<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: decent]]></title>
    <link>http://securityratty.com/tag/decent</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Two Classes of Airport Contraband]]></title>
      <link>http://securityratty.com/article/9add41f24cfea6a99d21547a04d8fdaf</link>
      <guid>http://securityratty.com/article/9add41f24cfea6a99d21547a04d8fdaf</guid>
      <description><![CDATA[Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been...]]></description>
      <content:encoded><![CDATA[<p>Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been too dangerous. And to demonstrate how dangerous he really thought that jar was, he blithely tossed it in a nearby bin of similar liquid bottles and sent me on my way.</p>

<p>There are two classes of contraband at airport security checkpoints: the class that will get you in trouble if you try to bring it on an airplane, and the class that will cheerily be taken away from you if you try to bring it on an airplane. This difference is important: Making security screeners confiscate anything from that second class is a waste of time. All it does is harm innocents; it doesn't stop terrorists at all.</p>

<p>Let me explain. If you're caught at airport security with a bomb or a gun, the screeners aren't just going to take it away from you. They're going to call the police, and you're going to be stuck for a few hours answering a lot of awkward questions. You may be arrested, and you'll almost certainly miss your flight. At best, you're going to have a very unpleasant day.</p>

<p>This is why articles about how screeners don't catch <a href="http://www.cnn.com/2008/US/01/28/tsa.bombtest/index.html">every</a> -- or even <a href="http://www.homelandstupidity.us/2007/10/25/tsa-screeners-fail-most-bomb-tests/">a</a> <a href="http://www.homelandstupidity.us/2006/10/31/tsa-screeners-still-fail-to-find-guns-bombs/">majority</a> -- of guns and bombs that <a href="http://www.boston.com/news/local/articles/2003/10/16/logan_screeners_fail_weapons_tests/">go through the checkpoints</a> don't bother me. The screeners don't have to be perfect; they just have to be good enough. No terrorist is going to base his plot on getting a gun through airport security if there's decent chance of getting caught, because the consequences of getting caught are too great.</p>

<p>Contrast that with a terrorist plot that requires a 12-ounce bottle of liquid. There's no evidence that the London liquid bombers actually had a workable plot, but assume for the moment they did. If some copycat terrorists try to bring their liquid bomb through airport security and the screeners catch them -- like they caught me with my bottle of pasta sauce -- the terrorists can simply try again. They can try again and again. They can keep trying until they succeed. Because there are no consequences to trying and failing, the screeners have to be 100 percent effective. Even if they slip up one in a hundred times, the plot can succeed.</p>

<p>The same is true for knitting needles, pocketknives, scissors, corkscrews, cigarette lighters and whatever else the airport screeners are confiscating this week. If there's no consequence to getting caught with it, then confiscating it only hurts innocent people. At best, it mildly annoys the terrorists.</p>

<p>To fix this, airport security has to make a choice. If something is dangerous, treat it as dangerous and treat anyone who tries to bring it on as potentially dangerous. If it's not dangerous, then stop trying to keep it off airplanes. Trying to have it both ways just distracts the screeners from actually making us safer.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=bB1FL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=bB1FL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uc79L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uc79L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 01:47:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/airport security checkpoints">airport security checkpoints</category>
      <category domain="http://securityratty.com/tag/checkpoints">checkpoints</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/security screeners">security screeners</category>
      <category domain="http://securityratty.com/tag/liquid">liquid</category>
      <category domain="http://securityratty.com/tag/london liquid bombers">london liquid bombers</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <category domain="http://securityratty.com/tag/plot">plot</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/the_two_classes.html">The Two Classes of Airport Contraband</source>
    </item>
    <item>
      <title><![CDATA[Federal grand jury meets on Palin hacking case]]></title>
      <link>http://securityratty.com/article/904ae58521090a23272501da79b4f938</link>
      <guid>http://securityratty.com/article/904ae58521090a23272501da79b4f938</guid>
      <description><![CDATA[A federal grand jury convened to hear testimony about the hack of GOP vice presidential nominee Sarah Palin's e-mail account, and the lawyer representing the college student suspect called his client...]]></description>
      <content:encoded><![CDATA[A federal grand jury convened to hear testimony about the hack of GOP vice presidential nominee Sarah Palin's e-mail account, and the lawyer representing the college student suspect called his client 'a decent and intelligent young man.'<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:81f5c372c7ab186b47da95976df03a36:%2FzrNCjmvqZElgydrmTwEP1mDPOT1xRhQCfyWTmqemu%2FHOTnwZzsZQaeApSFMR6de%2FSOyUvaGgqsdnsJxbKdN7YB523OmhEiFm5H4IN0V6%2Bo%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:15e768a83b4b343ed1c8de2b878fe627:8q87coPuBITEF%2BZpX5mNv24J4TaXMi%2Fw8pPgaqoyOBbGKTszuCZx8z%2BDUy5kijCTbqgDz8xO1x9URjA5MdS0IX1G0IqesRerovXIJFxzrrY%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:981d1849849957b1481c2619c571a58a:D7p%2FMi9HnB%2BbMnAZDI9Hggif%2BCDIC%2B5XyRglxLNBM1p3zhubLnlxhlRf3EqCT8as9Pi9GswlcE6HBJSzHyB7bXxjH8zoWzRBHmabSfdWQ1M%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:df3f82298806e98c49a1da345790e266:TzpXH4dKwB5nsXUTYWP6gEWuJB65HiOv7M%2BlUVLzd8EYZ44Y32FsqT8onWjOY4jzMnA1j3ZcmzOHaxweaCVwhmLOGWQGky48FqU%2FOO8IRzw%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=7b7f56c0c158b3ea432ce94f1e56da11" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7b7f56c0c158b3ea432ce94f1e56da11" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal grand jury">federal grand jury</category>
      <category domain="http://securityratty.com/tag/college student suspect">college student suspect</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/client">client</category>
      <category domain="http://securityratty.com/tag/intelligent">intelligent</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <category domain="http://securityratty.com/tag/lawyer">lawyer</category>
      <category domain="http://securityratty.com/tag/decent">decent</category>
      <category domain="http://securityratty.com/tag/testimony">testimony</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=7b7f56c0c158b3ea432ce94f1e56da11">Federal grand jury meets on Palin hacking case</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful]]></title>
      <link>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</link>
      <guid>http://securityratty.com/article/9b6db0f25f815641ea3655ef3cb29af5</guid>
      <description><![CDATA[Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been...]]></description>
      <content:encoded><![CDATA[<p>
Airport security found a jar of pasta sauce in my luggage last month. It was a 6-ounce jar, above the limit; the official confiscated it, because allowing it on the airplane with me would have been too dangerous. And to demonstrate how dangerous he really thought that jar was, he blithely tossed it in a nearby bin of similar liquid bottles and sent me on my way.
</p><p>
There are two classes of contraband at airport security checkpoints: the class that will get you in trouble if you try to bring it on an airplane, and the class that will cheerily be taken away from you if you try to bring it on an airplane. This difference is important: Making security screeners confiscate anything from that second class is a waste of time. All it does is harm innocents; it doesn't stop terrorists at all.
</p><p>
Let me explain. If you're caught at airport security with a bomb or a gun, the screeners aren't just going to take it away from you. They're going to call the police, and you're going to be stuck for a few hours answering a lot of awkward questions. You may be arrested, and you'll almost certainly miss your flight. At best, you're going to have a very unpleasant day.
</p><p>
This is why articles about how screeners don't catch <a href="http://www.cnn.com/2008/US/01/28/tsa.bombtest/index.html">every</a> -- or even <a href="http://www.homelandstupidity.us/2007/10/25/tsa-screeners-fail-most-bomb-tests/">a</a> <a href="http://www.homelandstupidity.us/2006/10/31/tsa-screeners-still-fail-to-find-guns-bombs/">majority</a> -- of guns and bombs that <a href="http://www.boston.com/news/local/articles/2003/10/16/logan_screeners_fail_weapons_tests/">go through the checkpoints</a> don't bother me. The screeners don't have to be perfect; they just have to be good enough. No terrorist is going to base his plot on getting a gun through airport security if there's decent chance of getting caught, because the consequences of getting caught are too great.
</p><p>
Contrast that with a terrorist plot that requires a 12-ounce bottle of liquid. There's no evidence that the London liquid bombers actually had a workable plot, but assume for the moment they did. If some copycat terrorists try to bring their liquid bomb through airport security and the screeners catch them -- like they caught me with my bottle of pasta sauce -- the terrorists can simply try again. They can try again and again. They can keep trying until they succeed. Because there are no consequences to trying and failing, the screeners have to be 100 percent effective. Even if they slip up one in a hundred times, the plot can succeed.
</p><p>
The same is true for knitting needles, pocketknives, scissors, corkscrews, cigarette lighters and whatever else the airport screeners are confiscating this week. If there's no consequence to getting caught with it, then confiscating it only hurts innocent people. At best, it mildly annoys the terrorists.
</p><p>
To fix this, airport security has to make a choice. If something is dangerous, treat it as dangerous and treat anyone who tries to bring it on as potentially dangerous. If it's not dangerous, then stop trying to keep it off airplanes. Trying to have it both ways just distracts the screeners from actually making us safer.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is chief security technology officer of BT. His new book is </cite>Schneier on Security<cite>.

</p><br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=aefd56c11b2eee64280f816001ed44dc"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=aefd56c11b2eee64280f816001ed44dc"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=aefd56c11b2eee64280f816001ed44dc" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=K4hTL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=K4hTL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=gnANl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=gnANl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7cfHl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7cfHl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lizGL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lizGL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=4j0mL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=4j0mL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=McKUl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=McKUl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=F517l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=F517l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=FIJtL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FIJtL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/396484059" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/396484061" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 14:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security screeners">security screeners</category>
      <category domain="http://securityratty.com/tag/airport security checkpoints">airport security checkpoints</category>
      <category domain="http://securityratty.com/tag/checkpoints">checkpoints</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/liquid">liquid</category>
      <category domain="http://securityratty.com/tag/london liquid bombers">london liquid bombers</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/396484061/securitymatters_0918">Security Matters: Airport Pasta-Sauce Interdiction Considered Harmful</source>
    </item>
    <item>
      <title><![CDATA[Summarizing August's Threatscape]]></title>
      <link>http://securityratty.com/article/01c05fcd5f209b7515be2cee57a93c9b</link>
      <guid>http://securityratty.com/article/01c05fcd5f209b7515be2cee57a93c9b</guid>
      <description><![CDATA[Following the previous summaries of June's and July's threatscape based on all the research published during the month, it's time to summarize August's threatscape

August's threatscape was dominated...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SL_ZoXre4vI/AAAAAAAACJ0/LKtKpSt0igQ/s1600-h/ddanchev_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SL_ZoXre4vI/AAAAAAAACJ0/Phtgyl6rLXQ/s200-R/ddanchev_august.png" /></a>Following the previous summaries of <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's</a> and <a href="http://ddanchev.blogspot.com/2008/08/summarizing-julys-threatscape.html">July's threatscape</a> based on all the research published during the month, it's time to summarize August's threatscape.<br />
<br />
August's threatscape was dominated by a huge increase of rogue security software domains made possible due to the easily obtainable templates for the sites, several malware campaigns targeting popular social networking sites, Russian's organized cyberattack against Georgia with evidence on who's behind it pointing to "everyone" and a few botnets dedicated to the attack making the whole process easy to outsource and turn responsibility into an "open topic", several new web based botnet management kits and tools found in the wild, evidence that the 76service may in fact be going mainstream since the concept of cybercrime as a service is already emerging, and, of course, a peek at India's CAPTCHA solving economy, where the best comment I've received so far is that every site should embrace reCAPTCHA, so that while solving CAPTCHAs and participating in the abuse of these services in question, they would be also digitizing books. As usual, August was a pretty dynamic month for the middle of summer, with everyone excelling in their own malicious field.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/08/mcafees-site-advisor-blocking-nruns-ag.html">McAfee's Site Advisor Blocking n.runs AG - "for starters"</a><br />
False positives are rather common, especially when you're aiming to protect the end user from himself and not let him gain access to "hacking tools", but you're flagging security tools as badware and missing over half the SQL injected domains currently in the wild due to the fact that SiteAdvisor's community still haven't reviewed them - that's not good<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/08/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</a><br />
Twitter, just like every Web 2.0 application, isn't and shouldn't be treated as a unique platform for dissemination of malware, since it's dissemination of malware "as usual". This particular malware campaign was not just executed by a lone gunman, but also, was taking advantage of a flaw allowing the author to add new followers potentially exposing them to the malicious links serving banker malware. For the the time being, MySpace, Facebook and Twitter accounts are the very last thing a malicious attacker is interesting in puchasing accounting data for, but how come? It's all due to the oversupply of automatically registered accounts at other popular services, whose ecosystem of Internet properties empower cybercriminals with the ability to launch, host and distribute malware in between abusing the very same company's services for the blackhat SEO campaign and redirection services. Theoretically, a distributed network build upon the services provided by a single company is faily easy to accomplish due to the single login authentication applied everywhere. A singly bogus Gmail account results in a blackhat SEO hosting blogspot account, flash based redirector hosted at Picasa, and a couple of thousands of spam emails sent automatically sent through Gmail in order to abuse it's trusted email reputation<br />
&nbsp; <br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/08/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</a><br />
If aggressiveness matter, this campaign consisting of remotely injected redirection scripts at legitimate sites next to on purposely introduced malware oriented domains, was perhaps the most aggressive one during the month. Fake flash players, fake windows media players and fake youtube players are prone to increase as a social engineering tactic of choice due to the template-ization of malware serving sites for the sake of efficiency<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
With Zeus vulnerable to a remotely exploitable flaw allowing cybercriminals to hijack other cybercriminal's Zeus botnet, private exploits targeting the still rather popular at least in respect to usefulness Pinch malware are leaking, allowing everyone including security researchers to take a peek at a particular campaign running unpatched Pinch gateway<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">Phishers Backdooring Phishing Pages to Scam One Another</a><br />
Backdooring phishing pages is perhaps the most minimalistic approach a cybercriminal wanting to scam another cybercriminal is going to take. The far more beneficial approach that I've encountered on a couple of occassions so far, would be to backdoor a proprietary web malware exploitation kit, release it in the wild, let them put the time and efforts into launching the campaigns, then hijack their botnet. In fact, the possibilities for backdooring copycat web malware exploitation kits in order to take advantage of the momentum while introducing a non-existent kit has always been there at the disposal of malicious attackers. One thing's for sure - there's no such thing as a free web malware exploitation kit, just like there isn't such thing as a free phishing page<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/08/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</a><br />
In between the scammers promising the Moon and asking for anything between $20 to $250 to hack into an email account, there are "legitimate" services taking advantage of web email hacking kits consisting of each and every known XSS vulnerability for a particular service in an attempt to increase the chances of the attacker. And given that the majority of these have been patched a long time ago, social engineering comes into play. Do these services have a future? Definitely as more and more people are in fact looking for and requesting such services, in fact, they're willing to pay a bonus considering how exotic it is for them to have any email that they provide hacked into and the accounting data sent back to them<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html">The Russia vs Georgia Cyber Attack</a><br />
Event of the month? Could be, but just like every "event of the moth" everyone seems to be once again restating their "selective retention" preferences. What is selective retention anyway? Selective retention is basically a situation where once Russian is attacking another country's infrastructure, you would automatically conclude that it's Russian FSB behind the attacks and consciously and subconsciously ignore all the research and articles telling you otherwise, namely that the FSB wouldn't even bother acknowledging Georgia's online presence, at least not directly. Moreover, talking about the FSB as the agency behind the cyberattacks indicates "selective retention", talking about FAPSI indicates better understanding of the subject.<br />
<br />
In times when cybercrime is getting ever easier to outsource, anyone following the news could basically orchestrate a large scale DDoS attack against a particular country in order to forward the responsibility to any country that they want to. In Russia vs Georgia, you have a combination of a collectivist society that's possessing the capabilities to launch DDoS attacks, knows where and how to order them, and that in times when your country is engaged in a war conflict drinking beer instead of DDoS-sing the major government sites of the adversary is not an option.<br />
<br />
Selective retention when combined with a typical mainstream media's mentality to "slice the threat on pieces" instead of turning the page as soon as possible, is perhaps the worst possible combination. Furthermore, coming up with <a href="http://intelfusion.net/wordpress/?p=398">Social Network analysis of the cyberattacks</a> would produce nothing more but a few fancy graphs of over enthusiastic Russian netizen's distributing the static list of the targets. The real conversations, as always, are <a href="http://blogs.nyu.edu/blogs/agc282/zia/2008/08/intelfusions_sna_of_russian_cy.html">happening in the "Dark Web" limiting the possibilities for open source intelligence</a> using a data mining software. Things changed, OPSEC is slowly emerging as a concept among malicious parties, whenever some of the "calls for action" in the DDoS attacks were posted at mainstream forums, they were immediately removed so that they don't show up in such academic initiatives<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</a><br />
The reappearance of the 76Service allowing everyone to log into a web based interface and collect all the accounting and financial data coming from malware infected hosts across the globe for the period of time for which they've bought access, indicates that what used to be proprietary services which were supposedly no longer available, are now being operated in a do-it-yourself fashion. Goods and products mature into services, so from a cost-benefit analysis perspective, outsourcing is naturally most beneficial even when it comes to cybercrime <br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</a><br />
If it's the botnets used in the attacks, they are known, if it's about who's providing the hosting for the command and control, it's the "usual suspects", but just like previous discussion of the Russian Business Network, it remains questionable on whether or not they work on a revenue-sharing basis, are simply providing the anti-abuse hosting, or are the shady conspirators that every newly born RBN expert is positioning them to be.<br />
<br />
Cheap conversation regarding the RBN ultimately serves the RBN, and just for the record, there's a RBN alternative in every country, but the only thing that remains the same are the customers, tracking the customers means exposing the RBN and the international franchises of their services, making it harder to identify their international operations. And given that the "tip of the iceberg", namely RBN's U.S operations remain in tact, talking about taking actions against their international operations in countries where cybercrime law is still pending, is yet another quality research into the topic building up the pile of research into the very same segments of the very same ISPs.<br />
<br />
Just for the record - these "very same ISPs" are regular readers of my blog, and if you analyze their activities, they're definitely reading yours too, ironically, surfing through gateways residing within their netblock that are so heavily blacklisted due to the guestbook and forum spamming activities that their bad reputation usually ends up in another massive blackhat SEO campaign exposed.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/08/guerilla-marketing-for-conspiracy-site.html">Guerilla Marketing for a Conspiracy Site</a><br />
Conspiracy theorists may in fact have a new wallpaper to show off with<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/08/banker-malware-targetting-brazilian.html">Banker Malware Targeting Brazilian Banks in the Wild</a><br />
When misinformed and not knowing anything about a particular underground segment, a potential cybercriminal would stick to using such primitive compared to the sophisticated banker malware kits currently in the wild. These sophisticated banker malware kits are often coming in a customer-tailored proposition, with their price increasing or decreasing based on the specific module to be included or excluded. For instance, a module targeting all the U.S banks that has been put in a "learning mode" long before it was made available to the customers can be requested and is often available with the business model build around the customer's wants&nbsp; <br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">Compromised Cpanel Accounts For Sale</a><br />
Despite the massive SQL injection attacks, accounting data for Cpanel accounts coming from malware infected hosts seems to be once again coming into play, which isn't surprising given the filtering capabilities and log parsing tools today's botnet masters are empowered with. These very same compromised Cpanel accounts and the associated domains often end up so heavility abused that it's tactics like these that are driving the underground multitasking mentality, namely, abusing a single compromised account for each and every malicious online activity you can think of - even hosting banners for their blackhat SEO services <br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
In August we saw a peek of fake security software, neatly typosquatted domains whose authors earn revenue each and every time someone installs the software. The vendors behind this software are forwarding the entire process of driving traffic to those excelling in aggregating traffic and abusing it. As anticipated, underground multitasking started taking place within the fake security software domains, with the people behind them introducing client-side exploits in order to improve the monetization of the traffic coming to the sites<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
There's no such thing as a (quality) free botnet kit. What's for free is often the leftovers from a single feature of a more sophisticated proprietary botnet kit. This one in particular is however trying to demonstrate that even a plain simple GUI botnet command and control software can achieve the results desired by an average script kiddie, and not necessarily satisfy the needs of the experienced botnet master<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><br />
As far as trends and fads are concerned, the majority of the domains are currently parked at up to four different IPs, with most of them going into a stand by mode once they get detected and reappear back couple of weeks later<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware - Part Two</a><br />
Due to the template-ization of fake celebrity video sites, and simple traffic management tools combined with blackhat SEO tactics, these sites are also prone to increase in the next couple of months<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
It's releases like these that remind us of the amount of time, efforts and personal touch that a malicious attacker would put into such a management kit, currently acting as a personal benchmark as far as complexity and features indicating the coder's experience with botnets is concerned. What's he's failing to anticipate is that this kit is sooner or later going to turn into the "MPack of botnet management"<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</a><br />
Keep it coming, we'll keep it exposing until we end up getting down to the "fake software vendor" itself<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic Email Harvesting 2.0</a><br />
Email harvesting is slowly maturing into a vertically integrated service provided by vendors of managed spamming services. This email harvesting module is aiming to close the page on text obfuscation in respect to fighting spam, and is successfully recognizing and collecting such publicly available emails. From a psychological perspective though, the end users who bothered to obfuscate their emails are less likely to fall victims into phishing scams, with the obfuscation speaking for a relatively decent situational awareness on how they emails end up in a spammer's campaign<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</a><br />
As a firm believer in sampling in order to draw conclusions on the big picture, an approach that has proven highly accurate in modeling historical and upcoming tactics and behavior, a single fake porn site serving malware campaign usually exposes a dozen of misconfigured redirectors, which thanks to their misconfiguration despite the evasive features available within the kits, expose another dozen of malware campaigns<br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/08/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</a><br />
With no particular flaw exploited other than the social engineering tactic of using already compromised Facebook accounts who would automatically spam all their friends with links to flash files hosted at legitimate services, the more persistent the campaign is, the higher the chance that it will scale enough. This campaign in particular is mainly relying on rotation of tactics, namely different messages, different services and file extensions used in order to trick someone's friend into visiting the URL. With the number of users increasing, the most popular social networking sites are naturally going to be permanently under attacks from cybercriminals<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</a><br />
Despite that it's a single brand, namely the International Virus Research Lab that's introducing client-side exploits within it's portfolio of domains, the opportunity for abuse may be noticed by the rest of the brands pretty fast<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/08/exposing-indias-captcha-solving-economy.html">Exposing India’s CAPTCHA Solving Economy</a><br />
Taking into consideration the mentality surrounding a particular country's cybercriminals, how they think, how they operate, what do they define as an opportunity, and how much personal efforts are they willing to put into their campaigns, I wouldn't be surpised if a Russian vendor offering 100,000 bogus Gmail accounts for sale has in fact outsourcing the account registration process to Indian workers, paid them pocket change and is then reselling them ten to twenty times higher than the price he originally paid for them. <br />
<br />
The text based CAPTCHAs used at the major Internet portals and services, are so efficiently abused by this approach that continuing to use is directly undermining the trust these email providers and services often come with as granted<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VdcSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VdcSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2dvxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2dvxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hYvml"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hYvml" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YfcJl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YfcJl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WUVJL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WUVJL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jRCTL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jRCTL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KYkll"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KYkll" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/388609194" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 02:57:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/facebook malware campaigns">facebook malware campaigns</category>
      <category domain="http://securityratty.com/tag/usefulness pinch malware">usefulness pinch malware</category>
      <category domain="http://securityratty.com/tag/banker malware kits">banker malware kits</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/diy botnet kit">diy botnet kit</category>
      <category domain="http://securityratty.com/tag/distribute malware">distribute malware</category>
      <category domain="http://securityratty.com/tag/banker malware">banker malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/388609194/summarizing-augusts-threatscape.html">Summarizing August's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Modelling Air Traffic Control]]></title>
      <link>http://securityratty.com/article/7f9e569822e0521bce9615d70124032f</link>
      <guid>http://securityratty.com/article/7f9e569822e0521bce9615d70124032f</guid>
      <description><![CDATA[Today I will discussa general approach to model air traffic control (ATC)using our CEP/EP reference architecture which is an application of the mature JDL multisensor data fusion model
ATC is an...]]></description>
      <content:encoded><![CDATA[<p>Today I will discuss a general approach to model air traffic control (ATC) using our <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">CEP/EP reference architecture </a>which is an application of the mature <a href="http://www.data-fusion.org/article.php?sid=70" target="_blank">JDL multisensor data fusion model</a>.</p>
<p>ATC is an excellent working example of complex event processing.   Radar and GPS provide the basic sensory information to accurately track and trace the position of each aircraft in the area of responsibility (AOR) of a particular control tower/zone.     Naturally,  sensory information is preprocessed and formatted in such a way that the data can be processed upstream by multiple real-time applications.</p>
<p>Before we look at complex ATC scenarios, such as &#8220;potential collision&#8221; or &#8220;aircraft off approach vector&#8221; we must trace and trace individual objects, aircraft-objects, accurately with very high confidence.    In addition to tracking aircraft-objects, there is a database of information about the aircraft (ideally), such as make, model, age, range, passengers and other properties about the aircraft-object.      In addition, there is a state-model for each aircraft, for example the aircraft might be &#8220;on the ground&#8221;, &#8220;approaching the runway&#8221;, &#8220;cleared for takeoff&#8221;, &#8220;cruising altitude&#8221;, &#8220;approaching runway&#8221;, &#8220;final decent&#8221; etc.  </p>
<p>Tracking and tracing individual aircraft is what is generally referred to as &#8220;object refinement&#8221; in our CEP/EP reference architecture.   The reason we call this function &#8220;object refinement&#8221; is that system engineers are focused on optimizing the situational knowledge about individual objects.     Sometimes we refer to this function as &#8220;track and trace&#8221; because that is what we are doing to  each object in the model.  In Marc Adler&#8217;s recent <a href="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/" target="_blank">shoplifting scenario</a>, Marc was interested in tracking and tracing people in a store using imaging processing techniques to estimate their behavioral patterns.  In the same way, before we can process for scenarios such as &#8220;potential shoplifter&#8221; or &#8220;suspicious criminal gang activity&#8221; we must be able to accurately process (track and trace) individual object, such as people or merchandise.</p>
<p>Back to aircraft and ATC, the &#8220;complex event processing&#8221; begins when we are looking about object-object relationships, in this model, aircraft-to-aircraft, but this is an overly simplistic model, as we have not yet added (to our model) ground features (towers, buildings, power lines), weather (storm cells, wind) and other flying objects (known migratory bird paths, swarms of insects) to our simple model.  </p>
<p>Complex event processing occurs when we are processing multiple objects in our model looking for threats in real-time.     Practically speaking, all ATC applications are CEP applications.  This means that vendors and integrators who build ATC applications are also CEP vendors.   </p>
<blockquote><p>Editorial Note: CEP/EP has been around for a long time and was not recently invented in the past decade as some &#8220;inventors&#8221; would like for us to believe. </p></blockquote>
<p>As you can imagine, there is considerable &#8220;complex event processing&#8221; that goes on &#8220;behind the scenes&#8221; to provide air traffic controllers and pilots situational knowledge into the &#8220;friendly skies&#8221;.   As you might further imagine, the situation is more complex when the skies are &#8220;not so friendly&#8221;, for example, in air combat situations.   </p>
<p>Processing myriad objects is not the end of the processing &#8220;chain&#8221;.  For example, decisions are being made constantly about potential damage, alternative airports, and more.    In our reference model, we refer to this, generally speaking, as &#8220;impact assessment&#8221; because we must take an estimated detected complex event, for example &#8220;aircraft collision,&#8221; and estimate potential damage based on numerous factors such as, the amount of jet fuel in the aircrafts and the location of the aircrafts (over a large city or rural area, near a hospital and emergency services).   Regardless of the scenario, an impact assessment is normally required before optimal decisions can be made.</p>
<blockquote><p>This is true, by the way, for our <a href="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/" target="_blank">shoplifting example</a> (the impact is different if a piece of gum is stolen versus a $1,000,000 diamond necklace or weapons-grade nuclear material) and other scenarios and models.  Static data (information about objects) is required for accurate decision processing.  </p></blockquote>
<p>Impact assessment is not the end of the &#8220;knowledge chain&#8221;.    Decisions are constantly being made that effect resources.  For example, suggestion an alternative route for an aircraft is a resource management decision.    Turning on and off radar or switching to alternative tracking devices is a resource management function.  In our CEP/EP reference model (based on the JDL data fusion model), we call this &#8220;resource management&#8221;.   This function includes contacting emergency services and directing them to a potential crash location or sending out a message to instruct all aircraft to stay off a certain radio frequency.  Resource management is critical.</p>
<p>Our simple ATC model today is by no means complete, it just scratches the surface.  In fact, I have a very close friend, <a href="http://www.linkedin.com/pub/0/b45/b16" target="_blank">Mark Secrist</a>, who is a former Marine fighter pilot and currently a senior captain for <a href="http://www.aa.com" target="_blank">American Airlines</a>.   I have asked Mark to read this post and help me further refine this crude &#8220;laymans&#8221; ATC model (Thanks Mark!).</p>
]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 09:27:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/crude laymansatc model">crude laymansatc model</category>
      <category domain="http://securityratty.com/tag/state-model">state-model</category>
      <category domain="http://securityratty.com/tag/simple atc model">simple atc model</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/isconsiderable complex event">isconsiderable complex event</category>
      <category domain="http://securityratty.com/tag/overly simplistic model">overly simplistic model</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/simple model">simple model</category>
      <source url="http://www.thecepblog.com/2008/09/08/modelling-air-traffic-control/">Modelling Air Traffic Control</source>
    </item>
    <item>
      <title><![CDATA[The Commoditization of Anti Debugging Features in RATs]]></title>
      <link>http://securityratty.com/article/d357b72fd1cde8f737f42b6043955d6b</link>
      <guid>http://securityratty.com/article/d357b72fd1cde8f737f42b6043955d6b</guid>
      <description><![CDATA[Is it a Remote Administration Tool (RAT) or is it malware ? That's the rhetorical question , since RATs are not supposed to have built-in Virustotal submission for the newly generated server,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SL1nh-1oqdI/AAAAAAAACJc/FJtmUCHs730/s1600-h/anti_debugging_rat_malware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SL1nh-1oqdI/AAAAAAAACJc/m8B4yux3_5I/s200-R/anti_debugging_rat_malware.png" /></a>Is it a <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Administration Tool</a> (RAT) or is it <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">malware</a>? That's the <a href="http://ddanchev.blogspot.com/2007/08/shark-2-diy-malware.html">rhetorical question</a>, since <a href="http://ddanchev.blogspot.com/2007/12/shark-malware-new-versions-coming.html">RATs are not supposed</a> to have built-in Virustotal submission for the newly generated server, antivirus software "killing" and <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">firewall bypassing capabilities</a>.<br />
<br />
Taking a peek into some of commodity features aiming to make it harder to analyze the malware found in pretty much all the average DIY malware builders available at the disposal at the average script kiddies, one of the latest releases pitched as RAT while it's malware clearly indicates the commoditization and availability of such modules :<br />
<br />
" <i>- FWB (DLL Injection, The DLL is Never Written to Disk)<br />
&nbsp;- Decent Strong Traffic Encryption<br />
&nbsp;- Try to Unhook UserMode APIs<br />
&nbsp;- No Plugins/3rd Party Applications<br />
&nbsp;- 4 Startup Methods (Shell, Policies, ActiveX, UserInIt)<br />
&nbsp;- Set Maximum Connections<br />
&nbsp;- Built In File Binder<br />
&nbsp;- Multi Threaded Transfers<br />
&nbsp;- Anti Debugging (Anti VMware, Anti Sandboxie, Anti Norman Sandbox, Anti VirtualPC, Anti Anubis Sandbox, Anti CW Sandbox)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SL6CyJQUdnI/AAAAAAAACJk/b4Erkx13fpg/s1600-h/anti_debugging_rat_malware_stats.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SL6CyJQUdnI/AAAAAAAACJk/Lum7M48FdSQ/s200-R/anti_debugging_rat_malware_stats.png" /></a>Malware coders or "malware modulators"? With the currently emerging <a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">malware as a web service</a> toolkits porting common malware tools to the web, drag and drop web interfaces for malware building are <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">definitely in the works</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2qWlBL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2qWlBL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BQjJaL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BQjJaL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6b1sjl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6b1sjl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CVEqWl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CVEqWl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BzubfL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BzubfL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7ZXFYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7ZXFYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LhD8dl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LhD8dl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382311481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/anti">anti</category>
      <category domain="http://securityratty.com/tag/anti vmware">anti vmware</category>
      <category domain="http://securityratty.com/tag/anti norman sandbox">anti norman sandbox</category>
      <category domain="http://securityratty.com/tag/common malware tools">common malware tools</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/anti virtualpc">anti virtualpc</category>
      <category domain="http://securityratty.com/tag/malware coders">malware coders</category>
      <category domain="http://securityratty.com/tag/anti anubis sandbox">anti anubis sandbox</category>
      <category domain="http://securityratty.com/tag/malware modulators">malware modulators</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382311481/commoditization-of-anti-debugging.html">The Commoditization of Anti Debugging Features in RATs</source>
    </item>
    <item>
      <title><![CDATA[Facebook Malware Campaigns Rotating Tactics]]></title>
      <link>http://securityratty.com/article/62296c3643a587ae28183112d47c0996</link>
      <guid>http://securityratty.com/article/62296c3643a587ae28183112d47c0996</guid>
      <description><![CDATA[Trust is vital, and coming up with ways to multiply the trust factor is crucial for a successful malware campaign spreading across social networks . Excluding the publicly available malware modules...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVZhfsUzjI/AAAAAAAACH0/KTs0CyEnwvY/s1600-h/imageshack_flash_malware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVZhfsUzjI/AAAAAAAACH0/rKZA6eLgyX8/s200-R/imageshack_flash_malware.JPG" /></a>Trust is vital, and coming up with ways to multiply the trust factor is crucial for a successful <a href="http://vil.nai.com/vil/content/v_148955.htm">malware campaign spreading across social networks</a>. Excluding the publicly available malware modules for spreading across <a href="http://ddanchev.blogspot.com/2008/01/myspace-phishers-now-targeting-facebook.html">popular social networking sites</a>, using the presumably, <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">already phished accounts</a> for the foundation of the trust factor, the recent malware campaigns spreading across Facebook and Myspace are all about plain simple social engineering and a combination of tactics.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVdgajolNI/AAAAAAAACH8/p5BY3A1kV5s/s1600-h/facebook_flash_redirector.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVdgajolNI/AAAAAAAACH8/EyJLoN6fQxg/s200-R/facebook_flash_redirector.JPG" /></a>However, in between combining typosquatting and on purposely introducing longer subdomains impersonating a web application's directory structure, there are certain exceptions. Like this flash file hosted at ImageShack and spammed across Facebook profiles, which at a particular moment in the past few days used to redirect to client-side exploits served on behalf of a shady affiliate network that's apparently geolocating the campaigns based on where the visitors are coming from.<br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLVjHR-P9vI/AAAAAAAACIE/Cx_1BIXZ1kY/s1600-h/facebook_blogspot_obfuscation.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLVjHR-P9vI/AAAAAAAACIE/WPYZNHd88gs/s200-R/facebook_blogspot_obfuscation.JPG" /></a><b>img228.imageshack .us/img228/3238/gameonit4.swf</b> redirects to <b>ermacysoffer .info</b> - (216.52.184.243) and to <b>tracking.profitsource .net</b> (67.208.131.124) that's also responding to <b>p223in.linktrust .com</b> (67.208.131.124). Just for the record, we also have <b>halifax-cnline.co.uk</b> parked at 216.52.184.243, 69.64.145.229 and 69.64.145.229, known badware IPs related to previous fraudulent activity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVmUiQTZJI/AAAAAAAACIM/kpCUSo21ipU/s1600-h/facebook_malware_wall.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVmUiQTZJI/AAAAAAAACIM/d-GYBiTRhOI/s200-R/facebook_malware_wall.png" /></a>Moreover, cross-checking this campaign with <a href="http://www.bangky.net/blog/?p=257">another Facebook malware campaign</a> enticing users to visit <b>whitneyganykus.blogspot .com </b>where a javascript obfuscation redirects to <b>absvdfd87 .com</b> and from there to the already known <b>tracking.profitsource .net/redir.aspx?CID=9725&amp;AFID=28836&amp;DID=44292</b>, and given that absvdfd87.com is parked at the now known 69.64.145.229, we have a decent smoking gun connecting the two campaigns. <br />
<br />
Facebook is often advising that users stay away from weird URLs, does this mean ignoring <a href="http://ddanchev.blogspot.com/2008/06/imageshack-typosquatted-to-serve.html">ImageShack</a> and Blogspot altogether? The next malware campaign could be taking advantage of <a href="http://blog.trendmicro.com/malware-abuses-doubleclicks-open-redirects">DoubleClick</a> and <a href="http://www.virusbtn.com/news/2008/06_03a.xml?rss">AdSense redirectors</a> - for starters.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lkuMCK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lkuMCK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VN4CtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VN4CtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pjIc8k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pjIc8k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uO3Bmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uO3Bmk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gFnCxK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gFnCxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4tQCAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4tQCAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g7cSMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g7cSMk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/376254144" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:04:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/successful malware campaign">successful malware campaign</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/facebook malware campaign">facebook malware campaign</category>
      <category domain="http://securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/campaigns based">campaigns based</category>
      <category domain="http://securityratty.com/tag/trust factor">trust factor</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/376254144/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</source>
    </item>
    <item>
      <title><![CDATA[[OT rant] Are there any home WiFi routers that DON'T SUCK?]]></title>
      <link>http://securityratty.com/article/2110e94e736fbe5f32088eee09481bee</link>
      <guid>http://securityratty.com/article/2110e94e736fbe5f32088eee09481bee</guid>
      <description><![CDATA[Warning: rant ahead, and names named
When I'm not traveling, I like to work from home some days rather than endure the trek from Seattle to Redmond (although it's much better now that our own employee...]]></description>
      <content:encoded><![CDATA[<p><em>Warning: rant ahead, and names named.</em></p>  <p>When I'm not traveling, I like to work from home some days rather than endure the trek from Seattle to Redmond (although it's much better now that our own <a href="http://seattlepi.nwsource.com/business/332970_msftbus25.html" target="_blank">employee transit service</a> has expanded into my neighborhood -- the existence of which is sad commentary on the availability and reliability of Seattle's public transit companies).</p>  <p>This means, of course, that I need fast and stable network connections. Comcast with their PowerBoost is working very well for me. But I just can't find a decent wireless router at all. My Lenovo T61p (with Intel 4965abgn adapter) just won't stay connected to my D-Link DIR-628 and IT'S DRIVING ME CRAZY! (Yes, I've tried various driver versions, from both Lenovo and Intel.)</p>  <p>My house is in an area with a lot of wireless activity -- sometimes I can see nine or ten SSIDs. I'm running draft N on 2.4GHz (which occupies two non-adjacent channels, currently 1 and 4), and I suspect the problem is collision interference. I could shift the router to 5.2GHz, which I probably would help, but then the rest of the computers in my house won't connect. Why, you ask? Well get this: the DIR-628 is part of <a href="http://www.dlink.com/products/category.asp?cid=1&amp;sec=1#cid_103" target="_blank">D-Link's RangeBooster N family</a>. So I stayed in the family and got two DWA-542 adapters for the desktop computers. Yet they only do 2.4GHz! Silly me, I assumed that being in the same family means full support of the router's capabilities.</p>  <p>I'm very tempted to replace my router again -- and I'm thinking that the best option is to get one with dual radios. That way I can move my T61p to 5.2GHz and replace the desktop adapters, while still having single-channel 802.11b/g on 2.4GHz for the Wii and my PlayStation Portable.</p>  <p>Now my request: tell me about your experience with home routers. What do you really like, and why? What should I buy?</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3110595" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 20:12:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/decent wireless router">decent wireless router</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/router">router</category>
      <category domain="http://securityratty.com/tag/lenovo">lenovo</category>
      <category domain="http://securityratty.com/tag/d-link dir-628">d-link dir-628</category>
      <category domain="http://securityratty.com/tag/lenovo t61p">lenovo t61p</category>
      <category domain="http://securityratty.com/tag/intel">intel</category>
      <category domain="http://securityratty.com/tag/dir-628">dir-628</category>
      <category domain="http://securityratty.com/tag/intel 4965abgn adapter">intel 4965abgn adapter</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/08/22/ot-rant-are-there-any-home-wifi-routers-that-don-t-suck.aspx">[OT rant] Are there any home WiFi routers that DON'T SUCK?</source>
    </item>
    <item>
      <title><![CDATA[Guerilla Marketing for a Conspiracy Site]]></title>
      <link>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</link>
      <guid>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</guid>
      <description><![CDATA[An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for Alex Jones' infowars.com

Alex Jones is considered by many to be...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/7pb6K-ZlId8/s1600-h/infowars_echelon_guerilla_marketing.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/PY2_yw9n2-8/s200-R/infowars_echelon_guerilla_marketing.jpg" style="border: 0pt none ;" /></a>An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for <a href="http://infowars.com/alexjones.html">Alex Jones' infowars.com</a> :<br />
<br />
"<i>Alex Jones is considered by many to be the grandfather of what has come to be known as the 9/11 Truth Movement. <b>Jones predicted the 9/11 attack in a July 2001 television taping when he warned that the Globalists were going to attack New York and blame it on their asset Osama bin Laden.</b> Since 9/11 Jones has broken many of the stories which later became the foundation of the evidence that the government was involved.</i>"<br />
<br />
Sorry to disappoint, but as always, <a href="http://killtown.911review.org/lonegunmen.html">The Lone Gunmen were first to predict 9/11 in their "Pilot" episode</a>, originally aired on 03/04/2001, obviously <a href="http://www.youtube.com/watch?v=rIZ205ccX8M">several months before Alex Jones did</a>. How did they do it? By having a firm grasp of the obvious I guess.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hvjPGK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hvjPGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TBCXkK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TBCXkK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rLOaMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rLOaMk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6k2N4k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6k2N4k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ld6AqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ld6AqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TNX2FK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TNX2FK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E43dXk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E43dXk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/365022639" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:58:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alex jones">alex jones</category>
      <category domain="http://securityratty.com/tag/jones">jones</category>
      <category domain="http://securityratty.com/tag/asset osama bin">asset osama bin</category>
      <category domain="http://securityratty.com/tag/decent guerrilla">decent guerrilla</category>
      <category domain="http://securityratty.com/tag/truth movement">truth movement</category>
      <category domain="http://securityratty.com/tag/firm grasp">firm grasp</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/thousand words">thousand words</category>
      <category domain="http://securityratty.com/tag/predict">predict</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/365022639/guerilla-marketing-for-conspiracy-site.html">Guerilla Marketing for a Conspiracy Site</source>
    </item>
    <item>
      <title><![CDATA[Memo to the President]]></title>
      <link>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</link>
      <guid>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>Obama has a cyber security plan.</p>

<p>It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.</p>

<p>I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.</p>

<p>One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p></p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html">use it, too</a>.

<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> <a href="http://www.schneier.com/essay-025.html">software</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.schneier.com/essay-116.html">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  </p>

<p>Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  </p>

<p>Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.</p>

<p>If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.</p>

<p>Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> immensely in the long run.</p>

<p>Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.</p>

<p>Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.</p>

<p>And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0807">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LZGCXK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LZGCXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=56vyIK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=56vyIK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/memo_to_the_pre.html">Memo to the President</source>
    </item>
  </channel>
</rss>
