<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: email-address]]></title>
    <link>http://securityratty.com/tag/email-address</link>
    <description></description>
    <pubDate>Wed, 29 Oct 2008 11:08:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-11-20 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</link>
      <guid>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</guid>
      <description><![CDATA[Got SIEM? - Part IV eIQviews Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blog.eiqnetworks.com/2008/11/20/got-siem-part-iv/">Got SIEM? - Part IV &laquo; eIQviews</a><br/>
Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior or policy violations before they have a chance to affect systems and data.</li>
<li><a href="http://siemblog.com/?p=13">SIEM Blog &raquo; Unrestricted Data Collection for Maximum Compliance and Forensic Visibility</a></li>
<li><a href="http://beastorbuddha.com/2008/11/19/so-we-own-your-client-database-and-everything-important-to-you/">Beast Or Buddha &raquo; Blog Archive &raquo; So we own your client database and everything important to you&hellip;</a><br/>
Web Developer: “Just because you can do that doesn’t mean we have a major problem like you say it is. It’s just you that did it!”
SG dude: “Well more than likely, others have….we didn’t do anything fancy…”.
Web Developer: “Well nothing has ever happened so it’s just you guys!”
SG dude: “You have no logging”.
Web Developer: “We’ve never been hacked!”</li>
<li><a href="http://ondlp.com/2008/10/13/my-wife-finally-knows-what-i-do/">On Data Loss Prevention (DLP) &raquo; My Wife Finally Knows What I Do</a></li>
<li><a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">The Two Kinds Of Security Threats, And How They Affect Your Life | securosis.com</a><br/>
We get money for noisy threats, and get called paranoid freaks for trying to prevent quiet threats (which can still lose our organizations a boatload of money, but don’t interfere with the married CEO’s ability to flirt with the new girl in marketing over email).</li>
<li><a href="http://www.csoonline.com/article/461422/Marcus_Ranum_on_Network_Security">Marcus Ranum on Network Security - CSO Online - Security and Risk</a><br/>
The real best practices have been the same since the 1970s: know where your data is, who has access to what, read your logs, guard your perimeter, minimize complexity, reduce access to &quot;need only&quot; and segment your networks.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460414088" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data collection">data collection</category>
      <category domain="http://securityratty.com/tag/web developer">web developer</category>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/siem blog">siem blog</category>
      <category domain="http://securityratty.com/tag/security threats">security threats</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460414088/anton18">Links for 2008-11-20 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Just Love This: Noisy vs Quiet from Rich]]></title>
      <link>http://securityratty.com/article/5b13607c4ea355a79b9b366f3adb21fd</link>
      <guid>http://securityratty.com/article/5b13607c4ea355a79b9b366f3adb21fd</guid>
      <description><![CDATA[OMG, some people (usually ex-Gartner... for whatever mystical reason) have this uncanny ability to present information in a way that just triggers an avalanche of insight. Here is an example: &quot; The...]]></description>
      <content:encoded><![CDATA[OMG, some people (usually ex-Gartner... for whatever mystical reason) have this uncanny ability to present information in a way that just triggers an avalanche of insight.  Here is an example: "<a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/" rel="bookmark" title="Permanent Link to The Two Kinds Of Security Threats, And How They Affect Your Life">The Two Kinds Of Security Threats, And How They Affect Your Life </a>" from Rich Mogul.<br /><br />Some <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">quotes</a>:  "We get money for noisy threats, and get called paranoid freaks for trying to prevent quiet threats (which can still lose our organizations a boatload of money, but don’t interfere with the married CEO’s ability to flirt with the new girl in marketing over email)."<br /><br />and<br /><br />"Slice up your budget and see how much you spend preventing noisy vs. quiet threats. It’s often our own little version of security theater."<br /><br />and<br /><br />"The problem is, noisy vs. quiet may bear little to no relationship to your actual risk and losses, but that’s just human nature."<br /><br />Overall, a MUST <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">read</a>.<br /><br />God, please, send us some credible <a href="http://www.securitymetrics.org/content/Wiki.jsp">security metrics</a>... please.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Raf0N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Raf0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fKCxN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fKCxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=VLpzN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=VLpzN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460247667" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 14:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/quiet">quiet</category>
      <category domain="http://securityratty.com/tag/prevent quiet threats">prevent quiet threats</category>
      <category domain="http://securityratty.com/tag/noisy">noisy</category>
      <category domain="http://securityratty.com/tag/quiet threats">quiet threats</category>
      <category domain="http://securityratty.com/tag/noisy threats">noisy threats</category>
      <category domain="http://securityratty.com/tag/credible security metrics">credible security metrics</category>
      <category domain="http://securityratty.com/tag/uncanny ability">uncanny ability</category>
      <category domain="http://securityratty.com/tag/human nature">human nature</category>
      <category domain="http://securityratty.com/tag/mystical reason">mystical reason</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460247667/just-love-this-noisy-vs-quiet-from-rich.html">Just Love This: Noisy vs Quiet from Rich</source>
    </item>
    <item>
      <title><![CDATA[Raffys Visualization Book]]></title>
      <link>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</link>
      <guid>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</guid>
      <description><![CDATA[Here is my long-overdue book review for Applied Security Visualization by Raffy Marty
First, here is what my early endorsement for the book said (can be found on the inside cover of the book
Amazingly...]]></description>
      <content:encoded><![CDATA[<p>Here is my long-overdue book review for <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">“Applied Security Visualization“&#160; by Raffy Marty</a>.</p>  <p>First, here is what my early endorsement for the book said (can be found on the inside cover of the book):</p>  <p>“Amazingly useful (and fun to read!) book that does justice to this&#160; somewhat esoteric subject - and this is coming from a long-time&#160; visualization skeptic! What is most impressive that&#160; this book is&#160; actually 'hands-on-useful,&quot; not conceptual, with examples usable by&#160; readers in their daily jobs. Chapter 8 on insiders is my favorite!”</p>  <p>What else do I think of the book, apart from the fact that it is awesome? :-)</p>  <p>First, I have to admit that I used to argue with Raffy about usefulness of visualization. I was burned by having to look at bad “visualization” tools and would take <em>an ugly, meaningful table over an ugly, meaningless picture</em> any day now. Thus, I was a visualization skeptic. Buy you know what? The book does justice to visualization really well, and it explains when to use it and when not to use it.</p>  <p>The book gives just the right amount of visualization theory, which is not onerous to read at all (unlike some other books), as well as other visualization basics. The fun starts at Chapter 4, where he covers&#160; the process from data to useful pictures. This actually explains why some visualization are useful and some are not; if you just jam data into a graphing program, there is a good chance that it would not be too useful. If you follow the ideas from Ch4, it is more likely to be useful.</p>  <p>Ch5 and 6 cover network data analysis: logs, packets, flows. This is what most people usually try to visualize; this book goes beyond “worms and scans” into nice visuals of email traffic, wireless and even vulnerability data (I found the latter slightly confusing). Ch7 covers “compliance”, which, in this case, covers all sorts of fun things, from risk assessment to database log visualization.&#160; As I said, Ch8 is my favorite: I agree that insider tracking MAY be the area where visualization tools and approaches beat others. In Ch9, the book covers a few visualization tools; obviously, including the author’s AfterGlow.</p>  <p>So, to summarize, get the book if you have any connection to security AND data analysis. In fact, it is very likely that if you are doing security, you’d have to do data analysis at some point and so will benefit from reading the book. And, yes, it does come with a CD full of visualization tools (DAVIX).</p>  <p>BTW, I am posting it <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">at Amazon</a> as well.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wgwyN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wgwyN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ADZPN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ADZPN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=N8CKN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=N8CKN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460098463" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 11:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visualization">visualization</category>
      <category domain="http://securityratty.com/tag/visualization tools">visualization tools</category>
      <category domain="http://securityratty.com/tag/bad visualization tools">bad visualization tools</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/database log visualization">database log visualization</category>
      <category domain="http://securityratty.com/tag/security visualization">security visualization</category>
      <category domain="http://securityratty.com/tag/long-time visualization skeptic">long-time visualization skeptic</category>
      <category domain="http://securityratty.com/tag/long-overdue book review">long-overdue book review</category>
      <category domain="http://securityratty.com/tag/book covers">book covers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460098463/raffys-visualization-book.html">Raffys Visualization Book</source>
    </item>
    <item>
      <title><![CDATA[Dissecting the Latest Koobface Facebook Campaign]]></title>
      <link>http://securityratty.com/article/86c70e5d2e4da8aa581ee9216947ac9a</link>
      <guid>http://securityratty.com/article/86c70e5d2e4da8aa581ee9216947ac9a</guid>
      <description><![CDATA[The latest Koobface malware campaign at Facebook , is once again exposing a diverse ecosystem worth assessing in times of active migration to alternative ISPs tolerating or conveniently ignoring the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRrlN5c-LfI/AAAAAAAACb8/oG5zfHxekJ4/s1600-h/koobface_facebook_redirections.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRrlN5c-LfI/AAAAAAAACb8/oG5zfHxekJ4/s200/koobface_facebook_redirections.JPG" /></a>The latest <a href="http://blogs.zdnet.com/security/?p=2146">Koobface malware campaign at Facebook</a>, is once again exposing a diverse ecosystem worth assessing in times of active migration to alternative ISPs tolerating or conveniently ignoring the malicious activities courtesy of their customers. The -- now removed -- binaries that the dropper was requesting were hosted at the American International Baseball Club in Vienna, indicating a compromise.<br />
<br />
us.geocities .com/adanbates84/index.htm<br />
<b>lostart .info/js/js.js</b> (79.132.211.51)<br />
<b>off34 .com/go/fb.php</b> (79.132.211.51)<br />
<b>youtube-spyvideo .com/youtube_file.html</b> (58.241.255.37)<br />
<b>ahdirz .com/movie1.php?id=638&amp;n=teen</b> (208.85.181.69)<br />
<b>top100clipz .com/m6/movie1.php?id=638&amp;n=teen</b> (208.85.181.67)<br />
<b>hq-vidz .com/movie1.php?id=638&amp;n=teen</b> (208.85.181.68)<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRwwNw6BKZI/AAAAAAAACcU/_coWTkcVuVM/s1600-h/koobface_facebook_activex.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRwwNw6BKZI/AAAAAAAACcU/_coWTkcVuVM/s200/koobface_facebook_activex.png" /></a>The dropper then phones back home to : <b>f071108 .com/fb/first.php</b> (79.132.211.50) with the binaries hosted at a legitimate site that's been compromised :<br />
<br />
<b>aibcvienna.org/youtube/ bnsetup24.exe</b><br />
<b>aibcvienna.org/youtube/ tinyproxy.exe </b><br />
<br />
Related fake Youtube domains participating :<br />
<b>catshof .com </b>(79.132.211.51)<br />
<b>youtube-spy .info </b>(94.102.60.119)<br />
<b>youtubehof .net </b>(218.93.205.30)<br />
<b>youtube-spyvideo .com </b>(58.241.255.37)<br />
<b>yyyaaaahhhhoooo.ocom .pl </b>(67.15.104.83)<br />
<b>youtube-x-files .com </b>(94.102.60.119) <br />
<br />
The development of cybercrime platforms utilizing legitimate infrastructure only, has always been in the works. With spamming systems relying exclusively on the automatically registered email accounts at free web based providers, to the automatic bulk registration of hundreds of thousands of domains enjoying a particular domain registrar's weak anti-abuse policies, it would be interesting to monitor whether <a href="http://www.renesys.com/blog/2008/09/internet_vigilantism_1.shtml">marginal thinking</a> or <a href="http://ddanchev.blogspot.com/2008/10/cost-of-anonymizing-cybercriminals.html">improved OPSEC relying on compromised hosts</a> will be favored in 2009.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">Phishing Campaign Spreading Across Facebook</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/large-scale-myspace-phishing-attack.html">Large Scale MySpace Phishing Attack</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/12/update-on-myspace-phishing-campaign.html">Update on the MySpace Phishing Campaign</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2008/01/myspace-phishers-now-targeting-facebook.html">MySpace Phishers Now Targeting Facebook</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2008/05/myspace-hosting-myspace-phishing.html">MySpace Hosting MySpace Phishing Profiles</a><span style="font-weight: bold;"></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b95SN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b95SN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eLeKN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eLeKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7mCXn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7mCXn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gPM0n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gPM0n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2GlmN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2GlmN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aavTN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aavTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NgiDn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NgiDn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451825134" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 05:08:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <category domain="http://securityratty.com/tag/myspace phishers">myspace phishers</category>
      <category domain="http://securityratty.com/tag/facebook malware campaigns">facebook malware campaigns</category>
      <category domain="http://securityratty.com/tag/koobface malware campaign">koobface malware campaign</category>
      <category domain="http://securityratty.com/tag/scale myspace">scale myspace</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/fake youtube domains">fake youtube domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451825134/dissecting-latest-koobface-facebook.html">Dissecting the Latest Koobface Facebook Campaign</source>
    </item>
    <item>
      <title><![CDATA[Teaching the Elderly about Scams and Security]]></title>
      <link>http://securityratty.com/article/e41572ac9f794d144e3f8f9e4d564c20</link>
      <guid>http://securityratty.com/article/e41572ac9f794d144e3f8f9e4d564c20</guid>
      <description><![CDATA[People were being scammed long before email and malware entered into daily use and its still happening offline as well as online. So what to do if you know that someone you love is being victimized...]]></description>
      <content:encoded><![CDATA[<p>People were being scammed long before email and malware entered into daily use &#8212; and it&#8217;s still happening offline as well as online. So what to do if you know that someone you love is being victimized and scammed?</p>
<p>That&#8217;s the question the Consumerist asked readers today, with a story about a <a rel="nofollow" target="_blank" href="http://consumerist.com/5083442/she+grifters-scam-granddad-for-10000%252B-a-month">Florida grand-dad </a>whose gardener is supposedly fleecing him for over $10k / month, allegedly to help an ailing friend:</p>
<blockquote><p>Shaun says his 80+-year old grandfather, Steve, is being scammed out of over $10,000 a month. It seems Steve recently hired a female gardener who introduced him to a &#8220;wealthy friend,&#8221; and now he&#8217;s loaning them money to pay for groceries, cable, home upkeep, and, get this, bodyguards to protect her from an ex-husband and son who to want to kill her. When the family tries to intervene, Steve says the family is trying to put him in a nursing home and steal his money. Shaun is at a loss. How can he help his grandfather, who doesn&#8217;t want to be helped?</p></blockquote>
<p>Another question that might be relevant in the IT Security community is, are the elderly more prone to these scams, and if so why? In the tech world it&#8217;s widely assumed that the older generation just has a harder time learning and grasping how to use technology so may not understand what is risky and what isn&#8217;t.</p>
<p>But perhaps there&#8217;s a deeper problem, either with some form of dementia and paranoia in the older years, or just a purer vulnerability associated with being alienated from the new, cutting edge and modern world as we age, or some kind of unwillingness to be suspicious because of the need to have caring people around you?</p>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 11:54:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/steve">steve</category>
      <category domain="http://securityratty.com/tag/steve recently hired">steve recently hired</category>
      <category domain="http://securityratty.com/tag/female gardener">female gardener</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/gardener">gardener</category>
      <category domain="http://securityratty.com/tag/home upkeep">home upkeep</category>
      <category domain="http://securityratty.com/tag/wealthy friend">wealthy friend</category>
      <category domain="http://securityratty.com/tag/shaun">shaun</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/450086772/">Teaching the Elderly about Scams and Security</source>
    </item>
    <item>
      <title><![CDATA[White House Network Hacked By Chinese On Multiple Occasions]]></title>
      <link>http://securityratty.com/article/332ff74797a239064908d5437e616985</link>
      <guid>http://securityratty.com/article/332ff74797a239064908d5437e616985</guid>
      <description><![CDATA[According to Demetri Sevastopulo from Financial Times, Chinese hackers have penetrated the White House computer network on multiple occasions, and obtained e-mails between government officials. US...]]></description>
      <content:encoded><![CDATA[According to Demetri Sevastopulo from Financial Times, Chinese hackers have penetrated the White House computer network on multiple occasions, and obtained e-mails between government officials. US officials say Chinese hackers have raided White House email archives multiple times. The Financial Times reports some people it describes as &#8220;US government cyber experts&#8221; suspect the raids were [...]]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 21:03:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial times">financial times</category>
      <category domain="http://securityratty.com/tag/financial times reports">financial times reports</category>
      <category domain="http://securityratty.com/tag/chinese hackers">chinese hackers</category>
      <category domain="http://securityratty.com/tag/multiple occasions">multiple occasions</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/government officials">government officials</category>
      <category domain="http://securityratty.com/tag/demetri sevastopulo">demetri sevastopulo</category>
      <category domain="http://securityratty.com/tag/e-mails">e-mails</category>
      <category domain="http://securityratty.com/tag/raids">raids</category>
      <source url="http://cyberinsecure.com/white-house-network-hacked-by-chinese-on-multiple-occasions/">White House Network Hacked By Chinese On Multiple Occasions</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #127]]></title>
      <link>http://securityratty.com/article/d60e884160f385e41db54c74a6f13c81</link>
      <guid>http://securityratty.com/article/d60e884160f385e41db54c74a6f13c81</guid>
      <description><![CDATA[Click to Download/Listen (07:52

It's election day in the US, and today's Speaking of Security Podcast focuses on the notorious breach of Sarah Palin's email account on Yahoo. Satchit Dokras, a...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1379">Click to Download/Listen</a> (07:52)<br><br />It's election day in the US, and today's Speaking of Security Podcast focuses on the notorious breach of Sarah Palin's email account on Yahoo. Satchit Dokras, a Director in RSA's EMC Product Security Office, talks about Palin's exposed email and how all of us can better protect our online accounts.<br />]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/palin">palin</category>
      <category domain="http://securityratty.com/tag/security podcast focuses">security podcast focuses</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/notorious breach">notorious breach</category>
      <category domain="http://securityratty.com/tag/satchit dokras">satchit dokras</category>
      <category domain="http://securityratty.com/tag/election day">election day</category>
      <category domain="http://securityratty.com/tag/online accounts">online accounts</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1379">Speaking of Security Podcast #127</source>
    </item>
    <item>
      <title><![CDATA[Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts]]></title>
      <link>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</link>
      <guid>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</guid>
      <description><![CDATA[Security researchers at RSAs FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or...]]></description>
      <content:encoded><![CDATA[Security researchers at RSA&#8217;s FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or Mebroot) trojan has also stole email and FTP account login details. Previous attempts to track the source of the Trojan were unsuccessful.
The haul [...]]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 17:12:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/online bank accounts">online bank accounts</category>
      <category domain="http://securityratty.com/tag/previous attempts">previous attempts</category>
      <category domain="http://securityratty.com/tag/aka torpig">aka torpig</category>
      <category domain="http://securityratty.com/tag/login credentials">login credentials</category>
      <category domain="http://securityratty.com/tag/sinowal">sinowal</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/haul">haul</category>
      <source url="http://cyberinsecure.com/undetectable-sinowaltorpig-trojan-steals-more-than-300000-bank-accounts/">Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts</source>
    </item>
    <item>
      <title><![CDATA[Pseudo Email Marketing Tools Empowering Spammers]]></title>
      <link>http://securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</link>
      <guid>http://securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</guid>
      <description><![CDATA[Largely ignoring its real life applicability, a vendor of &quot;email marketing&quot; tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years....]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/eVrvlQbC73Y/s1600-h/marketing_spamming_6.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/ByNNe5khEhY/s200-R/marketing_spamming_6.gif" /></a>Largely ignoring its real life applicability, a vendor of "email marketing" tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years. Originally released in 2004, the vendor appears to have been actively improving the real-time metrics of the campaigns, next to building interactivity into the spamming process through the WYSIWYG editor.<br />
<br />
For better or worse, despite that these applications are empowering spammers and lowering down the entry barriers into spamming, the tools have gotten <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">largely replaced</a> by the <a href="http://ddanchev.blogspot.com/2008/10/inside-managed-spam-service.html">increasing number</a> of <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming services</a>, whose quality assurance features of bypassing spam filters act as a main differentiation factor. Here are some of this tool's features :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/IJaKNStG3tY/s1600-h/marketing_spamming_1.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="151" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/A906A5o9i1I/s200-R/marketing_spamming_1.gif" width="200" /></a><i>"- High speed distribution - 200,000 letters per hour.</i><br />
<i>- Contains an embedded SMTP server that allows you to send letters directly to the recipient's mailbox without using your provider's SMTP server.</i><br />
<i>-&nbsp; If you are accessing the Internet via modem, and distribution using the SMTP server, you do not fit - also allowed to send mail through any number of remote SMTP servers (relay), or via SMTP server provider.</i><br />
<i>- Support for SMTP authentication.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/V9kNzRzibCQ/s1600-h/marketing_spamming_2.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/_uP9YfEEhEk/s200-R/marketing_spamming_2.gif" /></a><i>- Supports up to 500 concurrent streams to send to each mailing.</i><br />
<i>- Automatic caching DNS requests to speed up distribution and reducing the load on the DNS server.</i><br />
<i>- Ability to run multiple independent shots at the same time.</i><br />
<i>- Ability to suspend delivery and continue later with a point.</i><br />
<i>- All modes distribution - TO, CC, BCC and PersonalCopy. In the latter case, the program generates a personal letter to each recipient.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/-Zr9CYINTlY/s1600-h/marketing_spamming_3.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/aJp3Ub3Uwfo/s200-R/marketing_spamming_3.gif" /></a><i>- Ability to specify the size of BCC package regimes TO, CC, and BCC.</i><br />
<i>- Ability to specify the TO: field for mailing regimes and CS BCC.</i><br />
<i>- Full emulation signature letters Outlook Express to increase cross-your-mails through spam filters.</i><br />
<i>- Support for distribution via a proxy server.</i><br />
<i>- Automatically detect the bad (non-existent) and not by E-Mail addresses directly in the process of distribution based on a flexible, user SMTP rules. Thanks SMTP rules achieved a very precise definition of bad addresses virtually no false positives.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/Rf_WZkjuJ84/s1600-h/marketing_spamming_7.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/kujVnisjcjY/s200-R/marketing_spamming_7.gif" /></a><i>- Ability to create lists of addresses, depending on the specific responses of remote servers for SMTP commands.</i><br />
<i>- Organize automatically subscribe / unsubscribe to the mailing addresses.</i><br />
<i>- Perform any processing of existing lists.</i><br />
<i>- Develop a letter to the powerful WYSIWYG Html editor.</i><br />
<br />
<i>- Automatically apply to each recipient by name, as well as paste in a letter to a specific, personalized information through powerful Mail Merge templates.</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/dlmHlT-5hyw/s1600-h/marketing_spamming_8.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/fRcQsC-6XlY/s200-R/marketing_spamming_8.gif" /></a><i>- Set the calendar to automatically launch shots at the right time.</i><br />
<i>- Quickly send out mail.</i>"<br />
<br />
With managed spam services' on-demand, risk forwarding and completely outsourced processes, they're not only going to replace such DIY tools, but also, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">position them as a dynamically</a> evolving <a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">cybercrime platforms</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CqO0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CqO0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HbgzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HbgzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KVshm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KVshm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJpMm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJpMm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ON79M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ON79M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nKPXM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nKPXM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hPU3m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hPU3m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/436383197" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 16:28:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bad addresses">bad addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/smtp server">smtp server</category>
      <category domain="http://securityratty.com/tag/smtp server provider">smtp server provider</category>
      <category domain="http://securityratty.com/tag/e-mail addresses directly">e-mail addresses directly</category>
      <category domain="http://securityratty.com/tag/distribution">distribution</category>
      <category domain="http://securityratty.com/tag/modes distribution">modes distribution</category>
      <category domain="http://securityratty.com/tag/speed distribution">speed distribution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/436383197/pseudo-email-marketing-tools-empowering.html">Pseudo Email Marketing Tools Empowering Spammers</source>
    </item>
    <item>
      <title><![CDATA[CSI 35th 2008 Discount Passes]]></title>
      <link>http://securityratty.com/article/f1ad94b6283c47c53696f0ea9e012fac</link>
      <guid>http://securityratty.com/article/f1ad94b6283c47c53696f0ea9e012fac</guid>
      <description><![CDATA[Since I am speaking at CSI 35th Annual Conference (on SIEM, believe it or now), I can again give out discount conference passes

The passes cover the full conference, MondayWednesday, November 1719,...]]></description>
      <content:encoded><![CDATA[Since I am speaking at <a href="http://www.csiannual.com/">CSI 35th Annual Conference</a> (on SIEM, believe it or now), I can again give out discount conference passes:<br /><br />"The passes cover the full conference, Monday–Wednesday, November 17–19, 2008, for a <b>55% discount</b>!  To pass along your discount passes, send your guests to <a href="https://www.cmpevents.com/CSI35/a.asp?option=B" target="_blank">CSI 2008 Registration</a> to register for a CSI 2008 Conference Pass and have them enter the below Priority Code in the box provided:  <b>SPK73</b><p><b> </b></p>    <p> </p>   <p> </p>  <p><i>*Please note: This offer is only for new registrations, we cannot re-price current registrations."</i></p><p><span style="font-weight: bold;">UPDATE: THE OFFER BELOW HAVE BEEN TAKEN AS OF 5:00PM Oct 30th.</span><br /></p><p>For those rare people who read all the way to here :-), I can also give our 1 (one!) <span style="font-style: italic;">FREE </span>CSI pass; please email me for it as it will be given on "a first come, first served" basis and can only be used by my loyal blog readers :-)<i><br /></i></p>  <p><i> </i></p><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xLnxM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xLnxM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=HwgSM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=HwgSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=DAjLM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=DAjLM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/437416234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 11:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/discount passes">discount passes</category>
      <category domain="http://securityratty.com/tag/discount">discount</category>
      <category domain="http://securityratty.com/tag/pass">pass</category>
      <category domain="http://securityratty.com/tag/conference pass">conference pass</category>
      <category domain="http://securityratty.com/tag/csi">csi</category>
      <category domain="http://securityratty.com/tag/free csi pass">free csi pass</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/discount conference passes">discount conference passes</category>
      <category domain="http://securityratty.com/tag/registrations">registrations</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/437416234/csi-35th-2008-discount-passes.html">CSI 35th 2008 Discount Passes</source>
    </item>
  </channel>
</rss>
