<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dupe]]></title>
    <link>http://securityratty.com/tag/dupe</link>
    <description></description>
    <pubDate>Thu, 27 Dec 2007 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Web mail rivals at risk of password-reset hacks]]></title>
      <link>http://securityratty.com/article/cca3dec0ad718b7243ddc9acb9acaa1e</link>
      <guid>http://securityratty.com/article/cca3dec0ad718b7243ddc9acb9acaa1e</guid>
      <description><![CDATA[Yahoo Mail isn't the only Web-based e-mail service that hackers could dupe into giving up passwords, the tactic that apparently was used to break into Alaska Gov. Sarah Palin's Yahoo account this...]]></description>
      <content:encoded><![CDATA[Yahoo Mail isn't the only Web-based e-mail service that hackers could dupe into giving up passwords, the tactic that apparently was used to break into Alaska Gov. Sarah Palin's Yahoo account this month.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f57faaa49652f1ca5e40515d5dba8b8b:enhiibMsLpo20BVNdSZuZtpNa%2BkBZ1qoC7utaESvXZkY%2Fm0ffM%2FyAzzeRcmgpjLKxrtBLmmZ4ggH'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:42b9784e6fb5894dcbf1bf85a389ee07:Z%2Badb30kFh6IZ6FZ9xx7RrgGMB8D1VmHoTX30Nb01eqP34xn4DbqehbdzHqFycZQuO1rPBPk9gYngw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a3b6076835c5889473c68730a9c22f91:qDxfGf2x%2FMdH41p4SssgjkTfqJ0Ix9BiLNPMf0p6UsYm74%2B1Pj%2F452NJBvYfhfei4yAHR9trI%2BzCQg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:77fa4ac62c174b0213a48be4951e286d:zOolIISCqKemyaHqj%2FIx8%2BmO5AQqsXmtqrJOmXiVMRTCnyruqJnmb92ijBz2GbdD0wI1cXW0GY%2FnWw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=bc1191df76eef43e59b0e9da72c34b2a"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=bc1191df76eef43e59b0e9da72c34b2a"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=bc1191df76eef43e59b0e9da72c34b2a" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yahoo account">yahoo account</category>
      <category domain="http://securityratty.com/tag/yahoo mail">yahoo mail</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/alaska gov">alaska gov</category>
      <category domain="http://securityratty.com/tag/e-mail service">e-mail service</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/dupe">dupe</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=bc1191df76eef43e59b0e9da72c34b2a">Web mail rivals at risk of password-reset hacks</source>
    </item>
    <item>
      <title><![CDATA[Adobe warns over bogus Flash Player installers]]></title>
      <link>http://securityratty.com/article/0cd03a9a36d57fc695be862421d65054</link>
      <guid>http://securityratty.com/article/0cd03a9a36d57fc695be862421d65054</guid>
      <description><![CDATA[Hackers are trying to dupe people into downloading malicious software labeled as Adobe Systems' Flash Player, prompting a warning from the...]]></description>
      <content:encoded><![CDATA[Hackers are trying to dupe people into downloading malicious software labeled as Adobe Systems' Flash Player, prompting a warning from the company.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=49518?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=49518?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/malicious software">malicious software</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/dupe people">dupe people</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://www.networkworld.com/news/2008/080508-adobe-warns-over-bogus-flash.html?fsrc=rss-security">Adobe warns over bogus Flash Player installers</source>
    </item>
    <item>
      <title><![CDATA[Researcher warns of unpatched iPhone bugs]]></title>
      <link>http://securityratty.com/article/b3c39dc4a0ed9f5af8bfa0453a8277a2</link>
      <guid>http://securityratty.com/article/b3c39dc4a0ed9f5af8bfa0453a8277a2</guid>
      <description><![CDATA[Security researcher Aviv Raff warned today that security flaws in the iPhone's e-mail and Web browser apps can be used by phishers to dupe users into visiting malicious sites or by spammers to flood...]]></description>
      <content:encoded><![CDATA[Security researcher Aviv Raff warned today that security flaws in the iPhone's e-mail and Web browser apps can be used by phishers to dupe users into visiting malicious sites or by spammers to flood the phone's in-box with junk mail.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=enOreu"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=enOreu" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/343963297" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web browser apps">web browser apps</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/junk mail">junk mail</category>
      <category domain="http://securityratty.com/tag/malicious sites">malicious sites</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/dupe users">dupe users</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/flood">flood</category>
      <category domain="http://securityratty.com/tag/in-box">in-box</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/343963297/article.do">Researcher warns of unpatched iPhone bugs</source>
    </item>
    <item>
      <title><![CDATA[Researcher warns of unpatched iPhone bugs]]></title>
      <link>http://securityratty.com/article/f1d3afecdfe0206d5b2d742adadfcdeb</link>
      <guid>http://securityratty.com/article/f1d3afecdfe0206d5b2d742adadfcdeb</guid>
      <description><![CDATA[Security vulnerabilities in the iPhone's e-mail application and Safari Web browser can be used by phishers to dupe users into visiting malicious sites or by spammers to flood the phone's inbox with...]]></description>
      <content:encoded><![CDATA[Security vulnerabilities in the iPhone's e-mail application and Safari Web browser can be used by phishers to dupe users into visiting malicious sites or by spammers to flood the phone's inbox with junk mail, a researcher warned Wednesday.]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safari web browser">safari web browser</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/junk mail">junk mail</category>
      <category domain="http://securityratty.com/tag/malicious sites">malicious sites</category>
      <category domain="http://securityratty.com/tag/researcher">researcher</category>
      <category domain="http://securityratty.com/tag/e-mail application">e-mail application</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/dupe users">dupe users</category>
      <category domain="http://securityratty.com/tag/inbox">inbox</category>
      <source url="http://www.networkworld.com/news/2008/072308-researcher-warns-of-unpatched-iphone.html?fsrc=rss-security">Researcher warns of unpatched iPhone bugs</source>
    </item>
    <item>
      <title><![CDATA[The Dutch Embassy in Moscow Serving Malware]]></title>
      <link>http://securityratty.com/article/696e02e105047294115b26db783dd05f</link>
      <guid>http://securityratty.com/article/696e02e105047294115b26db783dd05f</guid>
      <description><![CDATA[The Register reports that the Royal Netherlands Embassy in Moscow was serving malware to its visitors at the beginning of last week

Earlier this week, the site for the Netherlands Embassy in Russia...]]></description>
      <content:encoded><![CDATA[<a href="http://bp2.blogger.com/_wICHhTiQmrA/R5487bWhg2I/AAAAAAAABVg/MUXC5GazZfQ/s1600-h/dutch_embassy_moscow.jpg"><img id="BLOGGER_PHOTO_ID_5160629214665343842" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R5487bWhg2I/AAAAAAAABVg/MUXC5GazZfQ/s200/dutch_embassy_moscow.jpg" border="0" /></a>The Register reports that the <a href="http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/">Royal Netherlands Embassy in Moscow was serving malware</a> to its visitors at the beginning of last week :<br /><br />"<em>Earlier this week, the site for the Netherlands Embassy in Russia was caught serving a script that tried to dupe people into installing software that made their machines part of a botnet, according to Ofer Elzam, director of product management for eSafe, a business unit of Aladdin that blocks malicious web content from its customers' networks.</em>"<br /><br />Let's be a little more descriptive. The only IP that was included in the IFRAME was <strong>68.178.194.64/tab.php</strong> which was then forwarding to <strong>68.178.194.64/w/wtsin.cgi?s=z</strong>. ip-68-178-194-64.ip.secureserver.net (also responding to <strong>lmifsp.com</strong> and <strong>foxbayrental.com</strong>) has been down as of 22 Jan 2008 18:56:38 GMT, but apparantly it was also used in several other malware embedded attacks. For instance, the IFRAME is currently active at <strong>restorants.ru</strong>. The secondary IFRAME is a redirector script in a traffic management script that can load several different URLs, to both, generate fake visits to certain sites that are paying for this, and a live exploit URL as it happens in between.<br /><br />Historical preservation of actionable intelligence on who's what and what's when is a necessity. Here are for instance two far more in-depth assessments given the exploits URLs were still alive back then, discussing the malware embedded at the sites of the <a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate in St. Petersburg</a>, and the <a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in the U.K</a>.<br /><br /><strong>Related posts:</strong><br /><a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC ActiveX Code Execution Exploit Still in the Wild</a><br /><a href="http://ddanchev.blogspot.com/2008/01/malware-serving-exploits-embedded-sites.html">Malware Serving Exploits Embedded Sites as Usual</a><br /><a href="http://ddanchev.blogspot.com/2008/01/massive-realplayer-exploit-embedded.html">Massive RealPlayer Exploit Embedded Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/10/portfolio-of-malware-embedded-magazines.html">A Portfolio of Malware Embedded Magazines</a><br /><a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">The New Media Malware Gang</a><br /><a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/11/another-massive-embedded-malware-attack.html">Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">I See Alive IFRAMEs Everywhere</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere-part-two.html">I See Alive IFRAMEs Everywhere - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">Have Your Malware in a Timely Fashion</a><br /><a href="http://ddanchev.blogspot.com/2007/12/cached-malware-embedded-sites.html">Cached Malware Embedded Sites</a><br /><a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><br /><a href="http://ddanchev.blogspot.com/2007/11/malware-serving-online-casinos.html">Malware Serving Online Casinos</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LwBeeCD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LwBeeCD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Syfx3VD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Syfx3VD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G0EOwed"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G0EOwed" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2n8h4Kd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2n8h4Kd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8JwVZKD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8JwVZKD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3W4Ad2D"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3W4Ad2D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FB7htJd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FB7htJd" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/224828351" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jan 2008 13:07:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/redirector script">redirector script</category>
      <category domain="http://securityratty.com/tag/script">script</category>
      <category domain="http://securityratty.com/tag/alive iframes">alive iframes</category>
      <category domain="http://securityratty.com/tag/royal netherlands embassy">royal netherlands embassy</category>
      <category domain="http://securityratty.com/tag/alive">alive</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/224828351/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Firefox hit with spoofing bug]]></title>
      <link>http://securityratty.com/article/16f28482e9e8121ae498c9d7cb707d19</link>
      <guid>http://securityratty.com/article/16f28482e9e8121ae498c9d7cb707d19</guid>
      <description><![CDATA[A serious flaw in how Firefox handles logons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said...]]></description>
      <content:encoded><![CDATA[A serious flaw in how Firefox handles logons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday.]]></content:encoded>
      <pubDate>Wed, 02 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firefox handles logons">firefox handles logons</category>
      <category domain="http://securityratty.com/tag/noted security researcher">noted security researcher</category>
      <category domain="http://securityratty.com/tag/identity thieves">identity thieves</category>
      <category domain="http://securityratty.com/tag/dupe users">dupe users</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/wednesday">wednesday</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <source url="http://www.networkworld.com/news/2008/010308-firefox-hit-with-spoofing.html?fsrc=rss-security">Firefox hit with spoofing bug</source>
    </item>
    <item>
      <title><![CDATA[Malware honeypots wait for '08 ]]></title>
      <link>http://securityratty.com/article/5e23a6265f976d595622dd74f160eba4</link>
      <guid>http://securityratty.com/article/5e23a6265f976d595622dd74f160eba4</guid>
      <description><![CDATA[An innovative malware honeypot project backed by a leading consortium of IT security experts is preparing to re-launch its global sensor network after Jan. 1 in an effort to dupe more cybercriminals...]]></description>
      <content:encoded><![CDATA[An innovative malware honeypot project backed by a leading consortium of IT security experts is preparing to re-launch its global sensor network after Jan. 1 in an effort to dupe more cybercriminals into handing over information about their latest attack methods.]]></content:encoded>
      <pubDate>Tue, 01 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global sensor network">global sensor network</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/attack methods">attack methods</category>
      <category domain="http://securityratty.com/tag/re-launch">re-launch</category>
      <category domain="http://securityratty.com/tag/effort">effort</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/cybercriminals">cybercriminals</category>
      <category domain="http://securityratty.com/tag/dupe">dupe</category>
      <category domain="http://securityratty.com/tag/jan">jan</category>
      <source url="http://www.networkworld.com/news/2008/010208-malware-honeypots.html?fsrc=rss-security">Malware honeypots wait for '08 </source>
    </item>
    <item>
      <title><![CDATA[Hackers quickly move to exploit Bhutto assassination]]></title>
      <link>http://securityratty.com/article/2bca4e5da6b76bed5f00ad2fee0b4914</link>
      <guid>http://securityratty.com/article/2bca4e5da6b76bed5f00ad2fee0b4914</guid>
      <description><![CDATA[Within hours of yesterday's assassination of former Pakistani Prime Minister Benazir Bhutto, malware makers exploited the breaking news to dupe users into downloading attack code, security researchers...]]></description>
      <content:encoded><![CDATA[Within hours of yesterday's assassination of former Pakistani Prime Minister Benazir Bhutto, malware makers exploited the breaking news to dupe users into downloading attack code, security researchers said Friday.]]></content:encoded>
      <pubDate>Thu, 27 Dec 2007 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack code">attack code</category>
      <category domain="http://securityratty.com/tag/assassination">assassination</category>
      <category domain="http://securityratty.com/tag/dupe users">dupe users</category>
      <category domain="http://securityratty.com/tag/malware makers">malware makers</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/hours">hours</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/yesterday">yesterday</category>
      <source url="http://www.networkworld.com/news/2007/122807-hackers-quickly-move-to-exploit.html?fsrc=rss-security">Hackers quickly move to exploit Bhutto assassination</source>
    </item>
  </channel>
</rss>
