<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: emails]]></title>
    <link>http://securityratty.com/tag/emails</link>
    <description></description>
    <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 10.24.08]]></title>
      <link>http://securityratty.com/article/8e899f9ef46d0a44116f8be8a4a6e8a3</link>
      <guid>http://securityratty.com/article/8e899f9ef46d0a44116f8be8a4a6e8a3</guid>
      <description><![CDATA[Ah a mystery. In The strange case of the slow server , Jack Hughes at The Tech Teapot had problems with internet presence slow website loading, problems logging in and slow emails. Sound familiar? In...]]></description>
      <content:encoded><![CDATA[<p>Ah a mystery. In “<a href="http://www.openxtra.co.uk/blog/the-strange-case-of-the-slow-server/" target="_blank">The strange case of the slow server</a>”, Jack Hughes at The Tech Teapot had problems with internet presence – slow website loading, problems logging in and slow emails. Sound familiar? In Jack’s case, the culprit was his main download site but the real issue was lack of visibility across multiple tools that provided much info but not in a way that was really usable. “The main lesson I take away from this is to make sure you’re creating meaningful stats for everything you’ve got because you never know what may be causing you a problem.”</p>
<p>Information Week’s new blog, Plug Into the Cloud, is already in the thick of the controversy on the emerging cloud computing trend. A recent post <a href="http://www.informationweek.com/cloud-computing/blog/archives/2008/10/cloud_computing_4.html" target="_blank">lists a bunch of highly opinionated comments on the topic</a> by site visitors, running the gamut from “Cloud computing is kind of like the Emperor’s New Clothes” to “cloud software can actually be more expensive than the software I load onto my hard drive.”</p>
<p>Jeff Doyle writes an interesting post about <a href="http://www.networkworld.com/community/node/34103" target="_blank">resistance to IPv6</a> adoption (what, you think <a href="http://blog.sciencelogic.com/times-up-ipv6-omb-mandate/06/2008" target="_blank">we forgot</a>?). Instead of the usual focus on IPv6 as an application issue, he points out that it’s actually an infrastructure thing. Would you wait to upgrade routers, switches, software, or servers until you can find a way to make the newer systems profitable? Would you wait to increase bandwidth only after you have customers waiting to use it? If you’ve answered these questions “no”, then why are you waiting to upgrade to IPv6?</p>
<p>We posted about whether or not there were <a href="http://blog.sciencelogic.com/are-there-recession-proof-it-products/10/2008" target="_blank">recession proof products in IT yesterday</a>. Network World Management Maven Denise Dubie also writes about <a href="http://www.networkworld.com/newsletters/nsm/2008/102008nsm2.html?nlhtnsm=ts_102208&amp;nladname=102208networksystemsmanagemental" target="_blank">readers weighing in on IT and the economy</a> – from having to do even more with less to seeing the economic downtown as an opportunity to highlight IT’s true value to the business.</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/clip-image002.jpg" border="0" alt="clip_image002" hspace="hspace" width="299" height="196" align="left" />And finally, on the lighter side: What would we do without crazy billionaires and their crazy purchases? According to a New York Times article, a company controlled by Google’s top execs just added a <a href="http://bits.blogs.nytimes.com/2008/10/23/a-new-fighter-jet-for-googles-founders/" target="_blank">fighter jet</a> to their roster. “Presumably no attacks on Microsoft are planned at this time.” <em>(<a href="http://en.wikipedia.org/wiki/Image:Alpha_jet_zj646_arp.jpg" target="_blank">image from Wikipedia</a>)</em></p>
]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 14:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud software">cloud software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/jeff doyle writes">jeff doyle writes</category>
      <category domain="http://securityratty.com/tag/ipv6 adoption">ipv6 adoption</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/recent post lists">recent post lists</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/writes">writes</category>
      <source url="http://blog.sciencelogic.com/links-list-102408/10/2008">Links List 10.24.08</source>
    </item>
    <item>
      <title><![CDATA[Malware? We don't need no stinking malware!]]></title>
      <link>http://securityratty.com/article/cbb029a08a78820b5ef90b69579719a1</link>
      <guid>http://securityratty.com/article/cbb029a08a78820b5ef90b69579719a1</guid>
      <description><![CDATA[Written by Oliver Fisher

This site may harm your computer
You may have seen those words in Google search results but what do they mean? If you click the search result link you get another warning...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Oliver Fisher</span><br /><br /><span style="font-weight: bold;">"This site may harm your computer"</span><br />You may have seen those words in Google search results — but what do they mean? If you click the search result link you get another warning page instead of the website you were expecting. But if the web page was your grandmother's baking blog, you're still confused. Surely your grandmother hasn't been secretly honing her l33t computer hacking skills at night school. Google must have made a mistake and your grandmother's web page is just fine...<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LMSk7hTEaIE/SQI_1LfaQYI/AAAAAAAAtcc/zI4emYNyj4g/s1600-h/example.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 125px;" src="http://3.bp.blogspot.com/_LMSk7hTEaIE/SQI_1LfaQYI/AAAAAAAAtcc/zI4emYNyj4g/s320/example.png" alt="" id="BLOGGER_PHOTO_ID_5260837497572311426" border="0" /></a><br /><br />I work with the team that helps put the warning in Google's search results, so let me try to explain. The good news is that your grandmother is still kind and <a href="http://fitz.blogspot.com/2008/10/everybody-should-have-one.html">loves turtles</a>. She isn't trying to start a botnet or steal credit card numbers. The bad news is that her website or the server that it runs on probably has a security vulnerability, most likely from some out-of-date software. That vulnerability has been exploited and malicious code has been added to your grandmother's website. It's most likely an invisible script or iframe that pulls content from another website that tries to attack any computer that views the page. If the attack succeeds, then viruses, spyware, key loggers, botnets, and other nasty stuff will get installed.<br /><br />If you see the warning on a site in Google's search results, it's a good idea to pay attention to it. Google has automatic scanners that are constantly looking for these sorts of web pages. I help build the scanners and continue to be surprised by how accurate they are. There is almost certainly something wrong with the website even if it is run by someone you trust. The automatic scanners make unbiased decisions based on the malicious content of the pages, not the reputation of the webmaster.<br /><br />Servers are just like your home computer and need constant updating. There are lots of tools that make building a website easy, but each one adds some risk of being exploited. Even if you're diligent and keep all your website components updated, your web host may not be. They control your website's server and may not have installed the most recent OS patches. And it's not just innocent grandmothers that this happens to. There have been warnings on the websites of banks, sports teams, and corporate and government websites.<br /><br /><span style="font-weight: bold;">Uh-oh... I need help!</span><br />Now that we understand what the malware label means in search results, what do you do if you're a webmaster and Google's scanners have found malware on your site?<br /><br />There are some resources to help clean things up. The Google Webmaster Central blog has <a href="http://googlewebmastercentral.blogspot.com/2008/04/my-sites-been-hacked-now-what.html">some tips</a> and a <a href="http://googlewebmastercentral.blogspot.com/2007/09/quick-security-checklist-for-webmasters.html">quick security checklist for webmasters</a>. <a href="http://stopbadware.org/">Stopbadware.org</a> has great information, and their <a href="http://groups.google.com/group/stopbadware">forums</a> have a number of helpful and knowledgeable volunteers who may be able to help (sometimes I'm one of them). You can also use the Google SafeBrowsing diagnostics page for your site (http://www.google.com/safebrowsing/diagnostic?site=<i>&lt;site-name-here&gt;</i>) to see specific information about what Google's automatic scanners have found. If your site has been flagged, Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> lists some of the URLs that were scanned and found to be infected.<br /><br />Once you've cleaned up your website, use Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> to <a href="http://googlewebmastercentral.blogspot.com/2008/08/hey-google-i-no-longer-have-badware.html">request a malware review</a>. The automatic systems will rescan your website and the warning will be removed if the malware is gone.<br /><br /><span style="font-weight: bold;">Advance warning</span><br />I often hear webmasters asking Google for advance warning before a malware label is put on their website. When the label is applied, Google usually <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=45432#2">emails the website owners</a> and then posts a warning in Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a>. But no warning is given ahead of time - <span style="font-weight: bold;">before</span> the label is applied - so a webmaster can't quickly clean up the site before a warning is applied.<br /><br />But, look at the situation from the user's point of view. As a user, I'd be pretty annoyed if Google sent me to a site it knew was dangerous. Even a short delay would expose some users to that risk, and it doesn't seem justified. I know it's frustrating for a webmaster to see a malware label on their website. But, ultimately, protecting users against malware makes the internet a safer place and everyone benefits, both webmasters and users.<br /><br />Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> has started a test to provide <a href="http://googlewebmastercentral.blogspot.com/2008/10/message-center-warnings-for-hackable.html">warnings to webmasters</a> that their server software may be vulnerable. Responding to that warning and updating server software can prevent your website from being compromised with malware. The best way to avoid a malware label is to never have any malware on the site!<br /><br /><span style="font-weight: bold;">Reviews</span><br />You can request a review via Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> and you can see the status of the review there. If you think the review is taking too long, make sure to check the status. Finding all the malware on a site is difficult and the automated scanners are far more accurate than humans. The scanners may have found something you've missed and the review may have failed.  If your site has a malware label, Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> will also list some sample URLs that have problems. This is not a full list of all of the problem URLs (because that's often very, very long), but it should get you started.<br /><br />Finally, don't confuse a malware review with a <a href="http://googlewebmastercentral.blogspot.com/2008/07/requesting-reconsideration-using-google.html">request for reconsideration</a>. If Google's automated scanners find malware on your website, the site will usually not be removed from search results. There is also a different process that removes spammy websites from Google search results. If that's happened and you disagree with Google, you should submit a <a href="http://googlewebmastercentral.blogspot.com/2008/07/requesting-reconsideration-using-google.html">reconsideration request</a>. But if your site has a malware label, a reconsideration request won't do any good — for malware you need to file a malware review from the Overview page.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_LMSk7hTEaIE/SQJAJQN-pYI/AAAAAAAAtck/DOkV2_QwJdQ/s1600-h/example2.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://4.bp.blogspot.com/_LMSk7hTEaIE/SQJAJQN-pYI/AAAAAAAAtck/DOkV2_QwJdQ/s320/example2.png" alt="" id="BLOGGER_PHOTO_ID_5260837842438759810" border="0" /></a><br /><br /><span style="font-weight: bold;">How long will a review take?</span><br />Webmasters are eager to have a Google malware label removed from their site and often ask how long a review of the site will take. Both the original scanning and the review process are fully automated. The systems analyze large portions of the internet, which is big place, so the review may not happen immediately. Ideally, the label will be removed within a few hours. At its longest, the process should take a day or so.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=Cuj5M"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=Cuj5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=v7cwm"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=v7cwm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/431137747" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 10:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/google malware label">google malware label</category>
      <category domain="http://securityratty.com/tag/label">label</category>
      <category domain="http://securityratty.com/tag/malware review">malware review</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/webmaster tools lists">webmaster tools lists</category>
      <category domain="http://securityratty.com/tag/malware label">malware label</category>
      <category domain="http://securityratty.com/tag/webmaster tools">webmaster tools</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/431137747/malware-we-dont-need-no-stinking.html">Malware? We don't need no stinking malware!</source>
    </item>
    <item>
      <title><![CDATA[Malware? We don't need no stinking malware!]]></title>
      <link>http://securityratty.com/article/7b001609aa5afd4ad270a86d179c2f41</link>
      <guid>http://securityratty.com/article/7b001609aa5afd4ad270a86d179c2f41</guid>
      <description><![CDATA[Written by Oliver Fisher

This site may harm your computer
You may have seen those words in Google search results but what do they mean? If you click the search result link you get another warning...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Oliver Fisher</span><br /><br /><span style="font-weight: bold;">"This site may harm your computer"</span><br />You may have seen those words in Google search results — but what do they mean? If you click the search result link you get another warning page instead of the website you were expecting. But if the web page was your grandmother's baking blog, you're still confused. Surely your grandmother hasn't been secretly honing her l33t computer hacking skills at night school. Google must have made a mistake and your grandmother's web page is just fine...<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_LMSk7hTEaIE/SQI_1LfaQYI/AAAAAAAAtcc/zI4emYNyj4g/s1600-h/example.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 125px;" src="http://3.bp.blogspot.com/_LMSk7hTEaIE/SQI_1LfaQYI/AAAAAAAAtcc/zI4emYNyj4g/s320/example.png" alt="" id="BLOGGER_PHOTO_ID_5260837497572311426" border="0" /></a><br /><br />I work with the team that helps put the warning in Google's search results, so let me try to explain. The good news is that your grandmother is still kind and <a href="http://fitz.blogspot.com/2008/10/everybody-should-have-one.html">loves turtles</a>. She isn't trying to start a botnet or steal credit card numbers. The bad news is that her website or the server that it runs on probably has a security vulnerability, most likely from some out-of-date software. That vulnerability has been exploited and malicious code has been added to your grandmother's website. It's most likely an invisible script or iframe that pulls content from another website that tries to attack any computer that views the page. If the attack succeeds, then viruses, spyware, key loggers, botnets, and other nasty stuff will get installed.<br /><br />If you see the warning on a site in Google's search results, it's a good idea to pay attention to it. Google has automatic scanners that are constantly looking for these sorts of web pages. I help build the scanners and continue to be surprised by how accurate they are. There is almost certainly something wrong with the website even if it is run by someone you trust. The automatic scanners make unbiased decisions based on the malicious content of the pages, not the reputation of the webmaster.<br /><br />Servers are just like your home computer and need constant updating. There are lots of tools that make building a website easy, but each one adds some risk of being exploited. Even if you're diligent and keep all your website components updated, your web host may not be. They control your website's server and may not have installed the most recent OS patches. And it's not just innocent grandmothers that this happens to. There have been warnings on the websites of banks, sports teams, and corporate and government websites.<br /><br /><span style="font-weight: bold;">Uh-oh... I need help!</span><br />Now that we understand what the malware label means in search results, what do you do if you're a webmaster and Google's scanners have found malware on your site?<br /><br />There are some resources to help clean things up. The Google Webmaster Central blog has <a href="http://googlewebmastercentral.blogspot.com/2008/04/my-sites-been-hacked-now-what.html">some tips</a> and a <a href="http://googlewebmastercentral.blogspot.com/2007/09/quick-security-checklist-for-webmasters.html">quick security checklist for webmasters</a>. <a href="http://stopbadware.org/">Stopbadware.org</a> has great information, and their <a href="http://groups.google.com/group/stopbadware">forums</a> have a number of helpful and knowledgeable volunteers who may be able to help (sometimes I'm one of them). You can also use the Google SafeBrowsing diagnostics page for your site (http://www.google.com/safebrowsing/diagnostic?site=<i>&lt;site-name-here&gt;</i>) to see specific information about what Google's automatic scanners have found. If your site has been flagged, Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> lists some of the URLs that were scanned and found to be infected.<br /><br />Once you've cleaned up your website, use Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> to <a href="http://googlewebmastercentral.blogspot.com/2008/08/hey-google-i-no-longer-have-badware.html">request a malware review</a>. The automatic systems will rescan your website and the warning will be removed if the malware is gone.<br /><br /><span style="font-weight: bold;">Advance warning</span><br />I often hear webmasters asking Google for advance warning before a malware label is put on their website. When the label is applied, Google usually <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=45432#2">emails the website owners</a> and then posts a warning in Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a>. But no warning is given ahead of time - <span style="font-weight: bold;">before</span> the label is applied - so a webmaster can't quickly clean up the site before a warning is applied.<br /><br />But, look at the situation from the user's point of view. As a user, I'd be pretty annoyed if Google sent me to a site it knew was dangerous. Even a short delay would expose some users to that risk, and it doesn't seem justified. I know it's frustrating for a webmaster to see a malware label on their website. But, ultimately, protecting users against malware makes the internet a safer place and everyone benefits, both webmasters and users.<br /><br />Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> has started a test to provide <a href="http://googlewebmastercentral.blogspot.com/2008/10/message-center-warnings-for-hackable.html">warnings to webmasters</a> that their server software may be vulnerable. Responding to that warning and updating server software can prevent your website from being compromised with malware. The best way to avoid a malware label is to never have any malware on the site!<br /><br /><span style="font-weight: bold;">Reviews</span><br />You can request a review via Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> and you can see the status of the review there. If you think the review is taking too long, make sure to check the status. Finding all the malware on a site is difficult and the automated scanners are far more accurate than humans. The scanners may have found something you've missed and the review may have failed.  If your site has a malware label, Google's <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a> will also list some sample URLs that have problems. This is not a full list of all of the problem URLs (because that's often very, very long), but it should get you started.<br /><br />Finally, don't confuse a malware review with a <a href="http://googlewebmastercentral.blogspot.com/2008/07/requesting-reconsideration-using-google.html">request for reconsideration</a>. If Google's automated scanners find malware on your website, the site will usually not be removed from search results. There is also a different process that removes spammy websites from Google search results. If that's happened and you disagree with Google, you should submit a <a href="http://googlewebmastercentral.blogspot.com/2008/07/requesting-reconsideration-using-google.html">reconsideration request</a>. But if your site has a malware label, a reconsideration request won't do any good — for malware you need to file a malware review from the Overview page.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_LMSk7hTEaIE/SQJAJQN-pYI/AAAAAAAAtck/DOkV2_QwJdQ/s1600-h/example2.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://4.bp.blogspot.com/_LMSk7hTEaIE/SQJAJQN-pYI/AAAAAAAAtck/DOkV2_QwJdQ/s320/example2.png" alt="" id="BLOGGER_PHOTO_ID_5260837842438759810" border="0" /></a><br /><br /><span style="font-weight: bold;">How long will a review take?</span><br />Webmasters are eager to have a Google malware label removed from their site and often ask how long a review of the site will take. Both the original scanning and the review process are fully automated. The systems analyze large portions of the internet, which is big place, so the review may not happen immediately. Ideally, the label will be removed within a few hours. At its longest, the process should take a day or so.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=SIUWOyG4"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=62ZsGul3"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=62ZsGul3" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/FIyRCnLebV4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 10:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/google malware label">google malware label</category>
      <category domain="http://securityratty.com/tag/label">label</category>
      <category domain="http://securityratty.com/tag/malware review">malware review</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/webmaster tools lists">webmaster tools lists</category>
      <category domain="http://securityratty.com/tag/malware label">malware label</category>
      <category domain="http://securityratty.com/tag/webmaster tools">webmaster tools</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/FIyRCnLebV4/malware-we-dont-need-no-stinking.html">Malware? We don't need no stinking malware!</source>
    </item>
    <item>
      <title><![CDATA[Inside a Managed Spam Service]]></title>
      <link>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</link>
      <guid>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</guid>
      <description><![CDATA[A managed spam vendor always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary managed spamming...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/w97lHPkkz7o/s1600-h/managed_spamming_service_2008.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/iBd96sIzD2o/s200-R/managed_spamming_service_2008.jpg" /></a>A <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spam vendor</a> always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">managed spamming system</a>, and is able to provide better spamming rates at a cheaper prices?&nbsp; Market forces and unethical competition at its best.<br />
<br />
So, what is this market challenger using the monopolist's -- in respect to managed spamming services not spam in general -- proprietary system (<a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>) up to anyway? Promising and delivering, 1, 400,000 emails daily, 60,000 mails per hour, and 100 emails per minute. What we've got here are the spam metrics out of 5 already finished spam campaigns that has managed to sent out a million spam emails using only 2000 malware infected hosts. Also, CC-ing and BCC-ing made it possible to multiple the effect of the campaign and increase the total number of emails spammed. Talking about benchmarks, 789 emails per minute at a rate of 12/13 emails per second is a pretty good one, considering it's only 2k bots that they were using. What they also promise is automatic rotation of IPs upon automatically checking them against public blacklists, and a mix rotation of IPs from their own netblocks located in Russia and Germany with the fresh IPs coming from the newly infected hosts.<br />
<br />
Earlier this month, I discussed the market leader's <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming system</a>, access to which they also offer for rent :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/nSP61RrjgSg/s1600-h/spamming_appliance_stats.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/0eV8S8Gv3NA/s200-R/spamming_appliance_stats.jpg" /></a>"<i>An inside look of the system obtained on 2008-08-12 indicates that they are indeed capable of delivering what they promise - speed, simplicity and 5000 malware infected hosts. Moreover, the attached screenshot demonstrates that 20 different email databases can be simultaneously used resulting in 16,523,247 emails about to get spammed using 52 different macroses. Furthermore, what they refer to as a dynamic set of regional servers aiming to ensure that the central server never gets exposed, is in fact fast-flux which depending on how many bots they are willing to put into “rtsegional server mode” shapes the size of the fast-flux network at a later stage.</i>"<br />
<br />
With cutting edge managed spam services like the ones currently in circulation, it remains to be seen whether or not spammers would migrate to this outsourcing model, or continue coming up with adaptive ways to send out their scams and malware on their own.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1n6HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1n6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=69CPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=69CPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JSXmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JSXmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UqH8m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UqH8m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rsD3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rsD3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=myLSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=myLSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PFEmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PFEmm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410205990" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:20:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam services">spam services</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/market follower starts">market follower starts</category>
      <category domain="http://securityratty.com/tag/emails daily">emails daily</category>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/million spam emails">million spam emails</category>
      <category domain="http://securityratty.com/tag/market challenger">market challenger</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410205990/inside-managed-spam-service.html">Inside a Managed Spam Service</source>
    </item>
    <item>
      <title><![CDATA[Microsofts CAPTCHA Under Spammers Attack Again]]></title>
      <link>http://securityratty.com/article/393185090e444ba30508b07635eda9d3</link>
      <guid>http://securityratty.com/article/393185090e444ba30508b07635eda9d3</guid>
      <description><![CDATA[Spammers and malware authors are once again attempting to break Microsofts CAPTCHA, and are able to sign up Live Hotmail accounts with a success rate of 10% to 15%, according to an assessment...]]></description>
      <content:encoded><![CDATA[Spammers and malware authors are once again attempting to break Microsoft’s CAPTCHA, and are able to sign up Live Hotmail accounts with a success rate of 10% to 15%, according to an assessment published by Websense. The &#8220;DomainKeys&#8221; verified server reputation is being abused in order to increase the probability of spam emails reaching the [...]]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 18:36:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsofts captcha">microsofts captcha</category>
      <category domain="http://securityratty.com/tag/live hotmail accounts">live hotmail accounts</category>
      <category domain="http://securityratty.com/tag/server reputation">server reputation</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <category domain="http://securityratty.com/tag/spam emails">spam emails</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/success">success</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <source url="http://cyberinsecure.com/microsofts-captcha-under-spammers-attack-again/">Microsofts CAPTCHA Under Spammers Attack Again</source>
    </item>
    <item>
      <title><![CDATA[Identifying the Gpcode Ransomware Author]]></title>
      <link>http://securityratty.com/article/7fcd166cea35b581caf45eb753d96890</link>
      <guid>http://securityratty.com/article/7fcd166cea35b581caf45eb753d96890</guid>
      <description><![CDATA[Interesting article, but it implies that there has been a shortage of quality OSINT regarding the campaigners behind the recent Gpcode targeted cryptoviral extortion attacks

The individual is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKf-AHSSyI/AAAAAAAACNA/2DxahyQID7E/s1600-h/gpcode_decryptor.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKf-AHSSyI/AAAAAAAACNA/xl-jNWBubqU/s200-R/gpcode_decryptor.jpg" /></a>Interesting article, but it implies that <a href="http://www.techworld.com/security/news/index.cfm?newsid=105043">there has been a shortage of quality OSINT</a> regarding the campaigners behind the recent <a href="http://it.slashdot.org/article.pl?sid=08/09/30/1446211">Gpcode targeted cryptoviral extortion attacks</a> :<br />
<br />
"<i>The individual is believed to be a Russian national, and has been in contact with at least one anti-malware company, Kaspersky Lab, in an attempt to sell a tool that could be used to decrypt victims' files. Kaspersky Lab set about locating the man by resolving the proxied IP addresses used to communicate with the world to their real addresses. The proxied addresses turned out to be zombie PCs in countries such as the US, which pointed to the fact that GPcode's author had almost certainly used compromised PCs from a single botnet to get Gpcode on to victim's machines.</i>"<br />
<br />
In reality, there hasn't been a shortage of timely OSINT aiming to to identify the authors - "<a href="http://blogs.zdnet.com/security/?p=1259">Who’s behind the GPcode ransomware?</a>" :<br />
<br />
"<i>So, the ultimate question - who’s behind the GPcode ransomware? It’s Russian  teens with pimples, using E-gold and Liberty Reserve accounts, running three  different GPcode campaigns, two of which request either $100 or $200 for the  decryptor, and communicating from Chinese IPs. Here are all the details  regarding the emails they use, the email responses they sent back, the currency  accounts, as well their most recent IPs used in the communication (<b>58.38.8.211; </b><b>221.201.2.227</b>) :</i><br />
<br />
<i><b>Emails used by the GPcode authors where the infected victims are  supposed to contact them :</b><br />
content715@yahoo .com<br />
saveinfo89@yahoo  .com<br />
cipher4000@yahoo .com<br />
decrypt482@yahoo .com</i><br />
<br />
<i><b>Virtual currency accounts used by the malware authors  :</b><br />
Liberty Reserve - account U6890784<br />
E-Gold - account -  5431725<br />
E-Gold - account - 5437838</i>"<br />
<br />
The bottom line - out of the four unique emails used by the GPcode campaigners, only two were actively corresponding with the victims, each of them requesting a different amount of money, but both, taking advantage of U.S based web services to accomplish their attack.<i></i><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bQZsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bQZsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q8qRL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q8qRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UNhel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UNhel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SUDkl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SUDkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d50OL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d50OL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RaaqL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RaaqL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YsUgl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YsUgl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407661528" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 13:23:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gpcode">gpcode</category>
      <category domain="http://securityratty.com/tag/gpcode campaigns">gpcode campaigns</category>
      <category domain="http://securityratty.com/tag/recent gpcode">recent gpcode</category>
      <category domain="http://securityratty.com/tag/gpcode ransomware">gpcode ransomware</category>
      <category domain="http://securityratty.com/tag/gpcode campaigners">gpcode campaigners</category>
      <category domain="http://securityratty.com/tag/gpcode authors">gpcode authors</category>
      <category domain="http://securityratty.com/tag/kaspersky lab">kaspersky lab</category>
      <category domain="http://securityratty.com/tag/virtual currency accounts">virtual currency accounts</category>
      <category domain="http://securityratty.com/tag/liberty reserve accounts">liberty reserve accounts</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407661528/identifying-gpcode-ransomware-author.html">Identifying the Gpcode Ransomware Author</source>
    </item>
    <item>
      <title><![CDATA[Root of Trust ?]]></title>
      <link>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</link>
      <guid>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</guid>
      <description><![CDATA[Ive given some talks this year about the Internets insecure infrastructure stressing that fundamental protocols such as BGP and DNS cannot really be trusted at the moment. Although they work just fine...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;ve given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080211-mailserver.pdf">some</a> <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080915-ISPsecurity.pdf">talks</a> this year about the Internet&#8217;s insecure infrastructure &#8212; stressing that fundamental protocols such as <a href="http://www.bgp4.as/">BGP</a> and <a href="http://oreilly.com/catalog/9780596100575/">DNS</a> cannot really be trusted at the moment. Although they work just fine most of the time, they are susceptible to attacks which can mean, for example, that you visit the wrong website, or your email is intercepted.</p>
<p>Steps are now being taken, <a href="http://voices.washingtonpost.com/securityfix/2008/08/dns_security_mandatory_for_all.html">rather faster</a> since Dan Kaminsky came up with a <a href="http://www.doxpara.com/?p=1185">really effective DNS poisoning attack</a>, to secure DNS by using <a href="http://www.dnssec.net/">DNSSEC</a>.</p>
<p>The basic idea of DNSSEC is that when you get an answer from the DNS it will be signed by someone you trust. At some point the &#8220;trust anchor&#8221; for the system will be &#8220;.&#8221; the DNS root, but for the moment there&#8217;s <a href="http://www.unbound.net/documentation/howto_anchor.html">just a handful of &#8220;trust anchors&#8221; one level down</a> from that. One such anchor is the &#8220;.se&#8221; country code domain for Sweden. Additionally, Brazil (.br), Puerto Rico (.pr), and Bulgaria (.bg) have signed their zones, but that&#8217;s about it for today.</p>
<p>So, wishing to get some experience with the <a href="http://www.sparknotes.com/lit/bravenew/">brave new world</a> of DNSSEC, I decided that Sweden was <a href="http://www.cartoonbank.com/item/25468">the &#8220;in&#8221; place to be</a>, and to purchase &#8220;cloudba.se&#8221; and roll out my first DNSSEC signed domain.</p>
<p>The purchase wasn&#8217;t as easy as it might have been &#8212; when you buy a domain, Sweden <a href="http://www.iis.se/docs/general_conditions.pdf">insists</a> that people provide their <a href="http://www.papersplease.org/id.html">identity numbers</a> (albeit they have absolutely no way of checking if you&#8217;re telling the truth) &#8212; or if a company they want a VAT or registration number (which are checkable, albeit I suspect they didn&#8217;t bother). I also found that they don&#8217;t like spaces in the VAT number &#8212; which held things up for a while!</p>
<p>However, eventually they sent me a PGP signed email to tell me I was now the proud owner of &#8220;cloudba.se&#8221;.  Unfortunately, this email wasn&#8217;t in RFC3156 PGP/MIME format (or any other format that my usually <a href="http://en.wikipedia.org/wiki/Turnpike_(software)">pretty capable email client</a> understood).</p>
<p>The email was signed with key 0xF440EE9B which was reassuring because the <a href="http://www.iis.se/">.se registry</a> gives the fingerprint for this key on their website <a href="https://domainmanager.iis.se/start/customerservice">here</a>. Rather less reassuringly footnote (*) next to the fingerprint says &#8220;<em>.SE signature for outgoing e-mail. (**) June 1 through August 31.</em>&#8221; (the (**) is for a second level of footnote, which is absent &#8212; and of course it is now September).</p>
<p>They also enable you to fetch the key through a link on <a href="http://www.iis.se/support">this page</a> to their &#8220;PGP nyckel-ID&#8221; at <a href="http://subkeys.pgp.net:11371/pks/lookup?op=get&#038;search=0xFCEC5128F440EE9B">http://subkeys.pgp.net</a>.</p>
<p>Unfortunately, fetching the key shows that the signature on the email is invalid.</p>
<p>Since the email seems to have originated in the Windows world, but was signed on a Linux box (giving it a mixture of 0D 0A and 0A line endings), then pushed through a three year old copy of <a href="http://search.cpan.org/dist/MIME-tools/">MIME-tools</a> I suppose the failure isn&#8217;t too surprising. But strictly the invalid signature means that I shouldn&#8217;t trust the email&#8217;s contents at all &#8212; because the contents have definitely been tampered with since the signature was applied.</p>
<p>Since the point of the email was to get me to login for the first time to the registry website and set my password to control the domain, this is a little <a href="http://www.cartoonbank.com/item/32907">unfortunate</a>.</p>
<p>Even if the signature had been correct, then should I trust the PGP key?</p>
<p>Well it is pointed to from the registry website which is a Good Thing. However, they do themselves no favours by referencing a version on <a href="http://www.rossde.com/PGP/pgp_keyserv.html">the public key servers</a>. I checked who had signed the key (which is an <a href="http://www.pgpi.org/doc/pgpintro/#p20">alternative way of trusting its provenance</a> &#8212; since the email had arrived to a non-DNSSEC secured domain). Turned out there was no-one I knew, and of 4 individual signatures, 2 were from expired keys. The other signature was the IIS root key &#8212; which sounds promising. That has 8 signatures, once again not people I know &#8212; but only 1 from a non-expired key, so perhaps I can get to know some of the other 7?</p>
<p>Of course, anyone can sign a key on a public key server, so perhaps it makes sense for .se to suggest that people fetch a key with as many signatures as possible &#8212; there&#8217;s more chance of it being signed by someone they know. Anyway, I have now added my own signature, using an email address at my nice shiny new domain. However, it is possible that I may not have increased the level of trust <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/09/signers.png" alt="" title="Signers of the .se PGP key" class="aligncenter size-full wp-image-381"></p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/public key servers">public key servers</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/iis root key">iis root key</category>
      <category domain="http://securityratty.com/tag/key 0xf440ee9b">key 0xf440ee9b</category>
      <category domain="http://securityratty.com/tag/pgp">pgp</category>
      <category domain="http://securityratty.com/tag/pgp nyckel-id">pgp nyckel-id</category>
      <category domain="http://securityratty.com/tag/public key server">public key server</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/29/root-of-trust/">Root of Trust ?</source>
    </item>
    <item>
      <title><![CDATA[Hijacking a Spam Campaign's Click-through Rate]]></title>
      <link>http://securityratty.com/article/358230080f61bb4bcad67ebc2f133eb5</link>
      <guid>http://securityratty.com/article/358230080f61bb4bcad67ebc2f133eb5</guid>
      <description><![CDATA[This spammer is DomainKeys verified , a natural observation considering that the spam compaign which I discussed last Wednesday is using bogus Yahoo Mail accounts , and is spamming only Yahoo Mail...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNzw2ZH_biI/AAAAAAAACMA/EJXYGgjLy2M/s1600-h/yahoo_internal_spam_domainkeys.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNzw2ZH_biI/AAAAAAAACMA/RySX2DJUDPo/s200-R/yahoo_internal_spam_domainkeys.JPG" /></a>This <a href="http://blogs.zdnet.com/security/?p=1514">spammer is DomainKeys verified</a>, a natural observation considering that the <a href="http://ddanchev.blogspot.com/2008/09/spam-campaign-abusing-yahoos-services.html">spam compaign which I discussed</a> last Wednesday is using <a href="http://blogs.zdnet.com/security/?p=1418">bogus Yahoo Mail accounts</a>, and is spamming only Yahoo Mail users through a segmented emails database.<br />
<br />
Not necessarily what I wanted to achieve, but once posting the spam campaigns SEO URLs, Yahoo's crawler's picked up the post pretty fast, and have ruined the SEO effect, with everyone clicking on the campaign's links reaching the post. Close to 15,000 unique visitors reached the article during the past 7 days since the now hijacked, spammer's link is no longer achieving the effect it used to.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SNz3efpaxFI/AAAAAAAACMI/KL7ULqT84Eg/s1600-h/replicas.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SNz3efpaxFI/AAAAAAAACMI/bdmpOhgXjcc/s200-R/replicas.png" /></a>What does this prove? It proves that users tend to trust emails that pass through spam filters so much that they actually click on the links. And whereas it's a spam campaign, and not a malware campaign, the next time they over trust such a email, they'll expose themselves to client-side vulnerabilities coursesy of a copycat web malware exploitation kit.<br />
<br />
<b>The latest search query the campaign is using :</b><br />
- yahoo.com/search/search;_ylt=?p=...........................................stossregularnew............$0.00.........<br />
<br />
leads to <b>stossregularnew.com</b> (61.255.135.185).<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zc4WL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zc4WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iPkXL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iPkXL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NeKHl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NeKHl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=L8wul"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=L8wul" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q5ZQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q5ZQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FtyJL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FtyJL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EhWl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EhWl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/403855063" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 06:07:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/spam campaign">spam campaign</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/yahoo mail users">yahoo mail users</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/post pretty fast">post pretty fast</category>
      <category domain="http://securityratty.com/tag/trust emails">trust emails</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/403855063/hijacking-spam-campaigns-click-through.html">Hijacking a Spam Campaign's Click-through Rate</source>
    </item>
    <item>
      <title><![CDATA[250k of Harvested Hotmail Emails Go For?]]></title>
      <link>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</link>
      <guid>http://securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</guid>
      <description><![CDATA[50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/fQ_TqPImTk0/s1600-h/harvested_hotmail_sale.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="113" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/YJqc75ZUQgE/s200-R/harvested_hotmail_sale.png" width="200" /></a>$50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to know about. Moreover, what someone is offering for sale, may in fact be already available as a value-added addition to a managed spamming service.<br />
<br />
With metrics and quality assurance applied in a growing number of spam and phishing campaigns, filling in the niche of email harvesting by distinguishing between different types of obfuscated emails by releasing an easily embeddable module, was an anticipated move. What's to come? <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Spam and malware campaigns across social networks</a> "as usual" will propagate faster thanks to the ongoing harvesting of usernames within social networks, that would later on get imported in Web 2.0 "marketing" tools targeting the high-trafficked sites and automatically spamming them.<br />
<br />
From a spammer's perspective, geolocating these 250k emails could increase their selling prices since the buyers would be able to launch localized attacks with messages in the native languages of the receipts. Is the demand for quality email databases fueling the developments of this market segment, or are the spammers self-serving themselves and cashing-in by reselling what they've already abused a log time ago? That seems to be the case, since there's no way a buyer could verify the freshness of the harvested emails database and whether or not it has already been abused. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/yhy61idSl6I/s1600-h/segmented_harvested_emails.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/xFYzYTCaDes/s200-R/segmented_harvested_emails.JPG" width="152" /></a>For the time being, we've got several developed and many other developing market segments within spamming and phishing as different markets with different players. On one hand are the legitimately looking spamming providers offering "direct marketing services" working with lone spammers who find a reliable business partner in the face of the spamming vendor whose customers drive both side's business models. On the other hand, you've got the <a href="http://blogs.zdnet.com/security/?p=1835">spammers excelling in outsourcing the automatic account registration process</a>, coming up with ways to build a spamming infrastructure -- already available as a module to integrate in <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming services</a> -- using legitimate services as a provider of the infrastructure.<br />
<br />
Despite that the arms race seems to be going on at several different fronts, spammers VS the industry and spammers VS spammers fighting for market share, the entire underground ecosystem is clearly allocating a lot of resources for research and development in order to ensure that they are always a step ahead of the industry.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting  Youtube Usernames for Spamming</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands  of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic  Email Harvesting 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - the Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/inside-email-harvesters-configuration.html">Inside an Email Harvester's Configuration File</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">Segmenting and Localizing Spam Campaigns</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample.html">Shots from the Malicious Wild West - Sample Four</a><br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=De2zL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=De2zL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CYcFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CYcFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OQPDl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OQPDl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lhexl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lhexl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sZRFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sZRFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ifNGL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ifNGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BYibl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BYibl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402968423" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 08:13:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email harvester">email harvester</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/lone spammers">lone spammers</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <category domain="http://securityratty.com/tag/250k emails">250k emails</category>
      <category domain="http://securityratty.com/tag/automatic email">automatic email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402968423/250k-of-harvested-hotmail-emails-go-for.html">250k of Harvested Hotmail Emails Go For?</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
  </channel>
</rss>
