<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: december]]></title>
    <link>http://securityratty.com/tag/december</link>
    <description></description>
    <pubDate>Fri, 31 Oct 2008 04:27:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gartner Data Center Conference 2008]]></title>
      <link>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</link>
      <guid>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</guid>
      <description><![CDATA[The Gartner Data Center Conference kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Pucks...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="96" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/12/clip-image002.jpg" width="439" border="0" /></p>
<p>The <a href="http://www.gartner.com/it/page.jsp?id=627607" target="_blank">Gartner Data Center Conference</a> kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Puck&#8217;s Bistro told me they were looking <a href="http://www.datacenterknowledge.com/archives/2008/12/02/at-the-gartner-data-center-conference/" target="_blank">forward to the 1800 people coming</a> to this show to fill the hotel up. As we&#8217;ve noted, the economic crisis is impacting business travel all around.</p>
<p>22% of the attendees at Data Center come from the public sector and government, with 44% coming from very large enterprises of 20K+ employees.</p>
<p>During the <a href="http://www.gartner.com/it/page.jsp?id=603107" target="_blank">Gartner IOM conference</a> in June, some of the most interesting info coming out of it was the quick polls of the audience on a variety of infrastructure and operations management topics. What are enterprises doing? Where are they headed? What&#8217;s important to them? Here are some quick takes from the opening session:</p>
<p>1) What is the largest data center challenge that you currently face?</p>
<ul>
<li><b>Smaller Budgets: 21%</b></li>
<li><b>Power &amp; Cooling: 20%</b></li>
<li>Dealing with the Rate of Technology Change: 15%</li>
<li>Aligning Activities with the Business: 15%</li>
<li>Modernizing Legacy Applications: 10%</li>
<li>Lack of Data Center Space because of Equipment Spread: 9%</li>
<li>How to Source IT Services: 5%</li>
<li>How to Find and Retain Talent: 5%</li>
</ul>
<p>Well, it&#8217;s taken almost a year to be &#8220;official&#8221;, but the National Bureau of Economic Research just announced that <a href="http://www.msnbc.msn.com/id/27999557/" target="_blank">the US has been in a recession since December of 2007</a>. It should come as a surprise to no one that dealing with smaller budgets is top of mind, even for the predominantly larger enterprises attending here. </p>
<p>2) What projects will receive the most funding in 2009?</p>
<ul>
<li><b>Virtualization/Consolidation: 31%</b></li>
<li>Data Center Facilities &#8211; new builds: 17%</li>
<li>IT Operations Process Improvement: 12%</li>
<li>IT Modernization: 7%</li>
<li><b>Green IT: 5%</b></li>
</ul>
<p>Virtualization and (server) consolidation projects are clearly a priority for larger enterprises in 2009. What&#8217;s interesting here is the relatively very low priority of <a href="http://www.devx.com/IT_Innovation/Article/40073?trk=DXRSS_LATEST" target="_blank">Green IT projects</a> &#8211; in spite of the importance to attendees of getting power and cooling costs under control. Perhaps there&#8217;s a gap here between what&#8217;s often the hype of Green IT and practical considerations for data center managers when it comes to power and cooling management.</p>
<p>3) Where are you with server consolidation projects?</p>
<ul>
<li>No Plans: 3%</li>
<li>Looking at it now and will start in next 2 years: 13%</li>
<li><b>In process now: 58%</b></li>
<li><b>Have already completed server consolidation project: 26%</b></li>
</ul>
<p>Larger enterprises are consolidating servers with a quarter of attendees already having gone through the process at least once. And according to poll #2, this trend will definitely continue.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 15:55:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/predominantly larger enterprises">predominantly larger enterprises</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/server consolidation projects">server consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center managers">data center managers</category>
      <category domain="http://securityratty.com/tag/consolidation projects">consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center facilities">data center facilities</category>
      <category domain="http://securityratty.com/tag/larger enterprises">larger enterprises</category>
      <source url="http://blog.sciencelogic.com/gartner-data-center-conference-2008/12/2008">Gartner Data Center Conference 2008</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up November 2008]]></title>
      <link>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</link>
      <guid>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month! If you are “too busy to read the blogs” (!), at least read <a href="http://chuvakin.blogspot.com/search/label/Monthly">these</a>.</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts/topics.</p>  <ol>   <li>Amazingly, this month by far the #1 post is my “'<a href="http://chuvakin.blogspot.com/2008/11/blogging-from-deepsec-2008-in-vienna.html">Blogging from DeepSec 2008 in Vienna</a>.” DeepSec was indeed an awesome conference.</li>    <li>Last month, I said that “SIEM bashing reached a new high.” OMFG. What should I say <a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">now</a>? I dunno. In any case, “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. BTW, “<a href="http://www.matasano.com/log/661/pro-forma-06-punditry-results/">On Open Source in SIEM and Log Management</a>” is also again on the top list, to much of my amazement.</li>    <li>Again and again, <a href="http://chuvakin.blogspot.com/search/label/PCI">PCI compliance</a> is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. </li>    <li>Get a firewall AND a fire extinguisher, now, will ya? Is it too much to ask? :-) The post “<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">On Small Companies and PCI Compliance</a>” is on the Top list.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAINx2</a> :-) this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as on the Top list.&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists. </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in December. Also see my annual “Top Posts” (<a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html">2007</a>)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/11/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up - October 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; </p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CToyO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CToyO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=q2gTO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=q2gTO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uBDPO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uBDPO" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/473057574" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/top list">top list</category>
      <category domain="http://securityratty.com/tag/annual top posts">annual top posts</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/473057574/monthly-blog-round-up-november-2008.html">Monthly Blog Round-Up November 2008</source>
    </item>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Fourteen]]></title>
      <link>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</link>
      <guid>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</guid>
      <description><![CDATA[You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s1600-h/microav_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s200/microav_rogue_november.png" /></a>You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is declining? With the upcoming holidays and the usual peak of web traffic, malicious activity on all fronts is prone to increase during December. <b>YEWGATE LTD</b>, <b>Sawert Alliance</b>, and <b>Sagent Group</b>, personal favorites affiliate participants in a revenue sharing program for serving fake security software, try to maintain a decent rhythm in their typosquatting process, always worth taking a peek at. The very latest rogue security software additions include :<br />
<br />
<b>micro-antiv2009 .com</b> (91.208.0.223)<br />
<b>micro-antivir2009 .com</b><br />
<b>micro-antivirus-2009 .com </b><br />
<b>micro-av-2009 .com</b><br />
<br />
<i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s1600-h/spyware_remover_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s200/spyware_remover_rogue_november.png" /></a></div><b>avmyscan .com</b> (91.203.92.186; 78.157.143.184)<br />
<b>go-your-scan .com</b><br />
<b>bestproscan .com</b><br />
<b>avproscan .com</b><br />
<b>goyourscan .com</b><br />
<b>iabestscan .com</b><br />
<b>avmyscan .com</b><br />
<b>best-scan-pro .com</b><br />
<b>avscan-pro .com</b><br />
<b>bestscanner-pro .com</b><br />
<b>avscanpro .com</b><br />
<b>iascannerpro .com</b><br />
<br />
<i>Jaroslav Voltz<br />
Email: <b>mensfult@gmail.com</b><br />
Organization: Private person<br />
Address: Biskupsk 9<br />
City: Praha<br />
State: Praha<br />
ZIP: 11000<br />
Country: CZ<br />
Phone: +420.2224811382</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s1600-h/sagent_group_rogue.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s200/sagent_group_rogue.png" /></a><b>virus-labs2009 .com</b> (66.232.113.62)<br />
<b>virus-trigger .com<br />
virusresponse2009 .com<br />
virusresplab .com<br />
virus-response .com</b><br />
<br />
<i>Roman Spitsikov<br />
Uus-Sadama 12&nbsp; <br />
Tallinn, Tallinn 10120<br />
Estonia<br />
<b>Roman.Spitsikov@gmail.com</b></i><br />
<br />
<b>virusremover2008plus .com</b> (77.245.61.80; 93.190.139.229)<br />
<br />
<i>Sagent Group&nbsp; (<b>sergbelo@gmail.com</b>)<br />
Brignal Solutions<br />
P.O. Box 3469 Geneva Place, Waterfront drive <br />
Road town,&nbsp;&nbsp; BVI<br />
BZ<br />
+1.14193017015</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s1600-h/sagent_group_rogue_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s200/sagent_group_rogue_2.png" /></a><b>antivirus-pro-scan.com</b> (84.243.197.183)<br />
<b>anti-virus-defence.com</b><br />
<b>protection-livescan.com</b><br />
<br />
<i>Aleksey Kononov <b>cndomainz@yahoo.com</b></i><br />
<i>+74954538435 fax: +74954538435</i><br />
<i>ul. Yakimanskay 34-56</i><br />
<i>Moskva Moskovskay oblast 112745</i><br />
<i>ru</i><br />
<br />
<b>rapidantivir .com</b><b> </b>(91.208.0.220)<b><br />
rapidantivirus-2009 .com<br />
securityscanner2009 .com<br />
rapidantivirus2009 .com<br />
rapid-antivir .com<br />
extraantivir .com<br />
rapid-antivirus .com<br />
rapidantivirus .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s1600-h/sqscan_rogue_november.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s200/sqscan_rogue_november.JPG" /></a><i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<b>sgscanner .com</b> (116.50.14.185)<br />
<b>sguardscan .com<br />
scansguard .com<br />
getsg2008 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s1600-h/virus_response_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s200/virus_response_rogue_november.png" /></a><i>Vrenk Tihomil<br />
Email: <b>gray444371@gmail.com</b><br />
Organization: Private person<br />
Address: Kolodvorska 73, Sl3270 Lasko<br />
City: Lasko<br />
State: LaskoLasko<br />
ZIP: Sl1355<br />
Country: SI<br />
Phone: +386.14588324</i><br />
<br />
<b>adwaredeluxe .com</b> (64.40.118.8) (private whois)<br />
<b>antivirusadvanced .com<br />
antivirusadvance .com<br />
spydestroy .com<br />
spywareremoval .ws</b><br />
<br />
Shipping them in batches means exposing them in batches.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security_12.html">A Diverse Portfolio of Fake Security Software - Part Thirteen</a><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9h0BN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9h0BN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x78xN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x78xN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SX1Dn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SX1Dn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=n7eun"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=n7eun" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xmqRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xmqRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4Ga4N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4Ga4N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Lo1n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Lo1n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/467329268" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 04:47:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/sawert alliance">sawert alliance</category>
      <category domain="http://securityratty.com/tag/road town">road town</category>
      <category domain="http://securityratty.com/tag/martti seodancergmail">martti seodancergmail</category>
      <category domain="http://securityratty.com/tag/upper flat">upper flat</category>
      <category domain="http://securityratty.com/tag/city">city</category>
      <category domain="http://securityratty.com/tag/road">road</category>
      <category domain="http://securityratty.com/tag/sl3270 lasko">sl3270 lasko</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/467329268/diverse-portfolio-of-fake-security_27.html">A Diverse Portfolio of Fake Security Software - Part Fourteen</source>
    </item>
    <item>
      <title><![CDATA[Gmail security and recent phishing activity]]></title>
      <link>http://securityratty.com/article/9a45bb9bbae6a2b37196f35b1390b206</link>
      <guid>http://securityratty.com/article/9a45bb9bbae6a2b37196f35b1390b206</guid>
      <description><![CDATA[Posted by Chris Evans

We've seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners' domains by unauthorized third parties. At Google...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Chris Evans</span><br /><br />We've seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners' domains by unauthorized third parties. At Google we're committed to providing secure products, and we mounted an immediate investigation. Our results indicate no evidence of a Gmail vulnerability.<br /><br />With help from affected users, we determined that the cause was a phishing scheme, a common method used by malicious actors to trick people into sharing their sensitive information. Attackers sent customized e-mails encouraging web domain owners to visit fraudulent websites such as "google-hosts.com" that they set up purely to harvest usernames and passwords. These fake sites had no affiliation with Google, and the ones we've seen are now offline. Once attackers gained the user credentials, they were free to modify the affected accounts as they desired. In this case, the attacker set up mail filters specifically designed to forward messages from web domain providers.<br /><br />Several news stories referenced a <a title="domain theft from December 2007" href="http://www.davidairey.com/google-gmail-security-hijack/" id="d.kh">domain theft from December 2007</a> that was incorrectly linked to a Gmail CSRF vulnerability</span>. We did have a Gmail CSRF bug reported to us in September 2007 that we fixed and deployed worldwide within 24 hours of private disclosure of the bug details. We know of no affected users. Neither this bug nor any other Gmail bug was involved in the December 2007 domain theft.<br /><br />We recognize how many people depend on Gmail, and we strive to make it as secure as possible. At this time, we'd like to thank the wider security community for working with us to achieve this goal. We're always looking at new ways to enhance Gmail security. For example, we recently gave users the option to <a href="http://gmailblog.blogspot.com/2008/07/making-security-easier.html" id="murn" title="always connect via https">always run their entire session using https</a>.<br /><br />To keep your Google account secure online, we recommend you only ever enter your Gmail sign-in credentials to web addresses starting with https://www.google.com/accounts, and never click-through any warnings your browser may raise about certificates. For more information on how to stay safe from phishing attacks, see our blog post <a href="http://googleblog.blogspot.com/2008/04/how-to-avoid-getting-hooked.html" id="o8q2" title="here">here</a>.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=5ziOaTxJ"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=UypYbMp4"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=UypYbMp4" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/jSxgatXB-tY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 10:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmail">gmail</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/bug details">bug details</category>
      <category domain="http://securityratty.com/tag/gmail bug">gmail bug</category>
      <category domain="http://securityratty.com/tag/gmail csrf vulnerability">gmail csrf vulnerability</category>
      <category domain="http://securityratty.com/tag/enhance gmail security">enhance gmail security</category>
      <category domain="http://securityratty.com/tag/gmail csrf bug">gmail csrf bug</category>
      <category domain="http://securityratty.com/tag/gmail sign-in credentials">gmail sign-in credentials</category>
      <category domain="http://securityratty.com/tag/domain theft">domain theft</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/jSxgatXB-tY/gmail-security-and-recent-phishing.html">Gmail security and recent phishing activity</source>
    </item>
    <item>
      <title><![CDATA[7 Easy Survival Tactics to Selling Smarter in the Recession]]></title>
      <link>http://securityratty.com/article/39edaf8cc4a3c591bb96b1c11a65ee6e</link>
      <guid>http://securityratty.com/article/39edaf8cc4a3c591bb96b1c11a65ee6e</guid>
      <description><![CDATA[WHEN:Tuesday, December 9th1pm ET / 10am PT Join now!SPONSORED BY: Microsoft Dynamics CRM OnlineGet the 7 easy survival tactics for selling smarter in the recession. Join now!Youll...]]></description>
      <content:encoded><![CDATA[WHEN:Tuesday, December 9th1pm ET / 10am PT Join now!SPONSORED BY: Microsoft Dynamics&trade; CRM OnlineGet the 7 easy survival tactics for selling smarter in the recession. Join now!You&rsquo;ll learn...]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 13:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/easy survival tactics">easy survival tactics</category>
      <category domain="http://securityratty.com/tag/december 9th1pm">december 9th1pm</category>
      <category domain="http://securityratty.com/tag/recession">recession</category>
      <category domain="http://securityratty.com/tag/smarter">smarter</category>
      <category domain="http://securityratty.com/tag/join">join</category>
      <category domain="http://securityratty.com/tag/10am">10am</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/464509205/">7 Easy Survival Tactics to Selling Smarter in the Recession</source>
    </item>
    <item>
      <title><![CDATA[Dont get a lump of coal this season!]]></title>
      <link>http://securityratty.com/article/76b2b4912a579fe9fd9b6d37062635a1</link>
      <guid>http://securityratty.com/article/76b2b4912a579fe9fd9b6d37062635a1</guid>
      <description><![CDATA[Make sure your online protection products are working and updated, or you may get a lump of coal this Holiday season


clipped from www.marketwatch.com

Webroot Threat Advisory: Online Threats to...]]></description>
      <content:encoded><![CDATA[<div > Make sure your online protection products are working and updated, or you may get a lump of coal this Holiday season. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/28686275-C882-4C1B-A9E1-759CBA367C2A/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/1301bf5b-a6cb-4d7a-8eef-aab9911ce964/28686275-C882-4C1B-A9E1-759CBA367C2A/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.marketwatch.com/news/story/Webroot-Threat-Advisory-Online-Threats/story.aspx?guid=%7B006BCB25-0501-4CC4-9D00-0B98C35C8C95%7D" href="http://www.marketwatch.com/news/story/Webroot-Threat-Advisory-Online-Threats/story.aspx?guid=%7B006BCB25-0501-4CC4-9D00-0B98C35C8C95%7D" style="font-size: 11px;">www.marketwatch.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Webroot-Threat-Advisory-Online-Threats/story.aspx?guid=%7B006BCB25-0501-4CC4-9D00-0B98C35C8C95%7D -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Webroot Threat Advisory: Online Threats to Increase This Holiday Season</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Webroot-Threat-Advisory-Online-Threats/story.aspx?guid=%7B006BCB25-0501-4CC4-9D00-0B98C35C8C95%7D --><DIV class="p"><br />
            To protect themselves during any online<br />
      shopping experience, consumers need to be aware of the security<br />
      risks and necessary precautions they should take to avoid being a victim<br />
      of cyber crime. Since the October to December timeframe will be a key<br />
      money-making season for today&#8217;s financially<br />
      motivated cyber criminals Webroot is recommending that consumers follow<br />
      these five steps:<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/28686275-C882-4C1B-A9E1-759CBA367C2A/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_181108054621"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=181108054621&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=181108054621&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=181108054621&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_181108054621" /></a></P>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:46:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/season">season</category>
      <category domain="http://securityratty.com/tag/online threats">online threats</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/holiday season">holiday season</category>
      <category domain="http://securityratty.com/tag/online protection products">online protection products</category>
      <category domain="http://securityratty.com/tag/cyber criminals webroot">cyber criminals webroot</category>
      <category domain="http://securityratty.com/tag/webroot threat advisory">webroot threat advisory</category>
      <category domain="http://securityratty.com/tag/consumers follow">consumers follow</category>
      <category domain="http://securityratty.com/tag/consumers">consumers</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=660">Dont get a lump of coal this season!</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[Check It Out! FAIR Public Training December 10-12]]></title>
      <link>http://securityratty.com/article/7c0dad2af3212f7ceb6a464d5f435a90</link>
      <guid>http://securityratty.com/article/7c0dad2af3212f7ceb6a464d5f435a90</guid>
      <description><![CDATA[Theres been quite a few people talking about what sorts of strategies make sense for security and security departments in a downturn. And theyre all very good - but theres one thing that Id like to...]]></description>
      <content:encoded><![CDATA[<p>There&#8217;s been quite a few people talking about what sorts of strategies make sense for security and security departments in a downturn.  And they&#8217;re all very good - but there&#8217;s one thing that I&#8217;d like to add.</p>
<p>One easy, inexpensive way to actually increase your effectiveness in 2009 is to, right now, make a quick review your risk management processes.  As you take a look at how you&#8217;re using risk in your organization, I&#8217;d ask you to make sure that those processes are providing value for the energy you&#8217;re spending.  If they&#8217;re not -<em><strong> if you&#8217;re not successfully using risk within security and with the other lines of business that you serve </strong></em>- then I&#8217;d like to invite you to  come take advantage of RMI&#8217;s public training session for 2008, held in Columbus Ohio on December 10-12.  <strong><a href="http://www.riskmanagementinsight.com/media/docs/analyst_training12_2008.pdf">&gt;A brochure is here&lt;</a>.</strong></p>
<p>For three days and $1,995 - you&#8217;ll get real answers to many of the commonly voiced frustrations RMI hears concerning risk &amp; risk management.  Answers around measurement, application, communicating risk to other lines of business, <em>heck</em>, basic answers as to what risk is and how to get consistent, defensible values that actually <em><strong>mean</strong></em> something.</p>
<p>Not to mention - <strong>Strengthening your Risk Management processes increases your ability to manage risk, which reduces the amount of risk you actually face.</strong></p>
<p><span style="color: #008000;"><strong>NEW TO THE PUBLIC STUFF!</strong></span></p>
<p>I&#8217;m personally excited because this is the first time that our public training we&#8217;ll feature measurement &#8220;calibration&#8221; exercises and include excel tools to take home and use for quantitative FAIR analysis.  These are benefits we&#8217;ve only previously reserved for private client workshops.</p>
<p>I know that FAIR can help you and your organization, but as the sales guys always say, &#8220;don&#8217;t take my word for it&#8221;.  Here&#8217;s something we recently received (unsolicited) from the CSO of one of the 10 largest banks in the US, who has had several of his analysts receive this same basic training:</p>
<blockquote><p>I would like to also add my deep appreciation for what FAIR and RMI has brought to (us) and how we go about the business of risk analysis. We have had some great conversations around risk with the lines of business that have ended very favorably for us.</p></blockquote>
<p>More information can be found on RMI&#8217;s website here:  <strong><a href="http://www.riskmanagementinsight.com/12_2008_training.html">http://www.riskmanagementinsight.com/12_2008_training.html</a></strong></p>
<p>Thanks.</p>
<p>Oh and tomorrow, we&#8217;ll talk a little bit about quantitative and qualitative risk.</p>
]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 12:32:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management processes">risk management processes</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/qualitative risk">qualitative risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/fair">fair</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/manage risk">manage risk</category>
      <category domain="http://securityratty.com/tag/quantitative fair analysis">quantitative fair analysis</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=510">Check It Out! FAIR Public Training December 10-12</source>
    </item>
    <item>
      <title><![CDATA[Happy (Belated) First Birthday!]]></title>
      <link>http://securityratty.com/article/0afd1c77456ad4b8b1421c1314abc638</link>
      <guid>http://securityratty.com/article/0afd1c77456ad4b8b1421c1314abc638</guid>
      <description><![CDATA[to my ADSL application

Last year in October a salesperson at Telkom phoned to let me know that my phone exchange supports ADSL and do I want to upgrade my line to have ADSL

I did the maths and...]]></description>
      <content:encoded><![CDATA[.... to my ADSL application.<br /><br />Last year in October a salesperson at Telkom phoned to let me know that my phone exchange supports ADSL and do I want to upgrade my line to have ADSL?<br /><br />I did the maths and worked out that it would be cheaper for me to have ADSL and have the benefit of all-time-on access to the Internet.<br /><br />So, I applied and a few days later my application was processed and I had an application number. It all got to the point where I had the modem connected and ready when a technical person at the exchange noticed that "no, the exchange is <span style="font-style: italic;">potentially</span> ready for ADSL but was not, in fact, ready."<br /><br />"But, good news, there is a project to upgrade the exchange to be ADSL capable. It should be done by latest end of December 2007."<br /><br />That became end of January, end of February, end of April... then it jumped to end of June.<br /><br />Now it is scheduled to be completed by the end of April 2009.<br /><br />The way things are looking - I'll probably be celebrating the second birthday of my ADSL application this time next year... many happy returns.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/437801003" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 04:27:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/adsl">adsl</category>
      <category domain="http://securityratty.com/tag/adsl application">adsl application</category>
      <category domain="http://securityratty.com/tag/adsl capable">adsl capable</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/all-time-on access">all-time-on access</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/exchange">exchange</category>
      <category domain="http://securityratty.com/tag/technical person">technical person</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/437801003/happy-belated-first-birthday.html">Happy (Belated) First Birthday!</source>
    </item>
  </channel>
</rss>
