<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fraud-detection]]></title>
    <link>http://securityratty.com/tag/fraud-detection</link>
    <description></description>
    <pubDate>Thu, 30 Oct 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting]]></title>
      <link>http://securityratty.com/article/281502f81a86714e3f7b33b438faa8bc</link>
      <guid>http://securityratty.com/article/281502f81a86714e3f7b33b438faa8bc</guid>
      <description><![CDATA[New Video: Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting I had to do a presentation for one of my MBA courses, and one of the topic choices was the Sarbanes-Oxley...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/hacking-your-sox-off-sarbanes-oxley-fraud-and-fraudulent-financial-reporting">Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting</a><br/>I had to do a presentation for one of my MBA courses, and one of the topic choices was the Sarbanes-Oxley act. I chose it because I thought I could relate it to computer security, but as it turns out the connection is somewhat tenuous as you will see if you watch the presentation.
<p><a href="http://feedads.googleadservices.com/~a/bycHk2dSKNYSDDAslWCKaurjXN4/a"><img src="http://feedads.googleadservices.com/~a/bycHk2dSKNYSDDAslWCKaurjXN4/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/CuSVZVnq9Mg" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 09:24:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sarbanes-oxley">sarbanes-oxley</category>
      <category domain="http://securityratty.com/tag/fraudulent financial">fraudulent financial</category>
      <category domain="http://securityratty.com/tag/sarbanes-oxley act">sarbanes-oxley act</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/topic choices">topic choices</category>
      <category domain="http://securityratty.com/tag/sox">sox</category>
      <category domain="http://securityratty.com/tag/mba courses">mba courses</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/CuSVZVnq9Mg/i.php">Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting]]></title>
      <link>http://securityratty.com/article/53096a8433f664fb46e666f371ecca54</link>
      <guid>http://securityratty.com/article/53096a8433f664fb46e666f371ecca54</guid>
      <description><![CDATA[New Video: Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting I had to do a presentation for one of my MBA courses, and one of the topic choices was the Sarbanes-Oxley...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/hacking-your-sox-off-sarbanes-oxley-fraud-and-fraudulent-financial-reporting">Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting</a><br/>I had to do a presentation for one of my MBA courses, and one of the topic choices was the Sarbanes-Oxley act. I chose it because I thought I could relate it to computer security, but as it turns out the connection is somewhat tenuous as you will see if you watch the presentation.
<p><a href="http://feedads.googleadservices.com/~a/bycHk2dSKNYSDDAslWCKaurjXN4/a"><img src="http://feedads.googleadservices.com/~a/bycHk2dSKNYSDDAslWCKaurjXN4/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/eezvR0knfj4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 09:24:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sarbanes-oxley">sarbanes-oxley</category>
      <category domain="http://securityratty.com/tag/fraudulent financial">fraudulent financial</category>
      <category domain="http://securityratty.com/tag/sarbanes-oxley act">sarbanes-oxley act</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/topic choices">topic choices</category>
      <category domain="http://securityratty.com/tag/sox">sox</category>
      <category domain="http://securityratty.com/tag/mba courses">mba courses</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/eezvR0knfj4/i.php">Hacking Your SOX Off: Sarbanes-Oxley, Fraud, and Fraudulent Financial Reporting</source>
    </item>
    <item>
      <title><![CDATA[Elgan: Why you can't trust 'friends' on Facebook]]></title>
      <link>http://securityratty.com/article/de87ddbc4f7463f03d5adac7536288e3</link>
      <guid>http://securityratty.com/article/de87ddbc4f7463f03d5adac7536288e3</guid>
      <description><![CDATA[Social networks like Facebook and MySpace are subject to new, more dangerous opportunities for fraud, writes Mike Elgan, and you would be well-advised to verify every...]]></description>
      <content:encoded><![CDATA[Social networks like Facebook and MySpace are subject to new, more dangerous opportunities for fraud, writes Mike Elgan, and you would be well-advised to verify every friend.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bb11352e54d0afa987e8a2aea4f0f9bc:vro76kW6DuSbXhQ22U6nQT3SQ2MHpWiautE2rj3uFlRmFufMqZljccRNhLr4cg%2F8ntCWypDAX3XU'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c8825578a6642725f60232941ab9264d:NE8abhirXP5EE%2FrpaDHofFQftQc9nXPYv0A7uAkAqjGYN19dgG11r9WXCeeDznUzGo1n0SohySEVAg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:84d9184914275b3e92062ca61158c5d0:O%2B5Spe9olUR6%2Bj2t4hR2OXNHExuIH%2FtmOuT%2F%2Bu%2BZ9KZpUVAekQ1MQprTR4Ui6CQsXHB%2FvC8eTjcbgw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:4da2764508a6222e93503372f09f81c3:0m9JMDF%2BWUAx55MtS3xmYOd86Z7OYmSHdKG1qkbnqQPZ6kFpDGx6K4PooXwbWHkgPHTTP6Gf9HAF2A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=c57c7615dc846d0486bc453a0e7db9e2&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=c57c7615dc846d0486bc453a0e7db9e2&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=c57c7615dc846d0486bc453a0e7db9e2" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/writes mike elgan">writes mike elgan</category>
      <category domain="http://securityratty.com/tag/dangerous opportunities">dangerous opportunities</category>
      <category domain="http://securityratty.com/tag/social networks">social networks</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/subject">subject</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=c57c7615dc846d0486bc453a0e7db9e2">Elgan: Why you can't trust 'friends' on Facebook</source>
    </item>
    <item>
      <title><![CDATA[New Visa Card, Generates Random Security Codes]]></title>
      <link>http://securityratty.com/article/8fb7d235678e673cc04f68061fd7aeb4</link>
      <guid>http://securityratty.com/article/8fb7d235678e673cc04f68061fd7aeb4</guid>
      <description><![CDATA[In response to popular concerns with online credit card fraud, Visa Europe has announced a newly designed credit card, complete with a keypad and digital number display, according to the Daily...]]></description>
      <content:encoded><![CDATA[In response to popular concerns with online credit card fraud, Visa Europe has announced a newly designed credit card, complete with a keypad and digital number display, according to the Daily Mail.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/NWJkMVx-OVY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 06:20:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa europe">visa europe</category>
      <category domain="http://securityratty.com/tag/popular concerns">popular concerns</category>
      <category domain="http://securityratty.com/tag/daily mail">daily mail</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/response">response</category>
      <category domain="http://securityratty.com/tag/display">display</category>
      <category domain="http://securityratty.com/tag/digital">digital</category>
      <category domain="http://securityratty.com/tag/newly">newly</category>
      <category domain="http://securityratty.com/tag/keypad">keypad</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/NWJkMVx-OVY/New_Visa_Card_Generates_Random_Security_Codes">New Visa Card, Generates Random Security Codes</source>
    </item>
    <item>
      <title><![CDATA[Apple plays catch-up, ads anti-fraud safeguard to Safari]]></title>
      <link>http://securityratty.com/article/949c25cc922a5535dd873e46a0e7d378</link>
      <guid>http://securityratty.com/article/949c25cc922a5535dd873e46a0e7d378</guid>
      <description><![CDATA[In an update to its Safari Web browser, Apple on Thursday patched several security flaws and added anti-phishing protection -- making it the last major browser to receive the feature that blocks known...]]></description>
      <content:encoded><![CDATA[In an update to its Safari Web browser, Apple on Thursday patched several security flaws and added anti-phishing protection -- making it the last major browser to receive the feature that blocks known identity-stealing sites.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a81f524bd87796a718dc935f96bf64b0:aSLzi9e0JNzXSvY%2Bu9Uu8Tjtpg%2F4VbUZU9as2mAYqkph%2FaWDgX%2Fg6ZJ88MzCtOlxyUmJrbM5R1%2BC'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d8058c83a09391fc4a875abd9273c2d8:Ove5%2FRPNbN39Bq7RW42e86yXw8B3yA2Lmd0kYc0RNiZJ0qUxXiSDKVYB%2BiVnGo25Wi%2B%2BmSFFjWtwXQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:214c44e436c54d95e2ce19b25f6330a5:VU3q1pVu8lQRivyhKfuFEEeIp6oe7xEg%2FGcKB7WpSGHxaNbUzGZvcATtWxKd2FFoM%2Budcc0CCW2dIQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0dc6c5d43e324af14a12a7a2b45a2503:13wLNFM%2BYtZruwJ7RAnLKf9A0uh96L%2BKy67UBuEOBm969rJuTqDb%2B%2Fyod1adK6BW%2BH10Um%2Bk7tAuaw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=c57d1d9341b46aa89dfe1a3a5f949aeb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=c57d1d9341b46aa89dfe1a3a5f949aeb" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safari web browser">safari web browser</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/major browser">major browser</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/blocks">blocks</category>
      <category domain="http://securityratty.com/tag/receive">receive</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=c57d1d9341b46aa89dfe1a3a5f949aeb">Apple plays catch-up, ads anti-fraud safeguard to Safari</source>
    </item>
    <item>
      <title><![CDATA[Apple plays catch-up, adds anti-fraud safeguard to Safari]]></title>
      <link>http://securityratty.com/article/6144ae4569c814f71e85265854f45805</link>
      <guid>http://securityratty.com/article/6144ae4569c814f71e85265854f45805</guid>
      <description><![CDATA[Apple Friday added anti-phishing protection to Safari, the last major browser to receive the feature that blocks known identity-stealing sites. The company also patched 11 security bugs in the...]]></description>
      <content:encoded><![CDATA[Apple Friday added anti-phishing protection to Safari, the last major browser to receive the feature that blocks known identity-stealing sites. The company also patched 11 security bugs in the program, the bulk of them specific to the Microsoft Windows version.]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft windows version">microsoft windows version</category>
      <category domain="http://securityratty.com/tag/major browser">major browser</category>
      <category domain="http://securityratty.com/tag/apple friday">apple friday</category>
      <category domain="http://securityratty.com/tag/security bugs">security bugs</category>
      <category domain="http://securityratty.com/tag/safari">safari</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/blocks">blocks</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://www.networkworld.com/news/2008/111408-apple-plays-catch-up-adds-anti-fraud.html?fsrc=rss-security">Apple plays catch-up, adds anti-fraud safeguard to Safari</source>
    </item>
    <item>
      <title><![CDATA[Experian South Africa launches fraud prevention tool]]></title>
      <link>http://securityratty.com/article/fc692c99417c4305c6267e8587cb39bc</link>
      <guid>http://securityratty.com/article/fc692c99417c4305c6267e8587cb39bc</guid>
      <description><![CDATA[Experian South Africa has launched its latest application, a fraud prevention tool aimed at helping companies tighten...]]></description>
      <content:encoded><![CDATA[Experian South Africa has launched its latest application, a fraud prevention tool aimed at helping companies tighten security.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=55128?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=55128?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/experian south africa">experian south africa</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <source url="http://www.networkworld.com/news/2008/111108-experian-south-africa-launches-fraud.html?fsrc=rss-security">Experian South Africa launches fraud prevention tool</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security AND Compliance 9]]></title>
      <link>http://securityratty.com/article/8c92a5eb0e9512d04ed455c88f9d493d</link>
      <guid>http://securityratty.com/article/8c92a5eb0e9512d04ed455c88f9d493d</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #9, dated October 30th, 2008....]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #9, dated October 30th, 2008. BTW, I am renaming it into “Fun Reading on Security AND Compliance”</p>  <ol>   <li>“A Gartnergate?” What happened after Mr Pescatore <a href="http://blogs.gartner.com/john_pescatore/2008/10/28/twelve-word-tuesday-measuring-security-program-effectiveness/">uttered his now famous 12 words</a>: “The best security program is at the business with the happiest customers.” <a href="http://1raindrop.typepad.com/1_raindrop/2008/10/whats-happiness-got-to-do-with-it-1.html">This</a> (complete with Gunnar’s famous “firewalls+SSL” chart), <a href="http://rationalsecurity.typepad.com/blog/2008/10/gunnar-peterson-channels-tina-turner-sort-of-whats-happiness-got-to-do-with-it.html">this</a> – will add more as this snowballs. </li>    <li>Do you have an “ignorable” security policy? If yours is BOTH “ignorable” and “unfair”, then fuggedaboutit. <a href="http://www.networkworld.com/news/2008/102808-cisco-security-policies.html?nlhtsecstrat=rn_102808&amp;nladname=102808securitystrategiesal">Cisco survey kinda proves it</a>. A few fun comments are <a href="http://www.computerweekly.com/blogs/stuart_king/2008/10/security-policies.html">here</a> (“If people can't get their jobs done without having to find a way to circumvent policy then the policy is wrong.”)</li>    <li>Risk and clouds – <a href="http://riskmanagementinsight.com/riskanalysis/?p=496">here</a>, <a href="http://techbuddha.wordpress.com/2008/10/26/cloud-computing-the-good-the-bad-and-the-cloudy/">here</a>, <a href="http://rationalsecurity.typepad.com/blog/2008/10/will-you-all-please-shut-up-about-securing-the-cloudno-such-thing.html">here</a> and <a href="http://rationalsecurity.typepad.com/blog/2008/10/cloud-computing-security-in-poetic-review.html">here in poetic form</a> (!). Fun reading, but you know what? For many, many organization, what they have today is LESS secure than any future cloud computing advance… </li>    <li>Richard Bejtlich <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back.html">drop-kicks SIEM</a>&#160;<a href="http://chuvakin.blogspot.com/search/label/SIEM">too</a>, then <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_25.html">kicks it in the balls</a>. Then <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">kicks the dead horse</a> (<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back.html">1</a>,<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_25.html">2</a>,<a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">3</a>) </li>    <li><a href="http://securosis.com/2008/10/29/the-good-enoughwoe-is-me-dissociation-postulate/">Excellent reminder</a> about why people don’t care about security with a fabled quote from MJR (yes, it is my fave too!) Overall, Rich “reassures” with: “Don’t worry. When things get bad enough, we’ll get the call. If you’ve kept your documentation and communications up, you won’t get shafted with the proverbial short end.” </li>    <li>A few essays on risk, from <a href="http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=211600785">ANSI</a>, from <a href="http://www.schneier.com/blog/archives/2008/10/does_risk_manag.html">Schneier</a> and from BlogInfoSec (<a href="http://www.bloginfosec.com/2008/09/04/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-1/">part 1</a> and <a href="http://www.bloginfosec.com/2008/10/29/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-2/">part 2</a>, especially read <a href="http://www.bloginfosec.com/2008/10/29/the-difference-between-quantitative-and-qualitative-risk-analysis-and-why-it-matters-part-2/">part 2</a>) </li>    <li>So, what do CTOs really do every day? Interesting summary <a href="http://www.emergentchaos.com/archives/2008/10/ctos_product_management_a.html">here</a> and <a href="http://startuplessonslearned.blogspot.com/2008/09/what-does-startup-cto-actually-do.html">here</a>. </li>    <li><a href="http://layer8.itsecuritygeek.com/layer8/why-security-privacy-and-compliance-dont-mix/">Fun exploration of <em>security x privacy x compliance</em></a>. </li>    <li><a href="http://srmsblog.burtongroup.com/2008/10/it-security-meets-the-crash-of-2008.html">Burton Group opines</a> on which security technologies will fare better/worse during &quot;The crisis”</li>    <li>A really fun interview with our CEO Philippe Courtot <a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;taxonomyName=Management&amp;articleId=9117939&amp;taxonomyId=14">here</a>. </li>    <li>More on <a href="http://taosecurity.blogspot.com/2008/09/security-vs-it-at-computerworld.html">IT vs IT security</a>, this time from Richard.</li>    <li>Do you want <a href="http://consumerist.com/5069018/how-outsourced-call-centers-are-costing-millions-in-identity-theft">people like that</a> doing “security”? A normal call center employee recognizes fraud, but their so-called “outsource security dept” authorizes the scam. Niiice.</li>    <li>Finally, “<a href="http://blog.wired.com/defense/2008/10/robot-packs-hun.html">Robots Hunt 'Non-Cooperative Humans' in Army Plan</a>” No comment :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OZKuM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OZKuM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Qv4oM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Qv4oM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0COrM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0COrM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/438357287" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 09:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/outsource security dept">outsource security dept</category>
      <category domain="http://securityratty.com/tag/security technologies">security technologies</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/circumvent policy">circumvent policy</category>
      <category domain="http://securityratty.com/tag/ignorable security policy">ignorable security policy</category>
      <category domain="http://securityratty.com/tag/security program">security program</category>
      <category domain="http://securityratty.com/tag/ignorable">ignorable</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/438357287/fun-reading-on-security-and-compliance.html">Fun Reading on Security AND Compliance 9</source>
    </item>
    <item>
      <title><![CDATA[ICANN Targeting Notorious Domain Name Seller]]></title>
      <link>http://securityratty.com/article/a5637715ddf9e86ac300b651f90f199d</link>
      <guid>http://securityratty.com/article/a5637715ddf9e86ac300b651f90f199d</guid>
      <description><![CDATA[The net's naming authority is moving to shut down a domain name seller after learning its CEO was convicted of online credit card fraud. Security researchers say the Estonia-based EstDomains plays too...]]></description>
      <content:encoded><![CDATA[The net's naming authority is moving to shut down a domain name seller after learning its CEO was convicted of online credit card fraud. Security researchers say the Estonia-based EstDomains plays too friendly with online criminals, while the company defends itself by saying it already has a new CEO.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=ccfcfa7ed837bdcd61efafa468d02482" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=ccfcfa7ed837bdcd61efafa468d02482" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=dhroM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=dhroM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=EGrjm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=EGrjm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Ao5qm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Ao5qm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Dt4rM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Dt4rM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=XqZ0M"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XqZ0M" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ycoim"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ycoim" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=5kIQm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=5kIQm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xbtFM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xbtFM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/437526823" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/437526824" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/seller">seller</category>
      <category domain="http://securityratty.com/tag/estdomains plays">estdomains plays</category>
      <category domain="http://securityratty.com/tag/online criminals">online criminals</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/ceo">ceo</category>
      <category domain="http://securityratty.com/tag/company defends">company defends</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/friendly">friendly</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/437526824/icann-targeting.html">ICANN Targeting Notorious Domain Name Seller</source>
    </item>
  </channel>
</rss>
