<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    
    <title>Frank Heidt - Leviathan Security Group</title>
    <link>http://www.leviathansecurity.com/blog/</link>
    <description></description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.6 - http://www.s9y.org/</generator>
    <pubDate>Thu, 26 Jan 2012 07:09:44 GMT</pubDate>

    <image>
        <url>http://www.leviathansecurity.com/blog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Frank Heidt - Leviathan Security Group - </title>
        <link>http://www.leviathansecurity.com/blog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>An Illustration of the Dichotomies in Security Industry Reportage</title>
    <link>http://www.leviathansecurity.com/blog/archives/13-An-Illustration-of-the-Dichotomies-in-Security-Industry-Reportage.html</link>
    
    <comments>http://www.leviathansecurity.com/blog/archives/13-An-Illustration-of-the-Dichotomies-in-Security-Industry-Reportage.html#comments</comments>
    <wfw:comment>http://www.leviathansecurity.com/blog/wfwcomment.php?cid=13</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.leviathansecurity.com/blog/rss.php?version=2.0&amp;type=comments&amp;cid=13</wfw:commentRss>
    

    <author>nospam@example.com (Frank Heidt)</author>
    <content:encoded>
    On the front page of Google news just now. The difference in the reporting style between the business and technology press has rarely been more stark.&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;http://leviathansecurity.com/blog/uploads/contradiction.jpg&quot; alt=&quot;Leviathan Security Group&quot; /&gt; 
    </content:encoded>

    <pubDate>Wed, 25 Jan 2012 17:00:00 -0700</pubDate>
    <guid isPermaLink="false">http://www.leviathansecurity.com/blog/archives/13-guid.html</guid>
    
</item>
<item>
    <title>Stuxnet Speculation Jumps The Shark</title>
    <link>http://www.leviathansecurity.com/blog/archives/10-Stuxnet-Speculation-Jumps-The-Shark.html</link>
    
    <comments>http://www.leviathansecurity.com/blog/archives/10-Stuxnet-Speculation-Jumps-The-Shark.html#comments</comments>
    <wfw:comment>http://www.leviathansecurity.com/blog/wfwcomment.php?cid=10</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.leviathansecurity.com/blog/rss.php?version=2.0&amp;type=comments&amp;cid=10</wfw:commentRss>
    

    <author>nospam@example.com (Frank Heidt)</author>
    <content:encoded>
    One of the lessons I remember best from my early security career with Uncle Sam was the maxim: “crawl, don’t jump to conclusions.”  Having heard of various &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.securelist.com/en/blog/272/Myrtus_and_Guava_Episode_3&#039;]);&quot;  href=&quot;http://www.securelist.com/en/blog/272/Myrtus_and_Guava_Episode_3&quot; title=&quot;http://www.securelist.com/en/blog/272/Myrtus_and_Guava_Episode_3&quot;&gt;botanic&lt;/a&gt;, &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/my.opera.com/JesusIsLife/blog/stuxnet-myrtus-queen-esther-vs-haman-iran&#039;]);&quot;  href=&quot;http://my.opera.com/JesusIsLife/blog/stuxnet-myrtus-queen-esther-vs-haman-iran&quot; title=&quot;http://my.opera.com/JesusIsLife/blog/stuxnet-myrtus-queen-esther-vs-haman-iran&quot;&gt;historic&lt;/a&gt; and &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/blogs.forward.com/the-shmooze/tags/myrtus/&#039;]);&quot;  href=&quot;http://blogs.forward.com/the-shmooze/tags/myrtus/&quot; title=&quot;http://blogs.forward.com/the-shmooze/tags/myrtus/&quot;&gt;religious&lt;/a&gt; analysis on how the word “myrtus”  - in a build path to a PDB file - clearly indicates that the Israelis are responsible for the Stuxnet worm, I have to conclude that this story has officially jumped the shark. &lt;br /&gt;
&lt;br /&gt;
Here’s what the string in question looks like in ASCII:&lt;br /&gt;
&lt;br /&gt;
b:\myrtus\src\objfre_w2k_x86\i386\guava.pdb&lt;br /&gt;
&lt;br /&gt;
I’ve had a bunch of SCADA security experience back in the day, and specifically with WinCC, so this path looked strangely familiar. What if we take the mystical word “myrtus” and write it like it would appear in the GUI like so: “My RTUs”.&lt;br /&gt;
&lt;br /&gt;
Okay, can we stop speculating now until we have enough collective information?  &lt;br /&gt;
&lt;br /&gt;
Kthxbye.&lt;br /&gt;
&lt;br /&gt;
P.S. Also, this really does highlight how ‘strings’ is not the best tool for reversing.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 04 Oct 2010 20:55:49 -0700</pubDate>
    <guid isPermaLink="false">http://www.leviathansecurity.com/blog/archives/10-guid.html</guid>
    
</item>

</channel>
</rss>
