<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cnn]]></title>
    <link>http://securityratty.com/tag/cnn</link>
    <description></description>
    <pubDate>Tue, 05 Aug 2008 14:50:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[CNN, MSNBC Spammers Downgrading Their EMails]]></title>
      <link>http://securityratty.com/article/b412b7768a969bd9f0f16c8b816bcbeb</link>
      <guid>http://securityratty.com/article/b412b7768a969bd9f0f16c8b816bcbeb</guid>
      <description><![CDATA[This is pretty interesting. After a week or two of seeing CNN spam , then MSNBC spam (both of which allude to &quot;breaking news stories&quot; in order to get peoples attention), it seems the people behind...]]></description>
      <content:encoded><![CDATA[
        This is pretty interesting. After a week or two of seeing <a href="http://blog.spywareguide.com/2008/08/cnn-custom-alerts.html">CNN spam</a>, then <a href="http://blog.spywareguide.com/2008/08/a-change-of-plan-for-your-spam.html">MSNBC spam</a> (both of which allude to "breaking news stories" in order to get peoples attention), it seems the people behind those attacks are now sending out plain emails (with none of the allusions to being from major news networks) that simply say "BREAKING news" in the title field:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="breakingnews.jpg" src="http://blog.spywareguide.com/images/breakingnews.jpg" class="mt-image-none" style="" height="90" width="418" /></span></div><br />If you visit the link in the email, you'll see this:<br /><div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/breakingnews2.html" onclick="window.open('http://blog.spywareguide.com/images/breakingnews2.html','popup','width=599,height=556,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/breakingnews2-thumb-399x370.jpg" alt="breakingnews2.jpg" class="mt-image-none" style="" height="370" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />I don't believe I've seen the length, rating and viewcount under the video before so that's likely a new tactic they've employed. Looks like they need to hire a spellchecker though...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Sun, 17 Aug 2008 12:00:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/news stories">news stories</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/major news networks">major news networks</category>
      <category domain="http://securityratty.com/tag/plain emails">plain emails</category>
      <category domain="http://securityratty.com/tag/title field">title field</category>
      <category domain="http://securityratty.com/tag/msnbc spam">msnbc spam</category>
      <category domain="http://securityratty.com/tag/cnn spam">cnn spam</category>
      <category domain="http://securityratty.com/tag/peoples attention">peoples attention</category>
      <category domain="http://securityratty.com/tag/spellchecker">spellchecker</category>
      <source url="http://blog.spywareguide.com/2008/08/cnn-msnbc-spammers-downgrading.html">CNN, MSNBC Spammers Downgrading Their EMails</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[A Change of Plan For Your Spam]]></title>
      <link>http://securityratty.com/article/20c092cee1e4a4187f4915c282e35789</link>
      <guid>http://securityratty.com/article/20c092cee1e4a4187f4915c282e35789</guid>
      <description><![CDATA[Someone really has to reign me in with these titles. Anyway, you may or may not have heard that the CNN spam mails have now morphed into mails that appear to come from Msnbc.com instead. The titles of...]]></description>
      <content:encoded><![CDATA[
        Someone really has to reign me in with these titles. Anyway, you may or may not have heard that the <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN spam mails</a> have now morphed into mails that appear to come from Msnbc.com instead. The titles of the emails are still as insane as ever:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="msb1.jpg" src="http://blog.spywareguide.com/images/msb1.jpg" class="mt-image-none" style="" height="37" width="395" /></span></div><br /> <div><br />......uh, wow. The email will take you to a fake Flash download, just like the previous efforts:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/msb2.html" onclick="window.open('http://blog.spywareguide.com/images/msb2.html','popup','width=949,height=534,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/msb2-thumb-349x196.jpg" alt="msb2.jpg" class="mt-image-none" style="" height="196" width="349" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Obviously, they haven't gotten around to making fake Msnbc pages so for now we're still stuck with the fake CNN pages.<br /><br />An odd side-effect of these emails is that they're likely lowering subscriber numbers for CNN and Msnbc, because the emails contain genuine unsubscribe links at the bottom:<br /><br /><div align="left"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="msb3.jpg" src="http://blog.spywareguide.com/images/msb3.jpg" class="mt-image-none" style="" height="209" width="555" /></span></div><br /></div><div><br />I doubt the creators of these scam mails intended that - they're just wanting to make the mails look realistic - but I could imagine disgruntled subscribers wondering why CNN and Msnbc keep sending them these things then reaching for the "no more, please!" link...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 11:42:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cnn spam mails">cnn spam mails</category>
      <category domain="http://securityratty.com/tag/mails">mails</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/fake cnn pages">fake cnn pages</category>
      <category domain="http://securityratty.com/tag/msnbc">msnbc</category>
      <category domain="http://securityratty.com/tag/fake msnbc pages">fake msnbc pages</category>
      <category domain="http://securityratty.com/tag/scam mails">scam mails</category>
      <category domain="http://securityratty.com/tag/genuine unsubscribe links">genuine unsubscribe links</category>
      <category domain="http://securityratty.com/tag/fake flash download">fake flash download</category>
      <source url="http://blog.spywareguide.com/2008/08/a-change-of-plan-for-your-spam.html">A Change of Plan For Your Spam</source>
    </item>
    <item>
      <title><![CDATA[Hackers spoof MSNBC alerts in new twist on massive malware ruse]]></title>
      <link>http://securityratty.com/article/8da128fc823587718e6bc7213808229c</link>
      <guid>http://securityratty.com/article/8da128fc823587718e6bc7213808229c</guid>
      <description><![CDATA[A group of hackers that last week was touting CNN to distribute malware this week changed its message to push stories said to be from rival network...]]></description>
      <content:encoded><![CDATA[A group of hackers that last week was touting CNN to distribute malware this week changed its message to push stories said to be from rival network MSNBC.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=RQX4ZZ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=RQX4ZZ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/364182025" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rival network msnbc">rival network msnbc</category>
      <category domain="http://securityratty.com/tag/push stories">push stories</category>
      <category domain="http://securityratty.com/tag/distribute malware">distribute malware</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/364182025/article.do">Hackers spoof MSNBC alerts in new twist on massive malware ruse</source>
    </item>
    <item>
      <title><![CDATA[Hackers spoof MSNBC alerts in new twist on malware ruse]]></title>
      <link>http://securityratty.com/article/e7db3d9e473638315e9a45bc91a0611d</link>
      <guid>http://securityratty.com/article/e7db3d9e473638315e9a45bc91a0611d</guid>
      <description><![CDATA[Hackers trying to plant malware on PCs have switched from touting CNN news in come-on messages to pushing breaking stories said to be from rival network MSNBC, security experts said...]]></description>
      <content:encoded><![CDATA[Hackers trying to plant malware on PCs have switched from touting CNN news in come-on messages to pushing breaking stories said to be from rival network MSNBC, security experts said today.]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rival network msnbc">rival network msnbc</category>
      <category domain="http://securityratty.com/tag/cnn news">cnn news</category>
      <category domain="http://securityratty.com/tag/come-on messages">come-on messages</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/plant malware">plant malware</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/stories">stories</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://www.networkworld.com/news/2008/081308-hackers-spoof-msnbc-alerts-in.html?fsrc=rss-security">Hackers spoof MSNBC alerts in new twist on malware ruse</source>
    </item>
    <item>
      <title><![CDATA[CNN Custom Alerts Spam]]></title>
      <link>http://securityratty.com/article/f544d5e769f123f7cc5f3036bac72fdd</link>
      <guid>http://securityratty.com/article/f544d5e769f123f7cc5f3036bac72fdd</guid>
      <description><![CDATA[In general, my anti-spam filters and tools are pretty effective. So when I start to see something like this







it's obvious that a huge spam wave is underway. These are, of course, related to the...]]></description>
      <content:encoded><![CDATA[
        In general, my anti-spam filters and tools are pretty effective. So when I start to see something like this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="cn1.jpg" src="http://blog.spywareguide.com/images/cn1.jpg" class="mt-image-none" style="" height="137" width="193" /></span></div><br /> <div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="cn2.jpg" src="http://blog.spywareguide.com/images/cn2.jpg" class="mt-image-none" style="" height="247" width="214" /></span></div>
<br />....it's obvious that a huge spam wave is underway. These are, of course, related to the <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">fake CNN Spam</a> from a few days ago. Here, the emails take the form of "custom alerts":<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/cn32.html" onclick="window.open('http://blog.spywareguide.com/images/cn32.html','popup','width=613,height=352,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/cn3-thumb-313x179.jpg" alt="cn3.jpg" class="mt-image-none" style="" height="179" width="313" /></a></span><br /><br />Click to Enlarge<br /></div><br />I've seen two types of this mail - one links to a genuine CNN article from the headline text (with the smaller link underneath leading to an infection site), the other simply links to the infection site from both clickable links. As before, deleting these Emails is the best course of action. Interestingly, the format of these mails might not be working to the spammers advantage. Lots of people I've talked to who had one of these mails sent through simply deleted them without a second thought, thinking it was merely something on the real CNN they thought they'd signed up to and didn't actually want.<br /><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Sun, 10 Aug 2008 13:28:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/links">links</category>
      <category domain="http://securityratty.com/tag/clickable links">clickable links</category>
      <category domain="http://securityratty.com/tag/simply links">simply links</category>
      <category domain="http://securityratty.com/tag/simply">simply</category>
      <category domain="http://securityratty.com/tag/custom alerts">custom alerts</category>
      <category domain="http://securityratty.com/tag/infection site">infection site</category>
      <category domain="http://securityratty.com/tag/fake cnn spam">fake cnn spam</category>
      <category domain="http://securityratty.com/tag/genuine cnn article">genuine cnn article</category>
      <category domain="http://securityratty.com/tag/huge spam wave">huge spam wave</category>
      <source url="http://blog.spywareguide.com/2008/08/cnn-custom-alerts.html">CNN Custom Alerts Spam</source>
    </item>
    <item>
      <title><![CDATA[Fake IE7 Downloads Advertised Via EMail]]></title>
      <link>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</link>
      <guid>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</guid>
      <description><![CDATA[There seem to be quite a few of these in circulation over the past day or so

Download the latest version

About this mailing
You are receiving this e-mail because you subscribed to
MSN Featured...]]></description>
      <content:encoded><![CDATA[
        There seem to be quite a few of these in circulation over the past day or so:<br /><br /><i>Download the latest version! &lt;URL Removed&gt; <br /><br />About this mailing: <br />You are receiving this e-mail because you subscribed to<br />MSN Featured Offers. Microsoft respects your privacy.<br />If you do not wish to receive this MSN Featured Offers e-mail,<br />please click the "Unsubscribe" link below. This will not<br />unsubscribe you from e-mail communications from third-party<br />advertisers that may appear in MSN Feature Offers.<br />This shall not constitute an offer by MSN. MSN shall<br />not be responsible or liable for the advertisers' content<br />nor any of the goods or service advertised. Prices and item<br />availability subject to change without notice.<br /><br />2008 Microsoft | Unsubscribe &lt;http://www.msn.com&gt;&nbsp; |<br />More Newsletters &lt;http://www.msn.com&gt;&nbsp; |<br />Privacy &lt;http://www.msn.com&gt; <br /><br />Microsoft Corporation, One Microsoft Way, Redmond, WA 98052</i><br /><br />As you might have guessed, it's fake. Microsoft don't send out EMails asking you to download files from random, non-Microsoft websites. This:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ie71.jpg" src="http://blog.spywareguide.com/images/ie71.jpg" class="mt-image-none" style="" height="63" width="76" /></span></div><br /> <div>....is not what it appears to be. Run the file, and instead of IE7, you're actually more likely to see a fake antivirus program appear on your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top106.html" onclick="window.open('http://blog.spywareguide.com/images/top106.html','popup','width=700,height=540,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top106-thumb-300x231.jpg" alt="top106.jpg" class="mt-image-none" style="" height="231" width="300" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />This particular fake AV is also being pushed quite heavily via the recent <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN videos scam</a>. You can see another example of these emails <a href="http://miekiemoes.blogspot.com/2008/08/beware-of-fake-email-from-microsoft.html">here</a>. There is more than one URL being used for this attack, so be alert!<br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 10:56:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/offers">offers</category>
      <category domain="http://securityratty.com/tag/offers e-mail">offers e-mail</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/non-microsoft websites">non-microsoft websites</category>
      <category domain="http://securityratty.com/tag/msn feature offers">msn feature offers</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/microsoft corporation">microsoft corporation</category>
      <category domain="http://securityratty.com/tag/microsoft respects">microsoft respects</category>
      <source url="http://blog.spywareguide.com/2008/08/fake-ie7-downloads-advertised.html">Fake IE7 Downloads Advertised Via EMail</source>
    </item>
    <item>
      <title><![CDATA[Massive Spam Campaign Spreads False CNN News Items With Fake Flash Player Malware]]></title>
      <link>http://securityratty.com/article/a225a716b4a000ec8b1b874643067ce6</link>
      <guid>http://securityratty.com/article/a225a716b4a000ec8b1b874643067ce6</guid>
      <description><![CDATA[Known social engineering tactic involving Adobe Flash Player is exploited in currently active malware campaign. Spammed user is encouraged to click on a site with a fake news item in order to install...]]></description>
      <content:encoded><![CDATA[Known social engineering tactic involving Adobe Flash Player is exploited in currently active malware campaign. Spammed user is encouraged to click on a site with a fake news item in order to install a fake Flash player update (file names might be flashupdate.exe, get_flash_update.exe, watchmovie.mpg.exe). If user clicks &#8220;Cancel&#8221; in the dialog that prompts for [...]]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 05:28:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/fake flash player">fake flash player</category>
      <category domain="http://securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/user clicks cancel">user clicks cancel</category>
      <category domain="http://securityratty.com/tag/fake news item">fake news item</category>
      <category domain="http://securityratty.com/tag/active malware campaign">active malware campaign</category>
      <category domain="http://securityratty.com/tag/exe">exe</category>
      <category domain="http://securityratty.com/tag/file names">file names</category>
      <source url="http://cyberinsecure.com/massive-spam-campaign-spreads-false-cnn-news-items-with-fake-flash-player-malware/">Massive Spam Campaign Spreads False CNN News Items With Fake Flash Player Malware</source>
    </item>
    <item>
      <title><![CDATA[Massive faux-CNN spam blitz uses legit sites to deliver fake Flash]]></title>
      <link>http://securityratty.com/article/12f4bbcf4ab32713a254176d17f53a3e</link>
      <guid>http://securityratty.com/article/12f4bbcf4ab32713a254176d17f53a3e</guid>
      <description><![CDATA[More than 1,000 hacked Web sites are serving up fake Flash Player software to users as part of a massive spam attack designed to look like CNN.com news notifications, security researchers said...]]></description>
      <content:encoded><![CDATA[More than 1,000 hacked Web sites are serving up fake Flash Player software to users as part of a massive spam attack designed to look like CNN.com news notifications, security researchers said today.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=df7dFe"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=df7dFe" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/357694223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massive spam attack">massive spam attack</category>
      <category domain="http://securityratty.com/tag/news notifications">news notifications</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/357694223/article.do">Massive faux-CNN spam blitz uses legit sites to deliver fake Flash</source>
    </item>
    <item>
      <title><![CDATA[CNN Daily Top 10 Videos Spam]]></title>
      <link>http://securityratty.com/article/435bec0379e65b99a3730188a6084946</link>
      <guid>http://securityratty.com/article/435bec0379e65b99a3730188a6084946</guid>
      <description><![CDATA[Like me, you've probably had quite a few &quot;CNN Top 10&quot; emails through over the last day or so. Here's just two of the many, many mails I've had through to various mailboxes





If you opened up any of...]]></description>
      <content:encoded><![CDATA[
        Like me, you've probably had quite a few "CNN Top 10" emails through over the last day or so. Here's just two of the many, many mails I've had through to various mailboxes:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="top101.jpg" src="http://blog.spywareguide.com/images/top101.jpg" class="mt-image-none" style="" height="72" width="371" /></span></div><br /> <div><br />If you opened up any of the mails, you'd have seen this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top102.html" onclick="window.open('http://blog.spywareguide.com/images/top102.html','popup','width=769,height=385,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top102-thumb-369x184.jpg" alt="top102.jpg" class="mt-image-none" style="" height="184" width="369" /></a></span></div><br /></div><div><div align="center">Click to Enlarge<br /></div><br />The first clue that something might have been amiss is the strangeness of some of the titles ("Michael Jackson sued by his own dog" isn't something I'd expect to see on CNN, at least not yet). Of course, the giveaway is that regardless of what link you click on, each one takes you to a website that isn't CNN.com - in fact, they all point to the same "video".<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top103.html" onclick="window.open('http://blog.spywareguide.com/images/top103.html','popup','width=512,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top103-thumb-312x292.jpg" alt="top103.jpg" class="mt-image-none" style="" height="292" width="312" /></a></span></div><div align="center"><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />If you download and install the file offered up, horrible things will start happening to your PC. Let's put it this way - anyone expecting to see Michael Jacksons dog in a courtroom is going to be severely disappointed.<br /><br />Before long, your desktop will look like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top105.html" onclick="window.open('http://blog.spywareguide.com/images/top105.html','popup','width=673,height=374,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top105-thumb-373x207.jpg" alt="top105.jpg" class="mt-image-none" style="" height="207" width="373" /></a></span><br /><br />Click to Enlarge<br /></div><br />You'll have warnings like these:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="top107.jpg" src="http://blog.spywareguide.com/images/top107.jpg" class="mt-image-none" style="" height="97" width="305" /></span></div><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top106.html" onclick="window.open('http://blog.spywareguide.com/images/top106.html','popup','width=700,height=540,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><br /></a></span>And a rogue antivirus product will magically appear on your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top106.html" onclick="window.open('http://blog.spywareguide.com/images/top106.html','popup','width=700,height=540,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top106-thumb-300x231.jpg" alt="top106.jpg" class="mt-image-none" style="" height="231" width="300" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Worst of all, look at the name of one of the fake infections they try to scare the user with. <br /><br />There's subtlety, then there's this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="top108.jpg" src="http://blog.spywareguide.com/images/top108.jpg" class="mt-image-none" style="" height="125" width="509" /></span>
<br /><br />....if you want to avoid your computer contributing to the "terrorist threat", don't open up any emails claiming to contain CNN videos.<br /><br />Even if its Michael Jackson and his dog.<br /><br /><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 14:50:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/cnn top">cnn top</category>
      <category domain="http://securityratty.com/tag/michael jacksons dog">michael jacksons dog</category>
      <category domain="http://securityratty.com/tag/michael jackson">michael jackson</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/dog">dog</category>
      <category domain="http://securityratty.com/tag/michael jackson sued">michael jackson sued</category>
      <category domain="http://securityratty.com/tag/cnn videos">cnn videos</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <source url="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN Daily Top 10 Videos Spam</source>
    </item>
  </channel>
</rss>
