<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: engage]]></title>
    <link>http://securityratty.com/tag/engage</link>
    <description></description>
    <pubDate>Wed, 04 Jun 2008 06:55:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</link>
      <guid>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place. </p>

<p>Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf. </p>

<p>If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections. </p>

<p>Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> published this year in International Security that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers: </p>

<p>Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved. </p>

<p>Abrahms has an alternative model to explain all this: People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States. </p>

<p>The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida. </p>

<p>For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist. </p>

<p>All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion. </p>

<p>This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups. </p>

<p>We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.</p>

<p>This essay <a href="http://www.wired.com/print/politics/security/commentary/securitymatters/2008/10/securitymatters_1002">previously appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QW5fM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QW5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YCnjM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YCnjM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 01:48:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_seven_habit.html">The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</link>
      <guid>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>
Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place.
</p>

<p>
Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf.
</p>

<p>
If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections.
</p>

<p>
Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> (.pdf) published this year in <cite>International Security</cite> that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers:
</p>

<p>
Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved.
</p>


<p>
Abrahms has an alternative model to explain all this:  People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States.
</p>

<p>
The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida.
</p>

<p>
For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist.
</p><p>
All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion.
</p><p>
This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups.
</p><p>
We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=16939d16056d6d01accd415177a76dbb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=16939d16056d6d01accd415177a76dbb" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=igbdM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=igbdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=CO91m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=CO91m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rBiKm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rBiKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=qO8rM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=qO8rM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=0b0DM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0b0DM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nYn4m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nYn4m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EcnRm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EcnRm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UhYOM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UhYOM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/408903389" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/408903390" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/408903390/securitymatters_1002">Security Matters: The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Gambling Domains Seized by Kentucky]]></title>
      <link>http://securityratty.com/article/b2a12ce3b79bb2383d563ad1918217f7</link>
      <guid>http://securityratty.com/article/b2a12ce3b79bb2383d563ad1918217f7</guid>
      <description><![CDATA[From reports, it appears that Kentucky Governor Steve Beshear has attempted to seize 141 gambling-related domain names under a state law that allows for seizure of items used for illegal gambling. It...]]></description>
      <content:encoded><![CDATA[From reports, it appears that Kentucky Governor Steve Beshear has attempted to seize 141 gambling-related domain names under a state law that allows for seizure of items used for illegal gambling. It appears that the seizure order (<a href="http://www.thedomains.com/wp-content/order-of-seizure-of-domain-names.pdf">click here for a copy of the initial order</a>) was signed by a circuit judge, but <a href="http://www.thedomains.com/2008/09/26/kentucky-hearing-update/">later reports indicate that the judge is holding further hearings and seeking further arguments</a>. A hearing will be held Oct. 7, <a href="http://www.thedomains.com/2008/09/26/kentucky-hearing-update/">according to TheDomains</a>.

See page 4 of the seizure order for a complete list of the 141 domains. Here are some of them:
<ul><li>123bingo.com</li>
	<li>777dragon.com</li>
	<li>indiancasino.com</li>
	<li>jackpotcity.com</li>
	<li>powerbet.com</li>
	<li>crazypoker.com</li>
	<li>vegaslucky.com</li></ul>

That sort of thing.

According to DomainNameNews, <a href="http://www.domainnamenews.com/up-to-the-minute/kentucks-seizes-141-gambling-domain-names/2413">several of the domains are for popular sites</a>, including PokerStars.com, FullTiltPoker.com, BodogLife.com, GoldenPalace.com, Bet21.com, DoylesRoom.com and IndianCasino.com. It also reports that <a href="http://www.domainnamenews.com/up-to-the-minute/ica-responds-to-kentucky-seizure-of-gambling-domains/2584">at least one registrar (Enom) has transferred domains pursuant to the order</a>, including one whose registrant died of a heart attack this summer.

The seizure order says that the domains are to be transferred by any registrar to a plaintiff's account at that registrar (the plaintiff being the Commonwealth of Kentucky), but that the domain names' configuration will be otherwise unchanged. This means that any gambling sites run on those domains or, for that matter, anything else on those domains, such as PPC ads, would remain functional.

All things considered, this seems like simple-minded grandstanding without any good law behind it. The Constitution vests Congress with power to regulate interstate commerce, which the domain name market clearly is. In fact, these businesses are truly international. And it's a safe bet that none of the gambling companies or registrars operates in Kentucky, perhaps not even any of the domain name holders. That the state argues that residents of Kentucky engage in illegal gambling doesn't give the state jurisdiction. The Internet Commerce Association, a domainer lobby, <a href="http://www.domainnamenews.com/up-to-the-minute/ica-responds-to-kentucky-seizure-of-gambling-domains/2584">has weighed in on the matter in opposition to the state's move</a>.
<p><a href="http://feedads.googleadservices.com/~a/FslEfsv6x1qu8Vcy3lti-mPyruM/a"><img src="http://feedads.googleadservices.com/~a/FslEfsv6x1qu8Vcy3lti-mPyruM/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/x8jm5xd8NoU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 03:32:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/kentucky">kentucky</category>
      <category domain="http://securityratty.com/tag/domains pursuant">domains pursuant</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/domain names">domain names</category>
      <category domain="http://securityratty.com/tag/kentucky engage">kentucky engage</category>
      <category domain="http://securityratty.com/tag/internet commerce association">internet commerce association</category>
      <category domain="http://securityratty.com/tag/seizure">seizure</category>
      <category domain="http://securityratty.com/tag/commerce">commerce</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/x8jm5xd8NoU/gambling_domains_seized_by_kentucky.html">Gambling Domains Seized by Kentucky</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: The ROI of Social Networking]]></title>
      <link>http://securityratty.com/article/8c52c835add6dca7c33f67c83e868434</link>
      <guid>http://securityratty.com/article/8c52c835add6dca7c33f67c83e868434</guid>
      <description><![CDATA[How do you derive business value from social networks
Moderator: Nick Hoover, Senior Editor, InformationWeek
Speaker - Anne Berkowitch, Co-Founder &amp; CEO, SelectMinds
Speaker - J.B. Holston, CEO and...]]></description>
      <content:encoded><![CDATA[<p>How do you derive business <a href="http://www.interop.com/newyork/conference/enterprise-20.php" target="_blank">value from social networks</a>?</p>
<ul>
<li>Moderator: Nick Hoover, Senior Editor, InformationWeek</li>
<li>Speaker - Anne Berkowitch, Co-Founder &amp; CEO, SelectMinds</li>
<li>Speaker - J.B. Holston, CEO and President, NewsGator</li>
<li>Speaker - Umberto Milletti, CEO, InsideView</li>
</ul>
<p>Businesses can take advantage of social networks by finding innovative ways to reach out to people. Looking at who you know and how you know them can benefit you. Knowing a personal connection to someone that you are trying to contact (for sales) is helpful. The blurring between home, personal, and business life is making this information more available and better able to leverage. People are able to capture more valuable long term information from social networks.</p>
<p>A lot of social network applications can be taken from the talent management space. Deploying alumni networks as a talent source is also a great asset. Alumni represent a well-known and relevant population. This provides a great economic benefit from a social network.</p>
<p>If you are running a sales organization and looking at building a pipeline of leads, consider how these leads are relevant. The ability to get more leads is apparent in finding the right person, right connection, and right contact. Underlying everything are productivity and efficiency. How much time are sales reps spending researching and pursuing each opportunity? With information on social networks, the time can be greatly decreased. Knowledge sharing is something that can be actively measured.</p>
<p>The ROI varies with the business issue that&#8217;s trying to be addressed by a particular network. Recruiting for example has a very concrete, measurable ROI. Knowledge share gets a little more tricky. How do you measure how much is shared and the impact on business systems? Businesses need to determine what specific goal they are trying to address.</p>
<p>CFOs want to see ROI, not intuitive information. If you can demonstrate engagement and participation in these networks and knowledge sharing tools, more and more executives are getting comfortable seeing how it&#8217;s used at a qualitative and process level. It&#8217;s a very case by case basis.</p>
<p>One major crisis that we see in our customers is the competition between sales and marketing. Each wants to do their own thing, they go together like oil and water. However, the push of the economy is now forcing them work together. This is a great opportunity for IT to step in and help them collaborate and be more productive.</p>
<p>Other resistance from companies are how to manage what they are trying to accomplish while still giving employees free reign of sites like Facebook. What are the incentives for using these technologies? How does it fit into your company culture and productivity scale? You must bring meaning to the structure of engaging in social networks.</p>
<p>Social networks like LinkedIn and Facebook would not exist if people did not contribute information to them. However, if people don&#8217;t know that it is there, it does not exist. People need to see the value and get drawn in to engage. There are two ways that companies get into social networks. Tie it into the business process. The general idea of social networks are intuitive and easy to understand, which make it an easier case to present to chief executives. Make it clear - how do you go about it and what&#8217;s the value?</p>
<p>Social networks are intrinsically about extending the network, the more contacts you have, the more to choose from when researching a specific contact. It also has to be integrated into your dataworkflow. Companies are going to build a variety of networks inside and outside the enterprise. The big companies (SAP, IBM) are all rushing to offer collaborative and social network functionality. However, this is not entirely useful unless it&#8217;s integrated into the entire infrastructure.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 17:54:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alumni networks">alumni networks</category>
      <category domain="http://securityratty.com/tag/social network applications">social network applications</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/social network">social network</category>
      <category domain="http://securityratty.com/tag/networks inside">networks inside</category>
      <category domain="http://securityratty.com/tag/social networks">social networks</category>
      <category domain="http://securityratty.com/tag/social network functionality">social network functionality</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/roi">roi</category>
      <source url="http://blog.sciencelogic.com/interop-ny-the-roi-of-social-networking/09/2008">Interop NY: The ROI of Social Networking</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial - Part Two]]></title>
      <link>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</link>
      <guid>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</guid>
      <description><![CDATA[Malware authors seeking financial gains from releasing their trojans often promote them as Remote Access Tools , which if we exclude the built-in anti-sandboxing and antivirus software killing...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/No0eDRtdb8s/s1600-h/hire_to_hack.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/BK1B_uN_Iew/s200-R/hire_to_hack.png" style="border: 0pt none ;" /></a>Malware authors seeking financial gains from releasing their trojans often promote them as <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Access Tools</a>, which if we exclude the built-in anti-sandboxing and antivirus software killing capabilities, <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">could pass for a RAT</a>. In a similar deceptive fashion, <a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">email hacking services are pitched as email password recovery services</a>. <br />
<br />
Hacking as a Service sites seems to be popping out like mushrooms these days, thanks primarily due to the fact that yesterday's script kiddies are today's entrepreneurs trying to even monetize the process of bruteforcing. Here's their pitch :<br />
<br />
"<i>Well.. There is nothing different in our       services. Like other group, we simply crack email addresses       , and provide you the current password used by the victim to       you for a suitable price. Nothing unique that we can brag       about....&nbsp; We don't hack NASA or CIA , we cannot hack a       bank and steal a million dollars.. We just crack email       password .. AND WE DO A HECK OF A JOB IN IT !! We cannot be as presentable as the other       groups, trying to look as formal and corporate, as if they       are running a Major Corporate Office. However they present       it...password retrieval, online investigation.. access       recovery...blah blah blah..&nbsp; the most simplest way to       put it is.. : Email Password Cracking: !! And since everyone else is busy faking       it, or trying to be more presentable, we utilize our skills       to get you what you want.. i.e. THE EMAIL PASSWORD. No       buttering up, no marketing skills..&nbsp; plain hardcore       hacking !! So, since you now know what we do , and       want us to do the job for you, please proceed to the order       page for your relevant TARGET EMAIL and submit your request.       All said and done, we will get the elusive password &amp; send       you a couple of proofs. You decide upon the authenticity of       the proofs, and let us know if you are comfortable going       ahead with the payment. PAY US, AND YOU GET THE PASSWORD !And as they say.......</i>"<br />
<br />
How much are they charging for the bruteforcing? $150 for starters, which is prone to increase due to their bla bla bla about how sophisticated it was to obtain the password - given they actually manage to deliver the goods :&nbsp; <br />
<br />
<div class="separator" style="text-align: center; clear: both;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/aVdgDf7K46o/s1600-h/hire_to_hack1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/wsy8qQ3XtGQ/s200-R/hire_to_hack1.png" style="border: 0pt none ;" width="200" /></a></div>"<i>Many groups charge a fixed price for an email cracking. We undertake more kinds of projects than anyone else. Frankly, each email is a different project in itself. We cannot charge you $100, for something which we can do for $50. Subsequently, we cannot charge you $100, for something which should be priced at $200. But we charge a minimum of $150 USD so that we end up taking orders from ONLY those who really need it. It is a small amount for the level of satisfaction, facts/truth and relief that you would ultimately achieve from this.It depends upon the nature of the job, the accessibility factor. and many other reasons likes:-<br />
<br />
1- The email service provider<br />
2- The target itself. How net-savvy he/she is.<br />
3- Complexity of the password<br />
4- Urgency of job and many other things collectively.<br />
<br />
We will let you know our charges once we have the desired results only. Be assured, we wont charge you the moon. We charge only what we deserve, and is acceptable by you. Trust us !!</i>"<br />
<br />
Some of their answers to the frequently asked questions :<br />
<br />
" <i>- <b>Who are you? Where are you from</b>?<br />
We are Hire2Hack Group. Member of our group are students in information technology, at some university in England, France, Italy, Japan, Australia, Canada, Brasilia and at United States of America.<br />
<br />
- <b>What services do you provide?</b><br />
We can hack ANY EMAIL password for you very fast, reliable, secure and worldwide for a suitable price.<br />
<br />
- <b>Can you really hack password or just a making a shit scam?</b><br />
Well, lot of people, lot of groups, companies do this service, but not guaranteed. This is only you can choose which group you want to Order. Be careful with these people. You can believe only on them who claims to provide proof before you really pay them.<br />
<br />
- <b>Is there any tool available to crack password?</b><br />
Yes there is. And we are not giving it to you.<br />
<br />
- <b>How long does it takes to crack a password?</b><br />
Each account is different and hacking time vary. On average, it might take about 1 to 3 days, but it may take anywhere from 24 hours to 30 days or more depending on how difficult is the hacking of each account.<br />
<br />
- <b>How can I believe you, that you got password?</b><br />
We will provide you some good proofs before requesting you to pay us. The proof can be anything, you can decide what kind proof you need.<br />
<br />
- <b>Is there person will know that his/her email id has been cracked?</b><br />
No, we provide you only the original password. That mean the current active password. Your victim/target will not realized that she/he has been hacked. NEVER, we said !<br />
<br />
- <b>How I will pay you, I do not have credit card or I do not want to give my credit card number on net?</b><br />
Well, you can use international money transfer service such as Western Union (www.westernunion.com) or Money Gram (www.moneygram.com). These services immediate transfer money on same day or same hour. You can locate their agents in yours area from their website.<br />
<br />
- <b>Do I have to give you my password?</b><br />
No. Any service which requires your password is simply trying to scam you out of access to your account.<br />
<br />
- <b>How will I know you really have the password?</b><br />
We will show you the proofs.. which are mostly convincing.<br />
<br />
- <b>Since you have the password anyway, will you give it to me?</b><br />
NO. Do not waste your time or ours. We will not release the password until full payment is made - no exceptions. We have had people request our service and once we recover the password, they reset the subject account then ask us for the original password so they can reset it back - the answer will be no. We have also had people ask if they could have the password since we've already recovered it and they cannot pay - the answer will be no. No password will be released until payment has been made in full - no exceptions.<br />
<br />
- <b>Will you recover more than one password? Can I request more than one email account?</b><br />
Yes, but a separate request must be filled out for each one as you will only be billed for each successful recovery. If we have previously recovered a password for you and you have not paid, we will not begin any new request for you until your previous request is paid in full with exceptions for our established clientele. We charge at minimum US $100 for each account hacked.<br />
<br />
- <b>Do you reset or change the current password?</b><br />
No. We do not try to guess the current password or the secret question's answer, we do not change their password. We give you only the Original password, which the victim is currently using.<br />
<br />
- <b>Is this confidential? Do you share my information with anyone else</b>?<br />
No, Not at all, Not in any case, its a trust between you and us. Your information will be respected as long as you abide by our Terms and Conditions and Privacy policy. We keep your personal records and requests confidential in our database but we respect your right to privacy and will not rent, share, sell, or trade any personal information unless required by law. <b>But, if you engage in any spamming or fraudulent actives, Your information will be given to the appropriate authorities.</b></i>"<br />
<br />
So you've got script kiddies cracking email addresses and probably engaging in the rest of the usual cybercrime activities, who are spam sensitive, and would expose their customers if they start spamming from the cracked emails? Now that's socially responsible, isn't it.<br />
<br />
Targeted attacks are sexy, but bruteforcing email accounts no matter the number of proxies and wordlists that they have access to is so irrelevant, that social engineering a potential victim into infecting herself with malware through a live exploit URL seems to be the method of choice, next to a plain simple phishing email of course. In this case, what they're asking for in respect to the victim's details is the victim's country and victim's language, so that a localized social engineering or phishing attack can take place. However, this particular group seems to be using a standard bruteforcing tool.<br />
<br />
One thing's for sure - cybercrime is getting easier to outsource, and with potential customers starting to have access to services they didn't a couple of years ago, <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">fake scammers are also emerging in between the real ones</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q4SazK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q4SazK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v68SQK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v68SQK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fTxCfk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fTxCfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m5GSCk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m5GSCk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rFpJlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rFpJlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hDloOK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hDloOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kzNwqk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kzNwqk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/359698182" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:31:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crack password">crack password</category>
      <category domain="http://securityratty.com/tag/crack">crack</category>
      <category domain="http://securityratty.com/tag/crack email password">crack email password</category>
      <category domain="http://securityratty.com/tag/email password">email password</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/original password">original password</category>
      <category domain="http://securityratty.com/tag/current password">current password</category>
      <category domain="http://securityratty.com/tag/password retrieval">password retrieval</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/359698182/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</source>
    </item>
    <item>
      <title><![CDATA[CyberAngels has a great piece on CyberBullying]]></title>
      <link>http://securityratty.com/article/4f0b9874a55b3e6d156c1bc978ec49ec</link>
      <guid>http://securityratty.com/article/4f0b9874a55b3e6d156c1bc978ec49ec</guid>
      <description><![CDATA[If youre a parent, take the time to read this great article, for your kids sake. Then talk to them about it. You remember how tough it was to be a kid when there was no Internet right? Imagine being...]]></description>
      <content:encoded><![CDATA[<div > If you&#8217;re a parent, take the time to read this great article, for your kids sake.<br/>Then talk to them about it.<br/>You remember how tough it was to be a kid when there was no Internet right?<br/>Imagine being bulled with zeros and ones. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/16C6CB3E-AA76-470C-999A-04955CD39F9D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/c8340db8-7f6d-43f6-92ec-36806a75183d/16C6CB3E-AA76-470C-999A-04955CD39F9D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.cyberangels.org/" href="http://www.cyberangels.org/" style="font-size: 11px;">www.cyberangels.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.cyberangels.org/ --> Cyberbullying</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.cyberangels.org/ --><DIV><STRONG></STRONG><br />
The feeling of anonymity on the web makes it a perfect playground for students to engage in cruel behavior. A study from the National Crime Prevention Council (NCPC) says that 43 percent of teens reported being victims of cyberbullying in the past year. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/16C6CB3E-AA76-470C-999A-04955CD39F9D/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 11:39:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kids sake">kids sake</category>
      <category domain="http://securityratty.com/tag/cyberangels">cyberangels</category>
      <category domain="http://securityratty.com/tag/cruel behavior">cruel behavior</category>
      <category domain="http://securityratty.com/tag/perfect playground">perfect playground</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/past">past</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=527">CyberAngels has a great piece on CyberBullying</source>
    </item>
    <item>
      <title><![CDATA[Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings]]></title>
      <link>http://securityratty.com/article/ea68adf4b019a71c0112661ffc8d8bf1</link>
      <guid>http://securityratty.com/article/ea68adf4b019a71c0112661ffc8d8bf1</guid>
      <description><![CDATA[It used to be a case where a botnet would be used for a single purpose, spamming, phishing, or malware spreading. At a later stage, the steady supply of malware infected allowed botnet masters more...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SI3DACirIII/AAAAAAAAB-M/mbToBJwm1uU/s1600-h/storm_pharma.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SI3DACirIII/AAAAAAAAB-M/YWIdXnUoPoU/s200-R/storm_pharma.png" style="border: 0pt none ;" /></a>It used to be a case where a botnet would be used for a single purpose, spamming, phishing, or malware spreading. At a later stage, the steady supply of malware infected allowed botnet masters more opportunities to "sacrifice" the clean IP reputation and engage in several malicious activities simultaneously - <a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">today's underground multitasking</a> improving the monetization of what used to be commodity goods and services.<br />
<br />
Today, a botnet will not only be <a href="http://ddanchev.blogspot.com/2008/02/inside-botnets-phishing-activities.html">sending out phishing emails</a>, automatically <a href="http://blogs.zdnet.com/security/?p=1122">SQL inject vulnerable sites across the web</a>, but also, provide <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux infrastructure to money mule recruitment services</a>, all of this for the sake of optimizing the efficiency provided by the botnet in general. This <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">optimization makes it possible for a single botnet to be partitioned</a> and access it it <a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">sold and resold so many times</a>, that it would be hard to keep track of all the malicious activities it participates in. Cybercrime in between on multiple fronts using a single botnet is only starting to take place as concept.<br />
<br />
That's the case with Stormy Wormy, according to IronPort whose "<a href="http://www.darkreading.com/document.asp?doc_id=156139&amp;WT.svl=news1_1">Researchers Link Storm Botnet to Illegal Pharmaceutical Sales</a>" : <br />
<br />
"<i>Our previous research revealed an extremely sophisticated supply chain behind the illegal pharmacy products shipped after orders were placed on botnet-spammed Canadian pharmacy websites. <b>But the relationship between the technology-focused botnet masters and the global supply chain organizations was murky until now</b>," said Patrick Peterson, vice president of technology at IronPort and a Cisco fellow. "Our research has revealed a smoking gun that shows that Storm and other botnet spam generates commissionable orders, which are then fulfilled by the supply chains, generating revenue in excess of (US)$150 million per year.</i>"<br />
<br />
Murky until now? I can barely see in the room due to all the smoke coming from the smoking guns of who's what, what's when, and who's done what with who, especially in respect to Storm Worm whose multitasking on different fronts in the first stages of their appearance online made it possible to establish links between several different malware groups and the "upstream hosting providers", until the botnet scaled enough making it harder to keep track of all of their activities.<br />
<br />
<a href="http://www.ironport.com/malwaretrends/">The Storm Worm-ers themselves aren't sending out pharma spam</a>, the customers to whom they've sold access to parts of Storm Worm are the ones sending the pharma spam. Here's a brief analysis published in May - "<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a>". What's in it for the scammers? Income based on a revenue-sharing affiliate program, <a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html">a pharmacy affiliate program</a> has been around for several years :<br />
<br />
"<i>This criminal organization recruits botnet spamming partners to advertise their illegal pharmacy websites, which receive a 40 percent commission on sales orders. The organization offers fulfillment of the pharmaceutical product orders, credit card processing and customer support services</i>" <br />
<br />
What's coming out of Storm Worm's botnet isn't necessarily coming from the hardcore Storm Worm-ers whose job today is more of a campaign-rotation related in order to ensure new bots are added, what's coming out of Storm Worm is coming from those <a href="http://it.slashdot.org/article.pl?sid=07/10/16/155209">using the access they've purchased to a part of the botnet</a>.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TUN7jJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TUN7jJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QEqwBJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QEqwBJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FeC9Rj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FeC9Rj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b6c7oj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b6c7oj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iJ3LCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iJ3LCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zhsGWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zhsGWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HuQaxj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HuQaxj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/349239892" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 23:29:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/hardcore storm worm-ers">hardcore storm worm-ers</category>
      <category domain="http://securityratty.com/tag/storm worm-ers">storm worm-ers</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/botnet masters">botnet masters</category>
      <category domain="http://securityratty.com/tag/botnet spam">botnet spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/349239892/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</source>
    </item>
    <item>
      <title><![CDATA[Right Wing Israeli Hackers Deface Hamas's Site]]></title>
      <link>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</link>
      <guid>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</guid>
      <description><![CDATA[Compared to historical hacktivism tensions between different nations, Israeli and Palestinian hacktivists seem to be most sensitive to &quot;virtual fire exchange&quot; like this one, and consequently, just...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s1600-h/hamas_hacked.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s200/hamas_hacked.png" alt="" id="BLOGGER_PHOTO_ID_5216261237759367394" border="0" /></a>Compared to historical hacktivism tensions between different nations, <a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Israeli and Palestinian hacktivists</a> seem to be most sensitive to "virtual fire exchange" like this one, and consequently, just like in real-life, always look and find for an excuse to engage in a conflict. <a href="http://www.ynetnews.com/articles/0,7340,L-3560756,00.html">Israeli hackers penetrate Hamas website</a> :<br /><br />"<span style="font-style: italic;">Israeli hackers boasted Thursday about breaking into the website of Izz al-Din al-Qassam, Hamas’ military wing, which now displays a white screen and words in Arabic announcing technical difficulties. The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.  In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site. "The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state.</span>"<br /><br />The message they left :<br /><br />"<span style="font-style: italic;">Hacked by XcxooXL and FENiX from Fanat Al Radical Greets: Sn4k3 Contact: Fanat.al.Radical@gmail.com </span>"<br /><br />These script kiddies using SQL injection vulnerabilities within the affected sites, since they indeed managed to deface several other as well, seem to have also participated in the 2006 cyber conflict sparkled due to the <a href="http://www.mfa.gov.il/MFA/MFAArchive/2000_2009/2004/1/Israeli%20MIAs">the kidnapping of three soldiers</a>. One of their defacements remains still active (<span style="font-weight: bold;">aviv.perffect-x.net/deface.html</span>)<br /><br />"<span style="font-style: italic;">We will stand against the Islam until the kidnapped soldiers, Gilad Shalit, Eldad Regev and Ehod Goldvaser will be return, We will attack arabic servers and site which support the Islam and protest against the zionism</span>"<br /><br />What if every script kiddie with a SQL injection scanners goes into politics? It's a mess already.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br /><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br /><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html"></a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ryWbnI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ryWbnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=frccjI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=frccjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yec9Yi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yec9Yi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdpmYi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdpmYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOanxI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOanxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XjskfI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XjskfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MXrvxi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MXrvxi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/320791816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 11:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/israeli">israeli</category>
      <category domain="http://securityratty.com/tag/israeli hackers">israeli hackers</category>
      <category domain="http://securityratty.com/tag/anti-jewish sites">anti-jewish sites</category>
      <category domain="http://securityratty.com/tag/al-qassam site">al-qassam site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/hacktivism tensions">hacktivism tensions</category>
      <category domain="http://securityratty.com/tag/historical hacktivism tensions">historical hacktivism tensions</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/320791816/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</source>
    </item>
    <item>
      <title><![CDATA[Minimizing the Attack Surface, Part 1]]></title>
      <link>http://securityratty.com/article/4cc07bb9b410d28285eec3f2156fa1e6</link>
      <guid>http://securityratty.com/article/4cc07bb9b410d28285eec3f2156fa1e6</guid>
      <description><![CDATA[What was the first thing you learned about network security? Theres a good chance it had something to do with port scanning. After scanning a few boxes, you realized that modern operating systems have...]]></description>
      <content:encoded><![CDATA[<p>What was the first thing you learned about network security?  There&#8217;s a good chance it had something to do with port scanning.  After scanning a few boxes, you realized that modern operating systems have a lot of open ports by default, meaning a lot of services.  Some had an obvious purpose, like telnet on tcp/23 or ftp fon tcp/21.  Others left you wondering, what the heck is listening on tcp/515 or tcp/7100?  And remember, you couldn&#8217;t ask Google because it didn&#8217;t exist (well, maybe it did depending on when you got into security).</p>
<p>Your first real lesson about locking down a host was how to reduce its attack surface.  You learned how to disable services using /etc/inetd.conf.  Then you learned about rc.d and how to prevent unnecessary services from being launched at startup.  Next, maybe you configured the Xserver to disallow remote connections or moved on to removing setuid permissions from files.  As you worked, you&#8217;d periodically re-scan the box to gauge progress, asking yourself &#8220;have I removed everything I don&#8217;t need?&#8221;  The underlying motivation, of course, is that an attacker can&#8217;t hack something that isn&#8217;t there.</p>
<p>You learned how to extend those concepts to the network &#8212; configuring firewall rules, router ACLs, VLANs, etc.  Segmenting the network.  Creating a DMZ.  No need to dwell on this, you get the idea.</p>
<p>Eventually, people realized that applications had an attack surface too.  Web servers and application servers got a lot of attention, followed closely by custom web applications.  &#8220;What do you mean you can execute SQL queries against my database?  That&#8217;s impossible, I have a firewall!&#8221;</p>
<p>Some companies, the ones who could afford it anyway, started to build security into their development cycle.  Doing threat modeling during the design phase made sense, because hey, it&#8217;s much cheaper to fix security holes in a whiteboard drawing than it is to rewrite your authorization module from scratch after it&#8217;s in production.</p>
<p>Let&#8217;s talk strictly about custom web applications now.  What I&#8217;ve observed is that most development groups, even the ones who actively engage in threat modeling, do not understand their web application&#8217;s attack surface.  The lead architect can whiteboard a high-level diagram of all the major components and how they interact.  Individual developers can go a bit deeper, telling you which files they touch, what database permissions they need, or how various pieces of data are encrypted in storage.  At the end of this exercise you have a complete picture of the processes, data flows, protocols, privilege boundaries, external entities, and so on, and you&#8217;re well on your way to understanding all of the potential attack vectors.</p>
<p>Or are you?</p>
<p>What often gets overlooked or glossed over is the impact of external libraries or packages.  Nobody writes everything from scratch. A typical list of third-party libraries for a Java-based Web 2.0 application might include DWR, GWT, Axis, and Dojo, plus about 30 other libraries to do everything from logging to parsing to image manipulation.  Nine out of ten times, the libraries will be installed in full, using the default configuration from page one of the README file.</p>
<p>Why is this relevant? Because just as those old Unix boxes exposed unnecessary services, libraries expose unnecessary code.  Let&#8217;s say you installed Dojo to simplify the process of creating an HTML table with rows and columns that can be sorted on demand.  Did you remember to remove all the .js files you didn&#8217;t need?  Or maybe you installed Axis or DWR or anything else that has its own Servlet(s) for processing requests.  Have you compared what that Servlet <i>can do</i> against what you <i>need it to do</i>?  </p>
<p>A fictitious example may help illustrate further.  Imagine you just downloaded a new library called WhizBang.  You follow the installation instructions to define and map two servlets in your web.xml file, WhizServlet and BangServlet, and you configure it to integrate with your web app.  After a bit of trial and error, it&#8217;s functional. Yay!  This is where most developers stop.  </p>
<p>Nobody asks, &#8220;how much of this do I actually need?&#8221;  Case in point, what if your application only uses WhizServlet?  BangServlet is still exposed, and you don&#8217;t even use it!  Similarly, what if WhizServlet takes an &#8220;action&#8221; parameter which can be either &#8220;view&#8221;, &#8220;edit&#8221;, or &#8220;delete&#8221;, and your application only uses &#8220;view&#8221;?  You&#8217;re still exposing the other actions to anybody who knows the URL syntax (pretty trivial if it&#8217;s open source).  You wouldn&#8217;t expose large chunks of your own code that you weren&#8217;t using, so why should it be any different with libraries?</p>
<p>This post is getting kind of long so I&#8217;m going to split it up.  In the next post, I&#8217;ll continue the discussion of attack surface minimization, as well as some of the tradeoffs that go along with this approach.</p>
]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 15:09:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack surface">attack surface</category>
      <category domain="http://securityratty.com/tag/custom web applications">custom web applications</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/prevent unnecessary services">prevent unnecessary services</category>
      <category domain="http://securityratty.com/tag/unnecessary services">unnecessary services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/third-party libraries">third-party libraries</category>
      <category domain="http://securityratty.com/tag/fix security holes">fix security holes</category>
      <source url="http://www.veracode.com/blog/?p=111">Minimizing the Attack Surface, Part 1</source>
    </item>
    <item>
      <title><![CDATA[UltimateBet cheating goes undetected for almost 21 months]]></title>
      <link>http://securityratty.com/article/ab86750c9ca2ca89b4459be51f0a8dee</link>
      <guid>http://securityratty.com/article/ab86750c9ca2ca89b4459be51f0a8dee</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/29/08

Organization
Tokwiro Enterprises ENRG

Tokwiro Enterprises Enrg&quot; is a recognized Mohawk owned and controlled, gaming sole proprietorship,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ultimatebet.jpg" align="right" height="102" width="120"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/29/08 <br><br><span style="font-weight: bold;">Organization: </span><br>Tokwiro Enterprises ENRG*<br><br><font size="1">*"Tokwiro Enterprises Enrg" is a recognized Mohawk owned and controlled, gaming sole proprietorship, presently undergoing a licencing process with the "Kahnawake Gaming Commission" ("KGC"), which was itself established on the 10th day of June, 1996. (Source: <a href="http://www.ultimatebet.com/about-us)</font><br><br><span">www.ultimatebet.com/about-us)</font><br><br><span</a> style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.ultimatebet.com/">UltimateBet</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"hole card information during live play" resulting is financial loss<br><br><span style="font-weight: bold;">Breach Description:</span><br>"MONTREAL, CANADA (MAY 29, 2008) --- Tokwiro Enterprises ENRG ("Tokwiro"), proprietors of UltimateBet.com ("UltimateBet"), one of the world's largest online card rooms, today announced the results of its lengthy investigation into allegations of unfair play, which was triggered by concerns about an account named 'NioNio'."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.ultimatebet.com/poker-news/2008/may/NioNio-Findings">UltimateBet Statement</a> (full statement text below)<br><a href="http://www.cjad.com/news/565/729153">CJAD NewsTalk Radio</a> <br><a href="http://www.cardplayer.com/poker-news/article/4279/owner-of-ultimatebet-confirms-security-breach">Card Player</a> <br><a href="http://www.pokerlistings.com/ultimatebet-wraps-investigation-of-unfair-play-27499">PokerListings</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Tokwiro Enterprises ENRG and Bob Pajich at Card Player<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Tokwiro Enterprises, the company that owns both Absolute Poker and UltimateBet, today released a statement confirming that cheating had gone on at UltimateBet by people who, according to the release, "worked for the previous ownership of UltimateBet prior to the sale of the business to Tokwiro in October 2006."<br><span style="font-style: italic;">[Evan] Shouldn't an information security and risk assessment be conducted as part of the acquisition and integration?&nbsp; If so, then wouldn't a code review of the proprietary software that came with the acquisition be included?&nbsp; This is the proprietary software that really drives the purpose of the site.</span><br><br>The player or players behind the 18 screen names that were identified as being corrupted have not been named.<br><br>Tokwiro will refund players their losses once the investigation is complete.<br><span style="font-style: italic;">[Evan] I wonder how expensive this will be.</span><br><br>The usernames that were used to cheat are: NioNio, Sleepless, NoPaddles, nvtease, flatbroke33, ilike2win, UtakeIt2, FlipFlop2, erick456, WhackMe44, RockStarLA, stoned2nite, monizzle, FireNTexas, HeadKase01, LetsPatttty, NYMobser, and WhoWhereWhen.<br><br>The cheating was able to take place because the perpetrators had access to what Tokwiro is calling an "unauthorized software code" that allowed the cheaters to see their opponents’ holecards.<br><span style="font-style: italic;">[Evan] This "unauthorized software code" use went undetected for almost 21 months!</span><br><br>The cheating took place from March 7, 2006 to Dec. 3, 2007, and it’s not known how much money the cheater(s) illicitly won.<br><br>The company refused to disclose the amount of fraudulent winnings, but poker observers have said it runs into the millions.<br><br>As soon as the cheating was suspected, Tokwiro said it contacted the Kahnawake Gaming Commission (KGC), the most used online poker regulatory commission, to start the investigation.<br><br>Tokwiro is mandated to contact KGC if any suspicious activety might be taking place.<br><br>This is the second cheating incident to hit the company since it purchased Absolute Poker and UltimateBet.<br><br>The first occurred when it was discovered that several players at Absolute Poker also had access to software that allowed them to see opponents’ holecards.<br><span style="font-style: italic;">[Evan] A link is included below</span><br><br><center>ULTIMATEBET ISSUES STATEMENT REGARDING UNFAIR PLAY</center><br><br><span style="font-weight: bold;">MONTREAL, CANADA (MAY 29, 2008)</span> --- Tokwiro Enterprises ENRG ("Tokwiro"), proprietors of UltimateBet.com ("UltimateBet"), one of the world's largest online card rooms, today announced the results of its lengthy investigation into allegations of unfair play, which was triggered by concerns about an account named 'NioNio'. Tokwiro has worked diligently in cooperation with its regulatory body, the Kahnawake Gaming Commission ("KGC"), and with independent third-party experts to conduct a thorough investigation that included a comprehensive review of hand histories and game data, thorough analyses of software and network security, and audits of its security practices and procedures.<br>&nbsp;<br>The investigation has concluded that certain player accounts did in fact have an unfair advantage, and that these accounts targeted the highest limit games on the site. The individuals responsible were found to have worked for the previous ownership of UltimateBet prior to the sale of the business to Tokwiro in October 2006. Tokwiro is taking full responsibility for this situation and will immediately begin refunding UltimateBet customers for any losses that were incurred as a result of unfair play. <br><br>The fraudulent activity was enabled by unauthorized software code that allowed the perpetrators to obtain hole card information during live play. The existence of this vulnerability was unknown to Tokwiro until February 2008 and existed prior to UltimateBet's acquisition by Tokwiro in October 2006. Our investigation has confirmed that the code was part of a legacy auditing system that was manipulated by the perpetrators. Gaming Associates, independent auditors hired by the KGC, have confirmed that the software code that provided the unfair advantage has been permanently removed.<br>&nbsp;<br>Throughout the investigation of this incident, Tokwiro's consistent priorities have been: <br></font><ol><li><font size="2">To permanently remove the ability to engage in unfair play;</font></li><li>To complete its investigation and come to a full understanding of what occurred;</li><li>To refund the affected customers; and</li><li>To implement measures that prevents future incidents. <br></li></ol><font size="2">The Company said, "We would like to thank our customers for their patience, loyalty and support, as well as for their understanding that we are doing everything we can to correct this situation. The staff and management of UltimateBet are fully committed to providing a safe and secure environment for our players, and we want to assure customers of our unwavering resolve to monitor site security with every resource at our disposal." <br><br><span style="font-weight: bold;">Investigation Timeline </span><br>These are the key events in the course of the incident. <br></font><ul><li><font size="2">January 2008: UltimateBet is alerted to suspicions of unfair play on the part of the account "NioNio". Within 24 hours, UltimateBet contacts the KGC to provide formal notice that UltimateBet has initiated an investigation of the incident. UltimateBet subsequently forwarded a copy of all related data to the KGC.</font></li><li>January 2008: The "NioNio" account and related accounts are suspended pending further investigation.</li><li>February 2008: Preliminary findings indicate abnormally high winning statistics for the suspect accounts. After discussions with the KGC, UltimateBet engages third-party gaming experts to assist with the analysis.</li><li>February 2008: Investigators confirm that the suspect accounts are associated with individuals who had worked for UltimateBet under the previous ownership.</li><li>February 2008: UltimateBet discovers the unauthorized code that allowed the perpetrators to obtain hole card information during live play. The code was part of a legacy auditing system that was manipulated by the perpetrators of the fraud.</li><li>February 2008: UltimateBet immediately removes the unauthorized code and works with the KGC and with third-party auditors to verify that the security hole has been eliminated.</li><li>March 2008: Six player accounts are confirmed to have participated in this scheme. No accounts were deleted at any point, although some account names were changed multiple times. The following account names are known to have been used in the fraudulent activity: NioNio, Sleepless, NoPaddles, nvtease, flatbroke33, ilike2win, UtakeIt2, FlipFlop2, erick456, WhackMe44, RockStarLA, stoned2nite, monizzle, FireNTexas, HeadKase01, LetsPatttty, NYMobser, and WhoWhereWhen.</li><li>May 2008: The investigation confirms that the fraudulent activity took place from March 7, 2006 to December 3, 2007.</li><li>May 2008: Gaming Associates certifies that the software code that enabled unfair play was removed from UltimateBet servers in February of 2008.</li><li>May 2008: Customers affected by this incident are identified, and plans for corrective action are reviewed with the KGC. <br></li></ul><font size="2"><span style="font-weight: bold;">Corrective Actions Taken </span><br>The following actions have been taken or are currently underway as a direct result of this investigation. <br></font><ul><li><font size="2">The security hole identified in UltimateBet's investigation has been permanently eliminated.</font></li><li>UltimateBet is establishing a state-of-the-art software Security Center that consolidates and greatly enhances existing security capabilities. The first release of the new Security Center focuses solely on the immediate detection of abnormal winnings. Gaming mathematicians, poker professionals, and security software developers have all contributed to the specifications for the new Security Center.</li><li>UltimateBet customers are no longer permitted to change account names unless they have suffered abuse in chat rooms. Requests for changes must be supported by proof of abuse and must be approved by the Chief Compliance Officer.</li><li>In addition to its existing security department, UltimateBet has established a new specialized Poker Security team of professionals dedicated to fraud prevention.</li><li>The refund process will begin immediately. The accounts associated with fraudulent activity did not use an unfair advantage in all play sessions. Regardless, UltimateBet is refunding all losses to these accounts.</li><li>Accounts related to the fraudulent activity have been disabled, and the individuals associated with those accounts permanently banned from the site.</li><li>UltimateBet has worked closely and transparently with its governing body, the KGC and its designated expert auditors, to determine exactly what happened, how it happened, and who was involved, and has taken action to prevent any possibility of this situation recurring.</li><li>Tokwiro is pursuing its legal options in regard to this incident. <br></li></ul><font size="2">For further inquiries please contract press@ultimatebet.com <br><br><span style="font-weight: bold;">Commentary:</span><br>This is potentially a multi-million dollar loss for Tokwiro Enterprises ENRG and its very troubling that this breach went undetected for so long. The software used by the site is proprietary and should really be subject to a significant amount of information security scrutiny.<br><br>If I were a player, I think I would be beyond angry.&nbsp; Not just angry about the loss of money, but angry about the loss of confidence and being cheated in general.&nbsp; I personally know people that refuse to play online poker because of the risk posed by poorly secured sites.<br><br>Information security of online gaming sites must be a #1 priority for the companies that run them.&nbsp; Seems obvious, but many statements in the information security business seem obvious.&nbsp; Personally, I like the response from Tokwiro.&nbsp; If they follow through (which I assume they would), Tokwiro's actions should go a long ways towards reducing risk and restoring customer confidence.<br><br>Check out the comments at <a href="http://www.cardplayer.com/poker-news/article/4279/owner-of-ultimatebet-confirms-security-breach">Card Player</a> to get some insight into what some players are thinking. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Tokwiro Enterprises ENRG/Absolute Poker:<br>October, 2007 - <a href="http://www.msnbc.msn.com/id/21381022/">Online poker cheating blamed on employee</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/04/ultimatebet.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 06:55:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ultimatebet">ultimatebet</category>
      <category domain="http://securityratty.com/tag/tokwiro enterprises enrg">tokwiro enterprises enrg</category>
      <category domain="http://securityratty.com/tag/tokwiro enterprises">tokwiro enterprises</category>
      <category domain="http://securityratty.com/tag/ultimatebet issues statement">ultimatebet issues statement</category>
      <category domain="http://securityratty.com/tag/ultimatebet prior">ultimatebet prior</category>
      <category domain="http://securityratty.com/tag/ultimatebet subsequently">ultimatebet subsequently</category>
      <category domain="http://securityratty.com/tag/ultimatebet immediately removes">ultimatebet immediately removes</category>
      <category domain="http://securityratty.com/tag/ultimatebet servers">ultimatebet servers</category>
      <category domain="http://securityratty.com/tag/ultimatebet statement">ultimatebet statement</category>
      <source url="http://breachblog.com/2008/06/04/ultimatebet.aspx">UltimateBet cheating goes undetected for almost 21 months</source>
    </item>
  </channel>
</rss>
