<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://172.30.1.245"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Fortinet</title>
 <link>http://172.30.1.245</link>
 <description></description>
 <language>en</language>
<item>
 <title>FortiGate-3950B Performance Validation Report With BreakingPoint Systems</title>
 <link>http://172.30.1.245/report/fortigate_3950b_performance_validation_report_breakingpoint_systems.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;Throughput, or a firewall&#039;s ability to inspect network traffic without dropping packets or degrading the user experience, is one of the most important metrics to consider when selecting an enterprise-class firewall. The FortiGate-3950B from Fortinet delivers 120 Gbps of firewall throughput for packets of any size, ensuring fast network performance and accurate policy enforcement for large corporations and service providers. Unique FortiASIC™ architecture enables near wire-speed performance by &#039;hard-coding&#039; resource-intensive tasks into a dedicated chip, freeing critical CPU cycles for other tasks.To validate firewall throughput in different deployment scenarios, Fortinet conducted rigorous performance testing of the FortiGate-3950B using multiple BreakingPoint Elite chassis and blades in different configurations. Download the report to find out how Fortinet&#039;s custom FortiASIC architecture makes the 3950B a leader in the security appliance market.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-reportfile field-type-file field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Download Report:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;span class=&quot;file&quot;&gt;&lt;img class=&quot;file-icon&quot; alt=&quot;&quot; title=&quot;application/pdf&quot; src=&quot;/modules/file/icons/application-pdf.png&quot; /&gt; &lt;a href=&quot;http://172.30.1.245/sites/default/files/analystreports/FortiGate3950B-Validation-Report_0.pdf&quot; type=&quot;application/pdf; length=277301&quot;&gt;FortiGate3950B-Validation-Report.pdf&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Tue, 01 Nov 2011 00:00:00 +0000</pubDate>
 <dc:creator />
 <guid isPermaLink="false">311 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/report/fortigate_3950b_performance_validation_report_breakingpoint_systems.html#comments</comments>
</item>
<item>
 <title>FortiClient Lite v2.00 (Beta) – For Android!</title>
 <link>http://172.30.1.245/content/forticlient_lite_v200_beta_%E2%80%93_android.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;&lt;img class=&quot;size-full wp-image-3577 alignleft&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/ForiClient-BETA-Logo-NEW_512.png&quot; alt=&quot;&quot; width=&quot;92&quot; height=&quot;92&quot; /&gt;&lt;br /&gt;
We are pleased to announce Android support for FortiClient Lite. Our beta version is now officially &lt;a href=&quot;https://market.android.com/details?id=com.fortinet.forticlient.lite&amp;amp;feature=search_result#?t=W251bGwsMSwxLDEsImNvbS5mb3J0aW5ldC5mb3J0aWNsaWVudC5saXRlIl0.&quot;&gt;available on the Android Marketplace&lt;/a&gt; and features SSL VPN functionality. The FortiClient Android SSL VPN  application works with your organization’s FortiGate security appliance  to establish a secure sockets layer VPN connection.  With this  application, you can work remotely and securely with your organization’s  digital assets anywhere and everywhere you have an Internet connection.&lt;/p&gt;
&lt;p&gt;&lt;img class=&quot;size-full wp-image-3578 alignleft&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/lite01.png&quot; alt=&quot;&quot; width=&quot;353&quot; height=&quot;234&quot; /&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Key Benefits&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Flexible, easy and secure access to your organization’s resources&lt;/li&gt;
&lt;li&gt;Simple set up and configuration&lt;/li&gt;
&lt;li&gt;Uses Fortinet’s award-winning technology&lt;/li&gt;
&lt;li&gt;Keeps you connected and productive on-the-go&lt;/li&gt;
&lt;li&gt;Supports Bookmarks that you define through the FortiGate’s SSL VPN Service Portal&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;img class=&quot;size-full wp-image-3580 alignleft&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/lite18.png&quot; alt=&quot;&quot; width=&quot;142&quot; height=&quot;213&quot; /&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;Android  2.2 and 2.3 is currently supported. FortiClient Lite is also available  for the Windows operating system – please visit FortiClient.com for &lt;a href=&quot;http://www.forticlient.com/lite.html&quot;&gt;more information&lt;/a&gt;. FortiClient Lite for Windows features antivirus and parental controls in addition to SSL and IPSEC VPN.&lt;/p&gt;
&lt;p&gt;&lt;img class=&quot;size-full wp-image-3581 alignleft&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/lite11.png&quot; alt=&quot;&quot; width=&quot;135&quot; height=&quot;203&quot; /&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;FortiClient  Lite is based off of Fortinet’s award winning FortiClient, which has  achieved more than 20 VB100 awards and is capable of detecting threats  on both a reactive and proactive basis. Proactive detection is based on  detecting zero-day malware that has never been seen before in the wild.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Fri, 28 Oct 2011 23:29:25 +0000</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7423 at http://172.30.1.245</guid>
</item>
<item>
 <title>FSM-064</title>
 <link>http://172.30.1.245/content/fsm_064.html</link>
 <description>&lt;div class=&quot;field field-name-field-specversion field-type-text field-label-inline clearfix&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Version:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;4.3&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-specfamily field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;specfamily:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;FortiGateModule&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwfsmslots field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwfsmslots:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwinterfacemgmt field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwinterfacemgmt:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwsizehdd field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwsizehdd:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;64 GB SSD&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwinterfaceacc10g field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwinterfaceacc10g:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwasmslots field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwasmslots:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwinterface field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwinterface:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;64GB SSD Storage Module&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwfmcslots field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwfmcslots:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwinterfaceaccrj45 field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwinterfaceaccrj45:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwinterfacewlan field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwinterfacewlan:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-modulecompatibility field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;modulecompatibility:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;FGT-200B, FGT-200B-POE, FGT-311B, FGT-621B, FGT-1240B, FGT-1240B-DC, FGT-3951B&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-specstatus field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;specstatus:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;Active&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-speclevel field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;speclevel:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;Low-end&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwformfactor field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwformfactor:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;Fortinet Storage Module (FSM)&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwcompliance field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwcompliance:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;FCC Part 15 Class A, C-Tick, VCCI, CE, CB&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwadmslots field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwadmslots:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwusbs field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwusbs:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-hwusbc field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;hwusbc:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-specdescription field-type-text field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;specdescription:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;Fortinet Storage Module  is a 64 GB solid state disk (SSD)&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Wed, 26 Oct 2011 23:28:12 +0000</pubDate>
 <dc:creator>xmlrpc</dc:creator>
 <guid isPermaLink="false">7413 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/content/fsm_064.html#comments</comments>
</item>
<item>
 <title>Clarifying Android DroidKungFu variants</title>
 <link>http://172.30.1.245/content/clarifying_android_droidkungfu_variants.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;Much like Ninja Turtles, DroidKungFu now comes in different flavours (5 so far), discovered by &lt;a href=&quot;http://www.cs.ncsu.edu/faculty/jiang&quot;&gt;Pr. Xuxian Jiang (and research team&lt;/a&gt;) and &lt;a href=&quot;http://blog.mylookout.com/2011/10/security-alert-legacy-makes-a-another-appearance-on-android-market-meet-legacy-native-lena/&quot;&gt;Lookout&lt;/a&gt;. If, like me, you are having difficulties keeping track of those variants, this post is for you :)&lt;/p&gt;
&lt;p&gt;The similarities and differences between all 5 variants are depicted below. The various blocks represent each variant, and their intersection shows how many methods they share exactly*.&lt;/p&gt;
&lt;p&gt;All variants share the same malicious commands (CMD box). They can download and install new package, start a program (called activity), open a given URL in the browser or delete a package**. To do so, they contact the same 3 remote web servers (URLs box), apart from variant A which uses a single one.&lt;/p&gt;
&lt;p&gt;As for differences, mainly, they rely on whether the sample uses exploits or  not (yellow and red knife), whether the malicious functionalities are  implemented natively or not (brown circle or green box) and whether some  payload is encrypted with AES or not (hatched rectangle) and the key it uses. Note that variant E has the particularity of encrypting a few strings to obfuscate its code (/system/bin/chmod 4755, WebView.db.init etc).&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/variants-art.png&quot;&gt;&lt;img class=&quot;size-full wp-image-3553 aligncenter&quot; title=&quot;variants-art&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/variants-art.png&quot; alt=&quot;&quot; width=&quot;634&quot; height=&quot;490&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;A few other similarities are not mentioned on the picture, such as the re-use of filenames and signing certificates. For instance, native code is typically in a file named WebView.db.init, and for certificates, variant A, B and C are signed by the same self-signed Google certificate, whereas variant D and E use a custom certificate.&lt;/p&gt;
&lt;p&gt;References:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Fortinet’s &lt;a href=&quot;http://www.fortiguard.com/antivirus/mobile_threats.html&quot;&gt;detailed virus descriptions&lt;/a&gt;, including details of &lt;strong&gt;&lt;a href=&quot;http://www.fortiguard.com/encyclopedia/virus/android_droidkungfu.b!tr.html&quot;&gt;native part inside version B. &lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://blog.mylookout.com/wp-content/uploads/2011/10/LeNa-Legacy-Native-Teardown_Lookout-Mobile-Security1.pdf&quot;&gt;Lookout’s teardown on LeNa&lt;/a&gt; (aka DroidKungFu)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;– the Crypto Girl&lt;/p&gt;
&lt;p&gt;* Computed using androsim.py from &lt;a href=&quot;http://code.google.com/p/androguard&quot;&gt;Androguard&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;** Actually, variant A features a fifth command, execHomepage, but implements it as “not supported”.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Wed, 26 Oct 2011 15:27:00 +0000</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7410 at http://172.30.1.245</guid>
</item>
<item>
 <title>VB2011 talks, Part 3 (and end)</title>
 <link>http://172.30.1.245/content/vb2011_talks_part_3_and_end.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;This concludes my overview of VB2011, with the final notes for the last tasks I attended.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Enhancing filtering proactivity with reverse IP and reverse whois queries – Claudiu Musat (presenting) and Alin Octavian Damian&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The most typical methods to filter spam is by URLs they contain or domain names. The main problem of those methods is the delay the filter becomes active: somebody has to decide that this URL or domain is malicious, and before that decision is made, the spam is not blocked. There are other methods, which seem more proactive: reverse IP and reverse Whois.&lt;/p&gt;
&lt;p&gt; With reverse Whois methods for instance, the idea is to use Internet domain registrant data, and block other domain names with the same data. In particular, one can build a database of registrant emails, and block all domain names with the same registrant email.&lt;br /&gt; The study shows that combining both methods helps regarding proactivity, i.e that we are able to detect spam URLs earlier than before.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cell Phone Money Laundering – Denis Maslennikov&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;How do cybercriminals make money out of mobile malware in Russia? This is what this talk was about.&lt;br /&gt; In Russia, most people have pre-paid SIM cards, with only a few dollars on it (not much, but enough for cybercriminals). SIM cards are extremely easy to buy, at the corner of any street, and no credential is required to acquire one. Larger sets of SIM cards can be bought from hacking websites. The price is around 0.15 USD per unit.&lt;br /&gt; Then, there are several easy ways to make money and have people send a SMS to a given phone number: ransomware, scams (“mum, unexpected problem: can you replenish my account please?”) etc. Indeed, accounts may be replenished by sending an SMS to the special number 3116 (same scenario as &lt;a href=&quot;http://www.fortiguard.com/search.php?action=search_virus&amp;amp;data=SymbOS/Flocker.AC!tr.python&quot;&gt;SymbOS/Flocker&lt;/a&gt;). Some malware, such as Java/Smmer, use this facility to have the mobile phone automatically send some money to&lt;br /&gt; the cybercriminal’s pre-paid card. Of course, mobile operators have implemented a few security measures so that if all of a sudden a given account is being replenished more than 10 or 20 times, it gets blocked. So, cybercriminals have to use several different numbers.&lt;/p&gt;
&lt;p&gt;So, after a while, cybercriminals have money “on” their SIM cards. They now need to get it out – and launder it. There are several ways for that:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;transfer SIM card money to a bank credit card. Of course, the cybercriminals then need to acquire a carded credit card from underground networks.&lt;/li&gt;
&lt;li&gt;transfer to a bank account or via Unistream: possible, but not anonymous.&lt;/li&gt;
&lt;li&gt;call another short number whose revenue goes in part to the cybercriminals. Some hackers’ forums actually provide this as a service: a (illegal!) third party offers to launder the money against a commission (~30%). The price depends on volumes, speed, clean cash or not etc.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;IEEE Software Taggant System – Mark Kennedy, Igor Muttik&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Many malware use packers to harden reverse engineering of their executable. The goal of the Taggant system is to make packers useless for malware authors, so that, ultimately, they are forced not to use them any longer.&lt;/p&gt;
&lt;p&gt;The Taggant system consists in marking the output of all (legitimate) packers to be able to tell the difference between legitimate use of packers and malicious use. The packed output is automatically tagged by the packer, including license. The taggant relies on PKI and crypto: a hash of vital parts, a default hash of the whole file.&lt;/p&gt;
&lt;p&gt;I would need to have a closer look at the design before making up my mind. I certainly have two questions in mind:&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;if the packed output is hashed twice, once vital parts then another time completely, isn’t that redundant? By the way, there are patents on partially signing parts of executables (not sure if they apply to this particular case, but it exists – it’s not new).&lt;/li&gt;
&lt;li&gt;I find it strange that IEEE’s public key will be licensed to (legitimate) participants. For me, a key is either fully public or private, but not in between. Unless this is a misunderstanding and the speakers meant a private key…  still, licensing a private key also seems strange to me…&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;– the Crypto Girl&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Tue, 25 Oct 2011 14:30:58 +0000</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7404 at http://172.30.1.245</guid>
</item>
<item>
 <title>FortiScan Virtual Appliances</title>
 <link>http://172.30.1.245/datasheet/fortiscan_vm.pdf</link>
 <description>&lt;div class=&quot;field field-name-field-productdatasheet field-type-file field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;span class=&quot;file&quot;&gt;
&lt;img src=&quot;/modules/file/icons/application-pdf.png&quot; title=&quot;application/pdf&quot; class=&quot;file-icon&quot; /&gt;
&lt;a type=&quot;application/pdf&quot; href=&quot;http://172.30.1.245/sites/default/files/productdatasheets/FSC-VM-DAT-R1.1-201109.pdf&quot;&gt;
( PDF )
&lt;/a&gt;
&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Mon, 24 Oct 2011 23:02:58 +0000</pubDate>
 <dc:creator>Gleb</dc:creator>
 <guid isPermaLink="false">7403 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/datasheet/fortiscan_vm.pdf#comments</comments>
</item>
<item>
 <title>Fortinet Reports Record Financial Results</title>
 <link>http://172.30.1.245/press_releases/fortinet_reports_record_financial_results.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;&lt;a href=&quot;http://www.fortinet.com/doc/fortinet_Q311_earnings.pdf&quot;&gt;http://www.fortinet.com/doc/fortinet_Q311_earnings.pdf&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;h4&gt;&lt;p&gt;About Fortinet (&lt;a href=&quot;http://www.fortinet.com&quot;&gt;www.fortinet.com&lt;/a&gt;)&lt;/p&gt;
&lt;/h4&gt;&lt;div class=&quot;field field-name-field-boilerplate2 field-type-text-long field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Fortinet (NASDAQ: FTNT) is a worldwide provider of network security appliances and the market leader in unified threat management (UTM). Our products and subscription services provide broad, integrated and high-performance protection against dynamic security threats while simplifying the IT security infrastructure. Our customers include enterprises, service providers and government entities worldwide, including the majority of the 2009 Fortune Global 100. Fortinet&#039;s flagship FortiGate product delivers ASIC-accelerated performance and integrates multiple layers of security designed to help protect against application and network threats. Fortinet&#039;s broad product line goes beyond UTM to help secure the extended enterprise - from endpoints, to the perimeter and the core, including databases and applications. Fortinet is headquartered in Sunnyvale, Calif., with offices around the world.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;em class=&quot;smaller&quot;&gt;&lt;p&gt;Copyright © 2011 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and unregistered trademarks of Fortinet, Inc., its subsidiaries and affiliates. Fortinet&#039;s trademarks include, but are not limited to, the following: Fortinet, FortiGate, FortiGuard, FortiManager, FortiMail, FortiClient, FortiCare, FortiAnalyzer, FortiReporter, FortiOS, FortiASIC, FortiWiFi, FortiSwitch, FortiVoIP, FortiBIOS, FortiLog, FortiResponse, FortiCarrier, FortiScan, FortiDB and FortiWeb. Other trademarks belong to their respective owners. Fortinet has not independently verified statements or certifications herein attributed to third parties and Fortinet does not independently endorse such statements. Nothing in the news release constitutes a warranty, guaranty, or contractually binding commitment. This news release may contain forward-looking statements that involve uncertainties and assumptions. If the uncertainties materialize or the assumptions prove incorrect, results may differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements, including but not limited to, any statements related to expected trends in cybercriminal activity. These trends are difficult to predict and any stated expectations regarding these trends may not ultimately be correct. Fortinet assumes no obligation to update any forward-looking statements, and does not intend to update these forward-looking statements.&lt;/p&gt;
&lt;/em&gt;</description>
 <pubDate>Mon, 24 Oct 2011 19:35:56 +0000</pubDate>
 <dc:creator>Holly</dc:creator>
 <guid isPermaLink="false">7376 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/press_releases/fortinet_reports_record_financial_results.html#comments</comments>
</item>
<item>
 <title>Fortinet Wins Three Computerworld Readers&#039; Choice Awards in the Categories of Unified Threat Management and Intrusion Detection/Prevention Systems</title>
 <link>http://172.30.1.245/press_releases/111024.html</link>
 <description>&lt;h3&gt;&lt;p&gt;Customers in Singapore and Malaysia Pick the FortiGate family of Integrated Multi-Threat Security Appliances as their Favorite Product&lt;/p&gt;
&lt;/h3&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;&lt;b&gt;SUNNYVALE, Calif., – October 24, 2011&lt;/b&gt; − Fortinet® (NASDAQ: FTNT) − a leading network security provider and worldwide leader of unified threat management (UTM) solutions − today announced that its flagship FortiGate® integrated multi-threat security appliance family has won three Readers’ Choice awards from Computerworld Singapore and Computerworld Malaysia. In Singapore, Fortinet clinched the 16th annual Readers&#039; Choice Award in the category of UTM security, and in Malaysia, the company won the 10th annual Readers&#039; Choice Award in the categories of UTM and Intrusion Detection/Prevention Systems. &lt;/p&gt;
&lt;p&gt;This is the third consecutive year that Fortinet has claimed the Readers&#039; Choice Award for UTM in Singapore and the first time the company has won in Malaysia since its last win in 2008. &lt;/p&gt;
&lt;p&gt;Computerworld&#039;s Readers&#039; Choice awards are presented to vendors that garner the most votes from end-users that pick their favorite products in a number of predetermined categories. The awards represent a strong endorsement by the Singapore and Malaysia markets. This year’s award ceremonies were held at Singapore&#039;s Raffles Hotel and Kuala Lumpur&#039;s Mandarin Oriental Hotel on Oct 21 and Oct 11, respectively. &lt;/p&gt;
&lt;p&gt;“Fortinet is a well-established brand in the UTM market, and this comes across clearly in the number of votes picked up by the company,” said Computerworld Singapore editor Jack Loo. “Functionality, performance and reliability are typical criteria used by our voters so Fortinet must have fared well in these areas, too.&quot; &lt;/p&gt;
&lt;p&gt;&quot;It&#039;s no mean feat to pick up two major awards at one go,” said Computerworld Malaysia editor Avanti Kumar. “That Fortinet managed to do so speaks well of its technology, as well as the reputation and mindshare it has in the Malaysian market.&quot;&lt;/p&gt;
&lt;p&gt;FortiGate consolidated security platforms deliver unmatched performance and protection while simplifying your network. Fortinet offers models to satisfy any deployment requirement from the FortiGate-20 series for small offices to the FortiGate-5000 series for very large enterprises, service providers and carriers. FortiGate platforms combine the FortiOS™ security operating system with FortiASIC processors and latest-generation CPUs to other hardware to provide a comprehensive, high-performance security solution to meet most business needs. &lt;/p&gt;
&lt;p&gt; “We are honored to have won three Computerworld awards,” said George Chang, Fortinet&#039;s regional director for Southeast Asia and Hong Kong. “This is as much an endorsement of our service level as our products. We will continue our strategy to closely engage with our customers and strengthen our partners’ ability to service them.&quot;&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;h4&gt;&lt;p&gt;About Fortinet (&lt;a href=&quot;http://www.fortinet.com&quot;&gt;www.fortinet.com&lt;/a&gt;)&lt;/p&gt;
&lt;/h4&gt;&lt;div class=&quot;field field-name-field-boilerplate2 field-type-text-long field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Fortinet (NASDAQ: FTNT) is a worldwide provider of network security appliances and the market leader in unified threat management (UTM). Our products and subscription services provide broad, integrated and high-performance protection against dynamic security threats while simplifying the IT security infrastructure. Our customers include enterprises, service providers and government entities worldwide, including the majority of the 2011 Fortune Global 100. Fortinet&#039;s flagship FortiGate product delivers ASIC-accelerated performance and integrates multiple layers of security designed to help protect against application and network threats. Fortinet&#039;s broad product line goes beyond UTM to help secure the extended enterprise - from endpoints, to the perimeter and the core, including databases and applications. Fortinet is headquartered in Sunnyvale, Calif., with offices around the world.&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;em class=&quot;smaller&quot;&gt;&lt;p&gt;Copyright © 2011 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and unregistered trademarks of Fortinet, Inc., its subsidiaries and affiliates. Fortinet&#039;s trademarks include, but are not limited to, the following: Fortinet, FortiGate, FortiGuard, FortiManager, FortiMail, FortiClient, FortiCare, FortiAnalyzer, FortiReporter, FortiOS, FortiASIC, FortiWiFi, FortiSwitch, FortiVoIP, FortiBIOS, FortiLog, FortiResponse, FortiCarrier, FortiScan, FortiDB and FortiWeb. Other trademarks belong to their respective owners. Fortinet has not independently verified statements or certifications herein attributed to third parties, such as Computerworld Singapore and Computerworld Malaysia and their representatives, and Fortinet does not independently endorse such statements. Nothing in the news release constitutes a warranty, guaranty, or contractually binding commitment. This news release may contain forward-looking statements that involve uncertainties and assumptions. If the uncertainties materialize or the assumptions prove incorrect, results may differ materially from those expressed or implied by such forward-looking statements and assumptions. All statements other than statements of historical fact are statements that could be deemed forward-looking statements, including but not limited to, any statements related to expected trends in cybercriminal activity. These trends are difficult to predict and any stated expectations regarding these trends may not ultimately be correct. Fortinet assumes no obligation to update any forward-looking statements, and does not intend to update these forward-looking statements.&lt;/p&gt;
&lt;/em&gt;</description>
 <pubDate>Mon, 24 Oct 2011 07:50:30 +0000</pubDate>
 <dc:creator>Holly</dc:creator>
 <guid isPermaLink="false">7375 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/press_releases/111024.html#comments</comments>
</item>
<item>
 <title>[FortiChallenge 2k11] Hint #1</title>
 <link>http://172.30.1.245/content/fortichallenge_2k11_hint_1.html</link>
 <description>&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot; property=&quot;content:encoded&quot;&gt;&lt;p&gt;&lt;img class=&quot;alignleft size-full wp-image-3491&quot; src=&quot;http://blog.fortinet.com/wp-content/uploads/2011/10/sherlock-holmes-silouette-with-text-md.png&quot; alt=&quot;&quot; width=&quot;179&quot; height=&quot;167&quot; /&gt;Stuck on our &lt;a href=&quot;http://blog.fortinet.com/fortihallenge-2k11/&quot;&gt;FortiChallenge 2k11&lt;/a&gt;? Here’s a first hint!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Translations:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;La fin est encore loin surtout quand on est sur le mauvais chemin !&lt;br /&gt; Wrong track, go back!&lt;/p&gt;
&lt;p&gt;La fin est proche, l’anneau est inclus.&lt;br /&gt; Dawn is close, search for the ring.&lt;/p&gt;
&lt;p&gt;Mon precieux&lt;br /&gt; My precious&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Hint:&lt;/strong&gt;&lt;/p&gt;
&lt;pre&gt;-6D01BAE018694CDB446DC7EADBA08BE497A8CBE78BCFE91478AB120B4400E357
-ad23ebc59b720eac0979ead3176de3331ddaa1356466ecc8e8c9fb82f62a6dca
-BCA85F09D8D174844C5D5B80095E6EF595181AAB0CABA9144324418B9F291645
-3EE90318AA2881118B8C09A777D52129E61760CCAE1EF679C744A25E9EB50789
-5868049FE51A60811D2C75C3B8896B956EE42114C568DE47531E436CEA2E0F77&lt;/pre&gt;&lt;p&gt;– the Reverse naM&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Fri, 21 Oct 2011 09:44:31 +0000</pubDate>
 <dc:creator />
 <guid isPermaLink="false">7374 at http://172.30.1.245</guid>
</item>
<item>
 <title>Kerry County Council</title>
 <link>http://172.30.1.245/case_study/kerry_county_council.html</link>
 <description>&lt;div class=&quot;field field-name-field-casestudyfile field-type-file field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;File:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;span class=&quot;file&quot;&gt;&lt;img class=&quot;file-icon&quot; alt=&quot;&quot; title=&quot;application/pdf&quot; src=&quot;/modules/file/icons/application-pdf.png&quot; /&gt; &lt;a href=&quot;http://172.30.1.245/sites/default/files/casestudies/KerryCountyCouncil-CS.pdf&quot; type=&quot;application/pdf; length=87593&quot;&gt;KerryCountyCouncil-CS.pdf&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-industrytags field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Industry Tags:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/taxonomy/term/40&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot;&gt;Government&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-field-customertags field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Customer Tags:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/taxonomy/term/39&quot; typeof=&quot;skos:Concept&quot; property=&quot;rdfs:label skos:prefLabel&quot;&gt;Mid-Enterprise&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Fri, 21 Oct 2011 00:20:53 +0000</pubDate>
 <dc:creator>Holly</dc:creator>
 <guid isPermaLink="false">7373 at http://172.30.1.245</guid>
 <comments>http://172.30.1.245/case_study/kerry_county_council.html#comments</comments>
</item>
</channel>
</rss>

