scada-presentation/</link>
			</item>
	<item>
		<title>Spot the Overflow</title>
		<description>To give our readers a taste of what Daniel and I do most days I thought I would post a little code snippet and ask you all to find the overflow (if there is one). Any discussion on the feasibility of exploiting the overflow (again if there is one) is ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/02/spot-the-overflow/</link>
			</item>
	<item>
		<title>Friday News and Notes</title>
		<description>	
Great blog entry from the guys at Matasano on hacking a 'toaster' running a VxWorks OS.
	The PCSF Annual Meeting will be held on August 26 - 28 in San Diego. The call for papers/solutions is out, and an agenda and registration is forthcoming. This is our top recommendation if you ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/02/friday-news-and-notes-44/</link>
			</item>
	<item>
		<title>Thoughts on the &#8220;7 Dirty Secrets of the Security Industry&#8221;</title>
		<description>Joshua Corman of IBM/ISS gave a presentation at Interop Las Vegas yesterday titled “Unsafe at any speed: 7 Dirty Secrets of the Security Industry”. Here’s the Network World report. The title alone is interesting – making a reference to automobile safety – especially considering some recent discussion about the relationship ...</description>
		<link>http://www.digitalbond.com/index.php/2008/05/01/thoughts-on-the-7-dirty-secrets-of-the-security-industry/</link>
			</item>
</channel>
</rss>
