<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: click]]></title>
    <link>http://securityratty.com/tag/click</link>
    <description></description>
    <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[SmartPhones Just One More Spam Vector]]></title>
      <link>http://securityratty.com/article/3334dd3ee138602a47ef51983940dd0c</link>
      <guid>http://securityratty.com/article/3334dd3ee138602a47ef51983940dd0c</guid>
      <description><![CDATA[The Apple iPhone has another vulnerability, one that shouldnt surprise you if youve been paying attention
The news of the latest problems surfaced after Apple allegedly ignored researchers reports to...]]></description>
      <content:encoded><![CDATA[<p>The Apple iPhone has another vulnerability, one that shouldn&#8217;t surprise you if you&#8217;ve been paying attention.</p>
<p>The <a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/personal_tech/iphone/showArticle.jhtml?articleID=210605451">news </a>of the latest problems surfaced after Apple allegedly ignored researchers&#8217; reports to them and the researchers decided to go public with the news :</p>
<p>In Mail, users can hover over an embedded hyperlink to see the URL, but these URLS get cut off due to the small screen. Users might see a trusted domain, but when they click it, find that the link actually resolves to an untrusted site.</p>
<p>The second vulnerability is that Mail automatically downloads images, leaving users open to malware.</p>
<p>It&#8217;s &#8220;a pretty dumb design flaw&#8221; says the <a rel="nofollow" target="_blank" href="http://aviv.raffon.net/2008/10/02/HappyNewYear.aspx">researcher </a>who discovered the problem.</p>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 07:03:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/researchers reports">researchers reports</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <category domain="http://securityratty.com/tag/downloads images">downloads images</category>
      <category domain="http://securityratty.com/tag/apple iphone">apple iphone</category>
      <category domain="http://securityratty.com/tag/apple allegedly">apple allegedly</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/416004668/">SmartPhones Just One More Spam Vector</source>
    </item>
    <item>
      <title><![CDATA[Cybercriminals Abusing Lycos Spain To Serve Malware]]></title>
      <link>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</link>
      <guid>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</guid>
      <description><![CDATA[Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/Few0-Tx3rNw/s1600-h/lycos_spain_fake_video_generator2.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/iAII9VuZa4c/s200-R/lycos_spain_fake_video_generator2.PNG" /></a>Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link generator redirecting to fake YouTube and Adobe Flash video pages. Whereas the concept of abusing legitimate web services for infection and propagation isn't new, what's new is the fact that <a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">the FTP access is efficiently abused</a>.&nbsp; <br />
<br />
Here's a description of the link generator : <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/nmOCnp413_4/s1600-h/lycos_spain_fake_video_generator1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/eipfSy4XHQA/s200-R/lycos_spain_fake_video_generator1.png" /></a>"<i>Download the program and run it asks for an ID (identifier), then copy it and paste it there, then press' Create Installer 'and the program will create the Installer! (this program to run a simulation that is installing the Adobe Flash and indicates to our page that "has been installed Adobe Flash," in order to show the video when YouVideo refresh the page, this you must file tie it in with your server! and what flames or Installer Setup (simulating being an installer)!&nbsp; Now you need to upload that file you've joined an FTP, click Next and put the path of that file in the next step!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/MxLdkIGeP-k/s1600-h/lycos_spain_fake_video_generator6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/Ajrlsv2pXY8/s200-R/lycos_spain_fake_video_generator6.png" /></a>Whereas the tool is exclusively relying on Lycos Spain to host the binaries and the campaign itself, the recent <a href="http://ddanchev.blogspot.com/2008/10/syndicating-google-trends-keywords-for.html">blackhat SEO campaign relying on pre-registered Windows Live Spaces and AOL Journals</a> syndicating hot Google Trends keywords, further indicates the malicious attacker's capabilities of efficiently abusing legitimate services. And with the process of <a href="http://ddanchev.blogspot.com/2008/08/exposing-indias-captcha-solving-economy.html">bogus accounts registration</a> performed automatically, or <a href="http://blogs.zdnet.com/security/?p=1835">outsourced entirely</a>, malicious services aiming to automate the abuse process are only going to get more efficient.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=k5GGM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=k5GGM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Z15BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Z15BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G192m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G192m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Moy2m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Moy2m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Dp6KM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Dp6KM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ysa5M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ysa5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S6Dhm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S6Dhm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/415620254" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 00:28:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lycos spain">lycos spain</category>
      <category domain="http://securityratty.com/tag/installer setup">installer setup</category>
      <category domain="http://securityratty.com/tag/installer">installer</category>
      <category domain="http://securityratty.com/tag/bogus accounts">bogus accounts</category>
      <category domain="http://securityratty.com/tag/bogus accounts registration">bogus accounts registration</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/malicious services">malicious services</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/adobe flash">adobe flash</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/415620254/cybercriminals-abusing-lycos-spain-to.html">Cybercriminals Abusing Lycos Spain To Serve Malware</source>
    </item>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[Clickjacking]]></title>
      <link>http://securityratty.com/article/d0ea1f000cff44a5f2bfc35ef78afadf</link>
      <guid>http://securityratty.com/article/d0ea1f000cff44a5f2bfc35ef78afadf</guid>
      <description><![CDATA[Good Q&amp;A on clickjacking: In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker...]]></description>
      <content:encoded><![CDATA[<p>Good <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9115818&source=NLT_SEC&nlid=38">Q&A</a> on clickjacking:</p>

<blockquote>In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker takes a car? Well, clickjacking is like that, except that the click is the car.</blockquote>

<p>"Clickjacking" is a stunningly sexy name, but the vulnerability is really just a variant of cross-site scripting.  We don't know how bad it really is, because the details are still being withheld.  But the name alone is causing dread.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=iifBM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=iifBM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=q9UeM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=q9UeM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 09:45:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stunningly sexy">stunningly sexy</category>
      <category domain="http://securityratty.com/tag/plain english">plain english</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/carjacker takes">carjacker takes</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/dread">dread</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/clickjacking.html">Clickjacking</source>
    </item>
    <item>
      <title><![CDATA[Change your passwords with your smoke detector batteries]]></title>
      <link>http://securityratty.com/article/0ee3167fcbeb9c9f820491dd8edae8bd</link>
      <guid>http://securityratty.com/article/0ee3167fcbeb9c9f820491dd8edae8bd</guid>
      <description><![CDATA[If youve changed your smoke detector batteries more recently than youve changed your passwords, then you should think about changing some of them now. If you can change passwords more often, great....]]></description>
      <content:encoded><![CDATA[If you&#8217;ve changed your smoke detector batteries more recently than you&#8217;ve changed your passwords, then you should think about changing some of them now.
If you can change passwords more often, great. But I realize that some of us have upwards of 25 passwords to manage on a regular basis (click HERE). It&#8217;s not fun having [...]]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 08:26:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/smoke detector batteries">smoke detector batteries</category>
      <category domain="http://securityratty.com/tag/change passwords">change passwords</category>
      <category domain="http://securityratty.com/tag/regular basis">regular basis</category>
      <category domain="http://securityratty.com/tag/recently">recently</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/upwards">upwards</category>
      <category domain="http://securityratty.com/tag/manage">manage</category>
      <source url="http://securityviews.com/blog/2008/10/05/change-your-passwords-with-your-smoke-detector-batteries/">Change your passwords with your smoke detector batteries</source>
    </item>
    <item>
      <title><![CDATA[When Psychology Meets Network Administration]]></title>
      <link>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</link>
      <guid>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</guid>
      <description><![CDATA[The library comic Unshelved has a fun strip todaywhere the new library intern announces she will reconfigure the network to correct the librarians snarky attitude. But can computer administrators...]]></description>
      <content:encoded><![CDATA[<p>The library comic Unshelved has a fun strip today&#8230;where the new library intern announces she will reconfigure the network to correct the librarian&#8217;s snarky attitude. But can computer administrators really control their users&#8217; behavior? Our fearless young librarian Dewey doesn&#8217;t seem too worried.</p>
<p><a rel="nofollow" target="_blank" href="http://www.unshelved.com/"><img class="alignnone" src="http://www.unshelved.com/strips/20080930.gif" alt="" width="600" height="210"/></a>Luckily we do have some technologies to warn users who still haven&#8217;t learned to stop opening spammy attachments, click pop up ads and so on&#8230;but I don&#8217;t think they&#8217;d help with the snarky attitude problems. I&#8217;m not sure I&#8217;d want my computer network to try doing that anyway.</p>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 11:17:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/snarky attitude">snarky attitude</category>
      <category domain="http://securityratty.com/tag/librarians snarky attitude">librarians snarky attitude</category>
      <category domain="http://securityratty.com/tag/library intern announces">library intern announces</category>
      <category domain="http://securityratty.com/tag/computer network">computer network</category>
      <category domain="http://securityratty.com/tag/fun strip todaywhere">fun strip todaywhere</category>
      <category domain="http://securityratty.com/tag/click pop">click pop</category>
      <category domain="http://securityratty.com/tag/librarian dewey">librarian dewey</category>
      <category domain="http://securityratty.com/tag/spammy attachments">spammy attachments</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/407690914/">When Psychology Meets Network Administration</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #123]]></title>
      <link>http://securityratty.com/article/7c6bde3b610c9fe31746a6ef7b3051f1</link>
      <guid>http://securityratty.com/article/7c6bde3b610c9fe31746a6ef7b3051f1</guid>
      <description><![CDATA[Click to Download/Listen (07:03

Recent updates to the Fair and Accurate Credit Transactions Act (FACTA) of 2003 mandate that U.S. financial institutions and creditors must comply with the Identity...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1354">Click to Download/Listen</a> (07:03)<br><br />Recent updates to the Fair and Accurate Credit Transactions Act (FACTA) of 2003   mandate that U.S. financial institutions and creditors must <strong>comply with   the Identity Theft Red Flag provisions by November 1, 2008</strong>. Amanda Van Veen speaks with EMC's resident <a href="http://rsa.com/node.aspx?id=3479" target="_blank">FACTA</a> expert, Dennis Mayer from <a href="http://www.emc.com/services/consulting/business/offerings/compliance-management-financial-services.htm" target="_blank">EMC Consulting</a> about the upcoming deadline and what it means to those who must comply.<br /><br /><br />]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facta">facta</category>
      <category domain="http://securityratty.com/tag/resident facta expert">resident facta expert</category>
      <category domain="http://securityratty.com/tag/credit transactions act">credit transactions act</category>
      <category domain="http://securityratty.com/tag/dennis mayer">dennis mayer</category>
      <category domain="http://securityratty.com/tag/emc">emc</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <category domain="http://securityratty.com/tag/amanda van">amanda van</category>
      <category domain="http://securityratty.com/tag/financial institutions">financial institutions</category>
      <category domain="http://securityratty.com/tag/creditors">creditors</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1354">Speaking of Security Podcast #123</source>
    </item>
    <item>
      <title><![CDATA[Gambling Domains Seized by Kentucky]]></title>
      <link>http://securityratty.com/article/b2a12ce3b79bb2383d563ad1918217f7</link>
      <guid>http://securityratty.com/article/b2a12ce3b79bb2383d563ad1918217f7</guid>
      <description><![CDATA[From reports, it appears that Kentucky Governor Steve Beshear has attempted to seize 141 gambling-related domain names under a state law that allows for seizure of items used for illegal gambling. It...]]></description>
      <content:encoded><![CDATA[From reports, it appears that Kentucky Governor Steve Beshear has attempted to seize 141 gambling-related domain names under a state law that allows for seizure of items used for illegal gambling. It appears that the seizure order (<a href="http://www.thedomains.com/wp-content/order-of-seizure-of-domain-names.pdf">click here for a copy of the initial order</a>) was signed by a circuit judge, but <a href="http://www.thedomains.com/2008/09/26/kentucky-hearing-update/">later reports indicate that the judge is holding further hearings and seeking further arguments</a>. A hearing will be held Oct. 7, <a href="http://www.thedomains.com/2008/09/26/kentucky-hearing-update/">according to TheDomains</a>.

See page 4 of the seizure order for a complete list of the 141 domains. Here are some of them:
<ul><li>123bingo.com</li>
	<li>777dragon.com</li>
	<li>indiancasino.com</li>
	<li>jackpotcity.com</li>
	<li>powerbet.com</li>
	<li>crazypoker.com</li>
	<li>vegaslucky.com</li></ul>

That sort of thing.

According to DomainNameNews, <a href="http://www.domainnamenews.com/up-to-the-minute/kentucks-seizes-141-gambling-domain-names/2413">several of the domains are for popular sites</a>, including PokerStars.com, FullTiltPoker.com, BodogLife.com, GoldenPalace.com, Bet21.com, DoylesRoom.com and IndianCasino.com. It also reports that <a href="http://www.domainnamenews.com/up-to-the-minute/ica-responds-to-kentucky-seizure-of-gambling-domains/2584">at least one registrar (Enom) has transferred domains pursuant to the order</a>, including one whose registrant died of a heart attack this summer.

The seizure order says that the domains are to be transferred by any registrar to a plaintiff's account at that registrar (the plaintiff being the Commonwealth of Kentucky), but that the domain names' configuration will be otherwise unchanged. This means that any gambling sites run on those domains or, for that matter, anything else on those domains, such as PPC ads, would remain functional.

All things considered, this seems like simple-minded grandstanding without any good law behind it. The Constitution vests Congress with power to regulate interstate commerce, which the domain name market clearly is. In fact, these businesses are truly international. And it's a safe bet that none of the gambling companies or registrars operates in Kentucky, perhaps not even any of the domain name holders. That the state argues that residents of Kentucky engage in illegal gambling doesn't give the state jurisdiction. The Internet Commerce Association, a domainer lobby, <a href="http://www.domainnamenews.com/up-to-the-minute/ica-responds-to-kentucky-seizure-of-gambling-domains/2584">has weighed in on the matter in opposition to the state's move</a>.
<p><a href="http://feedads.googleadservices.com/~a/FslEfsv6x1qu8Vcy3lti-mPyruM/a"><img src="http://feedads.googleadservices.com/~a/FslEfsv6x1qu8Vcy3lti-mPyruM/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/x8jm5xd8NoU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 03:32:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/kentucky">kentucky</category>
      <category domain="http://securityratty.com/tag/domains pursuant">domains pursuant</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/domain names">domain names</category>
      <category domain="http://securityratty.com/tag/kentucky engage">kentucky engage</category>
      <category domain="http://securityratty.com/tag/internet commerce association">internet commerce association</category>
      <category domain="http://securityratty.com/tag/seizure">seizure</category>
      <category domain="http://securityratty.com/tag/commerce">commerce</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/x8jm5xd8NoU/gambling_domains_seized_by_kentucky.html">Gambling Domains Seized by Kentucky</source>
    </item>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
  </channel>
</rss>
