<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VoIP Tech Chat</title>
	<atom:link href="http://www.voiptechchat.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voiptechchat.com</link>
	<description>Patrick and Fred Chat... sometimes about VoIP</description>
	<lastBuildDate>Sat, 19 Jun 2010 18:59:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Rackspace WordPress Sites Under Attack</title>
		<link>http://www.voiptechchat.com/tech/551/rackspace-wordpress-sites-under-attack/</link>
		<comments>http://www.voiptechchat.com/tech/551/rackspace-wordpress-sites-under-attack/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 17:39:04 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[rackspace]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=551</guid>
		<description><![CDATA[Got Rackspace? Got WordPress? If so&#8230; you may just have a problem. We&#8217;ve been getting calls today from Rackspace clients (hosting WordPress sites) that have been compromised similarly to the GoDaddy hack a few weeks back. The Unmask Parasites Blog has an excellent article on the attack posted on their, well, their blog. There are some [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_552" class="wp-caption alignright" style="width: 151px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/06/images.jpeg"><img class="size-full wp-image-552" title="images" src="http://www.voiptechchat.com/wp-content/uploads/2010/06/images.jpeg" alt="" width="141" height="55" /></a><p class="wp-caption-text">Fanatical Support</p></div>
<p>Got Rackspace? Got WordPress? <em>If so&#8230; you may just have a problem.</em></p>
<p>We&#8217;ve been getting calls today from Rackspace clients (hosting WordPress sites) that have been compromised similarly to the GoDaddy hack a few weeks back. The Unmask Parasites Blog has an <a href="http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/" onclick="pageTracker._trackPageview('/outgoing/blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/?referer=');">excellent article</a> on the attack posted on their, well, their blog.</p>
<p>There are some huge sites that have been hit, and some not-so-large as well (we personally were hit by an earlier attack). In the &#8220;Is Cloud the answer&#8221; debates, this will surely become an example of how a compromise in the cloud, can devastate an entire farm.</p>
<h3>Update 6/19/2010</h3>
<p>Shortly after this article was initially posted, Rackspace via their Rackcloud Twitter account posted the following message:<span id="more-551"></span></p>
<div id="attachment_556" class="wp-caption aligncenter" style="width: 620px"><a href="http://twitter.com/rackcloud/status/16241822695" onclick="pageTracker._trackPageview('/outgoing/twitter.com/rackcloud/status/16241822695?referer=');"><img class="size-full wp-image-556" title="rackcloud-twitter" src="http://www.voiptechchat.com/wp-content/uploads/2010/06/rackcloud-twitter.png" alt="Rackcloud advised that the reports were inaccurate and details would follow..." width="610" height="386" /></a><p class="wp-caption-text">Reports, schmeorts.</p></div>
<p>Of course&#8230; details never came. I tweeted them myself (Oh no you didn&#8217;t&#8230; Oh yes I did):</p>
<div id="attachment_557" class="wp-caption aligncenter" style="width: 620px"><a href="http://twitter.com/fredposner/status/16338590226" onclick="pageTracker._trackPageview('/outgoing/twitter.com/fredposner/status/16338590226?referer=');"><img class="size-full wp-image-557" title="fredposner-twitter" src="http://www.voiptechchat.com/wp-content/uploads/2010/06/fredposner-twitter.png" alt="Show me the money." width="610" height="350" /></a><p class="wp-caption-text">Show me the money.</p></div>
<p>At this point, they haven&#8217;t replied to my request or posted any additional information on their twitter account. I think they moved on&#8230; the next day they were more interested in talking about how &#8220;Cassandra by Example translated to Japanese!&#8221;</p>
<p>Also, one day&#8230; one day I&#8217;ll spell check my tweets. Until then, read at your own grammatical risk.</p>
<p><strong>Read more:</strong></p>
<p><a href="http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/" onclick="pageTracker._trackPageview('/outgoing/blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/?referer=');">http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/</a></p>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/551/rackspace-wordpress-sites-under-attack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>VoIP Users Conference SIP Hacks Discussion Brings the Heat</title>
		<link>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/</link>
		<comments>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/#comments</comments>
		<pubDate>Mon, 24 May 2010 12:45:22 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>
		<category><![CDATA[vuc]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=548</guid>
		<description><![CDATA[The VoIP Users Conference provides an open-to-all weekly conference call where anyone can engage in discussions related to, well, VoIP. Sometimes the conversations discuss new technologies / products. Sometimes discussions center around implementation. And lately, conversations may focus on security. Last week, Ward Mundy, Tim Panton, Karl Fife, Leif Madsen, Yours Truly, and many other [...]]]></description>
			<content:encoded><![CDATA[
<p><a href="http://www.voiptechchat.com/wp-content/uploads/2010/05/argument.jpeg"><img class="alignright size-medium wp-image-549" title="argument" src="http://www.voiptechchat.com/wp-content/uploads/2010/05/argument-300x239.jpg" alt="" width="300" height="239" /></a>The VoIP Users Conference provides an open-to-all weekly conference call where anyone can engage in discussions related to, well, VoIP. Sometimes the conversations discuss new technologies / products. Sometimes discussions center around implementation. And lately, conversations may focus on security.</p>
<p>Last week, Ward Mundy, Tim Panton, Karl Fife, Leif Madsen, Yours Truly, and many other regulars <a href="http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/" onclick="pageTracker._trackPageview('/outgoing/www.voipusersconference.org/2010/sip-hack-callerid-stuffing/?referer=');">discussed a SIP Caller ID Injection Hack</a>. As in all conversations, opinions differ. My position about where to best filter this injection differed than Ward Mundy&#8217;s thoughts&#8230; and, courtesy of the VoIP Users Conference, you can listen to the conversation and form your own opinions.</p>
<p>Although, next time&#8230; maybe you&#8217;d enjoy actively participating in our conversations rather than listening to the replay. <img src='http://www.voiptechchat.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>→ </strong><a href="http://www.voipusersconference.org/2010/sip-hack-callerid-stuffing/" onclick="pageTracker._trackPageview('/outgoing/www.voipusersconference.org/2010/sip-hack-callerid-stuffing/?referer=');"><strong>SIP Hacks: who should filter what, where?</strong></a><strong> (VoIP Users Conference)</strong></p>
<p>(The VoIP Users Conference provides weekly live discussion about VoIP, SIP, Asterisk and all kinds of telephony-related topics every Friday at 12pm EST. For more information, please visit <a href="http://vuc.me" onclick="pageTracker._trackPageview('/outgoing/vuc.me?referer=');">http://vuc.me</a>.)</p>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/548/voip-users-conference-sip-hacks-discussion-brings-the-heat/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Thieves Take Control of LifeLock CEO&#8217;s Identity</title>
		<link>http://www.voiptechchat.com/tech/544/lifelock-ceo-identity-stolen/</link>
		<comments>http://www.voiptechchat.com/tech/544/lifelock-ceo-identity-stolen/#comments</comments>
		<pubDate>Wed, 19 May 2010 13:11:19 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=544</guid>
		<description><![CDATA[LifeLock promises to &#8220;take control&#8221; of your identity — they just don&#8217;t tell you who gets to take control. Patrick and I chatted a while back about Todd Davis, the CEO of LifeLock, and how his ads promoting the ability of his company to protect identity, actually helped with the theft of his own. Back [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_545" class="wp-caption alignright" style="width: 310px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/05/lifelock-ceo.png"><img class="size-medium wp-image-545" title="lifelock-ceo" src="http://www.voiptechchat.com/wp-content/uploads/2010/05/lifelock-ceo-300x209.png" alt="" width="300" height="209" /></a><p class="wp-caption-text">Whoops. My bad.</p></div>
<p>LifeLock promises to &#8220;take control&#8221; of your identity — they just don&#8217;t tell you who gets to take control. Patrick and I chatted a while back about Todd Davis, the CEO of LifeLock, and how his ads promoting the ability of his company to protect identity, actually helped with the theft of his own. Back in 2007, a gentleman in Texas had used Davis&#8217; identity to obtain a $500.00 without Davis&#8217; knowledge. In fact, Davis only had learned about it after the unpaid loan was sold to a debt collection agency — but that&#8217;s old news.</p>
<p>Today, thanks to the <a href="http://www.phoenixnewtimes.com/2010-05-13/news/cracking-life-lock-even-after-a-12-million-penalty-for-deceptive-advertising-the-tempe-company-can-t-be-honest-about-its-identity-theft-protection-service/" onclick="pageTracker._trackPageview('/outgoing/www.phoenixnewtimes.com/2010-05-13/news/cracking-life-lock-even-after-a-12-million-penalty-for-deceptive-advertising-the-tempe-company-can-t-be-honest-about-its-identity-theft-protection-service/?referer=');">Phoenix News Times</a>, we learn that Davis had his identity stolen a grand total of 13 times. Or, at least 13 times that we know of.</p>
<p>With attention grabbing ads that published Davis&#8217; Social Security Number, LifeLock caught the attention of many customers; as well as the FTC — who accused the company of running a scam operation and fined them $12 million dollars.</p>
<h4>Additional Reading</h4>
<ul>
<li><a href="http://www.phoenixnewtimes.com/2010-05-13/news/cracking-life-lock-even-after-a-12-million-penalty-for-deceptive-advertising-the-tempe-company-can-t-be-honest-about-its-identity-theft-protection-service/" onclick="pageTracker._trackPageview('/outgoing/www.phoenixnewtimes.com/2010-05-13/news/cracking-life-lock-even-after-a-12-million-penalty-for-deceptive-advertising-the-tempe-company-can-t-be-honest-about-its-identity-theft-protection-service/?referer=');">Cracking LifeLock: Even After a $12 Million Penalty for Deceptive Advertising, the Tempe Company Can&#8217;t Be Honest About Its Identity-Theft-Protection Service</a> (Phoenix New Times)</li>
<li><a href="http://www.wired.com/threatlevel/2010/03/lifelock-accused-of-running-con-operation/" onclick="pageTracker._trackPageview('/outgoing/www.wired.com/threatlevel/2010/03/lifelock-accused-of-running-con-operation/?referer=');">Lifelock Dinged $12 Million for Deceptive Business Practices</a> (wired.com)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/544/lifelock-ceo-identity-stolen/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>SIP Attacks From Amazon EC2 Cloud Continue</title>
		<link>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/</link>
		<comments>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/#comments</comments>
		<pubDate>Sun, 16 May 2010 22:11:02 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[amazon ec2]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=538</guid>
		<description><![CDATA[Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud were on the rise. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this morning included what we assume was a standard dictionary attack. The first attack came from [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_458" class="wp-caption alignright" style="width: 174px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif"><img class="size-full wp-image-458" title="aws" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/aws.gif" alt="" width="164" height="60" /></a><p class="wp-caption-text">Attacks from the cloud.</p></div>
<p>Just over a month ago, we reported that SIP attacks from the Amazon EC2 cloud <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">were on the rise</a>. While the attacks we received last month were limited to &#8220;extension only&#8221; registration attempts, one of the attacks we received this morning included what we assume was a standard dictionary attack.</p>
<p>The first attack came from 204.236.245.101. In less than 60 seconds, this IP attempted more than 11,500 registrations against our server. Most of these were 4 digit extensions (<a href="http://www.voiptechchat.com/20100516-204ec2.txt.zip">download the log (zipped) here</a>). The second attack came from 184.73.4.183. In less than 90 seconds, this IP attempted more than 21,000 registrations against our server; including what we think is a standard dictionary attack complete with root, postmaster, pixadmin, etc. (<a href="http://www.voiptechchat.com/20100516-184ec2.txt.zip">download the log (zipped) here</a>).</p>
<p><span id="more-538"></span>From past experience, Amazon will simply not do anything about these attacks. The only way to contact Amazon to report abuse is through their web form, which results with Amazon either completely ignoring you or sending a delayed response asking for the exact information you have already sent (and then ignoring you).</p>
<p>So, I’m looking for more ideas from the community on how we can get Amazon to help us stop their network from leveraging a very powerful attack against little ol’ SIP servers.</p>
<p>We are currently deploying a custom perl script to block these attackers via iptables (which is why the attacks registration attempts “stopped”).</p>
<p>Thanks for reading and we’ll be updating this as soon as more information comes in!</p>
<p class="note">Update #1</p>
<p>The first response from Amazon:</p>
<blockquote><p>Thank you for submitting your abuse report.</p>
<p>We have completed an initial investigation of the issue and learned that the IP address you reported did indeed belong an Amazon EC2 instance. These intrusion attempts that you report were not, however, initiated by Amazon.</p>
<p>One of the biggest advantages of Amazon EC2 is that developers are given complete control of their instances. While the IPs may indicate that the network is Amazon&#8217;s, our developer customers are the ones controlling the instances. You may learn more about EC2 at http://aws.amazon.com/ec2</p>
<p>That said, we do take reports of unauthorized network activity from our environment very seriously. It is specifically forbidden in our terms of use. We&#8217;ve already contacted the Amazon EC2 customer who controlled the instance in question and informed them that they are required to terminate their unauthorized interaction with your network, failing which we will terminate their instance. In cases of egregious abuse or as we otherwise deem appropriate, we will immediately terminate all their instances and suspend their account.</p>
<p>If you have blocked this address range, please be aware that usage on the address range is transient and new users may soon be operating from those addresses and may not be able to reach you; once you have confirmed that the activity has been ceased by our customer, you should open your filters to re-allow traffic.</p>
<p>Thanks again for alerting us to this issue.</p>
<p>Original report:</p>
<p>* Source IPs: 204.236.245.101<br />
* Abuse Time: Sun May 16 08:53:00 UTC 2010<br />
* NTP: Y</p>
<p><strong>How can I send a message to the EC2 customer?</strong><br />
Complete and submit the web form <a href="https://www.amazon.com/gp/html-forms-controller/AWSAbuseReporter" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/gp/html-forms-controller/AWSAbuseReporter?referer=');">here</a>.</p>
<p><strong>How can I contact a member of the Amazon EC2 abuse team?</strong><br />
Send an e-mail to ec2-abuse@amazon.com to contact a member of the Amazon EC2 abuse team.</p>
<p>Please note: This e-mail message was sent from a notification-only address that cannot accept incoming e-mail. Please do not reply to this message.</p>
<p><a href="http://www.amazon.com/aws" onclick="pageTracker._trackPageview('/outgoing/www.amazon.com/aws?referer=');">Amazon Web Services</a></p>
<p>If you feel you are receiving this email in error and do not wish to receive further notifications, send an e-mail to ec2-abuse@amazon.com.</p>
<p>Amazon Web Services LLC is a subsidiary of Amazon.com, Inc. Amazon.com is a registered trademark of Amazon.com, Inc. This message produced and distributed by Amazon Web Services, LLC, 1200 12th Ave South, Seattle, WA 98144.</p></blockquote>
<p>I really don&#8217;t need a sales pitch in my abuse response.</p>
<h4>Additional Information:</h4>
<ul>
<li><a href="http://www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/" onclick="pageTracker._trackPageview('/outgoing/www.teamforrest.com/blog/171/asterisk-no-matching-peer-found-block/?referer=');">Automatically Block Failed SIP Peer Registrations</a> (Team Forrest)</li>
<li><a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Amazon EC2 SIP Brute Force Attacks on Rise</a> (VoIP Tech Chat)</li>
<li><a href="http://www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/" onclick="pageTracker._trackPageview('/outgoing/www.stuartsheldon.org/blog/2010/04/sip-brute-force-attack-originating-from-amazon-ec2-hosts/?referer=');">SIP Brute Force Attack Originating From Amazon EC2 Hosts</a> (Building The Net)</li>
<li><a href="http://jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/" onclick="pageTracker._trackPageview('/outgoing/jcs.org/notaweblog/2010/04/11/properly_stopping_a_sip_flood/?referer=');">Properly stopping a SIP flood</a> (joshua stein)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/538/sip-attacks-from-amazon-ec2-cloud-continue/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Michael Graves Discusses PBXact</title>
		<link>http://www.voiptechchat.com/voip/535/michael-graves-discusses-pbxact/</link>
		<comments>http://www.voiptechchat.com/voip/535/michael-graves-discusses-pbxact/#comments</comments>
		<pubDate>Fri, 14 May 2010 13:06:35 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[telephone]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=535</guid>
		<description><![CDATA[I&#8217;ve said before that I&#8217;m a big (not a fat reference) fan of Michael Graves&#8217; blog. Continuing his promotion of the wicked cool and useful†, Mr. Graves recently wrote about Schmooze Communications&#8217; PBXact system. It&#8217;s a GREAT read and I leave you with this: Magic Button. (read the article) Related links: e4 Technologies Michael Graves [...]]]></description>
			<content:encoded><![CDATA[
<p>I&#8217;ve <a href="http://www.voiptechchat.com/voip/118/michael-graves-rants-we-listen/">said before</a> that I&#8217;m a big (not a fat reference) fan of Michael Graves&#8217; blog. Continuing his promotion of the wicked cool and useful†, Mr. Graves recently wrote about Schmooze Communications&#8217; PBXact system.</p>
<p>It&#8217;s a <a href="http://www.mgraves.org/voip/2010/05/pbxact-unexpected-magic" onclick="pageTracker._trackPageview('/outgoing/www.mgraves.org/voip/2010/05/pbxact-unexpected-magic?referer=');">GREAT read</a> and I leave you with this: Magic Button. (<a href="http://www.mgraves.org/voip/2010/05/pbxact-unexpected-magic" onclick="pageTracker._trackPageview('/outgoing/www.mgraves.org/voip/2010/05/pbxact-unexpected-magic?referer=');">read the article</a>)</p>
<h3>Related links:</h3>
<ul>
<li><a href="http://www.8774e4voip.com/PBXact_Phone_Systems_s/93.htm" onclick="pageTracker._trackPageview('/outgoing/www.8774e4voip.com/PBXact_Phone_Systems_s/93.htm?referer=');">e4 Technologies</a></li>
<li><a href="http://www.mgraves.org/voip/" onclick="pageTracker._trackPageview('/outgoing/www.mgraves.org/voip/?referer=');">Michael Graves on SOHO VoIP</a></li>
</ul>
<p>†Yes&#8230; Wicked cool <em>and</em> useful. If it doesn&#8217;t meet the criteria for both, it doesn&#8217;t make his blog.</p>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/535/michael-graves-discusses-pbxact/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Maybe we could all be a little more neanderthalish?</title>
		<link>http://www.voiptechchat.com/tech/525/maybe-we-could-all-be-a-little-more-neanderthalish/</link>
		<comments>http://www.voiptechchat.com/tech/525/maybe-we-could-all-be-a-little-more-neanderthalish/#comments</comments>
		<pubDate>Wed, 12 May 2010 18:41:33 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=525</guid>
		<description><![CDATA[Early humans found hollowed out rocks to turn into homes, originating the term &#8220;Cave men&#8221;. 1 This constraint made community difficult, so humans advanced to creating homes from natural materials, such as wood. Primitive homes were modeled on the cave, with nothing but some closed walls and an uncovered opening. Thousands of years of evolution [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_527" class="wp-caption alignright" style="width: 225px"><img class="size-medium wp-image-527" src="http://www.voiptechchat.com/wp-content/uploads/2010/05/neanderthal_280_470743a-215x300.jpg" alt="Our Hero" width="215" height="300" /><p class="wp-caption-text">Our Hero</p></div>
<p>Early humans found hollowed out rocks to turn into homes, originating the term &#8220;Cave men&#8221;. <sup>1</sup> This constraint made community difficult, so humans advanced to creating homes from natural materials, such as wood. Primitive homes were modeled on the cave, with nothing but some closed walls and an uncovered opening. Thousands of years of evolution lead us to create doors that open, close, and lock, and windows that allow us to see out and in, then glass to keep what&#8217;s out out and what&#8217;s in in, then curtains to cover what&#8217;s both out and in. In the end, we have the same caves we had before, with our darkness and privacy.<span id="more-525"></span></p>
<p>In the 1600&#8242;s the Dutch East India company was like the Wal-Mart of the high seas. If you worked on a ship for the DEI, actually called VOC, but let&#8217;s not have an acromania tournament over it, you lived day in and day out with the other people on the ship. Everyone knew everyone&#8217;s business, and that&#8217;s just how it was. There would be no need to do a status update when you went to the head, because everyone watched you go.</p>
<p>With the onset of industrialization and assembly-style production in the 1900&#8242;s, factories became central to small towns and people began working together, but their was a similar environment of everyone knew everyone&#8217;s family and friends and kids and lifestyle. There just weren&#8217;t a lot of secrets. Only in the last 50 years have we moved to the cubiclised, white-collar, technically-oriented jobs where turnover is an expectation and no one really bothers to get to know everyone else. Cliques form, but on the whole there isn&#8217;t a sense of community.</p>
<p>In a relatively short span of time, we created a generation and a culture that has a &#8220;right to privacy.&#8221; We have seen this concept denied by courts who say employers can regulate lifestyle as a condition of employment, and that what an employee does outside of work can still be used against her at work. Drinking, drugs, cigarettes, and even functions allowed to be attended can all be used as conditions of employment in our &#8220;right to work&#8221; world.  Though it has been upheld time and time again, the belief in this right grows ever stronger.</p>
<p>The political buzzword of the last decade has been &#8220;transparency.&#8221; We the people should have an open window on the workings of our government, of our corporations, of our financial institutions. We should see how the cogs turn and the deals are made, we should have open access to it all. At the same time, a subculture of companies has grown around controlling the online image of individuals. Ex-boyfriend posted some risque pictures of you? They can fix that. You got fired from your old job for coming to work drunk, and some people decided to blog about it? They can fix that. From the benign to the outright slanderous, companies that specialize in online identity rehab are doing bang up business curing the internet of individuals&#8217; indiscretions.</p>
<p>Should it matter? Should you want to work for a company that would use your facebook status update about hating filing against you in an interview? Does that tweet about being drunk at the Alice In Chains concert make you a bad person or in any way impact your job performance? Are companies better off pretending that their employees don&#8217;t have a personal life? Maybe this is the wake up call that companies need to start treating their employees like people. Maybe it&#8217;s time to open up the door to the cave and not worry about what others will see, because their cave door is wide open too.</p>
<p><sup>1. This is rather vague and unresearched proposition, because this is a tech blog and not an anthropology blog. Please do not blame us when you crib this and fail your class. </sup></p>
<p>If you want to be judgmental of our thoughts, feel free to follow <a title="Twitter fredposner" href="http://twitter.com/fredposner" target="_blank" onclick="pageTracker._trackPageview('/outgoing/twitter.com/fredposner?referer=');">Fred</a> and <a title="Twitter Patrick! " href="http://twitter.com/pgoldberg" target="_blank" onclick="pageTracker._trackPageview('/outgoing/twitter.com/pgoldberg?referer=');">Patrick </a>on twitter!</p>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/525/maybe-we-could-all-be-a-little-more-neanderthalish/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>FreePBX Security Vulnerability</title>
		<link>http://www.voiptechchat.com/voip/516/freepbx-security-vulnerability/</link>
		<comments>http://www.voiptechchat.com/voip/516/freepbx-security-vulnerability/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 18:15:07 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[VoIP]]></category>
		<category><![CDATA[freepbx]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=516</guid>
		<description><![CDATA[Ward Mundy, of Nerd Vittles / PBX in a Flash fame, warns of a FreePBX Security Vulnerability allowing a system to be compromised simply by displaying a CDR report in the FreePBX browser. There is a very serious security vulnerability that needs to be patched by loading the very latest version of FreePBX Framework as [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_517" class="wp-caption alignright" style="width: 242px"><a href="http://www.freepbx.org" onclick="pageTracker._trackPageview('/outgoing/www.freepbx.org?referer=');"><img class="size-full wp-image-517" title="FreePBX" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/FreePBX.png" alt="" width="232" height="160" /></a><p class="wp-caption-text">I do love their logo.</p></div>
<p>Ward Mundy, of <a href="http://nerdvittles.com/" onclick="pageTracker._trackPageview('/outgoing/nerdvittles.com/?referer=');">Nerd Vittles / PBX in a Flash</a> fame, warns of a FreePBX Security Vulnerability allowing a system to be compromised simply by displaying a CDR report in the FreePBX browser.</p>
<blockquote><p>There is a very serious security vulnerability that needs to be patched by loading the very latest version of FreePBX Framework as soon as it becomes available for your version of FreePBX. <span style="color: #ff0000;">Just displaying a CDR report in the FreePBX browser could compromise your system.</span></p>
<p>The 2.5 and 2.6 patches already have been released and probably 2.7 as well. Load this patch IMMEDIATELY!!!</p>
<p>Setup, Module Admin, Check for Updates on Line, Upgrade All</p>
<p><strong>2.5.2.3</strong>: #4223 Security Vulnerability<br />
<strong>2.6.0.2</strong>: #3805, #3707, #4188, #4223 Security Vulnerability</p></blockquote>
<p>For more information, check out the <a href="http://pbxinaflash.com/forum/showthread.php?p=43379#post43379" onclick="pageTracker._trackPageview('/outgoing/pbxinaflash.com/forum/showthread.php?p=43379_post43379&amp;referer=');">PBX in a Flash Forum</a>.</p>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/voip/516/freepbx-security-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Acer Aspire One &#8211; Innocent Netbook</title>
		<link>http://www.voiptechchat.com/tech/493/acer-aspire-one-innocent-netbook/</link>
		<comments>http://www.voiptechchat.com/tech/493/acer-aspire-one-innocent-netbook/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 22:16:43 +0000</pubDate>
		<dc:creator>patrick</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[acer]]></category>
		<category><![CDATA[Ben Affleck]]></category>
		<category><![CDATA[cellphone]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[netbook]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[verizon]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=493</guid>
		<description><![CDATA[Or cleverly disguised secret agent for the video phone revolution? I love my netbook. I love my netbook so much, I have two of them (okay, one is the wife&#8217;s). Surprisingly, I managed to survive months on nothing but my netbook doing fairly intensive SQL / VoIP / Web work. The hard drive is a [...]]]></description>
			<content:encoded><![CDATA[
<h2>Or cleverly disguised secret agent for the video phone revolution?</h2>
<div class="wp-caption alignright" style="width: 205px"><img class="  " title="Acer Aspire One" src="http://www.computerbug.co.uk/uploaded_images/4385_Acer_Aspire_One_pink-710748.jpg" alt="Acer Aspire One" width="195" height="168" /><p class="wp-caption-text">I R Eatz U R Dataz! </p></div>
<p>I love my netbook. I love my netbook so much, I have two of them (okay, one is the wife&#8217;s). Surprisingly, I managed to survive months on nothing but my netbook doing fairly intensive SQL / VoIP / Web work. The hard drive is a little slow, but the overall performance is <em>outstanding</em>.</p>
<p>When I travel, I can use Skype to video chat with the built in webcam and get great quality (both ways) for both picture and sound. It&#8217;s like a giant smart phone. It reminds me of the $1000+ &#8220;video phones&#8221; that were supposed to be the future of talking on the phone&#8230; then people realized they really didn&#8217;t want to &#8220;get pretty&#8221; to use the phone. Now, for around $250 a unit, you can have that and so much more.</p>
<p><span id="more-493"></span></p>
<p>Recently, my wife&#8217;s netbook gave an error on boot that had something to do with a missing windows file (system32\ntoskrnl.exe<em>).</em> Apparently, she&#8217;s not the only one with this issue&#8230; it seems to be quite common. Of course, as the techie/geek/nerd of the castle, it was my job to slay this dragon and I came across the only problem I have had with this magical mini machine. Not so much a problem&#8230; more like open questions to Acer.</p>
<ol>
<li> To access the hard drive, you have to remove 17 screws (maybe more, I think I lost some extras), you have to remove the keyboard, you have to remove the top, you have to remove this little card on top of the mother board, this side circuit board, the motherboard. Then you slide the hard drive out, reverse. Why not put a panel on the bottom to access the hard drive directly?</li>
<li> Why can I find nothing in your documentation about Alt-F10? This is a handy mode that lets you recover the operating system to factory defaults, but I don&#8217;t see it in my Acer manual.</li>
<li> In line with question 2, Why is the only recovery option to completely reset to factory? Since this is basically a stripped version of the OS, why not offer an explorer window so I can copy files to an SD or USB drive before formatting, or just backup the user files to another partition?</li>
<li> What degree in sadism lead to the design of the three little clips that hold the keyboard in place?</li>
</ol>
<p>All told, from error to recovered could have been done in &lt; 30 minutes, and I HIGHLY recommend Acer products to everyone I know. From their higher-end Ferrari laptop to the humble netbook (go with XP home, Windows 7 netbook edition is crippleware garbage), I have never had a problem with their hardware or software that made me lose respect for the brand, which is saying a lot.</p>
<h3>For More Information:</h3>
<ul>
<li>Acer: <a href="http://www.acer.com/aspireone/aspireone_8_9/" onclick="pageTracker._trackPageview('/outgoing/www.acer.com/aspireone/aspireone_8_9/?referer=');">Acer Aspire One Website</a></li>
<li>Skype: <a href="http://www.skype.com/allfeatures/videocall/" onclick="pageTracker._trackPageview('/outgoing/www.skype.com/allfeatures/videocall/?referer=');">Free PC to PC Video Calls</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/493/acer-aspire-one-innocent-netbook/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>McAfee Anti-Virus Goes Bad Lieutenant</title>
		<link>http://www.voiptechchat.com/tech/488/mcafee-anti-virus-goes-bad-lieutenant/</link>
		<comments>http://www.voiptechchat.com/tech/488/mcafee-anti-virus-goes-bad-lieutenant/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 03:32:39 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=488</guid>
		<description><![CDATA[McAfee released a “faulty update” this morning causing the security program to believe a good file had gone bad. In what the company calls a “False Positive Issue,” the anti-virus software identifies a good windows file, svchost.exe, as the W32/Wecorl.a virus; causing the system to continuously reboot and lose network access. At the University Hospital [...]]]></description>
			<content:encoded><![CDATA[
<div id="attachment_489" class="wp-caption alignright" style="width: 160px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/04/mcaffee.jpg"><img class="size-full wp-image-489" title="mcaffee" src="http://www.voiptechchat.com/wp-content/uploads/2010/04/mcaffee.jpg" alt="" width="150" height="36" /></a><p class="wp-caption-text">Whoops. Our Bad.</p></div>
<p>McAfee released a “faulty update” this morning causing the security program to believe a good file had gone bad. In what the company calls a “False Positive Issue,” the anti-virus software identifies a good windows file, svchost.exe, as the W32/Wecorl.a virus; causing the system to continuously reboot and lose network access.</p>
<p>At the University Hospital in Syracuse, NY 2,500 computers were affected; however the hospital stated that patient care was not compromised. Other public service/safety organizations were also impacted, including the Kentucky State Police, the National Science Foundation, and Illinois State University.</p>
<p><span id="more-488"></span>The impact forced several Rhode Island hospitals to stop treatment of non-trauma patients in emergency rooms as well as postpone non-essential surgeries.</p>
<p>McAfee’s Barry McPherson posted on their security blog:</p>
<blockquote><p>McAfee is aware that a number of customers have incurred a false positive error due to this release. Corporations who kept a feature called “Scan Processes on Enable” in McAfee VirusScan Enterprise disabled, as it is by default, were not affected.</p>
<p>Our initial investigation indicates that the error can result in moderate to significant issues on systems running Windows XP Service Pack 3.</p>
<p>The faulty update was removed from all McAfee download servers within hours, preventing any further impact on customers. We believe that this incident has impacted less than one half of one percent of our enterprise accounts globally and a fraction of that within the consumer base.</p></blockquote>
<h3>For More Information:</h3>
<ul>
<li>McAfee: <a href="http://siblog.mcafee.com/support/mcafee-response-on-current-false-positive-issue/" onclick="pageTracker._trackPageview('/outgoing/siblog.mcafee.com/support/mcafee-response-on-current-false-positive-issue/?referer=');">McAfee Response To Current False Positive Issue</a></li>
<li>ZDNet: <a href="http://blogs.zdnet.com/Bott/?p=2003" onclick="pageTracker._trackPageview('/outgoing/blogs.zdnet.com/Bott/?p=2003&amp;referer=');">Defective McAfee update causes worldwide meltdown of XP PCs</a></li>
<li>Syracuse.com: <a href="http://www.syracuse.com/news/index.ssf/2010/04/university_hospital_plagued_by.html" onclick="pageTracker._trackPageview('/outgoing/www.syracuse.com/news/index.ssf/2010/04/university_hospital_plagued_by.html?referer=');">University Hospital computers plagued by anti-virus glitch</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/488/mcafee-anti-virus-goes-bad-lieutenant/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Princeton: No Love for iPad (But no Ban either)</title>
		<link>http://www.voiptechchat.com/tech/483/princeton-doesnt-ban-ipad/</link>
		<comments>http://www.voiptechchat.com/tech/483/princeton-doesnt-ban-ipad/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 12:45:46 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[Princeton]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=483</guid>
		<description><![CDATA[Despite rumors, Princeton has not banned the iPad from campus. It has however, found a bug (and workaround) with Apple&#8217;s latest device. Describing what they feel is a bug with the iPad&#8217;s operating system, Princeton recently announced (via their Knowledge Base): Network monitoring has shown that many iPad devices have caused a problem on the [...]]]></description>
			<content:encoded><![CDATA[
<p>Despite rumors, Princeton has not banned the iPad from campus. It has however, found a bug (and workaround) with Apple&#8217;s latest device.</p>
<p>Describing what they feel is a bug with the iPad&#8217;s operating system, Princeton <a href="http://helpdesk.princeton.edu/outages/view.plx?ID=3095" onclick="pageTracker._trackPageview('/outgoing/helpdesk.princeton.edu/outages/view.plx?ID=3095&amp;referer=');">recently announced</a> (via their Knowledge Base):</p>
<blockquote><p>Network monitoring has shown that many iPad devices have caused a problem on the campus network. These devices continue to use an IP address they have been leased well beyond the time they should. (In technical terms, the device&#8217;s DHCP client software stops renewing its lease, but the device keeps using the IP address after the DHCP lease expires. This is not a WiFi issue.) This behavior causes a disruption on the campus network.</p></blockquote>
<p><span id="more-483"></span>Additionally, Princeton posted an <a href="http://www.net.princeton.edu/announcements/ipad-iphoneos32-stops-renewing-lease-keeps-using-IP-address.html" onclick="pageTracker._trackPageview('/outgoing/www.net.princeton.edu/announcements/ipad-iphoneos32-stops-renewing-lease-keeps-using-IP-address.html?referer=');">extremely thorough description</a> of the problem. Although many articles and news reports have stated that Princeton has &#8220;banned&#8221; the iPad from it&#8217;s network, Princeton assures the public that this simply is not the case. Initially, only the devices having the issue were banned from the network, and those have been allowed to reconnect via a <a href="http://www.net.princeton.edu/ipad/ipad-iphoneos32-dhcp-workaround.html" onclick="pageTracker._trackPageview('/outgoing/www.net.princeton.edu/ipad/ipad-iphoneos32-dhcp-workaround.html?referer=');">workaround</a>.</p>
<blockquote><p>Beginning April 4 2010 (prior to having any workaround), when an individual iPad malfunctioned, we would contact the owner to advise him or her of the problem. When the same iPad malfunctioned a second time, we would block that device from using our network, and contact the owner again; at that time we would advise the owner that the blocks would remain in place until there was a fix from Apple, or there was a workaround to the problem.</p></blockquote>
<p>On a personal note&#8230;</p>
<p>The documentation from Princeton on this issue amazes me. It is extremely detailed and may just have raised the bar for incident reports. They have published steps to reproduce the issue as well as a workaround. AND&#8230; they made these documents available (easily) to the public. There&#8217;s no chest beating, hyperbole, or exaggeration. Just a detailed &#8220;this is the problem, this is what we&#8217;ve done&#8221; document. <a href="http://www.voiptechchat.com/voip/457/amazon-ec2-sip-brute-force-attacks-on-rise/">Amazon should really follow their example</a>.</p>
<p>Links of Interest</p>
<ul>
<li>NJ.com: <a href="http://www.nj.com/news/times/regional/index.ssf?/base/news-19/127182887941370.xml&amp;coll=5" onclick="pageTracker._trackPageview('/outgoing/www.nj.com/news/times/regional/index.ssf?/base/news-19/127182887941370.xml_amp_coll=5&amp;referer=');">Princeton Experiences iPad Problems</a></li>
<li>Princeton: <a href="http://www.net.princeton.edu/announcements/ipad-iphoneos32-stops-renewing-lease-keeps-using-IP-address.html" onclick="pageTracker._trackPageview('/outgoing/www.net.princeton.edu/announcements/ipad-iphoneos32-stops-renewing-lease-keeps-using-IP-address.html?referer=');">iPad/iPhone OS 3.2 Stops Renewing DHCP Lease, Keeps Using IP Address</a></li>
<li>Princeton: <a href="http://www.net.princeton.edu/ipad/ipad-iphoneos32-dhcp-workaround.html" onclick="pageTracker._trackPageview('/outgoing/www.net.princeton.edu/ipad/ipad-iphoneos32-dhcp-workaround.html?referer=');">Workaround for &#8220;iPad/iPhone OS 3.2 Stops Renewing DHCP Lease, Keeps Using IP Address&#8221; Issue</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/483/princeton-doesnt-ban-ipad/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.675 seconds -->
