<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Michael On Security</title>
	<atom:link href="http://michaelonsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaelonsecurity.com</link>
	<description>Thoughts on IT Management and Security.  Trying to Make it All Come Together.</description>
	<lastBuildDate>Thu, 28 Aug 2008 18:06:17 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
		<url>http://www.gravatar.com/blavatar/3f2d64579fcdbec1173bd70bf3b6725b?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Michael On Security</title>
		<link>http://michaelonsecurity.com</link>
	</image>
			<item>
		<title>Google Helps Me Get Answers From Experts Exchange</title>
		<link>http://michaelonsecurity.com/2008/08/28/google-helps-me-get-answers-from-experts-exchange/</link>
		<comments>http://michaelonsecurity.com/2008/08/28/google-helps-me-get-answers-from-experts-exchange/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 17:45:21 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Musings]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=49</guid>
		<description><![CDATA[update: it appears that Experts Exchange will usually show you the answers at the bottom if the referrer was Google.  If you just copy and paste the url into your browser, the answers will not be there.  Strangeness. 
Talk about a sensational headline, right?  But it is true, all thanks to this nice forum [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=49&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong><em>update: it appears that Experts Exchange will usually show you the answers at the bottom if the referrer was Google.  If you just copy and paste the url into your browser, the answers will not be there.  Strangeness. </em></strong></p>
<p>Talk about a sensational headline, right?  But it is true, all thanks to this nice forum post by <a href="http://hackforums.net/showthread.php?tid=25040">OXY</a>.  The real title of this article ought to be &#8220;If You Would Like Your Data to Remain Private, Don&#8217;t Show it to Google&#8221;.</p>
<p>The premise is simple.  Certain forums, <a href="http://experts-exchange.com">Experts Exchange</a> being a great example, allow Google to index their questions and answers.  This gives them a high page rank for queries relating to technical questions.  When folks like you or I go to Google to find help on a given network problem or operating system error, Experts Exchange always floats to the top.  We click on the link, only to find that the answer is not available to the public &#8211; you have to be a paying member.</p>
<p>I ran into this earlier today while trying to find an answer on some error messages related to IIS.  Google gave me this <a href="http://www.experts-exchange.com/Software/Server_Software/Web_Servers/Microsoft_IIS/Q_22597204.html">url</a>.  As you can see, there were no answers.  After using the Google &#8216;cache&#8217; directive, I was able to view this <a href="http://72.14.205.104/search?hl=en&amp;q=cache%3Ahttp%3A%2F%2Fwww.experts-exchange.com%2FSoftware%2FServer_Software%2FWeb_Servers%2FMicrosoft_IIS%2FQ_22597204.html&amp;btnG=Google+Search">url</a>.   Scroll down, and you have answers.</p>
<p>It is quite simple to put into play: find a URL like this, as &#8216;http://www.foo.com/secretinfo.html&#8217;.  Go to Google, and in the search box just type: &#8216;cache:http://www.foo.com/secretinfo.html&#8217;.</p>
<p>Not too bad, eh?</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/49/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/49/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=49&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/08/28/google-helps-me-get-answers-from-experts-exchange/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Spammers Have Resorted to Kidnapping My Baby</title>
		<link>http://michaelonsecurity.com/2008/08/26/spammers-have-resorted-to-kidnapping/</link>
		<comments>http://michaelonsecurity.com/2008/08/26/spammers-have-resorted-to-kidnapping/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 11:16:03 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Musings]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=46</guid>
		<description><![CDATA[My morning inbox contained an email with the following subject: &#8220;We have hijacked your baby&#8221;.  
The body is as so:
Hey We have hijacked your baby but you must pay once to us $50 000. The details we will send later&#8230; We has attached photo of your fume    
And of course, a zip file was attached [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=46&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>My morning inbox contained an email with the following subject: &#8220;We have hijacked your baby&#8221;.  </p>
<p>The body is as so:</p>
<blockquote><p>Hey We have hijacked your baby but you must pay once to us $50 000. The details we will send later&#8230; We has attached photo of your fume    </p></blockquote>
<p>And of course, a zip file was attached containing some sort of malicious executable archived within a zip.</p>
<p>This was certainly one of the more entertaining pieces of spam / malware that I&#8217;ve received.  To spammers everywhere: if you are going to do it, please use this as your model.  I want to see quality stuff!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/46/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/46/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=46&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/08/26/spammers-have-resorted-to-kidnapping/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>The Wonders of Social Engineering</title>
		<link>http://michaelonsecurity.com/2008/08/23/the-wonders-of-social-engineering/</link>
		<comments>http://michaelonsecurity.com/2008/08/23/the-wonders-of-social-engineering/#comments</comments>
		<pubDate>Sun, 24 Aug 2008 01:04:25 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Musings]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=39</guid>
		<description><![CDATA[It has been a while.  I&#8217;ve been busy, you&#8217;ve been busy.  You&#8217;ve called me, and all you got was my answering machine.  It is hard to put out good material while working and trying to spend time with your family.  I also adopted a pair of kittens that do their damnedest to keep my hands [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=39&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>It has been a while.  I&#8217;ve been busy, you&#8217;ve been busy.  You&#8217;ve called me, and all you got was my answering machine.  It is hard to put out good material while working and trying to spend time with your family.  I also adopted a pair of kittens that do their damnedest to keep my hands off of the keyboard and on them.  I am fending one of them off right now!  </p>
<p>But to all of those that still keep pumping out the posts despite the odds, I salute you!  Onward!</p>
<p>At the <a href="http://www.fogcreek.com">Fog Creek</a> lunch table on Friday, a few of us were chatting about our past (pre-Creek) experiences with social engineering.  The consensus was that if you provide the right environment, a fair amount of people will fall for whatever trick you present.</p>
<p>I shared an experience in which I wanted to see this first hand, and therefore built an external website asking for users to enter their company passwords.  While that sounds silly, I dressed it up with a company logo, and sent out an email to a small sample of people claiming that the website will perform a test on their password strength.  By going through the test, they&#8217;d help protect us all.  This was ten years ago, which was well before phishing schemes became the cool thing.  Oh, I also told them that the test was mandatory.  35% of the sample went along with it, and only a few of the others contacted me to test legitimacy.  I guess the rest just didn&#8217;t want to deal with it.  :-)</p>
<p>I gathered the sample by Googling usenet and the web for email addresses from my company, as that is how any attacker would do it.  I wrote a Perl script and let it go to town.</p>
<p>In the process, I also discovered that our SMTP servers would allow external messages to arrive with a from address of the internal domain.  This would allow any joe on the Internet to connect to our SMTP servers and send email to internal user while masquerading as another internal user.  Not cool, my friends.</p>
<p>These results led me to believe that in order to exploit the trust of your average man, you only need to do two things:</p>
<ol>
<li> give them reasonable assurance that you are a person who has the authority to make the request (in this case, the attacker masquerades as a member of the internal IT staff)</li>
<li>make it known that by following your easy instructions, they are really helping you out</li>
</ol>
<div>People just want to help out.  Make it easy enough for them, and they&#8217;ll do it with little thought.</div>
<div></div>
<div>Have you gone through these sorts of exercises at your place of work?  What techniques do you employ to keep your peers educated on these sorts of attacks?</div>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/39/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/39/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=39&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/08/23/the-wonders-of-social-engineering/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Staying On Top of Things</title>
		<link>http://michaelonsecurity.com/2008/02/19/staying-on-top-of-things/</link>
		<comments>http://michaelonsecurity.com/2008/02/19/staying-on-top-of-things/#comments</comments>
		<pubDate>Wed, 20 Feb 2008 00:48:00 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Musings]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=20</guid>
		<description><![CDATA[Anyone who has ever worked in the world of IT operations knows how hard it is to stay afloat.  We are fighting entropy.  We have a seemingly never ending todo list and people never stop interrupting.  Ever.  It&#8217;s the nature of this business, and we obviously like to hurt&#8230; err&#8230; like [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=20&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Anyone who has ever worked in the world of IT operations knows how hard it is to stay afloat.  We are fighting entropy.  We have a seemingly never ending todo list and people never stop interrupting.  Ever.  It&#8217;s the nature of this business, and we obviously like to hurt&#8230; err&#8230; like a good challange.</p>
<p>So how do you get things done?  Everyone has their own system, and I&#8217;d like to share mine.</p>
<p><span class="Apple-style-span"><strong>First, Come Up With an Organization System</p>
<p></strong></span>I use a text file with <a href="http://www.vim.org/">vim</a>.  Seriously.  It is located on a remote server that I can access from anywhere, and it has a very obvious format:</p>
<pre>Apply patches to front-end IIS servers:
x verify that a policy exists
x schedule change
- apply patch on 2/20/2008 @ 00:01
</pre>
<p>It&#8217;s a no brainer, really.  The first line denotes the goal, and the following lines are the tasks.  After each task is complete, I prepend an &#8216;x&#8217; and immediately write down the next action.  If the goal is realized, then I cut and paste this to the todo.archive file.  Simple as that.  In the morning I scan the list and pick my target.  Every Monday I go through and make sure that everything still fits with reality.</p>
<p>Eventually, I want to add some vim fanciness so that I can navigate the file easier or at least get some nice syntax highlighting.  After that, maybe I&#8217;ll roll a simple Python cgi that can serve up the text file as an alternate interface.  Hell, maybe it&#8217;ll even have a RESTful API of some sorts so that you can have all sorts of interface.  Ahhh&#8230; to dream&#8230; to dream&#8230;</p>
<p>I use the unix utility <a href="http://www.roaringpenguin.com/products/remind">remind</a> to keep up with calendar items.  I find the format clear and it is something I can bend to meet my needs without too much hassle.  <a href="http://www.google.com/calendar">Google Calendar</a> may be a better choice, though.  I haven&#8217;t decided.</p>
<p>All of this data is backed up on a daily basis to Amazon S3 so I can rest easy.</p>
<p><span class="Apple-style-span"><strong>Second, Keep Your Inbox Empty</strong></span><strong></p>
<p></strong>Nothing raises anxiety like clutter.  When I open my email inbox and see a bajillion read items, my mind races.  Rather than do that, make your inbox serve your organization system.  Every email is treated in one of three ways:</p>
<ol>
<li>immediately answered</li>
<li>the goal is extracted and added to my todo list, and the email is moved to the &#8216;archive&#8217; folder</li>
<li>the email is deleted</li>
</ol>
<p>By doing this, I keep the stress level down and don&#8217;t have to dig through piles or email to figure out what I still have to do.  That alone has made a big difference.</p>
<p><span class="Apple-style-span"><strong>Wrapping Up</strong></span><strong> </p>
<p></strong>So, that&#8217;s how I do it.  I&#8217;m no guru, and I&#8217;m sure it can be improved.  </p>
<p>If you&#8217;d like to share your own system and you have a blog, I encourage you to write about it and trackback to this post.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=20&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/19/staying-on-top-of-things/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Put Your Document Library Together!</title>
		<link>http://michaelonsecurity.com/2008/02/12/put-your-document-library-together/</link>
		<comments>http://michaelonsecurity.com/2008/02/12/put-your-document-library-together/#comments</comments>
		<pubDate>Tue, 12 Feb 2008 23:51:52 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Handbook]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[operations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=15</guid>
		<description><![CDATA[If your IT operations team does not have a document library, I suggest you create one right now.  As mentioned earlier, it defines everything you do and takes very little investment to get started.  Install a wiki, make sure it is being backed up, and you are ready to start.
So how do you organize everything?
I&#8217;m [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=15&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If your IT operations team does not have a document library, I suggest you create one right now.  <a href="http://michaelonsecurity.com/2008/01/25/change-management-the-first-step-to-securing-your-environment/">As mentioned earlier</a>, it defines everything you do and takes very little investment to get started.  Install a wiki, make sure it is being backed up, and you are ready to start.</p>
<p>So how do you organize everything?</p>
<p>I&#8217;m one who hates complication, and try to stamp it out whenever I confront (or create) it.  Your front page of your library should contain links to all of your documents.  Don&#8217;t spread them out and hide them on separate pages &#8211; it just makes it harder to find the right one.  If you make it difficult, people stop using it.  We all know this from experience.</p>
<p>I recommend creating a heading for each service that you provide (Active Directory, DHCP, DNS, <a href="http://www.fogbugz.com">FogBugz On Demand</a>, etc, etc), and then bullet point your policies and procedures below.  The first item under each heading can be the general policy for that service, and then order the other documents alphabetically.</p>
<p>Do not worry about getting it right the first time.  You probably won&#8217;t.  Since you&#8217;re storing this all in a wiki, you can easily refactor as things change.</p>
<p>All of this may sound simple and trite, but again, just make sure you have it in place.  If you aren&#8217;t writing it down, then you&#8217;re not doing a good job.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/15/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/15/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=15&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/12/put-your-document-library-together/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Patch Tuesday Fun</title>
		<link>http://michaelonsecurity.com/2008/02/08/patch-tuesday-fun/</link>
		<comments>http://michaelonsecurity.com/2008/02/08/patch-tuesday-fun/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 20:32:38 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Musings]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=18</guid>
		<description><![CDATA[Microsoft has provided a preview for their patch release next week.  I counted a total of 9 remote exploitation vulnerabilities, so start making your plans.  Remember, if you don&#8217;t have one already, it is time to write up a patch deployment policy.  Early on, the goal is to be consistent so that you can start [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=18&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Microsoft has <a href="http://www.microsoft.com/technet/security/bulletin/ms08-feb.mspx">provided a preview</a> for their patch release next week.  I counted a total of 9 remote exploitation vulnerabilities, so start making your plans.  Remember, if you don&#8217;t have one already, it is time to write up a patch deployment policy.  Early on, the goal is to be consistent so that you can start learning about the right way and wrong way to do things in your particular environment.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/18/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/18/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=18&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/08/patch-tuesday-fun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>The Nicest Things&#8230;</title>
		<link>http://michaelonsecurity.com/2008/02/06/the-nicest-things/</link>
		<comments>http://michaelonsecurity.com/2008/02/06/the-nicest-things/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 02:37:58 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[MoS]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[operations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=17</guid>
		<description><![CDATA[&#8230;are emails like this one:
Hi,
I look after about a dozen Unix boxes (mainly Fedora Linux, but also
Solaris, HP-UX and Digital Unix). I came to the conclusion after reading
 your article that I need to formalize updates and document everything on
the wiki a bit more comprehensively. I also came to the conclusion that
anytime I update any [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=17&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>&#8230;are emails like this one:</p>
<blockquote><p>Hi,</p>
<p>I look after about a dozen Unix boxes (mainly Fedora Linux, but also<br />
Solaris, HP-UX and Digital Unix). I came to the conclusion after reading<br />
<a href="http://michaelonsecurity.com/2008/01/25/change-management-the-first-step-to-securing-your-environment/"> your article</a> that I need to formalize updates and document everything on<br />
the wiki a bit more comprehensively. I also came to the conclusion that<br />
anytime I update any system configuration files on any of the servers I<br />
should check them in to the corporate CVS.</p>
<p>You can&#8217;t have too much documentation <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Thanks again for a useful resource.</p>
<p>Cheers,<br />
<font color="#888888">Jan.<br />
</font><span class="WQ9l9c"></span></p></blockquote>
<p>You can&#8217;t beat that!  It is fantastic encouragement, and really makes me feel like I may be able to do some good here.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=17&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/06/the-nicest-things/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>A Statement of Purpose</title>
		<link>http://michaelonsecurity.com/2008/02/06/a-statement-of-purpose/</link>
		<comments>http://michaelonsecurity.com/2008/02/06/a-statement-of-purpose/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 02:31:56 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[MoS]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[operations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.com/?p=16</guid>
		<description><![CDATA[Wanting to do things right around here, I have decided to summarize why I started this weblog and what I really want it to become.  I have run a number of sites in the past, but have had a very hard time keeping them on track.  This one is different, as the domain [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=16&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Wanting to do things right around here, I have decided to summarize why I started this weblog and what I really want it to become.  I have run a number of sites in the past, but have had a very hard time keeping them on track.  This one is different, as the domain name itself doesn&#8217;t leave a whole lot of room for variance. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Every day reminds me that no matter how many years I can claim to have worked in the IT industry, I&#8217;m still a beginner.  Twelve years ago I was a beginner to Microsoft Windows NT 4.0 and to the still young GNU Linux.  Four years later, I was a learning how to keeping my head in a large environment.  Five years from then, I had to figure out how to lead a large team of systems folk in an even larger organization and keep my soul.  I&#8217;m still not sure I made it all the way out of that one.</p>
<p>Today, I&#8217;m the sole systems guy in a thriving software development company.  I have my hands full with keeping up with day-to-day issues, managing risk, planning for the future, being continuously on call, and trying to build a capable operations team from the ground up.  I am regularly amazed that a company so young and so small can challenge me like this &#8211; but it is doing a damned good job.</p>
<p>One of the most frustrating realizations is that there isn&#8217;t a guidebook to lend a hand.  There are shelves full of operations management books out there, but none of them give you any idea as to what the hell you&#8217;re going to do come Monday morning.  The same can be said about a lot of the technical books out there: it is easy to find a book on your favorite Linux distro or a guide to implement Active Directory, but that doesn&#8217;t solve the core problem of how you keep ahead.</p>
<p>Sometimes I think that the technical books on the wall behind me are just pleasant distractions from the mess I live in.  It&#8217;s far easier for me to tinker with something new or arcane than it is to face up to the more immanent and difficult problems.</p>
<p>So this is what is going on: I am going to build a guidebook of sorts on how one can truly take charge of their environment.  It will be concise, and it will be living.  I&#8217;m going to use my posts to cover the topics, and I will write revisions as necessary.  I expect to make mistakes.  In the end, I&#8217;ll have a process that I trust and can use on a daily basis to not only keep things running in a safe and sane manner, but to keep making improvements.</p>
<p>Now, I will drift from time to time to keep things fresh and interesting.  I&#8217;ll ramble about code and and related news here or there.  As an example, I have a small series of articles detailing typical stack smashing techniques that will be fun to polish and publish.  This is a blog, after all &#8211; it is allowed to wear different hats.</p>
<p>There you have it, folks.  Now you know who I am and what I am up to here.  Time to get back to writing.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/16/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/16/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=16&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/06/a-statement-of-purpose/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Authenticating Against Active Directory With Python</title>
		<link>http://michaelonsecurity.com/2008/02/04/authenticating-against-active-directory-with-python/</link>
		<comments>http://michaelonsecurity.com/2008/02/04/authenticating-against-active-directory-with-python/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 20:50:00 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.com/?p=14</guid>
		<description><![CDATA[I&#8217;m a proponent of centralized authentication mechanisms, as the complexity of managing the password database for each system can be overwhelming.   A lot of organizations are already using Microsoft&#8217;s Active Directory product, and it has proven to be rather easy to perform simple authentication against.  I&#8217;m posting this here because it is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=14&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;m a proponent of centralized authentication mechanisms, as the complexity of managing the password database for each system can be overwhelming.   A lot of organizations are already using Microsoft&#8217;s Active Directory product, and it has proven to be rather easy to perform simple authentication against.  I&#8217;m posting this here because it is certainly security related, and I haven&#8217;t seen a quick howto out there covering this specific use case.</p>
<p><b>Prerequisites<br />
</b></p>
<p>I am testing this on a Debian Etch server, and only had to install the &#8216;python-ldap&#8217; package.</p>
<p><b>Code </b></p>
<pre name="code" class="python">

#!/usr/bin/env python

import ldap, sys

# fully qualified path to your ldap server
# if you&#039;d like to use an encrypted channel, just use &#039;ldaps&#039; instead of &#039;ldap&#039;
LDAP_SERVER=&#039;ldap://mydomain.local&#039;

# fully qualified AD user name
LDAP_USERNAME=&#039;myuser@mydomain.local&#039;

# your password
LDAP_PASSWORD=&#039;mypass&#039;

try:
        # build a client
        ldap_client = ldap.initialize(LDAP_SERVER)

        # perform a synchronous bind
        ldap_client.simple_bind_s(LDAP_USERNAME, LDAP_PASSWORD)

except ldap.INVALID_CREDENTIALS, e:
        print &quot;Invalid credentials: &quot;,e
        sys.exit()
except ldap.SERVER_DOWN, e:
        print &quot;Your server appears to be down: &quot;, e
        sys.exit()

# all is well
print &#039;connected!&#039;
ldap_client.unbind()
</pre>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/14/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/14/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=14&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/04/authenticating-against-active-directory-with-python/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
		<item>
		<title>Relocated to WordPress.com</title>
		<link>http://michaelonsecurity.com/2008/02/03/relocated-to-wordpresscom/</link>
		<comments>http://michaelonsecurity.com/2008/02/03/relocated-to-wordpresscom/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 01:49:24 +0000</pubDate>
		<dc:creator>Michael Gorsuch</dc:creator>
				<category><![CDATA[MoS]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress.com]]></category>

		<guid isPermaLink="false">http://michaelonsecurity.wordpress.com/?p=9</guid>
		<description><![CDATA[If you are seeing this, then things are working correctly.  I have moved this site over to WordPress.com.  More details can be found here.
You can expect a new article in a couple of days!
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=9&subd=michaelonsecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If you are seeing this, then things are working correctly.  I have moved this site over to WordPress.com.  More details can be found <a href="http://www.styledbits.com/2008/02/moving-michaelonsecuritycom-to-wordpresscom/">here</a>.</p>
<p>You can expect a new article in a couple of days!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/michaelonsecurity.wordpress.com/9/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/michaelonsecurity.wordpress.com/9/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/michaelonsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/michaelonsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/michaelonsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/michaelonsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/michaelonsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/michaelonsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/michaelonsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/michaelonsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/michaelonsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/michaelonsecurity.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=michaelonsecurity.com&blog=2685004&post=9&subd=michaelonsecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://michaelonsecurity.com/2008/02/03/relocated-to-wordpresscom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9de56d9e6137af5f6876173e6bf22f3c?s=96&#38;d=identicon" medium="image">
			<media:title type="html">michael gorsuch</media:title>
		</media:content>
	</item>
	</channel>
</rss>