<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cryptic]]></title>
    <link>http://securityratty.com/tag/cryptic</link>
    <description></description>
    <pubDate>Wed, 05 Mar 2008 05:19:46 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Red Hat Releases Critical OpenSSH Update After Detection Of Server Intrusion]]></title>
      <link>http://securityratty.com/article/9f3e955ac8d3e973bc65ce6f28510f3a</link>
      <guid>http://securityratty.com/article/9f3e955ac8d3e973bc65ce6f28510f3a</guid>
      <description><![CDATA[More than a week after a cryptic note hinted at a security breach at Fedora, the open-source group has finally agreed that two separate server intrusions compromised the security of Red Hats OpenSSH...]]></description>
      <content:encoded><![CDATA[More than a week after a cryptic note hinted at a security breach at Fedora, the open-source group has finally agreed that two separate server intrusions compromised the security of Red Hat’s OpenSSH packages. Red Hat has warned that hackers were able to commandeer its systems and tamper with code - but said that since [...]]]></content:encoded>
      <pubDate>Sun, 24 Aug 2008 12:32:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/red hat">red hat</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/server intrusions">server intrusions</category>
      <category domain="http://securityratty.com/tag/cryptic note">cryptic note</category>
      <category domain="http://securityratty.com/tag/open-source">open-source</category>
      <category domain="http://securityratty.com/tag/fedora">fedora</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/tamper">tamper</category>
      <source url="http://cyberinsecure.com/red-hat-releases-critical-openssh-update-after-detection-of-server-intrusion/">Red Hat Releases Critical OpenSSH Update After Detection Of Server Intrusion</source>
    </item>
    <item>
      <title><![CDATA[Cryptic Reading]]></title>
      <link>http://securityratty.com/article/1074fa4a081373bca809a4c54a416558</link>
      <guid>http://securityratty.com/article/1074fa4a081373bca809a4c54a416558</guid>
      <description><![CDATA[Frank Hayes reports that there's much for IT to learn from a study of the government's failure to implement a data encryption...]]></description>
      <content:encoded><![CDATA[Frank Hayes reports that there's much for IT to learn from a study of the government's failure to implement a data encryption mandate.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=bD85uZ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=bD85uZ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/354967803" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 00:28:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/frank hayes reports">frank hayes reports</category>
      <category domain="http://securityratty.com/tag/data encryption">data encryption</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/implement">implement</category>
      <category domain="http://securityratty.com/tag/study">study</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/354967803/article.do">Cryptic Reading</source>
    </item>
    <item>
      <title><![CDATA[When do you have an obligation to go public?]]></title>
      <link>http://securityratty.com/article/f062c79e169ca6db2fee6c28a0d75894</link>
      <guid>http://securityratty.com/article/f062c79e169ca6db2fee6c28a0d75894</guid>
      <description><![CDATA[No, not IPO public, but public about disclosing employer secrets which could provide a risk to the public. My friend Martin McKeay has written an article over the recent firing of an employee of TJX...]]></description>
      <content:encoded><![CDATA[<p>No, not IPO public, but public about disclosing employer secrets which could provide a risk to the public. My friend Martin McKeay has <a href="http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/">written an article</a> over the recent firing of an employee of TJX for disclosing in a public forum continued poor security practices by TJX. The same TJX I might add that as a result of slipshod security practices caused 100s of thousands of dollars, if not millions of dollars in bank fraud to occur.<br><br>Many have categorized CrYpTiC_MauleR, the employee who disclosed the information on hackers.org, as a "whistleblower". The term <a href="http://en.wikipedia.org/wiki/Whistleblower">whistleblower</a> is a term of art and in many circles will invoke some special immunity for the person who disclosed the confidential information. However, usually the disclosure of this information is made to a person or entity with the power or at least willingness to take corrective action. In this case, I think that is the missing pre-requisite. Just disclosing this information on a public message board does not meet the burden of defining this as whistleblowing. I think Martin is right on there. He says CrYpTiC (If I can call him that), was not a whistleblower in the strictest sense of the word and is not due any protection. He is just another person who violated his employment terms and his termination by TJX was perfectly justified. Let me say that I don't disagree with Martin about TJX having the right to fire CrYpTiC. They certainly do.<br><br>I have a problem with Martin when says that CrYpTiC should have done what he has done and that is keep your mouth shut and move on to the next opportunity. I think depending on the level of wrongdoing, not only is that wrong, but by willfully withholding certain information from the authorities it could make you guilty as an accomplice! Think about it Martin, if you knew your employer was committing a crime and you just quit your job rather than report that crime, you are an accomplice. When does the responsibility for the general good, outweigh your obligation to your employer. Is sticking your head in the sand and moving on while letting illegal or irresponsible behavior go on the right posture? I say not.<br><br>I think CrYpTiC felt strong enough about what TJX was doing was wrong that he posted it publicly. Though he did it anonymously and did not think it would be traced back to him, he felt strong enough that what TJX was doing was wrong and he wanted the world to know. When he made that decision, he also made the decision that letting the world know the truth was more important than his job at TJX. I am sure potential future victims of TJX fraud that will now be spared that loss would thank him for it. <br><br>Martin, there comes a time where keeping your mouth shut and moving along does not cut it. You have a duty to alert the proper authorities for the greater good of the public. The question is when does your duty to disclose surpass your duty to keep your employers information private? I think that is a personal question that all of us have to answer ourselves. Clearly criminal activity should be disclosed, otherwise you risk criminal exposure. Beyond that it is a judgment call. But saying not to disclose and just move on is appeasement at its worst.<br><br>The real question is why doesn't the PCI council or the government have a forum for people like CrYpTiC to go to in the future. That is what is needed!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=x0xPXI"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=x0xPXI" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TGuyAH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TGuyAH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Lfj0OH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Lfj0OH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=rF05qH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=rF05qH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZvarnH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZvarnH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aFO4Kh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aFO4Kh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CuqYoh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CuqYoh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/300938518" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 29 May 2008 17:13:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/public forum">public forum</category>
      <category domain="http://securityratty.com/tag/tjx">tjx</category>
      <category domain="http://securityratty.com/tag/tjx fraud">tjx fraud</category>
      <category domain="http://securityratty.com/tag/martin">martin</category>
      <category domain="http://securityratty.com/tag/cryptic">cryptic</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/cryptic mauler">cryptic mauler</category>
      <category domain="http://securityratty.com/tag/ipo public">ipo public</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/300938518/when-do-you-hav.html">When do you have an obligation to go public?</source>
    </item>
    <item>
      <title><![CDATA[Data Loss Prevention: Where Do We Go From Here?]]></title>
      <link>http://securityratty.com/article/4869467e293d1a8c11071dd7294dbc38</link>
      <guid>http://securityratty.com/article/4869467e293d1a8c11071dd7294dbc38</guid>
      <description><![CDATA[DLP is fast becoming one of the most overused yet misunderstood acronyms in an industry known for its cryptic abbreviations. The popular label for data loss prevention is appearing on a puzzling...]]></description>
      <content:encoded><![CDATA[DLP is fast becoming one of the most overused yet misunderstood acronyms in an industry known for its cryptic abbreviations. The popular label for data loss prevention is appearing on a puzzling varie...]]></content:encoded>
      <pubDate>Mon, 31 Mar 2008 09:43:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/popular label">popular label</category>
      <category domain="http://securityratty.com/tag/misunderstood acronyms">misunderstood acronyms</category>
      <category domain="http://securityratty.com/tag/cryptic abbreviations">cryptic abbreviations</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/varie">varie</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <source url="http://www.net-security.org/article.php?id=1123">Data Loss Prevention: Where Do We Go From Here?</source>
    </item>
    <item>
      <title><![CDATA[Rogue RBN Software Pushed Through Blackhat SEO]]></title>
      <link>http://securityratty.com/article/fa04cd3187b13dcd40d0d45f37c36901</link>
      <guid>http://securityratty.com/article/fa04cd3187b13dcd40d0d45f37c36901</guid>
      <description><![CDATA[On numerous occasions in the past, I emphasized on the malicious attacker Keep it Simple Stupid (KISS) approach for anything starting from Rock Phishing, to maintaining a huge live exploits domains...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R86jK8HWvII/AAAAAAAABbI/0pPU2tUPTQY/s1600-h/KISS_RBN_iframe_SEO.jpg"><img id="BLOGGER_PHOTO_ID_5174252430226275458" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R86jK8HWvII/AAAAAAAABbI/0pPU2tUPTQY/s200/KISS_RBN_iframe_SEO.jpg" border="0" /></a>On numerous occasions in the past, I emphasized on <a href="http://ddanchev.blogspot.com/2007/09/popular-web-malware-exploitation.html">the malicious attacker</a> Keep it Simple Stupid (KISS) approach for anything starting from Rock Phishing, to maintaining a huge live exploits domains portfolio hosted on a single IP. This is yet another example of the KISS strategy uncovering another huge IFRAME campaign, again taking advantage of locally cached pages generated upon searching for a particular word, and the IFRAME itself. In the previous example for instance, we had an second ongoing IFRAME campaign with just 4 pages injected with <strong>89.149.243.201</strong>, however, what Keep it Simple Stupid really means in this case is that the next IP in their netblock <strong>89.149.243.202</strong> is currently getting injected at many other sites as well. The difference between the previous campaign and this one, is that <a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html">the previous one was targeting just two high page rank-ed sites</a>, while in the second one, the malicious parties pushing <a href="http://en.wikipedia.org/wiki/Russian_Business_Network">RBN's</a> rogue XP AntiVirus are relying on a much more diverse set of domains loading the IFRAME. One factor remains the same, both campaigns continue pushing the rogue XP AntiVirus. XP AntiVirus's pitch, note the downloads success rate mentioned and how they forgot to change the template used in the campaign by putting the rogue's name :<br /><br /><a href="http://bp0.blogger.com/_wICHhTiQmrA/R86mqsHWvJI/AAAAAAAABbQ/y_ggYqg2J6Q/s1600-h/rogue_XP_antivirus_app.jpg"><img id="BLOGGER_PHOTO_ID_5174256274222005394" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R86mqsHWvJI/AAAAAAAABbQ/y_ggYqg2J6Q/s200/rogue_XP_antivirus_app.jpg" border="0" /></a>"<em><strong>XP antivirus has been downloaded over 4 Million times; with a 20,000 more downloads every week. Millions of people worldwide use Spyware Doctor to protect their identity and PC security.</strong> XP antivirus has consistently been awarded Editors' Choice, by leading PC magazines and testing laboratories around the world, including United States, United Kingdom, Germany and Australia. All current versions of XP antivirus have won Editors' Choice awards from Secure Home PC Magazine in United States. XP antivirus is advanced technology designed specially for people, not experts. It is automatically configured out of the box to give you optimal protection with limited interaction so all you need to do is install it for immediate and ongoing protection. XP antivirus's advanced RealOnGuard technology only alerts users on a true Spyware detection. This is significant because you should not be interrupted by cryptic questions every time you install software, add a site to your favorites or change your PC settings.</em>"<br /><br />Upon visiting <strong>89.149.243.202/t</strong> and <strong>89.149.243.202/a</strong> we get forwarded to <strong>bestsexworld.info/soft.php?aid=0064&amp;d=3&amp;product=XPA</strong> (72.232.224.154) and from there to <strong>xpantivirus2008.com</strong> (69.50.173.10). There're in fact several other domains currently promoting this as well : <strong>xpantiviruspro.com</strong> (69.50.183.50); <strong>xpdownloadings.com</strong> (69.50.183.50); <strong>xpantivirus.com</strong> (216.255.180.58), as well as the following : <strong>hotantivirus.info</strong> (74.86.81.80); <strong>easyantivirus.info</strong> (74.86.81.80); <strong>a2zantivirus.com</strong> (74.86.81.80). The downloader's detection rate :<br /><br /><strong>Scanner results</strong> : 17% Scanner(6/36) found malware!<br /><strong>Time</strong> : 2008/03/05 13:57:48 (EET)<br /><strong>File Size</strong> : 47104 byte<br /><strong>MD5</strong> : 2102cb53606f535ca8132c3324953596<br /><strong>SHA1</strong> : 0756f530e782c3d2e85a8186e052b722b017f1ea<br />AntiVir - TR/Crypt.ULPM.Gen<br />Fortinet - Suspicious<br />Microsoft - Trojan:Win32/Vxidl.gen!B(Suspicious)<br />Panda - Suspicious file<br />Prevx - TROJAN.DOWNLOADER.GEN<br />Sophos - Mal/HckPk-A<br /><br />Smells like RBN's used InterCage and ATRIVO netblocks from routers away.<br /><br /><strong>Related RBN coverage:</strong><br /><a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">RBN's Phishing Activities</a><br /><a href="http://ddanchev.blogspot.com/2008/02/rbns-malware-puppets-need-their-master.html">RBN's Puppets Need Their Master</a><br /><a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html">RBN's Fake Account Suspended Notices</a><br /><a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software</a><br /><a href="http://ddanchev.blogspot.com/2007/11/go-to-sleep-go-to-sleep-my-little-rbn.html">Go to Sleep, Go to Sleep my Little RBN</a><br /><a href="http://ddanchev.blogspot.com/2007/11/exposing-russian-business-network.html">Exposing the Russian Business Network</a><br /><a href="http://ddanchev.blogspot.com/2007/11/detecting-and-blocking-russian-business.html">Detecting the Blocking the Russian Business Network</a><br /><a href="http://ddanchev.blogspot.com/2007/10/over-100-malwares-hosted-on-single-rbn.html">Over 100 Malwares Hosted on a Single RBN IP</a><br /><a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br /><a href="http://ddanchev.blogspot.com/2007/10/russian-business-network.html">The Russian Business Network</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZoRBw0F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZoRBw0F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p8htseF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p8htseF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XyQB1If"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XyQB1If" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fuPuoqf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fuPuoqf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QiYrtkF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QiYrtkF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dRLqujF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dRLqujF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H6YxYkf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H6YxYkf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/246149123" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 05 Mar 2008 05:19:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rbn">rbn</category>
      <category domain="http://securityratty.com/tag/huge iframe campaign">huge iframe campaign</category>
      <category domain="http://securityratty.com/tag/iframe campaign">iframe campaign</category>
      <category domain="http://securityratty.com/tag/iframe">iframe</category>
      <category domain="http://securityratty.com/tag/rbn coverage">rbn coverage</category>
      <category domain="http://securityratty.com/tag/single rbn">single rbn</category>
      <category domain="http://securityratty.com/tag/russian business network">russian business network</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/246149123/rogue-rbn-software-pushed-through.html">Rogue RBN Software Pushed Through Blackhat SEO</source>
    </item>
  </channel>
</rss>
