<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: There sure are a lot of &quot;WTF are we doing?&quot; posts going around</title>
	<atom:link href="http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Thu, 02 Feb 2012 20:22:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Michael</title>
		<link>http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/comment-page-1/#comment-20368</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sat, 20 Oct 2007 13:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/#comment-20368</guid>
		<description>There&#039;s another over at &lt;a href=&quot;http://layer8.itsecuritygeek.com/index/layer8/&quot; rel=&quot;nofollow&quot;&gt;Layer 8&lt;/a&gt;, which is my current fave.  I *know* we&#039;re making a difference.  Look at what the attackers are having to do to beat us;

- Continuously re-engineer their tactics to avoid detection
- Shift from OS attacks to Application attacks because we&#039;ve learned how to aggressively maintain the OS
- Shift to well-known, oft-used ports for C&amp;C because we&#039;re implementing egress filtering to block the C&amp;C channels
- The list goes on...

Keep your chin up and your barrel steady.  I&#039;ve got another HEAT round locked and loaded for ya.</description>
		<content:encoded><![CDATA[<p>There&#8217;s another over at <a href="http://layer8.itsecuritygeek.com/index/layer8/" rel="nofollow">Layer 8</a>, which is my current fave.  I *know* we&#8217;re making a difference.  Look at what the attackers are having to do to beat us;</p>
<p>- Continuously re-engineer their tactics to avoid detection<br />
- Shift from OS attacks to Application attacks because we&#8217;ve learned how to aggressively maintain the OS<br />
- Shift to well-known, oft-used ports for C&amp;C because we&#8217;re implementing egress filtering to block the C&amp;C channels<br />
- The list goes on&#8230;</p>
<p>Keep your chin up and your barrel steady.  I&#8217;ve got another HEAT round locked and loaded for ya.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LonerVamp</title>
		<link>http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/comment-page-1/#comment-20361</link>
		<dc:creator>LonerVamp</dc:creator>
		<pubDate>Fri, 19 Oct 2007 18:08:42 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/10/18/there-sure-are-a-lot-of-wtf-are-we-doing-posts-going-around/#comment-20361</guid>
		<description>We definitely work in a frustrating and draining field. Thankfully, when one or a few of us get down and tired and worn out, there are others of us to encourage and bring us back up. :)

God help us if we all get depressed at once!</description>
		<content:encoded><![CDATA[<p>We definitely work in a frustrating and draining field. Thankfully, when one or a few of us get down and tired and worn out, there are others of us to encourage and bring us back up. <img src='http://infosecplace.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>God help us if we all get depressed at once!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

