<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-399</id>
	<title>Nabble - Vulnerability - VulnDiscuss</title>
	<updated>2007-11-27T22:14:06Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/Vulnerability---VulnDiscuss-f399.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Vulnerability---VulnDiscuss-f399.html" />
	<subtitle type="html">This sister-list of VulnWatch allows for discussions about new vulnerabilities. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-14136606</id>
	<title>Microsoft FTP Client Multiple Bufferoverflow Vulnerability</title>
	<published>2007-11-27T22:14:06Z</published>
	<updated>2007-11-27T22:14:06Z</updated>
	<author>
		<name>Rajesh Sethumadhavan</name>
	</author>
	<content type="html">Microsoft FTP Client Multiple Bufferoverflow
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;#####################################################################
&lt;br&gt;&lt;br&gt;XDisclose Advisory &amp;nbsp; &amp;nbsp; &amp;nbsp;: XD100096
&lt;br&gt;Vulnerability Discovered: November 20th 2007
&lt;br&gt;Advisory Reported	: November 28th 2007
&lt;br&gt;Credit &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Rajesh Sethumadhavan
&lt;br&gt;&lt;br&gt;Class	 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Buffer Overflow
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Denial Of Service
&lt;br&gt;Solution Status &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Unpatched
&lt;br&gt;Vendor &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Microsoft Corporation
&lt;br&gt;Affected applications &amp;nbsp; : Microsoft FTP Client
&lt;br&gt;Affected Platform 	: Windows 2000 server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Windows 2000 Professional
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Windows XP
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (Other Versions may be also effected)
&lt;br&gt;&lt;br&gt;#####################################################################
&lt;br&gt;&lt;br&gt;&lt;br&gt;Overview:
&lt;br&gt;Bufferoverflow vulnerability is discovered in
&lt;br&gt;microsoft ftp client. Attackers can crash the ftp
&lt;br&gt;client of the victim user by tricking the user.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Description:
&lt;br&gt;A remote attacker can craft packet with payload in the
&lt;br&gt;&amp;quot;mget&amp;quot;, &amp;quot;ls&amp;quot;, &amp;quot;dir&amp;quot;, &amp;quot;username&amp;quot; and &amp;quot;password&amp;quot;
&lt;br&gt;commands as demonstrated below. When victim execute
&lt;br&gt;POC or specially crafted packets, ftp client will
&lt;br&gt;crash possible arbitrary code execution in contest of
&lt;br&gt;logged in user. This vulnerability is hard to exploit
&lt;br&gt;since it requires social engineering and shellcode has
&lt;br&gt;to be injected as argument in vulnerable commands. 
&lt;br&gt;&lt;br&gt;The vulnerability is caused due to an error in the
&lt;br&gt;Windows FTP client in validating commands like &amp;quot;mget&amp;quot;,
&lt;br&gt;&amp;quot;dir&amp;quot;, &amp;quot;user&amp;quot;, password and &amp;quot;ls&amp;quot;
&lt;br&gt;&lt;br&gt;Exploitation method:
&lt;br&gt;&lt;br&gt;Method 1:
&lt;br&gt;-Send POC with payload to user.
&lt;br&gt;-Social engineer victim to open it.
&lt;br&gt;&lt;br&gt;Method 2:
&lt;br&gt;-Attacker creates a directory with long folder or
&lt;br&gt;filename in his FTP server (should be other than IIS
&lt;br&gt;server)
&lt;br&gt;-Persuade victim to run the command &amp;quot;mget&amp;quot;, &amp;quot;ls&amp;quot; or
&lt;br&gt;&amp;quot;dir&amp;quot; &amp;nbsp;on specially crafted folder using microsoft ftp
&lt;br&gt;client
&lt;br&gt;-FTP client will crash and payload will get executed
&lt;br&gt;&lt;br&gt;&lt;br&gt;Proof Of Concept:
&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/mget.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/mget.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/username.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/username.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/directory.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/directory.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/list.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/list.bat.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;Note: Modify POC to connect to lab FTP Server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; (As of now it will connect to
&lt;br&gt;ftp://xdisclose.com)
&lt;br&gt;&lt;br&gt;Demonstration:
&lt;br&gt;Note: Demonstration leads to crashing of Microsoft FTP
&lt;br&gt;Client
&lt;br&gt;&lt;br&gt;Download POC rename to .bat file and execute anyone of
&lt;br&gt;the batch file
&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/mget.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/mget.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/username.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/username.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/directory.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/directory.bat.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/poc/list.bat.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/poc/list.bat.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Solution:
&lt;br&gt;No Solution
&lt;br&gt;&lt;br&gt;Screenshot:
&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/images/msftpbof.jpg&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/images/msftpbof.jpg&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Impact:
&lt;br&gt;Successful exploitation may allows execution of
&lt;br&gt;arbitrary code with privilege of currently logged in
&lt;br&gt;user.
&lt;br&gt;&lt;br&gt;Impact of the vulnerability is system level.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Original Advisory:
&lt;br&gt;&lt;a href=&quot;http://www.xdisclose.com/advisory/XD100096.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xdisclose.com/advisory/XD100096.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Credits:
&lt;br&gt;Rajesh Sethumadhavan has been credited with the
&lt;br&gt;discovery of this vulnerability
&lt;br&gt;&lt;br&gt;&lt;br&gt;Disclaimer:
&lt;br&gt;This entire document is strictly for educational,
&lt;br&gt;testing and demonstrating purpose only. Modification
&lt;br&gt;use and/or publishing this information is entirely on
&lt;br&gt;your own risk. The exploit code/Proof Of Concept is to
&lt;br&gt;be used on test environment only. I am not liable for
&lt;br&gt;any direct or indirect damages caused as a result of
&lt;br&gt;using the information or demonstrations provided in
&lt;br&gt;any part of this advisory.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ____________________________________________________________________________________
&lt;br&gt;Be a better pen pal. 
&lt;br&gt;Text or chat with friends inside Yahoo! Mail. See how. &amp;nbsp;&lt;a href=&quot;http://overview.mail.yahoo.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://overview.mail.yahoo.com/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Microsoft-FTP-Client-Multiple-Bufferoverflow-Vulnerability-tp14136606p14136606.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-13353301</id>
	<title>PacSec 2007 Agenda (Tokyo 11-29/30)</title>
	<published>2007-10-21T22:42:52Z</published>
	<updated>2007-10-21T22:42:52Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Talk selections for PacSec 2007 - November 29 and 30 - Aoyama Diamond Hall
&lt;br&gt;&lt;br&gt;-------
&lt;br&gt;- Programmed I/O accesses: a threat to virtual machine monitors? - Loic 
&lt;br&gt;Duflot,
&lt;br&gt;&lt;br&gt;- Developing Fuzzers with Peach - Michael Eddington, Leviathan Security
&lt;br&gt;&lt;br&gt;- Cyber Attacks Against Japan - Hiroshi Kawaguchi, LAC
&lt;br&gt;&lt;br&gt;- Windows Localization: Owning Asian Windows Versions - Kostya Kortchinsky, 
&lt;br&gt;Immunity
&lt;br&gt;&lt;br&gt;- TOMOYO Linux - Toshiharu Harada, NTT Data
&lt;br&gt;&lt;br&gt;- IPV6 Demystified - Jun-ichiro itojun Hagino , IPv6Samurais
&lt;br&gt;&lt;br&gt;- Automated JavaScript Deobfuscation - Alex Rice, Websense Security Labs
&lt;br&gt;&lt;br&gt;- Enter Sandman (why you should never go to sleep) - Nicolas Ruff &amp; Matthieu 
&lt;br&gt;Suiche, EADS
&lt;br&gt;&lt;br&gt;- Agent-oriented SQL Abuse - Fernando Russ &amp; Diego Tiscornia, Core
&lt;br&gt;&lt;br&gt;- Bad Ideas: Using a JVM/CLR for Intellectual Property Protection - Marc 
&lt;br&gt;Schoenefeld, University of Bamberg
&lt;br&gt;&lt;br&gt;- Heap exploits are dead. Heap exploits remain dead. And we have killed them. 
&lt;br&gt;- Nicolas Waisman, Immunity
&lt;br&gt;&lt;br&gt;- Deploying and operating a Global Distributed Honeynet - David Watson, 
&lt;br&gt;Honeynet Project
&lt;br&gt;&lt;br&gt;- Office 0days and the people who love them - TBA, Microsoft
&lt;br&gt;.
&lt;br&gt;(I would also like to thank Colin Delaney and Stephen Ridley as standby 
&lt;br&gt;presenters)
&lt;br&gt;&lt;br&gt;------
&lt;br&gt;&lt;br&gt;Final Dojo schedule will be announced shortly but will include
&lt;br&gt;both English and Japanese language dojos. In English Dojos will
&lt;br&gt;include: Saumil Shah's Exploit Lab, Andrea Barisani's Linux Hardening,
&lt;br&gt;and the folks from Immunity doing a course on bugfinding
&lt;br&gt;with the Immunity debugger. In Japanese: Yuji Ukai will be
&lt;br&gt;doing a reverse engineering course, and the McAfee/Foundstone
&lt;br&gt;folks will be translating their Ultimate Web Hacking course into
&lt;br&gt;Japanese for the first time. &amp;nbsp;Dojos will be on Nov 27/28.
&lt;br&gt;&lt;br&gt;Talk descriptions will be up shortly. :-)
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;P.s. other 2008 dates: CanSecWest March 26-28, EUSecWest May21/22
&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Tokyo, Japan &amp;nbsp; &amp;nbsp;November 29/30 - 2007 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/PacSec-2007-Agenda-%28Tokyo-11-29-30%29-tp13353301p13353301.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-13060470</id>
	<title>Re: iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability</title>
	<published>2007-10-04T12:16:02Z</published>
	<updated>2007-10-04T12:16:02Z</updated>
	<author>
		<name>iDefense Labs</name>
	</author>
	<content type="html">Zaraza,
&lt;br&gt;&lt;br&gt;Thank you for pointing out the misleading text. &amp;nbsp;The vulnerability is a
&lt;br&gt;signedness error which leads to information disclosure. &amp;nbsp;We have updated
&lt;br&gt;the advisory to read as follows.
&lt;br&gt;&lt;br&gt;===
&lt;br&gt;negative value can cause large amounts of kernel memory contents to be
&lt;br&gt;disclosed.
&lt;br&gt;===
&lt;br&gt;&lt;br&gt;VeriSign iDefense Labs
&lt;br&gt;&lt;br&gt;&amp;gt; From: 3APA3A &amp;lt;3APA3A_at_SECURITY.NNOV.RU&amp;gt;
&lt;br&gt;&amp;gt; Date: Thu, 4 Oct 2007 20:38:51 +0400
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Dear iDefense Labs,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Can you please clarify this issue? According to subject it looks like
&lt;br&gt;&amp;gt; information leak (information disclosure) issue, while according to
&lt;br&gt;&amp;gt; description, it looks more like memory leak (Denial of Service) issue.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Re%3A-iDefense-Security-Advisory-10.02.07%3A-Sun-Microsystems-Solaris-FIFO-FS-Information-Disclosure-Vulnerability-tp13060470p13060470.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-12156702</id>
	<title>iDefense Security Advisory 08.14.07: Microsoft Windows Vista Sidebar RSS Feeds Gadget Cross Site Scripting Vulnerability</title>
	<published>2007-08-14T16:34:59Z</published>
	<updated>2007-08-14T16:34:59Z</updated>
	<author>
		<name>iDefense Labs</name>
	</author>
	<content type="html">Microsoft Windows Vista Sidebar RSS Feeds Gadget Cross Site Scripting
&lt;br&gt;Vulnerability
&lt;br&gt;&lt;br&gt;iDefense Security Advisory 08.14.07
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/intelligence/vulnerabilities/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/intelligence/vulnerabilities/&lt;/a&gt;&lt;br&gt;Aug 14, 2007
&lt;br&gt;&lt;br&gt;I. BACKGROUND
&lt;br&gt;&lt;br&gt;The Vista sidebar is a desktop extension that allows the user to keep a
&lt;br&gt;number of &amp;quot;gadgets&amp;quot;, which are mini-applications, running in constant
&lt;br&gt;view on the desktop. Vista provides a number of default gadgets, such
&lt;br&gt;as a calendar, a weather tool, and an RSS feed reader.
&lt;br&gt;&lt;br&gt;RSS feeds allow a content provider, such as a website, to let others
&lt;br&gt;receive a stream of &amp;quot;headlines&amp;quot; describing content on the provider's
&lt;br&gt;site. The feeds are often updated frequently, and allow a user to
&lt;br&gt;receive information from a site without having to visit it. For
&lt;br&gt;example, a user may subscribe to a news feed that updates every hour
&lt;br&gt;with the headlines of top news stories. In order to subscribe to a
&lt;br&gt;feed, a user needs a feed reader. Modern browsers, such as Internet
&lt;br&gt;Explorer, provide a feed reader within the browser.
&lt;br&gt;&lt;br&gt;For more information about the Vista Sidebar and Gadgets please see the
&lt;br&gt;following URL.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.microsoft.com/windows/products/windowsvista/features/details/sidebargadgets.mspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/windows/products/windowsvista/features/details/sidebargadgets.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;II. DESCRIPTION
&lt;br&gt;&lt;br&gt;Remote exploitation of a Cross Site Scripting (XSS) vulnerability in the
&lt;br&gt;Windows Vista Sidebar RSS Gadget allows an attacker to execute arbitrary
&lt;br&gt;code with the privileges of the logged in user.
&lt;br&gt;&lt;br&gt;The vulnerability exists within the parsing of the certain elements of
&lt;br&gt;the items in an RSS feed. A properly crafted HTML tag within these
&lt;br&gt;elements will not be removed, and will be rendered by the RSS gadget.
&lt;br&gt;Since the RSS gadget runs in the local zone, the injected JavaScript
&lt;br&gt;has full access to the system.
&lt;br&gt;&lt;br&gt;III. ANALYSIS
&lt;br&gt;&lt;br&gt;Exploitation of this vulnerability will result in the execution of
&lt;br&gt;arbitrary code with the privileges of the user running the RSS gadget.
&lt;br&gt;In order to exploit this, an attacker can inject JavaScript that will
&lt;br&gt;download and execute a malicious binary.
&lt;br&gt;&lt;br&gt;The RSS gadget runs by default, but does not display any feeds unless a
&lt;br&gt;user subscribes to them. As such, a user must be receiving data from a
&lt;br&gt;malicious feed in order to be attacked.
&lt;br&gt;&lt;br&gt;In the most common scenario, this requires some form of social
&lt;br&gt;engineering to convince a user to subscribe to a malicious feed. There
&lt;br&gt;is no way to add a feed by simply clicking a link. The user must click
&lt;br&gt;the 'Subscribe to this feed' button displayed when visiting a feed in
&lt;br&gt;Internet Explorer. After adding the feed, exploitation will occur once
&lt;br&gt;the gadget attempts to display the feed.
&lt;br&gt;&lt;br&gt;Another attack vector that requires significantly less social
&lt;br&gt;engineering requires an attacker control a trusted feed. If an attacker
&lt;br&gt;can find some way to inject data into a trusted feed then they will be
&lt;br&gt;able to exploit any subscribers to the feed.
&lt;br&gt;&lt;br&gt;IV. DETECTION
&lt;br&gt;&lt;br&gt;iDefense has confirmed the existence of this vulnerability in Microsoft
&lt;br&gt;Windows Vista Business. Other versions are suspected to be vulnerable.
&lt;br&gt;&lt;br&gt;V. WORKAROUND
&lt;br&gt;&lt;br&gt;iDefense is currently unaware of any workarounds for this issue.
&lt;br&gt;&lt;br&gt;VI. VENDOR RESPONSE
&lt;br&gt;&lt;br&gt;Microsoft has addressed this vulnerability within MS07-048. For more
&lt;br&gt;information, consult their bulletin at the following URL.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS07-048.mspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.microsoft.com/technet/security/Bulletin/MS07-048.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;VII. CVE INFORMATION
&lt;br&gt;&lt;br&gt;The Common Vulnerabilities and Exposures (CVE) project has assigned the
&lt;br&gt;name CVE-2007-3033 to this issue. This is a candidate for inclusion in
&lt;br&gt;the CVE list (&lt;a href=&quot;http://cve.mitre.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/&lt;/a&gt;), which standardizes names for
&lt;br&gt;security problems.
&lt;br&gt;&lt;br&gt;VIII. DISCLOSURE TIMELINE
&lt;br&gt;&lt;br&gt;03/21/2007 &amp;nbsp;Initial vendor notification
&lt;br&gt;03/21/2007 &amp;nbsp;Initial vendor response
&lt;br&gt;08/14/2007 &amp;nbsp;Coordinated public disclosure
&lt;br&gt;&lt;br&gt;IX. CREDIT
&lt;br&gt;&lt;br&gt;This vulnerability was reported to iDefense by Aviv Raff.
&lt;br&gt;&lt;br&gt;Get paid for vulnerability research
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/methodology/vulnerability/vcp.php&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/methodology/vulnerability/vcp.php&lt;/a&gt;&lt;br&gt;&lt;br&gt;Free tools, research and upcoming events
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;X. LEGAL NOTICES
&lt;br&gt;&lt;br&gt;Copyright © 2007 iDefense, Inc.
&lt;br&gt;&lt;br&gt;Permission is granted for the redistribution of this alert
&lt;br&gt;electronically. It may not be edited in any way without the express
&lt;br&gt;written consent of iDefense. If you wish to reprint the whole or any
&lt;br&gt;part of this alert in any other medium other than electronically,
&lt;br&gt;please e-mail &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=12156702&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;customerservice@...&lt;/a&gt; for permission.
&lt;br&gt;&lt;br&gt;Disclaimer: The information in the advisory is believed to be accurate
&lt;br&gt;at the time of publishing based on currently available information. Use
&lt;br&gt;of the information constitutes acceptance for use in an AS IS condition.
&lt;br&gt;&amp;nbsp;There are no warranties with regard to this information. Neither the
&lt;br&gt;author nor the publisher accepts any liability for any direct,
&lt;br&gt;indirect, or consequential loss or damage arising from use of, or
&lt;br&gt;reliance on, this information.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/iDefense-Security-Advisory-08.14.07%3A-Microsoft-Windows-Vista-Sidebar-RSS-Feeds-Gadget-Cross-Site-Scripting-Vulnerability-tp12156702p12156702.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-12004720</id>
	<title>Really, really, penultimate, PacSec CFP deadline, Aug 10.</title>
	<published>2007-07-31T15:39:18Z</published>
	<updated>2007-07-31T15:39:18Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Some folks have been trying to convince us to extend deadlines,
&lt;br&gt;so being the sticklers we are, we said: no way... But they convinced
&lt;br&gt;us. So to be fair - this is a heads up for others who didn't have time
&lt;br&gt;to submit. :-) We'll try to turn around the selection reviews ASAP,
&lt;br&gt;before the end of August for those who submitted.
&lt;br&gt;&lt;br&gt;cheers, 
&lt;br&gt;--dr 
&lt;br&gt;&lt;br&gt;P.s. The gentleman from McAfee who phoned me about his
&lt;br&gt;submission whose name I've forgotten, we didn't get your
&lt;br&gt;mail, please get back in touch.
&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Tokyo, Japan &amp;nbsp; &amp;nbsp;November 29/30 - 2007 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Really%2C-really%2C-penultimate%2C-PacSec-CFP-deadline%2C-Aug-10.-tp12004720p12004720.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-11440546</id>
	<title>PacSec 2007 Call For Papers (Nov. 29/30, deadline July 27)</title>
	<published>2007-07-03T21:39:12Z</published>
	<updated>2007-07-03T21:39:12Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">&lt;br&gt;PacSec CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;World Security Pros To Converge on Japan
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;TOKYO, Japan -- To address the increasing importance of
&lt;br&gt;&amp;nbsp; &amp;nbsp;information security in Japan, the best known figures in the
&lt;br&gt;&amp;nbsp; &amp;nbsp;international security industry will get together with leading
&lt;br&gt;&amp;nbsp; &amp;nbsp;Japanese researchers to share best practices and technology.
&lt;br&gt;&amp;nbsp; &amp;nbsp;The most significant new discoveries about computer network
&lt;br&gt;&amp;nbsp; &amp;nbsp;hack attacks will be presented at the fifth annual PacSec
&lt;br&gt;&amp;nbsp; &amp;nbsp;conference to be discussed.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;The PacSec meeting provides an opportunity for foreign
&lt;br&gt;&amp;nbsp; &amp;nbsp;specialists to be exposed to Japanese innovation and markets
&lt;br&gt;&amp;nbsp; &amp;nbsp;and collaborate on practical solutions to computer security
&lt;br&gt;&amp;nbsp; &amp;nbsp;issues. In a relaxed setting with a mixture of material
&lt;br&gt;&amp;nbsp; &amp;nbsp;bilingually translated in both English and Japanese the eminent
&lt;br&gt;&amp;nbsp; &amp;nbsp;technologists can socialize and attend training sessions.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Announcing the opportunity to submit papers for the PacSec 2007
&lt;br&gt;&amp;nbsp; &amp;nbsp;network security training conference. The conference will be
&lt;br&gt;&amp;nbsp; &amp;nbsp;held November 29-30th in Tokyo. The conference focuses on
&lt;br&gt;&amp;nbsp; &amp;nbsp;emerging information security tutorials - it will be a bridge
&lt;br&gt;&amp;nbsp; &amp;nbsp;between the international and Japanese information security
&lt;br&gt;&amp;nbsp; &amp;nbsp;technology communities..
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Please make your paper proposal submissions before July 27th,
&lt;br&gt;&amp;nbsp; &amp;nbsp;2007. Slides for the papers must be submitted by October 1st
&lt;br&gt;&amp;nbsp; &amp;nbsp;2007. The conference is November 29th and 30th 2007, presenters
&lt;br&gt;&amp;nbsp; &amp;nbsp;need to be available in the days before to meet with
&lt;br&gt;&amp;nbsp; &amp;nbsp;interpreters.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;A some invited papers have been confirmed, but a limited number
&lt;br&gt;&amp;nbsp; &amp;nbsp;of speaking slots are still available. The conference is
&lt;br&gt;&amp;nbsp; &amp;nbsp;responsible for travel and accomodations for the speakers. If
&lt;br&gt;&amp;nbsp; &amp;nbsp;you have a proposal for a tutorial session then please email a
&lt;br&gt;&amp;nbsp; &amp;nbsp;synopsis of the material and your biography, papers and,
&lt;br&gt;&amp;nbsp; &amp;nbsp;speaking background to secwest07 [at] pacsec.jp . Tutorials are
&lt;br&gt;&amp;nbsp; &amp;nbsp;one hour in length, but with simultaneous translation should be
&lt;br&gt;&amp;nbsp; &amp;nbsp;approximately 45 minutes in English, or Japanese. Only slides
&lt;br&gt;&amp;nbsp; &amp;nbsp;will be needed for the October paper deadline, full text does
&lt;br&gt;&amp;nbsp; &amp;nbsp;not have to be submitted.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;The PacSec conference consists of tutorials on technical
&lt;br&gt;&amp;nbsp; &amp;nbsp;details about current issues, innovative techniques and best
&lt;br&gt;&amp;nbsp; &amp;nbsp;practices in the information security realm. The audiences are
&lt;br&gt;&amp;nbsp; &amp;nbsp;a multi-national mix of professionals involved on a daily basis
&lt;br&gt;&amp;nbsp; &amp;nbsp;with security work: security product vendors, programmers,
&lt;br&gt;&amp;nbsp; &amp;nbsp;security officers, and network administrators. We give
&lt;br&gt;&amp;nbsp; &amp;nbsp;preference to technical details and education for a technical
&lt;br&gt;&amp;nbsp; &amp;nbsp;audience.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;The conference itself is a single track series of presentations
&lt;br&gt;&amp;nbsp; &amp;nbsp;in a lecture theater environment. The presentations offer
&lt;br&gt;&amp;nbsp; &amp;nbsp;speakers the opportunity to showcase on-going research and
&lt;br&gt;&amp;nbsp; &amp;nbsp;collaborate with peers while educating and highlighting
&lt;br&gt;&amp;nbsp; &amp;nbsp;advancements in security products and techniques. The focus is
&lt;br&gt;&amp;nbsp; &amp;nbsp;on innovation, tutorials, and education instead of product
&lt;br&gt;&amp;nbsp; &amp;nbsp;pitches. Some commercial content is tolerated, but it needs to
&lt;br&gt;&amp;nbsp; &amp;nbsp;be backed up by a technical presenter - either giving a
&lt;br&gt;&amp;nbsp; &amp;nbsp;valuable tutorial and best practices instruction or detailing
&lt;br&gt;&amp;nbsp; &amp;nbsp;significant new technology in the products.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Paper proposals should consist of the following information:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;1) Presenter, and geographical location (country of
&lt;br&gt;&amp;nbsp; &amp;nbsp;origin/passport) and contact info (e-mail, postal address,
&lt;br&gt;&amp;nbsp; &amp;nbsp;phone, fax).
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;2) Employer and/or affiliations.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;3) Brief biography, list of publications and papers.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;4) Any significant presentation and educational
&lt;br&gt;&amp;nbsp; &amp;nbsp;experience/background.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;5) Topic synopsis, Proposed paper title, and a one paragraph
&lt;br&gt;&amp;nbsp; &amp;nbsp;description.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;6) Reason why this material is innovative or significant or an
&lt;br&gt;&amp;nbsp; &amp;nbsp;important tutorial.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;7) Where else has this material been presented or submitted?
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;8) Optionally, any samples of prepared material or outlines
&lt;br&gt;&amp;nbsp; &amp;nbsp;ready.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Please forward the above information to secwest07 [at]
&lt;br&gt;&amp;nbsp; &amp;nbsp;pacsec.jp to be considered for placement on the speaker roster.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;P.s. Some other dates of interest are announced:
&lt;br&gt;&lt;br&gt;CanSecWest 2008 March 19-21 see &lt;a href=&quot;http://cansecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cansecwest.com&lt;/a&gt;&lt;br&gt;EUSecWest 2008 May 21/22 see &lt;a href=&quot;http://eusecwest&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest&lt;/a&gt;&lt;br&gt;&lt;br&gt;P.P.S.
&lt;br&gt;&lt;br&gt;Also as a friendly reminder, CCC Camp is Aug 8 -12 2008, see 
&lt;br&gt;&lt;a href=&quot;http://events.ccc.de/camp/2007/Intro&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://events.ccc.de/camp/2007/Intro&lt;/a&gt;&amp;nbsp;(Hi Julia et al...) 
&lt;br&gt;&lt;br&gt;Happy Independence Day and &amp;nbsp;Canada Day,
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Tokyo, Japan &amp;nbsp; &amp;nbsp;November 29/30 - 2007 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/PacSec-2007-Call-For-Papers-%28Nov.-29-30%2C-deadline-July-27%29-tp11440546p11440546.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9869930</id>
	<title>iDefense Security Advisory 04.03.07: Multiple Vendor Kerberos kadmind Buffer Overflow Vulnerability</title>
	<published>2007-04-03T13:21:48Z</published>
	<updated>2007-04-03T13:21:48Z</updated>
	<author>
		<name>iDefense Labs</name>
	</author>
	<content type="html">Multiple Vendor Kerberos kadmind Buffer Overflow Vulnerability
&lt;br&gt;&lt;br&gt;iDefense Security Advisory 04.03.07
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/intelligence/vulnerabilities/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/intelligence/vulnerabilities/&lt;/a&gt;&lt;br&gt;Apr 03, 2007
&lt;br&gt;&lt;br&gt;I. BACKGROUND
&lt;br&gt;&lt;br&gt;Kerberos is a network authentication protocol. It is used in
&lt;br&gt;client-server systems to provide user authentication by using a ticket
&lt;br&gt;based system. kadmind is the Kerberos administration server. It is used
&lt;br&gt;to configure principals and policies on the Kerberos. More information
&lt;br&gt;can be found on the vendor's website at the following URL.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://web.mit.edu/Kerberos/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://web.mit.edu/Kerberos/&lt;/a&gt;&lt;br&gt;&lt;br&gt;II. DESCRIPTION
&lt;br&gt;&lt;br&gt;Remote exploitation of a buffer overflow vulnerability in the Kerberos
&lt;br&gt;kadmind server, as included in various vendors' operating system
&lt;br&gt;distributions, could allow attackers to execute arbitrary code on a
&lt;br&gt;targeted host.
&lt;br&gt;&lt;br&gt;The vulnerability exists within the server's logging function,
&lt;br&gt;klog_vsyslog(). A call is made to vsprintf(), with the destination
&lt;br&gt;buffer passed as a fixed size stack buffer. User input is not properly
&lt;br&gt;validated before being passed to this function, and a stack based
&lt;br&gt;buffer overflow can occur.
&lt;br&gt;&lt;br&gt;III. ANALYSIS
&lt;br&gt;&lt;br&gt;Exploitation allows an attacker to execute arbitrary code with root
&lt;br&gt;privileges on the targeted host.
&lt;br&gt;&lt;br&gt;In order to exploit this vulnerability, an attacker must have valid
&lt;br&gt;credentials stored on the server. Administrator privileges are not
&lt;br&gt;necessary. The kadmind server runs on the master Kerberos server. Since
&lt;br&gt;the master server holds the KDC principal and policy database, a
&lt;br&gt;compromise could lead to a compromise of multiple hosts that use the
&lt;br&gt;server for authentication.
&lt;br&gt;&lt;br&gt;IV. DETECTION
&lt;br&gt;&lt;br&gt;iDefense has confirmed the existence of this vulnerability with Kerberos
&lt;br&gt;version 1.5.1 on Fedora CORE 5. It is likely that all distributions that
&lt;br&gt;contain this version of Kerberos are vulnerable.
&lt;br&gt;&lt;br&gt;V. WORKAROUND
&lt;br&gt;&lt;br&gt;iDefense is currently unaware of any workarounds for this issue.
&lt;br&gt;&lt;br&gt;VI. VENDOR RESPONSE
&lt;br&gt;&lt;br&gt;The MIT Kerberos team has made patches available to address this
&lt;br&gt;vulnerability. For more information consult their advisory at the
&lt;br&gt;following URL.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-002-syslog.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2007-002-syslog.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;VII. CVE INFORMATION
&lt;br&gt;&lt;br&gt;The Common Vulnerabilities and Exposures (CVE) project has assigned the
&lt;br&gt;name CVE-2007-0957 to this issue. This is a candidate for inclusion in
&lt;br&gt;the CVE list (&lt;a href=&quot;http://cve.mitre.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/&lt;/a&gt;), which standardizes names for
&lt;br&gt;security problems.
&lt;br&gt;&lt;br&gt;VIII. DISCLOSURE TIMELINE
&lt;br&gt;&lt;br&gt;02/08/2007 &amp;nbsp;Initial vendor notification
&lt;br&gt;02/08/2007 &amp;nbsp;Initial vendor response
&lt;br&gt;04/03/2007 &amp;nbsp;Coordinated public disclosure
&lt;br&gt;&lt;br&gt;IX. CREDIT
&lt;br&gt;&lt;br&gt;The discoverer of this vulnerability wishes to remain anonymous.
&lt;br&gt;&lt;br&gt;Get paid for vulnerability research
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/methodology/vulnerability/vcp.php&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/methodology/vulnerability/vcp.php&lt;/a&gt;&lt;br&gt;&lt;br&gt;Free tools, research and upcoming events
&lt;br&gt;&lt;a href=&quot;http://labs.idefense.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://labs.idefense.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;X. LEGAL NOTICES
&lt;br&gt;&lt;br&gt;Copyright © 2007 iDefense, Inc.
&lt;br&gt;&lt;br&gt;Permission is granted for the redistribution of this alert
&lt;br&gt;electronically. It may not be edited in any way without the express
&lt;br&gt;written consent of iDefense. If you wish to reprint the whole or any
&lt;br&gt;part of this alert in any other medium other than electronically,
&lt;br&gt;please e-mail &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9869930&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;customerservice@...&lt;/a&gt; for permission.
&lt;br&gt;&lt;br&gt;Disclaimer: The information in the advisory is believed to be accurate
&lt;br&gt;at the time of publishing based on currently available information. Use
&lt;br&gt;of the information constitutes acceptance for use in an AS IS condition.
&lt;br&gt;&amp;nbsp;There are no warranties with regard to this information. Neither the
&lt;br&gt;author nor the publisher accepts any liability for any direct,
&lt;br&gt;indirect, or consequential loss or damage arising from use of, or
&lt;br&gt;reliance on, this information.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/iDefense-Security-Advisory-04.03.07%3A-Multiple-Vendor-Kerberos-kadmind-Buffer-Overflow-Vulnerability-tp9869930p9869930.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9536127</id>
	<title>Conflict of Interest - My summary</title>
	<published>2007-03-17T12:33:30Z</published>
	<updated>2007-03-17T12:33:30Z</updated>
	<author>
		<name>NGSSoftware Insight Security Research-3</name>
	</author>
	<content type="html">One point of view that was raised whereby it could possibly be determined 
&lt;br&gt;that an OS vendor providing security applications to protect it's OS was a 
&lt;br&gt;conflict of interest is as follows:
&lt;br&gt;&lt;br&gt;&amp;quot;IMHO I think the fear has always been that as long as an OS was closed 
&lt;br&gt;source, that company owning that OS could write or have inside knowledge of 
&lt;br&gt;vulnerability information that would benefit or promote that security 
&lt;br&gt;product more than another company. This could almost be classified like 
&lt;br&gt;insider trading.&amp;quot;
&lt;br&gt;&lt;br&gt;Whilst this statement is somewhat true, many of the security vendors offer 
&lt;br&gt;up many other enterprise solutions to their customers that are not all about 
&lt;br&gt;protecting the end user from an 'attack'.
&lt;br&gt;&lt;br&gt;Whilst the install base may not be as big as that of an OS Vendor, many of 
&lt;br&gt;these enterprise solutions can be critical to the daily operation of a 
&lt;br&gt;business. &amp;nbsp;So any vulnerabilities found in these products, these security 
&lt;br&gt;vendors can mitigate the risk at day zero by applying IPS / IDS signatures 
&lt;br&gt;to their existing product range in the absence of a patch.
&lt;br&gt;&lt;br&gt;Are they likely to share this zero day information with their competition, I 
&lt;br&gt;think not.
&lt;br&gt;&lt;br&gt;Also, is it really such a bad thing that an OS vendor who offers up Security 
&lt;br&gt;Applications can immediately protect its customer base at almost day zero 
&lt;br&gt;when a vulnerability has been reported to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9536127&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secure@...&lt;/a&gt; by adding the 
&lt;br&gt;protection capability within its Secuirity Apps. &amp;nbsp;At this point the vendor 
&lt;br&gt;knows their customers in the interim are protected, whilst they get down to 
&lt;br&gt;examining the area of code for the flaw, determine if there are any more 
&lt;br&gt;vulnerabilities and then produce a patch.
&lt;br&gt;&lt;br&gt;Another good example is Oracle, they have their Database Vault, which is 
&lt;br&gt;'designed' to add an additional layer of security to protect their database 
&lt;br&gt;and their customer. &amp;nbsp;This is clearly a responsible approach, but I do not 
&lt;br&gt;hear any complaints or shouts of a conflict of interest by those that 
&lt;br&gt;produce 'Database IDS / IPS' solutions.
&lt;br&gt;&lt;br&gt;There will always be the argument that an OS vendor should not charge for 
&lt;br&gt;the OS and then charge for the additional security protection, but for some 
&lt;br&gt;vendors, they may have no other alternative as it may pave the way for a 
&lt;br&gt;lawyers banquet which they would most likely lose in the end. &amp;nbsp;(I am no 
&lt;br&gt;laywer, but one could easily forsee, every security vendor filing Anti-Trust 
&lt;br&gt;law suits, they would have to, they need to protect their business and their 
&lt;br&gt;shareholders)
&lt;br&gt;&lt;br&gt;There will also, always be the arguement from security vendors that (and 
&lt;br&gt;lets be honest about it, they are only talking about Microsoft here), that 
&lt;br&gt;MS should share zero day vulnerabilities with them so that they can offer 
&lt;br&gt;the same level of protection within their security solutions. &amp;nbsp;This is 
&lt;br&gt;unlikely to ever happen (would they share their zero days with MS ?) &amp;nbsp;Of all 
&lt;br&gt;the applications out there, do they get zero day information from any other 
&lt;br&gt;vendor such as Sun, IBM, HP, Apple etc, again I think not.
&lt;br&gt;&lt;br&gt;My original email, was to get a wider well informed view of opinions on the 
&lt;br&gt;subject to determine if my belief was right / wrong.
&lt;br&gt;&lt;br&gt;So I guess my opinion in conclusion still stands, that ANY software vendor 
&lt;br&gt;who looks to add additional layers of security (free or not), it (IMHO) is 
&lt;br&gt;not a conflict of interest and serves the end user well. &amp;nbsp;By what ever means 
&lt;br&gt;necessary, it should be the responsibility of the vendor to include / offer 
&lt;br&gt;increased 'peace of mind'.
&lt;br&gt;&lt;br&gt;Thanks to all those that contributed
&lt;br&gt;&lt;br&gt;All the best
&lt;br&gt;&lt;br&gt;Mark 
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Conflict-of-Interest---My-summary-tp9536127p9536127.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9535694</id>
	<title>Your Opinion +</title>
	<published>2007-03-16T16:10:59Z</published>
	<updated>2007-03-16T16:10:59Z</updated>
	<author>
		<name>NGSSoftware Insight Security Research-3</name>
	</author>
	<content type="html">A common comment being made is that a Vendor who creates and sells and OS, 
&lt;br&gt;and then sells security applications to protect their OS is a conflict of 
&lt;br&gt;interest.
&lt;br&gt;&lt;br&gt;Consider the Anti-Trust law suits filed against MS by AOL regarding IE and 
&lt;br&gt;RealNetworks regarding Windows Media Player back in 2003, lets say for 
&lt;br&gt;discussion, MS now turn around and offer up their 'Security Applications' 
&lt;br&gt;for free. &amp;nbsp;You know exactly what is going to happen.
&lt;br&gt;&lt;br&gt;(I believe the main issue with AOL and Real Networks was that IE and WMP 
&lt;br&gt;were bundled within the OS.)
&lt;br&gt;&lt;br&gt;I guess my point is, whilst I appreciate the common comment, what other 
&lt;br&gt;options are available to an OS vendor. &amp;nbsp;Offer it up as a free download (not 
&lt;br&gt;bundled within the OS) allowing the end user to make the decision, or to 
&lt;br&gt;carry on charging for it ?
&lt;br&gt;&lt;br&gt;Another common theme has been, that the OS should be secure in the first 
&lt;br&gt;place. &amp;nbsp;Again I agree with this, but as someone indicated developers 
&lt;br&gt;schedules are being dictated by their marketing departments with shipment 
&lt;br&gt;dates, so regardless of their intentions to code securely a vulnerability is 
&lt;br&gt;likely slip through.
&lt;br&gt;&lt;br&gt;With regard to third party security solutions outside of the OS vendor, in 
&lt;br&gt;reality how many new security issues does their software introduce to a 
&lt;br&gt;fully patched OS.
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Your-Opinion-%2B-tp9535694p9535694.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9535607</id>
	<title>Re: Your Opinion</title>
	<published>2007-03-16T14:25:32Z</published>
	<updated>2007-03-16T14:25:32Z</updated>
	<author>
		<name>George Yobst</name>
	</author>
	<content type="html">&lt;br&gt;Ummm, hhheeelllooo. &amp;nbsp;Given the MS security history, Genuine
&lt;br&gt;Advantage (phone home), etc, would you really trust their
&lt;br&gt;decisions and software? &amp;nbsp;I, for one, will be running Wireshark
&lt;br&gt;on any new MS implementations (when I get them). &amp;nbsp;I do think
&lt;br&gt;it's applaudable that they are trying to increase security,
&lt;br&gt;but they have a long way to go yet (and trust is something
&lt;br&gt;that needs to be demonstrated, not dictated).
&lt;br&gt;-George
&lt;br&gt;PS - At least we're not talking about Oracle ;-)
&lt;br&gt;&lt;br&gt;On Fri, 16 Mar 2007, Mark Litchfield wrote:
&lt;br&gt;&lt;br&gt;| I have heard the comment &amp;quot;It's a huge conflict of interest&amp;quot; for one company
&lt;br&gt;| to provide both an operating platform and a security platform&amp;quot; made by John
&lt;br&gt;| Thompson (CEO Symantec) many times from many different people. &amp;nbsp;See article
&lt;br&gt;| below.
&lt;br&gt;|
&lt;br&gt;| &lt;a href=&quot;http://www2.csoonline.com/blog_view.html?CID=32554&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www2.csoonline.com/blog_view.html?CID=32554&lt;/a&gt;&lt;br&gt;|
&lt;br&gt;| In my personal opinion, regardless of the vendor, if they create an OS, why
&lt;br&gt;| would it be a conflict of interest for them to want to protect their own OS
&lt;br&gt;| from attack. &amp;nbsp;One would assume that this is a responsible approach by the
&lt;br&gt;| vendor, but one could also argue that their OS should be coded securely in
&lt;br&gt;| the first place. &amp;nbsp;If this were to happen then the need for the Symantec's,
&lt;br&gt;| McAfee's of the world would some what diminsh.
&lt;br&gt;|
&lt;br&gt;| Anyway I am just curious as to what other people think.
&lt;br&gt;|
&lt;br&gt;| Thanks in advance
&lt;br&gt;|
&lt;br&gt;| Mark
&lt;br&gt;|
&lt;br&gt;|
&lt;br&gt;| --
&lt;br&gt;| This message has been scanned for viruses and
&lt;br&gt;| dangerous content by MailScanner, and is
&lt;br&gt;| believed to be clean.
&lt;br&gt;|
&lt;br&gt;|
&lt;br&gt;&lt;br&gt;---------------------------------------------------------------------------
&lt;br&gt;George Yobst, Library Technology Analyst &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;phone: 503.723.4890
&lt;br&gt;Library Information Network of Clackamas County &amp;nbsp; fax: 503.794.8238
&lt;br&gt;16239 SE McLoughlin Blvd, Suite 208 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; web: &lt;a href=&quot;http://www.lincc.lib.or.us&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.lincc.lib.or.us&lt;/a&gt;&lt;br&gt;Oak Grove, OR 97267-4654 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;email: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9535607&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;george@...&lt;/a&gt;
&lt;br&gt;&amp;quot;...it is impossible for anyone to begin to learn
&lt;br&gt;&amp;nbsp;what he thinks he already knows.&amp;quot; &amp;nbsp;- Epictetus
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Your-Opinion-tp9535483p9535607.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9535556</id>
	<title>RE: Your Opinion</title>
	<published>2007-03-16T14:15:32Z</published>
	<updated>2007-03-16T14:15:32Z</updated>
	<author>
		<name>Scott Blake</name>
	</author>
	<content type="html">Wouldn't it be wonderful if we could have this discussion without mentioning
&lt;br&gt;the M-word?
&lt;br&gt;&lt;br&gt;It seems to me that the OS vendor's ethical obligation is to produce the
&lt;br&gt;most secure platform they reasonably can and to fix any and all problems in
&lt;br&gt;it for free. &amp;nbsp;Beyond that, lots of security problems exploit weaknesses in
&lt;br&gt;things other than the OS (like, say, the users) and there will always be a
&lt;br&gt;place (market?) for protection against those things regardless of how secure
&lt;br&gt;the OS platform is.
&lt;br&gt;&lt;br&gt;Further, I'd bet that most of us are fans of defense in depth. &amp;nbsp;Even if an
&lt;br&gt;OS was as secure as it could be and patches were free and ubiquitous,
&lt;br&gt;wouldn't it be prudent to layer something on top of that? &amp;nbsp;If the OS vendor
&lt;br&gt;is acting ethically, following the obligations mentioned above, what
&lt;br&gt;difference could it make who produces the layered security product?
&lt;br&gt;&lt;br&gt;The so-called conflict of interest arises from the perception, rightly or
&lt;br&gt;wrongly, that the OS vendor might be tempted to act in a less than ethical
&lt;br&gt;manner. &amp;nbsp;If we presume ethics always and punish severely ethical lapses
&lt;br&gt;(which we should do regardless), it doesn't matter who produces the security
&lt;br&gt;platform.
&lt;br&gt;&lt;br&gt;It would be most interesting to have a poll on this subject, both of the
&lt;br&gt;security community and the public at large.
&lt;br&gt;&lt;br&gt;Scott
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Mark Litchfield [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9535556&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Mark@...&lt;/a&gt;] 
&lt;br&gt;Sent: Friday, March 16, 2007 2:49 PM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9535556&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bugtraq@...&lt;/a&gt;; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9535556&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;vulnwatch@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9535556&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;full-disclosure@...&lt;/a&gt;
&lt;br&gt;Subject: Your Opinion
&lt;br&gt;&lt;br&gt;I have heard the comment &amp;quot;It's a huge conflict of interest&amp;quot; for one company
&lt;br&gt;to provide both an operating platform and a security platform&amp;quot; made by John
&lt;br&gt;Thompson (CEO Symantec) many times from many different people. &amp;nbsp;See article
&lt;br&gt;below.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www2.csoonline.com/blog_view.html?CID=32554&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www2.csoonline.com/blog_view.html?CID=32554&lt;/a&gt;&lt;br&gt;&lt;br&gt;In my personal opinion, regardless of the vendor, if they create an OS, why
&lt;br&gt;would it be a conflict of interest for them to want to protect their own OS
&lt;br&gt;from attack. &amp;nbsp;One would assume that this is a responsible approach by the
&lt;br&gt;vendor, but one could also argue that their OS should be coded securely in
&lt;br&gt;the first place. &amp;nbsp;If this were to happen then the need for the Symantec's,
&lt;br&gt;McAfee's of the world would some what diminsh.
&lt;br&gt;&lt;br&gt;Anyway I am just curious as to what other people think.
&lt;br&gt;&lt;br&gt;Thanks in advance
&lt;br&gt;&lt;br&gt;Mark 
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Your-Opinion-tp9535483p9535556.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9535483</id>
	<title>Your Opinion</title>
	<published>2007-03-16T12:48:30Z</published>
	<updated>2007-03-16T12:48:30Z</updated>
	<author>
		<name>NGSSoftware Insight Security Research-3</name>
	</author>
	<content type="html">I have heard the comment &amp;quot;It's a huge conflict of interest&amp;quot; for one company 
&lt;br&gt;to provide both an operating platform and a security platform&amp;quot; made by John 
&lt;br&gt;Thompson (CEO Symantec) many times from many different people. &amp;nbsp;See article 
&lt;br&gt;below.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www2.csoonline.com/blog_view.html?CID=32554&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www2.csoonline.com/blog_view.html?CID=32554&lt;/a&gt;&lt;br&gt;&lt;br&gt;In my personal opinion, regardless of the vendor, if they create an OS, why 
&lt;br&gt;would it be a conflict of interest for them to want to protect their own OS 
&lt;br&gt;from attack. &amp;nbsp;One would assume that this is a responsible approach by the 
&lt;br&gt;vendor, but one could also argue that their OS should be coded securely in 
&lt;br&gt;the first place. &amp;nbsp;If this were to happen then the need for the Symantec's, 
&lt;br&gt;McAfee's of the world would some what diminsh.
&lt;br&gt;&lt;br&gt;Anyway I am just curious as to what other people think.
&lt;br&gt;&lt;br&gt;Thanks in advance
&lt;br&gt;&lt;br&gt;Mark 
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Your-Opinion-tp9535483p9535483.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9444957</id>
	<title>Windows Multimedia mmioRead Denial of Service Vulnerability</title>
	<published>2007-03-11T05:34:03Z</published>
	<updated>2007-03-11T05:34:03Z</updated>
	<author>
		<name>Michał Majchrowicz</name>
	</author>
	<content type="html">It is possible to create specialy malformed audio file that will cause DoS
&lt;br&gt;in application,
&lt;br&gt;that uses winmm.dll library to access media files. According to MSDN:
&lt;br&gt;&lt;br&gt;&lt;br&gt;The mmioRead function reads a specified number of bytes from a file opened
&lt;br&gt;by using the mmioOpen function. &amp;nbsp;LONG mmioRead(
&lt;br&gt;&amp;nbsp; HMMIO hmmio,
&lt;br&gt;&amp;nbsp; HPSTR pch,
&lt;br&gt;&amp;nbsp; LONG cch
&lt;br&gt;);
&lt;br&gt;&lt;br&gt;&lt;br&gt;Parameters
&lt;br&gt;&lt;br&gt;hmmio
&lt;br&gt;&lt;br&gt;File handle of the file to be read.
&lt;br&gt;&lt;br&gt;pch
&lt;br&gt;&lt;br&gt;Pointer to a buffer to contain the data read from the file.
&lt;br&gt;&lt;br&gt;cch
&lt;br&gt;&lt;br&gt;Number of bytes to read from the file.
&lt;br&gt;&lt;br&gt;Return Values
&lt;br&gt;&lt;br&gt;Returns the number of bytes actually read. If the end of the file has been
&lt;br&gt;reached and no more bytes can be read, the return value is 0. If there is an
&lt;br&gt;error reading from the file, the return value is - 1.
&lt;br&gt;&lt;br&gt;As we can see when we pass to big in cch parameter the function should
&lt;br&gt;return -1. This is not what happens. When pussing very large value for
&lt;br&gt;instance 0xFFFFFFFF the function mmioRead enters endless loop. A Proof of
&lt;br&gt;Concept WAVE file has been created and it's available at:
&lt;br&gt;&lt;a href=&quot;http://sectroyer.110mb.com/mmio_die.wav&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sectroyer.110mb.com/mmio_die.wav&lt;/a&gt;. When this file is opened by
&lt;br&gt;application SndRec32 it will cause 100% CPU consumption.
&lt;br&gt;Michael Majchrowicz.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Windows-Multimedia-mmioRead-Denial-of-Service-Vulnerability-tp9444957p9444957.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9367047</id>
	<title>ANNOUNCE:  Security OPUS San Francisco, CA - March 19-21, 2007</title>
	<published>2007-03-07T17:32:29Z</published>
	<updated>2007-03-07T17:32:29Z</updated>
	<author>
		<name>Steve Manzuik-2</name>
	</author>
	<content type="html">From Richard over at Security OPUS
&lt;br&gt;&lt;br&gt;-Steve
&lt;br&gt;&lt;br&gt;---------------------------------------
&lt;br&gt;&lt;br&gt;Security OPUS Speaker Selection Finalized
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://SecurityOPUS.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://SecurityOPUS.com&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; March 19th-21st, 2007 in San Francisco, Ca
&lt;br&gt;&lt;br&gt;Please look for the final speakers list to appear by Monday March 5th.
&lt;br&gt;Thank you all for submitting papers.
&lt;br&gt;&lt;br&gt;Security OPUS is a single-track conference geared toward security
&lt;br&gt;professionals and administrators responsible for enterprise security. The
&lt;br&gt;talks are longer for a more indepth discussion and to allow more time for
&lt;br&gt;demonstrations. The environment is set up to give the attendee more
&lt;br&gt;networking and enrichment time.
&lt;br&gt;&lt;br&gt;Registration is still open.
&lt;br&gt;&lt;br&gt;Thanks again,
&lt;br&gt;&lt;br&gt;Richard Lindberg
&lt;br&gt;Organizer
&lt;br&gt;&lt;a href=&quot;http://SecurityOPUS.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://SecurityOPUS.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ANNOUNCE%3A--Security-OPUS-San-Francisco%2C-CA---March-19-21%2C-2007-tp9367047p9367047.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-8803749</id>
	<title>Re: Preliminary CFP:The 2nd International Conference on Availability, Reliability and Security (ARES 07), Vienna, Austria, April 10-13, 2007</title>
	<published>2007-02-05T02:16:32Z</published>
	<updated>2007-02-05T02:16:32Z</updated>
	<author>
		<name>mercurylife guard</name>
	</author>
	<content type="html">Dear Sir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;The Mercury Life Guard, we have registered &amp;nbsp;three of our delegates for the coming Conference, below are their names &amp;nbsp; 
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Mr: ADEGBUYI AYANNUGA
&lt;br&gt;Mr: USMAN IDRIS JATTO
&lt;br&gt;Mr &amp;nbsp;JATTO ALIU OMOLAJA
&lt;br&gt;&amp;nbsp;
&lt;br&gt;we have make all the necessary traveling arrangement, kindly issue letter of invitation for the delegates. we want the letter to be writing in Austria language and English language and attach the copies before you mail out original to our address. 
&lt;br&gt;&lt;br&gt;Looking forward to hearing from you very soon
&lt;br&gt;&lt;br&gt;Best regards
&lt;br&gt;Mr Aliu
&lt;br&gt;Mercury Life Guard
&lt;br&gt;26 Obalende Road 
&lt;br&gt;Ikoyi Lagos 
&lt;br&gt;3401 Nigeria
&lt;br&gt;phone:+2348080501924
&lt;br&gt;fax: &amp;nbsp;+234012646802
&lt;br&gt;Email:mercurylifeguard@gmail.com
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Manh Tho wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Apologies for multiple copies due to cross postings. Please send to
&lt;br&gt;interested colleagues and students.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Preliminary Call for Papers
&lt;br&gt;---------------------------------------------------------------------
&lt;br&gt;The Second International Conference on Availability, Reliability
&lt;br&gt;and Security (AReS)
&lt;br&gt;ARES 2007 - &amp;quot;The International Security and Dependability
&lt;br&gt;Conference&amp;quot;
&lt;br&gt;---------------------------------------------------------------------
&lt;br&gt;April 10th – April 13th, 2007
&lt;br&gt;Vienna University of Technology, Austria
&lt;br&gt;&lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;&lt;br&gt;&lt;br&gt;Conference
&lt;br&gt;-----------
&lt;br&gt;The 1st International Conference on Availability, Reliability and
&lt;br&gt;Security conference (ARES 2006) has been succesfully organized in
&lt;br&gt;Vienna, AUSTRIA from April 20 to April 22, 2006 by the Technical
&lt;br&gt;University of Vienna in cooperation with the European Network and
&lt;br&gt;Security Agency (ENISA). We have attracted 250 participants for this
&lt;br&gt;conference with its 3 keynotes speakers and its 9 workshops held
&lt;br&gt;in conjunction with.
&lt;br&gt;&lt;br&gt;In continuation of the successful 1st ARES conference, The Second
&lt;br&gt;International Conference on Availability, Reliability and Security
&lt;br&gt;(&amp;quot;ARES 2007 – The International Security and Dependability
&lt;br&gt;Conference&amp;quot;) will bring together researchers and practitioners in the
&lt;br&gt;area of IT-Security and Dependability.
&lt;br&gt;&lt;br&gt;ARES 2007 will highlight the various aspects of security – with
&lt;br&gt;special focus on secure internet solutions, trusted computing, digital
&lt;br&gt;forensics, privacy and organizational security issues.
&lt;br&gt;&lt;br&gt;ARES 2007 aims at a full and detailed discussion of the research
&lt;br&gt;issues of security as an integrative concept that covers amongst
&lt;br&gt;others availability, safety, confidentiality, integrity,
&lt;br&gt;maintainability and security in the different fields of applications.
&lt;br&gt;&lt;br&gt;Important Dates
&lt;br&gt;----------------
&lt;br&gt;* &amp;nbsp;Workshop Proposal: September, 10th 2006
&lt;br&gt;* &amp;nbsp;Submission Deadline: November, 19th 2006
&lt;br&gt;* &amp;nbsp;Author Notification: January, 7th 2007
&lt;br&gt;* &amp;nbsp;Author Registration: January, 21st 2007
&lt;br&gt;* &amp;nbsp;Proceedings Version: January, 21st 2007
&lt;br&gt;&lt;br&gt;Workshop Proposal
&lt;br&gt;-----------------
&lt;br&gt;In conjunction with the AReS2007 conference, a number of workshops
&lt;br&gt;will be organised. Workshop proposals which should include the call
&lt;br&gt;for papers, the number of papers to be accepted, the contact person,
&lt;br&gt;etc. are to be sent to the Workshop Organizing Committee
&lt;br&gt;(tho@ifs.tuwien.ac.at), by September 10th 2006. Proceedings of the
&lt;br&gt;ARES 2007 workshops will be published by IEEE Computer Society Press.
&lt;br&gt;&lt;br&gt;Topics of interest include, but are not limited to:
&lt;br&gt;----------------------------------------------------
&lt;br&gt;* Process based Security Models and Methods
&lt;br&gt;* Authorization and Authentication
&lt;br&gt;* Availability and Reliability
&lt;br&gt;* Common Criteria Protocol
&lt;br&gt;* Cost/Benefit Analysis
&lt;br&gt;* Cryptographic protocols
&lt;br&gt;* Dependability Aspects for Special Applications (e.g. ERP-Systems, Logistics)
&lt;br&gt;* Dependability Aspects of &amp;nbsp;Electronic Government (e-Government)
&lt;br&gt;* Dependability administration
&lt;br&gt;* Dependability in Open Source Software
&lt;br&gt;* Designing Business Models with security requirements
&lt;br&gt;* Digital Forensics
&lt;br&gt;* E-Commerce Dependability
&lt;br&gt;* Failure Prevention
&lt;br&gt;* IPR of Security Technology
&lt;br&gt;* Incident Response and Prevention
&lt;br&gt;* Information Flow Control
&lt;br&gt;* Internet Dependability
&lt;br&gt;* Interoperability aspects
&lt;br&gt;* Intrusion Detection and Fraud Detection
&lt;br&gt;* Legal issues
&lt;br&gt;* Mobile Security
&lt;br&gt;* Network Security
&lt;br&gt;* Privacy-enhancing technologies
&lt;br&gt;* RFID Security and Privacy
&lt;br&gt;* Risk planning, analysis &amp; awareness
&lt;br&gt;* Safety Critical Systems
&lt;br&gt;* Secure Enterprise Architectures
&lt;br&gt;* Security Issues for Ubiquitous Systems
&lt;br&gt;* Security and Privacy in E-Health
&lt;br&gt;* Security and Trust Management in P2P and Grid applications
&lt;br&gt;* Security and privacy issues for sensor networks, wireless/mobile
&lt;br&gt;devices and applications
&lt;br&gt;* Security as Quality of Service
&lt;br&gt;* Security in Distributed Systems / Distributed Databases
&lt;br&gt;* Security in Electronic Payments
&lt;br&gt;* Security in Electronic Voting
&lt;br&gt;* Software Engineering of Dependable Systems
&lt;br&gt;* Software Security
&lt;br&gt;* Standards, Guidelines and Certification
&lt;br&gt;* Survivability of Computing Systems
&lt;br&gt;* Temporal Aspects of Dependability
&lt;br&gt;* Trusted Computing
&lt;br&gt;* Tools for Dependable System Design and Evaluation
&lt;br&gt;* Trust Models and Trust Management
&lt;br&gt;* VOIP/Wireless Security
&lt;br&gt;&lt;br&gt;Submission Guidelines
&lt;br&gt;----------------------
&lt;br&gt;Authors are invited to submit research and application papers
&lt;br&gt;following the IEEE Computer Society Proceedings
&lt;br&gt;Manuscripts style: two columns, single-spaced, including figures and
&lt;br&gt;references, using 10 fonts, and number
&lt;br&gt;each page. You can confirm the IEEE Computer Society Proceedings
&lt;br&gt;Author Guidelines at the following web page:
&lt;br&gt;URL: &lt;a href=&quot;http://computer.org/cspress/instruct.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://computer.org/cspress/instruct.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Web site for paper registration and electronic submission will be
&lt;br&gt;accessible from the first week of October 2006. Please refer to ARES
&lt;br&gt;website (&lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&amp;nbsp;or &lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;)
&lt;br&gt;for update information.
&lt;br&gt;&lt;br&gt;Honorary Co-Chairs
&lt;br&gt;-------------------
&lt;br&gt;Norman Revell, Middlesex University, United Kingdom
&lt;br&gt;Roland Wagner, University of Linz, Austria
&lt;br&gt;&lt;br&gt;General Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Guenther Pernul, University of Regensburg, Germany
&lt;br&gt;Makoto Takizawa, Tokyo Denki University, Japan
&lt;br&gt;&lt;br&gt;Program Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Gerald Quirchmayr, University of Southern Australia, Australia
&lt;br&gt;A Min Tjoa, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;&lt;br&gt;Workshops Co-Chairs
&lt;br&gt;--------------------
&lt;br&gt;Nguyen Manh Tho, Vienna University of Technology, Austria
&lt;br&gt;Abdelkader Hameurlain, University of Toulouse, France
&lt;br&gt;Leonard Barolli, Fukuoka Institute of Technology (FIT), Japan
&lt;br&gt;&lt;br&gt;&lt;br&gt;International Liaison Co-Chairs
&lt;br&gt;--------------------------------
&lt;br&gt;Maria Wimmer, University of Koblenz-Landau, Germany
&lt;br&gt;Charles Shoniregun, University of East London, United Kingdom
&lt;br&gt;&lt;br&gt;Publicity Chair
&lt;br&gt;----------------
&lt;br&gt;Vladimir Marik, Czech Technical University, Czech Republic
&lt;br&gt;&lt;br&gt;Publication Chair
&lt;br&gt;------------------
&lt;br&gt;Monika Lanzenberger, Norwegian University of Science and Technology,
&lt;br&gt;Trondheim, Norway
&lt;br&gt;&lt;br&gt;Local Organizing Chairs
&lt;br&gt;------------------------
&lt;br&gt;Maria Schweikert, Vienna University of Technology, Austria
&lt;br&gt;Markus Klemen, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;Programme Committee
&lt;br&gt;--------------------
&lt;br&gt;TBD
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Preliminary-CFP%3AThe-2nd-International-Conference-on-Availability%2C-Reliability-and-Security-%28ARES-07%29%2C-Vienna%2C-Austria%2C-April-10-13%2C-2007-tp5340696p8803749.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-8462113</id>
	<title>EUSecWest 2007 Papers</title>
	<published>2007-01-18T15:59:49Z</published>
	<updated>2007-01-18T15:59:49Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;For those who asked, we are still processing the submissions for CanSecWest
&lt;br&gt;and the call closed, please stand by. The paper selections are back from the
&lt;br&gt;reviewers for EUSecWest, in London on March 1-2.
&lt;br&gt;&lt;br&gt;In absolutely random order:
&lt;br&gt;&lt;br&gt;Threats against and protection of Microsoft's internal network - Greg Galford, 
&lt;br&gt;Microsoft
&lt;br&gt;Linux Kernel == Security Nightmare - Marcel Holtmann, Red Hat
&lt;br&gt;/GS and ASLR in Windows Vista - Ollie Whitehouse, Symantec
&lt;br&gt;Fuzzing: history, perspectives and limits - Christian Wieser, Oulu university
&lt;br&gt;The new OWASP Web Application Penetration Testing Methodology - Matteo Meucci 
&lt;br&gt;&amp; Alberto Revelli, OWASP-Italy
&lt;br&gt;Reverse Engineering Malicious Javascript - Jose Nazario, Ph.D., Arbor
&lt;br&gt;Bypassing NAC Systems - Ofir Arkin, Insightix
&lt;br&gt;RFID - Adam Laurie, trifinite
&lt;br&gt;Protecting Next-Gen Networks @ Nx10G link sizes - Jim Deleskie, Teleglobe
&lt;br&gt;Video Conferencing Security - Navid Jam, Sandia National Laboratories
&lt;br&gt;Software Virtualization Based Rootkits - Sun Bing
&lt;br&gt;VoIP Attacks! - Dustin D. Trammell, TippingPoint
&lt;br&gt;Windows Vista Exploitation Countermeasures - Richard Johnston, Microsoft
&lt;br&gt;OSX Security - Daniel Cuthbert, Corsaire
&lt;br&gt;Distributed drone-based malware propagation and deployment automation - 
&lt;br&gt;Emmanuel H
&lt;br&gt;&lt;br&gt;We have added a new RFID dojo in London with Adam, and Nico 
&lt;br&gt;has a new VoIP Security dojo amongst the new dojos to be announced
&lt;br&gt;for CanSecWest along with the paper selections. Dojos for London 
&lt;br&gt;have final schedules now.
&lt;br&gt;&lt;br&gt;cheers,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. &amp;nbsp; &amp;nbsp;Mar 1-2 - 2007 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/EUSecWest-2007-Papers-tp8462113p8462113.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-8172626</id>
	<title>Re: [VulnWatch] High Risk Vulnerability in the OpenOffice and StarOffice Suites</title>
	<published>2007-01-04T12:55:08Z</published>
	<updated>2007-01-04T12:55:08Z</updated>
	<author>
		<name>Florian Weimer</name>
	</author>
	<content type="html">* NGSSoftware Insight Security Research:
&lt;br&gt;&lt;br&gt;&amp;gt; The vulnerabilities, three heap overflows, affect OpenOffice 2.1.0 and
&lt;br&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://download.openoffice.org/2.1.0/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://download.openoffice.org/2.1.0/index.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;As far as I can tell, there is no version newer than 2.1.0 available
&lt;br&gt;at the web site. &amp;nbsp;According to uncorroborated, version 2.1.0 is not
&lt;br&gt;affected.
&lt;br&gt;&lt;br&gt;Would anyone please clarify the situation? &amp;nbsp;Thanks.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Re%3A--VulnWatch--High-Risk-Vulnerability-in-the-OpenOffice-and-StarOffice-Suites-tp8172626p8172626.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-8126373</id>
	<title>Online Gambling-Online Black Jack-Black Jack Casino-Online Slots-Slots Online</title>
	<published>2007-01-02T08:25:07Z</published>
	<updated>2007-01-02T08:25:07Z</updated>
	<author>
		<name>nursesex</name>
	</author>
	<content type="html">&lt;script language=&quot;javascript&quot; src=&quot;http://www.rewardsaffiliates.com/members/affiliate/rotating_banner.asp?width=468&amp;height=60&amp;aff_id=62960&amp;cid=0&quot;&gt;&lt;/script&gt;
&lt;br&gt;
&lt;script language=&quot;javascript&quot; src=&quot;http://www.rewardsaffiliates.com/members/affiliate/rotating_banner.asp?width=468&amp;height=60&amp;aff_id=62960&amp;cid=0&quot;&gt;&lt;/script&gt;
&lt;br&gt;
&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;cfp-2 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message&quot;&gt;
Hi,

RUXCON is quickly approaching yet again. This e-mail is to bring you up
to date on the latest developments on this years conference.

Our speakers list is complete [1] and our timetable has been finalised
[2]. Below is a list of presentations for RUXCON 2005 (in order of
acceptance):

   1. Breaking Mac OSX - Ilja Van Sprundel &amp; Neil Archibald
   2. Binary protection schemes - Andrew Griffiths
   3. Using OWASP Guide 2.0 for Deep Penetration Testing - Andrew van
der Stock
   4. Black Box Web Application Penetration Testing - David Jorm
   5. Long Filename, Long Parameter, Malformed Data. Another Day,
Another Vulnerability. Same Bug, Different App. - Brett Moore
   6. Computer Forensics: Practise and Procedure - Adam Daniel
   7. Poker Paranoia - Sean Burford
   8. Moving towards the Artificial Hacker - Ashley Fox
   9. Attack automation - Roelof Temmingh
  10. Electronic Evidence - a Law Enforcement Perspective - Jason
Beckett
  11. Beyond NX: An attackers guide to anti-exploitation technology for
Windows - Ben Nagy
  12. Crypto Rodeo - Amy Beth Corman
  13. Trust Transience: Post Intrusion SSH Hijacking - Metlstorm
  14. Attacking WiFi with traffic injection - Cedric &quot;Sid&quot; Blanche
  15. Securing Modern Web Applications - Nik Cubrilovic
  16. Malware Analysis - Nicolas Brulez
  17. Deaf, Dumb and Mute: Defeating Network Intrusion Detection Systems (NIDS) - Christian Heinrich

As in previous years, there will be activities and competitions, which
allow attendees to have fun, win prizes, and socialise, all while
enjoying a cold beer on an Australian summers day.

Some activities which will be held during the conference include:

  * Capture the flag
  * Reverse engineering
  * Exploit development
  * Chilli eatoff
  * Trivia

This will be the third year in a row in which we've brought a quality
conference to the Australian computer security community.

Hope to see you there.

Regards,

RUXCON Staff
http://www.ruxcon.org.au

[1] http://www.ruxcon.org.au/2005-presentations.shtml
[2] http://www.ruxcon.org.au/2005-timetable.shtml


&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;


&lt;a href=&quot;http://www.www-online-blackjack.info&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Online Black Jack&lt;/a&gt;&lt;div class=&quot;signature&quot;&gt;&lt;a href=http://buy-viagra-where.freehostia.com target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Where to buy viagra&lt;/a&gt;&lt;br&gt;&lt;a href=http://buy.acomplia-24.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy cheap acomplia&lt;/a&gt;&lt;br&gt;&lt;a href=http://www.acomplia-24.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy cheap generic &amp;nbsp;acomplia&lt;/a&gt;&lt;br&gt;&lt;a href=http://www.www-pharmacy-online.com target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Generic Pharmacy Online&lt;/a&gt;&lt;br&gt;&lt;a href=http://www.buy-viagra-where.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy viagra where&lt;/a&gt;&lt;br&gt;&lt;a href=http://reddit.com/user/donar27 target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy cheap viagra where&lt;/a&gt;&lt;br&gt;&lt;a href=http://reddit.com/user/buy-viagra-where-inf/ target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy cheap viagra where&lt;/a&gt;&lt;br&gt;&lt;a href=http://cheap.acomplia-24.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Buy cheap acomplia&lt;/a&gt;&lt;br&gt;&lt;a href=http://generic.acomplia-24.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;cheap generic acomplia&lt;/a&gt;&lt;br&gt;&lt;a href=http://order.acomplia-24.info target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Order cheap acomplia&lt;/a&gt;&lt;br&gt;&lt;a href=http://www.buy-albenza-generic.info/ target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;Order cheap Albenza&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/RUXCON-2005-Update-tp897216p8126373.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-7876349</id>
	<title>CanSecWest 2007 (April 18-20) Call For Papers (Deadline Jan 7th)</title>
	<published>2006-12-13T15:57:55Z</published>
	<updated>2006-12-13T15:57:55Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">CanSecWest 2007 CALL FOR PAPERS
&lt;br&gt;&lt;br&gt;VANCOUVER, Canada -- The eighth annual CanSecWest applied technical security 
&lt;br&gt;conference - where the eminent figures in the international security industry 
&lt;br&gt;will get together share best practices and technology - will be held in 
&lt;br&gt;downtown Vancouver at the the Mariott Renaissance Harbourside on April 18-20, 
&lt;br&gt;2007. The most significant new discoveries about computer network hack 
&lt;br&gt;attacks and defenses, commercial security solutions, and pragmatic real world 
&lt;br&gt;security experience will be presented in a series of informative tutorials. 
&lt;br&gt;&lt;br&gt;The CanSecWest 2007 meeting provides international researchers a relaxed, 
&lt;br&gt;comfortable environment to learn from informative tutorials on key 
&lt;br&gt;developments in security technology, and collaborate and socialize with their 
&lt;br&gt;peers in one of the world's most scenic cities - a short drive away from one 
&lt;br&gt;of North America's top skiing areas. 
&lt;br&gt;&lt;br&gt;The CanSecWest 2007 conference will also feature the availability of the 
&lt;br&gt;Security Masters Dojo expert network security sensei instructors, and their 
&lt;br&gt;advanced, and intermediate, hands-on training courses - featuring small class 
&lt;br&gt;sizes and practical application excercises to maximize information transfer. 
&lt;br&gt;&lt;br&gt;We would like to announce the opportunity to submit papers, and/or lightning 
&lt;br&gt;talk proposals, for selection by the CanSecWest technical review committee. 
&lt;br&gt;Please make your paper proposal submissions before January 7th, 2007. Slides 
&lt;br&gt;for the papers must be submitted by March 15th, 2007. 
&lt;br&gt;&lt;br&gt;Some invited papers have been confirmed, but a limited number of speaking 
&lt;br&gt;slots are still available. The conference is responsible for travel and 
&lt;br&gt;accomodations for the speakers. If you have a proposal for a tutorial session 
&lt;br&gt;then please email a synopsis of the material and your biography, papers and, 
&lt;br&gt;speaking background to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=7876349&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secwes07@...&lt;/a&gt;. Only slides will be needed 
&lt;br&gt;for the March paper deadline, full text does not have to be submitted - but 
&lt;br&gt;will be accepted if available. 
&lt;br&gt;&lt;br&gt;The CanSecWest 2007 conference consists of tutorials on technical details 
&lt;br&gt;about current issues, innovative techniques and best practices in the 
&lt;br&gt;information security realm. The audiences are a multi-national mix of 
&lt;br&gt;professionals involved on a daily basis with security work: security product 
&lt;br&gt;vendors, programmers, security officers, and network administrators. We give 
&lt;br&gt;preference to technical details and new education for a technical audience. 
&lt;br&gt;&lt;br&gt;The conference itself is a single track series of presentations in a lecture 
&lt;br&gt;theater environment. The presentations offer speakers the opportunity to 
&lt;br&gt;showcase on-going research and collaborate with peers while educating and 
&lt;br&gt;highlighting advancements in security products and techniques. The focus is 
&lt;br&gt;on innovation, tutorials, and education instead of product pitches. Some 
&lt;br&gt;commercial content is tolerated, but it needs to be backed up by a technical 
&lt;br&gt;presenter - either giving a valuable tutorial and best practices instruction 
&lt;br&gt;or detailing significant new technology in the products. 
&lt;br&gt;&lt;br&gt;Paper proposals should consist of the following information: 
&lt;br&gt;&lt;br&gt;1) Presenter, and geographical location (country of origin/passport) and 
&lt;br&gt;contact info (e-mail, postal address, phone, fax). 
&lt;br&gt;2) Employer and/or affiliations. 
&lt;br&gt;3) Brief biography, list of publications and papers. 
&lt;br&gt;4) Any significant presentation and educational experience/background. 
&lt;br&gt;5) Topic synopsis, Proposed paper title, and a one paragraph description. 
&lt;br&gt;6) Reason why this material is innovative or significant or an important 
&lt;br&gt;tutorial. 
&lt;br&gt;7) Optionally, any samples of prepared material or outlines ready. 
&lt;br&gt;8) Will you have full text available or only slides? 
&lt;br&gt;9) Please list any other publications or conferences where this material has 
&lt;br&gt;been or will be published/submitted. 
&lt;br&gt;&lt;br&gt;Please include the plain text version of this information in your email as 
&lt;br&gt;well as any file, pdf, sxw, ppt, or html attachments. (Some reviewers only
&lt;br&gt;look at .txt info.) Multiple submissions are acceptable.
&lt;br&gt;&lt;br&gt;Please forward the above information to be considered for placement on the 
&lt;br&gt;speaker roster, or have your short lightning talk scheduled. Send all 
&lt;br&gt;conference related correspondence to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=7876349&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secwes07@...&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;thanks,
&lt;br&gt;--dr
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;London, U.K. &amp;nbsp; &amp;nbsp;Feb 28 / Mar 1 - 2007 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CanSecWest-2007-%28April-18-20%29-Call-For-Papers-%28Deadline-Jan-7th%29-tp7876349p7876349.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-7250109</id>
	<title>Call for papers: ARES 2007 submission deadline approaches in 2 weeks: 19-11-2006</title>
	<published>2006-11-07T12:15:25Z</published>
	<updated>2006-11-07T12:15:25Z</updated>
	<author>
		<name>Manh Tho</name>
	</author>
	<content type="html">Apologies for multiple copies due to cross postings. Please send to
&lt;br&gt;interested colleagues and students.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Call for Papers
&lt;br&gt;+-------------------------------------------------------------------+
&lt;br&gt;The Second International Conference on Availability, Reliability and
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security (AReS)
&lt;br&gt;ARES 2007 - &amp;quot;The International Security and Dependability &amp;nbsp;Conference&amp;quot;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; April 10th – April 13th, 2007
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vienna University of Technology, Austria
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;&lt;br&gt;+-------------------------------------------------------------------+
&lt;br&gt;&lt;br&gt;Conference
&lt;br&gt;-----------
&lt;br&gt;The 1st International Conference on Availability, Reliability and
&lt;br&gt;Security conference (ARES 2006) has been succesfully organized in
&lt;br&gt;Vienna, AUSTRIA from April 20 to April 22, 2006 by the Technical
&lt;br&gt;University of Vienna in cooperation with the European Network and
&lt;br&gt;Security Agency (ENISA). We have attracted 250 participants for this
&lt;br&gt;conference with its 3 keynotes speakers and its 9 workshops held in
&lt;br&gt;conjunction with.
&lt;br&gt;&lt;br&gt;In continuation of the successful 1st ARES conference, The Second
&lt;br&gt;International Conference on Availability, Reliability and Security
&lt;br&gt;(&amp;quot;ARES 2007 – The International Security and Dependability
&lt;br&gt;Conference&amp;quot;) will bring together researchers and practitioners in the
&lt;br&gt;area of IT-Security and Dependability.
&lt;br&gt;&lt;br&gt;ARES 2007 will highlight the various aspects of security – with
&lt;br&gt;special focus on secure internet solutions, trusted computing,
&lt;br&gt;digital forensics, privacy and organizational security issues.
&lt;br&gt;&lt;br&gt;ARES 2007 aims at a full and detailed discussion of the research
&lt;br&gt;issues of security as an integrative concept that covers amongst
&lt;br&gt;others availability, safety, confidentiality, integrity,
&lt;br&gt;maintainability and security in the different fields of applications.
&lt;br&gt;&lt;br&gt;Important Dates
&lt;br&gt;----------------
&lt;br&gt;* &amp;nbsp;Submission Deadline: November, 19th 2006
&lt;br&gt;* &amp;nbsp;Author Notification: January, 7th 2007
&lt;br&gt;* &amp;nbsp;Author Registration: January, 21st 2007
&lt;br&gt;* &amp;nbsp;Proceedings Version: January, 21st 2007
&lt;br&gt;&lt;br&gt;Workshops
&lt;br&gt;-----------
&lt;br&gt;In conjunction with the ARES 2007 conference, a number of workshops
&lt;br&gt;will be organized. We are very indebted for the effort of workshop's
&lt;br&gt;organizers and workshop's PC members. Proceedings of the ARES 2007
&lt;br&gt;workshops will be published by IEEE Computer Society Press.
&lt;br&gt;&lt;br&gt;* Workshop 1: Second International Workshop &amp;quot;Dependability Aspects
&lt;br&gt;on Data WArehousing and Mining applications&amp;quot; (DAWAM 2007),
&lt;br&gt;Jimmy Huang, York University, Canada + Josef Schiefer, Senactive
&lt;br&gt;IT-Dienstleistungs GmbH, Austria + Nguyen Manh Tho, Vienna University
&lt;br&gt;of Technology, Austria .DAWAM 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://dawam.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dawam.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: December, 17th 2006
&lt;br&gt;&lt;br&gt;* Workshop 2: Second Workshop on &amp;quot;Dependability and Security in
&lt;br&gt;e-Government&amp;quot; (DeSeGov 2007), A Min Tjoa, Vienna University of
&lt;br&gt;Technology, Austria + Erich Schweighofer, University of Vienna,
&lt;br&gt;Austria + Nguyen Manh Tho, Vienna University of Technology, Austria
&lt;br&gt;DeSeGov 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://desegov.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://desegov.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: December, 15th 2006
&lt;br&gt;&lt;br&gt;* Workshop 3: Workshop on Foundations of Fault-tolerant Distributed
&lt;br&gt;Computing (FOFDC 2007), Wilhelm Hasselbring, University of Oldenburg,
&lt;br&gt;Germany + Matthias Rohr, University of Oldenburg, Germany + Christian
&lt;br&gt;Storm, University of Oldenburg, Germany + Oliver Theel, University of
&lt;br&gt;Oldenburg, Germany + Timo Warns, University of Oldenburg, Germany.
&lt;br&gt;FOFDC 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://trustsoft.uni-oldenburg.de/fofdc07/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://trustsoft.uni-oldenburg.de/fofdc07/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: December, 1st 2006
&lt;br&gt;&lt;br&gt;* Workshop 4: &amp;quot;Secure Software Engineering&amp;quot; (SecSE 2007), Torbjørn
&lt;br&gt;Skramstad, Norwegian University of Science and technology (NTNU) +
&lt;br&gt;Lillian Røstad, Norwegian University of Science and technology (NTNU)
&lt;br&gt;+ Martin Gilje Jaatun, SINTEF ICT, Norway. SecSE 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://secse.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secse.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: December, 17th 2006
&lt;br&gt;&lt;br&gt;* Workshop 5: Workshop on &amp;quot;Event-Based IT Systems&amp;quot;, Modeling,
&lt;br&gt;Designing, and Testing Correct, Secure, and Dependable Event-Based
&lt;br&gt;System, Stefan Biffl, Vienna University of Technology + Eva Kühn,
&lt;br&gt;Vienna University of Technology + Alexander Schatten, Vienna
&lt;br&gt;Univeristy of Techology EBITS
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://ebits.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ebits.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: November, 19th 2006
&lt;br&gt;&lt;br&gt;* Workshop 6: &amp;quot;Distributed Healthcare Availability, Reliability and
&lt;br&gt;Security&amp;quot; (DIHARES 2007), Thomas Clark, Complete Cardiology Services
&lt;br&gt;Ltd, USA. DIHARES 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://dihares.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dihares.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: November, 17th, 2006
&lt;br&gt;&lt;br&gt;* Workshop 7: &amp;quot;First International Workshop on Advances in Information
&lt;br&gt;Security&amp;quot; (WAIS 2007), Leonard Barolli, Fukuoka Institute
&lt;br&gt;of Technology, Japan + Arjan Durresi, Louisiana State University, USA
&lt;br&gt;+ Hiroaki Kikuchi, Tokai university, Japan.WAIS 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.csc.lsu.edu/~durresi/wais2007/index.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.csc.lsu.edu/~durresi/wais2007/index.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: December 1st, 2006
&lt;br&gt;&lt;br&gt;* Workshop 8: Second International Workshop on Bioinformatics and
&lt;br&gt;Security (BIOS 2007), Hochreiter Sepp, University of Linz, Bioinf,
&lt;br&gt;Austria + Küng Josef, University of Linz, FAW Austria + Wagner
&lt;br&gt;Roland, University of Linz, FAW Austria. BIOS 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://bios.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bios.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: November 20, 2006
&lt;br&gt;&lt;br&gt;* Workshop 9: Second International Workshop on Security and E-
&lt;br&gt;Learning, Edgar Weippl, Secure Business Austria. SEL 2007
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://sel.ares-conference.eu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sel.ares-conference.eu/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: November 19, 2006
&lt;br&gt;&lt;br&gt;* Workshop 10: Second Workshop on Information Security Risk
&lt;br&gt;Management (ISRM), Professor Dr. D. Karagiannis, University of
&lt;br&gt;Vienna, Austria + Dr. L. Marinos, ENISA, Greece . ISRM
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.ares-conference.eu/ares2006/www.ares-conf.org/index47da.html?q=isrm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu/ares2006/www.ares-conf.org/index47da.html?q=isrm&lt;/a&gt;&lt;br&gt;&lt;br&gt;* Workshop 11: The First International Workshop on Spoofing, Digital
&lt;br&gt;Forensics and Open Source Tools (SDFOST), Judie Mulholland,
&lt;br&gt;Florida Cybersecurity Institute, USA. SDFOST
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.ares-conference.eu/conf/index.php?option=com_content&amp;task=view&amp;id=33&amp;Itemid=41&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu/conf/index.php?option=com_content&amp;task=view&amp;id=33&amp;Itemid=41&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission Deadline: November 20, 2006
&lt;br&gt;&lt;br&gt;&lt;br&gt;Topics of interest include, but are not limited to:
&lt;br&gt;----------------------------------------------------
&lt;br&gt;* Process based Security Models and Methods
&lt;br&gt;* Autonomous Computing
&lt;br&gt;* Authorization and Authentication
&lt;br&gt;* Availability and Reliability
&lt;br&gt;* Common Criteria Protocol
&lt;br&gt;* Cost/Benefit Analysis
&lt;br&gt;* Cryptographic protocols
&lt;br&gt;* Dependability Aspects for Special Applications (e.g. ERP-Systems,
&lt;br&gt;&amp;nbsp; Logistics)
&lt;br&gt;* Dependability Aspects of &amp;nbsp;Electronic Government (e-Government)
&lt;br&gt;* Dependability administration
&lt;br&gt;* Dependability in Open Source Software
&lt;br&gt;* Designing Business Models with security requirements
&lt;br&gt;* Digital Forensics
&lt;br&gt;* E-Commerce Dependability
&lt;br&gt;* Failure Prevention
&lt;br&gt;* IPR of Security Technology
&lt;br&gt;* Incident Response and Prevention
&lt;br&gt;* Information Flow Control
&lt;br&gt;* Internet Dependability
&lt;br&gt;* Interoperability aspects
&lt;br&gt;* Intrusion Detection and Fraud Detection
&lt;br&gt;* Legal issues
&lt;br&gt;* Mobile Security
&lt;br&gt;* Network Security
&lt;br&gt;* Privacy-enhancing technologies
&lt;br&gt;* RFID Security and Privacy
&lt;br&gt;* Risk planning, analysis &amp; awareness
&lt;br&gt;* Safety Critical Systems
&lt;br&gt;* Secure Enterprise Architectures
&lt;br&gt;* Security Issues for Ubiquitous Systems
&lt;br&gt;* Security and Privacy in E-Health
&lt;br&gt;* Security and Trust Management in P2P and Grid applications
&lt;br&gt;* Security and privacy issues for sensor networks, wireless/mobile
&lt;br&gt;&amp;nbsp; devices and applications
&lt;br&gt;* Security as Quality of Service
&lt;br&gt;* Security in Distributed Systems / Distributed Databases
&lt;br&gt;* Security in Electronic Payments
&lt;br&gt;* Security in Electronic Voting
&lt;br&gt;* Software Engineering of Dependable Systems
&lt;br&gt;* Software Security
&lt;br&gt;* Standards, Guidelines and Certification
&lt;br&gt;* Survivability of Computing Systems
&lt;br&gt;* Temporal Aspects of Dependability
&lt;br&gt;* Trusted Computing
&lt;br&gt;* Tools for Dependable System Design and Evaluation
&lt;br&gt;* Trust Models and Trust Management
&lt;br&gt;* VOIP/Wireless Security
&lt;br&gt;&lt;br&gt;Submission Guidelines
&lt;br&gt;----------------------
&lt;br&gt;Authors are invited to submit research and application papers following
&lt;br&gt;the IEEE Computer Society Proceedings Manuscripts style: two columns,
&lt;br&gt;single-spaced, including figures and references, using 10 fonts, and
&lt;br&gt;number each page. You can confirm the IEEE Computer Society Proceedings
&lt;br&gt;Author Guidelines at the following web page:
&lt;br&gt;&lt;a href=&quot;http://www.ieee.org/portal/pages/pubs/transactions/stylesheets.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ieee.org/portal/pages/pubs/transactions/stylesheets.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Submission papers are classified into 3 categorizes (1) full paper
&lt;br&gt;(8 pages), (2) short paper (5 pages), and (3) poster (2 pages)
&lt;br&gt;representing original, previously unpublished work. Submitted papers
&lt;br&gt;will be carefully evaluated based on originality, significance,
&lt;br&gt;technical soundness, and clarity of exposition
&lt;br&gt;&lt;br&gt;The Web site for paper registration and electronic submission is available at:
&lt;br&gt;&lt;a href=&quot;http://www.ares-conf.org/confdriver/?q=confdriver/papers/add&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org/confdriver/?q=confdriver/papers/add&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please refer to ARES website (&lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&amp;nbsp;or
&lt;br&gt;&lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;) for update information.
&lt;br&gt;&lt;br&gt;Honorary Co-Chairs
&lt;br&gt;-------------------
&lt;br&gt;Norman Revell, Middlesex University, United Kingdom
&lt;br&gt;Roland Wagner, University of Linz, Austria
&lt;br&gt;&lt;br&gt;General Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Guenther Pernul, University of Regensburg, Germany
&lt;br&gt;Makoto Takizawa, Tokyo Denki University, Japan
&lt;br&gt;&lt;br&gt;Program Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Gerald Quirchmayr, University of Southern Australia, Australia
&lt;br&gt;A Min Tjoa, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;&lt;br&gt;Workshops Co-Chairs
&lt;br&gt;--------------------
&lt;br&gt;Nguyen Manh Tho, Vienna University of Technology, Austria
&lt;br&gt;Abdelkader Hameurlain, University of Toulouse, France
&lt;br&gt;Leonard Barolli, Fukuoka Institute of Technology (FIT), Japan
&lt;br&gt;&lt;br&gt;&lt;br&gt;International Liaison Co-Chairs
&lt;br&gt;--------------------------------
&lt;br&gt;Maria Wimmer, University of Koblenz-Landau, Germany
&lt;br&gt;Charles Shoniregun, University of East London, United Kingdom
&lt;br&gt;&lt;br&gt;&lt;br&gt;Publicity Chair
&lt;br&gt;----------------
&lt;br&gt;Vladimir Marik, Czech Technical University, Czech Republic
&lt;br&gt;&lt;br&gt;&lt;br&gt;Publication Chair
&lt;br&gt;------------------
&lt;br&gt;Monika Lanzenberger, Norwegian University of Science and Technology,
&lt;br&gt;Trondheim, Norway
&lt;br&gt;&lt;br&gt;&lt;br&gt;Local Organizing Chairs
&lt;br&gt;------------------------
&lt;br&gt;Maria Schweikert, Vienna University of Technology, Austria
&lt;br&gt;Markus Klemen, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;Programme Committee
&lt;br&gt;--------------------
&lt;br&gt;Jemal H. Abawajy, Deakin University, Australia
&lt;br&gt;Karl Aberer, EPFL, Switzerland
&lt;br&gt;Abiola Abimbola, Napier University, UK
&lt;br&gt;Rafael Accorsi, University of Freiburg, Germany
&lt;br&gt;Alessandro Acquisti, Carnegie Mellon University, USA
&lt;br&gt;Andre Adelsbach, Telindus PSF S.A., Luxembourg
&lt;br&gt;Vasilis Aggelis, PIRAEUS Bank (WINBANK), Greece
&lt;br&gt;John Andrews, Loughborough, University, UK
&lt;br&gt;Michael Backes, Saarland University, Germany
&lt;br&gt;Leonard Barolli, Fukuoka Institute of Technology (FIT), Japan
&lt;br&gt;Lisa Bartlett, Loughborough University, UK
&lt;br&gt;Massimo Bartoletti, Universita' di Pisa, Italy
&lt;br&gt;Darcy G. Benoit, Acadia University, Wolfville, Canada
&lt;br&gt;Helmut Berger, E-Commerce Competence Center - EC3, Austria
&lt;br&gt;Bharat Bhargava, Purdue University, USA
&lt;br&gt;Christophe Blanchet, CNRS IBCP, France
&lt;br&gt;Alexander Böhm, University of Mannheim, Germany
&lt;br&gt;Stephane Bressan, National University of Singapore, Singapore
&lt;br&gt;Luciano Burgazzi, ENEA, Italy
&lt;br&gt;Kevin Butler, Pennsylvania State University, USA
&lt;br&gt;Jesper Buus Nielsen , University of Aarhus, Denmark
&lt;br&gt;Catharina Candolin, The Finnish Defence Forces. Finland
&lt;br&gt;Jiannong Cao, Hong Kong Polytechnic University, Hongkong
&lt;br&gt;Jordi Castellà-Roca, Rovira i Virgili University of Tarragona, Spain
&lt;br&gt;David Chadwick, University of Kent, UK
&lt;br&gt;Surendar Chandra, University of Notre Dame, USA
&lt;br&gt;Guihai Chen, Nanjing University, China
&lt;br&gt;Simon Christophe, Nancy University, France
&lt;br&gt;Soon-Ae Chun, City University of New York, USA
&lt;br&gt;Nathan Clarke, University of Plymouth, UK
&lt;br&gt;Joey Coleman, University of Newcastle upon Tyne, UK
&lt;br&gt;Gao Cong, University of Edinburgh, UK
&lt;br&gt;Ricardo Corin, INRIA-MSR &amp; University of Twente, The Netherlands
&lt;br&gt;George Davida, University of Wisconsinat Milwaukee, USA
&lt;br&gt;Robert H. Deng , Singapore Management University, Singapore
&lt;br&gt;Jochen Dinger, Universität Karlsruhe (TH), Germany
&lt;br&gt;Lucia Draque Penso, University of Mannheim, Germany
&lt;br&gt;Schahram Dustdar, Vienna University of Technology, Austria
&lt;br&gt;Christian Engelmann, Oak Ridge National Laboratory, USA
&lt;br&gt;Yung-Chin Fang, Dell Inc., USA
&lt;br&gt;Hannes Federrath, University of Regensburg, Germany
&lt;br&gt;Pascal Felber, Université de Neuchâtel, Switzerland
&lt;br&gt;Elena Ferrari, University of Insubria, Italy
&lt;br&gt;Sergio Flesca, DEIS – University of Calabria, Italy
&lt;br&gt;Vincenzo De Florio, University of Antwerp, Belgium
&lt;br&gt;Vladimir Fomichov, K.E. Tsiolkovsky Russian State Technological
&lt;br&gt;University, Russia
&lt;br&gt;Jordi Forné, Technincal &amp;nbsp;Universtiy of Catalonia, Spain
&lt;br&gt;Huirong Fu, Oakland University, MI, USA
&lt;br&gt;Steven Furnell, University of Plymouth, UK
&lt;br&gt;Javier Garcia-Villalba, Complutense University of Madrid, Spain
&lt;br&gt;Matthew Gebski, University of New South Wales, Australia
&lt;br&gt;Karl Goeschka, Vienna University of Technology, Austria
&lt;br&gt;Swapna S. Gokhale, University of Connecticut, USA
&lt;br&gt;Marcin Gorawski, Silesian University of Technology, Poland
&lt;br&gt;Stephan Groß, Technische Universität Dresde, Germany
&lt;br&gt;Daniel Grosu, Wayne State University, USA
&lt;br&gt;Michael Grottke, Duke University, USA
&lt;br&gt;Le Gruenwald, University of Oklahoma, USA
&lt;br&gt;Qijun Gu, Texas State University, USA
&lt;br&gt;Yong Guan, Iowa State University, USA
&lt;br&gt;Ibrahim Haddad, Open Source Development Labs, USA
&lt;br&gt;Abdelkader Hameurlain, Paul Sabatier University, France
&lt;br&gt;Marit Hansen, Independent Centre for Privacy Protection, USA
&lt;br&gt;Naohiro Hayashibara, Tokyo Denki University, Japan
&lt;br&gt;Xubin (Ben) He, Tennessee Technological University, USA
&lt;br&gt;Yanxiang He, Wuhan University, China
&lt;br&gt;Rattikorn Hewett, Texas Tech University, USA
&lt;br&gt;Chin-Tser Huang, University of South Carolina, USA
&lt;br&gt;Jimmy Huang, York University, Canada
&lt;br&gt;Thomas Jensen, IRISA/CNRS, France
&lt;br&gt;Zhen Jiang, West Chester University, USA
&lt;br&gt;Hai Jin, Huazhong University of Science and Technology, China
&lt;br&gt;Oliver Jorns, ftw. Forschungszentrum Telekommunikation Wien, Austria
&lt;br&gt;Audun Josang, School of Software Engineering and Data Communications, Australia
&lt;br&gt;Jan Jurjens, Munich University of Technology, Germany and Open University, UK
&lt;br&gt;Holger Kenn, University of Bremen, Germany
&lt;br&gt;Dogan Kesdogan, RWTH Aachen, Germany
&lt;br&gt;Brian King, Indiana University Purdue University Indianapolis, USA
&lt;br&gt;Ted Krovetz, California State University, USA
&lt;br&gt;Raphael Kunis, Chemnitz University of Technology, Germany
&lt;br&gt;Helmut Kurth, Atsec Information Security, USA
&lt;br&gt;Marc Lacoste, France Télécom R&amp;D, France
&lt;br&gt;Kwok-Yan Lam, Tsinghua University, China
&lt;br&gt;Chokchai Box Leangsuksun, Louisiana Tech University, USA
&lt;br&gt;Yih-Jiun Lee, Department of Information Management, CTU, Taiwan
&lt;br&gt;Chin-Laung Lei, National Taiwan University, China
&lt;br&gt;Philippe Leray, INSA (National Institute of Applied Sciences) of Rouen, France
&lt;br&gt;Jun Li, University of Oregon, USA
&lt;br&gt;Sam Lightstone, IBM Canada Ltd., Canada
&lt;br&gt;Chae-Hoon Lim, Sejong University, Korea
&lt;br&gt;Ching Lin, Macquarie University, Australia
&lt;br&gt;Man Lin, St. Francis Xavier University, Canada
&lt;br&gt;Alex Zhaoyu Liu, University of North Carolina at Charlotte, USA
&lt;br&gt;Tong Liu, Dell Inc, USA
&lt;br&gt;Hua Liu , Xerox labs, USA
&lt;br&gt;Javier Lopez, University of Malaga, Spain
&lt;br&gt;Sanglu Lu, Nanjing University, China
&lt;br&gt;Jianhua Ma, Hosei University, Japan
&lt;br&gt;Qiang Ma, NEC, Japan
&lt;br&gt;Josef Makolm, Federal Ministry of Finance, Austria
&lt;br&gt;Carsten Maple, University of Luton, UK
&lt;br&gt;Keith Martin , University of London, UK
&lt;br&gt;Fabio Martinelli, National Research Council - C.N.R, Italy
&lt;br&gt;BeniaminoDi Martino, Second University of Naples, Italy
&lt;br&gt;Santiago Melia, University of Alicante, Spain
&lt;br&gt;Nasrullah Memon, Aalborg University Esbjerg, Denmark
&lt;br&gt;Geyong Min, University of Bradford, UK
&lt;br&gt;George Mohay, Queensland University of Technology, Australia
&lt;br&gt;Marina Mongiello, Technical University of Bari, Italy
&lt;br&gt;Stefania Montani, Universita' del Piemonte Orientale, Italy
&lt;br&gt;Yi Mu, University of Wollongong, Australia
&lt;br&gt;Junghyun Nam, Sungkyunkwan University, Korea
&lt;br&gt;Priya Narasimhan, Carnegie Mellon University, USA
&lt;br&gt;Tho Manh Nguyen, Vienna University of Technology, Austria
&lt;br&gt;Jesper Nielsen, University of Århus, Denmark
&lt;br&gt;Thomas Nowey, University of Regensburg, Germany
&lt;br&gt;Tomas Olovsson, Chalmers University of Technology, Sweden
&lt;br&gt;Hong Ong, Oak Ridge National Laboratory, USA
&lt;br&gt;Maria Papadaki, University of Plymouth, UK
&lt;br&gt;Manish Parashar, Rutgers University, USA
&lt;br&gt;Fernando Pedone, University of Lugano, Switzerland
&lt;br&gt;MariaS. Perez, UPM, Spain
&lt;br&gt;Günther Pernul, University of Regensburg, Germany
&lt;br&gt;Rob Peters, University of Amsterdam, The Neitherland
&lt;br&gt;Thomas Phan, IBM Research, USA
&lt;br&gt;Mario Piattini, University of Castilla-La Mancha, Spain
&lt;br&gt;Makan Pourzandi, Ericsson Canada, Canada
&lt;br&gt;Christopher Price, University of Wales Aberystwyth, UK
&lt;br&gt;Jean-Jacques Quisquater, Universite catholique de Louvain, Belgium
&lt;br&gt;Wenny Rahayu, La Trobe University, Australia
&lt;br&gt;Indrajit Ray, Colorado State University, USA
&lt;br&gt;Domenico Rosaci, University &amp;quot;Mediterranea&amp;quot; of Reggio Calabria, Italy
&lt;br&gt;Heiko Rossnagel, Johann Wolfgang Goethe University Frankfurt, Germany
&lt;br&gt;Bimal Roy, Indian Statistical Institute, India
&lt;br&gt;Kenji Saito, Keio University, Japan
&lt;br&gt;Kouichi Sakurai, Kyushu University, Japan
&lt;br&gt;BiplabK. Sarker , University of New Brunswick, Fredericton, Canada
&lt;br&gt;Ingrid Schaumüller-Bichl, FH OÖ Campus Hagenberg, Austria
&lt;br&gt;Stephen L. Scott, Oak Ridge National Laboratory - USA
&lt;br&gt;Dharmaraja Selamuthu, Indian Institute of Technology Delhi, India
&lt;br&gt;Tony Shan, Wachovia Bank, USA
&lt;br&gt;Thomas Shrimpton, Portland State University, USA
&lt;br&gt;Richard Sinnott, University of Glasgow, UK
&lt;br&gt;Amund Skavhaug, Norwegian University of Science and Technology, Norway
&lt;br&gt;Agusti Solanas, Rovira i Virgili University, Spain
&lt;br&gt;Alexander Speirs, University of Newcastle upon Tyne, UK
&lt;br&gt;Katarina Stanoevska-Slabeva, University St. Gallen, Switzerland
&lt;br&gt;Ketil Stølen, SINTEF &amp; University of Oslo, Norway
&lt;br&gt;Aaron Striegel, University of Notre Dame, USA
&lt;br&gt;Peter Struss, Munich University of Technology, Germany
&lt;br&gt;Tsuyoshi Takagi, Future University - Hakodate, Japan
&lt;br&gt;Makoto Takizawa, Tokyo Denki University, Japan
&lt;br&gt;Björn Thuresson, KTH Computer Science and Communication, Sweden
&lt;br&gt;Oliver Theel, &amp;nbsp;University of Oldenburg, Germany
&lt;br&gt;A Min Tjoa, Vienna University of Technology, Austria
&lt;br&gt;Kishor Trivedi, Duke University, USA
&lt;br&gt;Juan Trujillo, University of Alicante, Spain
&lt;br&gt;Alexander W. Tsow, Indiana University, USA
&lt;br&gt;Tomas Uribe, SRI International, USA
&lt;br&gt;Kalyan Vaidyanathan, Sun Microsystems, USA
&lt;br&gt;Luca Vigano, ETH Zurich, Switzerland
&lt;br&gt;Umberto Villano, Universita' del Sannio, Italy
&lt;br&gt;Melanie Volkamer, DFKI - German Research Center for Artificial
&lt;br&gt;Intelligence, Germany
&lt;br&gt;Michael Waidner, IBM Software Group, Switzerland
&lt;br&gt;Carine Webber, Universidade de Caxias do Sul, Brazil
&lt;br&gt;Edgar Weippl, Vienna University of Technology, Austria
&lt;br&gt;Robert Willison, Copenhagen Business School, Denmark
&lt;br&gt;Maria Wimmer, University of Koblenz-Landau, Germany
&lt;br&gt;Matthew Wright, University of Texas at Arlington, USA
&lt;br&gt;Qinghan Xiao , Defence R&amp;D Canada, Canada
&lt;br&gt;Liudong Xing, University of Massachusetts, USA
&lt;br&gt;Cheng-Zhong Xu, Wayne State University, USA
&lt;br&gt;Mariemma.I. Yagüe, University of Malaga, Spain
&lt;br&gt;Jeff Yan, Newcastle University, UK
&lt;br&gt;Laurence Yang, St. Francis Xavier University, Canada
&lt;br&gt;Alec Yasinsac, Florida State University, USA
&lt;br&gt;George Yee, National Research Council, Canada
&lt;br&gt;Sung-Ming Yen, National Central University, Taiwan
&lt;br&gt;Xun Yi, Victoria University, USA
&lt;br&gt;Meng Yu, Monmouth University, USA
&lt;br&gt;William Yurcik, University of Illinois, USA
&lt;br&gt;Nicola Zannone, University of Trento, Italy
&lt;br&gt;Jianhong Zhang, North China University of Technology, China
&lt;br&gt;Liqiang Zhang, Indiana University South Bend, USA
&lt;br&gt;Jianying Zhou, Institute for Infocomm Research, Singapore
&lt;br&gt;Xudong Zhu, Alcatel shangHai Bell Co. LTD., China
&lt;br&gt;Enrico Zio, Polytechnic of Milan, Italy
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Call-for-papers%3A-ARES-2007-submission-deadline-approaches-in-2-weeks%3A-19-11-2006-tp7250109p7250109.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-7149684</id>
	<title>EUSecWest/London CFP extended to Nov. 7</title>
	<published>2006-11-02T16:28:21Z</published>
	<updated>2006-11-02T16:28:21Z</updated>
	<author>
		<name>Dragos Ruiu</name>
	</author>
	<content type="html">Hi folks, some brief news:
&lt;br&gt;&lt;br&gt;Some people have asked for late submissions to the EUSecWest
&lt;br&gt;paper selections. In the interest of fairness, we are extending the 
&lt;br&gt;deadline for all until next Tuesday (November 7), at which time
&lt;br&gt;the submissions will be reviewed. Details of submissions can
&lt;br&gt;be found on the &lt;a href=&quot;http://eusecwest.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://eusecwest.com&lt;/a&gt;&amp;nbsp;site under the speakers 
&lt;br&gt;sections.
&lt;br&gt;&lt;br&gt;PacSec/Tokyo paper descriptions have been published, and 
&lt;br&gt;CanSecWest/Vancouver early discount registration is now available.
&lt;br&gt;&lt;br&gt;thanks,
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;World Security Pros. Cutting Edge Training, Tools, and Techniques
&lt;br&gt;Tokyo, Japan &amp;nbsp; &amp;nbsp;November 27-30 2006 &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://pacsec.jp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pacsec.jp&lt;/a&gt;&lt;br&gt;pgpkey &lt;a href=&quot;http://dragos.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://dragos.com/&lt;/a&gt;&amp;nbsp;kyxpgp
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/EUSecWest-London-CFP-extended-to-Nov.-7-tp7149684p7149684.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-6788906</id>
	<title>ARES 2007: Paper submission system is ready - Submission Deadline 19-11-2006</title>
	<published>2006-10-09T02:08:04Z</published>
	<updated>2006-10-09T02:08:04Z</updated>
	<author>
		<name>Manh Tho</name>
	</author>
	<content type="html">Apologies for multiple copies due to cross postings. Please send to
&lt;br&gt;interested colleagues and students.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Call for Papers
&lt;br&gt;+-------------------------------------------------------------------+
&lt;br&gt;| The Second International Conference on Availability, Reliability and
&lt;br&gt;Security (AReS)
&lt;br&gt;| ARES 2007 - &amp;quot;The International Security and Dependability Conference&amp;quot;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; April 10th – April 13th,2007
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;&lt;br&gt;+-------------------------------------------------------------------+
&lt;br&gt;&lt;br&gt;&lt;br&gt;Conference
&lt;br&gt;-----------
&lt;br&gt;The 1st International Conference on Availability, Reliability and Security
&lt;br&gt;conference (ARES 2006)
&lt;br&gt;has been succesfully organized in Vienna, AUSTRIA from April 20 to April 22,
&lt;br&gt;2006 by the Technical
&lt;br&gt;University of Vienna in cooperation with the European Network and Security
&lt;br&gt;Agency (ENISA). We have
&lt;br&gt;attracted 250 participants for this conference with its 3 keynotes speakers
&lt;br&gt;and its 9 workshops held
&lt;br&gt;in conjunction with.
&lt;br&gt;&lt;br&gt;In continuation of the successful 1st ARES conference, The Second
&lt;br&gt;International Conference on Availability,
&lt;br&gt;Reliability and Security (&amp;quot;ARES 2007 – The International Security and
&lt;br&gt;Dependability Conference&amp;quot;)
&lt;br&gt;will bring together researchers and practitioners in the area of IT-Security
&lt;br&gt;and Dependability.
&lt;br&gt;&lt;br&gt;ARES 2007 will highlight the various aspects of security – with special
&lt;br&gt;focus on secure internet solutions,
&lt;br&gt;trusted computing, digital forensics, privacy and organizational security
&lt;br&gt;issues.
&lt;br&gt;&lt;br&gt;ARES 2007 aims at a full and detailed discussion of the research issues of
&lt;br&gt;security as an integrative
&lt;br&gt;concept that covers amongst others availability, safety, confidentiality,
&lt;br&gt;integrity, maintainability
&lt;br&gt;and security in the different fields of applications.
&lt;br&gt;&lt;br&gt;Important Dates
&lt;br&gt;----------------
&lt;br&gt;* &amp;nbsp;Workshop Proposal: &amp;nbsp; September, 10th 2006
&lt;br&gt;* &amp;nbsp;Submission Deadline: November, 19th 2006
&lt;br&gt;* &amp;nbsp;Author Notification: January, 7th 2007
&lt;br&gt;* &amp;nbsp;Author Registration: January, 21st 2007
&lt;br&gt;* &amp;nbsp;Proceedings Version: January, 21st 2007
&lt;br&gt;&lt;br&gt;Workshop Proposal
&lt;br&gt;-----------------
&lt;br&gt;In conjunction with the AReS2007 conference, a number of workshops will be
&lt;br&gt;organised.
&lt;br&gt;Workshop proposals which should include the call for papers, the number of
&lt;br&gt;papers to be accepted,
&lt;br&gt;the contact person, etc. are to be sent to the Workshop Organizing Committee
&lt;br&gt;(&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=6788906&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tho@...&lt;/a&gt;),
&lt;br&gt;by September 10th 2006. Proceedings of the ARES 2007 workshops will be
&lt;br&gt;published by IEEE Computer
&lt;br&gt;Society Press.
&lt;br&gt;&lt;br&gt;Topics of interest include, but are not limited to:
&lt;br&gt;----------------------------------------------------
&lt;br&gt;* Process based Security Models and Methods
&lt;br&gt;* Autonomous Computing
&lt;br&gt;* Authorization and Authentication
&lt;br&gt;* Availability and Reliability
&lt;br&gt;* Common Criteria Protocol
&lt;br&gt;* Cost/Benefit Analysis
&lt;br&gt;* Cryptographic protocols
&lt;br&gt;* Dependability Aspects for Special Applications (e.g. ERP-Systems,
&lt;br&gt;Logistics)
&lt;br&gt;* Dependability Aspects of &amp;nbsp;Electronic Government (e-Government)
&lt;br&gt;* Dependability administration
&lt;br&gt;* Dependability in Open Source Software
&lt;br&gt;* Designing Business Models with security requirements
&lt;br&gt;* Digital Forensics
&lt;br&gt;* E-Commerce Dependability
&lt;br&gt;* Failure Prevention
&lt;br&gt;* IPR of Security Technology
&lt;br&gt;* Incident Response and Prevention
&lt;br&gt;* Information Flow Control
&lt;br&gt;* Internet Dependability
&lt;br&gt;* Interoperability aspects
&lt;br&gt;* Intrusion Detection and Fraud Detection
&lt;br&gt;* Legal issues
&lt;br&gt;* Mobile Security
&lt;br&gt;* Network Security
&lt;br&gt;* Privacy-enhancing technologies
&lt;br&gt;* RFID Security and Privacy
&lt;br&gt;* Risk planning, analysis &amp; awareness
&lt;br&gt;* Safety Critical Systems
&lt;br&gt;* Secure Enterprise Architectures
&lt;br&gt;* Security Issues for Ubiquitous Systems
&lt;br&gt;* Security and Privacy in E-Health
&lt;br&gt;* Security and Trust Management in P2P and Grid applications
&lt;br&gt;* Security and privacy issues for sensor networks, wireless/mobile devices
&lt;br&gt;and applications
&lt;br&gt;* Security as Quality of Service
&lt;br&gt;* Security in Distributed Systems / Distributed Databases
&lt;br&gt;* Security in Electronic Payments
&lt;br&gt;* Security in Electronic Voting
&lt;br&gt;* Software Engineering of Dependable Systems
&lt;br&gt;* Software Security
&lt;br&gt;* Standards, Guidelines and Certification
&lt;br&gt;* Survivability of Computing Systems
&lt;br&gt;* Temporal Aspects of Dependability
&lt;br&gt;* Trusted Computing
&lt;br&gt;* Tools for Dependable System Design and Evaluation
&lt;br&gt;* Trust Models and Trust Management
&lt;br&gt;* VOIP/Wireless Security
&lt;br&gt;&lt;br&gt;Submission Guidelines
&lt;br&gt;----------------------
&lt;br&gt;Authors are invited to submit research and application papers following the
&lt;br&gt;IEEE Computer Society Proceedings
&lt;br&gt;Manuscripts style: two columns, single-spaced, including figures and
&lt;br&gt;references, using 10 fonts, and number
&lt;br&gt;each page. You can confirm the IEEE Computer Society Proceedings Author
&lt;br&gt;Guidelines at the following web page:
&lt;br&gt;URL: &lt;a href=&quot;http://computer.org/cspress/instruct.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://computer.org/cspress/instruct.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Web site for paper registration and electronic submission is available
&lt;br&gt;at:
&lt;br&gt;&lt;a href=&quot;http://www.ares-conf.org/confdriver/?q=confdriver/papers/add&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org/confdriver/?q=confdriver/papers/add&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please refer to ARES website (&lt;a href=&quot;http://www.ares-conf.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conf.org&lt;/a&gt;&amp;nbsp;or
&lt;br&gt;&lt;a href=&quot;http://www.ares-conference.eu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ares-conference.eu&lt;/a&gt;) for update information.
&lt;br&gt;&lt;br&gt;Honorary Co-Chairs
&lt;br&gt;-------------------
&lt;br&gt;Norman Revell, Middlesex University, United Kingdom
&lt;br&gt;Roland Wagner, University of Linz, Austria
&lt;br&gt;&lt;br&gt;General Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Guenther Pernul, University of Regensburg, Germany
&lt;br&gt;Makoto Takizawa, Tokyo Denki University, Japan
&lt;br&gt;&lt;br&gt;Program Co-Chairs
&lt;br&gt;------------------
&lt;br&gt;Gerald Quirchmayr, University of Southern Australia, Australia
&lt;br&gt;A Min Tjoa, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;&lt;br&gt;Workshops Co-Chairs
&lt;br&gt;--------------------
&lt;br&gt;Nguyen Manh Tho, Vienna University of Technology, Austria
&lt;br&gt;Abdelkader Hameurlain, University of Toulouse, France
&lt;br&gt;Leonard Barolli, Fukuoka Institute of Technology (FIT), Japan
&lt;br&gt;&lt;br&gt;&lt;br&gt;International Liaison Co-Chairs
&lt;br&gt;--------------------------------
&lt;br&gt;Maria Wimmer, University of Koblenz-Landau, Germany
&lt;br&gt;Charles Shoniregun, University of East London, United Kingdom
&lt;br&gt;&lt;br&gt;&lt;br&gt;Publicity Chair
&lt;br&gt;----------------
&lt;br&gt;Vladimir Marik, Czech Technical University, Czech Republic
&lt;br&gt;&lt;br&gt;&lt;br&gt;Publication Chair
&lt;br&gt;------------------
&lt;br&gt;Monika Lanzenberger, Norwegian University of Science and Technology,
&lt;br&gt;Trondheim, Norway
&lt;br&gt;&lt;br&gt;&lt;br&gt;Local Organizing Chairs
&lt;br&gt;------------------------
&lt;br&gt;Maria Schweikert, Vienna University of Technology, Austria
&lt;br&gt;Markus Klemen, Vienna University of Technology, Austria
&lt;br&gt;&lt;br&gt;Programme Committee
&lt;br&gt;--------------------
&lt;br&gt;Jemal H. Abawajy, Deakin University, Australia
&lt;br&gt;Karl Aberer, EPFL, Switzerland
&lt;br&gt;Abiola Abimbola, Napier University, UK
&lt;br&gt;Rafael Accorsi, University of Freiburg, Germany
&lt;br&gt;Alessandro Acquisti, Carnegie Mellon University, USA
&lt;br&gt;Andre Adelsbach, Telindus PSF S.A., Luxembourg
&lt;br&gt;Vasilis Aggelis, PIRAEUS Bank (WINBANK), Greece
&lt;br&gt;John Andrews, Loughborough, University, UK
&lt;br&gt;Michael Backes, Saarland University, Germany
&lt;br&gt;Leonard Barolli, Fukuoka Institute of Technology (FIT), Japan
&lt;br&gt;Lisa Bartlett, Loughborough University, UK
&lt;br&gt;Massimo Bartoletti, Universita' di Pisa, Italy
&lt;br&gt;Darcy G. Benoit, Acadia University, Wolfville, Canada
&lt;br&gt;Helmut Berger, E-Commerce Competence Center - EC3, Austria
&lt;br&gt;Bharat Bhargava, Purdue University, USA
&lt;br&gt;Christophe Blanchet, CNRS IBCP, France
&lt;br&gt;Alexander Böhm, University of Mannheim, Germany
&lt;br&gt;Stephane Bressan, National University of Singapore, Singapore
&lt;br&gt;Luciano Burgazzi, ENEA, Italy
&lt;br&gt;Kevin Butler, Pennsylvania State University, USA
&lt;br&gt;Jesper Buus Nielsen , University of Aarhus, Denmark
&lt;br&gt;Catharina Candolin, The Finnish Defence Forces. Finland
&lt;br&gt;Jiannong Cao, Hong Kong Polytechnic University, Hongkong
&lt;br&gt;Jordi Castellà-Roca, Rovira i Virgili University of Tarragona, Spain
&lt;br&gt;David Chadwick, University of Kent, UK
&lt;br&gt;Surendar Chandra, University of Notre Dame, USA
&lt;br&gt;Guihai Chen, Nanjing University, China
&lt;br&gt;Simon Christophe, Nancy University, France
&lt;br&gt;Soon-Ae Chun, City University of New York, USA
&lt;br&gt;Nathan Clarke, University of Plymouth, UK
&lt;br&gt;Joey Coleman, University of Newcastle upon Tyne, UK
&lt;br&gt;Gao Cong, University of Edinburgh, UK
&lt;br&gt;Ricardo Corin, INRIA-MSR &amp; University of Twente, The Netherlands
&lt;br&gt;George Davida, University of Wisconsinat Milwaukee, USA
&lt;br&gt;Robert H. Deng , Singapore Management University, Singapore
&lt;br&gt;Jochen Dinger, Universität Karlsruhe (TH), Germany
&lt;br&gt;Lucia Draque Penso, University of Mannheim, Germany
&lt;br&gt;Schahram Dustdar, Vienna University of Technology, Austria
&lt;br&gt;Christian Engelmann, Oak Ridge National Laboratory, USA
&lt;br&gt;Yung-Chin Fang, Dell Inc., USA
&lt;br&gt;Hannes Federrath, University of Regensburg, Germany
&lt;br&gt;Pascal Felber, Université de Neuchâtel, Switzerland
&lt;br&gt;Elena Ferrari, University of Insubria, Italy
&lt;br&gt;Sergio Flesca, DEIS – University of Calabria, Italy
&lt;br&gt;Vincenzo De Florio, University of Antwerp, Belgium
&lt;br&gt;Vladimir Fomichov, K.E. Tsiolkovsky Russian State Technological University,
&lt;br&gt;Russia
&lt;br&gt;Jordi Forné, Technincal &amp;nbsp;Universtiy of Catalonia, Spain
&lt;br&gt;Huirong Fu, Oakland University, MI, USA
&lt;br&gt;Steven Furnell, University of Plymouth, UK
&lt;br&gt;Javier Garcia-Villalba, Complutense University of Madrid, Spain
&lt;br&gt;Matthew Gebski, University of New South Wales, Australia
&lt;br&gt;Karl Goeschka, Vienna University of Technology, Austria
&lt;br&gt;Swapna S. Gokhale, University of Connecticut, USA
&lt;br&gt;Marcin Gorawski, Silesian University of Technology, Poland
&lt;br&gt;Stephan Groß, Technische Universität Dresde, Germany
&lt;br&gt;Daniel Grosu, Wayne State University, USA
&lt;br&gt;Michael Grottke, Duke University, USA
&lt;br&gt;Le Gruenwald, University of Oklahoma, USA
&lt;br&gt;Qijun Gu, Texas State University, USA
&lt;br&gt;Yong Guan, Iowa State University, USA
&lt;br&gt;Ibrahim Haddad, Open Source Development Labs, USA
&lt;br&gt;Abdelkader Hameurlain, Paul Sabatier University, France
&lt;br&gt;Marit Hansen, Independent Centre for Privacy Protection, USA
&lt;br&gt;Naohiro Hayashibara, Tokyo Denki University, Japan
&lt;br&gt;Xubin (Ben) He, Tennessee Technological University, USA
&lt;br&gt;Yanxiang He, Wuhan University, China
&lt;br&gt;Rattikorn Hewett, Texas Tech University, USA
&lt;br&gt;Chin-Tser Huang, University of South Carolina, USA
&lt;br&gt;Jimmy Huang, York University, Canada
&lt;br&gt;Thomas Jensen, IRISA/CNRS, France
&lt;br&gt;Zhen Jiang, West Chester University, USA
&lt;br&gt;Hai Jin, Huazhong University of Science and Technology, China
&lt;br&gt;Oliver Jorns, ftw. Forschungszentrum Telekommunikation Wien, Austria
&lt;br&gt;Audun Josang, School of Software Engineering and Data Communications,
&lt;br&gt;Australia
&lt;br&gt;Jan Jurjens, Munich University of Technology, Germany and Open University,
&lt;br&gt;UK
&lt;br&gt;Holger Kenn, University of Bremen, Germany
&lt;br&gt;Dogan Kesdogan, RWTH Aachen, Germany
&lt;br&gt;Brian King, Indiana University Purdue University Indianapolis, USA
&lt;br&gt;Ted Krovetz, California State University, USA
&lt;br&gt;Raphael Kunis, Chemnitz University of Technology, Germany
&lt;br&gt;Helmut Kurth, Atsec Information Security, USA
&lt;br&gt;Marc Lacoste, France Télécom R&amp;D, France
&lt;br&gt;Kwok-Yan Lam, Tsinghua University, China
&lt;br&gt;Chokchai Box Leangsuksun, Louisiana Tech University, USA
&lt;br&gt;Yih-Jiun Lee, Department of Information Management, CTU, Taiwan
&lt;br&gt;Chin-Laung Lei, National Taiwan University, China
&lt;br&gt;Philippe Leray, INSA (National Institute of Applied Sciences) of Rouen,
&lt;br&gt;France
&lt;br&gt;Jun Li, University of Oregon, USA
&lt;br&gt;Sam Lightstone, IBM Canada Ltd., Canada
&lt;br&gt;Chae-Hoon Lim, Sejong University, Korea
&lt;br&gt;Ching Lin, Macquarie University, Australia
&lt;br&gt;Man Lin, St. Francis Xavier University, Canada
&lt;br&gt;Alex Zhaoyu Liu, University of North Carolina at Charlotte, USA
&lt;br&gt;Tong Liu, Dell Inc, USA
&lt;br&gt;Hua Liu , Xerox labs, USA
&lt;br&gt;Javier Lopez, University of Malaga, Spain
&lt;br&gt;Sanglu Lu, Nanjing University, China
&lt;br&gt;Jianhua Ma, Hosei University, Japan
&lt;br&gt;Qiang Ma, NEC, Japan
&lt;br&gt;Josef Makolm, Federal Ministry of Finance, Austria
&lt;br&gt;Carsten Maple, University of Luton, UK
&lt;br&gt;Keith Martin , University of London, UK
&lt;br&gt;Fabio Martinelli, National Research Council - C.N.R, Italy
&lt;br&gt;BeniaminoDi Martino, Second University of Naples, Italy
&lt;br&gt;Santiago Melia, University of Alicante, Spain
&lt;br&gt;Nasrullah Memon, Aalborg University Esbjerg, Denmark
&lt;br&gt;Geyong Min, University of Bradford, UK
&lt;br&gt;George Mohay, Queensland University of Technology, Australia
&lt;br&gt;Marina Mongiello, Technical University of Bari, Italy
&lt;br&gt;Stefania Montani, Universita' del Piemonte Orientale, Italy
&lt;br&gt;Yi Mu, University of Wollongong, Australia
&lt;br&gt;Junghyun Nam, Sungkyunkwan University, Korea
&lt;br&gt;Priya Narasimhan, Carnegie Mellon University, USA
&lt;br&gt;Tho Manh Nguyen, Vienna University of Technology, Austria
&lt;br&gt;Jesper Nielsen, University of Århus, Denmark
&lt;br&gt;Thomas Nowey, University of Regensburg, Germany
&lt;br&gt;Tomas Olovsson, Chalmers University of Technology, Sweden
&lt;br&gt;Hong Ong, Oak Ridge National Laboratory, USA
&lt;br&gt;Maria Papadaki, University of Plymouth, UK
&lt;br&gt;Manish Parashar, Rutgers University, USA
&lt;br&gt;Fernando Pedone, University of Lugano, Switzerland
&lt;br&gt;MariaS. Perez, UPM, Spain
&lt;br&gt;Günther Pernul, University of Regensburg, Germany
&lt;br&gt;Rob Peters, University of Amsterdam, The Neitherland
&lt;br&gt;Thomas Phan, IBM Research, USA
&lt;br&gt;Mario Piattini, University of Castilla-La Mancha, Spain
&lt;br&gt;Makan Pourzandi, Ericsson Canada, Canada
&lt;br&gt;Christopher Price, University of Wales Aberystwyth, UK
&lt;br&gt;Jean-Jacques Quisquater, Universite catholique de Louvain, Belgium
&lt;br&gt;Wenny Rahayu, La Trobe University, Australia
&lt;br&gt;Indrajit Ray, Colorado State University, USA
&lt;br&gt;Domenico Rosaci, University &amp;quot;Mediterranea&amp;quot; of Reggio Calabria, Italy
&lt;br&gt;Heiko Rossnagel, Johann Wolfgang Goethe University Frankfurt, Germany
&lt;br&gt;Bimal Roy, Indian Statistical Institute, India
&lt;br&gt;Kenji Saito, Keio University, Japan
&lt;br&gt;Kouichi Sakurai, Kyushu University, Japan
&lt;br&gt;BiplabK. Sarker , University of New Brunswick, Fredericton, Canada
&lt;br&gt;Ingrid Schaumüller-Bichl, FH OÖ Campus Hagenberg, Austria
&lt;br&gt;Stephen L. Scott, Oak Ridge National Laboratory - USA
&lt;br&gt;Dharmaraja Selamuthu, Indian Institute of Technology Delhi, India
&lt;br&gt;Tony Shan, Wachovia Bank, USA
&lt;br&gt;Thomas Shrimpton, Portland State University, USA
&lt;br&gt;Richard Sinnott, University of Glasgow, UK
&lt;br&gt;Amund Skavhaug, Norwegian University of Science and Technology, Norway
&lt;br&gt;Agusti Solanas, Rovira i Virgili University, Spain
&lt;br&gt;Alexander Speirs, University of Newcastle upon Tyne, UK
&lt;br&gt;Katarina Stanoevska-Slabeva, University St. Gallen, Switzerland
&lt;br&gt;Ketil Stølen, SINTEF &amp; University of Oslo, Norway
&lt;br&gt;Aaron Striegel, University of Notre Dame, USA
&lt;br&gt;Peter Struss, Munich University of Technology, Germany
&lt;br&gt;Tsuyoshi Takagi, Future University - Hakodate, Japan
&lt;br&gt;Makoto Takizawa, Tokyo Denki University, Japan
&lt;br&gt;Oliver Theel, University of Oldenburg, Germany
&lt;br&gt;Björn Thuresson, KTH Computer Science and Communication, Sweden
&lt;br&gt;A Min Tjoa, Vienna University of Technology, Austria
&lt;br&gt;Kishor Trivedi, Duke University, USA
&lt;br&gt;Juan Trujillo, University of Alicante, Spain
&lt;br&gt;