<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: criminals]]></title>
    <link>http://securityratty.com/tag/criminals</link>
    <description></description>
    <pubDate>Tue, 05 Aug 2008 02:36:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Senator Obama's security concerns]]></title>
      <link>http://securityratty.com/article/ce6e50c5b4d179e0d726e937841e4dde</link>
      <guid>http://securityratty.com/article/ce6e50c5b4d179e0d726e937841e4dde</guid>
      <description><![CDATA[It appears as if the authorities in Colorado are trying to down play the reported assassination plot of Senator Obama. Question is; how real was it


It would certainly appear that the suspects were...]]></description>
      <content:encoded><![CDATA[It appears as if the authorities in Colorado are trying to down play the reported assassination plot of Senator Obama.  Question is; how real was it?<br /><span id="fullpost"><br /> <br />It would certainly appear that the suspects were preparing for something out of the ordinary as they were reported as having a bullet proof vest and a high powered rifle with telescopic scope in their possession when apprehended.  The fact that one of the them was described by his cohort as a "white supremist" who did not believe that a man of color could be the President of the U.S.A. is surely telling.<br /><br />These three criminals were caught in much the same manner as the domestic terrorist, Timothy McVeigh.  A dilgent policeman was doing his duty and pulled over the first suspect on a traffic stop.  Some may call that luck, but having been a former Law Enforcement officer, I look upon it as good Police work.  Many others might have not noticed the one little sign that made that officer suspicious and prompted him to check out the driver of the van.<br /><br />That is why security can never rest.  Whether it is foiling a potential terrorist plot or finding a child who has been abducted, we must always remain vigilant.  It is a shame that there are those who believe a man is inferior based upon the color of his skin.  It is even more terrible to realize that such a person would be willing to kill another based on racial hatred.  <br /><br />Unfortunately, this is a sad fact of life and steps need to be taken to thwart those disturbed individuals.  Was this latest episode a non-event or by dismissing it are we attempting to sweep the shame of racism under the carpet?  I for one, don't think that we should take these warnings lightly.  Afterall, it has been 45 years and people still debate the assassination of JFK.  We still hear it being said that Lee Harvey Oswald was incapable of carrying out the killing himself.<br /><br />I recently watched a documentary on the assassination of Robert Kennedy, produced on the 40th anniversary of his death.  When interviewed, the brother of the asssassin claims that his brother was too nice a guy to do something so awful. The fact of the matter however, is that both Kennedys were brutally gunned down.  I am sure it is something that nobody ever wants to see repeated.  <br /><br />Let us hope that whomever succeeds as President in November has a long and healthy Presidency and helps to allevitae the problems that have been piling up.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 14:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/assassination">assassination</category>
      <category domain="http://securityratty.com/tag/senator obama">senator obama</category>
      <category domain="http://securityratty.com/tag/assassination plot">assassination plot</category>
      <category domain="http://securityratty.com/tag/potential terrorist plot">potential terrorist plot</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/law enforcement officer">law enforcement officer</category>
      <category domain="http://securityratty.com/tag/inferior based">inferior based</category>
      <category domain="http://securityratty.com/tag/lee harvey oswald">lee harvey oswald</category>
      <category domain="http://securityratty.com/tag/bullet proof vest">bullet proof vest</category>
      <source url="http://www.thebulletproofblog.com/2008/08/senator-obamas-security-concerns.html">Senator Obama's security concerns</source>
    </item>
    <item>
      <title><![CDATA[If there were gold medals for Data Leakage...]]></title>
      <link>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</link>
      <guid>http://securityratty.com/article/9ec180dabd953b9e40bf780ac4cd7485</guid>
      <description><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the...]]></description>
      <content:encoded><![CDATA[I've just returned from my summer vacation, somewhat foolishly deciding to spend it under canvas in the south-west of the UK and expecting to get good weather. If my tent had leaked as badly in the last couple of weeks as data seems to have been leaking in the UK during the same period, I'd be in need of an <a href="http://en.wikipedia.org/wiki/Aqua_Lung">aqualung</a> by now! If it were an Olympic sport, Britain would have beaten China for pole position in the <a href="http://news.bbc.co.uk/sport2/hi/olympics/medals_table/default.stm">medals table</a>!
<P>
It all started with the loss of a <a href="http://news.bbc.co.uk/1/hi/uk_politics/7575989.stm">memory stick</a> by a UK Government contractor which contained somewhere around 120,000 records, including the details of 10,000 of our nation's most serious criminals. <B>We then heard about a compromise at global hotel chain Best Western...</b>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global hotel chain">global hotel chain</category>
      <category domain="http://securityratty.com/tag/olympic sport">olympic sport</category>
      <category domain="http://securityratty.com/tag/summer vacation">summer vacation</category>
      <category domain="http://securityratty.com/tag/pole position">pole position</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/government contractor">government contractor</category>
      <category domain="http://securityratty.com/tag/medals table">medals table</category>
      <category domain="http://securityratty.com/tag/memory stick">memory stick</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1334">If there were gold medals for Data Leakage...</source>
    </item>
    <item>
      <title><![CDATA[Erase Your Hard Drives Before Selling Them]]></title>
      <link>http://securityratty.com/article/1863838def4b467b54e51c1ef762ffdf</link>
      <guid>http://securityratty.com/article/1863838def4b467b54e51c1ef762ffdf</guid>
      <description><![CDATA[Sounds like a no-brainer, but its a lesson that some large companies still have to learn
IT manager Andrew Chapman purchased a used drive on eBay, for just 77 British pounds, only to find that it...]]></description>
      <content:encoded><![CDATA[<p>Sounds like a no-brainer, but it&#8217;s a lesson that some large companies still have to learn.</p>
<p><span style="font-size:x-small;">IT manager Andrew Chapman purchased a used drive on eBay, for just 77 British pounds, only to find that it contained the financial history and information for several million people, customers of the </span><span style="font-size:x-small;">Royal Bank of Scotland (RBS) and its subsidiary, Natwest. Luckily for them, Chapman had their best interests at heart and reported the problem, rather than selling or using the information.</span></p>
<p>According to Evan at the Breach Blog:</p>
<blockquote><p><span style="font-size:x-small;"><span style="font-style:italic;"> The University of Glamorgan conducted research about hard drives bought on eBay that contained sensitive information and </span><a rel="nofollow" style="font-style:italic;" target="_blank" href="http://breachblog.com/2007/09/13/university-of-glamorgan-discovers-data-on-discarded-drives.aspx">published</a><span style="font-style:italic;"> their findings in September 2007. If people don&#8217;t think that criminals are buying hard drives on eBay, searching for sensitive information (personal information, health information, corporate secrets, intellectual property, etc.), then they are deluded</span></span></p></blockquote>
<p>Click here to read the<a rel="nofollow" target="_blank" href="http://breachblog.com/2008/08/27/ebay.aspx"> full article.</a></p>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/health information">health information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/chapman">chapman</category>
      <category domain="http://securityratty.com/tag/manager andrew chapman">manager andrew chapman</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/ebay">ebay</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/376404913/">Erase Your Hard Drives Before Selling Them</source>
    </item>
    <item>
      <title><![CDATA[And the attacks keep coming...]]></title>
      <link>http://securityratty.com/article/dc3336423e75b4771497f1797bc8bfe3</link>
      <guid>http://securityratty.com/article/dc3336423e75b4771497f1797bc8bfe3</guid>
      <description><![CDATA[Seems like the intensity and frequency breaches have just started to warm up! Even as we pat ourselves about the recent indictment of criminals we see reports of increased activity . Millions of cards...]]></description>
      <content:encoded><![CDATA[Seems like the intensity and frequency breaches have just started to warm up! Even as we pat ourselves about the recent indictment of criminals we see reports of <a href="http://www.darkreading.com/document.asp?doc_id=161838&amp;WT.svl=news1_5">increased activity</a>. Millions of cards stolen and more loss...<br /><br />Brings us back to a hard question we have to ask ourselves - are we ready to tackle this seriously? Vendors, retailers, banks, government and consumers all have a huge stake in this (and don't forget, so does organized crime). However, it seems like organized crime is living up to its name - they seem a bit more organized about this. Not having looked at the numbers, but is feels like we are being pushed back and they currently have the upper hand...<br /><br />Not a very PC thing to say, I know. However, we have to wake up to the reality and get more serious about this.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=iDTL9K"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=iDTL9K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=s6e7ek"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=s6e7ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=b0FIUK"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=b0FIUK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/371263082" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 16:29:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hard question">hard question</category>
      <category domain="http://securityratty.com/tag/recent indictment">recent indictment</category>
      <category domain="http://securityratty.com/tag/crime">crime</category>
      <category domain="http://securityratty.com/tag/frequency breaches">frequency breaches</category>
      <category domain="http://securityratty.com/tag/huge stake">huge stake</category>
      <category domain="http://securityratty.com/tag/upper hand">upper hand</category>
      <category domain="http://securityratty.com/tag/retailers">retailers</category>
      <category domain="http://securityratty.com/tag/pat">pat</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/371263082/and-attacks-keep-coming.html">And the attacks keep coming...</source>
    </item>
    <item>
      <title><![CDATA[Compromised Cpanel Accounts For Sale]]></title>
      <link>http://securityratty.com/article/6228ebb081126296ff70b5f6268fd2a3</link>
      <guid>http://securityratty.com/article/6228ebb081126296ff70b5f6268fd2a3</guid>
      <description><![CDATA[Is the once popular in the second quarter of 2007, embedded malware tactic on the verge of irrelevance, and if so, what has contributed to its decline? Have SQL injections executed through botnets...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKlq1uSeDFI/AAAAAAAACDM/l4bxcru-BQk/s1600-h/cpanel_multiple_domains1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKlq1uSeDFI/AAAAAAAACDM/ho301JgoMUs/s200-R/cpanel_multiple_domains1.png" /></a> Is the once popular in the second quarter of 2007, embedded malware tactic on the verge of irrelevance, and if so, what has contributed to its decline? Have SQL injections executed through botnets turned into the most efficient way to infect hundreds of thousands of legitimate web sites? Depends on who you're dealing with.<br />
<br />
A cyber criminal's position in the "underground food chain" can be easily tracked down on the basis of tools and tactics that he's taking advantage of, in fact, some would on purposely misinform on what their actual capabilities are in order not to attract too much attention to their real ones, consisting of high-profile compromises at hundreds of high-profile web sites.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKmDVdDGnPI/AAAAAAAACDU/qNbLBUKlHp0/s1600-h/cpanel_multiple_domains3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKmDVdDGnPI/AAAAAAAACDU/ZsmcK9HMeUs/s200-R/cpanel_multiple_domains3.jpg" /></a>Embedded malware may not be as hot as it used to be in the last quarter of 2007, but thanks to the oversupply of stolen accounting data, certain individuals within the underground ecosystem seem to be abusing entire portfolios of domains on the basis of purchasing access to the compromised accounts. In fact, the oversupply of compromised Cpanel accounts is logically resulting in their decreasing price, with the sellers differentiating their propositions, and charging premium prices based on the site's page ranks and traffic, measured through publicly available services, or through the internal statistics.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKmMyr4CWEI/AAAAAAAACDc/UafOTCKAb-0/s1600-h/cpanel_multiple_domains22.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKmMyr4CWEI/AAAAAAAACDc/7IRBMNndy-w/s200-R/cpanel_multiple_domains22.JPG" /></a><br />
SQL injections may be the tactic of choice for the time being, but as long as stolen accounting data consisting of Cpanel logins, and web shells access to misconfigured web servers remain desired underground goods, goold old fashioned embedded malware will continue taking place.<br />
<br />
Interestingly, from an economic perspective, the way the seller markets his goods, can greatly influence the way they get abused given he continues offering after-sale services and support. It's blackhat search engine optimization I have in mind, sometimes the tactic of choice especially given its high liquidity in respect to monetizing the compromised access.<br />
<br />
The bottom line - for the time being, there's a higher probability that your web properties will get SQL injected, than IFRAME-ed, as it used to be half a year ago, and that's because what used to be a situation where malicious parties would aim at launching a targeted attack at high profile site and abuse the huge traffic it receives, is today's pragmatic reality where a couple of hundred low profile web sites can in fact return more traffic to the cyber criminals, and greatly extend the lifecycle of their campaign taking advantage of the fact the the low profile site owners would remain infected and vulnerable for months to come.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">Embedding Malicious IFRAMEs Through Stolen FTP Accounts</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/injecting-iframes-by-abusing-input.html">Injecting IFRAMEs by Abusing Input Validation</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast-flux Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware </a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">SQL Injection Through Search Engines Reconnaissance</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">Google Hacking for Vulnerabilities</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><br />
<a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<a href="http://blogs.zdnet.com/security/?p=1118">Redmond Magazine Successfully SQL Injected by Chinese Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ExzKaK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ExzKaK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AgwoKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AgwoKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5JjO7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5JjO7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Z85mk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Z85mk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=s4xhGK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=s4xhGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ReebmK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ReebmK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T0yjTk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T0yjTk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368194376" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 06:42:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/massive sql injection">massive sql injection</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site sql">site sql</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/tactic">tactic</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368194376/compromised-cpanel-accounts-for-sale.html">Compromised Cpanel Accounts For Sale</source>
    </item>
    <item>
      <title><![CDATA[Great Trend Micro article on Understanding Malware]]></title>
      <link>http://securityratty.com/article/a1e037e7a2efc121e989d6fb3ef16620</link>
      <guid>http://securityratty.com/article/a1e037e7a2efc121e989d6fb3ef16620</guid>
      <description><![CDATA[Reading this article will be worth your time. Cyber criminals are constantly coming up with new angles to get you to become infected with their Malware


clipped from newsletters.trendmicro.com
...]]></description>
      <content:encoded><![CDATA[<div > Reading this article will be worth your time.<br/>Cyber criminals are constantly coming up with new angles to get you to become infected with their Malware. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/95783F43-2539-4DAF-B269-4A4A74FAA8A1/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/d3bb0194-f21e-4917-ac72-c7e66c9de51f/95783F43-2539-4DAF-B269-4A4A74FAA8A1/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL" href="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL" style="font-size: 11px;">newsletters.trendmicro.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL --></p>
<table background="undefined" bgcolor="">
<tr><TD valign="top" colspan="2">Malicious URLs: Ticket to Malware</TD></tr>
</table>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_TBTB_.40ev.2e_0okLHm_eHgKlJHiL --><DIV><br />
To better understand malicious URLs, it helps to divide them into two broad categories: 1) URLs that use social engineering to initially entice users to click on them, and 2) techniques that do not involve social engineering, but instead employ various technological means. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/95783F43-2539-4DAF-B269-4A4A74FAA8A1/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 11:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/urls">urls</category>
      <category domain="http://securityratty.com/tag/malicious urls">malicious urls</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/involve social">involve social</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/entice users">entice users</category>
      <category domain="http://securityratty.com/tag/cyber criminals">cyber criminals</category>
      <category domain="http://securityratty.com/tag/broad categories">broad categories</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=542">Great Trend Micro article on Understanding Malware</source>
    </item>
    <item>
      <title><![CDATA[Indictments Against Largest ID Theft Ring Ever]]></title>
      <link>http://securityratty.com/article/159412d8049db4c0dd6a8e114a645515</link>
      <guid>http://securityratty.com/article/159412d8049db4c0dd6a8e114a645515</guid>
      <description><![CDATA[It was really big news yesterday , but I don't think it's that much of a big deal. These crimes are still easy to commit and it's still too hard to catch the criminals. Catching one gang, even a large...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/05/AR2008080501859.html?hpid=moreheadlines">It</a> <a href="http://money.cnn.com/2008/08/05/news/companies/card_fraud/?postversion=2008080604">was</a> <a href="http://technology.timesonline.co.uk/tol/news/world/us_and_americas/article4468114.ece">really</a> <a href="http://www.iht.com/articles/ap/2008/08/06/business/NA-US-Retailer-Fraud-Indictment.php">big</a> <a href="http://www.theregister.co.uk/2008/08/06/id_fraud_hacking_case/">news</a> <a href="http://ap.google.com/article/ALeqM5hlC-7Qgf2_9ytmu5kKBpnEf5XzeQD92D20KG0">yesterday</a>, but I don't think it's that much of a big deal.  These crimes are still easy to commit and it's still too hard to catch the criminals.  Catching one gang, even a large one, isn't going to make us any safer.</p>

<p>If we want to <a href="http://www.schneier.com/blog/archives/2005/04/mitigating_iden.html">mitigate identity theft</a>, we have to make it harder for people to get credit, make transactions, and generally do financial business remotely:</p>

<blockquote>The crime involves two very separate issues. The first is the privacy of personal data. Personal privacy is important for many reasons, one of which is impersonation and fraud. As more information about us is collected, correlated, and sold, it becomes easier for criminals to get their hands on the data they need to commit fraud. This is what's been in the news recently: ChoicePoint, LexisNexis, Bank of America, and so on. But data privacy is more than just fraud. Whether it is the books we take out of the library, the websites we visit, or the contents of our text messages, most of us have personal data on third-party computers that we don't want made public. The posting of Paris Hilton's phone book on the Internet is a celebrity example of this.

<p>The second issue is the ease with which a criminal can use personal data to commit fraud. It doesn't take much personal information to apply for a credit card in someone else's name. It doesn't take much to submit fraudulent bank transactions in someone else's name. It's surprisingly easy to get an identification card in someone else's name. Our current culture, where identity is verified simply and sloppily, makes it easier for a criminal to impersonate his victim.</p>

<p>Proposed fixes tend to concentrate on the first issue -- making personal data harder to steal -- whereas the real problem is the second. If we're ever going to manage the risks and effects of electronic impersonation, we must concentrate on preventing and detecting fraudulent transactions.</blockquote></p>

<p>I am, however, impressed that we managed to pull together the police forces from several countries to prosecute this case.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=DF8G3K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=DF8G3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aICGEK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aICGEK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 08:45:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data harder">personal data harder</category>
      <category domain="http://securityratty.com/tag/harder">harder</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/commit fraud">commit fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/commit">commit</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/personal privacy">personal privacy</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/indictments_aga.html">Indictments Against Largest ID Theft Ring Ever</source>
    </item>
    <item>
      <title><![CDATA[Eight Steps to Responsible Surfing]]></title>
      <link>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</link>
      <guid>http://securityratty.com/article/a72ad36f246a9ff490930a87868f7ede</guid>
      <description><![CDATA[Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of...]]></description>
      <content:encoded><![CDATA[<div><strong></strong>Web threats and attacks will continue to evolve, but surfers can protect themselves against the majority of malicious code by following eight different steps. To provide the greatest degree of security, surfers cannot rely entirely on technology, and should also address the behavioral issues that are most likely to create risky situations.</div>
<p><strong>Changing Behavior</strong></p>
<div>The safest way to deal with a danger is avoidance. By surfing safely and adapting offline sensibilities online, surfers can greatly reduce their danger of exposure to malware.</div>
<p><strong>1. Educate yourself.</strong><br />
At least every 6 to 12 months, surfers should browse the educational information provided by their operating system and security vendors and subscribe to any security-related newsletters they might offer. According to David Perry, familiarity with the latest threats, dangers, and recommended safety tips will allow surfers to make safe choices. &#8220;Until you know what&#8217;s out there, you&#8217;re just flying blind. Without an education, you&#8217;re wide open&#8221;.<br />
<strong>2. Avoid suspect sites.</strong><br />
While criminals can infect even mainstream Web sites, sites such as gambling sites, adult Internet sites, and illegal file-sharing sites are far more likely to carry malicious code. Web sites that offer &#8220;something for nothing&#8221; frequently recoup their losses by infecting visitors&#8217; PCs.<br />
<strong>3. Lose Your Comfort Zone.</strong></p>
<div>Web surfers should migrate their offline precautions to their online experience. By beginning with an attitude of healthy skepticism and only doing business with trusted Web sites, surfers can bypass a good deal of risk.</div>
<p><strong>Recommended Technology</strong></p>
<div>Despite the best precautions, every user will encounter Web-based malware. While no technology can guarantee protection against all attacks, a combination of preventive technologies provides the most comprehensive protection possible.</div>
<p><strong>4. Use an updated virus scanning suite.</strong><br />
The most important component of any threat mitigation system is a virus scanning suite. In addition to detecting and removing known viruses and malware, modern virus scanning suites provide additional protections against new attacks by disabling their known protocols. For example, Trend Micro™ Internet Security encrypts keyboard traffic, protecting personal data from keyboard logging programs that might go unnoticed. Users should update their scanner and virus definitions as frequently as possible to ensure the best possible coverage.<br />
<strong>5. Upgrade your OS and browser.</strong><br />
In addition to offering more features, Microsoft&#8217;s Internet Explorer version 7 and the latest Mozilla Firefox are both substantially more secure than previous-generation browsers. Users of older browsers should upgrade immediately to take advantage of increased security. Similarly, Windows Vista and Mac OS X are more secure than their predecessors, and users of older operating systems should consider upgrading, as well.<br />
<strong>6. Disable scripting and &#8220;widgets.&#8221;</strong><br />
Many Web-based attacks use various scripting languages to run infectious programs in a browser or use downloadable &#8220;widgets&#8221; to execute infections locally. By disabling scripting and avoiding downloadable widgets wherever possible, surfers disable these common attack vectors.<br />
<strong>7. Rate your Web pages.</strong><br />
Some available services rate the risk of Web pages in search results, allowing surfers to avoid unwanted content and hidden threats before viewing the pages. Rating applications (e.g., Trend Micro TrendProtect™) consume few system resources and run unobtrusively, so they are suitable for any Web-enabled personal computer.<br />
<strong>8. Ask your provider.</strong><br />
Commerce companies, banks, and credit card associations are all interested in computer security, and many offer additional features. For example, Visa&#8217;s Verified By Visa program requires cardholders to enter a second password to identify themselves during a transaction, while businesses in Poland require cell-phone confirmation of credit card purchases. While nothing will be 100 percent effective, any additional security measure provided by a trusted source will increase protection, and surfers should adopt as many as possible.</p>
<p>This article provided for your reading pleasure by Trend Micro.</p>
]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 20:30:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mainstream web sites">mainstream web sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/adult internet sites">adult internet sites</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web surfers">web surfers</category>
      <category domain="http://securityratty.com/tag/surfers">surfers</category>
      <category domain="http://securityratty.com/tag/surfers disable">surfers disable</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=536">Eight Steps to Responsible Surfing</source>
    </item>
    <item>
      <title><![CDATA[Smackdown on data criminals]]></title>
      <link>http://securityratty.com/article/2fb6d43eeb3824a910e01d61357c7f4a</link>
      <guid>http://securityratty.com/article/2fb6d43eeb3824a910e01d61357c7f4a</guid>
      <description><![CDATA[The long arm of the law finally flexed in a major indictment of criminals who were charged with hacking and stealing credit cards from major retailers

Eleven folks were charged with the crimes...]]></description>
      <content:encoded><![CDATA[The long arm of the law finally flexed in a <a href="http://www.marketwatch.com/news/story/retail-hacking-ring-charged-stealing/story.aspx?guid=%7B0AD56640-FAC5-4DF4-8729-A0F5989438ED%7D&amp;dist=hppr">major indictment of criminals </a>who were charged with hacking and stealing credit cards from major retailers.<br /><br />Eleven folks were charged with the crimes ranging from conspiracy, computer intrusion, fraud and identity theft.<br /><br />Interesting nuggets from the report:<br /><ul><li>They hacked nine major U.S. retailers, stole and sold more than 40 million credit and debit card numbers...</li><li>Apparently this is the single largest and most complex identity theft case ever charged in this country</li></ul>"<span style="font-style: italic;">While technology has made our lives much easier it has also created new vulnerabilities. This case clearly shows how strokes on a keyboard with a criminal purpose can have costly results. Consumers, companies and governments from around the world must further develop ways to protect our sensitive personal and business information and detect those, whether here or abroad, that conspire to exploit technology for criminal gain,</span>" said U.S. Attorney Michael J. Sullivan.<br /><br />I agree with the US Attorney - we need better ways to prevent such hacking. But one point is clear again in this case - those who hack work for increasingly sophisticated criminal enterprises and will deploy significant resources to steal as long as the returns are worth it.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=3AbsmK"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=3AbsmK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=Eoj8uk"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=Eoj8uk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=7t5n4K"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=7t5n4K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/356757053" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 17:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/major">major</category>
      <category domain="http://securityratty.com/tag/major indictment">major indictment</category>
      <category domain="http://securityratty.com/tag/complex identity theft">complex identity theft</category>
      <category domain="http://securityratty.com/tag/retailers">retailers</category>
      <category domain="http://securityratty.com/tag/major retailers">major retailers</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/attorney michael">attorney michael</category>
      <category domain="http://securityratty.com/tag/deploy significant resources">deploy significant resources</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/356757053/smackdown-on-data-criminals.html">Smackdown on data criminals</source>
    </item>
    <item>
      <title><![CDATA[Italians Use Soldiers to Prevent Crime]]></title>
      <link>http://securityratty.com/article/c78f1c770359cb273d03943d7dec2ab0</link>
      <guid>http://securityratty.com/article/c78f1c770359cb273d03943d7dec2ab0</guid>
      <description><![CDATA[Interesting : Soldiers were deployed throughout Italy on Monday to embassies, subway and railway stations, as part of broader government measures to fight violent crime here for which illegal...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/05/world/europe/05italy.html">Interesting</a>:</p>

<blockquote>Soldiers were deployed throughout Italy on Monday to embassies, subway and railway stations, as part of broader government measures to fight violent crime here for which illegal immigrants are broadly blamed.

<p>[...]</p>

<p>The conservative government of Silvio Berlusconi won elections in April while promising to crack down on petty crime and illegal immigrants. The new patrols of soldiers, who are not empowered to make arrests, do not seem aimed only at illegal immigrants, though the patrols were deployed to centers where illegal immigrants are housed. </p>

<p>“Security is something concrete,” Mr. La Russa said on Monday. The troops, he said, will be a “deterrent to criminals.”</blockquote></p>

<p>That reminds me of one of my favorite logical fallacies: "We must do something.  This is something. Therefore, we must do it."  It does seem largely to be a demonstration of "doing something" by the Berlusconi government.  The legitimate police, of course, think it's a terrible idea.</p>

<blockquote>“You need to be specially trained to carry out some kinds of controls,” Nicola Tanzi, the secretary of a trade union that represents Italian police officers. “Soldiers just aren’t qualified.”

<p>He also questioned whether the $93.6 million that will be spent for the extra deployment, called Operation Safe Streets, might not have been better used to increase the budgets for Italy’s police and military.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lUII6K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lUII6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lLsCCK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lLsCCK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 02:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/illegal immigrants">illegal immigrants</category>
      <category domain="http://securityratty.com/tag/soldiers">soldiers</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/broader government measures">broader government measures</category>
      <category domain="http://securityratty.com/tag/italys police">italys police</category>
      <category domain="http://securityratty.com/tag/favorite logical fallacies">favorite logical fallacies</category>
      <category domain="http://securityratty.com/tag/operation safe streets">operation safe streets</category>
      <category domain="http://securityratty.com/tag/fight violent crime">fight violent crime</category>
      <category domain="http://securityratty.com/tag/silvio berlusconi">silvio berlusconi</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/italians_use_so.html">Italians Use Soldiers to Prevent Crime</source>
    </item>
  </channel>
</rss>
