<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: campaigns]]></title>
    <link>http://securityratty.com/tag/campaigns</link>
    <description></description>
    <pubDate>Tue, 04 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Embassy of Brazil in India Compromised]]></title>
      <link>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</link>
      <guid>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</guid>
      <description><![CDATA[Only an amateur or unethical competition would embedd malicious links at the Embassy of Brazil in India's site , referencing their online community. With the chances of an Embassy involvement into the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s1600-h/brazil_embassy_india_compromised_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s200/brazil_embassy_india_compromised_1.JPG" /></a>Only an amateur or unethical competition would embedd <a href="http://securitylabs.websense.com/content/Alerts/3228.aspx">malicious links at the Embassy of Brazil in India's site</a>, referencing their online community. With the chances of <a href="http://www.brazilembassy.in/">an Embassy</a> involvement into the fake antivirus software industry close to zero,<br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s1600-h/brazil_embassy_free_web_space_rogue.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s200/brazil_embassy_free_web_space_rogue.JPG" /></a>The compromise is a great example of a mixed use of pure malicious domains in a combination with compromised legitimate ones and on purposely registered accounts at free web space providers, hosting the blackhat SEO content. However, digging deeper we expose the entire malicious doorways ecosystem pushing PDF exploits, banker malware and Zlob variants. The malicious attackers embedded links to their blackhat SEO farms advertising fake security software, and also a link to a traffic redirection doorway<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><b>epmwckme.dex1.com</b><br />
<b>htkobaf.dex1.com</b><br />
<b>ogbucof.dex1.com</b><br />
<b>segundomuelle.com/mex/antivirus</b><br />
<b>jgzleaa.dex1.com</b><br />
<b>igpran.ru/services/tolstye</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s1600-h/obfuscation_brazil_embassy.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s200/obfuscation_brazil_embassy.JPG" /></a>The active and redirecting <b>traff .asia</b> (89.149.251.203) is currently serving a fake account suspended notice - "<i>This account has been suspended. Either the domain has been overused, or the reseller ran out of resources.</i>" but is whatsoever redirecting us to <b>antimalware09 .net</b>. This particular traffic redirection doorway is actively redirecting us to a command and control server running a well known web malware exploitation kit which is currently serving PDF exploits. <b>&nbsp;</b><br />
<br />
<b>google-analyze .com/socket/index.php</b> (216.195.59.77) from where we're redirected to <b>google-analyze.com/tracker/load.php</b> which is serving system.exe (Trojan-Spy.Win32.Zbot.ehk; Win32.TrojanSpy.Zbot.gen!C.5), and <b>google-analyze .com/tracker/pdf.php</b> (Exploit:Win32/Pdfjsc.G; Exploit.JS.Pdfka.w; Bloodhound.Exploit.196). Naturally, within the live exploit URLs there are multiple IFRAMEs redirecting us to more of this group's campaigns. <b>google-analyze .com</b>&nbsp; has multiple IFRAMEs pointing to <b>google-analystic .net</b> (209.160.67.56), yet another traffic redirection doorway further exposing their campaigns.<br />
<br />
For instance, <b>google-analystic .net/in.cgi?20</b> loads <b>google-analystic.net/tea.php</b> (209.160.67.56) where <b>google-analystic .net/in.cgi?8</b> is redirecting to <b>91.203.93.61 /in.cgi?2</b> taking us to <b>91.203.93.61 /25/2/</b> where we deobfuscate the javascript leading us to the exact location of the PDF exploit - <b>91.203.93.61 /25/2/getfile.php?f=pdf</b>. This is just for starters. <b>google-analystic .net/in.cgi?9</b> redirects to <b>mangust32 .cn/pod/index.php</b> (218.93.202.102) where they serve load.exe (Backdoor:Win32/Koceg.gen!A) at <br />
<b>mangust32 .cn/pod2/load.php</b> and load.exe at <b>mangust32 .cn/eto2/load.php</b>, moreover, <b>google-analystic .net/in.cgi?10</b> leads us to <b>mmcounter .com/in.cgi?id194</b> (94.102.50.130) a traffic management login which is no longer responding. The last IFRAME found within google-analystic points to <b>busyhere .ru/in.cgi?pipka</b> which redirects to <b>beshragos .com/work/index.php</b> (79.135.187.38) where once we<br />
deobfuscate the script, we get to see the PDF exploit location <b>beshragos.com /work/getfile.php?f=pdf</b>.<br />
<br />
What's contributing to the increase of PDF exploits durin the last month? It's an updated version of a web based malware exploitation tool, which despite the fact that it remains proprietary for the time being, will leak in the next couple of weeks causing the usual short-lived epidemic.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate in St. Petersburg Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">French Embassy in Libya Serving Malware</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GVhoN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GVhoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1M6tN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1M6tN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BksVn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BksVn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u03In"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u03In" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HzjZN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HzjZN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9KBON"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9KBON" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2Qbtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2Qbtn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451892286" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 06:47:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/embassy">embassy</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/traffic redirection doorway">traffic redirection doorway</category>
      <category domain="http://securityratty.com/tag/syrian embassy">syrian embassy</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/live exploit urls">live exploit urls</category>
      <category domain="http://securityratty.com/tag/cgi">cgi</category>
      <category domain="http://securityratty.com/tag/pdf exploits durin">pdf exploits durin</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451892286/embassy-of-brazil-in-india-compromised.html">Embassy of Brazil in India Compromised</source>
    </item>
    <item>
      <title><![CDATA[Dissecting the Latest Koobface Facebook Campaign]]></title>
      <link>http://securityratty.com/article/86c70e5d2e4da8aa581ee9216947ac9a</link>
      <guid>http://securityratty.com/article/86c70e5d2e4da8aa581ee9216947ac9a</guid>
      <description><![CDATA[The latest Koobface malware campaign at Facebook , is once again exposing a diverse ecosystem worth assessing in times of active migration to alternative ISPs tolerating or conveniently ignoring the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRrlN5c-LfI/AAAAAAAACb8/oG5zfHxekJ4/s1600-h/koobface_facebook_redirections.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRrlN5c-LfI/AAAAAAAACb8/oG5zfHxekJ4/s200/koobface_facebook_redirections.JPG" /></a>The latest <a href="http://blogs.zdnet.com/security/?p=2146">Koobface malware campaign at Facebook</a>, is once again exposing a diverse ecosystem worth assessing in times of active migration to alternative ISPs tolerating or conveniently ignoring the malicious activities courtesy of their customers. The -- now removed -- binaries that the dropper was requesting were hosted at the American International Baseball Club in Vienna, indicating a compromise.<br />
<br />
us.geocities .com/adanbates84/index.htm<br />
<b>lostart .info/js/js.js</b> (79.132.211.51)<br />
<b>off34 .com/go/fb.php</b> (79.132.211.51)<br />
<b>youtube-spyvideo .com/youtube_file.html</b> (58.241.255.37)<br />
<b>ahdirz .com/movie1.php?id=638&amp;n=teen</b> (208.85.181.69)<br />
<b>top100clipz .com/m6/movie1.php?id=638&amp;n=teen</b> (208.85.181.67)<br />
<b>hq-vidz .com/movie1.php?id=638&amp;n=teen</b> (208.85.181.68)<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRwwNw6BKZI/AAAAAAAACcU/_coWTkcVuVM/s1600-h/koobface_facebook_activex.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRwwNw6BKZI/AAAAAAAACcU/_coWTkcVuVM/s200/koobface_facebook_activex.png" /></a>The dropper then phones back home to : <b>f071108 .com/fb/first.php</b> (79.132.211.50) with the binaries hosted at a legitimate site that's been compromised :<br />
<br />
<b>aibcvienna.org/youtube/ bnsetup24.exe</b><br />
<b>aibcvienna.org/youtube/ tinyproxy.exe </b><br />
<br />
Related fake Youtube domains participating :<br />
<b>catshof .com </b>(79.132.211.51)<br />
<b>youtube-spy .info </b>(94.102.60.119)<br />
<b>youtubehof .net </b>(218.93.205.30)<br />
<b>youtube-spyvideo .com </b>(58.241.255.37)<br />
<b>yyyaaaahhhhoooo.ocom .pl </b>(67.15.104.83)<br />
<b>youtube-x-files .com </b>(94.102.60.119) <br />
<br />
The development of cybercrime platforms utilizing legitimate infrastructure only, has always been in the works. With spamming systems relying exclusively on the automatically registered email accounts at free web based providers, to the automatic bulk registration of hundreds of thousands of domains enjoying a particular domain registrar's weak anti-abuse policies, it would be interesting to monitor whether <a href="http://www.renesys.com/blog/2008/09/internet_vigilantism_1.shtml">marginal thinking</a> or <a href="http://ddanchev.blogspot.com/2008/10/cost-of-anonymizing-cybercriminals.html">improved OPSEC relying on compromised hosts</a> will be favored in 2009.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">Phishing Campaign Spreading Across Facebook</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/large-scale-myspace-phishing-attack.html">Large Scale MySpace Phishing Attack</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/12/update-on-myspace-phishing-campaign.html">Update on the MySpace Phishing Campaign</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2008/01/myspace-phishers-now-targeting-facebook.html">MySpace Phishers Now Targeting Facebook</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2008/05/myspace-hosting-myspace-phishing.html">MySpace Hosting MySpace Phishing Profiles</a><span style="font-weight: bold;"></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b95SN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b95SN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eLeKN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eLeKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7mCXn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7mCXn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gPM0n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gPM0n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2GlmN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2GlmN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aavTN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aavTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NgiDn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NgiDn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451825134" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 05:08:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <category domain="http://securityratty.com/tag/myspace phishers">myspace phishers</category>
      <category domain="http://securityratty.com/tag/facebook malware campaigns">facebook malware campaigns</category>
      <category domain="http://securityratty.com/tag/koobface malware campaign">koobface malware campaign</category>
      <category domain="http://securityratty.com/tag/scale myspace">scale myspace</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/fake youtube domains">fake youtube domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451825134/dissecting-latest-koobface-facebook.html">Dissecting the Latest Koobface Facebook Campaign</source>
    </item>
    <item>
      <title><![CDATA[The Economics of Spam]]></title>
      <link>http://securityratty.com/article/ce621f4781770ea2968bfaa3678135c2</link>
      <guid>http://securityratty.com/article/ce621f4781770ea2968bfaa3678135c2</guid>
      <description><![CDATA[Excellent paper on the economics of spam. The authors infiltrated the Storm worm and monitored its doings. After 26 days, and almost 350 million e-mail messages, only 28 sales resulted -- a conversion...]]></description>
      <content:encoded><![CDATA[<p>Excellent <a href="http://www.icsi.berkeley.edu/pubs/networking/2008-ccs-spamalytics.pdf">paper</a> on the economics of spam.  The authors infiltrated the Storm worm and monitored its doings.</p>

<blockquote>After 26 days, and almost 350 million e-mail messages, only 28 sales resulted -- a conversion rate of well under 0.00001%. Of these, all but one were for male-enhancement products and the average purchase price was close to $100. Taken together, these conversions would have resulted in revenues of $2,731.88 -- a bit over $100 a day for the measurement period or $140 per day for periods when the campaign was active. However, our study interposed on only a small fraction of the overall Storm network -- we estimate roughly 1.5 percent based on the fraction of worker bots we proxy. Thus, the total daily revenue attributable to Storm's pharmacy campaign is likely closer to $7000 (or $9500 during periods of campaign activity). By the same logic, we estimate that Storm self-propagation campaigns can produce between 3500 and 8500 new bots per day.

<p>Under the assumption that our measurements are representative over time (an admittedly dangerous assumption when dealing with such small samples), we can extrapolate that, were it sent continuously at the same rate, Storm-generated pharmaceutical spam would produce roughly 3.5 million dollars of revenue in a year. This number could be even higher if spam-advertised pharmacies experience repeat business. A bit less than "millions of dollars every day," but certainly a healthy enterprise.</blockquote></p>

<p>Of course, the authors point out that it's dangerous to make these sorts of generalizations:</p>

<blockquote>We would be the first to admit that these results represent a single data point and are not necessarily representative of spam as a whole. Different campaigns, using different tactics and marketing different products will undoubtedly produce different outcomes. Indeed, we caution strongly against researchers using the conversion rates we have measured for these Storm-based campaigns to justify assumptions in any other context.</blockquote>

<p>Spam is all about economics.  When sending junk mail costs a dollar in paper, list rental, and postage, a marketer needs a reasonable conversion rate to make the campaign worthwhile.  When sending junk mail is almost free, a one in ten million conversion rate is acceptable.</p>

<p><a href="http://voices.washingtonpost.com/securityfix/2008/11/study_spam_still_profitable_at.html">News</a> <a href="http://www.theregister.co.uk/2008/11/10/storm_botnet_spam_economics/">articles</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=MWN9N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=MWN9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CvOtN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CvOtN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 03:52:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/campaign activity">campaign activity</category>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/conversion">conversion</category>
      <category domain="http://securityratty.com/tag/reasonable conversion">reasonable conversion</category>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/junk mail costs">junk mail costs</category>
      <category domain="http://securityratty.com/tag/produce">produce</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_economics_o.html">The Economics of Spam</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[Report: White House e-mail system attacked]]></title>
      <link>http://securityratty.com/article/2e917094401650b6a1da3d84bcbe90ec</link>
      <guid>http://securityratty.com/article/2e917094401650b6a1da3d84bcbe90ec</guid>
      <description><![CDATA[It was revealed this week that the presidential campaigns of Barack Obama and John McCain were hacked over the summer. Now, a report has surfaced that the White House has suffered multiple attacks in...]]></description>
      <content:encoded><![CDATA[It was revealed this week that the presidential campaigns of Barack Obama and John McCain were hacked over the summer. Now, a report has surfaced that the White House has suffered multiple attacks in recent months as well.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/tPk4RP7FHA4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 08 Nov 2008 15:30:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/white house">white house</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/presidential campaigns">presidential campaigns</category>
      <category domain="http://securityratty.com/tag/recent months">recent months</category>
      <category domain="http://securityratty.com/tag/multiple attacks">multiple attacks</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/john mccain">john mccain</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/summer">summer</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/tPk4RP7FHA4/Report_White_House_e_mail_system_attacked">Report: White House e-mail system attacked</source>
    </item>
    <item>
      <title><![CDATA[US Government Detects Attacks on Obama and McCain Computers]]></title>
      <link>http://securityratty.com/article/6097824d379ae9660e32fe10fd040b20</link>
      <guid>http://securityratty.com/article/6097824d379ae9660e32fe10fd040b20</guid>
      <description><![CDATA[Now that the presidential race is over Newsweek is reporting that the US Government, through the FBI and Secret Service, notified the Obama and McCain campaigns that their computers had been...]]></description>
      <content:encoded><![CDATA[<p>Now that the presidential race is over <a href="http://www.newsweek.com/id/167581">Newsweek is reporting</a> that the US Government, through the FBI and Secret Service, notified the Obama and McCain campaigns that their computers had been compromised and sensitive documents copied. </p>
<blockquote><p>&#8230;the FBI and the Secret Service came to the campaign with an ominous warning: &#8220;You have a problem way bigger than what you understand,&#8221; an agent told Obama&#8217;s team. &#8220;You have been compromised, and a serious amount of files have been loaded off your system.&#8221; The following day, Obama campaign chief David Plouffe heard from White House chief of staff Josh Bolten, to the same effect: &#8220;You have a real problem &#8230; and you have to deal with it.&#8221; The Feds told Obama&#8217;s aides in late August that the McCain campaign&#8217;s computer system had been similarly compromised.</p></blockquote>
<p>This information demonstrates that the US government has a sophisticated intrusion detection capability.  This is likely part of the <a href="http://www.spamdailynews.com/publish/ATT_tech_outs_NSA_spy_room.asp">NSA internet surveillance system</a> that was made public by an AT&#038;T technician in 2006.  </p>
<p><center><img alt="" src="http://www.spamdailynews.com/uploads/intercept-diagram-1.gif" class="photonoborder" width="432" height="233" /></center></p>
<p>It is likely that the system has a set of watch IP ranges that are sensitive from a national security perspective.  The campaigns&#8217; computers were probably on this list. The traffic between foreign IP addresses and these watch IPs is then scrutinized for espionage.  The pattern of activity flagged would be Microsoft Office documents and PDFs being retrieved or other intruder signs such as an encrypted tunnel with a foreign endpoint.</p>
<p>This shows that the US Government has the capability to detect some types foreign attacks although they probably have to be selective of the IP ranges they monitor.  It&#8217;s nice to know that if the White House computers were leaking documents to China or Russia that there is some detection capability, but the fact that this is done at the Internet backbone level means any IP could be targeted and it might not just be to look for foreign intrusions.</p>
]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 13:18:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/intrusion detection capability">intrusion detection capability</category>
      <category domain="http://securityratty.com/tag/detection capability">detection capability</category>
      <category domain="http://securityratty.com/tag/foreign">foreign</category>
      <category domain="http://securityratty.com/tag/foreign intrusions">foreign intrusions</category>
      <category domain="http://securityratty.com/tag/sensitive">sensitive</category>
      <category domain="http://securityratty.com/tag/sensitive documents">sensitive documents</category>
      <category domain="http://securityratty.com/tag/documents">documents</category>
      <category domain="http://securityratty.com/tag/white house computers">white house computers</category>
      <source url="http://www.veracode.com/blog/2008/11/us-government-detects-attacks-on-obama-and-mccain-computers/">US Government Detects Attacks on Obama and McCain Computers</source>
    </item>
    <item>
      <title><![CDATA[DIY Phishing Pages With Command and Control Interfaces]]></title>
      <link>http://securityratty.com/article/78a81ce667063a0a1268788bb3f66128</link>
      <guid>http://securityratty.com/article/78a81ce667063a0a1268788bb3f66128</guid>
      <description><![CDATA[The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s1600-h/rapidshare_phishing_admin_panel.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRIwl6hmo2I/AAAAAAAACa8/_1fYFgW0kzk/s200/rapidshare_phishing_admin_panel.jpg" /></a>The day when DIY phishing pages start coming with manuals is the day when consciously or subconsciously a phisher is lowering down the entry barriers into phishing for yet another time. A much more user-friendly compared to the old-fashioned -- yet effective -- <a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">rock phish directory listing</a>, a recently released command and control interface for Rapidshare phishing campaigns aims to empower its users with easy dynamic link generation for their campaigns.<br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s1600-h/DIY_phishing_scripts.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLdeRIJEbI/AAAAAAAACbE/ta5F-iiF2gg/s200/DIY_phishing_scripts.JPG" /></a>What they've managed to achieve is another trust factor since Rapidshare generates a second dynamic link upon clicking on the original one. The script not only generates a dynamically looking link, but also, actually logs in the victim into their account in order to avoid suspicion whereas it still logs all the accounting data.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s1600-h/rapidshare_phishing_insecure_directory_permissions.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRLhzGDKcrI/AAAAAAAACbM/5-CHdeukArk/s200/rapidshare_phishing_insecure_directory_permissions.JPG" /></a></div>Scammers also tend to be ironic every then and now. For instance, in this particular case, one of the users finds it ironic that the Rapidshare phishing page is hosted at Rapidshare itself. Is the script actually working? It appears so at least going through a misconfigured accounting data dump left by one of the phishers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">Phishing Pages for Every Bank are a Commodity</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/diy-phishing-kits.html">DIY Phishing Kits</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/diy-phishing-kit-goes-20.html">DIY Phishing Kit Goes 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY Phishing Kits Introducing New Features</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5kY3N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5kY3N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=r8EaN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=r8EaN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qtrtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qtrtn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qM6qn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qM6qn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T3U6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T3U6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YwrRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YwrRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nQNrn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nQNrn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/444324371" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 03:31:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diy">diy</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/rapidshare">rapidshare</category>
      <category domain="http://securityratty.com/tag/data dump">data dump</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://securityratty.com/tag/dynamic link">dynamic link</category>
      <category domain="http://securityratty.com/tag/pages start">pages start</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/444324371/diy-phishing-pages-with-command-and.html">DIY Phishing Pages With Command and Control Interfaces</source>
    </item>
    <item>
      <title><![CDATA[After Election: Files Stolen In Obama And McCain Campaigns Cyberattack, Obama-themed Malware Makes Rounds]]></title>
      <link>http://securityratty.com/article/0c4e9a71391fb0ab0e26aae5e887723d</link>
      <guid>http://securityratty.com/article/0c4e9a71391fb0ab0e26aae5e887723d</guid>
      <description><![CDATA[According to an article published Wednesday by Newsweek, hackers broke into computer systems of both the Barack Obama and John McCain campaigns and stole a large amount of data Officials with the FBI...]]></description>
      <content:encoded><![CDATA[According to an article published Wednesday by Newsweek, hackers broke into computer systems of both the Barack Obama and John McCain campaigns and stole a large amount of data
Officials with the FBI and the Secret Service notified Obama staffers in August of the breach after tech consultants for the campaign detected what they thought at [...]]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 21:49:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john mccain campaigns">john mccain campaigns</category>
      <category domain="http://securityratty.com/tag/secret service">secret service</category>
      <category domain="http://securityratty.com/tag/computer systems">computer systems</category>
      <category domain="http://securityratty.com/tag/data officials">data officials</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/obama staffers">obama staffers</category>
      <category domain="http://securityratty.com/tag/tech consultants">tech consultants</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://cyberinsecure.com/after-election-files-stolen-in-obama-and-mccain-campaigns-cyberattack-obama-themed-malware-makes-rounds/">After Election: Files Stolen In Obama And McCain Campaigns Cyberattack, Obama-themed Malware Makes Rounds</source>
    </item>
    <item>
      <title><![CDATA[Report: Obama, McCain campaign computers were hacked by 'foreign entity']]></title>
      <link>http://securityratty.com/article/15ea53df49bbfa1ef6cce078e18e2f05</link>
      <guid>http://securityratty.com/article/15ea53df49bbfa1ef6cce078e18e2f05</guid>
      <description><![CDATA[An unidentified 'foreign entity' stole a large number of policy-related files from computer systems used by the Obama and McCain campaigns, according to a Newsweek...]]></description>
      <content:encoded><![CDATA[An unidentified 'foreign entity' stole a large number of policy-related files from computer systems used by the Obama and McCain campaigns, according to a <i>Newsweek</i> story.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b2fcc3eec0f42596288a94c454aa3a4d:s5mTH2n0lE%2BaYXvxr5m%2BK2ZBz6JM93cYmhvIcpu%2Bc90PyJh0Wl%2BLo72od%2BpNlEdg21jjQmrjDRc6'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e408c5f39421b468a74543c5560d9277:O99edlhvCrcv3TYEEFwLLpe8VPhCOhGp4IPiv3vmNkNdaJwZ7H9%2FXGMg4hAk4gknZi7oT68js4wvbg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:99b28544c77867d558e02956ca6fda7b:D53g2JNb3acI45RhDA60yiLCS64ySsBjRJm84yflyWh1ucwl%2BBjeqJkuqnmISfzmWS5KFc%2BiZOOJ%2Bg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b80655012d5b6c33095a10cd01689015:t2DvfbA6jCCAX9i22nFz2zAMdiEdD1ZJ0dGpMwW5I4WLI6Et1qA3txCPml7iGFF6qdEdXa6cvGVG%2Fw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=dca10ecffbc667fe759f31c01bb9cc9c"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=dca10ecffbc667fe759f31c01bb9cc9c"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=dca10ecffbc667fe759f31c01bb9cc9c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/foreign entity">foreign entity</category>
      <category domain="http://securityratty.com/tag/newsweek story">newsweek story</category>
      <category domain="http://securityratty.com/tag/mccain campaigns">mccain campaigns</category>
      <category domain="http://securityratty.com/tag/obama">obama</category>
      <category domain="http://securityratty.com/tag/computer systems">computer systems</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=dca10ecffbc667fe759f31c01bb9cc9c">Report: Obama, McCain campaign computers were hacked by 'foreign entity'</source>
    </item>
    <item>
      <title><![CDATA[Report: 'Foreign entity' hacked Obama, McCain PCs]]></title>
      <link>http://securityratty.com/article/2bdc576bd869e881e6e98957182a1f68</link>
      <guid>http://securityratty.com/article/2bdc576bd869e881e6e98957182a1f68</guid>
      <description><![CDATA[Computer systems used by the election campaigns of both President-elect Barack Obama and his Republican rival John McCain were broken into earlier this year, and a large number of files related to the...]]></description>
      <content:encoded><![CDATA[Computer systems used by the election campaigns of both President-elect Barack Obama and his Republican rival John McCain were broken into earlier this year, and a large number of files related to the evolving policy positions of the two candidates were stolen, according to a story posted online Wednesday by Newsweek magazine.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=81170?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=81170?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/president-elect barack obama">president-elect barack obama</category>
      <category domain="http://securityratty.com/tag/online wednesday">online wednesday</category>
      <category domain="http://securityratty.com/tag/computer systems">computer systems</category>
      <category domain="http://securityratty.com/tag/policy positions">policy positions</category>
      <category domain="http://securityratty.com/tag/newsweek magazine">newsweek magazine</category>
      <category domain="http://securityratty.com/tag/election campaigns">election campaigns</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <source url="http://www.networkworld.com/news/2008/110508-report-foreign-entity-hacked-obama.html?fsrc=rss-security">Report: 'Foreign entity' hacked Obama, McCain PCs</source>
    </item>
  </channel>
</rss>
