On mySimon: Oprah's Favorite Things
BNET Business Network:
BNET
TechRepublic
ZDNet

May 20th, 2008

McAfee partner isn't McAfee secure

Posted by Nathan McFeters @ 11:16 pm

Categories: McAfee, PCI, Punditocracy

Tags: McAfee Inc., Video, Russ McRee, Corporate Communications, Marketing, Nathan McFeters

Nate McFeters CertifiedI was over reading Russ McRee’s blog today, and I’ve got to say, if McAfee’s HackerSafe (or whatever they’re calling it now) doesn’t die off soon, then he’ll be able to write a novel about their trials and tribulations.

Apparently, McAfee authorized distributor Winferno.com is not HackerSafe… not that it would’ve mattered, as that wouldn’t have helped them prevent the XSS issues that McRee exposed on his blog.  McRee says:

Shouldn’t a McAfee Partner be McAfee Secure?
Apparently not, and being one wouldn’t have cured the XSS blues anyway.
Next in our video series, a supposedly secure shopping cart that is far from.

Here’s an IFRAME.
Here’s the cookie.
As well we know, coughing up the cookie counts as a really bad thing for any shopping cart, let alone an SSL protected shopping cart that happens to be a McAfee Partner and authorized distributor of McAfee Software. But lest we forget, McAfee doesn’t count XSS as concerning.
Here’s the video

One thing even McAfee has to agree on, McRee has style.  I like the video documentation and ticker tape messages.  McRee covers even more details on this topic over at his blog, and I recommend you go over there and have a look for yourself.

Of course, if you’re a current HackerSafe customer and are starting to worry, I’m still offering the “Nate McFeters Safe” certification.  Don’t be the last to fall in line, others have been quick to jump on, for example, the following noted security researchers are already proudly signed up and displaying the “Nate McFeters Safe” certification:

-Nate

Nathan McFeters

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 1 Talkback(s)
I don't know about all of you...  nmcfeters | 05/20/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Save time with automated shipping solutions
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Visit the UPS Business Essentials Guide
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here