<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: card]]></title>
    <link>http://securityratty.com/tag/card</link>
    <description></description>
    <pubDate>Mon, 14 Jul 2008 09:27:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Money Mule Recruiters use ASProx's Fast Fluxing Services]]></title>
      <link>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</link>
      <guid>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</guid>
      <description><![CDATA[Just consider this scheme for a second. A well known money mule recruitment site Cash Transfers is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/c7TMX064n4w/s1600-h/cash_transfers_money_mule_recruitment.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/CaeHtWn_06M/s200-R/cash_transfers_money_mule_recruitment.png" style="border: 0pt none ;" /></a>Just consider this scheme for a second. A well known <a href="http://www.docep.wa.gov.au/ConsumerProtection/scamnet/Scams/Cash-Transfers_Inc.html">money mule recruitment site Cash Transfers</a> is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting services for several hundred domains used on the last wave of SQL injection attacks. Ironically, <a href="http://www.banksafeonline.org.uk/moneymule_explained.html">the money mule recruitment site</a> is sharing IPs with many of them. Who are these money launderers (<b>cashtransfers.tk</b>; <b>cashtransfers.eu; type53.eu</b>; <b>sid57.tk</b>; <b>catdbw.mobi</b>; <b>cdrpoex.com </b>etc.&nbsp; ) anyway?<br />
<br />
<div style="text-align: left;">"<i>Cash-Transfers Inc. is an online-to-offline international money transfer service. We offer a secure, fast, and inexpensive means of sending money from the UK to offline recipients worldwide. Recipients do not require a bank account or Internet connection to receive funds. We have teamed with select local disbursement partners to provide a convenient, secure, and cost-effective means of sending money to family, friends and business partners abroad. The basic requirements to send money/transfer money are:</i></div><i><br />
1) Senders must have Internet access and a bank account or credit/debit card to transfer money. However, recipients do not require either a bank account or Internet connection.<br />
<br />
2) Money sent through Cash-Transfers Inc. is available for pick up at the distribution partner instantly, or, in most countries, money can be delivered to the recipient in a matter of hours.<br />
<br />
3) Our local agents will call your recipient (during local business hours) to provide additional details, including: forms of identification required, hours of operation, and other locations. The sender will also receive an email confirmation with transaction details and tracking information.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/qtHLcMs6sVs/s1600-h/cash_transfers_asprox_SQL_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/y-aSv2_Sztk/s200-R/cash_transfers_asprox_SQL_injection.JPG" style="border: 0pt none ;" /></a></div>The fast-flux infrastructure they're currently using is also providing services to domains that are currently used, or have been used in previous SQL injection attacks. Some info on the current DNS servers used in the fast-flux :<br />
<br />
<b>ns10.cashtransfers.tk<br />
ns11.cashtransfers.tk<br />
ns1.cashtransfers.tk<br />
ns12.cashtransfers.tk<br />
ns2.cashtransfers.tk<br />
ns13.cashtransfers.tk<br />
ns3.cashtransfers.tk<br />
ns14.cashtransfers.tk<br />
ns4.cashtransfers.tk<br />
ns15.cashtransfers.tk<br />
ns5.cashtransfers.tk<br />
ns16.cashtransfers.tk<br />
ns6.cashtransfers.tk<br />
ns17.cashtransfers.tk<br />
ns7.cashtransfers.tk<br />
ns8.cashtransfers.tk</b><br />
<br />
With the distributed and dynamic hosting infrastructure courtesy of the malware infected user, scammers, spammers, phishers and malware authors are only starting to experiment with the potential abuses of such an underground ecosystem build on the foundations of compromises hosts.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aMnYfJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aMnYfJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wo8AkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wo8AkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=22rmej"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=22rmej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ec2OKj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ec2OKj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LfbMJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LfbMJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LYf9J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LYf9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LO3zj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LO3zj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338919917" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 02:23:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/cashtransfers">cashtransfers</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <category domain="http://securityratty.com/tag/transfer money">transfer money</category>
      <category domain="http://securityratty.com/tag/fast-flux infrastructure">fast-flux infrastructure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338919917/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</source>
    </item>
    <item>
      <title><![CDATA[The Ayyildiz Turkish Hacking Group VS Everyone]]></title>
      <link>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</link>
      <guid>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</guid>
      <description><![CDATA[Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div style="text-align: left;"></div><div class="" style="clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/dn0skav9XIg/s1600-h/AYYILDIZ_TEAM.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/mYlVgqX-mVU/s200-R/AYYILDIZ_TEAM.jpg" style="border: 0pt none ;" /></a>Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure and reputation on the international scene, smart enough to do on one front, there are certain hacktivist groups who ensure their future existence by declaring war and every single country that has ever made statements in contradiction with their vision. Quite a stimulating factor for ensuring the future of your script kiddies group, isn't it?<br />
<br />
One of these groups is the AYYILDIZ TEAM, a group of Turkish script kiddies who've been pretty active as of recently, targeting everyone, everywhere, leaving statements like the following :</div><br />
"<i>Me, as AYT-Admin Barbaros, swear to everything which is lovely and holy to me, that you will pay for your actions. We, AYT, as a Cyber Attacking Army will make it sure. Read right, what will we do:<br />
<br />
* The government websites will be inaccessible an all lawsuits will be manipulated</i><br />
<i>* We will infiltrate the server of inland revenues for the manipulation of the data which are there.</i><br />
<i>* At the same time we will insist into the server of banks and will care for chaos</i><br />
<i>* Websites of the press will be extinguished.</i><br />
<i>* If the offence of our prophet (s.a.v.) called your press freedom, we will show you this press freedom</i><br />
<i>* Websites of divers shops will be hacked. Databank information's and the dates which are there, for example credit card dates, will be policed in this page. (Don't worry, we wouldn't taste one cent of your moneys, we aren't thieves like you. However we don't take care of what happens, if other hackers see this dates and empty your account)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/WwX3npoBZvI/s1600-h/SQL_turkz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/saIYE3fxpdA/s200-R/SQL_turkz.JPG" style="border: 0pt none ;" /></a>While this may sound inspiring, <b>some of the group's members are also involved in SQL injections in between the web site defacements</b>, which are naturally done by exploiting web application vulnerabilities. For instance, right after the defacement messages, they are also injecting the following fast-fluxed domains, part of the latest wave of SQL injections attacks.<b></b><br />
<br />
<b>bkpadd.mobi /ngg.js<br />
usaadw.com /ngg.js<br />
cliprts.com /ngg.js</b><br />
<br />
They are monetizing their defacements by either compiling lists of sites known to be SQL injectable since they've managed to defaced them, then reselling these to the SQL injectors, or are in fact part of the whole process in this scammy ecosystem. Speaking of SQL injections, here's the most recent list of fast-fluxed SQL injected domains participating in the last wave that I've been keeping track of for a while :<br />
<br />
<b>pyttco .com/ngg.js<br />
butdrv .com/ngg.js<br />
gitporg .com/ngg.js<br />
brcporb .ru/ngg.js<br />
korfd .ru/ngg.js<br />
adwnetw .com/ngg.js<br />
wowofmusiopl .com.cn/456.js<br />
adwbn .ru/ngg.js<br />
btoperc .ru/ngg.js<br />
nudk .ru/ngg.js<br />
bkpadd .mobi/ngg.js<br />
cliprts .com/ngg.js<br />
adwr .ru/ngg.js<br />
bnrc .ru/ngg.js<br />
adpzo .com/ngg.js<br />
iogp .ru/ngg.js<br />
lodse .ru/ngg.js<br />
usabnr .com/ngg.js<br />
vcre .ru/ngg.js<br />
sdkj .ru/ngg.js<br />
rcdplc .ru/ngg.js<br />
7maigol .cn/ri.js<br />
j8heisi .cn/ri.js<br />
usaadp .com/ngg.js<br />
gbradp .com/ngg.js<br />
cdrpoex .com/ngg.js<br />
rrcs .ru/ngg.js<br />
gbradw .com/ngg.js<br />
hiwowpp .cn/ri.js<br />
cdport .eu/ngg.js<br />
nopcls .com/ngg.js<br />
loopadd .com/ngg.js<br />
tertad .mobi/ngg.js<br />
gbradde .tk/ngg.js<br />
tctcow .com/ngg.js<br />
ausbnr .com/ngg.js<br />
movaddw .com/ngg.js<br />
grtsel .ru/ngg.js<br />
sslwer .ru/ngg.js<br />
destad .mobi/ngg.js<br />
hdrcom .com/ngg.js<br />
addrl .com/ngg.js<br />
porttw .mobi/ngg.js<br />
bnsdrv .com/ngg.js<br />
drvadw .com/ngg.js<br />
crtbond .com/ngg.js<br />
usaadw .com/ngg.js</b><br />
<br />
What used to be plain simple cooperating among every single participant in the underground marketplace, seems to be evolving into long-term business relationships.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br />
<a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=727PxJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=727PxJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JwIAWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JwIAWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RvHRWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RvHRWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZamBlj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZamBlj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YzU9yJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YzU9yJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2kBf4J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2kBf4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LV5ldj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LV5ldj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338894561" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 01:48:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/comngg">comngg</category>
      <category domain="http://securityratty.com/tag/sql injections attacks">sql injections attacks</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/rungg">rungg</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338894561/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</source>
    </item>
    <item>
      <title><![CDATA[Estee Lauder revamps security in face of regulatory requirements]]></title>
      <link>http://securityratty.com/article/3b9419fe2c5fb9807160f3f70672b29c</link>
      <guid>http://securityratty.com/article/3b9419fe2c5fb9807160f3f70672b29c</guid>
      <description><![CDATA[Cosmetics company Estee Lauder is relying in part on NAC technology to meet regulations imposed on it by the payment card industry and the Sarbanes-Oxley...]]></description>
      <content:encoded><![CDATA[Cosmetics company Estee Lauder is relying in part on NAC technology to meet regulations imposed on it by the payment card industry and the Sarbanes-Oxley law. ]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment card industry">payment card industry</category>
      <category domain="http://securityratty.com/tag/nac technology">nac technology</category>
      <category domain="http://securityratty.com/tag/sarbanes-oxley law">sarbanes-oxley law</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <source url="http://www.networkworld.com/news/2008/071808-estee-lauder.html?fsrc=rss-security">Estee Lauder revamps security in face of regulatory requirements</source>
    </item>
    <item>
      <title><![CDATA[The Perfect Storm]]></title>
      <link>http://securityratty.com/article/32f71212618ca9738aa75adab4f5a3b5</link>
      <guid>http://securityratty.com/article/32f71212618ca9738aa75adab4f5a3b5</guid>
      <description><![CDATA[Its time to get your raincoats and lifeboats - the perfect storm is finished brewing - it is about to rain down upon us

This may sound dramatic but I think that I may not be conveying the amount of...]]></description>
      <content:encoded><![CDATA[Its time to get your raincoats and lifeboats - the perfect storm is finished brewing - it is about to rain down upon us.<br /><br />This may sound dramatic but I think that I may not be conveying the amount of pain that Information Security is about to receive. We will certainly have to step up our game.<br /><br /><span class="blsp-spelling-error" id="SPELLING_ERROR_0">Symantec</span> and Verizon have done some interesting research into the underground hacker community and their findings are rather interesting. A bit scary too.<br /><br />There is an entire community of totally different players that all work together to get from the point where a nerdy kid finds a vulnerability to where a hacker uses that to get into a PC, steal personal information and credit card details, sell them or use them and move on.<br /><br />So far, it seems, that the community has been quite lazy and have just <span class="blsp-spelling-corrected" id="SPELLING_ERROR_1">discarded</span> company information to get to the credit card information and personal information (ID numbers, social security numbers, addresses etc).<br /><br />This has provided us in Information Security with a perfect <span class="blsp-spelling-corrected" id="SPELLING_ERROR_2">opportunity</span>. We have been able to observe how hackers work while they have been taking information that is not our own. Companies that have credit card information have been the ones that were most under attack but those that don't handle credit card information have largely been ignored by hackers except for some members of staff who have been caught out but then they have only lost their own personal information.<br /><br />There just really isn't a (black/underground) market for information that is not credit card or personal finance related.<br /><br />However, it was always my feeling that the credit card/personal finance market would become saturated at some stage and the <span class="blsp-spelling-corrected" id="SPELLING_ERROR_3">loosely</span>-bound-but-still-very-organised-and-co-ordinated <span class="blsp-spelling-corrected" id="SPELLING_ERROR_4">underground</span> market would start to look elsewhere.<br /><br />Essentially, the infrastructure is there for wide-scale information theft but the will wasn't there. I have thought this for a while my question was always - when will the will be there? When will Jack-the-hacker decide that credit card theft is no longer worth his time and start to deal in company information ?<br /><br /><a href="http://securosis.com/2008/07/16/the-data-supply/">Adrian Lane from <span class="blsp-spelling-error" id="SPELLING_ERROR_5">Securosis</span> </a>thinks that the falling prices in the underground economy is <span class="blsp-spelling-corrected" id="SPELLING_ERROR_6">humorous</span>. I disagree. I look at it as very scary and the final puzzle-piece.<br /><br />I think that the perfect storm is about to be unleashed.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/337832309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 03:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/company information">company information</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/wide-scale information theft">wide-scale information theft</category>
      <category domain="http://securityratty.com/tag/credit card information">credit card information</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/337832309/perfect-storm.html">The Perfect Storm</source>
    </item>
    <item>
      <title><![CDATA[Compliance recycling: Combining compliance efforts to manage PCI DSS]]></title>
      <link>http://securityratty.com/article/fa33a3bbd14ae72bbd68b9b12f4d186b</link>
      <guid>http://securityratty.com/article/fa33a3bbd14ae72bbd68b9b12f4d186b</guid>
      <description><![CDATA[While the Payment Card Industry Data Security Standard (PCI DSS) looms large over most enterprises' compliance efforts, it doesn't necessarily mean abandoning other compliance efforts. Expert Diana...]]></description>
      <content:encoded><![CDATA[While the Payment Card Industry Data Security Standard (PCI DSS) looms large over most enterprises' compliance efforts, it doesn't necessarily mean abandoning other compliance efforts. Expert Diana Kelley explains not only how to use existing controls to achieve PCI DSS compliance, but also how other compliance frameworks can ease the PCI DSS compliance process.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/337214794" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 08:23:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance efforts">compliance efforts</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/compliance frameworks">compliance frameworks</category>
      <category domain="http://securityratty.com/tag/ease">ease</category>
      <category domain="http://securityratty.com/tag/necessarily">necessarily</category>
      <category domain="http://securityratty.com/tag/looms">looms</category>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/337214794/0,289483,sid14_gci1319451,00.html">Compliance recycling: Combining compliance efforts to manage PCI DSS</source>
    </item>
    <item>
      <title><![CDATA[Are Stolen Credit Card Details Getting Cheaper?]]></title>
      <link>http://securityratty.com/article/a67e13e215d163e122340bffab059502</link>
      <guid>http://securityratty.com/article/a67e13e215d163e122340bffab059502</guid>
      <description><![CDATA[What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through credit card cloning or ATM skimming ) put into the process of obtaining the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/9rHV8A0Ggz4/s1600-h/ccz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/WQG5_Cal0xY/s200-R/ccz.JPG" style="border: 0pt none ;" /></a>What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through <a href="http://ddanchev.blogspot.com/2007/02/credit-card-data-cloning-tactic.html">credit card cloning</a> or <a href="http://www.snopes.com/fraud/atm/atmcamera.asp">ATM skimming</a>) put into the process of obtaining the details, or can we even talk about investments being made where an experienced scammer has just purchased 1GB of raw credit cards data from a novice botnet master who isn't really aware of the actual value of his "botnet output"?<br />
<br />
Depends on which economic theory you believe in, or whether or not you'll take the "bottom-up approach" or the "top-down" one. And since I'm not aware of the existence of "the invisible hand of the underground market" and centralized power to increase the supply or decrease it to boost prices for the stolen credit card details, also indicating the existence of underground cartels putting everyone in a "price taker" position.<br />
<br />
The basics of demand and supply for anything underground will always apply unless of course, The more they want, the cheaper it gets, the less they want, the higher the price on per credit card basis gets, since the investment on behalf of the malicious party that originally stolen them is virtually the same, and he can theoretically break-even in every single case since the credit card details were obtained efficiently. It's up to the seller to follow or entirely ignore economic behavior, and do what they feel like doing with this good which must on the other hand reach its market liquidity as soon as possible, else it becomes obsolete. The current market model can be further explained as a good example of competitive equilibrium :<br />
<br />
"<i>Competitive market equilibrium is the traditional concept of economic equilibrium, appropriate for the analysis of commodity markets with flexible prices and many traders, and serving as the benchmark of efficiency in economic analysis. <b>It relies crucially on the assumption of a competitive environment where each trader decides upon a quantity that is so small compared to the total quantity traded in the market that their individual transactions have no influence on the prices.</b></i>"<br />
<br />
This can be easily explained in a single sentence - it's a mess and every participant is doing whatever they want to, so generalizing on the prices charged for stolen credit card numbers would be unrealistic, since it's the price a single seller with no real impact on the "average" market price for the same good. As for the average market price itself, it would be hard to measure it depending on the quality of the sample you want to rely on, since this is a type of market where sellers don't have to report price changes in their goods for the purpose of statistical research.<br />
<br />
<a href="http://www.finjan.com/Content.aspx?id=827#SecurityTrendsReport">A recently released report by Finjan</a>, with whom I've been on the same page of several high profile incidents so far, <a href="http://news.yahoo.com/s/nm/20080715/wr_nm/cybercrime_finjan_dc">touches this very same topic</a> :<br />
<br />
"<i>Prices charged by cybercriminals selling hacked bank and credit card details have fallen sharply as the volume of data on offer has soared, forcing them to look elsewhere to boost profit margins, a new report says. Researchers for Finjan, a Web security firm, said the high volumes traded had led to bank and credit card information becoming "commoditized" - account details with PIN codes that once fetched $100 or more each might now go for $10 or $20. In its latest quarterly survey of Web trends, the California-based company said cybercrime had evolved into "a major shadow economy ruled by business rules and logic that closely mimics the legitimate business world.</i>"<br />
<br />
Excluding the presence of <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">price discrimination</a> for a while, as well as open topic offers in the lines of "how much for X amount of Y?" answered as "how much are you willing to pay?", it's all a matter of the seller in a particular situation.<br />
<br />
Furthermore, in real-life market there's always the scarcity problem, however, in the underground market there's no shortage of resources despite the ever growing wants of the buyers. Generalizing even more, take for instance the butterfly effect of a price change in petrol, and result of which is inevitable increase of prices in every single aspect of your life, but in the underground market mostly due to the malicious economies of scale achieved, a price increase in renting a botnet would have no effect in the prices charged for the stolen credit card details obtained through the infected hosts. How come? Basically, the price and resources for malware infection are prone to decrease, if we take a malware infected host as a static foundation for the basis of any upcoming cybercrime activities using it.<br />
<br />
Perhaps the most disturbing part is that the market for stolen credit card details is so mature, and its entry barriers so low these days, that the confidential data that cannot be efficiently obtained through real-life means like credit card cloning or ATM skimming on a large scale, is now purchased online for the purpose of abusing it in real-life by<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html"> embedding the valid information into plastic cards</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=c5gmVJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=c5gmVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yABcqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yABcqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iuXpaj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iuXpaj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ctkd2j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ctkd2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KJLEOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KJLEOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6teEcJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6teEcJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XpeGzj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XpeGzj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/336435935" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 11:36:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/price">price</category>
      <category domain="http://securityratty.com/tag/average market price">average market price</category>
      <category domain="http://securityratty.com/tag/market price">market price</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/competitive market equilibrium">competitive market equilibrium</category>
      <category domain="http://securityratty.com/tag/credit card basis">credit card basis</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/336435935/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</source>
    </item>
    <item>
      <title><![CDATA[Using a File Erasure Tool Considered Suspicious]]></title>
      <link>http://securityratty.com/article/482d790dc2ad9e113ad227524837a2bf</link>
      <guid>http://securityratty.com/article/482d790dc2ad9e113ad227524837a2bf</guid>
      <description><![CDATA[By a California court : The designer, Carter Bryant, has been accused by Mattel of using Evidence Eliminator on his laptop computer just two days before investigators were due to copy its hard drive....]]></description>
      <content:encoded><![CDATA[By a <a href="http://www.latimes.com/technology/la-fi-consumer6-2008jul06,0,325447.story">California court</a>:

<blockquote>The designer, Carter Bryant, has been accused by Mattel of using Evidence Eliminator on his laptop computer just two days before investigators were due to copy its hard drive.

Carter hasn't denied that the program was run on his computer, but he said it wasn't to destroy evidence. He said he had legitimate reasons to use the software.

[...]

But the wiper programs don't ensure a clean getaway. They leave behind a kind of digital calling card.

"Not only do these programs leave a trace that they were used, they each have a distinctive fingerprint," Kessler said. "Evidence Eliminator leaves one that's different from Window Washer, and so on."

It's the kind of information that can be brought up in court. And if the digital calling card was left by Evidence Eliminator, it could raise some eyebrows, even if the wiper was used for the most innocent of reasons.</blockquote>

I have often recommended that people use file erasure tools regularly, especially when crossing international borders with their computers.  Now we have one more reason to use them regularly: plausible deniability if you're accused of erasing data to keep it from the police.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=OGpJ9J"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=OGpJ9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Pg8WgJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Pg8WgJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 09:36:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/evidence eliminator leaves">evidence eliminator leaves</category>
      <category domain="http://securityratty.com/tag/evidence eliminator">evidence eliminator</category>
      <category domain="http://securityratty.com/tag/wiper programs">wiper programs</category>
      <category domain="http://securityratty.com/tag/programs">programs</category>
      <category domain="http://securityratty.com/tag/wiper">wiper</category>
      <category domain="http://securityratty.com/tag/laptop computer">laptop computer</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/california court">california court</category>
      <category domain="http://securityratty.com/tag/carter">carter</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/using_a_file_er.html">Using a File Erasure Tool Considered Suspicious</source>
    </item>
    <item>
      <title><![CDATA[SIM card registration to aid crime fighting in Botswana]]></title>
      <link>http://securityratty.com/article/727cf90cdc5b313a91b70a74727a8235</link>
      <guid>http://securityratty.com/article/727cf90cdc5b313a91b70a74727a8235</guid>
      <description><![CDATA[In order to more easily track those who use their mobile phones to commit crimes, the Botswana Telecommunication Authority (BTA) is requiring the registration of all prepaid mobile phone SIM...]]></description>
      <content:encoded><![CDATA[In order to more easily track those who use their mobile phones to commit crimes, the Botswana Telecommunication Authority (BTA) is requiring the registration of all prepaid mobile phone SIM (Subscriber Identity Module) cards beginning in September.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/remote;sz=468x60;ord=91935?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/remote;sz=468x60;ord=91935?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/subscriber identity module">subscriber identity module</category>
      <category domain="http://securityratty.com/tag/mobile phones">mobile phones</category>
      <category domain="http://securityratty.com/tag/easily track">easily track</category>
      <category domain="http://securityratty.com/tag/commit crimes">commit crimes</category>
      <category domain="http://securityratty.com/tag/registration">registration</category>
      <category domain="http://securityratty.com/tag/botswana">botswana</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/authority">authority</category>
      <category domain="http://securityratty.com/tag/september">september</category>
      <source url="http://www.networkworld.com/news/2008/071508-sim-card-registration-to-aid.html?fsrc=rss-security">SIM card registration to aid crime fighting in Botswana</source>
    </item>
    <item>
      <title><![CDATA[Transport For London System Failure Disabled Electronic Oyster Cards For Thousands Of Travelers]]></title>
      <link>http://securityratty.com/article/52a31d40beb9a87f38cd310ba24b9d1b</link>
      <guid>http://securityratty.com/article/52a31d40beb9a87f38cd310ba24b9d1b</guid>
      <description><![CDATA[Thousands of people using Londons public transport network may find their electronic Oyster card no longer works after a fault hit the system. The system was inoperable for at least five hours on...]]></description>
      <content:encoded><![CDATA[Thousands of people using London&#8217;s public transport network may find their electronic Oyster card no longer works after a fault hit the system. The system was inoperable for at least five hours on Saturday. Some cards used during that time have since stopped working or incurred a fine. London commuters are suffered more problems than [...]]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 13:11:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/electronic oyster card">electronic oyster card</category>
      <category domain="http://securityratty.com/tag/fault hit">fault hit</category>
      <category domain="http://securityratty.com/tag/thousands">thousands</category>
      <category domain="http://securityratty.com/tag/london commuters">london commuters</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/hours">hours</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/inoperable">inoperable</category>
      <source url="http://cyberinsecure.com/transport-for-london-system-failure-disabled-electronic-oyster-cards-for-thousands-of-travelers/">Transport For London System Failure Disabled Electronic Oyster Cards For Thousands Of Travelers</source>
    </item>
    <item>
      <title><![CDATA[The most insecure banking/sales terminal]]></title>
      <link>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</link>
      <guid>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</guid>
      <description><![CDATA[Can you imagine an ATM running Windows XP Home Edition and being connected to the Internet or a Point of Sale terminal running Tetris ? Unlikely! Why then is allowing a customer to use any computer on...]]></description>
      <content:encoded><![CDATA[<p>Can you imagine an <a href="http://www.youtube.com/watch?v=FAnmuRHYamc">ATM running Windows</a> XP Home Edition and being connected to the Internet or a Point of Sale <a href="http://www.youtube.com/watch?v=wWTzkD9M0sU">terminal running Tetris</a>? &ndash; Unlikely! Why then is allowing a customer to use any computer on the Internet to connect to the banking system, and transfer much more money than you can take out of a cash machine, a good idea? Why did arguably the most conservative organisations in the world &ndash; the banks &ndash; agree to lower their defenses so low that they practically invited the criminals in?</p>

<p>The answer is simple &ndash; the same reasons why even risk-averse investors were chasing after every Internet company in the late 90s  &ndash; the attractiveness of the global scale and reduced costs of e-channels. </p>

<p>Over the years, payments and savings have always been a subject of the most advanced protection:</p>

<ul>
  <li>Banknotes have watermarks and other security features to resist counterfeiting</li>


  <li>Cheques require the account holder's signature</li>


  <li>ATMs require both your card and your PIN, run secure software, and are physically tamper-resistant</li>


  <li>Point of Sale terminals in your favourite supermarket are protected from tampering and use dedicated secure connections to the payment processing network</li>


</ul>


<p>These are all very sensible measures that work (to one degree or another) to protect customers' and banks' money.</p>

<p>Today, however, there is a huge imbalance between the value of electronically accessible funds and their security. This is being very effectively exploited by criminals and the banks are looking for a solution. Personal computers are not tamper proof sales terminals, therefore it is unfeasible to rely on the customer to keep them 100% secure. No one can take away online banking but banks can deploy new security measures, and  solving this problem requires a new innovative approach that can equally address security, ease of use, and cost.</p>

<p>At Cronto, we identified this imbalance years ago. We also correctly predicted that the only <a href="http://blog.cronto.com/index.php?title=transaction_verification_can_protect_aga">solution to address this problem is transaction authentication</a> (where the customer confirms each banking instruction). We then developed an innovative visual transaction signing solution. Based on our unique <a href="http://www.cronto.com/visual_cryptogram.htm">Visual Cryptogram</a>, the Cronto solution supports multiple end user options allowing the bank to choose what is right for their customers whilst maintaining consistency in their backend systems.</p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 09:27:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/address">address</category>
      <category domain="http://securityratty.com/tag/address security">address security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/security features">security features</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/banks agree">banks agree</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/internet company">internet company</category>
      <source url="http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1">The most insecure banking/sales terminal</source>
    </item>
  </channel>
</rss>
