<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Adtools &#187; Security</title>
	<atom:link href="http://blog.adtools.co.uk/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.adtools.co.uk</link>
	<description>Advertising Operations &#38; Ad Technology, insights from within the world of AdOps.</description>
	<lastBuildDate>Wed, 25 Aug 2010 09:56:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Douglas Crockford on JavaScript and HTML5</title>
		<link>http://blog.adtools.co.uk/douglas-crockford-on-javascript-and-html5/520/</link>
		<comments>http://blog.adtools.co.uk/douglas-crockford-on-javascript-and-html5/520/#comments</comments>
		<pubDate>Mon, 10 May 2010 11:01:55 +0000</pubDate>
		<dc:creator>Sean</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[HTML5]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[Misc]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[standards]]></category>

		<guid isPermaLink="false">http://blog.adtools.co.uk/?p=520</guid>
		<description><![CDATA[Webmonkey have secured themselves some good video interviews last week at Web 2.0 Expo. Here Douglas Crockford talks about the future of Javascript &#038; HTML5.]]></description>
			<content:encoded><![CDATA[<p>Webmonkey have secured themselves some good video interviews last week at Web 2.0 Expo. Here Douglas Crockford talks about the future of Javascript &#038; HTML5.</p>
<div align="center"><object width="640" height="385">
<param name="movie" value="http://www.youtube.com/v/10fnZ2chEYg&#038;color1=0xb1b1b1&#038;color2=0xd0d0d0&#038;hl=en_US&#038;feature=player_embedded&#038;fs=1"></param>
<param name="allowFullScreen" value="true"></param>
<param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/10fnZ2chEYg&#038;color1=0xb1b1b1&#038;color2=0xd0d0d0&#038;hl=en_US&#038;feature=player_embedded&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="385"></embed></object></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.adtools.co.uk/douglas-crockford-on-javascript-and-html5/520/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Contenio &#8211; &#8216;Pre-flighting&#8217; your creative before your you do.</title>
		<link>http://blog.adtools.co.uk/contenio-pre-flighting-your-creative-before-your-you-do/370/</link>
		<comments>http://blog.adtools.co.uk/contenio-pre-flighting-your-creative-before-your-you-do/370/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 10:20:35 +0000</pubDate>
		<dc:creator>Sean</dc:creator>
				<category><![CDATA[AdOps]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Misc]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[decompilation]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[qa]]></category>
		<category><![CDATA[quality assurance]]></category>
		<category><![CDATA[swf]]></category>

		<guid isPermaLink="false">http://blog.adtools.co.uk/?p=370</guid>
		<description><![CDATA[A number of years ago I had a meeting with OneVision, a company used in newspaper/print for pre-production/press Quality Assurance amongst others things. At the time we were looking at trying to resolve issues with badly coded flash ads, where the clickTag() hadn&#8217;t been set properly or been set to CLICKTAG() or cLiCKTag() or some [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.onevision.com/contenio.html"><img src="http://blog.adtools.co.uk/wp-content/uploads/2010/01/contenio.gif" alt="contenio" title="contenio" width="299" height="218" class="alignright size-full wp-image-377" /></a>A number of years ago I had a meeting with <a href="http://www.onevision.com/">OneVision</a>, a company used in newspaper/print for pre-production/press Quality Assurance amongst others things. At the time we were looking at trying to resolve issues with badly coded flash ads, where the clickTag() hadn&#8217;t been set properly or been set to CLICKTAG() or cLiCKTag() or some equally silly alternative. </p>
<p>In the past we used, and still do, tools such as <a href="http://www.sothink.com/product/flashdecompiler/">Sothink SWF Decompiler</a> and <a href="http://www.buraks.com/uae/">URLActionEditor</a> to analyse flash files and amend them accordingly. But enter OneVision wo&#8217;ve been busy in the intervening years and by all accounts have built out a fully-featured pre-flighting tool called <a href="http://www.onevision.com/contenio.html">Contenio</a> for use by online AdOps departments to check and authorise creatives as they come into the department. I haven&#8217;t yet seen the product working but I&#8217;m hopeful it will address some of the ore recurrent themes such as checking for clickTag() case sensitivity/spelling, fix _root. issues, check for embedded urls, check for target=&#8221;_blank&#8221; etc, but hopefully we&#8217;ll get to see this in action soon and report back our findings.</p>
<p>For those of you trying to automate out your QA process this could be of vital interest. I look forward to speaking to someone who&#8217;s currently or planning on working with this soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.adtools.co.uk/contenio-pre-flighting-your-creative-before-your-you-do/370/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flash &amp; Adobe Reader to be prime targets for hackers in 2010</title>
		<link>http://blog.adtools.co.uk/flash-adobe-reader-to-be-prime-targets-for-hackers-in-2010/305/</link>
		<comments>http://blog.adtools.co.uk/flash-adobe-reader-to-be-prime-targets-for-hackers-in-2010/305/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 15:07:56 +0000</pubDate>
		<dc:creator>Sean</dc:creator>
				<category><![CDATA[AdOps]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Misc]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[swf]]></category>

		<guid isPermaLink="false">http://blog.adtools.co.uk/?p=305</guid>
		<description><![CDATA[Mcafee are reporting that Adobe Reader and Flash are to be prime targets for criminal hackers next in 2010. This on the back of this report: http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/ and http://websecurity.com.ua/3789/ My personal take on this is that yes, it could be used as a potential XSS but invariabaly it would have meant that the original 3rd [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://mcafee.com">Mcafee</a> are reporting that Adobe Reader and Flash are to be prime targets for criminal hackers next in 2010.</strong></p>
<p>This on the back of this report:<br />
<a href="http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/">http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/</a> and <a href="http://websecurity.com.ua/3789/">http://websecurity.com.ua/3789/</a></p>
<p>My personal take on this is that yes, it could be used as a potential XSS but invariabaly it would have meant that the original 3rd party adserver had been compromised anyway&#8230; which is a much more serious issue, eg;</p>
<p><a href="http://blog.wareseeker.com/fp/technology-news-events/openx-ad-server-reported-to-be-hacked/">OpenX Ad Server reported to be hacked</a> [2009-12]<br />
<a href="http://www.macworld.co.uk/digitallifestyle/news/index.cfm?newsid=28128">Hackers hit OpenX ad server in Adobe attack</a> [2009-12]<br />
<a href="http://securitylabs.websense.com/content/Alerts/3310.aspx">eWeek Web Site Leads Users to Rogue Anti-Virus (AV) Application</a> [2009-02]<br />
<a href="http://www.computerworld.com.au/article/196980/details_hijacked_24_7_ad_server_emerge/">Details of hijacked 24/7 ad server emerge</a> [2007-10]<br />
<a href="http://blog.washingtonpost.com/securityfix/2006/07/myspace_ad_served_adware_to_mo.html">Hacked Ad Seen on MySpace Served Spyware to a Million</a> [2006-07]<br />
<a href="http://www.theregister.co.uk/2004/11/21/register_adserver_attack/">Bofra exploit hits our ad serving supplier</a> [2004-11]</p>
<p>It&#8217;s full list of threat predictions include:<br />
McAfee Labs foresees an increase in threats related to social networking sites, banking security, and botnets, as well as attacks targeting users, businesses, and applications. However, in 2010 we expect to see an increase in the effectiveness of law enforcement to ight back against cybercrime.</p>
<ul>
<li>Social networking sites such as Facebook will face more sophisticated threats as the number of users grows.</li>
<li>The explosion of applications on Facebook and other services will be an ideal vector for cybercriminals, who will take advantage of friends trusting friends to click links they might otherwise treat cautiously. </li>
<li>HTML 5 will blur the line between desktop and online applications. This, along with the release of Google Chrome OS, will create another opportunity for malware writers to prey on users. </li>
<li>Email attachments have delivered malware for years, yet the increasing number of attacks targeted at corporations, journalists, and individual users often fool them into downloading Trojans and other malware. </li>
<li>Cybercriminals have long picked on Microsoft products due to their popularity. In 2010, we anticipate Adobe software, especially Acrobat Reader and Flash, will take the top spot.</li>
<li>Banking Trojans will become more clever, sometimes interrupting a legitimate transaction to make an unauthorized withdrawal. </li>
<li>Botnets are the leading infrastructure for cybercriminals, used for actions from spamming to identity theft. Recent successes in shutting down botnets will force their controllers to switch to alternate, less vulnerable methods of command, including peer-to-peer setups. </li>
</ul>
<p><strong>PDF report here:</strong> <a href="http://mcafee.com/us/local_content/white_papers/7985rpt_labs_threat_predict_1209_v2.pdf">http://mcafee.com/us/local_content/white_papers/7985rpt_labs_threat_predict_1209_v2.pdf</a></p>
<p><strong>Related Slashdot Article:</strong> <a href="http://it.slashdot.org/story/09/12/29/1435259/Adobe-Flash-To-Be-Top-Hacker-Target-In-2010?from=rss&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed:+Slashdot/slashdot+(Slashdot)">http://it.slashdot.org/story/09/12/29/1435259/Adobe-Flash-To-Be-Top-Hacker-Target-In-2010?from=rss&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed:+Slashdot/slashdot+(Slashdot)</a><br />
<strong>Anothe realated article:</strong> <a href="http://www.itjungle.com/tfh/tfh010410-story09.html">http://www.itjungle.com/tfh/tfh010410-story09.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.adtools.co.uk/flash-adobe-reader-to-be-prime-targets-for-hackers-in-2010/305/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
