<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ebay]]></title>
    <link>http://securityratty.com/tag/ebay</link>
    <description></description>
    <pubDate>Fri, 29 Aug 2008 13:03:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Skype messages being monitored in China, group says]]></title>
      <link>http://securityratty.com/article/8ea62ef4d5ac26dbb1cfc17339756501</link>
      <guid>http://securityratty.com/article/8ea62ef4d5ac26dbb1cfc17339756501</guid>
      <description><![CDATA[Tom-Skype, a joint venture in China between eBay's Skype unit and Tom Online, has been known to operate a text filter on text chats, but a new report says that the data is stored insecurely and the...]]></description>
      <content:encoded><![CDATA[Tom-Skype, a joint venture in China between eBay's Skype unit and Tom Online, has been known to operate a text filter on text chats, but a new report says that the data is stored insecurely and the text messages and records containing personal data can be easily accessed.]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/tom online">tom online</category>
      <category domain="http://securityratty.com/tag/joint venture">joint venture</category>
      <category domain="http://securityratty.com/tag/skype unit">skype unit</category>
      <category domain="http://securityratty.com/tag/text chats">text chats</category>
      <category domain="http://securityratty.com/tag/text filter">text filter</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/text messages">text messages</category>
      <source url="http://www.networkworld.com/news/2008/100208-skype-messages-being-monitored-in.html?fsrc=rss-security">Skype messages being monitored in China, group says</source>
    </item>
    <item>
      <title><![CDATA[MI6 Camera -- Including Secrets -- Sold on eBay]]></title>
      <link>http://securityratty.com/article/787b3bf3fc7e8ad2d3585c7a4f37ed35</link>
      <guid>http://securityratty.com/article/787b3bf3fc7e8ad2d3585c7a4f37ed35</guid>
      <description><![CDATA[I wish I'd known : A 28-year-old delivery man from the UK who bought a Nikon Coolpix camera for about $31 on eBay got more than he bargained for when the camera arrived with top secret information...]]></description>
      <content:encoded><![CDATA[<p>I <a href="http://www.techcrunch.com/2008/09/30/top-secret-mi6-camera-sold-to-the-highest-bidder-on-ebay/">wish</a> I'd <a href="http://gizmodo.com/5056749/mi6-camera-with-secret-images-bought-on-ebay-for-30">known</a>:</p>

<blockquote>A 28-year-old delivery man from the UK who bought a Nikon Coolpix camera for about $31 on eBay got more than he bargained for when the camera arrived with top secret information from the UK's MI6 organization.

<p>Allegedly sold by one of the clandestine organization's agents, the camera contained named al-Qaeda cells, names, images of suspected terrorists and weapons, fingerprint information, and log-in details for the Secret Service's computer network, containing a "Top Secret" marking.</blockquote></p>

<p>He turned the camera in to the police.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=T8c9M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=T8c9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CejeM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CejeM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 09:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/camera">camera</category>
      <category domain="http://securityratty.com/tag/nikon coolpix camera">nikon coolpix camera</category>
      <category domain="http://securityratty.com/tag/top secret">top secret</category>
      <category domain="http://securityratty.com/tag/top secret information">top secret information</category>
      <category domain="http://securityratty.com/tag/named al-qaeda cells">named al-qaeda cells</category>
      <category domain="http://securityratty.com/tag/ebay">ebay</category>
      <category domain="http://securityratty.com/tag/clandestine organization">clandestine organization</category>
      <category domain="http://securityratty.com/tag/secret service">secret service</category>
      <category domain="http://securityratty.com/tag/fingerprint information">fingerprint information</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/mi6_camera_--_i.html">MI6 Camera -- Including Secrets -- Sold on eBay</source>
    </item>
    <item>
      <title><![CDATA[Camera sold on eBay contained MI6 files]]></title>
      <link>http://securityratty.com/article/a4ff3f889939cb0fde84cdb23ce6fc35</link>
      <guid>http://securityratty.com/article/a4ff3f889939cb0fde84cdb23ce6fc35</guid>
      <description><![CDATA[The eBay sale of digital camera said to have contained MI6 images of terror suspects is being investigated by...]]></description>
      <content:encoded><![CDATA[The eBay sale of digital camera said to have contained MI6 images of terror suspects is being investigated by police. ]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 15:20:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mi6 images">mi6 images</category>
      <category domain="http://securityratty.com/tag/ebay sale">ebay sale</category>
      <category domain="http://securityratty.com/tag/terror suspects">terror suspects</category>
      <category domain="http://securityratty.com/tag/digital camera">digital camera</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <source url="http://digg.com/security/Camera_sold_on_eBay_contained_MI6_files">Camera sold on eBay contained MI6 files</source>
    </item>
    <item>
      <title><![CDATA[MI6 Terror Suspects Pictures Found on eBay Camera]]></title>
      <link>http://securityratty.com/article/2d0f3091e0214325eca7d4ee348fc684</link>
      <guid>http://securityratty.com/article/2d0f3091e0214325eca7d4ee348fc684</guid>
      <description><![CDATA[The types of data breaches in the UK never seize to amaze me. If you ever need proof that security is a People, Process and Technology problem then stories like this serve as a good reminder....]]></description>
      <content:encoded><![CDATA[The types of data breaches in the UK never seize to amaze me. If you ever need proof that security is a People, Process and Technology problem then stories like this serve as a good reminder. 
http://www.thisislondon.co.uk/standard/article-23561908-details/&#8217;MI6&#8217;s+t/error+snaps%27+on+eBay+camera/article.do
Thanks to Daniel for posting on a list&#8230;&#8230;
&#160;&#160;&#160;&#160;&#160;&#160;     ]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 07:18:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://securityratty.com/tag/daniel">daniel</category>
      <category domain="http://securityratty.com/tag/serve">serve</category>
      <category domain="http://securityratty.com/tag/types">types</category>
      <category domain="http://securityratty.com/tag/reminder">reminder</category>
      <category domain="http://securityratty.com/tag/thisislondon">thisislondon</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/proof">proof</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://securitybuddha.com/2008/09/30/mi6-terror-suspects-pictures-found-on-ebay-camera/">MI6 Terror Suspects Pictures Found on eBay Camera</source>
    </item>
    <item>
      <title><![CDATA[Merged Banks' Names Already Cyber-squatted]]></title>
      <link>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</link>
      <guid>http://securityratty.com/article/2e490f1861f13ae3554a91a0487bf943</guid>
      <description><![CDATA[Domain name speculators are already buying up names of recently merged banks , according to the BBC. In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman...]]></description>
      <content:encoded><![CDATA[<a href="http://news.bbc.co.uk/2/hi/technology/7621647.stm">Domain name speculators are already buying up names of recently merged banks</a>, according to the BBC.

In fact, names are being bought even in the speculation of sales. Earlier this week, as Lehman Brothers was failing and rumors circulated as to who might buy them, the names barclayslehman.com, hsbclehman.com, hsbclehmanbrothers.com and bofalehman.com were all reserved. The buyers are in the Netherlands and New York City, and one domain is registered anonymously.

The same phenomenon is occurring in the U.K., where speculation surrounding the merger of Lloyds TSB with HBOS led someone to buy lloydstsbhbos.com and hboslloydstsb.com.

Some of these domains include a notice that they are for sale. The person who bought bankofamericamerrilllynch.com went further, including a link to an eBay auction where the domain is for sale with a $1,500 reserve. About two days into the auction, no bids have been made. People who reserve domain names with clear trademarks in them routinely lose them in arbitration cases brought, under <a href="http://www.icann.org/en/udrp/#udrp">ICANN's Uniform Domain Name Dispute Resolution Policy</a>, by the trademark holders.
<p><a href="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/a"><img src="http://feedads.googleadservices.com/~a/LRPJk9bZbQjdjTpzsK54lwxP7q0/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/HSwU0TmTLAk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/reserve domain names">reserve domain names</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/uniform domain">uniform domain</category>
      <category domain="http://securityratty.com/tag/reserve">reserve</category>
      <category domain="http://securityratty.com/tag/names barclayslehman">names barclayslehman</category>
      <category domain="http://securityratty.com/tag/dispute resolution policy">dispute resolution policy</category>
      <category domain="http://securityratty.com/tag/auction">auction</category>
      <category domain="http://securityratty.com/tag/ebay auction">ebay auction</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/HSwU0TmTLAk/merged_banks_names_already_cybersquatted.html">Merged Banks' Names Already Cyber-squatted</source>
    </item>
    <item>
      <title><![CDATA[Fun Financial News Economic Meltdown Overdue?]]></title>
      <link>http://securityratty.com/article/7157e87c54b6bdfad599ca7e480ffb51</link>
      <guid>http://securityratty.com/article/7157e87c54b6bdfad599ca7e480ffb51</guid>
      <description><![CDATA[Are we in the biggest and best economic recession-turned-depression since the 1930s
If you look at the news, youll see layoffs, buyouts, bankruptcy, going-out-of-business there are a lot of companies...]]></description>
      <content:encoded><![CDATA[<p>Are we in the biggest and best economic recession-turned-depression since the 1930s?</p>
<p>If you look at the news, you&#8217;ll see layoffs, buyouts, bankruptcy, going-out-of-business&#8211; there are a lot of companies in trouble right now</p>
<p><a rel="nofollow" target="_blank" href="http://richi.co.uk/blog/2008/09/bye-bye-ebay.html">Ebay</a> &#8212; laying off around 1500 workers.</p>
<p><a rel="nofollow" target="_blank" href="http://www.pdnonline.com/pdn/content_display/esearch/e3ic20afe7664ada9ef8f01ffe7285b913e">Corbis</a> &#8212; Cutting 170 Jobs, as its start-up rival <a rel="nofollow" target="_blank" href="http://www.pdnonline.com/pdn/content_display/esearch/e3iaf02e0820238924b90d20260893cac71">Photoshelter </a>closes its doors.</p>
<p><a rel="nofollow" target="_blank" href="http://www.forbes.com/feeds/ap/2008/09/15/ap5427610.html">Washington Mutual </a>in trouble</p>
<p><a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/services/outsourcing/showArticle.jhtml?articleID=210601748">HP </a>cutting 24,600 jobs</p>
<p><a rel="nofollow" target="_blank" href="http://uk.reuters.com/article/bankingfinancial-SP/idUKN1551539520080915">B of A </a>&#8211; stocks tumble as the bank buys Merrill Lync</p>
<p><a rel="nofollow" target="_blank" href="http://www.bloomberg.com/apps/news?pid=20601039&amp;refer=columnist_pauly&amp;sid=a.o3AnmqPqwU">Fannie Mae and Freddie Mac</a> taken over by the Feds a couple weeks back</p>
<p>I&#8217;ve read in many places that even though the economy is headed under, tech is still going strong. But with fewer jobs overall and less confidence, tech is sure to take a tumble as well. These are tough times that aren&#8217;t going to be solved by going out and buying buttons for your favorite political candidate.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 13:00:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fewer jobs">fewer jobs</category>
      <category domain="http://securityratty.com/tag/jobs">jobs</category>
      <category domain="http://securityratty.com/tag/tumble">tumble</category>
      <category domain="http://securityratty.com/tag/stocks tumble">stocks tumble</category>
      <category domain="http://securityratty.com/tag/freddie mac">freddie mac</category>
      <category domain="http://securityratty.com/tag/economic">economic</category>
      <category domain="http://securityratty.com/tag/favorite political">favorite political</category>
      <category domain="http://securityratty.com/tag/tough times">tough times</category>
      <category domain="http://securityratty.com/tag/fannie mae">fannie mae</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/393695005/">Fun Financial News Economic Meltdown Overdue?</source>
    </item>
    <item>
      <title><![CDATA[Contest: Cory Doctorow's Cipher Wheel Rings]]></title>
      <link>http://securityratty.com/article/5bf9715088e83f021dd3a8a86d47bb52</link>
      <guid>http://securityratty.com/article/5bf9715088e83f021dd3a8a86d47bb52</guid>
      <description><![CDATA[Cory Doctorow wanted a secret decoder wedding ring, and he asked me to help design it. I wanted something more than the standard secret decoder ring , so this is what I asked for: &quot;I want each wheel...]]></description>
      <content:encoded><![CDATA[<p>Cory Doctorow wanted a secret decoder wedding ring, and he asked me to help design it.  I wanted something more than the standard <a href="http://en.wikipedia.org/wiki/Secret_decoder_ring">secret decoder ring</a>, so this is what I asked for: "I want each wheel to be the alphabet, with each letter having either a dot above, a dot below, or no dot at all.  The first wheel should have alternating above, none, below.  The second wheel should be the repeating sequence of above, above, none, none, below, below.  The third wheel should be the repeating sequence of above, above, above, none, none, none, below, below, below."  (I know it sounds confusing, but <a href="http://www.flickr.com/photos/doctorow/2816467273/">here's</a> a chart.)</p>

<p>So that's what he asked for, and that's what <a href="http://www.flickr.com/photos/doctorow/2817314740/">he got</a>.  And now it's time to create some cryptographic applications for the rings.  Cory and I are holding an open contest for the cleverest application.</p>

<p>I don't think we can invent any encryption algorithms that will survive computer analysis -- there's just not enough entropy in the system -- but we can come up with some clever pencil-and-paper ciphers that will serve them well if they're ever stuck back in time.  And there are certainly other  cryptographic uses for the rings.</p>

<p>Here's a way to use the rings as a password mnemonic:  First, choose a two-letter key.  Align the three wheels according to the key.  For example, if the key is "EB" for eBay, align the three wheels AEB.  Take the common password "PASSWORD" and encrypt it.  For each letter, find it on the top wheel.  Count one letter to the left if there is a dot over the letter, and one letter to the right if there is a dot under it.  Take that new letter and look at the letter below it (in the middle wheel).  Count two letters to the left if there is a dot over it, and two letters to the right if there is a dot under it.  Take that new letter (in the middle wheel), and look at the letter below it (in the lower wheel).  Count three letters to the left if there is a dot over it, and three letters to the right if there is a dot under it.  That's your encrypted letter.  Do that with every letter to get your password.</p>

<p>"PASSWORD" and the key "EB" becomes "NXPPVVOF."</p>

<p>It's not very good; can anyone see why?  (Ignore for now whether or not publishing this on a blog makes it no longer secure.)</p>

<p>How can I do that better?  What else can we do with the rings?  Can we incorporate other elements -- a deck of playing cards as in <a href="http://www.schneier.com/solitaire.html">Solitaire</a>, different-sized coins to make the system more secure?</p>

<p>Post your contest entries as comments to <a href="http://www.boingboing.net/2008/09/05/help_design_a_cipher.html">Cory's blog post</a> -- you can post them here, but they're not going to count as contest submissions --  or send them to <a href="mailto:cryptocontest@craphound.com">cryptocontest@craphound.com</a>.  Deadline is October 1st.  </p>

<p>Good luck, and have fun with this. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XHAZL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XHAZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vFg0L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vFg0L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 08:01:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wheel">wheel</category>
      <category domain="http://securityratty.com/tag/letter">letter</category>
      <category domain="http://securityratty.com/tag/two-letter key">two-letter key</category>
      <category domain="http://securityratty.com/tag/middle wheel">middle wheel</category>
      <category domain="http://securityratty.com/tag/dot">dot</category>
      <category domain="http://securityratty.com/tag/cory doctorow">cory doctorow</category>
      <category domain="http://securityratty.com/tag/cory">cory</category>
      <category domain="http://securityratty.com/tag/rings">rings</category>
      <category domain="http://securityratty.com/tag/top wheel">top wheel</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/contest_cory_do.html">Contest: Cory Doctorow's Cipher Wheel Rings</source>
    </item>
    <item>
      <title><![CDATA[RNC]]></title>
      <link>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</link>
      <guid>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</guid>
      <description><![CDATA[Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and Bruce Schneier to even get a cup of coffee down there. Here is the round...]]></description>
      <content:encoded><![CDATA[<p>Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and <a href="http://geekz.co.uk/schneierfacts/">Bruce Schneier</a> to even get a cup of coffee down there. Here is the round up from <a href="http://www.economist.com/blogs/freeexchange/2008/09/above_the_fold_251.cfm">The Economist&#39;s blog</a></p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">You&#39;ll have to pardon me this morning if the round-up seems a bit off. I&#39;m still a little stunned at the spectacle of an arena full of (seemingly sober and sane) adults chanting, &quot;Drill, baby, drill&quot;.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">So let&#39;s see, what&#39;s in the news? Well, last night Republicans trotted out a Massachusetts venture capitalist and governor, the former mayor of New York City, former executives of eBay and HP, and an Alaskan neophyte pol who as mayor of a small town delivered $4,000 in federal pork for every man, woman, and child, in railing against coastal elites and Washington politics, while supporting a candidate who&#39;s been in the Senate for 26 years.</span></p></blockquote>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 07:34:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts venture capitalist">massachusetts venture capitalist</category>
      <category domain="http://securityratty.com/tag/alaskan neophyte pol">alaskan neophyte pol</category>
      <category domain="http://securityratty.com/tag/washington politics">washington politics</category>
      <category domain="http://securityratty.com/tag/bruce schneier">bruce schneier</category>
      <category domain="http://securityratty.com/tag/rnc">rnc</category>
      <category domain="http://securityratty.com/tag/federal pork">federal pork</category>
      <category domain="http://securityratty.com/tag/drill">drill</category>
      <category domain="http://securityratty.com/tag/round-up">round-up</category>
      <category domain="http://securityratty.com/tag/pretty tight">pretty tight</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/rnc.html">RNC</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kits are Faddish]]></title>
      <link>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</link>
      <guid>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</guid>
      <description><![CDATA[For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/u4h7TuozLDI/s1600-h/copycat_web_malware_exploitation_kit.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/H8HQ-QzSBfg/s200-R/copycat_web_malware_exploitation_kit.gif" /></a>For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained several moths later -- with all the related and royalty free updates coming with it, there are always the copycat malware kits like this one offered for $100.<br />
<br />
Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally <a href="http://blogs.zdnet.com/security/?p=1598">ignored the possibility of their kits leaking to the general public</a>, or copies of the kits ending up as a bargain in particular underground deal where the once highly exclusive kit was offered as a bonus.<br />
<br />
"Me too" web malware kits were a faddish way to enjoy the popularity of web malware kits like MPack and Icepack and try to cash in on that popularity by coming up average kits lacking any significant differentiation factors in the process. But just like the original and proprietary kits, whose authors didn't envision the long term growth strategy of integrating different services into their propositions or the kits themselves, the authors of copycat malware kits didn't bother considering the lack of long-term growth strategy for their releases. Branding in respect to releasing a Firepack malware kit to compete with Icepack which was originally released to compete with Mpack, has failed to achieve the desired results as well.<br />
<br />
And with malware kits now a commodity, and underground vendors excelling in a particular practice with the long term objective to vertically integrate in their area of expertise -- think spammers offering localization of messages into different languages and segmented email databases from a specific country -- would we witness the emergence of <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">managed cybercrime services</a> charging a premium for providing fresh dumps of credit card numbers, PayPal, Ebay accounts or whatever the buyer is requesting?<br />
<br />
That may well be the case in the long term.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jUilFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jUilFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LiAKxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LiAKxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GnpH1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GnpH1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bjjwel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bjjwel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NAlZrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NAlZrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybk3ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybk3ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0j6X0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0j6X0l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382290326" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/copycat malware kits">copycat malware kits</category>
      <category domain="http://securityratty.com/tag/proprietary kits">proprietary kits</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/long-term growth strategy">long-term growth strategy</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382290326/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</source>
    </item>
    <item>
      <title><![CDATA[Exposing Indias CAPTCHA Solving Economy]]></title>
      <link>http://securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</link>
      <guid>http://securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</guid>
      <description><![CDATA[Are you a Human?&quot; - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/6poURrjAkGI/s1600-h/india_captcha_breakers9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/HZ5BF3hc6nY/s200-R/india_captcha_breakers9.JPG" /></a>"Are you a Human?" - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based authentication in the face of human CAPTCHA solvers, seems to have evolved into a booming economy in India during the past 12 months, with thousands of people involved.<br />
<br />
The following article - "<a href="http://blogs.zdnet.com/security/?p=1835">Inside India’s CAPTCHA solving economy</a>" aims to expose legitimate data entry workers, whose business models and techniques are in fact used by Russian cybercriminals not only for personal phishing, spamming and malware spreading purposes, but also, to resell the bogus accounts and earn a premium in the process :<br />
<br />
"<i>No CAPTCHA can survive a human that’s receiving financial incentives for solving it, and with an army of low-wagedIndia CAPTCHA breakers human CAPTCHA solvers officially in the business of “data processing” while earning a mere $2 for solving a thousand CAPTCHA’s, I’m already starting to see evidence of consolidation between India’s major CAPTCHA solving companies. The consolidation logically leading to increased bargaining power, is resulting in an international franchising model recruiting data processing workers empowered with do-it-yourself CAPTCHA syndication web based kits, API keys, and thousands of proxies to make their work easier, and the process more efficient.</i>"<br />
<br />
Cybercrime is just as outsourceable as CAPTCHA breaking is these days.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a><br />
<a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing </a><br />
<a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers</a><br />
<a href="http://blogs.zdnet.com/security/?p=1232">Microsoft’s CAPTCHA successfully broken</a><br />
<a href="http://ddanchev.blogspot.com/2007/03/vladuzs-ebay-captcha-populator.html">Vladuz's Ebay CAPTCHA Populator</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/spammers-and-phishers-breaking-captchas.html">Spammers and Phishers Breaking CAPTCHAs</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/diy-captcha-breaking-service.html">DIY CAPTCHA Breaking Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/which-captcha-do-you-want-to-decode.html">Which CAPTCHA Do You Want to Decode Today?</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HJ3QtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HJ3QtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m6hgDK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m6hgDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0TXeOk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0TXeOk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4jwe6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4jwe6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9clPFK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9clPFK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JCXayK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JCXayK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5ic3Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5ic3Pk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/378395296" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 13:03:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/captcha">captcha</category>
      <category domain="http://securityratty.com/tag/microsofts captcha">microsofts captcha</category>
      <category domain="http://securityratty.com/tag/indias major captcha">indias major captcha</category>
      <category domain="http://securityratty.com/tag/hotmails captcha">hotmails captcha</category>
      <category domain="http://securityratty.com/tag/unbreakable captcha">unbreakable captcha</category>
      <category domain="http://securityratty.com/tag/human captcha solvers">human captcha solvers</category>
      <category domain="http://securityratty.com/tag/human">human</category>
      <category domain="http://securityratty.com/tag/inside indias captcha">inside indias captcha</category>
      <category domain="http://securityratty.com/tag/captcha based authentication">captcha based authentication</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/378395296/exposing-indias-captcha-solving-economy.html">Exposing Indias CAPTCHA Solving Economy</source>
    </item>
  </channel>
</rss>
