<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: firm]]></title>
    <link>http://securityratty.com/tag/firm</link>
    <description></description>
    <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Spam levels fluctuate as crooks try to revive botnets]]></title>
      <link>http://securityratty.com/article/56f12388b579b846be1e8a67255946c1</link>
      <guid>http://securityratty.com/article/56f12388b579b846be1e8a67255946c1</guid>
      <description><![CDATA[Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already...]]></description>
      <content:encoded><![CDATA[Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already bounced back.]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/global spam volumes">global spam volumes</category>
      <category domain="http://securityratty.com/tag/junk mail">junk mail</category>
      <category domain="http://securityratty.com/tag/researchers continue">researchers continue</category>
      <category domain="http://securityratty.com/tag/remain">remain</category>
      <category domain="http://securityratty.com/tag/firm">firm</category>
      <category domain="http://securityratty.com/tag/claim">claim</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <category domain="http://securityratty.com/tag/weeks">weeks</category>
      <source url="http://www.networkworld.com/news/2008/112508-spam-levels-fluctuate-as-crooks.html?fsrc=rss-security">Spam levels fluctuate as crooks try to revive botnets</source>
    </item>
    <item>
      <title><![CDATA[Not Your Father's Data Breach]]></title>
      <link>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</link>
      <guid>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</guid>
      <description><![CDATA[I am surprised this doesn't happen more often, or become public when it does happen, and I suspect it will


Corporate custodians of confidential medical data should be closely monitoring events...]]></description>
      <content:encoded><![CDATA[<p>I am surprised <a href="http://www.stltoday.com/blogzone/the-platform/published-editorials/2008/11/express-scripts-data-breach-is-bitter-medicine/"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">this</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> doesn&#39;t happen more often, or become public when it does happen, and I suspect it will:</span></p><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Corporate custodians</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;of confidential medical data should be closely monitoring events connected to a nightmarish computer security breach in the St. Louis region.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Express Scripts is one of the nation’s largest pharmacy benefits managers. The company, with headquarters in St. Louis County, handles approximately 500 million prescriptions per year for 50 million workers at 1,600 American companies. Early in October, it received an extortion letter, the details of which it released on Nov. 6.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The letter included personal information on about 75 Express Scripts clients — Social Security numbers, dates of birth and, in some cases, information about prescription medications. Whoever sent the letter demanded money from the company — the amount has not been disclosed — and threatened to use the Internet to reveal personal and medical information about millions of people if the demands were not met.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Beyond&#0160;</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">the scale of the problem for Express Scripts — and the potential impact on the company is enormous — the issue extends well beyond the mounting concerns about identity theft, a phenomenon with which most people have become at least somewhat familiar.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The greater problem is the unique nature of personal medical records, the importance of moving to computerization of such records to improve health safety and reduce costs and the irreversibility of the damage people can suffer if confidential medical information becomes public. The stakes are so high that a federal law establishes strict standards for maintaining the privacy of medical information and stiff fines for failing to do so.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Medical records of all kinds — paper and, especially, electronic — must be protected with the most sophisticated kinds of security systems available, including backup protections and automatic alerts of security violations. Yet Express Scripts learned of this breach in the “worst way,” as InformationWeek.com security correspondent George Hulme put it in an online report: “via an extortion letter.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Express Scripts</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;breach raises many questions for all elements of the health industry: hospitals, clinics and doctors’ practices, benefits management firms, insurance companies, pharmacies, employers and government agencies:</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Are they using the most advanced information security technology possible? Do they minimize the amount of data they collect and keep it only as long as necessary? Do they have strict protocols governing access to personal and medical data — and systems to enforce those protocols? If criminals were to hack into their systems, how would the companies know? How soon? And are the systems capable of instantly cutting off illegal access as soon as a breach is discovered?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Confronted</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;with a grave breach of electronic security, Express Scripts has responded by contacting law enforcement, establishing an informational website, offering a substantial reward and hiring a private consulting firm to help clients who have privacy concerns and investigate situations that “appear to be tied to identity theft” and provide “identity restoration services.” There is no question that the company is taking the situation extremely seriously.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Given the ongoing criminal situation, information about how Express Scripts’ data systems were compromised — and whether it could have been avoided — has yet to be disclosed. But the American people have the right to expect that their sensitive personal and medical information is zealously protected and kept secure — not only by Express Scripts but also by every person or company entrusted with it.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The reason I am surprised this doesn&#39;t happen more often is that many Fortune 500 companies have oceans and oceans of personal data. Almost the only companies that have even tried to get to a medium level assurance are financial companies, yet many of the other companies have as much or even more data, with lower assurance. All that was lacking in the mix was an incentive and a bit of creativity and risk taking by the bad guys.</span></span></p><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">I posted this to the security metrics list and Andy Jaquith quoted it in his great book S<a href="http://1raindrop.typepad.com/1_raindrop/2007/08/chicken-soup-fo.html">ecurity Metrics</a>:</span></div><div><span style="color: #333333; line-height: 17px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; ">&quot;Customers and customer relationships...have tangible measurable value to businesses, and their value is much easier to communicate to those who fund projects. So in an enterprise risk management scenartio, their vlaue informs the risk management process...[For example, consider] a farmer deciding which crop to grow. A farmer interested in short term profits may grow the same high yield crop every year, but over time this would burn the fields out. The long term focused farmer would rotate the crops and invest in things that build the value of the farm and soil over time. Investing in security on behalf of your customers is like this. The investment made in securing your customer&#39;s data build current and future value for them. Measuring the value of the customer and relationships helps to target where to allocate security resources.&quot;</span></p></blockquote><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">Of course this is the opposite of how most organizations do risk management and security architecture, and now, the fields have turned brown.<br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">(Thanks to Chris for pointing me to this story)</span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 06:37:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/medical information">medical information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/personal medical records">personal medical records</category>
      <category domain="http://securityratty.com/tag/medical records">medical records</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/not-your-fathers-data-breach.html">Not Your Father's Data Breach</source>
    </item>
    <item>
      <title><![CDATA[ICS and "Where Do I Start"]]></title>
      <link>http://securityratty.com/article/e9d38932a6ec7c99f65d6f8ad8b56dc4</link>
      <guid>http://securityratty.com/article/e9d38932a6ec7c99f65d6f8ad8b56dc4</guid>
      <description><![CDATA[It is a surprisingly simple question, but one that I am not accustomed to answering, and I think that I did a poor job in addressing. I basically pointed the guy back to the lifecycle and said &quot;If...]]></description>
      <content:encoded><![CDATA[It is a surprisingly simple question, but one that I am not accustomed to answering, and I think that I did a poor job in addressing.  I basically pointed the guy back to the lifecycle and said "If it's new data, go through this process.  If it is existing data, go through this process".  Technically sound, but not very helpful.  If you are working at a large firm with hundreds of legacy systems and data strewn all over the place, the challenges are far greater than that. ]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 04:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data strewn">data strewn</category>
      <category domain="http://securityratty.com/tag/surprisingly simple question">surprisingly simple question</category>
      <category domain="http://securityratty.com/tag/legacy systems">legacy systems</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/poor job">poor job</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/firm">firm</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <source url="http://infocentric.typepad.com/blog/2008/11/ics-and-where-do-i-start.html">ICS and "Where Do I Start"</source>
    </item>
    <item>
      <title><![CDATA[Hosting firm takedown bags 500,000 bots]]></title>
      <link>http://securityratty.com/article/2aa44764005da16b59081934c3d8d457</link>
      <guid>http://securityratty.com/article/2aa44764005da16b59081934c3d8d457</guid>
      <description><![CDATA[The shutdown last week of Web hosting company McColo crippled more than half a million bots, which can no longer receive commands from criminals, a security researcher said...]]></description>
      <content:encoded><![CDATA[The shutdown last week of Web hosting company McColo crippled more than half a million bots, which can no longer receive commands from criminals, a security researcher said today.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:720d222e1e248951db2f0ffc1d8ec5cd:BZWzGOi2sYq99fGf1qQixRUHYm4kfgzz4C1XBAM26BvXD6LYaK%2FmlavtoaoGG7JUoLnbwJ5jD5jW'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c186dbc6f51362d57ff523944b0e12e7:RusZPMuJurQPDMHc7X7o%2FJznzRxUlTv7UhzptW8e2AkTRcvlNeTwc6hCOPVCjmWetFDj%2Feo3KgApdw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:14455ea9acd776a6fb8021cfde7d7ede:EFWVRxbGDG99buAbkP%2Fn%2B5n5NQHXaet6D3%2BFma%2FEyaZ9qUa8kmSK1t%2FzlnNzpaY8qoCY91fpsCGj3Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:55a8a0982f5c5217923fb9ead96a05bd:d1svRJ0Ls4i7qsofossJT%2F5irnD2pFfDlCy1Ahwue9Gmd%2B4SS9LN2PMmhh13VPbobUvtauQ96RJELQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=e13dfce99aa28e495299b2b0c607fe5c"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=e13dfce99aa28e495299b2b0c607fe5c" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=e13dfce99aa28e495299b2b0c607fe5c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/company mccolo">company mccolo</category>
      <category domain="http://securityratty.com/tag/million bots">million bots</category>
      <category domain="http://securityratty.com/tag/receive commands">receive commands</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/half">half</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e13dfce99aa28e495299b2b0c607fe5c">Hosting firm takedown bags 500,000 bots</source>
    </item>
    <item>
      <title><![CDATA[Hosting firm takedown bags 500,000 bots]]></title>
      <link>http://securityratty.com/article/dc228a654506a197a89cb9beb7bd29b9</link>
      <guid>http://securityratty.com/article/dc228a654506a197a89cb9beb7bd29b9</guid>
      <description><![CDATA[The shutdown last week of a U.S.-based Web hosting company crippled more than 500,000 bots, or compromised computers, which no longer are able to receive commands from criminals, a security researcher...]]></description>
      <content:encoded><![CDATA[The shutdown last week of a U.S.-based Web hosting company crippled more than 500,000 bots, or compromised computers, which no longer are able to receive commands from criminals, a security researcher said Tuesday.]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/receive commands">receive commands</category>
      <category domain="http://securityratty.com/tag/bots">bots</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <source url="http://www.networkworld.com/news/2008/111808-hosting-firm-takedown-bags-500000.html?fsrc=rss-security">Hosting firm takedown bags 500,000 bots</source>
    </item>
    <item>
      <title><![CDATA[Add a staffing firm to your job search arsenal]]></title>
      <link>http://securityratty.com/article/92a55a154c69638260de6a202e681f9a</link>
      <guid>http://securityratty.com/article/92a55a154c69638260de6a202e681f9a</guid>
      <description><![CDATA[Today's turbulent economy has made job search efforts more challenging -- and nerve-racking -- for those in...]]></description>
      <content:encoded><![CDATA[Today's turbulent economy has made job search efforts more challenging -- and nerve-racking -- for those in IT.]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/turbulent economy">turbulent economy</category>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/efforts">efforts</category>
      <source url="http://www.networkworld.com/news/2008/111808-add-a-staffing-firm-to.html?fsrc=rss-security">Add a staffing firm to your job search arsenal</source>
    </item>
    <item>
      <title><![CDATA[Most Spam Came from a Single Web Hosting Firm]]></title>
      <link>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</link>
      <guid>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</guid>
      <description><![CDATA[Really : Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible...]]></description>
      <content:encoded><![CDATA[<p><a href="http://voices.washingtonpost.com/securityfix/2008/11/spam_volumes_drop_by_23_after.html?nav=rss_blog">Really</a>:</p>

<blockquote>Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible for coordinating the sending of roughly 75 percent of all spam each day.</blockquote>

<p>Certainly this won't last:</p>

<blockquote>Bhandari said he expects the spam volume to recover to normal levels in about a week, as the spam operations that were previously hosted at McColo move to a new home.

<p>"We're seeing a slow recovery," Bhandari. "We fully expect this to recover completely, and to go into the highest ever spam period during the upcoming holiday season."</blockquote></p>

<p>But with all the talk of massive botnets sending spam, it's interesting that most of it still comes from hosting services.  You'd think this would make the job of detecting spam a lot easier.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dOYuN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dOYuN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HEDZN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HEDZN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:11:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam volume">spam volume</category>
      <category domain="http://securityratty.com/tag/spam period">spam period</category>
      <category domain="http://securityratty.com/tag/spam operations">spam operations</category>
      <category domain="http://securityratty.com/tag/recover">recover</category>
      <category domain="http://securityratty.com/tag/recover completely">recover completely</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/home base">home base</category>
      <category domain="http://securityratty.com/tag/machines responsible">machines responsible</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/most_spam_came.html">Most Spam Came from a Single Web Hosting Firm</source>
    </item>
    <item>
      <title><![CDATA[Laid-off sysadmin arrested for threats to harm servers]]></title>
      <link>http://securityratty.com/article/9a48f1748f26bbc342ffbe1db0604070</link>
      <guid>http://securityratty.com/article/9a48f1748f26bbc342ffbe1db0604070</guid>
      <description><![CDATA[A systems administrator who was laid off by a financial services firm in New York was arrested for allegedly threatening to damage its servers if his severance pay wasn't...]]></description>
      <content:encoded><![CDATA[A systems administrator who was laid off by a financial services firm in New York was arrested for allegedly threatening to damage its servers if his severance pay wasn't increased.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:072b7aac629b4334d24e6586a65fdf05:sGN4tOC68c0nAcdNM090eRLjPFs0j%2FbImiEp1xBV2w6koAQdnuq0DeSQE2lq1vbU92wyHSfAX6DT'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:35bd07b262e295e4c3c0688f1f34081b:GcnADB1%2BmB52DRd26D7DIKDDGlJzKJg1cBFc6H9uTL8KaCBMiSpocD2kQMSM2wtcIBbSyfpwlHWS%2FQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c5c3ef735e030ea7ad55220e22689f0e:mDKRDGh5qRYlbYh8VtyPIZr04GzXI5hJII7L34vmaoILFIXqsvVNFVota%2FL3cNKPySAwO9w1eAxMgg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0dbc43cbf87013a8404a3252ebb83542:XSKC%2Fwc2dhdPPd2Wzfo3dzCjRBZ8nG0OL4oTBV8Y5XtwONxogMgx4D7znRD8o98SzZJa5OA4JG11dw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=657e711c0a9b2012184e49fa28e1ac96" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=657e711c0a9b2012184e49fa28e1ac96" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial services firm">financial services firm</category>
      <category domain="http://securityratty.com/tag/laid">laid</category>
      <category domain="http://securityratty.com/tag/systems administrator">systems administrator</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/severance">severance</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/york">york</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=657e711c0a9b2012184e49fa28e1ac96">Laid-off sysadmin arrested for threats to harm servers</source>
    </item>
    <item>
      <title><![CDATA[Hosting firm shutdown forces botnets to relocate]]></title>
      <link>http://securityratty.com/article/4f4f997274a541f5854267f9851c99fe</link>
      <guid>http://securityratty.com/article/4f4f997274a541f5854267f9851c99fe</guid>
      <description><![CDATA[The shutdown Tuesday of a California-based hosting company not only cut spam volumes, it also put a dent in malware-spreading botnets and other criminal activity, researchers said...]]></description>
      <content:encoded><![CDATA[The shutdown Tuesday of a California-based hosting company not only cut spam volumes, it also put a dent in malware-spreading botnets and other criminal activity, researchers said today.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6ee380da8eb1f27477166de1324a4816:Ugmgn9IP8%2BxskOkzR5BWUy420Jx%2BgrmHypS6kmu6AsWQSlUYSardMeHUlaPrJMn5PyyQEMC9pFs3'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fefbbebd0da74766f037b339d8d21351:tnQXCjtu0ZGZLwWRqx3HXpQRZEre%2FZYTU%2F0jqqCKpUI6ZHaQAPs5UkAjzTmvhuTD0ylflKHbhNEi7A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3cb42d7365956d982dab8e4cdc8887df:qzLiq5XZ5AqTT0F0%2Fl5sP3hY%2Bq%2Bja4pwHGUR34m8gpx2jX7yTn5qUMPZ0YedCaU7GUKG4EXECkQ99w%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bba0a8f27c13855c1516ebb5eeeb396e:cpcghEVeBC2DVPXeiijRnxF3BM34LBkQT9%2BaotkyhOiL1e%2FMxplXHAAvKq%2F%2FFnM8ZowxsV%2F781ko%2BA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=403c642d88ddb213ab3c0995650848fb"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=403c642d88ddb213ab3c0995650848fb"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=403c642d88ddb213ab3c0995650848fb" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cut spam volumes">cut spam volumes</category>
      <category domain="http://securityratty.com/tag/shutdown tuesday">shutdown tuesday</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <category domain="http://securityratty.com/tag/criminal activity">criminal activity</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/dent">dent</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=403c642d88ddb213ab3c0995650848fb">Hosting firm shutdown forces botnets to relocate</source>
    </item>
  </channel>
</rss>
