<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: confirmation]]></title>
    <link>http://securityratty.com/tag/confirmation</link>
    <description></description>
    <pubDate>Tue, 15 Jul 2008 10:15:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Obama's DHS pick may find support for raising H-1B cap at confirmation hearing]]></title>
      <link>http://securityratty.com/article/a9c93eae85c969a9c8f5b6f3f1430b39</link>
      <guid>http://securityratty.com/article/a9c93eae85c969a9c8f5b6f3f1430b39</guid>
      <description><![CDATA[Janet Napolitano, President-elect Barack Obama's choice to lead the Department of Homeland Security, is a supporter of expanding the H-1B visa program. She will face a nomination hearing headed by...]]></description>
      <content:encoded><![CDATA[Janet Napolitano, President-elect Barack Obama's choice to lead the Department of Homeland Security, is a supporter of expanding the H-1B visa program. She will face a nomination hearing headed by Sen. Joseph Lieberman, who has been both an advocate and a critic of the program.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:602e44c240604e704d567cc1a597050d:nj85h9r8DMnSMPOkPbXm0iAwP6Ync%2FQcoS54vgK0SyA49XBr6mgh7igm3wh2ErfFqhKeSm3c1UZU'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:52bad47f588bd554c4636d30d70a935c:Peu%2FbFdrLwFLBcL1BIaPMLujOimdZC4WvWAlc8yCZOv4lJ%2FaQ62uZicXz48WdE5XX7FVhBOjm%2Fz0qw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:809d7ba6bb34614ab3b2d2aa4ece0fb7:KdTYNipNNZk59wIfXQ7%2B6tIZhsYoeB0pBxZjdqSzUfNduRqn2Bs%2Ft9bBtFb0GeM3qylV0A5mS0geEA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:92f360d1af41d4438df13c4e25ec864e:tiQKWtY51rwV3%2FVi4xVofu%2FAagNYwjkQ0MCuJ0Wg9NGGGAYuGpnht%2BLzXSCAfOfKer1vPyv%2BPSSDTA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=a165e83be51d820c08ecce05e9ce1683&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=a165e83be51d820c08ecce05e9ce1683&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a165e83be51d820c08ecce05e9ce1683" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/h-1b visa program">h-1b visa program</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/president-elect barack obama">president-elect barack obama</category>
      <category domain="http://securityratty.com/tag/joseph lieberman">joseph lieberman</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/janet napolitano">janet napolitano</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/supporter">supporter</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a165e83be51d820c08ecce05e9ce1683">Obama's DHS pick may find support for raising H-1B cap at confirmation hearing</source>
    </item>
    <item>
      <title><![CDATA[Facebook added friend confirmation Malicious Spam]]></title>
      <link>http://securityratty.com/article/50f239d80b4c92e72601deaae4591d8b</link>
      <guid>http://securityratty.com/article/50f239d80b4c92e72601deaae4591d8b</guid>
      <description><![CDATA[Websense Security Labs has discovered another round of malicious Facebook messages. This campaign is another visual social-engineering spam campaign which tries to visually trick users into believing...]]></description>
      <content:encoded><![CDATA[Websense Security Labs has discovered another round of malicious Facebook messages. This campaign is another visual social-engineering spam campaign which tries to visually trick users into believing that the message is a legitimate added friend confirmation. The &#8220;From&#8221; address in the message is spoofed to make it look as if it was sent from Facebook, [...]]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 23:54:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/friend confirmation">friend confirmation</category>
      <category domain="http://securityratty.com/tag/malicious facebook messages">malicious facebook messages</category>
      <category domain="http://securityratty.com/tag/spam campaign">spam campaign</category>
      <category domain="http://securityratty.com/tag/websense security labs">websense security labs</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/trick users">trick users</category>
      <category domain="http://securityratty.com/tag/visual">visual</category>
      <source url="http://cyberinsecure.com/facebook-added-friend-confirmation-malicious-spam/">Facebook added friend confirmation Malicious Spam</source>
    </item>
    <item>
      <title><![CDATA[Four Google officials likely to face charges in Italy]]></title>
      <link>http://securityratty.com/article/005fb60561834de048e51994a0d2a757</link>
      <guid>http://securityratty.com/article/005fb60561834de048e51994a0d2a757</guid>
      <description><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a bullying...]]></description>
      <content:encoded><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a bullying video.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7eba575780657c2ec5e27c04e5320c15:h4gInyOXsXXumjyiAzjludQbe9ptyIcCkN2i5lSGwFSWDJvqwQ6Cb593gWlEAUDmUS0W3xA8jgzF'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:eb571d3ff0b24cbf81c0633df5582f4b:WcM0%2B17vgE2kjN2gwOiwYUH7qEyIovl1cAv2sTkmt42ZNM9jlrCbjk%2FWy46B2%2BHnnwXjvhfbG4WYzA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1cfd1999a48e143dbe93b3dea1d636f1:hIanYcz8KaqIruo5pdFhg1ql3XUxpQ1ihdDSr41KpV9GDRYEGbh5zP5Z6FzD2E6TixxjnaZ%2F%2FCyJiQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:af2f81acaf61ea01ed9b62997e774f92:1At9A10b6TcFgKrE8laYU%2FGDOJA3O6frjibLMeSK1W49aAWQJOQgeJT6PSUnC9r95EwD8s2DoGICjQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d1e17c6c1e7c0899329058fba3dca68b" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d1e17c6c1e7c0899329058fba3dca68b" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/italy">italy</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <category domain="http://securityratty.com/tag/confirmation">confirmation</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=d1e17c6c1e7c0899329058fba3dca68b">Four Google officials likely to face charges in Italy</source>
    </item>
    <item>
      <title><![CDATA[Four Google officials likely to stand trial in Italy]]></title>
      <link>http://securityratty.com/article/587e13df8650eea41de19fe82e61cabf</link>
      <guid>http://securityratty.com/article/587e13df8650eea41de19fe82e61cabf</guid>
      <description><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a video of a disabled teenager being...]]></description>
      <content:encoded><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a video of a disabled teenager being bullied.]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/italy">italy</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/teenager">teenager</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <category domain="http://securityratty.com/tag/confirmation">confirmation</category>
      <source url="http://www.networkworld.com/news/2008/110608-four-google-officials-likely-to.html?fsrc=rss-security">Four Google officials likely to stand trial in Italy</source>
    </item>
    <item>
      <title><![CDATA[Linksys WRT610N Review]]></title>
      <link>http://securityratty.com/article/edcd9863740d597dbc3a37c18f2e59ff</link>
      <guid>http://securityratty.com/article/edcd9863740d597dbc3a37c18f2e59ff</guid>
      <description><![CDATA[My review of the Linksys WRT610N at Macworld: The router works quite well at handling Wi-Fi and other functions, but is terrible at working with Mac OS X, one of the advertised features of the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.macworld.com/article/135222/2008/09/linksyswrt610n.html"><strong>My review of the Linksys WRT610N at Macworld:</strong></a> The router works quite well at handling Wi-Fi and other functions, but is terrible at working with Mac OS X, one of the advertised features of the product. The WRT610N is a revised design of the previous simultaneous dual-band (2.4/5 GHz) Draft N WRT600N model which had far worse problems. </p>

<p>Linksys addressed many of my concerns with that previous device. The 610N can mount a drive and share it via SMB and FTP, have two full-speed connections running over both bands without skipping a beat, and supports several methods of getting the one-click WPS (Wi-Fi Protected Setup) to work. Read the review for all the details, but I can't recommend this router to Mac users with any needs beyond basic networking; I'm perfectly happy to give it a full thumbs-up for Windows XP and Vista users, however.</p>

<p><img src="http://wifinetnews.com//images/2008/WRT610N_M.jpg" alt="WRT610N_M.jpg" border="0" width="229" height="111" /></p>

<p>WPS is a particular mess, by the way. Linksys has four somewhat distinct methods of using WPS to enable a password-free encrypted connection between a client and a base station: a button on the front that, when pressed, turns on WPS; and three modes (one of them similar to that button) accessible via their Web configuration software. One option is to get the base station to create a short PIN that's then entered on the client system as an out-of-band confirmation that there's no man in the middle.</p>

<p>Apple, by contrast, has a single way of joining a WPS-offering base station: it displays the network's name in bold. Select the network, and Mac OS X displays a key code that needs to be entered on the base station. But the WRT610N can't handle that option. If you put the WRT610N into a mode in which Apple can spot the device as offering a WPS handshake, you can't enter the code into the Linksys router!</p>

<p>This shows that there's still rough edges in the WPS protocol that two of the highest-selling makers of Wi-Fi gear can manage to not mesh up their respective options. (Apple declined to comment for my Macworld story; Linksys confirmed the lack of compatibility, but put the burden on Apple's doorstep.)</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:27:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wrt610n">wrt610n</category>
      <category domain="http://securityratty.com/tag/linksys wrt610n">linksys wrt610n</category>
      <category domain="http://securityratty.com/tag/linksys">linksys</category>
      <category domain="http://securityratty.com/tag/wps protocol">wps protocol</category>
      <category domain="http://securityratty.com/tag/wps">wps</category>
      <category domain="http://securityratty.com/tag/base station">base station</category>
      <category domain="http://securityratty.com/tag/linksys router">linksys router</category>
      <category domain="http://securityratty.com/tag/one-click wps">one-click wps</category>
      <category domain="http://securityratty.com/tag/wps handshake">wps handshake</category>
      <source url="http://wifinetnews.com/archives/008441.html">Linksys WRT610N Review</source>
    </item>
    <item>
      <title><![CDATA[Eight Steps to Responsible Surfing]]></title>
      <link>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</link>
      <guid>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</guid>
      <description><![CDATA[Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of...]]></description>
      <content:encoded><![CDATA[<div><strong></strong>Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of security, surfers cannot rely entirely on technology, and should also address the behavioral issues that are most likely to create risky situations.</div>
<p><strong>Changing Behavior</strong></p>
<div>The safest way to deal with a danger is avoidance. By surfing safely and adapting offline sensibilities online, surfers can greatly reduce their danger of exposure to malware.</div>
<p><strong>1. Educate yourself.</strong><br />
At least every 6 to 12 months, surfers should browse the educational information provided by their operating system and security vendors and subscribe to any security-related newsletters they might offer. According to David Perry, familiarity with the latest threats, dangers, and recommended safety tips will allow surfers to make safe choices. &#8220;Until you know what&#8217;s out there, you&#8217;re just flying blind. Without an education, you&#8217;re wide open&#8221;.<br />
<strong>2. Avoid suspect sites.</strong><br />
While criminals can infect even mainstream Web sites, sites such as gambling sites, adult Internet sites, and illegal file-sharing sites are far more likely to carry malicious code. Web sites that offer &#8220;something for nothing&#8221; frequently recoup their losses by infecting visitors&#8217; PCs.<br />
<strong>3. Lose Your Comfort Zone.</strong></p>
<div>Web surfers should migrate their offline precautions to their online experience. By beginning with an attitude of healthy skepticism and only doing business with trusted Web sites, surfers can bypass a good deal of risk.</div>
<p><strong>Recommended Technology</strong></p>
<div>Despite the best precautions, every user will encounter Web-based malware. While no technology can guarantee protection against all attacks, a combination of preventive technologies provides the most comprehensive protection possible.</div>
<p><strong>4. Use an updated virus scanning suite.</strong><br />
The most important component of any threat mitigation system is a virus scanning suite. In addition to detecting and removing known viruses and malware, modern virus scanning suites provide additional protections against new attacks by disabling their known protocols. For example, Trend Micro™ Internet Security encrypts keyboard traffic, protecting personal data from keyboard logging programs that might go unnoticed. Users should update their scanner and virus definitions as frequently as possible to ensure the best possible coverage.<br />
<strong>5. Upgrade your OS and browser.</strong><br />
In addition to offering more features, Microsoft&#8217;s Internet Explorer version 7 and the latest Mozilla Firefox are both substantially more secure than previous-generation browsers. Users of older browsers should upgrade immediately to take advantage of increased security. Similarly, Windows Vista and Mac OS X are more secure than their predecessors, and users of older operating systems should consider upgrading, as well.<br />
<strong>6. Disable scripting and &#8220;widgets.&#8221;</strong><br />
Many Web-based attacks use various scripting languages to run infectious programs in a browser or use downloadable &#8220;widgets&#8221; to execute infections locally. By disabling scripting and avoiding downloadable widgets wherever possible, surfers disable these common attack vectors.<br />
<strong>7. Rate your Web pages.</strong><br />
Some available services rate the risk of Web pages in search results, allowing surfers to avoid unwanted content and hidden threats before viewing the pages. Rating applications (e.g., Trend Micro TrendProtect™) consume few system resources and run unobtrusively, so they are suitable for any Web-enabled personal computer.<br />
<strong>8. Ask your provider.</strong><br />
Commerce companies, banks, and credit card associations are all interested in computer security, and many offer additional features. For example, Visa&#8217;s Verified By Visa program requires cardholders to enter a second password to identify themselves during a transaction, while businesses in Poland require cell-phone confirmation of credit card purchases. While nothing will be 100 percent effective, any additional security measure provided by a trusted source will increase protection, and surfers should adopt as many as possible.</p>
<p>This article provided for your reading pleasure by Trend Micro.</p>
]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 20:30:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mainstream web sites">mainstream web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/adult internet sites">adult internet sites</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web surfers">web surfers</category>
      <category domain="http://securityratty.com/tag/surfers">surfers</category>
      <category domain="http://securityratty.com/tag/surfers disable">surfers disable</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=536">Eight Steps to Responsible Surfing</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial]]></title>
      <link>http://securityratty.com/article/c942d386cfed24bfc702c39e34ba0eea</link>
      <guid>http://securityratty.com/article/c942d386cfed24bfc702c39e34ba0eea</guid>
      <description><![CDATA[This email hacking as a service offering is the direct result of the public release of a DIY hacking kit consisting of each and every publicly known vulnerability for a variety of web based email...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SIb2scvQlJI/AAAAAAAAB80/xZ9U_kM3uFY/s1600-h/email_hacking_for_hire.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SIb2scvQlJI/AAAAAAAAB80/h8JpVAHsl1E/s200-R/email_hacking_for_hire.png" style="border: 0pt none ;" /></a>This email hacking as a service offering is the direct result of the public release of a <a href="http://ddanchev.blogspot.com/2008/04/web-email-exploitation-kit-in-wild.html">DIY hacking kit consisting of each and every publicly known vulnerability for a variety of web based email service providers</a>, with the idea to make it easier for someone to execute their attacks more efficiently. Outsource the hacking of someone's email, and receive a proof in the form of a screenshot of the inbox, next to a guarantee that you'll be able to get back in even after they've changed their passwords? Too good to be true, but since they only charge after they provide you with a proof that they did the job, they could be in fact attempting to hack these emails, compared to the majority of cases where scammers scam the scammers. The service works in 7 steps :<br />
<br />
"<i><b>1-</b> Submit your case to one of our experts.<br />
<b>2-</b> After successful submission , you will be sent a confirmation email along with your Case Reference Number (CRN) .<br />
<b>3-</b> Our expert(s) will revert back to you in a few minutes with the details, the charges &amp; the turn-around time. You may also be asked to provided additional information through a private form if required by our expert.<br />
<b>4-</b> Once our expert has all the required information, you will be provided a username/password to our client area where you can view the real-time progress of your case.<br />
<b>5-</b> Within a matter of hours (maximum 72 hrs), you can see the results. Our expert will provide you with proof-of-success , which you can verify and confirm.<br />
<b>6- </b>Once you have verified the authenticity of success, you will be sent detailed payment instructions. You will be asked to pay using anyone of our multiple payment methods.<br />
<b>7-</b> Once the payment is realized, we will provide you the requisite information</i>"<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SIgn4G_LUJI/AAAAAAAAB9E/gUjdnUIhb2I/s1600-h/email_hacking_for_hire2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SIgn4G_LUJI/AAAAAAAAB9E/K90KY6BFmtc/s200-R/email_hacking_for_hire2.png" style="border: 0pt none ;" /></a>Who's doing the actual email hacking? Independent contractors on behalf of the service as it looks like :<br />
<br />
"<i>Most other groups employ phishing , trojans or viruses which could damage or even alert the target. Our experts use techniques which are developed by themselves , not shared by anyone. We don't ask them how they do it, but as long as they provide us the desired results, its ok for us. Since we test their methods while they are on probation period with us, we check if the target is being alerted or not. As of now, for the past 4 years, we have NOT RECEIVED A SINGLE COMPLAINT IN THIS REGARD, which is testimonial to the ingenuity of the methods used by CSP.</i>"<br />
<br />
How would they prove that they've managed to hack the email account before requesting the payment?<br />
<br />
"<i><b>1-</b> Multiple screenshots of the mailbox<br />
<b>2-</b> A copy of your own email which you had sent to the target<br />
<b>3-</b> A copy / part of the address-book of the target mailbox.</i>"<br />
<br />
Ironically, a hypothetical questionarry that I once speculated a private detection would require from someone interested in <a href="http://ddanchev.blogspot.com/2007/04/outsourcing-spying-on-your-wife.html">Outsourcing The Spying on Their Wife</a>, in order to set the foundations for a successful social engineering attack, is being used by the email hacking group.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BtCtQJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BtCtQJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ICiRJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ICiRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sz7zbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sz7zbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a0Galj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a0Galj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OnvMKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OnvMKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u7PbTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u7PbTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6TRHXj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6TRHXj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/344330657" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 22:04:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/confirmation email">confirmation email</category>
      <category domain="http://securityratty.com/tag/methods">methods</category>
      <category domain="http://securityratty.com/tag/multiple payment methods">multiple payment methods</category>
      <category domain="http://securityratty.com/tag/actual email">actual email</category>
      <category domain="http://securityratty.com/tag/payment">payment</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/mailbox">mailbox</category>
      <category domain="http://securityratty.com/tag/target mailbox">target mailbox</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/344330657/email-hacking-going-commercial.html">Email Hacking Going Commercial</source>
    </item>
    <item>
      <title><![CDATA[Money Mule Recruiters use ASProx's Fast Fluxing Services]]></title>
      <link>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</link>
      <guid>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</guid>
      <description><![CDATA[Just consider this scheme for a second. A well known money mule recruitment site Cash Transfers is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/c7TMX064n4w/s1600-h/cash_transfers_money_mule_recruitment.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/CaeHtWn_06M/s200-R/cash_transfers_money_mule_recruitment.png" style="border: 0pt none ;" /></a>Just consider this scheme for a second. A well known <a href="http://www.docep.wa.gov.au/ConsumerProtection/scamnet/Scams/Cash-Transfers_Inc.html">money mule recruitment site Cash Transfers</a> is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting services for several hundred domains used on the last wave of SQL injection attacks. Ironically, <a href="http://www.banksafeonline.org.uk/moneymule_explained.html">the money mule recruitment site</a> is sharing IPs with many of them. Who are these money launderers (<b>cashtransfers.tk</b>; <b>cashtransfers.eu; type53.eu</b>; <b>sid57.tk</b>; <b>catdbw.mobi</b>; <b>cdrpoex.com </b>etc.&nbsp; ) anyway?<br />
<br />
<div style="text-align: left;">"<i>Cash-Transfers Inc. is an online-to-offline international money transfer service. We offer a secure, fast, and inexpensive means of sending money from the UK to offline recipients worldwide. Recipients do not require a bank account or Internet connection to receive funds. We have teamed with select local disbursement partners to provide a convenient, secure, and cost-effective means of sending money to family, friends and business partners abroad. The basic requirements to send money/transfer money are:</i></div><i><br />
1) Senders must have Internet access and a bank account or credit/debit card to transfer money. However, recipients do not require either a bank account or Internet connection.<br />
<br />
2) Money sent through Cash-Transfers Inc. is available for pick up at the distribution partner instantly, or, in most countries, money can be delivered to the recipient in a matter of hours.<br />
<br />
3) Our local agents will call your recipient (during local business hours) to provide additional details, including: forms of identification required, hours of operation, and other locations. The sender will also receive an email confirmation with transaction details and tracking information.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/qtHLcMs6sVs/s1600-h/cash_transfers_asprox_SQL_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/y-aSv2_Sztk/s200-R/cash_transfers_asprox_SQL_injection.JPG" style="border: 0pt none ;" /></a></div>The fast-flux infrastructure they're currently using is also providing services to domains that are currently used, or have been used in previous SQL injection attacks. Some info on the current DNS servers used in the fast-flux :<br />
<br />
<b>ns10.cashtransfers.tk<br />
ns11.cashtransfers.tk<br />
ns1.cashtransfers.tk<br />
ns12.cashtransfers.tk<br />
ns2.cashtransfers.tk<br />
ns13.cashtransfers.tk<br />
ns3.cashtransfers.tk<br />
ns14.cashtransfers.tk<br />
ns4.cashtransfers.tk<br />
ns15.cashtransfers.tk<br />
ns5.cashtransfers.tk<br />
ns16.cashtransfers.tk<br />
ns6.cashtransfers.tk<br />
ns17.cashtransfers.tk<br />
ns7.cashtransfers.tk<br />
ns8.cashtransfers.tk</b><br />
<br />
With the distributed and dynamic hosting infrastructure courtesy of the malware infected user, scammers, spammers, phishers and malware authors are only starting to experiment with the potential abuses of such an underground ecosystem build on the foundations of compromises hosts.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aMnYfJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aMnYfJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wo8AkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wo8AkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=22rmej"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=22rmej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ec2OKj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ec2OKj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LfbMJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LfbMJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LYf9J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LYf9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LO3zj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LO3zj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338919917" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 02:23:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/cashtransfers">cashtransfers</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <category domain="http://securityratty.com/tag/transfer money">transfer money</category>
      <category domain="http://securityratty.com/tag/fast-flux infrastructure">fast-flux infrastructure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338919917/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</source>
    </item>
    <item>
      <title><![CDATA[Very few details are available for Missouri National Guard breach]]></title>
      <link>http://securityratty.com/article/a9da228def34f73b19354bb07ad9da29</link>
      <guid>http://securityratty.com/article/a9da228def34f73b19354bb07ad9da29</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/15/08

Organization
National Guard Bureau

Contractor/Consultant/Branch
Missouri National Guard (&quot;MOGUARD

Victims
Citizen-Soldier and employee&quot;s
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/moguard.jpg" width="155" align="right" height="155"><font size="2"><b>Date Reported: </b><br>7/15/08<br><br><b>Organization: </b><br><a href="http://www.ngb.army.mil/default.aspx">National Guard Bureau</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.moguard.com/">Missouri National Guard ("MOGUARD")</a> <br><br><span style="font-weight: bold;">Victims:</span><br>"Citizen-Soldier and employee"s<br><br><span style="font-weight: bold;">Number Affected:</span><br>"approximately 2,000"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"some personal information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The Missouri National Guard learned on Monday, July 14, 2008, that some personal information was compromised. Details of how this information was compromised are being withheld at this time, so as not to interfere with the ongoing law enforcement investigation."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.moguard.com/What%20Happened%20in%20July%202008%20and%20How%20Does%20this%20Affect%20Me%20(Final%20Version)%2015JUL08.pdf">Missouri National Guard Press Release</a> <br><a href="http://www.stltoday.com/stltoday/news/stories.nsf/news/missouristatenews/story/ca0fe7785a2d8471862574870051f7fd?OpenDocument">St. Louis Post-Dispatch</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Missouri National Guard<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The Missouri National Guard learned on Monday, July 14, 2008, that some personal information was compromised.<br><br>Details of how this information was compromised are being withheld at this time, so as not to interfere with the ongoing law enforcement investigation.<br><span style="font-style: italic;">[Evan] Sounds like a good excuse to not reveal details.</span><br><br>It is important to note that we have no reason to believe that the information that was compromised was for the purpose of gaining Citizen-Soldier or employee information or that the information has been or will be used inappropriately.<br><span style="font-style: italic;">[Evan] It's nice that MOGUARD can make this judgment call on behalf of the victims.&nbsp; Its too bad the victims are not allowed to make a determination themselves based on the facts surrounding this breach.</span><br><br>The Missouri National Guard has a list of those Citizen-Soldiers or employees whose information was compromised.<br><span style="font-style: italic;">[Evan] Keyword is "was", and not the phrase "may have been".</span><br><br>Letters are being sent to these individuals and/or their Families.<br><br>The list includes approximately 2,000 individuals.<br><br>At this time we have no confirmation of misuse of Citizen-Soldier or employee information resulting from the loss.<br><br>"I am distressed that sensitive information has been compromised," <a href="http://www.moguard.com/tag/MONG.tag.asp">Major General King Sidwell</a> <br><span style="font-style: italic;">[Evan] I am impressed when a leader of an organization steps forward and speaks about a breach.&nbsp; In my opinion it demonstrates strong leadership and the understanding that the "buck" ultimately stops with him.</span><br><br>"I am especially concerned about the problems and inconveniences this may cause for our Missouri National Guard Citizen-Soldiers and their families," King said.<br><br>Because Social Security Numbers may have been contained within the missing information, we advise individuals to monitor financial accounts continuously for suspicious activity as a matter of good practice.<br><span style="font-style: italic;">[Evan] This statement provide a clue as to what "some personal information" may be.</span><br><br>The Missouri National Guard has safeguards in place to protect private information.<br><br>We provide ongoing privacy training to all employees.<br><br>The Missouri National Guard has taken action to rectify this unfortunate situation, and is working to insure our Citizen-Soldier’s or employee’s information receives the highest standard of security and privacy protection.<br><br>Any soldier or family member with questions should call a hotline number at 1-888-526-6664 extension 7888.<br><br>If the soldier is deployed overseas, the soldier may use the Defense Switching Network and call 312-555-9500 extension. 7888. <br><br><span style="font-weight: bold;">Commentary:</span><br>We have no idea as to what the cause of this breach may have been.&nbsp; Anyone want to guess?&nbsp; If so, post a comment.<br><br>It’s a little ironic.&nbsp; I was just typing an email response to an information security friend of mine about military breaches and the way the military has a completely different way of disclosing details (if any).&nbsp; This breach is proof positive.&nbsp; We'll have to see if further details emerge over time.<br><br>I sincerely hope that the owners of the "personal information" (the victims) get all of the answers that they require in order to evaluate risk themselves and make educated decisions on how they will proceed. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/moguard.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 10:15:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/missouri national guard">missouri national guard</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/employee information">employee information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/employees information receives">employees information receives</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <source url="http://breachblog.com/2008/07/15/moguard.aspx">Very few details are available for Missouri National Guard breach</source>
    </item>
  </channel>
</rss>
