<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:dtvmedia="http://participatoryculture.org/RSSModules/dtv/1.0"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>ITTS Update</title>
	<link>http://itts.ala.org/update</link>
	<description>Updates from the IT department of the American Library Association</description>
	<pubDate>Tue, 19 Aug 2008 17:54:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
		<!-- podcast_generator="podPress/8.5" -->
		<copyright>&#xA9;American Library Association </copyright>
		<managingEditor>jlevine@ala.org (American Library Association)</managingEditor>
		<webMaster>jlevine@ala.org</webMaster>
		<category></category>
		<ttl>1440</ttl>
		<itunes:keywords>ALA, libraries</itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary>Podcast from the IT department of the American Library Association</itunes:summary>
		<itunes:author>American Library Association</itunes:author>
		<itunes:category text="Government &amp; Organizations">
  <itunes:category text="National"/>
</itunes:category>
<itunes:category text="Government &amp; Organizations">
  <itunes:category text="Non-Profit"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>American Library Association</itunes:name>
			<itunes:email>jlevine@ala.org</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://itts.ala.org/update/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<image>
			<url>http://itts.ala.org/update/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
			<title>ITTS Update</title>
			<link>http://itts.ala.org/update</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Attack on ALA Web Servers</title>
		<link>http://itts.ala.org/update/2008/08/19/attack-on-ala-web-servers/</link>
		<comments>http://itts.ala.org/update/2008/08/19/attack-on-ala-web-servers/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 17:52:21 +0000</pubDate>
		<dc:creator>Sherri</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/08/19/attack-on-ala-web-servers/</guid>
		<description><![CDATA[



 

Yesterday, our Collage web servers began to show signs of another injection attack.  The attack was similar to the last one, where the attack attempted to use our website to push visitors a known attack website in China.  If successful, the attack would execute malicious java script to download more hostile software to the [...]]]></description>
			<content:encoded><![CDATA[<p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="Word.Document" /><meta name="Generator" content="Microsoft Word 12" /><meta name="Originator" content="Microsoft Word 12" /></p>
<link href="file:///C:%5CDOCUME%7E1%5CSherri%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" rel="File-List" />
<link href="file:///C:%5CDOCUME%7E1%5CSherri%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" rel="themeData" />
<link href="file:///C:%5CDOCUME%7E1%5CSherri%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" rel="colorSchemeMapping" /><!--[if gte mso 9]><xml>  <w:WordDocument>   <w:View>Normal</w:View>   <w:Zoom>0</w:Zoom>   <w:TrackMoves/>   <w:TrackFormatting/>   <w:PunctuationKerning/>   <w:ValidateAgainstSchemas/>   <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>   <w:IgnoreMixedContent>false</w:IgnoreMixedContent>   <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>   <w:DoNotPromoteQF/>   <w:LidThemeOther>EN-US</w:LidThemeOther>   <w:LidThemeAsian>X-NONE</w:LidThemeAsian>   <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>   <w:Compatibility>    <w:BreakWrappedTables/>    <w:SnapToGridInCell/>    <w:WrapTextWithPunct/>    <w:UseAsianBreakRules/>    <w:DontGrowAutofit/>    <w:SplitPgBreakAndParaMark/>    <w:DontVertAlignCellWithSp/>    <w:DontBreakConstrainedForcedTables/>    <w:DontVertAlignInTxbx/>    <w:Word11KerningPairs/>    <w:CachedColBalance/>   </w:Compatibility>   <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>   <m:mathPr>    <m:mathFont m:val="Cambria Math"/>    <m:brkBin m:val="before"/>    <m:brkBinSub m:val="--"/>    <m:smallFrac m:val="off"/>    <m:dispDef/>    <m:lMargin m:val="0"/>    <m:rMargin m:val="0"/>    <m:defJc m:val="centerGroup"/>    <m:wrapIndent m:val="1440"/>    <m:intLim m:val="subSup"/>    <m:naryLim m:val="undOvr"/>   </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml>  <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"   DefSemiHidden="true" DefQFormat="false" DefPriority="99"   LatentStyleCount="267">   <w:LsdException Locked="false" Priority="0" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Normal"/>   <w:LsdException Locked="false" Priority="9" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>   <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>   <w:LsdException Locked="false" Priority="39" Name="toc 1"/>   <w:LsdException Locked="false" Priority="39" Name="toc 2"/>   <w:LsdException Locked="false" Priority="39" Name="toc 3"/>   <w:LsdException Locked="false" Priority="39" Name="toc 4"/>   <w:LsdException Locked="false" Priority="39" Name="toc 5"/>   <w:LsdException Locked="false" Priority="39" Name="toc 6"/>   <w:LsdException Locked="false" Priority="39" Name="toc 7"/>   <w:LsdException Locked="false" Priority="39" Name="toc 8"/>   <w:LsdException Locked="false" Priority="39" Name="toc 9"/>   <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>   <w:LsdException Locked="false" Priority="10" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Title"/>   <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>   <w:LsdException Locked="false" Priority="11" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>   <w:LsdException Locked="false" Priority="22" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Strong"/>   <w:LsdException Locked="false" Priority="20" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>   <w:LsdException Locked="false" Priority="59" SemiHidden="false"    UnhideWhenUsed="false" Name="Table Grid"/>   <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>   <w:LsdException Locked="false" Priority="1" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 1"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 1"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 1"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>   <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>   <w:LsdException Locked="false" Priority="34" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>   <w:LsdException Locked="false" Priority="29" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Quote"/>   <w:LsdException Locked="false" Priority="30" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 1"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 1"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 2"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 2"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 2"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 2"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 2"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 3"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 3"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 3"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 3"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 3"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 4"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 4"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 4"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 4"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 4"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 5"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 5"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 5"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 5"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 5"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>   <w:LsdException Locked="false" Priority="60" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Shading Accent 6"/>   <w:LsdException Locked="false" Priority="61" SemiHidden="false"    UnhideWhenUsed="false" Name="Light List Accent 6"/>   <w:LsdException Locked="false" Priority="62" SemiHidden="false"    UnhideWhenUsed="false" Name="Light Grid Accent 6"/>   <w:LsdException Locked="false" Priority="63" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>   <w:LsdException Locked="false" Priority="64" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>   <w:LsdException Locked="false" Priority="65" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>   <w:LsdException Locked="false" Priority="66" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>   <w:LsdException Locked="false" Priority="67" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>   <w:LsdException Locked="false" Priority="68" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>   <w:LsdException Locked="false" Priority="69" SemiHidden="false"    UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>   <w:LsdException Locked="false" Priority="70" SemiHidden="false"    UnhideWhenUsed="false" Name="Dark List Accent 6"/>   <w:LsdException Locked="false" Priority="71" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>   <w:LsdException Locked="false" Priority="72" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful List Accent 6"/>   <w:LsdException Locked="false" Priority="73" SemiHidden="false"    UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>   <w:LsdException Locked="false" Priority="19" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>   <w:LsdException Locked="false" Priority="21" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>   <w:LsdException Locked="false" Priority="31" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>   <w:LsdException Locked="false" Priority="32" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>   <w:LsdException Locked="false" Priority="33" SemiHidden="false"    UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>   <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>   <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>  </w:LatentStyles> </xml><![endif]--><br />
<style><!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Tahoma; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:1627400839 -2147483648 8 0 66047 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style>
<p><!--[if gte mso 10]></p>
<style>  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} </style>
<p> <![endif]--></p>
<p class="MsoNormal"><strong>Yesterday, our Collage web servers began to show signs of another injection attack.  The attack was similar to the last one, where the attack attempted to use our website to push visitors a known attack website in China.  If successful, the attack would execute malicious java script to download more hostile software to the visitor&#8217;s PC.  This represents a newer form of attack, attempting to use a trusted source (in this case ALA), to refer web visitors to a hostile site.   We have identified a number of other external websites that were attacked by the same method.<o:p></o:p></strong></p>
<p class="MsoNormal"><strong><o:p> </o:p></strong></p>
<p class="MsoNormal"><strong>We have located the malicious code that the attack inserted into some of our forms databases, and have removed it.  We have also added more rules to our filtering system on our two outward-facing Collage web servers to prevent this attack from occurring again.   If you experience any odd behavior related to online forms, please send a report to <a href="mailto:helpdesk@ala.org"><span style="color: windowtext">helpdesk@ala.org</span></a> with as much detail as you can provide.<o:p></o:p></strong></p>
<p class="MsoNormal"><strong><o:p> </o:p></strong></p>
<p class="MsoNormal"><strong>We will keep you updated by email and the ITTS Update blog as events require. <o:p></o:p></strong></p>
<p class="MsoNormal"><strong><o:p> </o:p></strong></p>
<p class="MsoNormal"><strong><br />
<o:p></o:p></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: 'Tahoma','sans-serif'"><o:p> </o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/08/19/attack-on-ala-web-servers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Dreamhost Server Performance Hit</title>
		<link>http://itts.ala.org/update/2008/08/13/dreamhost-server-performance-hit/</link>
		<comments>http://itts.ala.org/update/2008/08/13/dreamhost-server-performance-hit/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 20:49:03 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/08/13/dreamhost-server-performance-hit/</guid>
		<description><![CDATA[The server on our shared hosting account at Dreamhost is encountering an extremely heavy load.  Blogs, wikis, and classes housed on the account may encounter slowness.  I have reported the problem, and am monitoring the server&#8217;s performance, which appears to be gradually improving.  Please contact me any time you run into major [...]]]></description>
			<content:encoded><![CDATA[<p>The server on our shared hosting account at Dreamhost is encountering an extremely heavy load.  Blogs, wikis, and classes housed on the account may encounter slowness.  I have reported the problem, and am monitoring the server&#8217;s performance, which appears to be gradually improving.  Please contact me any time you run into major problems using the external hosting account, as this data is vital in terms of long range planning for our off site resources.</p>
<p>Matt Ivaliotes - ITTS</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/08/13/dreamhost-server-performance-hit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>2008 Annual Conference WAC Meeting Notes</title>
		<link>http://itts.ala.org/update/2008/08/04/2008-annual-conference-wac-meeting-notes/</link>
		<comments>http://itts.ala.org/update/2008/08/04/2008-annual-conference-wac-meeting-notes/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 20:54:56 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
		
		<category><![CDATA[ALAConnect]]></category>

		<category><![CDATA[Web Advisory Committee (WAC)]]></category>

		<category><![CDATA[Web Planning]]></category>

		<category><![CDATA[Website Search]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/08/04/2008-annual-conference-wac-meeting-notes/</guid>
		<description><![CDATA[The notes from the 2008 Annual Website Advisory Committee meeting are now available (PDF, 171KB). If you have questions, please post them in the comments so that we can answer them for everyone. Thanks!
]]></description>
			<content:encoded><![CDATA[<p><a href="http://itts.ala.org/update/wp-content/uploads/2008/08/annual08_wac_notes.pdf" title="2008 Annual WAC meeting minutes">The notes from the 2008 Annual Website Advisory Committee meeting are now available</a> (PDF, 171KB). If you have questions, please post them in the comments so that we can answer them for everyone. Thanks!</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/08/04/2008-annual-conference-wac-meeting-notes/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Weblog Migration</title>
		<link>http://itts.ala.org/update/2008/07/31/weblog-migration/</link>
		<comments>http://itts.ala.org/update/2008/07/31/weblog-migration/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 22:01:30 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/31/weblog-migration/</guid>
		<description><![CDATA[For some time now, we have had WordPress software available on our offsite hosting account at Dreamhost.  We still have about forty weblogs internally hosted on blogs.ala.org using the b2evolution software package.  For a host of system stability, security, and efficiency reasons, we&#8217;d like to have weblogs migrated off of blogs.ala.org and to [...]]]></description>
			<content:encoded><![CDATA[<p>For some time now, we have had WordPress software available on our offsite hosting account at Dreamhost.  We still have about forty weblogs internally hosted on blogs.ala.org using the b2evolution software package.  For a host of system stability, security, and efficiency reasons, we&#8217;d like to have weblogs migrated off of blogs.ala.org and to Dreamhost-hosted WordPress installations as quickly as reasonably possible.  If the address of your weblog begins with <a href="http://blogs.ala.org/">http://blogs.ala.org</a>, then it will need to be migrated.<o:p> </o:p></p>
<p class="MsoNormal">On the Tech support wiki, you will find an instruction document on how to make this migration (thanks to Stephanie Kuenn for putting this together after going through the migration process herself).  Please look the instructions over, and plan to move your weblog in the next several weeks.  I of course will be happy to answer questions you may have about this process.  Note that Stephanie references using an FTP site for uploading a blog theme.  If your unit already has applications on Dreamhost, you should have a login and password for FTP-ing files.  If not, when you request the new WordPress blog from me, I will send you the FTP information.</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/31/weblog-migration/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wikis Up Again</title>
		<link>http://itts.ala.org/update/2008/07/31/wikis-up-again/</link>
		<comments>http://itts.ala.org/update/2008/07/31/wikis-up-again/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 18:56:49 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/31/wikis-up-again/</guid>
		<description><![CDATA[The wikis at wikis.ala.org are back in service.  There was an error that overwrite the password the wikis use to access their  databases.  The risk of this sort of single point of failure is one of the reasons why no more new wikis are going to be created on this server.  We are sorry about [...]]]></description>
			<content:encoded><![CDATA[<p>The wikis at wikis.ala.org are back in service.  There was an error that overwrite the password the wikis use to access their  databases.  The risk of this sort of single point of failure is one of the reasons why no more new wikis are going to be created on this server.  We are sorry about this downtime, and do not anticipate a repeat.</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/31/wikis-up-again/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Virus attacks on ALA web servers</title>
		<link>http://itts.ala.org/update/2008/07/31/virus-attacks-on-ala-web-servers/</link>
		<comments>http://itts.ala.org/update/2008/07/31/virus-attacks-on-ala-web-servers/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 17:56:01 +0000</pubDate>
		<dc:creator>Rob Carlson</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[ALA web]]></category>

		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/31/virus-attacks-on-ala-web-servers/</guid>
		<description><![CDATA[Some time in the past few days (this started between  7/20/08 and 07/30/2008), several of our web servers began to show signs of a virus attack.  The attack attempted to use our website to push visitors to verynx.cn, a known attack website in China.  If successful, the attack would execute malicious java script to download [...]]]></description>
			<content:encoded><![CDATA[<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Calibri">Some time in the past few days (this started between  7/20/08 and 07/30/2008), several of our web servers began to show signs of a virus attack.  The attack attempted to use our website to push visitors to verynx.cn, a known attack website in China.  If successful, the attack would execute malicious java script to download more hostile software to the visitor&#8217;s PC.  This represents a newer form of attack, attempting to use a trusted source (in this case ALA), to refer web visitors to a hostile site. </font></p>
<p><o:p><font face="Calibri"> </font></o:p></p>
<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Calibri">We have located the malicious code that the virus inserted into some of our forms databases, and have removed it.  We have also installed a new filter system on our two outward-facing Collage web servers, and are in the process of fine-tuning its performance.  This new filter should block any further attacks of this kind, which will give us the breathing room to take other measures to prevent more attacks in the future.  If you experience any odd behavior related to online forms, please send a report to </font><a href="mailto:helpdesk@ala.org"><font face="Calibri">helpdesk@ala.org</font></a><font face="Calibri"> with as much detail as you can provide.</font></p>
<p><o:p><font face="Calibri"> </font></o:p></p>
<p style="margin: 0in 0in 0pt" class="MsoNormal"><font face="Calibri">We will keep you updated by email and the ITTS Update blog as events require. </font></p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/31/virus-attacks-on-ala-web-servers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Another Wiki Issue</title>
		<link>http://itts.ala.org/update/2008/07/31/another-wiki-issue/</link>
		<comments>http://itts.ala.org/update/2008/07/31/another-wiki-issue/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 16:19:18 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/31/another-wiki-issue/</guid>
		<description><![CDATA[The wikis hosted at wikis.ala.org are encountering another problem.  The issue does not appear to be causing any problems for web log analysis using urchin or the weblogs housed at blogs.ala.org using b2evolution.  Troubleshooting of a database connectivity issue between Mediawiki and mysql is in progress.
]]></description>
			<content:encoded><![CDATA[<p>The wikis hosted at wikis.ala.org are encountering another problem.  The issue does not appear to be causing any problems for web log analysis using urchin or the weblogs housed at blogs.ala.org using b2evolution.  Troubleshooting of a database connectivity issue between Mediawiki and mysql is in progress.</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/31/another-wiki-issue/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Blog/Wiki server downtime</title>
		<link>http://itts.ala.org/update/2008/07/29/blogwiki-server-downtime/</link>
		<comments>http://itts.ala.org/update/2008/07/29/blogwiki-server-downtime/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 21:13:36 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/29/blogwiki-server-downtime/</guid>
		<description><![CDATA[Late last week and this weekend we experienced downtime on our internal blog/wiki/urchin server.  This affected all wikis house at wikis.ala.org, all weblogs currently using b2evolution on blogs.ala.org, and our web log stats analysis software, urchin.  The problem was tracked down to an issue with php configuration on the server which was causing [...]]]></description>
			<content:encoded><![CDATA[<p>Late last week and this weekend we experienced downtime on our internal blog/wiki/urchin server.  This affected all wikis house at wikis.ala.org, all weblogs currently using b2evolution on blogs.ala.org, and our web log stats analysis software, urchin.  The problem was tracked down to an issue with php configuration on the server which was causing the system to not release available memory when a process terminated.  The situation has been resolved.  We are continuing to monitor the server, and will post notice of any further action required in this space.</p>
<p>Going forward, we will be posting information on how to migrate all blogs hosted on b2evolution at blogs.ala.org as well as all wikis hosted at wikis.ala.org to our outside hosting space. Expect both the blog and wiki instructions by early next week.</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/29/blogwiki-server-downtime/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Questions about ALA Connect</title>
		<link>http://itts.ala.org/update/2008/07/28/questions-about-ala-connect/</link>
		<comments>http://itts.ala.org/update/2008/07/28/questions-about-ala-connect/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 15:20:10 +0000</pubDate>
		<dc:creator>Jenny</dc:creator>
		
		<category><![CDATA[ALAConnect]]></category>

		<category><![CDATA[ala connect]]></category>

		<category><![CDATA[Online Communities]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/28/questions-about-ala-connect/</guid>
		<description><![CDATA[I was recently asked two questions about ALA&#8217;s upcoming Online Communities v2 service, now known as &#8220;ALA Connect.&#8221; I thought I&#8217;d answer them here in case others are wondering the same things.
Q1. Will the new version be for ALA members only, or will it also have public-access communities?
A. ALA Connect will not be members-only, although [...]]]></description>
			<content:encoded><![CDATA[<p>I was recently asked two questions about ALA&#8217;s upcoming Online Communities v2 service, now known as &#8220;ALA Connect.&#8221; I thought I&#8217;d answer them here in case others are wondering the same things.</p>
<p><strong>Q1. Will the new version be for ALA members only, or will it also have public-access communities?</strong><br />
A. ALA Connect will not be members-only, although there will be sections that will be set up that way. There will be a basic, &#8220;registered users&#8221; login for non-members who want to comment on blog posts, participate in discussion forums, and contribute to public-access communities (e.g., a community for library advocacy). However, all of the networking, member search, online résumé, and other pieces that connect you specifically with other members will be available for members only. The different types of permissions are outlined in the Requirements Document available at <a href="http://itts.ala.org/update/2008/05/08/online-communities-update-with-documents/">http://itts.ala.org/update/2008/05/08/online-communities-update-with-documents/</a> (section 6, page 9). It will be up to a community&#8217;s administrators to decide how they want to configure access for their community.</p>
<p><strong>Q2. Will Google search ALA Connect communities and show results?</strong><br />
A. Google the web search engine will be able to index publicly-accessible pages in ALA Connect (AC), but those communities that have set permissions to member-only will not be searchable outside of the AC search engine. ALA does run its own version of Google to search our website, but it won&#8217;t be able to search members-only areas of ALA Connect because of those permissions, either. ALA units probably want to take this information into account when deciding how to configure their communities.</p>
<p>We&#8217;re moving forward (full speed ahead), but we&#8217;re happy to take a break to help everyone understand where we&#8217;re heading, so please use the <a href="http://itts.ala.org/update/contact-us/">Contact Us form</a> or leave a comment if you have further questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/28/questions-about-ala-connect/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Today&#8217;s Sympa Problem</title>
		<link>http://itts.ala.org/update/2008/07/22/todays-sympa-problem/</link>
		<comments>http://itts.ala.org/update/2008/07/22/todays-sympa-problem/#comments</comments>
		<pubDate>Tue, 22 Jul 2008 21:53:51 +0000</pubDate>
		<dc:creator>Sherri</dc:creator>
		
		<category><![CDATA[Email Issues]]></category>

		<category><![CDATA[Mailing Lists]]></category>

		<guid isPermaLink="false">http://itts.ala.org/update/2008/07/22/todays-sympa-problem/</guid>
		<description><![CDATA[ALA Members and Staff,
I&#8217;d like to explain what happened to our mailing list server that caused the large temporary backlog of messages.  We fell victim not to a focused spam attack, but to the collateral damage of a spammer, so to speak.  A spammer pretended to be sending possibly millions of spam messages [...]]]></description>
			<content:encoded><![CDATA[<p>ALA Members and Staff,</p>
<p>I&#8217;d like to explain what happened to our mailing list server that caused the large temporary backlog of messages.  We fell victim not to a focused spam attack, but to the collateral damage of a spammer, so to speak.  A spammer pretended to be sending possibly millions of spam messages from one of our lists - by forging the mail they sent to make it look like it was coming from the list&#8217;s address.  The result was thousands upon thousands of &#8220;bounce&#8221; messages that were sent from around the world to our Sympa server.</p>
<p>Spammers generally have many thousands of bad email addresses in their sneakily gathered lists, and any email to a bad address generates a bounce.  That bounce is sent to the sender&#8217;s (or in this case, the faked sender&#8217;s) address.  The huge number of incoming bounce messages had to be processed by the Sympa server as they arrived, and the volume of additional bounces bogged the server down terribly, causing a backlog to build up.  We identified the list that had been impersonated, shut it off (so the server would no longer concern itself with bounces to that list), and began culling the bad messages from the queue.</p>
<p>We are investigating whether there is anything we can do in order to prevent this in the future.  It is a problem plaguing many high volume list servers.  The difficult part is that the bounces themselves are not spam to be filtered, and filtering all bounce messages would break an important function of email servers.</p>
<p>The Sympa list server is now operating as normal again, and will be caught up with its message backlog within a few hours.</p>
<p>Matthew Ivaliotes<br />
Information Technology &#038; Telecommunication Services<br />
American Library Association<br />
(312) 280-4266</p>
]]></content:encoded>
			<wfw:commentRss>http://itts.ala.org/update/2008/07/22/todays-sympa-problem/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
