<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: extensive]]></title>
    <link>http://securityratty.com/tag/extensive</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Skype security flub leads to discovery of Chinese monitoring]]></title>
      <link>http://securityratty.com/article/45c85bac2a4d86fa20904e4f706539a8</link>
      <guid>http://securityratty.com/article/45c85bac2a4d86fa20904e4f706539a8</guid>
      <description><![CDATA[Researchers have found evidence that Skype and Chinese partner TOM Online are monitoring text communications online for &quot;sensitive&quot; topics, and storing extensive logs on publicly-accessible servers....]]></description>
      <content:encoded><![CDATA[Researchers have found evidence that Skype and Chinese partner TOM Online are monitoring text communications online for "sensitive" topics, and storing extensive logs on publicly-accessible servers. Not only is this a major security risk, it also raises questions as to what level Skype is complying with the requests of the Chinese government.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 22:00:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/major security risk">major security risk</category>
      <category domain="http://securityratty.com/tag/level skype">level skype</category>
      <category domain="http://securityratty.com/tag/text communications online">text communications online</category>
      <category domain="http://securityratty.com/tag/extensive logs">extensive logs</category>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <category domain="http://securityratty.com/tag/raises questions">raises questions</category>
      <category domain="http://securityratty.com/tag/requests">requests</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <source url="http://digg.com/security/Skype_security_flub_leads_to_discovery_of_Chinese_monitoring">Skype security flub leads to discovery of Chinese monitoring</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Seven]]></title>
      <link>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</link>
      <guid>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</guid>
      <description><![CDATA[In case you haven't heard - Microsoft and the Washington state are suing a U.S based -- naturally -- &quot;scareware&quot; vendor Branch Software

We won't tolerate the use of alarmist warnings or deceptive...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/V5DqP_zsvuk/s1600-h/lawsuit_got_one.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="161" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/FVk3TrvBJIo/s200-R/lawsuit_got_one.gif" width="200" /></a>In case you haven't heard - <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">Microsoft and the Washington state</a> are suing a U.S based -- naturally -- "scareware" vendor Branch Software :<br />
<br />
"<i>We won't tolerate the use of alarmist warnings or deceptive 'free scans' to  trick consumers into buying software to fix a problem that doesn't even exist,"  Washington <b style="font-weight: normal;">Attorney General Rob McKenna</b> said. <b>"We've repeatedly  proven that Internet companies that prey on consumers' anxieties are within our  reach.</b></i><b>"</b><br />
<br />
Sadly, Branch Software is the tip of the iceberg on the top of the affiliates participating in different affiliation based programs, which similar to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">IBSOFTWARE CYPRUS</a> and <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Interactivebrands</a>, which I've been tracking down for a while, are the aggregators of scareware<b><span style="font-weight: normal;"> that popped up on the radars due to their extensive portfolios. These three companies offering software bundles or plain simple fake software, are somewhere in between the food chain of this ecosystem, with the real vendors paying out the commissions on a per installation basis slowly starting to issue invitation codes that they've distributed only across invite-only forums/sections of particular forums.</span></b><br />
<br />
Behind these brands is everyone that is participating in the franchise and is putting personal efforts into monetizing the high payout rates that the fake security software vendor is paying for successful installation. These high payout rates -- with the financing naturally coming straight from other criminal activities online -- are in fact so high, that I can easily say that the last two quarters we've witnesses the largest increase of such domains ever, and they're only heating up since the typosquatting possibilities are countless and they seem to know that as well.<br />
<br />
It's important to point out that their business model of acquiring traffic is outsourced to all the affiliates that do the blackhat SEO, SQL injections, web sessions hijacking of malware infected hosts in order to monetize, so basically, you have an affiliates network whose actions are directly driving the growth into all these areas. Throwing money into the underground marketplace as a "financial injection", is proving itself as a growth factor, and incentive for innovation on behalf of all the participants.<br />
<br />
Here are some of the most recent fake security software domains, a "deja vu" moment with a known RBN domain from a "previous life" that is also parked at one of the servers, and evidence that typosquatting for fraudulent purposes is still pretty active with a dozen of Norton Antivirus related domains, some of which have already started issuing "fake security notices" by brandjacking the vendor for traffic acquisition purposes.<br />
<br />
<b>Antivirus-Alert .com </b>(203.117.111.47) where<b> pepato .org</b> a domain that was used in the <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">Wired.com and History.com IFRAME injections</a>, which back in March was also hosted at Hostfresh (58.65.238.59).<br />
<br />
<b>softload2008name .com</b> (78.157.143.250)<br />
<b>softload2008nm .com<br />
softload2008n .com<br />
softload2008jq .com</b><br />
<br />
<b>microantivir-2009 .com</b> (91.208.0.223)<br />
<b>scanner.microantivir-2009 .com<br />
microantivir2009 .com<br />
microantivirus-2009 .com<br />
microantivirus2009 .com</b><br />
<br />
<b>ms-scan .com</b> (91.208.0.228)<br />
<b>msscanner .com</b><br />
<b>ms-scanner .com</b><br />
<br />
<b>Personalantispy .com</b> (93.190.139.197)<br />
<b>freepcsecure .com<br />
quickinstallpack .com<br />
quickdownloadpro .com<br />
advancedcleaner .com<br />
performanceoptimizer .com<br />
internetanonymizer .com</b><br />
<br />
<b>ieprogramming .com</b> (92.62.101.83)<br />
<b>uptodatepage .com<br />
fileliveupdate .com<br />
qwertypages .com<br />
sharedupdates .com<br />
ierenewals .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/eJI5I5BgGoQ/s1600-h/norton_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/Rpjz8LY4LEQ/s200-R/norton_alert.png" /></a><b>norton-antivirus-alert .com<br />
norton-anti-virus-2007 .com <br />
norton-antivirus-2007 .com <br />
norton-antivirus2007 .com <br />
nortonantivirus2007 .com <br />
norton-antivirus-2008 .com <br />
nortonantivirus2008 .com <br />
nortonantivirus2008freedownload .com <br />
norton-antivirus-2009 .com <br />
nortonantivirus2009 .com <br />
norton-antivirus-2010 .com <br />
nortonantivirus2010 .com <br />
nortonantivirus360 .com <br />
nortonantivirus8 .com <br />
nortonantivirusa .com <br />
nortonantivirusactivation .com <br />
norton-antivirus-alert .com <br />
nortonantivirusalerts .com <br />
norton--anti-virus .com <br />
norton-anti-virus .com <br />
norton-antivirus .com <br />
nortonanti-virus .com <br />
nortonantivirus.com <br />
nortonantiviruscom .com <br />
nortonantiviruscorporate .com <br />
nortonantiviruscorporateedition .com <br />
nortonantiviruscoupon .com <br />
nortonantivirusdefinition .com <br />
nortonantivirusdefinitions .com <br />
nortonantivirusdirect .com</b><br />
<br />
Fake Antivirus Inc. is not going away as long as the affiliate based model remains active. If the real vendors were greedy enough not to share the revenues with others, they would have been the one popping up on the radar, compared to the situation where it's the affiliate network's participations greed that's increasing their visibility online.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Cybersquatting Symantec's Norton AntiVirus</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">Cybersquatting Security Vendors for Fraudulent Purposes</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake  Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=88nnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=88nnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F8uQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F8uQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T1xil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T1xil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eAF4l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eAF4l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rdg2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rdg2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nXveL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nXveL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=moMol"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=moMol" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407645950" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/vendor branch software">vendor branch software</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/software bundles">software bundles</category>
      <category domain="http://securityratty.com/tag/branch software">branch software</category>
      <category domain="http://securityratty.com/tag/norton antivirus">norton antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407645950/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Plan-based Complex Event Detection across Distributed Sources]]></title>
      <link>http://securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</link>
      <guid>http://securityratty.com/article/7f2d9ec37ddd235b47e10e69a8a18a32</guid>
      <description><![CDATA[Here is an interesting 2008 paper, Plan-based Complex Event Detection across Distributed Sources
Abstract
Complex Event Detection (CED) is emerging as a key capability for many monitoring applications...]]></description>
      <content:encoded><![CDATA[<p>Here is an interesting 2008 paper, <a class="l" onmousedown="return clk(this.href,'','','res','4','')" href="http://www.cs.brown.edu/%7Eugur/ced.pdf">Plan-based Complex Event Detection across Distributed Sources.</a></p>
<p><strong>Abstract</strong></p>
<blockquote><p><em>Complex Event Detection (CED) is emerging as a key capability for many monitoring applications such as intrusion detection, sensorbased activity &amp; phenomena tracking, and network monitoring. Existing CED solutions commonly assume centralized availability and processing of all relevant events, and thus incur significant overhead in distributed settings. In this paper, we present and evaluate communication efficient techniques that can efficiently perform CED across distributed event sources.</em></p>
<p><em>Our techniques are plan-based: we generate multi-step event acquisition and processing plans that leverage temporal relationships among events and event occurrence statistics to minimize event transmission costs, while meeting application-specific latency expectations. We present an optimal but exponential-time dynamic programming algorithm and two polynomial-time heuristic algorithms, as well as their extensions for detecting multiple complex events with common sub-expressions. We characterize the behavior and performance of our solutions via extensive experimentation on synthetic and real-world data sets using our prototype implementation.</em></p></blockquote>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:49:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complex event detection">complex event detection</category>
      <category domain="http://securityratty.com/tag/sources">sources</category>
      <category domain="http://securityratty.com/tag/multiple complex events">multiple complex events</category>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/communication efficient techniques">communication efficient techniques</category>
      <category domain="http://securityratty.com/tag/efficiently perform ced">efficiently perform ced</category>
      <category domain="http://securityratty.com/tag/ced">ced</category>
      <category domain="http://securityratty.com/tag/techniques">techniques</category>
      <category domain="http://securityratty.com/tag/event sources">event sources</category>
      <source url="http://www.thecepblog.com/2008/09/25/plan-based-complex-event-detection-across-distributed-sources/">Plan-based Complex Event Detection across Distributed Sources</source>
    </item>
    <item>
      <title><![CDATA[More Details on McAfee's Artemis]]></title>
      <link>http://securityratty.com/article/3ef62fbfbd2bb374f1c20b9b41dc0c41</link>
      <guid>http://securityratty.com/article/3ef62fbfbd2bb374f1c20b9b41dc0c41</guid>
      <description><![CDATA[I spoke with McAfee recently, following my column about its Artemis technology . I learned a few things. Artemis kicks in when the local anti-virus scanner sees, through behavioral methods, if the...]]></description>
      <content:encoded><![CDATA[I spoke with McAfee recently, following <a href="http://www.eweek.com/c/a/Security/McAfee-Putting-Malware-Signatures-in-the-Cloud/">my column about its Artemis technology</a>. I learned a few things.

Artemis kicks in when the local anti-virus scanner sees, through behavioral methods, if the file is suspicious. Then it sends a fingerprint of the file up to the Artemis servers for further analysis.

I had assumed that this fingerprint was a hash of some kind, but that was a simplistic assumption. The fingerprint includes characteristics of the file, including the ones that the scanner used to determine that the file was suspicious: Is it packed? Using certain packers in particular? Is it compressed (not the same thing)? Is it a certain size? In case I was unclear before, none of this involves signatures in the conventional sense.

It occurs to me that this could lower false-positives, compared with conventional behavioral analysis, because it subjects suspicious threats to more extensive analysis in the cloud. It all depends on how aggressive McAfee is at that stage.

Another thought I had is that since Artemis kicks in as a result of behavioral analysis, the threat has already hit the system by the time Artemis is invoked. Presumably the process is asynchronous and Artemis could return its analysis some time after the submission. If this is the case, it could be awhile during which malware is running rampant on your system.
<p><a href="http://feedads.googleadservices.com/~a/gTm8XhZRINn6ceS8NEYjhBg8ZZo/a"><img src="http://feedads.googleadservices.com/~a/gTm8XhZRINn6ceS8NEYjhBg8ZZo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/VyuqqR5FRAs" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 07:25:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/artemis">artemis</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/conventional behavioral analysis">conventional behavioral analysis</category>
      <category domain="http://securityratty.com/tag/artemis servers">artemis servers</category>
      <category domain="http://securityratty.com/tag/artemis kicks">artemis kicks</category>
      <category domain="http://securityratty.com/tag/extensive analysis">extensive analysis</category>
      <category domain="http://securityratty.com/tag/behavioral analysis">behavioral analysis</category>
      <category domain="http://securityratty.com/tag/artemis technology">artemis technology</category>
      <category domain="http://securityratty.com/tag/fingerprint">fingerprint</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/VyuqqR5FRAs/more_details_on_mcafees_artemis.html">More Details on McAfee's Artemis</source>
    </item>
    <item>
      <title><![CDATA[Spam Campaign Abusing Yahoo's Services]]></title>
      <link>http://securityratty.com/article/c2626f449f476aba6a0e3171d77be643</link>
      <guid>http://securityratty.com/article/c2626f449f476aba6a0e3171d77be643</guid>
      <description><![CDATA[Think spammers.Yahoo.com trusts Yahoo.com, consequently, a spam campaign that using bogus Yahoo.com email accounts, and spamming only Yahoo users with links to Yahoo's search engine using queries...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEJZU3UKFI/AAAAAAAACKk/nL7rnM4boe0/s1600-h/captcha_outsource_bogus_accounts_yahoo1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEJZU3UKFI/AAAAAAAACKk/G05GItHoyBs/s200-R/captcha_outsource_bogus_accounts_yahoo1.JPG" /></a>Think spammers.Yahoo.com trusts Yahoo.com, consequently, a spam campaign that using bogus Yahoo.com email accounts, and spamming only Yahoo users with links to Yahoo's search engine using queries leading to the exact spammer's URLs, is almost 100% sure to make it through spam filters. That seems to be case with this spam campaign perfectly fitting into the "spam that made it through" category.<br />
<br />
<b>Sample search queries resulting in a single result with the spammer's URL :</b><br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=())))))))))))))callfold(((((((((((((((()))))))))))((((()))))))5000)))))))))))(((((((<br />
- search.yahoo.com/search?p=(((((())))))))((((((((((((((housetear((((())))))(((((((())))))))(((((((((5000((((((())))))))))))))))))))<br />
- yahoo.com/search/search;_ylt=?p=]]]]]]]]]]]][[[[[[galestay[[]]]]]]][[[[[[[[[[[[[[[[[[[[$229[[[[[[[[[[[[[[[[[[[]]]]<br />
- yahoo.com/search/search;_ylt=?p=(((((())))))))))galestay((((((()((((((((((((((((($229)))))))))))(((()<br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=))))))))))))))(((((richorbit((((((((((((((())))))))))))((((((())))))$229)))))))))))(((((((<br />
- yahoo.com/////////////////////////////search/search;_ylt=?p=))))))(((())))))))))richorbit((((((((((((())))))))((((((((((((((((((((((((((((($229))))))((((())<br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEMVvsjNOI/AAAAAAAACKw/8DNIdG5HwUw/s1600-h/captcha_outsource_bogus_accounts_yahoo2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNEMVvsjNOI/AAAAAAAACKw/L0wwRor-SUQ/s200-R/captcha_outsource_bogus_accounts_yahoo2.JPG" /></a><br />
The search queries lead to<b> galestay.com; housetear.com; callfold.com; richorbit.com</b> with several hundred spam domains participating in the campaign parked at <b>218.61.7.21</b> and <b>220.248.185.64</b>.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SNEOBcMV7WI/AAAAAAAACK4/Agv8JwvW6WY/s1600-h/king_replicas_spam.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SNEOBcMV7WI/AAAAAAAACK4/OmHHnCUAIHc/s200-R/king_replicas_spam.png" width="200" /></a>With CAPTCHA solving and automatic account registration getting easier to outsource next to the easily obtainable <a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">segmented email databases of a particular ISP or web based email service provider</a>, launching such a campaign requires less efforts than it used to before. Interestingly, the spammed through Yahoo emails never leave Yahoo Mail since it's only spamming Yahoo users according to the extensive number of emails CC-ed.<br />
<br />
What's to come in the long-term? With an entire spamming infrastructure build on the foundation of the hundreds of thousands of bogus accounts at legitimate services, spammers are already starting to embrace the "legitimate sender" mentality and<b> </b>are working on ways to integrate that infrastructure in their spam systems, evidence of which can be seen in several <a href="http://blogs.zdnet.com/security/?p=1899">different managed spamming services</a>.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=1232">Microsoft’s CAPTCHA successfully broken</a><br />
<a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers</a><br />
<a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing</a><br />
<a href="http://blogs.zdnet.com/security/?p=1835">Inside India’s CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tyomL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tyomL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RprrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RprrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LDOil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LDOil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cIk3l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cIk3l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xSFKL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xSFKL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5sTAL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5sTAL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IVbIl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IVbIl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/395238291" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 05:25:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/spam campaign perfectly">spam campaign perfectly</category>
      <category domain="http://securityratty.com/tag/spam campaign">spam campaign</category>
      <category domain="http://securityratty.com/tag/yahoo users">yahoo users</category>
      <category domain="http://securityratty.com/tag/spam systems">spam systems</category>
      <category domain="http://securityratty.com/tag/spam domains">spam domains</category>
      <category domain="http://securityratty.com/tag/yahoo emails">yahoo emails</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/395238291/spam-campaign-abusing-yahoos-services.html">Spam Campaign Abusing Yahoo's Services</source>
    </item>
    <item>
      <title><![CDATA[EstDomains and Intercage VS Cybercrime]]></title>
      <link>http://securityratty.com/article/54303a8239cd0becf5843fb3552a50a8</link>
      <guid>http://securityratty.com/article/54303a8239cd0becf5843fb3552a50a8</guid>
      <description><![CDATA[Surreal, especially when you get to read that EstDomains has &quot; ruthlessly suspended over five thousand domains only for last week &quot;, and also, that it &quot; has a reliable ally in its battle against...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SM7tc-r3kHI/AAAAAAAACKc/aUL1ohUu-Zc/s1600-h/estdomain_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SM7tc-r3kHI/AAAAAAAACKc/yiFaA33Sfdw/s200-R/estdomain_alert.png" /></a>Surreal, especially when you get to read that EstDomains has "<i>ruthlessly suspended over five thousand domains only for last week</i>", and also, that it "<i>has a reliable ally in its battle against malware in a face of Intercage, Inc</i>".<br />
<br />
Here's <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html">the press release</a> :<br />
<br />
"<i>The EstDomains, Inc management does not deny the fact that no one is secured from having a customer who uses provided services for delinquent purposes. But it must be noted that the carefully planned infrastructure of EstDomains, Inc makes the special provision for the cases of malware distribution that may originate from the domain name registered under the company's name. Such domain names are suspended immediately along with domain holder's account if there is an evidence of malware presence on the web site. <b>According to the most recent statistics over five thousand domain names were detected and ruthlessly suspended by EstDomains, Inc specialists only last week.</b><br />
<br />
<b>The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality.</b> But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance.</i> "<br />
<br />
The press release reminds me of <a href="http://ddanchev.blogspot.com/2008/04/hacked-by-rbn.html">RBN's defacement of my blog</a> posted on the 1st of April, and despite that <a href="http://www.malwarebytes.org/forums/index.php?showtopic=6159">EstDomains started "performing for the community"</a> as of recently, thanks to the collective intelligence and persistence of everyone turning their research into actionable intelligence against them, this performance aiming to minimize the effect of the negative PR is more or less futile considering <a href="http://www.spyware-techie.com/malicious-website-list/">all the cybercrime activities that they've been tolerating or ignoring</a> for the past couple of years. For future generations to see, <a href="http://www.malwarebytes.org/forums/index.php?showtopic=6159">this is how EstDomains "performs for the community"</a> :<br />
<br />
"<i>We've suspended all the domains listed in this topic. But please don't make posting these domains on this forum a habit. We have a 24/7 online tech support which can be contacted at <a href="https://support.estdomains.com/" target="_blank">https://support.estdomains.com</a><br />
<br />
Best regards,<br />
EstDomains Team&nbsp;</i><br />
<br />
<i>EstMate says : Ihatemondayand.com and antispycheck.com - both suspended. If any of the suspended websites are still active to you it maybe be because of your computer's or ISP's DNS-cache, others won't be able to access these websites</i><br />
<br />
<i>googlescanners-360.com isn't registered with us. As for other domains, the ones, which were registered through us, have been suspended. Regarding our preventive measures, the fact that you don't see them doesn't mean there isn't any. Yes, we don't write about them but in most cases we suspend whole accounts with problematic domains and look for connections to other accounts etc. During the last week we've suspended over 15000 different domains.</i>"<br />
<br />
What's more disturbing regarding this particular domain registrar is that it's a U.S based operation, namely, using the lack of international cybercrime cooperation as an excuse for not taking actions earlier doesn't fit into the picture. Moreover, this is just the tip of the iceberg, and taking into consideration a personal mentality that the cybercriminals you know are better than the cybercriminals you don't know, the RBN or any of its "leftovers" aren't fully taking advantage of the tactics they could be using in order to make it harder to shut them down, but how come? Simply, they don't have to put extra efforts and would once again remain online for years to come, which is perhaps more disturbing at the first place.<br />
<br />
What in the world is the Russian Business Network, is it still alive and kicking, are the same people that used to maintain my favorite netblock ever, still the ones running it, and what tactics are they taking advantage of in order to make it harder for the community to establish direct links with a particular netblock and the RBN itself?<br />
<br />
With RBN's "leftovers" -- <b>InterCage, Inc., Softlayer Technologies, Layered Technologies, Inc., Ukrtelegroup Ltd, Turkey Abdallah Internet Hizmetleri, and Hostfresh --</b> making headlines just like the way it should be, what I've been researching for the past couple of months is how they've migrated from the centralized hosting provider to what appears to be a fully operational franchise. The business model is very simple, the RBN through its extensive underground networking skills supplies to customers to franchisers operating small anti-abuse netblocks across the globe, where they offer dedicated hosting and share revenue with the RBN. Anyone trusted enough and capable of supplying such netblocks starts running the RBN anti-abuse franchise. It's also worth pointing out that these franchises are in fact starting to cut the middle man, and disintermediate the RBN by actively advertising their services in order for them to create a self-sustainable business model without having to rely on the RBN connecting them with customers.<br />
<br />
What used to be a centralized cybercrime powerhouse operating several highly visible anti-abuse netblocks, is today's decentralized infrastructure, with the profit margins for the anti-abuse services that it's logically capable to break-even and earn profits even with a few high profile dedicated hosting customers. Anyone can be the Russian Business Network, gain experience into the market segment, then disintermediate them by starting to advertise their own services. From a powerhouse to a franchise model, what the RBN had to offer can be easily duplicated by a countless number of local RBN's, and this is only starting to take place.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd. </a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs you Rarely See in Any Report</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocationg Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/new-media-malware-gang-part-four.html">The New Media Malware Gang - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">The New Media Malware Gang - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">The New Media Malware Gang</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html">RBN's Fake Account Suspended Notices </a><br />
<a href="http://ddanchev.blogspot.com/2008/04/hacked-by-rbn.html">HACKED BY THE RBN!</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">Rogue RBN Software Pushed Through Blackhat SEO</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">RBN's Phishing Activities</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-malware-puppets-need-their-master.html">RBN's Puppets Need Their Master</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html">RBN's Fake Account Suspended Notices</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/go-to-sleep-go-to-sleep-my-little-rbn.html">Go to Sleep, Go to Sleep my Little RBN</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/exposing-russian-business-network.html">Exposing the Russian Business Network</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/detecting-and-blocking-russian-business.html">Detecting the Blocking the Russian Business Network</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/over-100-malwares-hosted-on-single-rbn.html">Over 100 Malwares Hosted on a Single RBN IP</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/russian-business-network.html">The Russian Business Network</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CWZlL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CWZlL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wdsJL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wdsJL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6wf1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6wf1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JLXVl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JLXVl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fkyiL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fkyiL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=l6gML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=l6gML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kPS6l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kPS6l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/394232850" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:09:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/single rbn">single rbn</category>
      <category domain="http://securityratty.com/tag/rbn">rbn</category>
      <category domain="http://securityratty.com/tag/rbn anti-abuse franchise">rbn anti-abuse franchise</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware distribution">malware distribution</category>
      <category domain="http://securityratty.com/tag/thousand domain names">thousand domain names</category>
      <category domain="http://securityratty.com/tag/domain names">domain names</category>
      <category domain="http://securityratty.com/tag/rogue rbn software">rogue rbn software</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/394232850/estdomains-and-intercage-vs-cybercrime.html">EstDomains and Intercage VS Cybercrime</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/17aff72127a968eb7ecc82a4f6c94f6f</link>
      <guid>http://securityratty.com/article/17aff72127a968eb7ecc82a4f6c94f6f</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 that???s due out in October. While many Analysts...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that???s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I???ll be releasing an extensive update on Burton Group???s PCI coverage around the October release date), they really haven???t commented on what???s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I???ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> ??? while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can???t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> ??? organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there???s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> ??? while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> ??? while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn???t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> ??? while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> ??? what are the best practices around merging PCI security requirements into an enterprise???s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won???t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group???s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I???d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://srmsblog.burtongroup.com/2008/09/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis]]></title>
      <link>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</link>
      <guid>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</guid>
      <description><![CDATA[Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned here , here ; SANS jumped in as well ), I decided to follow along and join the initiative. One of the bloggers called it...]]></description>
      <content:encoded><![CDATA[<p>Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/08/pay_it_forward__1.html">here</a>, <a href="http://mcwresearch.com/archives/265">here </a>; <a href="http://isc.sans.org/diary.php?storyid=1530&amp;rss">SANS jumped in as well</a>), I decided to follow along and join the initiative. One of the bloggers called it <a href="http://mcwresearch.com/archives/255">&quot;pay it forward</a>&quot; to the community.</p>  <p>So, Anton Security Tip of the Day #16: <strong>Virtually Screwed - Journey Into VMWare ESX Log Analysis</strong></p>  <p>CISecurty guide for VMWare (<u><a href="http://www.cisecurity.org/bench_vm.html">here</a></u>) and DISA STIG for virtual machines (<u><a href="http://iase.disa.mil/stigs/stig/index.html">here</a></u>) both mandate collection and analysis of VM platform logs; none goes into enough details on what to look for in logs. Let's try to shed some light on security-focused log analysis of VMWare ESX v. 3.x logs. </p>  <p>First, at least until ESXi becomes the default choice, one needs to keep in mind that ESX as &quot;Linux-inside&quot; and thus diving into <em>/var/log</em> will not reveal any &quot;alien technology&quot; (well, not much :-)). However, one of the most useful logs is <em>/var/log/hostd.N </em>which is not a descendant of Linux standard logs. Extensive VM event records are written into this file. </p>  <p>Let's focus on various types of logins to the ESX platform and identify logs that indicate a successful and failed attempts to log in. Here are a few useful examples to analyze:</p>  <p><strong>Successful logins:</strong></p>  <ul>   <li><em>May 30 09:20:42 esx2 su(pam_unix)[9405]: session opened for user root by jhonny(uid=1626)</em> </li> </ul>  <p>This is a classic Linux root login message; you can watch for these by searching VMWare ESX logs for &quot;session AND opened AND user AND root.&quot;&#160; Notice the user name of the user who switched to root.</p>  <ul>   <li><em>May 30 09:20:34 esx2 sshd(pam_unix)[9364]: session opened for user jhonny by (uid=0)</em> </li> </ul>  <p>This is also a classic Linux message for a normal (non-root) user login.</p>  <ul>   <li><em>[2008-05-25 06:57:48.774 'ha-eventmgr' 111639472 info] Event 40645 : User jhonny@1.1.1.1 logged in</em> </li> </ul>  <p>This is a VMWare -specific application login to ESX. You can track such events by username, by event ID or by keywords &quot;event AND logged AND user&quot; (if you are using search)</p>  <p><strong>Failed logins:</strong></p>  <ul>   <li><em>May 30 09:20:31 esx2 sshd[9356]: Failed password for jhonny from 1.1.1.1 port 54773 ssh2</em> </li> </ul>  <p>Another classic Linux message from the ESX system; a failure to login due to incorrect password. </p>  <ul>   <li><em>May 27 12:06:59 esx2 sshd[4756]: Failed password for illegal user jonny from 1.1.1.1 port 30594 ssh2</em> </li> </ul>  <p>A message indicating a failure to login due to incorrect username (note a typo). </p>  <ul>   <li><em>May 25 07:03:48 esx1 sudo:&#160;&#160;&#160;&#160; jhonny : 3 incorrect password attempts ; TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/bin/bash</em> </li> </ul>  <p>This ESX Linux platform message should also be familiar to Linux/Unix admins: it indicates multiple sudo password failures; look for such messages in the logs.</p>  <p>BTW, do you <a href="http://chuvakin.blogspot.com/2006/09/anton-security-tip-of-day-3-watch-for.html">need to be reminded</a> to track NOT only failed, but also successful login events?!</p>  <p>Overall, you must prepare for the future by learning to analyze&#160; VMWare logs, just like you handled &quot;legacy OS&quot;, such as Linux/Unix and Windows.</p>  <p>As I said before, I am tagging all the tips on <a href="http://del.icio.us/anton18">my del.icio.us feed</a>; here is the link: <a href="http://del.icio.us/anton18/security+tips">All Security Tips of the Day</a>.</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:54499c21-dd11-4ff7-9221-4cf2ec0c95fe" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/tips" rel="tag">tips</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a></div> <script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");<br />document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var pageTracker = _gat._getTracker("UA-101395-5");<br />pageTracker._initData();<br />pageTracker._trackPageview();</script>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fhl1bK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fhl1bK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xW7PtK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xW7PtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qHcDbK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qHcDbK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374532539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware esx">vmware esx</category>
      <category domain="http://securityratty.com/tag/analyze vmware logs">analyze vmware logs</category>
      <category domain="http://securityratty.com/tag/analyze">analyze</category>
      <category domain="http://securityratty.com/tag/vmware esx logs">vmware esx logs</category>
      <category domain="http://securityratty.com/tag/esx">esx</category>
      <category domain="http://securityratty.com/tag/security tip">security tip</category>
      <category domain="http://securityratty.com/tag/anton security tip">anton security tip</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374532539/anton-security-tip-of-day-16-virtually.html">Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis</source>
    </item>
  </channel>
</rss>
