<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: army]]></title>
    <link>http://securityratty.com/tag/army</link>
    <description></description>
    <pubDate>Fri, 18 Jul 2008 01:48:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[DTrace: The Reverse Engineer's Unexpected Swiss Army Knife]]></title>
      <link>http://securityratty.com/article/594df3f05ac0efe38d2eec8416609b2b</link>
      <guid>http://securityratty.com/article/594df3f05ac0efe38d2eec8416609b2b</guid>
      <description><![CDATA[David Weston is a security engineer at Science Applications International Corporation. In this video, made at Black Hat Europe, David illustrates his research related to DTrace. Created by SUN and...]]></description>
      <content:encoded><![CDATA[David Weston is a security engineer at Science Applications International Corporation. In this video, made at Black Hat Europe, David illustrates his research related to DTrace. Created by SUN and ori...]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 14:42:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/david weston">david weston</category>
      <category domain="http://securityratty.com/tag/black hat europe">black hat europe</category>
      <category domain="http://securityratty.com/tag/david">david</category>
      <category domain="http://securityratty.com/tag/dtrace">dtrace</category>
      <category domain="http://securityratty.com/tag/security engineer">security engineer</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/ori">ori</category>
      <category domain="http://securityratty.com/tag/sun">sun</category>
      <source url="http://www.net-security.org/article.php?id=1167">DTrace: The Reverse Engineer's Unexpected Swiss Army Knife</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[Soldiers Receive All-in-One Nonlethal Warfare Kit]]></title>
      <link>http://securityratty.com/article/7ba162df0c65e1fc7a3e90c514512abe</link>
      <guid>http://securityratty.com/article/7ba162df0c65e1fc7a3e90c514512abe</guid>
      <description><![CDATA[There are many ways to skin a cat without killing him, apparently, as the U.S. Army demonstrates with an array of new, nonlethal weapons designed for everything from checkpoint control to quelling...]]></description>
      <content:encoded><![CDATA[There are many ways to skin a cat without killing him, apparently, as the U.S. Army demonstrates with an array of new, nonlethal weapons designed for everything from checkpoint control to quelling rioters.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=979a1dd8929fcd1d0fcc49a33453b65c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=979a1dd8929fcd1d0fcc49a33453b65c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xPX3nK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xPX3nK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=9HxIyk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=9HxIyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=q98sik"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=q98sik" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=0KvFQK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=0KvFQK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=frUlEK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=frUlEK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xZg26k"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xZg26k" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=l9vx8k"><img src="http://feeds.wired.com/~f/wired/politics/security?i=l9vx8k" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=10FyQK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=10FyQK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/359612262" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/359612263" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nonlethal weapons">nonlethal weapons</category>
      <category domain="http://securityratty.com/tag/checkpoint control">checkpoint control</category>
      <category domain="http://securityratty.com/tag/array">array</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/skin">skin</category>
      <category domain="http://securityratty.com/tag/cat">cat</category>
      <category domain="http://securityratty.com/tag/rioters">rioters</category>
      <category domain="http://securityratty.com/tag/army">army</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/359612263/us-army-deploys.html">Soldiers Receive All-in-One Nonlethal Warfare Kit</source>
    </item>
    <item>
      <title><![CDATA[Anthrax Scientist Kills Self as Feds Close In]]></title>
      <link>http://securityratty.com/article/51b181213f10cd43bd7eb1fbea2d1fef</link>
      <guid>http://securityratty.com/article/51b181213f10cd43bd7eb1fbea2d1fef</guid>
      <description><![CDATA[An Army microbiologist, who U.S. officials believe was responsible for the 2001 anthrax attacks that killed five people, has apparently committed suicide just as prosecutors were getting ready to...]]></description>
      <content:encoded><![CDATA[An Army microbiologist, who U.S. officials believe was responsible for the 2001 anthrax attacks that killed five people, has apparently committed suicide just as prosecutors were getting ready to arrest him.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=d0ea55a0bc5bad066132659ec6194270"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=d0ea55a0bc5bad066132659ec6194270"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=d0ea55a0bc5bad066132659ec6194270" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=M9xMoK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=M9xMoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gjSbbk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gjSbbk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=n5CR1k"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=n5CR1k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=oSMNzK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=oSMNzK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=UiPe5K"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UiPe5K" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TDvFtk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TDvFtk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=MEH1Uk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=MEH1Uk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=vMjUpK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=vMjUpK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/352707610" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/352707628" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 10:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/anthrax attacks">anthrax attacks</category>
      <category domain="http://securityratty.com/tag/army microbiologist">army microbiologist</category>
      <category domain="http://securityratty.com/tag/suicide">suicide</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/responsible">responsible</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/prosecutors">prosecutors</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/352707628/ANTHRAX_SCIENTIST">Anthrax Scientist Kills Self as Feds Close In</source>
    </item>
    <item>
      <title><![CDATA[How to Do Business With a Blacklisted Russian Weapons Company]]></title>
      <link>http://securityratty.com/article/cc380277397a3b0bf3331cddc0ad43f4</link>
      <guid>http://securityratty.com/article/cc380277397a3b0bf3331cddc0ad43f4</guid>
      <description><![CDATA[The U.S. Army indirectly handed out $325 million to the blacklisted Russian weapons agency to buy nearly two dozen Russian Mi-17 helicopters for the Iraq war. Did officials knowingly violate...]]></description>
      <content:encoded><![CDATA[The U.S. Army indirectly handed out $325 million to the blacklisted Russian weapons agency to buy nearly two dozen Russian Mi-17 helicopters for the Iraq war. Did officials knowingly violate government sanctions?<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=249b23a44784988be8453de84c75068c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=249b23a44784988be8453de84c75068c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2aWNdJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2aWNdJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=m2qd1j"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=m2qd1j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=JYppJj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=JYppJj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lYb7iJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lYb7iJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=3y54VJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=3y54VJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=tQgZuj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=tQgZuj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=NdV9Zj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=NdV9Zj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OSfjhJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OSfjhJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/348773053" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/348787384" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 13:16:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian weapons agency">russian weapons agency</category>
      <category domain="http://securityratty.com/tag/russian mi-17 helicopters">russian mi-17 helicopters</category>
      <category domain="http://securityratty.com/tag/officials knowingly">officials knowingly</category>
      <category domain="http://securityratty.com/tag/government sanctions">government sanctions</category>
      <category domain="http://securityratty.com/tag/iraq war">iraq war</category>
      <category domain="http://securityratty.com/tag/army indirectly">army indirectly</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/348787384/how-to-do-busin.html">How to Do Business With a Blacklisted Russian Weapons Company</source>
    </item>
    <item>
      <title><![CDATA[Did the U.S. Army Arrange a 'Sweetheart' Deal to Sell Russian Helicopters to Iraq?]]></title>
      <link>http://securityratty.com/article/dc6744a214c10dff4ba18134b2dfab17</link>
      <guid>http://securityratty.com/article/dc6744a214c10dff4ba18134b2dfab17</guid>
      <description><![CDATA[Earlier this year, the Defense Department quietly gave a U.S. company a contract to provide 22 new Russian-made Mi-17 troop transport helicopters to the Iraqi military in a deal worth an eye-brow...]]></description>
      <content:encoded><![CDATA[Earlier this year, the Defense Department quietly gave a U.S. company a contract to provide 22 new Russian-made Mi-17 troop transport helicopters to the Iraqi military in a deal worth an eye-brow raising $325 million, DANGER ROOM learns.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=0a2f5eecd6409d413d01a72aa93c0db8"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=0a2f5eecd6409d413d01a72aa93c0db8"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=0a2f5eecd6409d413d01a72aa93c0db8" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=T0a4lJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=T0a4lJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TIwmoj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TIwmoj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=y4c6Aj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=y4c6Aj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7YxwoJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7YxwoJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=OgN25J"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OgN25J" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=PlLCbj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=PlLCbj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=XAnplj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XAnplj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=iiPCIJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=iiPCIJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/345717615" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/345717617" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 08:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/defense department quietly">defense department quietly</category>
      <category domain="http://securityratty.com/tag/iraqi military">iraqi military</category>
      <category domain="http://securityratty.com/tag/deal worth">deal worth</category>
      <category domain="http://securityratty.com/tag/contract">contract</category>
      <category domain="http://securityratty.com/tag/danger">danger</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/learns">learns</category>
      <category domain="http://securityratty.com/tag/provide">provide</category>
      <category domain="http://securityratty.com/tag/eye-brow">eye-brow</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/345717617/earlier-this-ye.html">Did the U.S. Army Arrange a 'Sweetheart' Deal to Sell Russian Helicopters to Iraq?</source>
    </item>
    <item>
      <title><![CDATA[ Washington Post Comments on Terrorist Plots]]></title>
      <link>http://securityratty.com/article/2ee2a966a24904d622bc50ab9e471893</link>
      <guid>http://securityratty.com/article/2ee2a966a24904d622bc50ab9e471893</guid>
      <description><![CDATA[From this article , published last April: Batiste confided, somewhat fantastically, that he wanted to blow up the Sears Tower in Chicago, which would then fall into a nearby prison, freeing Muslim...]]></description>
      <content:encoded><![CDATA[<p>From <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/04/20/AR2008042002227.html">this article</a>, published last April:</p>

<blockquote>Batiste confided, somewhat fantastically, that he wanted to blow up the Sears Tower in Chicago, which would then fall into a nearby prison, freeing Muslim prisoners who would become the core of his Moorish army. With them, he would establish his own country.</blockquote>

<p><i>Somewhat</i> fantastically?  What would the <i>Washington Post</i> consider to be truly fantastic?  A plan involving Godzilla?  Clearly they have some very high standards.</p>

<p>I'm sick of people taking these <a href="http://www.schneier.com/blog/archives/2007/06/portrait_of_the_1.html">idiots</a> seriously.  This plot is beyond fantastic, it's delusional.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=KxyvJJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=KxyvJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=99TfCJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=99TfCJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 02:48:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/washington post">washington post</category>
      <category domain="http://securityratty.com/tag/moorish army">moorish army</category>
      <category domain="http://securityratty.com/tag/fantastic">fantastic</category>
      <category domain="http://securityratty.com/tag/nearby prison">nearby prison</category>
      <category domain="http://securityratty.com/tag/sears tower">sears tower</category>
      <category domain="http://securityratty.com/tag/muslim prisoners">muslim prisoners</category>
      <category domain="http://securityratty.com/tag/core">core</category>
      <category domain="http://securityratty.com/tag/batiste">batiste</category>
      <category domain="http://securityratty.com/tag/april">april</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/washington_post.html"> Washington Post Comments on Terrorist Plots</source>
    </item>
    <item>
      <title><![CDATA[On Government Employees, Culture, and Survivability]]></title>
      <link>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</link>
      <guid>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</guid>
      <description><![CDATA[A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert. One thing he said still sticks in my mind...]]></description>
      <content:encoded><![CDATA[<p>A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert.  One thing he said still sticks in my mind (obviously paraphrased):</p>
<blockquote><p>&#8220;The Afghanis, they live in mud huts, they don&#8217;t have electricity, they are stick-people weighing 85 lbs, and to say that we could bomb them into the stone age would be an advancement in their technology level.  But never underestimate these people, they&#8217;re survivors.  They&#8217;ve survived 35 years of warfare, starting with the Soviets, then they fought a civil war before we arrived on the scene.  Never underestimate their ability to survive, and have respect for them because of who they are.&#8221;</p></blockquote>
<p>Today, I feel the same way about government employees, even more so because it&#8217;s an election year:  they&#8217;re survivors.</p>
<p>Now time for what I see is the &#8220;real&#8221; reason why the government is doing badly (if that&#8217;s what you believe&#8211;opinions differ) at security: it&#8217;s all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious:</p>
<ul>
<li>Pride at making a difference</li>
<li>Helping people</li>
<li>Supporting a cause</li>
<li>Gaining unique experience on a global-class scope</li>
<li>Job stability</li>
<li>Retirement benefits</li>
</ul>
<p>And one thing is noticeably absent: better pay and personal recognition.  Hey, sounds like me in the army.</p>
<p style="text-align: center;"><em><img src="http://farm2.static.flickr.com/1348/1470902823_4a5145322e.jpg?v=0" alt="The Companion Family Plan to Survival at Home" width="362" height="500" /></em></p>
<p style="text-align: center;"><em>The Companion Family Plan for Survival at Home photo by <a href="http://www.flickr.com/photos/jikan/" target="_blank">Uh &#8230; Bob</a>.</em></p>
<p>Now I&#8217;m not trying to stereotype, but you need to know the organizational behavior pieces to understand how government security works. And in this case, the typical government employee is about as survival-aware as their Afghani counterpart.</p>
<p>Best advice I ever heard from a public policy wonk: the key to survival in this town is to influence everything you can get your hands on and never have your name actually written on anything.</p>
<p>In other words, don&#8217;t criticize, be nice to everybody even though you think they are a jerk, and avoid saying anything at all because you never know when it will be contrary to the political scene.  The Government culture is a silent culture. That&#8217;s why every day amazing things happen to promote security in the Government and you&#8217;ll never hear about it on the outside.</p>
<p>One of the reasons that I started blogging was to counter the naysayers who say that FISMA is failing and that the Government would succeed if they would just buy their product for technical policy compliance or end-to-end encryption.  Sadly, the true heroes in Government, the people who just do their job every day and try to survive a hostile political environment, are giving credit to the critics because of their silence.</p>
<p>Which brings me to my point:</p>
<p>Yes, my name is Rybolov and I&#8217;m a heretic, but this is the secret to security in the Government:  it&#8217;s cultural at all layers of the personnel stack.  Security (and innovation, now that I think about it) needs a culture of openness where it&#8217;s allowable to make mistakes and/or criticize.  Doesn&#8217;t sound like any government&#8211;local, state, or federal&#8211;that I&#8217;ve ever seen.  However, if you fix the culture, you fix the security.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" alt="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to digg" alt="Add 'On Government Employees, Culture, and Survivability' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to reddit" alt="Add 'On Government Employees, Culture, and Survivability' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=On+Government+Employees%2C+Culture%2C+and+Survivability&amp;url=http://www.guerilla-ciso.com/archives/298&amp;version=0.7" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" alt="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Technorati" alt="Add 'On Government Employees, Culture, and Survivability' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/298&amp;t=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" alt="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" alt="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" alt="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo" alt="Add 'On Government Employees, Culture, and Survivability' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines" alt="Add 'On Government Employees, Culture, and Survivability' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=KQw1LJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=KQw1LJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=8UDDwj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=8UDDwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/341552257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/government security">government security</category>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/government culture">government culture</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/typical government employee">typical government employee</category>
      <category domain="http://securityratty.com/tag/promote security">promote security</category>
      <category domain="http://securityratty.com/tag/silent culture">silent culture</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/341552257/298">On Government Employees, Culture, and Survivability</source>
    </item>
    <item>
      <title><![CDATA[The Langley Files]]></title>
      <link>http://securityratty.com/article/1d86287caa54b846b08a3d1020799d36</link>
      <guid>http://securityratty.com/article/1d86287caa54b846b08a3d1020799d36</guid>
      <description><![CDATA[The Central Intelligence Agency doesn't like to talk about its mistakes. It's not just embarrassing, but officials believe exposing details about how an operation went wrong reveals too much about how...]]></description>
      <content:encoded><![CDATA[The Central Intelligence Agency doesn't like to talk about its mistakes. It's not just embarrassing, but officials believe exposing details about how an operation went wrong reveals too much about how it captures enemy secrets. But published statements and news reports suggest one recent error-the U.S. bombing of the Chinese embassy in Belgrade during the Kosovo war last year, which killed three and injured 20-happened in part because CIA officers targeted what they thought was a Yugoslav Army warehouse based on outdated maps, and others failed to catch the mistake before the proposal was passed to the military.]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central intelligence agency">central intelligence agency</category>
      <category domain="http://securityratty.com/tag/captures enemy secrets">captures enemy secrets</category>
      <category domain="http://securityratty.com/tag/cia officers">cia officers</category>
      <category domain="http://securityratty.com/tag/recent error-the">recent error-the</category>
      <category domain="http://securityratty.com/tag/kosovo war">kosovo war</category>
      <category domain="http://securityratty.com/tag/wrong reveals">wrong reveals</category>
      <category domain="http://securityratty.com/tag/news reports">news reports</category>
      <category domain="http://securityratty.com/tag/chinese embassy">chinese embassy</category>
      <category domain="http://securityratty.com/tag/statements">statements</category>
      <source url="http://www.networkworld.com/news/2008/072108-the-langley.html?fsrc=rss-security">The Langley Files</source>
    </item>
    <item>
      <title><![CDATA[The Ayyildiz Turkish Hacking Group VS Everyone]]></title>
      <link>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</link>
      <guid>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</guid>
      <description><![CDATA[Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div style="text-align: left;"></div><div class="" style="clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/dn0skav9XIg/s1600-h/AYYILDIZ_TEAM.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/mYlVgqX-mVU/s200-R/AYYILDIZ_TEAM.jpg" style="border: 0pt none ;" /></a>Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure and reputation on the international scene, smart enough to do on one front, there are certain hacktivist groups who ensure their future existence by declaring war and every single country that has ever made statements in contradiction with their vision. Quite a stimulating factor for ensuring the future of your script kiddies group, isn't it?<br />
<br />
One of these groups is the AYYILDIZ TEAM, a group of Turkish script kiddies who've been pretty active as of recently, targeting everyone, everywhere, leaving statements like the following :</div><br />
"<i>Me, as AYT-Admin Barbaros, swear to everything which is lovely and holy to me, that you will pay for your actions. We, AYT, as a Cyber Attacking Army will make it sure. Read right, what will we do:<br />
<br />
* The government websites will be inaccessible an all lawsuits will be manipulated</i><br />
<i>* We will infiltrate the server of inland revenues for the manipulation of the data which are there.</i><br />
<i>* At the same time we will insist into the server of banks and will care for chaos</i><br />
<i>* Websites of the press will be extinguished.</i><br />
<i>* If the offence of our prophet (s.a.v.) called your press freedom, we will show you this press freedom</i><br />
<i>* Websites of divers shops will be hacked. Databank information's and the dates which are there, for example credit card dates, will be policed in this page. (Don't worry, we wouldn't taste one cent of your moneys, we aren't thieves like you. However we don't take care of what happens, if other hackers see this dates and empty your account)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/WwX3npoBZvI/s1600-h/SQL_turkz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/saIYE3fxpdA/s200-R/SQL_turkz.JPG" style="border: 0pt none ;" /></a>While this may sound inspiring, <b>some of the group's members are also involved in SQL injections in between the web site defacements</b>, which are naturally done by exploiting web application vulnerabilities. For instance, right after the defacement messages, they are also injecting the following fast-fluxed domains, part of the latest wave of SQL injections attacks.<b></b><br />
<br />
<b>bkpadd.mobi /ngg.js<br />
usaadw.com /ngg.js<br />
cliprts.com /ngg.js</b><br />
<br />
They are monetizing their defacements by either compiling lists of sites known to be SQL injectable since they've managed to defaced them, then reselling these to the SQL injectors, or are in fact part of the whole process in this scammy ecosystem. Speaking of SQL injections, here's the most recent list of fast-fluxed SQL injected domains participating in the last wave that I've been keeping track of for a while :<br />
<br />
<b>pyttco .com/ngg.js<br />
butdrv .com/ngg.js<br />
gitporg .com/ngg.js<br />
brcporb .ru/ngg.js<br />
korfd .ru/ngg.js<br />
adwnetw .com/ngg.js<br />
wowofmusiopl .com.cn/456.js<br />
adwbn .ru/ngg.js<br />
btoperc .ru/ngg.js<br />
nudk .ru/ngg.js<br />
bkpadd .mobi/ngg.js<br />
cliprts .com/ngg.js<br />
adwr .ru/ngg.js<br />
bnrc .ru/ngg.js<br />
adpzo .com/ngg.js<br />
iogp .ru/ngg.js<br />
lodse .ru/ngg.js<br />
usabnr .com/ngg.js<br />
vcre .ru/ngg.js<br />
sdkj .ru/ngg.js<br />
rcdplc .ru/ngg.js<br />
7maigol .cn/ri.js<br />
j8heisi .cn/ri.js<br />
usaadp .com/ngg.js<br />
gbradp .com/ngg.js<br />
cdrpoex .com/ngg.js<br />
rrcs .ru/ngg.js<br />
gbradw .com/ngg.js<br />
hiwowpp .cn/ri.js<br />
cdport .eu/ngg.js<br />
nopcls .com/ngg.js<br />
loopadd .com/ngg.js<br />
tertad .mobi/ngg.js<br />
gbradde .tk/ngg.js<br />
tctcow .com/ngg.js<br />
ausbnr .com/ngg.js<br />
movaddw .com/ngg.js<br />
grtsel .ru/ngg.js<br />
sslwer .ru/ngg.js<br />
destad .mobi/ngg.js<br />
hdrcom .com/ngg.js<br />
addrl .com/ngg.js<br />
porttw .mobi/ngg.js<br />
bnsdrv .com/ngg.js<br />
drvadw .com/ngg.js<br />
crtbond .com/ngg.js<br />
usaadw .com/ngg.js</b><br />
<br />
What used to be plain simple cooperating among every single participant in the underground marketplace, seems to be evolving into long-term business relationships.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br />
<a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=727PxJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=727PxJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JwIAWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JwIAWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RvHRWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RvHRWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZamBlj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZamBlj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YzU9yJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YzU9yJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2kBf4J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2kBf4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LV5ldj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LV5ldj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338894561" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 01:48:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/comngg">comngg</category>
      <category domain="http://securityratty.com/tag/sql injections attacks">sql injections attacks</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/rungg">rungg</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338894561/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</source>
    </item>
  </channel>
</rss>
