<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml" xmlns:xsp="xsp:core" xmlns:http="http://xmind.biz/namespace/http" xmlns:error="http://xmind.biz/namespace/error" xmlns:GEN="xsp:gen">

	<head>
	<title>Internet Security Update</title>
	<meta name="section-branded" content="home" xmlns="">
		</meta>

	

	<META http-equiv="Content-Script-Type" content="text/javascript" xmlns="" />

	<script xmlns="">
		var sectionName = 'home';
	</script>

	<script type="text/javascript" src="/montebello.js" xmlns="">
	// prevent collapse to empty element
	</script>

	<style type="text/css" xmlns="">
		.color { background: #FFFFDD; }
		.text-color, .colored { color: #006600; }
	</style>

	<link rel="stylesheet" type="text/css" href="/montebello.css" xmlns="" />
	<head>
<meta name="Author" content="Ames Cornish" />
<meta name="section" content="home" />
<title>Internet Security Update</title></head></head>

	<body onLoad="init();" onResize="init();">

	<table class="layout" id="page" xmlns="">
	<tr class="short">
	<td id="nav-left" class="skinny color" rowspan="2">
		<div><a href="/Home.xhtml" target="_self" onMouseOver="pushDown('home');" onMouseOut="popUp('home');">
		<img src="/images/nav_home.gif" alt="home page" name="home" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Company.xhtml" target="_self" onMouseOver="pushDown('company');" onMouseOut="popUp('company');">
		<img src="/images/nav_company.gif" alt="company background" name="company" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Clients.xhtml" target="_self" onMouseOver="pushDown('clients');" onMouseOut="popUp('clients');">
		<img src="/images/nav_clients.gif" alt="some of our clients" name="clients" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Services.xhtml" target="_self" onMouseOver="pushDown('services');" onMouseOut="popUp('services');">
		<img src="/images/nav_services.gif" alt="services we offer" name="services" WIDTH="122" HEIGHT="22" /></a></div>

		<div><a href="/Products.xhtml" target="_self" onMouseOver="pushDown('products');" onMouseOut="popUp('products');">
		<img src="/images/nav_products.gif" alt="products we offer" name="products" WIDTH="122" HEIGHT="22" /></a></div>

		<div><img name="graphic" src="/images/pic_home.jpeg">
			</img></div></td>

	<td>
	<div id="nav-top">

		<a href="/Contact.xhtml" target="_self" onMouseOver="pushDown('contact');" onMouseOut="popUp('contact');">
			<img src="/images/nav_contact.gif" alt="how to contact us" name="contact" align="left" WIDTH="63" HEIGHT="22" /></a>
		<a href="/Client_Area.xhtml" target="_self" onMouseOver="pushDown('client_area');" onMouseOut="popUp('client_area');">
			<img src="/images/nav_client_area.gif" alt="private area for current clients" name="client_area" align="left" WIDTH="70" HEIGHT="22" /></a>
		
		<div id="logo"><a href="http://montebellopartners.com" target="_self">
		<img src="/images/logo.gif" alt="Montebello Partners" WIDTH="112" HEIGHT="22" /></a></div></div>

	<div class="color" id="nav-title">
		<div id="title" style="text-color">Internet Security Update</div></div>

	<div id="content">
		<body xmlns="http://www.w3.org/1999/xhtml">

<p>Welcome to Montebello Partners' security home page.  Here we include
important current alerts, resources, and announcements.  If this is your
first visit here, you may want to browse:</p>

<ul class="compact">
  <li>Our <a href="/Security/Dangers.xhtml">introduction to Internet Security</a>,</li>
  <li>Description of our <a href="/SecServices.xhtml">security services</a></li>
  <li>Monthly <a href="http://lists.montebellopartners.com">email news</a> and updates</li>
  <li>The monthly meetings of the SDForum <a href="http://sdforum.org/sigs/security"> Internet Security SIG</a></li>
  <li>The FBI-sponsored <a href="http://www.sfbay-infragard.org">bay area
  Infragard</a> chapter</li>
  <li>Useful security <a href="/Security/Tools.xhtml">links and tools</a></li>
  <li>Various <a href="/slides/">presentations</a> given by us.</li></ul>

<h3 xmlns="">April, 2005 Update</h3>

	<h3 xmlns=""><hack>Hacks</hack></h3>
		<ul xmlns="">
		<li>
			<p><text>Chico university, in accordance with California's hacking disclosure
		law, announced that <a href="http://www.csuchico.edu/inf/security/03-14-2005.shtml">hackers took
		over one of their servers</a> for file sharing.  Because the server also
		stored student social security numbers, they are notifying the affected
		individuals.</text></p></li><li>
			<p><text>Security researchers estimate that <a href="http://news.bbc.co.uk/2/hi/technology/4354109.stm">more than one
		million computers have become hijacked &quot;zombies&quot;</a>.</text></p></li><li>
			<p><text><a href="http://www.nytimes.com/2005/03/12/theater/newsandfeatures/12hack.html">31,000 names and e-mail addresses were stolen</a> from the website for the
		Broadway musical &quot;Spamalot&quot; -- presumably to be used for spamming.</text></p></li><li>
			<p><text><a href="http://news.bbc.co.uk/2/hi/uk_news/4356661.stm">Electronic
		bank robbers almost got away with $423 million</a>.  They used key-logging
		software to infiltrate the London offices of Sumitomo Mitsui bank.  They
		were got by police in Israel, where the money was destined.</text></p></li><li>
			<p><text>Like ChoicePoint last month, now <a href="http://www.nytimes.com/2005/03/09/technology/10cnd-data.html?ex=1111813200&amp;en=12981eb0796dec50&amp;ei=5070">
		LexisNexis has lost more than 30,000 sensitive personal records</a> to identity
		theives.</text></p></li></ul><h3 xmlns=""><hole>Holes</hole></h3>
		<ul xmlns="">
		<li>
			<p><text>Caller-ID spoofing, enabled by VOIP technologies, is <a href="http://money.cnn.com/2005/03/18/technology/personaltech/scam_phones.reut/index.htm?cnn=yes">allowing cybercriminals to transfer money directly from stolen credit-card
		accounts.</a></text></p></li></ul><h3 xmlns=""><hint>Hints</hint></h3>
		<ul xmlns="">
		<li>
			<p><text>IBM has published a spam-blocking technique called <a href="http://www.alphaworks.ibm.com/tech/fairuce">FairUCE</a>.  It works by
		attempting to connect the sender's domain with the sending IP address.
		Forged spam often fails that test.</text></p></li><li>
			<p><text>Yours truly was interviewed on the radio about mobile phone hacking.
		Public interest was prompted by Paris' Hilton's lost address book.  Hackers
		can use BlueTooth, Server-side infiltration, password guessing, or simply
		steal a phone to get at sensitive data.  Often you don't know how sensitive
		your data was until after you lose it.</text></p></li></ul><h3 xmlns=""><event>Upcoming Events</event></h3>
		<ul xmlns="">
		<li>
			<p><text>The next SDForum Security SIG will be about patch management on
		Thursday, April 28th.</text></p></li></ul>

<h3>Other Updates</h3>
<ul class="compact">
  <li><a href="/Security/Update200506.xml">June, 2006</a></li>
  <li><a href="/Security/Update200505.xml">May, 2006</a></li>
  <li><a href="/Security/Update200511.xml">November, 2005</a></li>
  <li><a href="/Security/Update200508.xml">August, 2005</a></li>
  <li><a href="/Security/Update200506.xml">June, 2005</a></li>
  <li><a href="/Security/Update200505.xml">May, 2005</a></li>
  <li><a href="/Security/Update200504.xml">April, 2005</a></li>
  <li><a href="/Security/Update200503.xml">March, 2005</a></li>
  <li><a href="/Security/Update200501.xml">January, 2005</a></li>
  <li><a href="/Security/Update200412.xml">December, 2004</a></li>
  <li><a href="/Security/Update200411.xml">November, 2004</a></li>
  <li><a href="/Security/Update200410.xml">October, 2004</a></li>
  <li><a href="/Security/Update200409.xml">September, 2004</a></li>
  <li><a href="/Security/Update200408.xml">August, 2004</a></li>
  <li><a href="/Security/Update200304.xml">April, 2003</a></li>
  <li><a href="/Security/Update200303.xml">March, 2003</a></li></ul></body></div></td></tr>

	<tr><td id="nav-bottom">
		<div id="links">
			<a href="/Home.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">home</a> |
		<a href="/Security" target="_self" xmlns="http://www.w3.org/1999/xhtml">security</a> |
		<a href="/Security/#events" target="_self" xmlns="http://www.w3.org/1999/xhtml">events</a> |
		<a href="/Services.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">services</a> |
		<a href="/Directions.xhtml" target="_self" xmlns="http://www.w3.org/1999/xhtml">directions</a></div>
		<div class="mousetype">
			Copyright © 2004 Montebello Partners.  All rights reserved.
</div></td></tr></table></body></html>