<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7122745763234660283.post8915532602178811387..comments</id><updated>2011-04-29T22:48:12.216-07:00</updated><category term='jQuery'/><category term='Web Attacks'/><category term='Advisory'/><category term='Applet Security'/><category term='Http Request Splitting'/><category term='Application Security'/><category term='Http Parameter Pollution'/><category term='malware'/><category term='Cross Site Scripting'/><category term='Dom Xss'/><category term='DOMinator'/><category term='WWeb Security'/><category term='Banking'/><category term='Java'/><category term='Information Disclosure'/><category term='Omniture'/><category term='Spring MVC'/><category term='Expression Language Injection'/><category term='Java Security'/><category term='twitter'/><category term='Sharepoint'/><category term='Web Security'/><category term='Client Side HTTP Parameter Pollution'/><category term='JNLP Security'/><category term='JSON'/><category term='Liferay'/><category term='Same Origin Policy'/><category term='Arbitrary Code Execution'/><title type='text'>Comments on Minded Security Blog: Discretionary controls may lead to social engineer...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.mindedsecurity.com/feeds/8915532602178811387/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html'/><author><name>Minded Security</name><uri>http://www.blogger.com/profile/01503616812076743415</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-6886883843467768009</id><published>2011-04-07T10:01:00.340-07:00</published><updated>2011-04-07T10:01:00.340-07:00</updated><title type='text'>Good work! Bests to Minded Security Team.

MGX</title><content type='html'>Good work! Bests to Minded Security Team.&lt;br /&gt;&lt;br /&gt;MGX</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/6886883843467768009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/6886883843467768009'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1302195660340#c6886883843467768009' title=''/><author><name>Massimiliano MGX Graziani</name><uri>http://www.mgx.it</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-738358140'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-3056048697361816642</id><published>2011-03-19T17:06:39.497-07:00</published><updated>2011-03-19T17:06:39.497-07:00</updated><title type='text'>Where can I get anti malware device? And how much?...</title><content type='html'>Where can I get anti malware device? And how much?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/3056048697361816642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/3056048697361816642'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1300579599497#c3056048697361816642' title=''/><author><name>engineering leveling guide</name><uri>http://engineering-leveling-guide.com/what-help-me-with-my-engineering-guide</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1322524450'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-250393279119140748</id><published>2009-06-07T04:32:58.616-07:00</published><updated>2009-06-07T04:32:58.616-07:00</updated><title type='text'>@Jimmy: Thank you

@Travis: You are right. I think...</title><content type='html'>@Jimmy: Thank you&lt;br /&gt;&lt;br /&gt;@Travis: You are right. I think that separators and special characters should be filtered via Input Validation. In addition I would suggest to use some chroma, or a different font type (style and size) to better discriminate from the field and its properties.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/250393279119140748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/250393279119140748'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1244374378616#c250393279119140748' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-8788256359369090147</id><published>2009-06-07T04:24:17.273-07:00</published><updated>2009-06-07T04:24:17.273-07:00</updated><title type='text'>Hi Giorgio, very nice post. You mentioned &amp;quot;Tr...</title><content type='html'>Hi Giorgio, very nice post. You mentioned &amp;quot;Transfer Details&amp;quot;, as it could be bad if they are not displayed on the external device.&lt;br /&gt;&lt;br /&gt;However I think thay displaying on a small LCD the transfer details could open social engineering attacks by abusing this field.&lt;br /&gt;&lt;br /&gt;E.g. Tranfer Detail: Name: Alice, Amount 100 &lt;br /&gt;Could be very misleading&lt;br /&gt;&lt;br /&gt;Good post indeed. Travis Lee</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/8788256359369090147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/8788256359369090147'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1244373857273#c8788256359369090147' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-461662803'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-6940259261337285811</id><published>2009-06-06T05:34:59.631-07:00</published><updated>2009-06-06T05:34:59.631-07:00</updated><title type='text'>Really the social engineering attack could be very...</title><content type='html'>Really the social engineering attack could be very practical for luring the user of banking dongles. A surge is expected in such cases.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/6940259261337285811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/6940259261337285811'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1244291699631#c6940259261337285811' title=''/><author><name>Jimmy</name><uri>http://www.internetdongle.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1442643223'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-292922892938740485</id><published>2009-05-22T12:03:33.833-07:00</published><updated>2009-05-22T12:03:33.833-07:00</updated><title type='text'>You are correct mentioning "Transfer Details". "Tr...</title><content type='html'>You are correct mentioning "Transfer Details". "Transfer Details" may give more room for social engineering attacks if they are not displayed on the external device.&lt;br /&gt;&lt;br /&gt;Since the operator of the receiving institute make his decision upon the information contained in the data transfer, an attacker may forge particular subjects to push the operator in the wrong direction. &lt;br /&gt;&lt;br /&gt;E.g. Inserting some information related to the attacker e.g. Surname, name, etc.. (real owner of destination account)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/292922892938740485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/292922892938740485'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1243019013833#c292922892938740485' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-3303880569175561134</id><published>2009-05-22T11:51:41.581-07:00</published><updated>2009-05-22T11:51:41.581-07:00</updated><title type='text'>I had some security thoughts reading the article. ...</title><content type='html'>I had some security thoughts reading the article. I think that is a pretty known issue, but you give new implications connecting it to Antimalware solutions.&lt;br /&gt;&lt;br /&gt;You did not mention the transfer details. They need to be changed?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/3303880569175561134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/3303880569175561134'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1243018301581#c3303880569175561134' title=''/><author><name>Dr. D. Travis</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-534327338'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-2076958284742113265</id><published>2009-05-22T11:28:48.251-07:00</published><updated>2009-05-22T11:28:48.251-07:00</updated><title type='text'>As mentioned in the article the described social e...</title><content type='html'>As mentioned in the article the described social engineering attack could be very practical for luring the user of "banking dongles" into confirming the transaction. Anti-Malware devices are still not very common, so attacks like the one mentioned are more likely to be encountered in the near future.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/2076958284742113265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/2076958284742113265'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1243016928251#c2076958284742113265' title=''/><author><name>Giorgio Fedon</name><uri>http://www.blogger.com/profile/10261243238330266276</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_vcTLhf3MjL0/SX2S-u9P_iI/AAAAAAAAAAg/1fZmsX7wtRE/S220/giorgio_fedon.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1631116005'/></entry><entry><id>tag:blogger.com,1999:blog-7122745763234660283.post-39839979303538100</id><published>2009-05-22T04:25:00.508-07:00</published><updated>2009-05-22T04:25:00.508-07:00</updated><title type='text'>Nice Article. 

Did you have observed any fraud at...</title><content type='html'>Nice Article. &lt;br /&gt;&lt;br /&gt;Did you have observed any fraud attempt trying to force you so called recipient bank "discretionary controls"?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/39839979303538100'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7122745763234660283/8915532602178811387/comments/default/39839979303538100'/><link rel='alternate' type='text/html' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html?showComment=1242991500508#c39839979303538100' title=''/><author><name>Francois Dera</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.mindedsecurity.com/2009/05/discretionary-controls-may-lead-to.html' ref='tag:blogger.com,1999:blog-7122745763234660283.post-8915532602178811387' source='http://www.blogger.com/feeds/7122745763234660283/posts/default/8915532602178811387' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1346751715'/></entry></feed>
