<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: data-centric]]></title>
    <link>http://securityratty.com/tag/data-centric</link>
    <description></description>
    <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for September]]></title>
      <link>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</link>
      <guid>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</guid>
      <description><![CDATA[As usual, here's September's summary of all of my posts at Zero Day . You may also want to catch up and go through August's and July's summaries , next to adding my personal RSS feed or Zero Day's...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/Ktm1do-Wybs/s1600-h/zero_day_october.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/77K4rA4iDJo/s200-R/zero_day_october.png" /></a>As usual, here's September's summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a>. You may also want to catch up and go through <a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html">August's</a> and <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summaries</a>, next to adding <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal RSS feed</a> or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a> to your RSS reader.<br />
<br />
Notable article for September - <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1847">DoS vulnerability hits Google's Chrome, crashes with all tabs</a><br />
<b>02.</b> <a href="http://blogs.zdnet.com/security/?p=1852">Malware and spam attacks exploiting Picasa and ImageShack</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1908">Facebook introducing new security warning feature</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1911">Google downplays Chrome's carpet-bombing flaw</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1922">Targeted malware attack against U.S schools intercepted</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1926">The most "dangerous" celebrities to search for in 2008</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1935">Norwegian BitTorrent tracker under DDoS attack</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1939">Attacker: Hacking Sarah Palin's email was easy</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1958">Bill O'Reilly's web site hacked, attackers release personal details of users</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1964">India's government: At last, we've cracked Blackberry's encryption</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1975">Memory exhaustion DoS vulnerability hits Google's Chrome</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1983">44% of second hand mobile devices still contain sensitive data</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1986">Spammers attacking Microsoft's CAPTCHA -- again</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8t7TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8t7TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9ttSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9ttSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rNcm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rNcm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BtQ4m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BtQ4m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7SqTM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7SqTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZCYzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZCYzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Gu2Bm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Gu2Bm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413926169" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 06:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google downplays chrome">google downplays chrome</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/vendor launches">vendor launches</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/september">september</category>
      <category domain="http://securityratty.com/tag/norwegian bittorrent tracker">norwegian bittorrent tracker</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/hand mobile devices">hand mobile devices</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413926169/summarizing-zero-days-posts-for.html">Summarizing Zero Day's Posts for September</source>
    </item>
    <item>
      <title><![CDATA[Web Based Malware Emphasizes on Anti-Debugging Features]]></title>
      <link>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</link>
      <guid>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</guid>
      <description><![CDATA[Following the ongoing development of a particular web based malware, always comes handy in terms of assessing the commoditization of anti-debugging features within modern malware. With plain simple,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/fmDkcbMwPSs/s1600-h/web_based_malware_cc1_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/1HWDayNG6dU/s200-R/web_based_malware_cc1_.JPG" /></a>Following the ongoing development of a particular web based malware, always comes handy in terms of assessing <a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">the commoditization</a> of <a href="http://ddanchev.blogspot.com/2008/09/commercialization-of-anti-debugging.html">anti-debugging features</a> within modern malware. With plain simple, "managed binary crypting and firewall bypassing verification" on demand in February, to August's overall anti antivirus software mentality as a key differentiation factor of the malware.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/oRig4C4IWHo/s1600-h/web_based_malware_cc3_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/FyZQV_azx1o/s200-R/web_based_malware_cc3_.JPG" /></a>So what are they working on? Anti tracing and emulation protection, PeiD and PESniffer protection, as well as anti heuristic scanning with a simple junk data adding feature in order to maintain a smaller binary size.<i> <br />
</i><br />
Here's a translated description :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/vMxRy0XpiTc/s1600-h/web_based_malware_cc_new_version1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/WCAOc2P-dV8/s200-R/web_based_malware_cc_new_version1.jpg" /></a>"<i>- The binary works under admin and under normal user</i><br />
<i>- The binary is always run as the "current user"</i><br />
<i>- An unlimited number of bots can be loaded and integrated within the command and control, and with the geolocation feature, filters can be applied for a particular country</i><br />
<i>-After successful infection, the binary which is tested against popular firewall and proactive protection security ensures that the actions it takes and their order do not trigger protactive protection mechanisms in place</i><br />
<i>- binary file size is 25k, the size can be reduced once it's crypted<br />
</i><br />
<i></i> <br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/PD09GhFmXi4/s1600-h/web_based_malware_cc_new_version2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/6VE-Clw7bNk/s200-R/web_based_malware_cc_new_version2.jpg" /></a><i>- Doesn't take advantage of BITS protocol </i><br />
<i>- Doesn't allow an infected host to be infected twice</i><br />
<i>- Bypassing NAT and supporting "always-on" connections</i><br />
<i>- A simple, easy to configure web based admin panel</i>" <br />
<br />
What if the buyer doesn't care about the quality assurance practices applied? <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Managed lower AV detection and firewall bypassing service</a> comes into play.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W8uJM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W8uJM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ilgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ilgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZaTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZaTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=msyxm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=msyxm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YpECM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YpECM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1sBzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1sBzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pqSlm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pqSlm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413578893" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 22:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/binary file">binary file</category>
      <category domain="http://securityratty.com/tag/binary">binary</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/plain simple">plain simple</category>
      <category domain="http://securityratty.com/tag/anti">anti</category>
      <category domain="http://securityratty.com/tag/simple junk data">simple junk data</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413578893/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</source>
    </item>
    <item>
      <title><![CDATA[Symantec updates DLP endpoint, antispam gateway]]></title>
      <link>http://securityratty.com/article/c35ab87dd35bf0956806ae67828222e5</link>
      <guid>http://securityratty.com/article/c35ab87dd35bf0956806ae67828222e5</guid>
      <description><![CDATA[Symantec plans to release updated versions of its antispam gateway and data-loss-prevention...]]></description>
      <content:encoded><![CDATA[Symantec plans to release updated versions of its antispam gateway and data-loss-prevention agent.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/antispam gateway">antispam gateway</category>
      <category domain="http://securityratty.com/tag/symantec plans">symantec plans</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <category domain="http://securityratty.com/tag/agent">agent</category>
      <category domain="http://securityratty.com/tag/release">release</category>
      <source url="http://www.networkworld.com/news/2008/100708-symantec-dlp-antispam-updates.html?fsrc=rss-security">Symantec updates DLP endpoint, antispam gateway</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale]]></title>
      <link>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</link>
      <guid>http://securityratty.com/article/b7d7d76e0604b84cbe7c11b2c852ec6f</guid>
      <description><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records...]]></description>
      <content:encoded><![CDATA[In 2006, 17 million German customer records were stolen from T-Mobile, a mobile network operator headquartered in Bonn, Germany. T-Mobile has admitted the incident where stolen customer records included names, addresses, phone numbers, dates of birth and email addresses.
Silent about the data loss for more than two years, the company published its version of events [...]]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 07:44:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/email addresses">email addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/mobile network operator">mobile network operator</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/customer records">customer records</category>
      <category domain="http://securityratty.com/tag/birth">birth</category>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <source url="http://cyberinsecure.com/disk-containing-data-on-17-million-t-mobile-customers-missing-the-data-is-for-sale/">Disk Containing Data on 17 Million T-Mobile Customers Missing, The Data Is For Sale</source>
    </item>
    <item>
      <title><![CDATA[Is Google Using Chrome to Index Password Protected Web?]]></title>
      <link>http://securityratty.com/article/8a63a597e63a81e80a36c5703b5f3e7a</link>
      <guid>http://securityratty.com/article/8a63a597e63a81e80a36c5703b5f3e7a</guid>
      <description><![CDATA[An interesting theory we heard recently is that Google will use Chrome to index the password protected Web. Right now the Chrome Terms of Service prevents Google from indexing private data. But when...]]></description>
      <content:encoded><![CDATA[An interesting theory we heard recently is that Google will use Chrome to index the password protected Web. Right now the Chrome Terms of Service prevents Google from indexing private data. But when you consider that Chrome was initially presented as a browser for applications, instead of just web pages, this theory begins to make more sense.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 07:20:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/service prevents google">service prevents google</category>
      <category domain="http://securityratty.com/tag/chrome terms">chrome terms</category>
      <category domain="http://securityratty.com/tag/theory">theory</category>
      <category domain="http://securityratty.com/tag/theory begins">theory begins</category>
      <category domain="http://securityratty.com/tag/web pages">web pages</category>
      <category domain="http://securityratty.com/tag/index">index</category>
      <source url="http://digg.com/security/Is_Google_Using_Chrome_to_Index_Password_Protected_Web">Is Google Using Chrome to Index Password Protected Web?</source>
    </item>
    <item>
      <title><![CDATA[PCI Bans WEP SecurityStarting 2010]]></title>
      <link>http://securityratty.com/article/5f38b99c3f2e614c14cdba03311ea183</link>
      <guid>http://securityratty.com/article/5f38b99c3f2e614c14cdba03311ea183</guid>
      <description><![CDATA[Version 1.2 for the PCI Data Security Standard was released last week
One interesting outcome is that the insecure wireless WEP protocol will be banned but not until June 2010. Says Ars Technica...]]></description>
      <content:encoded><![CDATA[<p>Version 1.2 for the PCI Data Security Standard was released last week.</p>
<p>One interesting outcome is that the insecure wireless <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081003-credit-card-processors-finally-get-clue-will-ban-wep.html">WEP</a> protocol will be <a rel="nofollow" target="_blank" href="http://wifinetnews.com/archives/008474.html">banned</a>&#8230;but not until June 2010. Says <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081003-credit-card-processors-finally-get-clue-will-ban-wep.html">Ars Technica</a>:</p>
<blockquote><p>Although TJX has become the poster-child for consumer data theft over WiFi, it is (by far) not the only company to use insecure wireless technologies. Wireless security manufacturer AirDefense released a report in late 2007 saying that a quarter of the 4,748 retail access points it surveyed across the US had no security whatsoever, while another quarter only used WEP, &#8220;one of the weakest protocols for wireless data encryption.&#8221; Just under half (49 percent) of the surveyed hotspots used WiFi Protected Access (WPA) or WPA 2—much stronger encryption protocols than WEP.</p></blockquote>
<p>If you&#8217;re wondering about what other impacts will have, you might want to read through the <a rel="nofollow" target="_blank" href="https://www.pcisecuritystandards.org/security_standards/supporting_documents.shtml">PCI site</a> or sign up for the<a rel="nofollow" target="_blank" href="http://www.secureworks.com/research/webcasts/20081014-gen-www"> SecureWorks webcast </a>on October 14th to learn more.</p>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 05:38:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wep">wep</category>
      <category domain="http://securityratty.com/tag/insecure wireless technologies">insecure wireless technologies</category>
      <category domain="http://securityratty.com/tag/wireless data encryption">wireless data encryption</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/retail access">retail access</category>
      <category domain="http://securityratty.com/tag/consumer data theft">consumer data theft</category>
      <category domain="http://securityratty.com/tag/secureworks webcast">secureworks webcast</category>
      <category domain="http://securityratty.com/tag/quarter">quarter</category>
      <category domain="http://securityratty.com/tag/security whatsoever">security whatsoever</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/412950080/">PCI Bans WEP SecurityStarting 2010</source>
    </item>
    <item>
      <title><![CDATA[Schwarzenegger again nixes data breach bill]]></title>
      <link>http://securityratty.com/article/b18549d7ba497f2c9b45a58944bc57c5</link>
      <guid>http://securityratty.com/article/b18549d7ba497f2c9b45a58944bc57c5</guid>
      <description><![CDATA[For the second time in 12 months, California Gov. Arnold Schwarzenegger has vetoed legislation that would have set new IT security requirements designed to protect credit and debit card data in retail...]]></description>
      <content:encoded><![CDATA[For the second time in 12 months, California Gov. Arnold Schwarzenegger has vetoed legislation that would have set new IT security requirements designed to protect credit and debit card data in retail systems.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b4feb71108223eaa89889cda3541d3d6:%2Bljl9N2lkICVQyC7YvFTj8%2BulBSs1g0Y1L2LgWtXMhrNtzMSGzWQI6bj6OAeiGhcEJo49ovSwC7v'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2f25bd788cf96f70a15cacfe9ec9e5a6:8ydJYBLJTV2a2qbThHy1OXXO7uSzZRPYG5ScVAXYkRWlrLXXYCtZWBYhprglpTEsNDsz%2Bi7tbZpuUg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:51e28f79df211aa7e11d1aab44e249eb:exI4silRTX6JyhzMbp%2BjJJPq5fb8Ybgoqrt3J1gnbHhvvDghRhgxNrn4Tw89jarbv5Ebp4x3GCME6Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1333fb505caf33a1f6952bf856e36ccd:W1lOI5ZOccLDy3pEtSPXVoIxe%2FBd%2BjeF1E8w8a7fMBbAG9%2FW7WT3Ua%2F0MHdHYxW%2Blm4WffE%2BM%2BffxA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=486715e67b26aa759fe6b7d5bddf9a61" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=486715e67b26aa759fe6b7d5bddf9a61" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/debit card data">debit card data</category>
      <category domain="http://securityratty.com/tag/protect credit">protect credit</category>
      <category domain="http://securityratty.com/tag/arnold schwarzenegger">arnold schwarzenegger</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/california gov">california gov</category>
      <category domain="http://securityratty.com/tag/retail systems">retail systems</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/legislation">legislation</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=486715e67b26aa759fe6b7d5bddf9a61">Schwarzenegger again nixes data breach bill</source>
    </item>
    <item>
      <title><![CDATA[T-Mobile loses disk containing data on 17 million customers]]></title>
      <link>http://securityratty.com/article/144ef195cc115c959f375bf7d5307616</link>
      <guid>http://securityratty.com/article/144ef195cc115c959f375bf7d5307616</guid>
      <description><![CDATA[T-Mobile lost a disk containing personal information on 17 million of its German mobile-phone customers in early 2006, the company...]]></description>
      <content:encoded><![CDATA[T-Mobile lost a disk containing personal information on 17 million of its German mobile-phone customers in early 2006, the company confirmed.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a003abddc3b6068e4e8e187bf2cd0834:2EbNz8vwhaqJhlgPpsbuvTjbg7UIUHsAHo9QiYKstNm%2B15fySkSrHZ8zBNK%2FUMJ5H1ocFjgaf54t'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:85421fd5b0ef8380eb5d287de97ae696:M5%2FM5CJ29G7wwEucfw40alHhrXRAnlEKWKE2LD3g9HT48HqQC%2F7cfiaWNxskvW52q566fMx0JsjIag%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:62e6a403d26da086b09d4e9296d4d249:VF7LvNt8aN%2FmuN9j%2Bl5GEqEzj3G36Bvh%2FdrjwHFwVqEtp7OwcPQonY3O%2FSSyvE0zzQSeSY8gS2gHUg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6a10111a8237baff4cb266f397713292:5rEEkAzAPbCcgddQb79mWRWR91XMkAFEQ59LgAJ3lJb17h52jFVdYkoAj3a6ku0fdObJBhqEUo8Ttw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=07ff6f8592c209d70865c233dd0a48e7" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=07ff6f8592c209d70865c233dd0a48e7" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/german mobile-phone customers">german mobile-phone customers</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/disk">disk</category>
      <category domain="http://securityratty.com/tag/t-mobile lost">t-mobile lost</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=07ff6f8592c209d70865c233dd0a48e7">T-Mobile loses disk containing data on 17 million customers</source>
    </item>
    <item>
      <title><![CDATA[Shell fingers IT contractor in theft of employee data]]></title>
      <link>http://securityratty.com/article/2a01f6585ce4cbce603677d012f06bb4</link>
      <guid>http://securityratty.com/article/2a01f6585ce4cbce603677d012f06bb4</guid>
      <description><![CDATA[Shell Oil has notified its U.S. employees that an IT contractor used the personal data of four Shell workers to file fake unemployment claims in...]]></description>
      <content:encoded><![CDATA[Shell Oil has notified its U.S. employees that an IT contractor used the personal data of four Shell workers to file fake unemployment claims in Texas.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f500658dc15bf996fce890db68bd91dd:rvPj%2Fsr0zAs0DPV8UuXe79QACs7gUcdkzLwHUhxzJ9mCmk9Td27tlPvtvyZEb9y%2BYsf4Oa2mLNoQ'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6efa3b42573ba924bb4c9843858dd2c0:mqc09TZmNUqRKalumVBow5sGFQphmMrSjbCTD%2Bc1F0kTPWLpNUk0jFjcfQmmcYdhGk0K7gwkr9Ifxw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d24e26643cad3f8496a0c56be1c5e706:pR2Yo5s2A1oMGKdaAIfiSSHyFzkR1tFO4%2BvJdzXBGb5G9l4%2BcYfDfi834txL7Deq5lgxmhoxe%2F4Dow%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:21f6c290b2c8131f8da40a019c009343:TLRrCFfvcpnapfMZREjgG1gbxAaZejzmqBZhBZlnjCY%2F7b3lX2LulBU8h2tVXYsge8v9N%2FSuWCexYg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=113757f83d0b988e61a8d3a867407848"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=113757f83d0b988e61a8d3a867407848"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=113757f83d0b988e61a8d3a867407848" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/shell oil">shell oil</category>
      <category domain="http://securityratty.com/tag/shell workers">shell workers</category>
      <category domain="http://securityratty.com/tag/contractor">contractor</category>
      <category domain="http://securityratty.com/tag/texas">texas</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=113757f83d0b988e61a8d3a867407848">Shell fingers IT contractor in theft of employee data</source>
    </item>
  </channel>
</rss>
