<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><!-- generator="wordpress/2.3.1" --><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Security Samizdat</title>
	<link>http://security-samizdat.com</link>
	<description>Information Security, from a pragmatic point of view</description>
	<pubDate>Thu, 27 Dec 2007 10:17:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SecuritySamizdat" type="application/rss+xml" /><item>
		<title>On hold</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684583/</link>
		<comments>http://security-samizdat.com/on-hold/#comments</comments>
		<pubDate>Wed, 26 Dec 2007 21:01:20 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Meta]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/on-hold/</guid>
		<description><![CDATA[Dear readers,
Security Samizdat won&#8217;t be updated for the time being. I have plans or this domain, and I hope to have it up and running again soon.
Meanwhile, the entries already posted are yours to peruse.
Kind regards
Alfredo





]]></description>
			<content:encoded><![CDATA[<p>Dear readers,</p>
<p>Security Samizdat won&#8217;t be updated for the time being. I have plans or this domain, and I hope to have it up and running again soon.</p>
<p>Meanwhile, the entries already posted are yours to peruse.</p>
<p>Kind regards</p>
<p><a href="http://www.areino.com">Alfredo</a></p>
<p>
<script type="text/javascript"><!--
google_ad_client = "pub-6404355368913094";
//security-samizdat.com
google_ad_slot = "6068307693";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/on-hold/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/on-hold/</feedburner:origLink></item>
		<item>
		<title>Understanding and Reducing Insider Threat</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684584/</link>
		<comments>http://security-samizdat.com/understanding-and-reducing-insider-threat/#comments</comments>
		<pubDate>Mon, 05 Nov 2007 21:42:09 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Papers]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/understanding-and-reducing-insider-threat/</guid>
		<description><![CDATA[This is an excellent series of articles by Kai the Security Guy about insider threat, to help understand the issue, and answer some tricky questions, such as &#8220;why do companies ignore it?&#8221;, &#8220;how big is the risk?&#8221;, &#8220;why do they do it?&#8221; and &#8220;what are they after?&#8221;.
&#8220;Dripping Data: Understanding and Reducing Insider Threat&#8220;
(part I, part [...]]]></description>
			<content:encoded><![CDATA[<p>This is an excellent series of articles by <a href="http://blogs.technet.com/kaiaxford/" target="_blank">Kai the Security Guy</a> about insider threat, to help understand the issue, and answer some tricky questions, such as &#8220;why do companies ignore it?&#8221;, &#8220;how big is the risk?&#8221;, &#8220;why do they do it?&#8221; and &#8220;what are they after?&#8221;.</p>
<blockquote><p>&#8220;<em>Dripping Data: Understanding and Reducing Insider Threat</em>&#8220;<br />
(<a href="http://blogs.technet.com/kaiaxford/archive/2007/09/18/dripping-data-understanding-and-reducing-insider-threat.aspx" target="_blank">part I</a>, <a href="http://blogs.technet.com/kaiaxford/archive/2007/09/29/dripping-data-understanding-and-reducing-insider-threat-part-ii.aspx" target="_blank">part II</a>, <a href="http://blogs.technet.com/kaiaxford/archive/2007/10/04/dripping-data-understanding-and-reducing-insider-threat-part-iii.aspx" target="_blank">part III</a>, <a href="http://blogs.technet.com/kaiaxford/archive/2007/11/01/dripping-data-understanding-and-reducing-insider-threat-part-iv.aspx" target="_blank">part IV</a>, <a href="http://blogs.technet.com/kaiaxford/archive/2007/11/05/dripping-data-understanding-and-reducing-insider-threat-part-v.aspx" target="_blank">part V</a>), <a href="http://blogs.technet.com/kaiaxford/archive/2007/11/13/dripping-data-understanding-and-reducing-insider-threat-part-vi-social-engineering.aspx" target="_blank">part VI</a>)</p>
</blockquote>
<p>Apparently more parts are yet to be published. I&#8217;ll add the appropriate links as Kai posts them.</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/understanding-and-reducing-insider-threat/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/understanding-and-reducing-insider-threat/</feedburner:origLink></item>
		<item>
		<title>Visualization of drive contents</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684585/</link>
		<comments>http://security-samizdat.com/visualization-of-drive-contents/#comments</comments>
		<pubDate>Sun, 04 Nov 2007 16:29:45 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Products]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/visualization-of-drive-contents/</guid>
		<description><![CDATA[Modern operating systems typically have thousands of files, and thousands of hyerarchically-nested folders. There are cases in which we might need to have an overview of the content of a hard drive (or a USB pendrive, or DVD), and quickly find out what size and type of files there are. This is the case during [...]]]></description>
			<content:encoded><![CDATA[<p>Modern operating systems typically have thousands of files, and thousands of hyerarchically-nested folders. There are cases in which we might need to have an overview of the content of a hard drive (or a USB pendrive, or DVD), and quickly find out what size and type of files there are. This is the case during the initial phases of a forensics investigation.</p>
<p>While reading <a href="http://www.rumint.org/gregconti/" target="_blank">Greg Conti</a>&#8217;s excellent &#8220;<a href="http://nostarch.com/frameset.php?startat=securityvisualization" target="_blank">Security Data Visualization</a>&#8221; I came across this wonderful piece of software: <a href="http://w3.win.tue.nl/nl/onderzoek/onderzoek_informatica/visualization/sequoiaview/" target="_blank">SequoiaView</a>. It is developed at the <a href="http://www.tue.nl/" target="_blank">Technical University of Eindhoven</a> (The Netherlands)</p>
<blockquote><p><em>&#8220;Ever wondered why your hard disk is full? Or what directory is taking up most of the space? When using conventional disk browsing tools, such as Windows Explorer, these questions may be hard to answer. With SequoiaView however, they can be answered almost immediately. SequoiaView uses a visualization technique called <strong>cushion treemaps</strong> to provide you with a single picture of the entire contents of your hard drive. You can use it to locate those large files that you haven&#8217;t accessed in one year, or to quickly locate the largest picture files on your drive.&#8221;</em></p></blockquote>
<p><img src="http://security-samizdat.com/wp-content/uploads/2007/11/gdmap.jpg" alt="GDMap" /></p>
<p>The software is available for free, but only for Windows systems. For Unix-like and Linux users, there are several options. One of them is <a href="http://gdmap.sourceforge.net/" target="_blank">GDMap</a>, which is very similar to SequoiaView, but with only some basic functionality implemented. For KDE desktops, there is the powerful <a href="http://kdirstat.sourceforge.net/" target="_blank">KDirStat</a> (there is a Windows clone called <a href="http://windirstat.info/" target="_blank">WinDirStat</a>). For Gnome users, there is <a href="http://www.marzocca.net/linux/baobab.html" target="_blank">Baobab</a>. A nice alternative is <a href="http://www.methylblue.com/filelight/" target="_blank">firelight</a>, which uses circular representation of treemaps to show similar data (only for KDE).</p>
<p>Wouldn&#8217;t it be nice if popular forensics packages, such as <a href="http://www.e-fense.com/helix/index.php" target="_blank">Helix</a>, bundled these kind of tools?</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/visualization-of-drive-contents/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/visualization-of-drive-contents/</feedburner:origLink></item>
		<item>
		<title>The War on Terror and the CYA attitude</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684586/</link>
		<comments>http://security-samizdat.com/the-war-on-terror-and-the-cya-attitude/#comments</comments>
		<pubDate>Thu, 01 Nov 2007 19:58:47 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/the-war-on-terror-and-the-cya-attitude/</guid>
		<description><![CDATA[Excellent article from Bruce Schneier:
&#8220;We&#8217;ve opened up a new front on the war on terror. It&#8217;s an attack on the unique, the unorthodox, the unexpected; it&#8217;s a war on different. If you act different, you might find yourself investigated, questioned, and even arrested &#8212; even if you did nothing wrong, and had no intention of [...]]]></description>
			<content:encoded><![CDATA[<p>Excellent article from Bruce Schneier:</p>
<blockquote><p><em>&#8220;We&#8217;ve opened up a new front on the war on terror. It&#8217;s an attack on the unique, the unorthodox, the unexpected; it&#8217;s a war on different. If you act different, you might find yourself investigated, questioned, and even arrested &#8212; even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats.&#8221;</em></p></blockquote>
<p>Read the <a href="http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html" target="_blank">complete article here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/the-war-on-terror-and-the-cya-attitude/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/the-war-on-terror-and-the-cya-attitude/</feedburner:origLink></item>
		<item>
		<title>Escalation of Privilege in Windows XP/2003</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684587/</link>
		<comments>http://security-samizdat.com/escalation-of-privilege-in-windows-xp2003/#comments</comments>
		<pubDate>Wed, 17 Oct 2007 08:35:51 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/escalation-of-privilege-in-windows-xp2003/</guid>
		<description><![CDATA[The Symantec Security Response blog reports a new local escalation of privilege vulnerability for Windows XP and Windows Server 2003 (fully patched and with latest Service Packs applied). Apparently Microsoft is already aware of the issue. Some driver included by default seems to be the culprit.

]]></description>
			<content:encoded><![CDATA[<p>The Symantec Security Response blog <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/10/privilege_escalation_exploit_i.html" target="_blank">reports a new local escalation of privilege vulnerability for Windows XP and Windows Server 2003</a> (fully patched and with latest Service Packs applied). Apparently Microsoft is already aware of the issue. Some driver included by default seems to be the culprit.</p>
<p><img src="http://security-samizdat.com/wp-content/uploads/2007/10/escalation.JPG" alt="Escalation of Privilege - Windows" /></p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/escalation-of-privilege-in-windows-xp2003/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/escalation-of-privilege-in-windows-xp2003/</feedburner:origLink></item>
		<item>
		<title>Forensics article in Spanish</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684588/</link>
		<comments>http://security-samizdat.com/forensics-article-in-spanish/#comments</comments>
		<pubDate>Tue, 16 Oct 2007 16:05:58 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/forensics-article-in-spanish/</guid>
		<description><![CDATA[If you can read Spanish, I&#8217;ve posted an article in three parts on my personal blog about Computing Forensics.

Informática Forense I
Informática Forense II
Informática Forense III

 UPDATE: The folks at Juris have translated the article to Portuguese (part I, part II, part III)
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.areino.com/wp-content/uploads/2007/10/policeline.jpg" align="right" height="169" width="250" />If you can read Spanish, I&#8217;ve posted an article in three parts on my personal blog about Computing Forensics.</p>
<ul>
<li><a href="http://www.areino.com/forensics-1" target="_blank">Informática Forense I</a></li>
<li><a href="http://www.areino.com/forensics-2" target="_blank">Informática Forense II</a></li>
<li><a href="http://www.areino.com/forensics-3" target="_blank">Informática Forense III</a></li>
</ul>
<p><strong> UPDATE: </strong><em>The folks at <a href="http://doc.jurispro.net/index.php" target="_blank">Juris</a> have translated the article to Portuguese (<a href="http://doc.jurispro.net/articles.php?lng=pt&amp;pg=9710" target="_blank">part I</a>, <a href="http://doc.jurispro.net/articles.php?lng=pt&amp;pg=9717" target="_blank">part II</a>, <a href="http://doc.jurispro.net/articles.php?lng=pt&amp;pg=9733" target="_blank">part III</a>)</em></p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/forensics-article-in-spanish/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/forensics-article-in-spanish/</feedburner:origLink></item>
		<item>
		<title>Storm Analysis</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684589/</link>
		<comments>http://security-samizdat.com/storm-analysis/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 15:56:37 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Papers]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/storm-analysis/</guid>
		<description><![CDATA[Don&#8217;t know what to read this weekend? :)
&#8220;A Multi-perspective Analysis of the Storm (Peacomm) Worm&#8221; by Phillip Porras, Hassen Saidi, and Vinod Yegneswaran. Also, some useful links in the same site with further info on Storm.
]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t know what to read this weekend? :)</p>
<p>&#8220;<a href="http://www.cyber-ta.org/pubs/StormWorm/" target="_blank">A Multi-perspective Analysis of the Storm (Peacomm) Worm</a>&#8221; by Phillip Porras, Hassen Saidi, and Vinod Yegneswaran. Also, some useful links in the same site with <a href="http://www.cyber-ta.org/pubs/StormWorm/links.html" target="_blank">further info on Storm</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/storm-analysis/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/storm-analysis/</feedburner:origLink></item>
		<item>
		<title>Exploits of a mom</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684590/</link>
		<comments>http://security-samizdat.com/exploits-of-a-mom/#comments</comments>
		<pubDate>Wed, 10 Oct 2007 06:36:13 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Fun and Weird]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/exploits-of-a-mom/</guid>
		<description><![CDATA[
Seen at xkcd
]]></description>
			<content:encoded><![CDATA[<p><a href="http://xkcd.com/327/" target="_blank"><img src="http://security-samizdat.com/wp-content/uploads/2007/10/exploits_of_a_mom.png" alt="XKCD" border="0" /></a></p>
<p>Seen at <a href="http://xkcd.com/327/" target="_blank">xkcd</a></p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/exploits-of-a-mom/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/exploits-of-a-mom/</feedburner:origLink></item>
		<item>
		<title>Counterintelligence</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684591/</link>
		<comments>http://security-samizdat.com/counterintelligence/#comments</comments>
		<pubDate>Thu, 04 Oct 2007 20:33:16 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/counterintelligence/</guid>
		<description><![CDATA[Interesting article on &#8220;counterintelligence&#8221; initiatives to proactively stop insider attacks and information leaks: &#8220;Insider Attacks Put IT Security on the Offensive&#8221; by Tim Wilson at DarkReading.com
&#8220;Companies are beginning to see that most of the tools they are using &#8212; firewalls, intrusion prevention, log analysis, even a lot of the data leak prevention tools &#8212; are [...]]]></description>
			<content:encoded><![CDATA[<p>Interesting article on &#8220;counterintelligence&#8221; initiatives to proactively stop insider attacks and information leaks: &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=135460&amp;WT.svl=news1_1" target="_blank">Insider Attacks Put IT Security on the Offensive</a>&#8221; by Tim Wilson at <a href="http://www.darkreading.com/" target="_blank">DarkReading.com</a></p>
<blockquote><p><em><font></font><font>&#8220;Companies are beginning to see that most of the tools they are using &#8212; firewalls, intrusion prevention, log analysis, even a lot of the data leak prevention tools &#8212; are really only useful after you&#8217;ve been compromised,&#8221; says Kevin Harvey, senior sales engineer at Fidelis, who has participated in hundreds of insider threat assessments for large enterprises. &#8220;What they&#8217;re looking to do now is develop ways to proactively seek out the threats and prevent them, rather than just find out who did it.&#8221;</font></em></p></blockquote>
<p>I wonder if it&#8217;s possible to implement this without companies misunderstanding it and turning their IT environments into Orwellian &#8220;ubiquitous law-enforcement&#8221; tools?</p>
<blockquote><p> <em><font>Another key piece of the &#8220;counterintelligence&#8221; puzzle is monitoring employee activity. &#8220;In our environment, any employee can use an online form to report suspicious activity,&#8221; says an IT security officer at a large banking company, who asked not to be identified. &#8220;That alerts corporate security, which then investigates. </font></em></p>
<p><em>[&#8230;]</em><em><font>Many experts also recommend using employee monitoring tools, which can help identify unusual behavior and activity at odd hours.</font></em></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/counterintelligence/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/counterintelligence/</feedburner:origLink></item>
		<item>
		<title>Spend less on IT Security</title>
		<link>http://feeds.feedburner.com/~r/SecuritySamizdat/~3/206684592/</link>
		<comments>http://security-samizdat.com/spend-less-on-it-security/#comments</comments>
		<pubDate>Fri, 21 Sep 2007 11:09:43 +0000</pubDate>
		<dc:creator>alfredo reino</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://security-samizdat.com/spend-less-on-it-security/</guid>
		<description><![CDATA[Two articles about the same issue. &#8220;Security to drop out of CIO spending top ten&#8221; by John Leyden at The Register, and &#8220;Spend less on IT Security, says Gartner&#8221; by SA Mathieson at InfoSecurity Magazine. Both come from a keynote speech by Gartner&#8217;s vice-president John Pescatore at the IT Security Summit in London this month.
From [...]]]></description>
			<content:encoded><![CDATA[<p>Two articles about the same issue. &#8220;<a href="http://www.theregister.co.uk/2007/09/18/security3_gartner/" target="_blank">Security to drop out of CIO spending top ten</a>&#8221; by John Leyden at The Register, and &#8220;<a href="http://www.infosecurity-magazine.com/news/070918_pescatore.html" target="_blank">Spend less on IT Security, says Gartner</a>&#8221; by SA Mathieson at InfoSecurity Magazine. Both come from a keynote speech by <a href="http://www.gartner.com/AnalystBiography?authorId=14409" target="_blank">Gartner&#8217;s vice-president John Pescatore</a> at the <a href="http://agendabuilder.gartner.com/sec8i/WebPages/Home.aspx" target="_blank">IT Security Summit</a> in London this month.</p>
<p>From <a href="http://www.infosecurity-magazine.com/news/070918_pescatore.html" target="_blank">Mathieson&#8217;s article</a>:</p>
<blockquote><p> Getting to a mature stage of IT security will take many organisations some time, Pescatore said: by 2010, Gartner estimates just a fifth will have reached its ‘operations excellence’ stage where they spend just 3-4% of IT on security, while two-fifths will still be in the previous ‘corrective’ stage, spending 7-8%.</p>
<p>In response to a question, Pescatore dismissed the idea that insider threats are growing: he believes that attacks generated by malicious insiders are stable at 20-25%. Half come from mistakes made by insiders, while around 30% of attacks are made solely by outsiders, the majority of whom are cybercriminals.</p></blockquote>
<p>From <a href="http://www.theregister.co.uk/2007/09/18/security3_gartner/" target="_blank">Leyden&#8217;s article</a>:</p>
<blockquote><p>For security managers the process involves persuading their counterparts in, for example, application development to include security functions in their projects. In this way security expenditure in real terms can go up even as security budgets (as such) stay flat or modestly increase. Security budgets freed from firefighting problems can then be invested with a view to managing future risks.</p>
<p>&#8220;Even a reduced security budget does not necessarily mean reducing security-related spending,&#8221; Pescatore said. &#8220;Security professionals need to think in terms of changing who pays for security controls,&#8221; so they can &#8220;move upstream&#8221; and spend their time and resources on more demanding projects, he added.</p>
<p>Gartner predicts that security spending will rise 9.3 per cent in 2007, but will drop out the first ten spending priorities for CIOs for the first time since the prolific internet worms of 2003. Malware threats these days have evolved into targeted attacks featuring malware payloads designed not to draw attention to themselves.</p></blockquote>
<p>It sounds reasonable. If all corporate departments assume their part in keeping the business secure (by means of security awareness, purchase of secure products and solutions, and inclusion of security-aware development practices, for example), the IT Security departments could shift from &#8220;firefighter mode&#8221; and focus on proactive security.</p>
]]></content:encoded>
			<wfw:commentRss>http://security-samizdat.com/spend-less-on-it-security/feed/</wfw:commentRss>
		<feedburner:origLink>http://security-samizdat.com/spend-less-on-it-security/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic Page Served (once) in 0.303 seconds -->
