<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: city-wide]]></title>
    <link>http://securityratty.com/tag/city-wide</link>
    <description></description>
    <pubDate>Tue, 07 Oct 2008 01:48:53 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Communications During Terrorist Attacks are Not Bad]]></title>
      <link>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</link>
      <guid>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</guid>
      <description><![CDATA[Twitter was a vital source of information in Mumbai: News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the...]]></description>
      <content:encoded><![CDATA[<p>Twitter was a vital <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5245059.ece">source of information</a> in Mumbai:</p>

<blockquote>News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the carnage. 

<p>The website has a stream of comments on the attacks which is being updated by the second, often by eye-witnesses and people in the city. Although the chatter cannot be verified immediately and often reflects the chaos on the streets, it is becoming the fastest source of information for those seeking unfiltered news from the scene.</blockquote></p>

<p>But we simply have to be smarter than this:</p>

<blockquote>In the past hour, people using Twitter reported that bombings and attacks were continuing, but none of these could be confirmed. Others gave details on different locations in which hostages were being held. 

<p>And this morning, Twitter users said that Indian authorities was asking users to stop updating the site for security reasons.</p>

<p>One person wrote: "Police reckon tweeters giving away strategic info to terrorists via Twitter".</blockquote></p>

<p><a href="http://stephensonstrategies.com/2008/11/26/us-officials-must-monitor-learn-from-use-of-web-20-in-mumbai/">Another link</a>:</p>

<blockquote>I can't stress enough: people can and will use these devices and apps in a terrorist attack, so it is imperative that officials start telling us what kind of information would be relevant from Twitter, Flickr, etc. (and, BTW, what shouldn't be spread: one Twitter user in Mumbai tweeted me that people were sending the exact location of people still in the hotels, and could tip off the terrorists) and that they begin to monitor these networks in disasters, terrorist attacks, etc.</blockquote>

<p>This fear is exactly backwards.  During a terrorist attack -- during any crisis situation, actually -- the one thing people can do is exchange information.  It helps people, calms people, and actually reduces the thing the terrorists are trying to achieve: terror.  Yes, there are specific movie-plot scenarios where certain public pronouncements might help the terrorists, but those are rare.  I would much rather err on the side of more information, more openness, and more communication.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=slTEO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=slTEO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BvXZO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BvXZO" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 09:02:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/calms people">calms people</category>
      <category domain="http://securityratty.com/tag/twitter user">twitter user</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/helps people">helps people</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/exchange information">exchange information</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/communications.html">Communications During Terrorist Attacks are Not Bad</source>
    </item>
    <item>
      <title><![CDATA[FBI Stoking Fear]]></title>
      <link>http://securityratty.com/article/42b3e4fb9c51c77ab790e583dada33f4</link>
      <guid>http://securityratty.com/article/42b3e4fb9c51c77ab790e583dada33f4</guid>
      <description><![CDATA[Another unsubstantiated terrorist plot: An internal memo obtained by The Associated Press says the FBI has received a &quot;plausible but unsubstantiated&quot; report that al-Qaida terrorists in late September...]]></description>
      <content:encoded><![CDATA[<p>Another <a href="http://www.google.com/hostednews/ap/article/ALeqM5j1NEBSpGCN1_9rZCXTwXBcnNXOxAD94MNT4O0">unsubstantiated</a> terrorist plot:</p>

<blockquote>An internal memo obtained by The Associated Press says the FBI has received a "plausible but unsubstantiated" report that al-Qaida terrorists in late September may have discussed attacking the subway system.

<p>[...]</p>

<p>The internal bulletin says al-Qaida terrorists "in late September may have discussed targeting transit systems in and around New York City. These discussions reportedly involved the use of suicide bombers or explosives placed on subway/passenger rail systems," according to the document.</p>

<p>"We have no specific details to confirm that this plot has developed beyond aspirational planning, but we are issuing this warning out of concern that such an attack could possibly be conducted during the forthcoming holiday season," according to the warning dated Tuesday.</p>

<p>[...]</p>

<p>Rep. Peter King, the top Republican on the House Homeland Security Committee, said authorities "have very real specifics as to who it is and where the conversation took place and who conducted it."</p>

<p>"It certainly involves suicide bombing attacks on the mass transit system in and around New York and it's plausible, but there's no evidence yet that it's in the process of being carried out," King said.</p>

<p>Knocke, the DHS spokesman, said the warning was issued "out of an abundance of caution going into this holiday season."</blockquote></p>

<p>Got that:  "plausible but unsubstantiated," "may have discussed attacking the subway system," "specific details to confirm that this plot has developed beyond aspirational planning," "attack could possibly be conducted," "it's plausible, but there's no evidence yet that it's in the process of being carried out."</p>

<p>I have no specific details, but I want to warn everybody today that fiery rain might fall from the sky.  Terrorists may have discussed this sort of tactic, and while there is no evidence yet that it's in the process of being carried out, I want to be extra-cautious this holiday season.  Ho ho ho.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=uxqxN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=uxqxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hww2N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hww2N" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 09:27:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday season">holiday season</category>
      <category domain="http://securityratty.com/tag/specific details">specific details</category>
      <category domain="http://securityratty.com/tag/al-qaida terrorists">al-qaida terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorist plot">terrorist plot</category>
      <category domain="http://securityratty.com/tag/subway system">subway system</category>
      <category domain="http://securityratty.com/tag/plausible">plausible</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <category domain="http://securityratty.com/tag/mass transit system">mass transit system</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/fbi_stoking_fea.html">FBI Stoking Fear</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Fourteen]]></title>
      <link>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</link>
      <guid>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</guid>
      <description><![CDATA[You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s1600-h/microav_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s200/microav_rogue_november.png" /></a>You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is declining? With the upcoming holidays and the usual peak of web traffic, malicious activity on all fronts is prone to increase during December. <b>YEWGATE LTD</b>, <b>Sawert Alliance</b>, and <b>Sagent Group</b>, personal favorites affiliate participants in a revenue sharing program for serving fake security software, try to maintain a decent rhythm in their typosquatting process, always worth taking a peek at. The very latest rogue security software additions include :<br />
<br />
<b>micro-antiv2009 .com</b> (91.208.0.223)<br />
<b>micro-antivir2009 .com</b><br />
<b>micro-antivirus-2009 .com </b><br />
<b>micro-av-2009 .com</b><br />
<br />
<i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s1600-h/spyware_remover_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s200/spyware_remover_rogue_november.png" /></a></div><b>avmyscan .com</b> (91.203.92.186; 78.157.143.184)<br />
<b>go-your-scan .com</b><br />
<b>bestproscan .com</b><br />
<b>avproscan .com</b><br />
<b>goyourscan .com</b><br />
<b>iabestscan .com</b><br />
<b>avmyscan .com</b><br />
<b>best-scan-pro .com</b><br />
<b>avscan-pro .com</b><br />
<b>bestscanner-pro .com</b><br />
<b>avscanpro .com</b><br />
<b>iascannerpro .com</b><br />
<br />
<i>Jaroslav Voltz<br />
Email: <b>mensfult@gmail.com</b><br />
Organization: Private person<br />
Address: Biskupsk 9<br />
City: Praha<br />
State: Praha<br />
ZIP: 11000<br />
Country: CZ<br />
Phone: +420.2224811382</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s1600-h/sagent_group_rogue.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s200/sagent_group_rogue.png" /></a><b>virus-labs2009 .com</b> (66.232.113.62)<br />
<b>virus-trigger .com<br />
virusresponse2009 .com<br />
virusresplab .com<br />
virus-response .com</b><br />
<br />
<i>Roman Spitsikov<br />
Uus-Sadama 12&nbsp; <br />
Tallinn, Tallinn 10120<br />
Estonia<br />
<b>Roman.Spitsikov@gmail.com</b></i><br />
<br />
<b>virusremover2008plus .com</b> (77.245.61.80; 93.190.139.229)<br />
<br />
<i>Sagent Group&nbsp; (<b>sergbelo@gmail.com</b>)<br />
Brignal Solutions<br />
P.O. Box 3469 Geneva Place, Waterfront drive <br />
Road town,&nbsp;&nbsp; BVI<br />
BZ<br />
+1.14193017015</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s1600-h/sagent_group_rogue_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s200/sagent_group_rogue_2.png" /></a><b>antivirus-pro-scan.com</b> (84.243.197.183)<br />
<b>anti-virus-defence.com</b><br />
<b>protection-livescan.com</b><br />
<br />
<i>Aleksey Kononov <b>cndomainz@yahoo.com</b></i><br />
<i>+74954538435 fax: +74954538435</i><br />
<i>ul. Yakimanskay 34-56</i><br />
<i>Moskva Moskovskay oblast 112745</i><br />
<i>ru</i><br />
<br />
<b>rapidantivir .com</b><b> </b>(91.208.0.220)<b><br />
rapidantivirus-2009 .com<br />
securityscanner2009 .com<br />
rapidantivirus2009 .com<br />
rapid-antivir .com<br />
extraantivir .com<br />
rapid-antivirus .com<br />
rapidantivirus .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s1600-h/sqscan_rogue_november.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s200/sqscan_rogue_november.JPG" /></a><i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<b>sgscanner .com</b> (116.50.14.185)<br />
<b>sguardscan .com<br />
scansguard .com<br />
getsg2008 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s1600-h/virus_response_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s200/virus_response_rogue_november.png" /></a><i>Vrenk Tihomil<br />
Email: <b>gray444371@gmail.com</b><br />
Organization: Private person<br />
Address: Kolodvorska 73, Sl3270 Lasko<br />
City: Lasko<br />
State: LaskoLasko<br />
ZIP: Sl1355<br />
Country: SI<br />
Phone: +386.14588324</i><br />
<br />
<b>adwaredeluxe .com</b> (64.40.118.8) (private whois)<br />
<b>antivirusadvanced .com<br />
antivirusadvance .com<br />
spydestroy .com<br />
spywareremoval .ws</b><br />
<br />
Shipping them in batches means exposing them in batches.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security_12.html">A Diverse Portfolio of Fake Security Software - Part Thirteen</a><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9h0BN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9h0BN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x78xN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x78xN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SX1Dn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SX1Dn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=n7eun"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=n7eun" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xmqRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xmqRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4Ga4N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4Ga4N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Lo1n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Lo1n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/467329268" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 04:47:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/sawert alliance">sawert alliance</category>
      <category domain="http://securityratty.com/tag/road town">road town</category>
      <category domain="http://securityratty.com/tag/martti seodancergmail">martti seodancergmail</category>
      <category domain="http://securityratty.com/tag/upper flat">upper flat</category>
      <category domain="http://securityratty.com/tag/city">city</category>
      <category domain="http://securityratty.com/tag/road">road</category>
      <category domain="http://securityratty.com/tag/sl3270 lasko">sl3270 lasko</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/467329268/diverse-portfolio-of-fake-security_27.html">A Diverse Portfolio of Fake Security Software - Part Fourteen</source>
    </item>
    <item>
      <title><![CDATA[British Hospital System Hit by Computer Virus]]></title>
      <link>http://securityratty.com/article/f1d8bd877d349859de699cde8caa6ac4</link>
      <guid>http://securityratty.com/article/f1d8bd877d349859de699cde8caa6ac4</guid>
      <description><![CDATA[Three London hospitals that make up St Bartholomew's (Barts) and The London NHS Trust have been forced to shut down their computer systems for at least 24 hours due to a computer virus attack . The...]]></description>
      <content:encoded><![CDATA[Three London hospitals that make up St Bartholomew's (Barts) and The London NHS Trust <a href="http://news.bbc.co.uk/2/hi/uk_news/england/london/7735502.stm">have been forced to shut down their computer systems for at least 24 hours due to a computer virus attack</a>. The three hospitals are Barts in the City, the Royal London Hospital in Whitechapel and The London Chest Hospital in Bethnal Green.

Neither a BBC report nor <a href="http://www.bartsandthelondon.org.uk/formedia/press/release.asp?id=2054&sid=10">a press release from the hospitals</a> said anything about the nature of the attack or the extent of the damage or if patient services were affected, although one would think this would have to be the case. The terse press release says that "The Trust's well rehearsed emergency procedures have been activated to ensure that key clinical systems continue safely while the system is being stabilised and a solution is being found."

The problem was first detected at 12:00 GMT Monday according to a spokesman.
<p><a href="http://feedads.googleadservices.com/~a/5O7UI8F7mHF--xx0jjKhwICpCgo/a"><img src="http://feedads.googleadservices.com/~a/5O7UI8F7mHF--xx0jjKhwICpCgo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/OssPZ1W7pOw" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:01:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/press release">press release</category>
      <category domain="http://securityratty.com/tag/terse press release">terse press release</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/london hospitals">london hospitals</category>
      <category domain="http://securityratty.com/tag/computer virus attack">computer virus attack</category>
      <category domain="http://securityratty.com/tag/hospitals">hospitals</category>
      <category domain="http://securityratty.com/tag/london nhs trust">london nhs trust</category>
      <category domain="http://securityratty.com/tag/royal london hospital">royal london hospital</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/OssPZ1W7pOw/british_hospital_system_hit_by_computer_virus.html">British Hospital System Hit by Computer Virus</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Twelve]]></title>
      <link>http://securityratty.com/article/d462bee817ac892232f1b929608cd422</link>
      <guid>http://securityratty.com/article/d462bee817ac892232f1b929608cd422</guid>
      <description><![CDATA[These very latest rogue security software domains have been in circulation -- blackhat SEO, SQL injections, traffic redirection scripts -- since Friday and remain active

premium-pc-scan .com...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9py9LcidI/AAAAAAAACaU/fQfM4EAzuKo/s1600-h/rogue_security_software_portfolio_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9py9LcidI/AAAAAAAACaU/dLsxwtYrDik/s200-R/rogue_security_software_portfolio_november.png" /></a>These very latest rogue security software domains have been in circulation -- blackhat SEO, SQL injections, traffic redirection scripts -- since Friday and remain active : <br />
<br />
<b>premium-pc-scan .com</b> (78.159.118.217; 89.149.253.215; 91.203.92.47)<br />
<b>antivirus-pc-scan .com</b> (208.72.169.100)<br />
<b>securityfullscan .com</b> (84.243.197.184)<br />
<b>antivirus-live-scan .com</b> (84.243.196.136; 89.149.227.196)<br />
<b>windefender-2009 .com</b> - (200.63.45.55)<br />
<b>windefender2009 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQ9q3PPub7I/AAAAAAAACac/4qLyQ0P9_iY/s1600-h/rogue_security_software_portfolio_november_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQ9q3PPub7I/AAAAAAAACac/mxOldlIx5B4/s200-R/rogue_security_software_portfolio_november_1.png" /></a>What these domains have in common, excluding the last two WinDefender ones, is the domain registrant, the DNS servers used, and that despite the fact that it has already been featured in several malicious doorways, meaning these are receiving traffic already, they forgot to upload the binaries on all of the active domains : <br />
<br />
"<i>Not Found. The requested URL /2009/download/trial/A9installer_.exe was not found on this server.</i>"<br />
<br />
<i>Registrant:&nbsp;</i><br />
<i>Vladimir Polilov&nbsp;</i><br />
<i>Email: gpdomains@yahoo.com</i><br />
<i>Organization: Private person</i><br />
<i>Address: ul. Bauma 13-76</i><br />
<i>City: Moskva</i><br />
<i>State: Moskovskaya oblast</i><br />
<i>ZIP: 112621</i><br />
<i>Country: RU</i><br />
<i>Phone: +7.9031609536 </i><br />
<br />
DNS servers used - <i>ns1.freefastdns.com; ns2.freefastdns.com</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SQ9uoEsQJ9I/AAAAAAAACak/3NBPR8SZ5q0/s1600-h/rogue_security_software_portfolio_november_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SQ9uoEsQJ9I/AAAAAAAACak/rpBUB4rPmgI/s200-R/rogue_security_software_portfolio_november_2.png" /></a>Moreover, the following domains are also parked at the same IPs, but are currently in stand-by mode, yet they're also using the same DNS servers with the only difference in the registrant who seems to have been running a very extensive portfolio of bogus domains, potentially making hundreds of thousands in the process :<br />
<br />
<b>save-my-pc-now .com<br />
real-antivirus .com<br />
liveantivirustest .com<br />
antiviruspctest .com<br />
premium-live-scan .com<br />
liveantivirustest .com<br />
antiviruspersonaltest .com<br />
mysecuritysupport .com<br />
updateyourprotection .com<br />
antivirus-premiumscan .com<br />
securitylivescan .com<br />
security-full-scan .com<br />
secured-liveupdate .com<br />
livepcupdate .com<br />
protection-update .com<br />
antivirus-scan-online .com<br />
xpsoftupgrade .com<br />
live-virus-defence .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9xN8GkbcI/AAAAAAAACas/ebLo_gyI2Mg/s1600-h/rogue_software_phones_back_home.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9xN8GkbcI/AAAAAAAACas/olFP5HLvCFg/s200-R/rogue_software_phones_back_home.JPG" /></a><i>Registrant:<br />
Shestakov Yuriy <br />
alexey@cocainmail.com/alexeyvas@safe-mail.net <br />
+7.9218839910<br />
Lenina 21 16<br />
Mirniy,MSK,RU 102422</i><br />
<br />
The sampled WinDefender binaries phone back to <b>megauplinkbindinstaller .com/cfg1.php</b> (91.203.92.99) with the entire netblock clearly a bad neighborhood. Here are some sample command and control locations :<br />
<br />
<b>91.203.92.101 /admin/cd.php?userid=19102008_184429_260953 <br />
91.203.92.25 /dmn/domen.txt<br />
91.203.92.135 /alligator/cfg.bin<br />
91.203.92.132 /c.bin</b><br />
<br />
This operation is being monitored, results will be posted as they emerge.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KFegN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KFegN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uDICN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uDICN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g1W6n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g1W6n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=V2Qnn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=V2Qnn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HZkbN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HZkbN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1Md6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1Md6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IxBRn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IxBRn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/441437574" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 13:11:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/windefender binaries phone">windefender binaries phone</category>
      <category domain="http://securityratty.com/tag/active domains">active domains</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/registrant">registrant</category>
      <category domain="http://securityratty.com/tag/domain registrant">domain registrant</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/441437574/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</source>
    </item>
    <item>
      <title><![CDATA[Personal Data Of Thousands Posted On Indygov.gov Website, Undiscovered For More Than A Week]]></title>
      <link>http://securityratty.com/article/abbe5501b0721f3546ba03d0f6d62fb8</link>
      <guid>http://securityratty.com/article/abbe5501b0721f3546ba03d0f6d62fb8</guid>
      <description><![CDATA[Personal information of about 3,300 people charged with minor drug and alcohol offenses was accidentally posted on the city of Indianapolis new Web site for 11 days in late September and early this...]]></description>
      <content:encoded><![CDATA[Personal information of about 3,300 people charged with minor drug and alcohol offenses was accidentally posted on the city of Indianapolis&#8217; new Web site for 11 days in late September and early this month, according to official release in Wednesday.
The file contained names, dates of birth and Social Security numbers of 3,300 people charged with [...]]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 18:32:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/minor drug">minor drug</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/official release">official release</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/alcohol offenses">alcohol offenses</category>
      <category domain="http://securityratty.com/tag/birth">birth</category>
      <category domain="http://securityratty.com/tag/indianapolis">indianapolis</category>
      <source url="http://cyberinsecure.com/personal-data-of-thousands-posted-on-indygovgov-website-undiscovered-for-more-than-a-week/">Personal Data Of Thousands Posted On Indygov.gov Website, Undiscovered For More Than A Week</source>
    </item>
    <item>
      <title><![CDATA[Does Risk Management Make Sense?]]></title>
      <link>http://securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</link>
      <guid>http://securityratty.com/article/1c474a0ca5e46c2d82ff6187ee46f0eb</guid>
      <description><![CDATA[We engage in risk management all the time, but it only makes sense if we do it right
Risk management&quot; is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's...]]></description>
      <content:encoded><![CDATA[<p>We engage in risk management all the time, but it only makes sense if we do it right. </p>

<p>"Risk management" is just a fancy term for the cost-benefit tradeoff associated with any security decision. It's what we do when we react to fear, or try to make ourselves feel secure. It's the fight-or-flight reflex that evolved in primitive fish and remains in all vertebrates. It's instinctual, intuitive and fundamental to life, and one of the brain's primary functions. </p>

<p>Some have hypothesized that humans have a "risk thermostat" that tries to maintain some optimal risk level. It explains why we drive our motorcycles faster when we wear a helmet, or are more likely to take up smoking during wartime. It's our natural risk management in action. </p>

<p>The problem is our brains are intuitively suited to the sorts of risk management decisions endemic to living in small family groups in the East African highlands in 100,000 BC, and not to living in the New York City of 2008. We make </p>

<p>systematic risk management mistakes -- miscalculating the probability of rare events, reacting more to stories than data, responding to the feeling of security rather than reality, and making decisions based on irrelevant context. And that risk cockpit of ours? It's not nearly as finely tuned as we might like it to be. </p>

<p>Like a rabbit that responds to an oncoming car with its default predator avoidance behavior -- dart left, dart right, dart left, and at the last moment jump -- instead of just getting out of the way, our Stone Age intuition doesn't serve us well in a modern technological society. So when we in the security industry use the term "risk management," we don't want you to do it by trusting your gut. We want you to do risk management consciously and intelligently, to analyze the tradeoff and make the best decision. </p>

<p>This means balancing the costs and benefits of any security decision -- buying and installing a new technology, implementing a new procedure or forgoing a common precaution. It means allocating a security budget to mitigate different risks by different amounts. It means buying insurance to transfer some risks to others. It's what businesses do, all the time, about everything. IT security has its own risk management decisions, based on the threats and the technologies. </p>

<p>There's never just one risk, of course, and bad risk management decisions often carry an underlying tradeoff. Terrorism policy in the U.S. is based more on politics than actual security risk, but the politicians who make these decisions are concerned about the risks of not being re-elected. </p>

<p>Many corporate security decisions are made to mitigate the risk of lawsuits rather than address the risk of any actual security breach. And individuals make risk management decisions that consider not only the risks to the corporation, but the risks to their departments' budgets, and to their careers. </p>

<p>You can't completely remove emotion from risk management decisions, but the best way to keep risk management focused on the data is to formalize the methodology. That's what companies that manage risk for a living -- insurance companies, financial trading firms and arbitrageurs -- try to do. They try to replace intuition with models, and hunches with mathematics. </p>

<p>The problem in the security world is we often lack the data to do risk management well. Technological risks are complicated and subtle. We don't know how well our network security will keep the bad guys out, and we don't know the cost to the company if we don't keep them out. And the risks change all the time, making the calculations even harder. But this doesn't mean we shouldn't try. </p>

<p>You can't avoid risk management; it's fundamental to business just as to life. The question is whether you're going to try to use data or whether you're going to just react based on emotions, hunches and anecdotes. </p>

<p>This essay appeared as the first half of a <a href="http://searchsecurity.techtarget.com/loginMembersOnly/1,289498,sid14_gci1332745,00.html?">point-counterpoint</a> with Marcus Ranum in <i>Information Security</i> magazine.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=etFHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=etFHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=KYvhM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=KYvhM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 09:25:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management decisions">risk management decisions</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/avoid risk management">avoid risk management</category>
      <category domain="http://securityratty.com/tag/natural risk management">natural risk management</category>
      <category domain="http://securityratty.com/tag/risk management consciously">risk management consciously</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security world">security world</category>
      <category domain="http://securityratty.com/tag/information security magazine">information security magazine</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/does_risk_manag.html">Does Risk Management Make Sense?</source>
    </item>
    <item>
      <title><![CDATA[Clever Counterterrorism Tactic]]></title>
      <link>http://securityratty.com/article/9b0993eb71be732aed5e6c621525d339</link>
      <guid>http://securityratty.com/article/9b0993eb71be732aed5e6c621525d339</guid>
      <description><![CDATA[Used against the IRA : One of the most interesting operations was the laundry mat [sic]. Having lost many troops and civilians to bombings, the Brits decided they needed to determine who was making...]]></description>
      <content:encoded><![CDATA[<p>Used <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/10/03/AR2008100301978.html?hpid=opinionsbox1">against the IRA</a>:</p>

<blockquote>One of the most interesting operations was the laundry mat [sic]. Having lost many troops and civilians to bombings, the Brits decided they needed to determine who was making the bombs and where they were being manufactured. One bright fellow recommended they operate a laundry and when asked "what the hell he was talking about," he explained the plan and it was incorporated -- to much success.

<p>The plan was simple: Build a laundry and staff it with locals and a few of their own. The laundry would then send out "color coded" special discount tickets, to the effect of "get two loads for the price of one," etc. The color coding was matched to specific streets and thus when someone brought in their laundry, it was easy to determine the general location from which a city map was coded.</p>

<p>While the laundry was indeed being washed, pressed and dry cleaned, it had one additional cycle -- every garment, sheet, glove, pair of pants, was first sent through an analyzer, located in the basement, that checked for bomb-making residue. The analyzer was disguised as just another piece of the laundry equipment; good OPSEC [operational security]. Within a few weeks, multiple positives had shown up, indicating the ingredients of bomb residue, and intelligence had determined which areas of the city were involved. To narrow their target list, [the laundry] simply sent out more specific coupons [numbered] to all houses in the area, and before long they had good addresses. After confirming addresses, authorities with the SAS teams swooped down on the multiple homes and arrested multiple personnel and confiscated numerous assembled bombs, weapons and ingredients. During the entire operation, no one was injured or killed.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=1VsTM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=1VsTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=omBpM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=omBpM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 09:22:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laundry">laundry</category>
      <category domain="http://securityratty.com/tag/laundry simply">laundry simply</category>
      <category domain="http://securityratty.com/tag/laundry equipment">laundry equipment</category>
      <category domain="http://securityratty.com/tag/laundry mat sic">laundry mat sic</category>
      <category domain="http://securityratty.com/tag/color coded">color coded</category>
      <category domain="http://securityratty.com/tag/coded">coded</category>
      <category domain="http://securityratty.com/tag/bomb residue">bomb residue</category>
      <category domain="http://securityratty.com/tag/opsec operational security">opsec operational security</category>
      <category domain="http://securityratty.com/tag/city">city</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/clever_countert.html">Clever Counterterrorism Tactic</source>
    </item>
    <item>
      <title><![CDATA[The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</link>
      <guid>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place. </p>

<p>Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf. </p>

<p>If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections. </p>

<p>Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> published this year in International Security that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers: </p>

<p>Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved. </p>

<p>Abrahms has an alternative model to explain all this: People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States. </p>

<p>The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida. </p>

<p>For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist. </p>

<p>All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion. </p>

<p>This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups. </p>

<p>We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.</p>

<p>This essay <a href="http://www.wired.com/print/politics/security/commentary/securitymatters/2008/10/securitymatters_1002">previously appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QW5fM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QW5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YCnjM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YCnjM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 01:48:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_seven_habit.html">The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
  </channel>
</rss>
