<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cyber-security]]></title>
    <link>http://securityratty.com/tag/cyber-security</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 09:45:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Spies Launch 'Cyber-Behavior' Investigation]]></title>
      <link>http://securityratty.com/article/4ff1a0adafe8d22b55a5aaa0485d6764</link>
      <guid>http://securityratty.com/article/4ff1a0adafe8d22b55a5aaa0485d6764</guid>
      <description><![CDATA[In effort to get a handle on wannabe spies' cyber behaviors, the Office of the Director of National Intelligence hands out $800,000 to researchers to figure out whether hopping on World of Warcraft or...]]></description>
      <content:encoded><![CDATA[In effort to get a handle on wannabe spies' cyber behaviors, the Office of the Director of National Intelligence hands out $800,000 to researchers to figure out whether hopping on World of Warcraft or Facebook "suggests an unwillingness to abide by rules."<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=dfbf5c2514aa18d00019db7b46140f86" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=dfbf5c2514aa18d00019db7b46140f86" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8bgpM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8bgpM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=NDBDm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=NDBDm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zMjfm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zMjfm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=KmjwM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=KmjwM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=sJ9LM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=sJ9LM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=pKatm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=pKatm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=skB7m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=skB7m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xeENM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xeENM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/418801617" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/418801620" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 11:27:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/national intelligence hands">national intelligence hands</category>
      <category domain="http://securityratty.com/tag/cyber behaviors">cyber behaviors</category>
      <category domain="http://securityratty.com/tag/wannabe spies">wannabe spies</category>
      <category domain="http://securityratty.com/tag/figure">figure</category>
      <category domain="http://securityratty.com/tag/suggests">suggests</category>
      <category domain="http://securityratty.com/tag/effort">effort</category>
      <category domain="http://securityratty.com/tag/warcraft">warcraft</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/418801620/spies-launch-cy.html">Spies Launch 'Cyber-Behavior' Investigation</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-10-09 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/3f5041f2ca487cf209923936d4e1ac1b</link>
      <guid>http://securityratty.com/article/3f5041f2ca487cf209923936d4e1ac1b</guid>
      <description><![CDATA[Policies vs. Plans vs. Procedures vs. Standards | securosis.com
Cyber Attack Data-Sharing Is Lacking, Congress Told -...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securosis.com/2008/10/07/policies-vs-plans-vs-procedures-vs-standards/">Policies vs. Plans vs. Procedures vs. Standards | securosis.com</a></li>
<li><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/18/AR2008091803730.html">Cyber Attack Data-Sharing Is Lacking, Congress Told - washingtonpost.com</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/416458916" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cyber attack">cyber attack</category>
      <category domain="http://securityratty.com/tag/procedures">procedures</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/securosis">securosis</category>
      <category domain="http://securityratty.com/tag/policies">policies</category>
      <category domain="http://securityratty.com/tag/washingtonpost">washingtonpost</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/416458916/anton18">Links for 2008-10-09 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Air Force Will Fight Online, Without 'Cyber Command']]></title>
      <link>http://securityratty.com/article/8e3f2b1858422281bbe1c72a42d6efb0</link>
      <guid>http://securityratty.com/article/8e3f2b1858422281bbe1c72a42d6efb0</guid>
      <description><![CDATA[The Air Force is going ahead with plans to put together a force that will wage wars online. But it won't be a full-fledged Cyber Command as previously...]]></description>
      <content:encoded><![CDATA[The Air Force is going ahead with plans to put together a force that will wage wars online. But it won't be a full-fledged Cyber Command as previously advertised.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=1c9ee8172514f72305a38a81dba5d7e4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1c9ee8172514f72305a38a81dba5d7e4" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=GHEAM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=GHEAM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=S7pRm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=S7pRm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=1UzLm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=1UzLm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=diBRM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=diBRM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=eDhTM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=eDhTM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UahTm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UahTm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Yfprm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Yfprm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=piZeM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=piZeM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/414935546" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/414935549" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 11:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/air force">air force</category>
      <category domain="http://securityratty.com/tag/force">force</category>
      <category domain="http://securityratty.com/tag/cyber command">cyber command</category>
      <category domain="http://securityratty.com/tag/wage wars online">wage wars online</category>
      <category domain="http://securityratty.com/tag/ahead">ahead</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/previously">previously</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/414935549/air-force-will.html">Air Force Will Fight Online, Without 'Cyber Command'</source>
    </item>
    <item>
      <title><![CDATA[Federal Charges Filed Against Alleged Cyber Peeping Tom]]></title>
      <link>http://securityratty.com/article/86dd1b9c05f907fcb650cb7699f2de73</link>
      <guid>http://securityratty.com/article/86dd1b9c05f907fcb650cb7699f2de73</guid>
      <description><![CDATA[A college student who allegedly rigged a woman's laptop to snap nude photos through her webcam faces federal charges this week, and tops Threat Level's roundup of cybercrime in the federal...]]></description>
      <content:encoded><![CDATA[A college student who allegedly rigged a woman's laptop to snap nude photos through her webcam faces federal charges this week, and tops Threat Level's roundup of cybercrime in the federal courts.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5e743031c0cace49ee8f1950873fcf31" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5e743031c0cace49ee8f1950873fcf31" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=PgSIM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=PgSIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jjd9m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jjd9m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=pw8om"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=pw8om" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ohwMM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ohwMM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=QboLM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=QboLM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=MECHm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=MECHm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Dijbm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Dijbm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Php3M"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Php3M" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/410660103" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/410660104" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal charges">federal charges</category>
      <category domain="http://securityratty.com/tag/tops threat level">tops threat level</category>
      <category domain="http://securityratty.com/tag/snap nude photos">snap nude photos</category>
      <category domain="http://securityratty.com/tag/federal courts">federal courts</category>
      <category domain="http://securityratty.com/tag/college student">college student</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/roundup">roundup</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/410660104/fed-blotter-cha.html">Federal Charges Filed Against Alleged Cyber Peeping Tom</source>
    </item>
    <item>
      <title><![CDATA[The Commercialization of Anti Debugging Tactics in Malware]]></title>
      <link>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</link>
      <guid>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</guid>
      <description><![CDATA[Commoditization or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/J_vLiffz110/s1600-h/figure_multiple.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="128" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/bz624nz5JbE/s200-R/figure_multiple.jpg" width="200" /></a><a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">Commoditization</a> or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to detection rates of the crypted binary offered by a trusted online scanner that is NOT distributing the samples to the vendors? These are just some of the questions malware authors often ask themselves, while others distribute pirated copies of Code Virtualizer urging everyone to start taking advantage of commercial anti-reverse engineering tools to make their malware harder to analyze. Once again, just like we've seen before, a legitimate commercial application can come handy in the hands of the wrong people :<br />
<br />
"<i>Code Virtualizer will convert your original code (Intel x86 instructions) into Virtual Opcodes that will only be understood by an internal Virtual Machine. Those Virtual Opcodes and the Virtual Machine itself are unique for every protected application, avoiding a general attack over Code Virtualizer. Code Virtualizer can protect your sensitive code areas in any x32 and x64 native PE files (like executable files/EXEs, system services, DLLs , OCXs , ActiveX controls, screen savers and device drivers).</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/lB8WtKqycj4/s1600-h/cvprotopt.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="149" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/kgSYpWIHW2E/s200-R/cvprotopt.png" width="200" /></a><i>Code Virtualizer can generate multiple types of virtual machines with a different instruction set for each one. This means that a specific block of Intel x86 instructions can be converted into different instruction set for each machine, preventing an attacker from recognizing any generated virtual opcode after the transformation from x86 instructions. The following picture represents how a block of Intel x86 instructions is converted into different kinds of virtual opcodes, which could be emulated by different virtual machines.</i><br />
<br />
<i>When an attacker tries to decompile a block of code that was protected by Code Virtualizer, he will not find the original x86 instructions. Instead, he will find a completely new instruction set which is not recognized by him or any other special decompiler. This will force the attacker to go through the extremely hard work of identifying how each opcode is executed and how the specific virtual machine works for each protected application. Code Virtualizer totally obfuscates the execution of the virtual opcodes and the study of each unique virtual machine in order to prevent someone from studying how the virtual opcodes are executed.</i>"<br />
<br />
With Cyber-as-a-Service business model becoming increasingly common, the entire <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">quality assurance model in respect to malware</a> is slowly maturing from individual malware crypting propositions, where the seller of the service is basically taking advantage of a diverse set of public/private tools, into DIY web services offering crypting discounts on a volume basis, and perhaps most importantly - improving the customer's experience by letting him take advantage of the inventory of crypting tools and bypassing verification services. Within the tool's inventory are naturally lots of (pirated) commercial anti-reverse engineering tools.<br />
<br />
As we've seen before, whenever someone starts commercializing what used to be a self-selving process, others will either follow, or disintermediate their services by persistently releasing crypting tools for free in the wild. At the end of the day, it's all a matter of how serious they're about commercializing this market segment, and taking into consideration that a spamming vendor is offering malware crypting services "in between" the rest of the services in their portfolio, this underground cash cow is yet to prove itself in the long term.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJDSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJDSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QoCNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QoCNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e4uxl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e4uxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sXqbl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sXqbl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=khiOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=khiOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2cQ2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2cQ2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HiSTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HiSTl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406651187" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 12:55:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/machine">machine</category>
      <category domain="http://securityratty.com/tag/specific virtual machine">specific virtual machine</category>
      <category domain="http://securityratty.com/tag/internal virtual machine">internal virtual machine</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/sensitive code">sensitive code</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/unique virtual machine">unique virtual machine</category>
      <category domain="http://securityratty.com/tag/original code">original code</category>
      <category domain="http://securityratty.com/tag/code virtualizer">code virtualizer</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406651187/commercialization-of-anti-debugging.html">The Commercialization of Anti Debugging Tactics in Malware</source>
    </item>
    <item>
      <title><![CDATA[Merged Banks' Names Already Cyber-squatted]]></title>
      <link>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</link>
      <guid>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</guid>
      <description><![CDATA[Domain name speculators are already buying up names of recently merged banks , according to the BBC. In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman...]]></description>
      <content:encoded><![CDATA[<a href="http://news.bbc.co.uk/2/hi/technology/7621647.stm">Domain name speculators are already buying up names of recently merged banks</a>, according to the BBC.

In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman Brothers was failing and rumors circulated as to who might buy them, the names barclayslehman.com, hsbclehman.com, hsbclehmanbrothers.com and bofalehman.com were all reserved. The buyers are in the Netherlands and New York City, and one domain is registered anonymously.

The same phenomenon is occurring in the U.K., where speculation surrounding the merger of Lloyds TSB with HBOS led someone to buy lloydstsbhbos.com and hboslloydstsb.com.

Some of these domains include a notice that they are for sale. The person who bought bankofamericamerrilllynch.com went further, including a link to an eBay auction where the domain is for sale with a $1,500 reserve. About two days into the auction, no bids have been made. People who reserve domain names with clear trademarks in them routinely lose them in arbitration cases brought, under <a href="http://www.icann.org/en/udrp/#udrp">ICANN's Uniform Domain Name Dispute Resolution Policy</a>, by the trademark holders.
<p><a href="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/a"><img src="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/HSwU0TmTLAk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/reserve domain names">reserve domain names</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/uniform domain">uniform domain</category>
      <category domain="http://securityratty.com/tag/reserve">reserve</category>
      <category domain="http://securityratty.com/tag/names barclayslehman">names barclayslehman</category>
      <category domain="http://securityratty.com/tag/dispute resolution policy">dispute resolution policy</category>
      <category domain="http://securityratty.com/tag/auction">auction</category>
      <category domain="http://securityratty.com/tag/ebay auction">ebay auction</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/HSwU0TmTLAk/merged_banks_names_already_cybersquatted.html">Merged Banks' Names Already Cyber-squatted</source>
    </item>
    <item>
      <title><![CDATA[Bill allows victims of identity theft to obtain restitution]]></title>
      <link>http://securityratty.com/article/c1120bc034580fee43963351809a9f60</link>
      <guid>http://securityratty.com/article/c1120bc034580fee43963351809a9f60</guid>
      <description><![CDATA[Finally, criminals can be held responsible for the theft of our personal data


clipped from www.eweek.com

Congress Approves Computer Fraud Bill


The bill amends the federal criminal code to expand...]]></description>
      <content:encoded><![CDATA[<div > Finally, criminals can be held responsible for the theft of our personal data. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clip-to-blog/" title="clipmarks' clip-to-blog"><img src="http://content.clipmarks.com/blog_icon/a87ed7a1-2f8b-4e20-b5fb-29b24260d97c/49961837-3FD3-4E0A-9167-54A039DF9B94/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.eweek.com/c/a/Security/Congress-Approves-Computer-Fraud-Bill/" href="http://www.eweek.com/c/a/Security/Congress-Approves-Computer-Fraud-Bill/" style="font-size: 11px;">www.eweek.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.eweek.com/c/a/Security/Congress-Approves-Computer-Fraud-Bill/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Congress Approves Computer Fraud Bill</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.eweek.com/c/a/Security/Congress-Approves-Computer-Fraud-Bill/ --><P>The bill amends the federal criminal code to expand<br />
interstate and foreign jurisdiction for prosecution of computer fraud offenses<br />
and imposes criminal and civil forfeitures of property used to commit computer<br />
fraud offenses. In addition, the legislation makes it a felony to damage 10 or<br />
more protected computers used by or for the federal government or a financial<br />
institution.</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.eweek.com/c/a/Security/Congress-Approves-Computer-Fraud-Bill/ --><P>The legislation also expands the federal definition of<br />
cyber extortion to include a demand for money in relation to damage to a<br />
protected computer, where such damage was caused to facilitate the extortion.<br />
It also allows victims of identity theft to obtain restitution for time and<br />
money spent to restore credit and imposes a fine and imprisonment for<br />
installing spyware on a computer.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/49961837-3FD3-4E0A-9167-54A039DF9B94/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_170908112807"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908112807&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908112807&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=170908112807&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_170908112807" /></a></P>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 19:28:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer fraud offenses">computer fraud offenses</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <category domain="http://securityratty.com/tag/fraud offenses">fraud offenses</category>
      <category domain="http://securityratty.com/tag/obtain restitution">obtain restitution</category>
      <category domain="http://securityratty.com/tag/commit computer">commit computer</category>
      <category domain="http://securityratty.com/tag/imposes criminal">imposes criminal</category>
      <category domain="http://securityratty.com/tag/extortion">extortion</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=616">Bill allows victims of identity theft to obtain restitution</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kits are Faddish]]></title>
      <link>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</link>
      <guid>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</guid>
      <description><![CDATA[For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/u4h7TuozLDI/s1600-h/copycat_web_malware_exploitation_kit.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/H8HQ-QzSBfg/s200-R/copycat_web_malware_exploitation_kit.gif" /></a>For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained several moths later -- with all the related and royalty free updates coming with it, there are always the copycat malware kits like this one offered for $100.<br />
<br />
Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally <a href="http://blogs.zdnet.com/security/?p=1598">ignored the possibility of their kits leaking to the general public</a>, or copies of the kits ending up as a bargain in particular underground deal where the once highly exclusive kit was offered as a bonus.<br />
<br />
"Me too" web malware kits were a faddish way to enjoy the popularity of web malware kits like MPack and Icepack and try to cash in on that popularity by coming up average kits lacking any significant differentiation factors in the process. But just like the original and proprietary kits, whose authors didn't envision the long term growth strategy of integrating different services into their propositions or the kits themselves, the authors of copycat malware kits didn't bother considering the lack of long-term growth strategy for their releases. Branding in respect to releasing a Firepack malware kit to compete with Icepack which was originally released to compete with Mpack, has failed to achieve the desired results as well.<br />
<br />
And with malware kits now a commodity, and underground vendors excelling in a particular practice with the long term objective to vertically integrate in their area of expertise -- think spammers offering localization of messages into different languages and segmented email databases from a specific country -- would we witness the emergence of <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">managed cybercrime services</a> charging a premium for providing fresh dumps of credit card numbers, PayPal, Ebay accounts or whatever the buyer is requesting?<br />
<br />
That may well be the case in the long term.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jUilFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jUilFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LiAKxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LiAKxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GnpH1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GnpH1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bjjwel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bjjwel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NAlZrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NAlZrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybk3ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybk3ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0j6X0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0j6X0l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382290326" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/copycat malware kits">copycat malware kits</category>
      <category domain="http://securityratty.com/tag/proprietary kits">proprietary kits</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/long-term growth strategy">long-term growth strategy</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382290326/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</source>
    </item>
    <item>
      <title><![CDATA[Watch Out! Firing IT Workers Can Cost You]]></title>
      <link>http://securityratty.com/article/58e9222ea818b146a5e3f7452193a99b</link>
      <guid>http://securityratty.com/article/58e9222ea818b146a5e3f7452193a99b</guid>
      <description><![CDATA[When IT employees are dismissed, watch out! A new survey by Cyber-Ark Software, a provider of identity management products, reports that theft of sensitive information by disgruntled former insiders...]]></description>
      <content:encoded><![CDATA[When IT employees are dismissed, watch out! A new survey by Cyber-Ark Software, a provider of identity management products, reports that theft of sensitive information by disgruntled former insiders is out of control.]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity management products">identity management products</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/cyber-ark software">cyber-ark software</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/insiders">insiders</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/reports">reports</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <source url="http://www.networkworld.com/news/2008/082808-watch-out-firing-it-workers.html?fsrc=rss-security">Watch Out! Firing IT Workers Can Cost You</source>
    </item>
    <item>
      <title><![CDATA[Best Western Rebuts Claims of Massive Data Breach]]></title>
      <link>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</link>
      <guid>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</guid>
      <description><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global...]]></description>
      <content:encoded><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global network in the "the greatest cyber-heist in world history." Best Western says 10 people were affected at one hotel.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b4a67e5ea9cc98c6e9393c741fea0fdd" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b4a67e5ea9cc98c6e9393c741fea0fdd" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TLFKNK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TLFKNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rGFaWk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rGFaWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IwFkSk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IwFkSk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AmXXuK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AmXXuK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=Guh3jK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Guh3jK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IFYaBk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IFYaBk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=sOvMck"><img src="http://feeds.wired.com/~f/wired/politics/security?i=sOvMck" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qFUDqK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qFUDqK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/376205367" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/376205368" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/western">western</category>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/western international">western international</category>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/sunday herald newspaper">sunday herald newspaper</category>
      <category domain="http://securityratty.com/tag/global network">global network</category>
      <category domain="http://securityratty.com/tag/million customers">million customers</category>
      <category domain="http://securityratty.com/tag/world history">world history</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/376205368/DATA_BREACH_DISPUTE">Best Western Rebuts Claims of Massive Data Breach</source>
    </item>
  </channel>
</rss>
