<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fund]]></title>
    <link>http://securityratty.com/tag/fund</link>
    <description></description>
    <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[ET and IT]]></title>
      <link>http://securityratty.com/article/f7836c0e5e12bf621dfc029dec99f890</link>
      <guid>http://securityratty.com/article/f7836c0e5e12bf621dfc029dec99f890</guid>
      <description><![CDATA[Interesting piece by Tom Friedman (who has been on the green bus longer than anyone in MSM) comparing the candidates' energy stances, especially this part

Why? Because renewable energy technologies...]]></description>
      <content:encoded><![CDATA[<p>Interesting <a href="http://www.nytimes.com/2008/09/03/opinion/03friedman.html?em=&amp;pagewanted=print">piece</a> by Tom Friedman (who has been on the green bus longer than anyone in MSM) comparing the candidates&#39; energy stances, especially this part:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Why? Because renewable energy technologies — what I call “E.T.” — are going to constitute the next great global industry. They will rival and probably surpass “I.T.” — information technology. The country that spawns the most E.T. companies will enjoy more economic power, strategic advantage and rising standards of living. We need to make sure that is America. Big oil and OPEC want to make sure it is not.</p></blockquote><br /><div><a href="http://money.cnn.com/2008/07/08/technology/Kleiner_bets_the_farm_Lashinsky.fortune/index.htm">Kleiner Perkins set up a $500M green growth fund</a>, which sounds like a lot, until you realize that energy is a $6 trillion industry. So Friedman is right that ET is going to be bigger than IT on the top line, now profit margins may be a different story.</div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 07:34:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/energy">energy</category>
      <category domain="http://securityratty.com/tag/renewable energy technologies">renewable energy technologies</category>
      <category domain="http://securityratty.com/tag/energy stances">energy stances</category>
      <category domain="http://securityratty.com/tag/friedman">friedman</category>
      <category domain="http://securityratty.com/tag/tom friedman">tom friedman</category>
      <category domain="http://securityratty.com/tag/kleiner perkins set">kleiner perkins set</category>
      <category domain="http://securityratty.com/tag/top line">top line</category>
      <category domain="http://securityratty.com/tag/strategic advantage">strategic advantage</category>
      <category domain="http://securityratty.com/tag/economic power">economic power</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/et-and-it.html">ET and IT</source>
    </item>
    <item>
      <title><![CDATA[Straight Talking Warren Buffett]]></title>
      <link>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</link>
      <guid>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</guid>
      <description><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards

Mr. Buffett...]]></description>
      <content:encoded><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards. <br /><span id="fullpost"><br />Mr. Buffett came straight out and accused Mr. Edwards of soliciting and taking money by deceitful means during his unsuccessful Presidential bid earlier this year.  According to Mr. Buffett, John Edwards knew back then that it was only a matter of time before the media uncovered the story of his mistress and alleged love-child.  <br />  <br /></span><br />Unfortunately, this did not stop him from asking suporters to fund his campaign.  Had people knew about the extra-marital affair, they most likely would not have sent in their hard earned dollars as there was no chance that he could continue in the race once the damning news broke.  Mr. Buffett suggested that Edwards should cut back on a few of those expensive haircuts and return those fifty and one hundred dollar donations that came in from ordinary hard working followers.<br /><br />This sentiment rings true for my industry.  At our training courses, we focus on Ethics at the beginning of the course and it runs throughout the training.  Nobody is saying that we are not human and we do not make mistakes - we all do, but covering up the truth to further your own selfish goals is a practice that would probably even disgust the animal Kingdom - except the reptiles possibly.<br /><br />Thank you Mr. Buffett for being so frank and forthright in this era of sterile political correctness.  This is why I enjoy working with successful business people and despise the empty promises and double-talking of policticians, to whatever party they belong.  To those of you in the security world, again I implore you to never forget that your word is your bond and at the end of the day, your reputation will live on after you are long gone.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/edwards">edwards</category>
      <category domain="http://securityratty.com/tag/john edwards">john edwards</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/successful business people">successful business people</category>
      <category domain="http://securityratty.com/tag/sterile political correctness">sterile political correctness</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/unsuccessful presidential bid">unsuccessful presidential bid</category>
      <category domain="http://securityratty.com/tag/ordinary hard">ordinary hard</category>
      <source url="http://www.thebulletproofblog.com/2008/08/straight-talking-warren-buffett.html">Straight Talking Warren Buffett</source>
    </item>
    <item>
      <title><![CDATA[Cyberattack Against Georgia Preceded Real Attack]]></title>
      <link>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</link>
      <guid>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</guid>
      <description><![CDATA[This is interesting: Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end,...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/13/technology/13cyber.html">This</a> is interesting:</p>

<blockquote>Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end, Georgia, with a population of just 4.6 million and a relative latecomer to the Internet, saw little effect beyond inaccessibility to many of its government Web sites, which limited the government's ability to spread its message online and to connect with sympathizers around the world during the fighting with Russia.

<p>[...]</p>

<p>In Georgia, media, communications and transportation companies were also attacked, according to security researchers. Shadowserver saw the attack against Georgia spread to computers throughout the government after Russian troops entered the Georgian province of South Ossetia. The National Bank of Georgia's Web site was defaced at one point. Images of 20th-century dictators as well as an image of Georgia's president, Mr. Saakashvili, were placed on the site. "Could this somehow be indirect Russian action? Yes, but considering Russia is past playing nice and uses real bombs, they could have attacked more strategic targets or eliminated the infrastructure kinetically," said Gadi Evron, an Israeli network security expert. "The nature of what's going on isn't clear," he said.</p>

<p>[...]</p>

<p>In addition to D.D.O.S. attacks that crippled Georgia's limited Internet infrastructure, researchers said there was evidence of redirection of Internet traffic through Russian telecommunications firms beginning last weekend. The attacks continued on Tuesday, controlled by software programs that were located in hosting centers controlled by a Russian telecommunications firms. A Russian-language Web site, stopgeorgia.ru, also continued to operate and offer software for download used for D.D.O.S. attacks.</blockquote></p>

<p>Welcome to 21st century warfare.</p>

<blockquote>"It costs about 4 cents per machine," Mr. Woodcock said. "You could fund an entire cyberwarfare campaign for the cost of replacing a tank tread, so you would be foolish not to."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FRnMDK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FRnMDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O8aHKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O8aHKK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 09:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/indirect russian action">indirect russian action</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/georgian government">georgian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/russian troops">russian troops</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/georgia spread">georgia spread</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/cyberattack_aga.html">Cyberattack Against Georgia Preceded Real Attack</source>
    </item>
    <item>
      <title><![CDATA[Corporate Identity Theft]]></title>
      <link>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</link>
      <guid>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</guid>
      <description><![CDATA[I remember a talk by the value investor Mason Hawkins (Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at...]]></description>
      <content:encoded><![CDATA[<p>I remember a <a href="http://www.bengrahaminvesting.ca/Resources/videos.htm#hawkins">talk</a>&#160;by the value investor&#160;<a href="http://en.wikipedia.org/wiki/Mason_Hawkins">Mason Hawkins</a>&#160;(Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at some point, where there is a rule of law. Here is one example of what he is worried about and why investing in places where your assets have no legal protection does not give the investor a margin of safety.</p><div>Hermitage Fund was until recently the largest fund in Russia. From the Business Week story<a href="http://hermitagefund.com/index.pl/news/article.html?id=895"> &quot;Hijacking the Hermitage Fund&quot;</a></div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Corruption, intimidation, robbery, violent assault, forgery, large-scale fraud. No, not the subject of the latest John Grisham novel, but sensational allegations, made public Apr. 4 by Hermitage Capital Management -- until recently the largest foreign portfolio investor in Russia. In a detailed and damning report, titled Criminal Justice -- Russian-Style, Hermitage alleges the fund&#39;s Russian subsidiaries have fallen victim to an elaborate con designed to defraud the fund of hundreds of millions of dollars.&#160;<br />&#160;&#160;<br />The most sensational part of Hermitage&#39;s allegations is that the attempted larceny was carried out with the direct connivance of officials in the Russian police. Hermitage alleges the police seized documents and equipment that were instrumental to the attempted fraud, which involved bogus court cases based on forged documents, the aim of which was to sue Hermitage subsidiaries for hundreds of millions of dollars. &quot;The most shocking thing is not that there are corporate raiders in Russia who attempt to steal your shares,&quot; says Jamison Firestone, managing partner of Firestone Duncan, Hermitage&#39;s law firm. &quot;The shocking thing is that the police worked hand-in-hand with them, and actually performed the theft of the documents so that the corporate raiders could then do their work.&quot;</p></blockquote><div><br /><div>From the most recent Hermitage Fund letter, here is the current state:</div><br /><br /></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>So the two-pronged scam worked in one area and failed in another. The perpetrators weren’t able to steal the assets from us based on the fake court claims, but they were able to steal $230 million from the Russian government by filing amended tax returns on behalf of our stolen companies. What makes this story even more shocking is that we filed six 255-page criminal complaints with the Russian authorities in December last year, one month before the tax fraud took place, and they did nothing to stop it. Two complaints were sent to the Russian General Prosecutor, two to the Russian State Investigative Committee and two to the Internal Affairs Department of the Interior Ministry. There was enough information to prevent the fraud and indict a number of people behind it if the government had acted.&#160;</p><p>Instead of doing anything to save the Russian state from this highly sophisticated and organized looting, two of our complaints were thrown out immediately; two were returned to the same Interior Ministry official we were complaining about (essentially, he was being asked to “investigate himself”); and one was thrown out for “lack of any crime committed.” Only one complaint was taken seriously. It was taken up by the Russian State Investigative Committee in early February, but before it could get any traction, the case was lowered to the South region of the Moscow district of the State Investigative Committee (the lowest level of the Committee) and by June, another senior Interior Ministry official whom we had named in our complaint had joined the “investigation” team (again, to “investigate himself”). To this day there has been no serious response by the Russian authorities to this massive fraud against the Russian state.&#160;</p><p>As we described in our April letter, the problem of corporate “raiding” is now so endemic in Russia that President Medvedev speaks about it as one of the biggest problems faced by Russian businesses. In this case, raiders have taken this problem to a new and absurd extreme by “raiding” the Russian state itself and so far getting away with it. Together with HSBC, we will shortly be filing new criminal complaints with the Russian General Prosecutor and Russian State Investigative Committee as well as with many law enforcement authorities outside of Russia. It is hard to predict what will happen next in this unfolding and unbelievable saga, but as always we will keep you updated on any further developments as they arise.</p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><p>Of course we see individual identity theft on a regular basis (actually as Ross Anderson points out its not really identity theft but poor controls on the bank&#39;s parts using SSNs as secrets and so on), but you dont see a major corporation stolen every day.</p>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 05:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian police">russian police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/russian-style">russian-style</category>
      <category domain="http://securityratty.com/tag/hermitage">hermitage</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/corporate-identity-theft.html">Corporate Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
    <item>
      <title><![CDATA[Card Wars: The Phantom Menace]]></title>
      <link>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</link>
      <guid>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</guid>
      <description><![CDATA[Just like George Lucas cant help but return to his old projects , I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of phantomwithdrawals.com ,...]]></description>
      <content:encoded><![CDATA[<p>Just like George Lucas can&#8217;t help but <a href="http://www.cinematical.com/2005/05/25/lucas-idea-for-new-star-wars-prequel/">return to his old projects</a>, I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of <a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a>, freshly re-vamped, updated and turned into a Wiki editable by the general public.</p>
<p>In fact, it&#8217;s not just great artists like Mr. Lucas and I starting up old projects, our honourable colleagues wearing the black hats have got the same idea. We have new victims reporting in, <a href="http://www.newsvine.com/_news/2008/07/01/1629600-citibank-atm-breach-reveals-pin-security-problems">rumours</a>&nbsp;<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-issues.html">abound</a> of an auth system compromise at Citi, the Ombudsman is backlogged with months of disputed withdrawal cases, and some like <a href="http://www.guardian.co.uk/technology/2008/jan/03/hitechcrime.news">Alain Job</a> are even going to court.</p>
<p>One original contributor to the phantom case histories has just been hit by a second phantom withdrawal five years on and is chalking up another case in the files. While her new phantom is a bread-and-butter skim incident (a magstripe clone used in the far east), amongst this mass, true phantoms &#8212; the real mystery cases &#8212; are on the rise too. Two new victims with whom I have been corresponding very kindly offered to fund the hosting for the revamped site.</p>
<p>Let&#8217;s consider one of these mysteries. The McGaughey case has been reported in the media in Northern Ireland: dozens of withdrawals taking place over four weeks, totaling almost five thousand pounds, all within a ten mile radius of the McGaughey&#8217;s home. Summarised that way it looks like a classic first party fraud (couple short on cash withdraw money, then deny it later). But no-one in the family is short on cash, the McGaugheys look after their card details carefully, and have solid <a href="http://www.bridgewebs.com/derryvolgie/">alibis</a> at the time of many of the withdrawals, and the interlocking pattern of real and disputed withdrawals is such that any third party would have a hard time taking and returning the card (whether covertly or in collusion with the McGaugheys). No-one appears to have either the means or the motive.</p>
<p>Unusually the bank has been very cooperative, providing logs from their authorisation system (<A href="http://www.aciworldwide.com/products/detail.aspx?product_id=236">BASE24</a>), including all of the cryptograms, input data and transaction parameters covering the affected transactions. Everything turns on the Application Transaction Counter (ATC), an on-card counter which increments with every transaction initiated. If an EMV chip can be fully cloned (secret keys and all), then it will have to submit an ATC value when transacting, and if used in parallel with the real card, it won&#8217;t be long before the same number pops up twice in the auth system, or large gaps in the sequence appear. The McGaughey&#8217;s ATC sequence appears to interlock perfectly: clearly the original card was used?</p>
<p>Of course logs can be misinterpreted (<a href="http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm">Badger</a>) or even faked, auth systems may not work as expected, and customers may lie and cheat following all sorts of agendas; just around the corner the missing piece of the jigsaw may lie, which reveals the truth behind the case. And there is the totally separate matter of who should suffer the loss in the interim, whilst the truth remains unclear. <a href="http://www.lightbluetouchpaper.org/2008/04/09/new-banking-code-shifts-more-liability-to-customers/">Liability for disputed withdrawals</a> is the most hotly contested issue of all.</p>
<p><a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a> can&#8217;t do much more for the McGaugheys, but it can bear witness. Documenting the incidence of phantoms and the experiences of customers disputing them adds much needed transparency to the process, and helps researchers and experts seek out the really interesting cases.</p>
<p>Maybe we can lift the lid and discover the truth behind the &#8220;phantom menace&#8221; &#8212; everyone is united in that goal at least &#8212; but let&#8217;s also hope that Episode 2: <a href="http://www.epaynews.com/index.cgi?survey=&#038;ref=browse&#038;f=view&#038;id=11497625028614136145&#038;block=">Attack of the Clones</a> has not yet started shooting!</p>
<p>Mike.</p>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 11:06:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/phantom">phantom</category>
      <category domain="http://securityratty.com/tag/real">real</category>
      <category domain="http://securityratty.com/tag/real card">real card</category>
      <category domain="http://securityratty.com/tag/card details">card details</category>
      <category domain="http://securityratty.com/tag/phantom menace">phantom menace</category>
      <category domain="http://securityratty.com/tag/phantom withdrawal">phantom withdrawal</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/application transaction counter">application transaction counter</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/05/card-wars-the-phantom-menace/">Card Wars: The Phantom Menace</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Research on Digital Divide; NYC May Opt for Fiber for Housing Projects]]></title>
      <link>http://securityratty.com/article/bee176c3470a5229e4b9bd38947d3add</link>
      <guid>http://securityratty.com/article/bee176c3470a5229e4b9bd38947d3add</guid>
      <description><![CDATA[Participate in a research survey on the role of wireless to shrink the digital divide: Gwen Shaffer, a Temple University (Phila.) doctoral student, is looking for responses from many kinds of...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://templeuniversit.wirelesscommunities.sgizmo.com"><strong>Participate in a research survey on the role of wireless to shrink the digital divide:</strong></a> Gwen Shaffer, a Temple University (Phila.) doctoral student, is looking for responses from many kinds of stakeholders in building networks that have a purpose, at least in part, to extend Wi-Fi access. She notes that this could include community networks, non-profits, and for-profit firms like Fon. Personal information will not be collected, and she's looking to conduct in-depth interviews with some participants.</p>

<p><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9110977"><strong>New York City considers plan to bring fiber to public housing residents:</strong></a> Wireless networks are definitely out in the recommendations of a private consultant to the city's Broadband Advisory Committee, ComputerWorld reports. They may opt to use $4m in a fund from Verizon and a potential $8m from the two incumbent cable operators.</p>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 10:40:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/include community networks">include community networks</category>
      <category domain="http://securityratty.com/tag/digital divide">digital divide</category>
      <category domain="http://securityratty.com/tag/wireless networks">wireless networks</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/incumbent cable operators">incumbent cable operators</category>
      <category domain="http://securityratty.com/tag/extend wi-fi access">extend wi-fi access</category>
      <category domain="http://securityratty.com/tag/broadband advisory committee">broadband advisory committee</category>
      <category domain="http://securityratty.com/tag/conduct in-depth interviews">conduct in-depth interviews</category>
      <source url="http://wifinetnews.com/archives/008404.html">Wee-Fi: Research on Digital Divide; NYC May Opt for Fiber for Housing Projects</source>
    </item>
    <item>
      <title><![CDATA[NAC secures U.N. agency]]></title>
      <link>http://securityratty.com/article/24552cf19a7e0bcbbec350a287ae7235</link>
      <guid>http://securityratty.com/article/24552cf19a7e0bcbbec350a287ae7235</guid>
      <description><![CDATA[The United Nations Population Fund (UNFPA) is using network access control at 11 regional offices around the world to keep potentially dangerous non-compliant machines from compromising the agency's...]]></description>
      <content:encoded><![CDATA[The United Nations Population Fund (UNFPA) is using network access control at 11 regional offices around the world to keep potentially dangerous non-compliant machines from compromising the agency's core network in New York City.]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network access control">network access control</category>
      <category domain="http://securityratty.com/tag/dangerous non-compliant machines">dangerous non-compliant machines</category>
      <category domain="http://securityratty.com/tag/nations population fund">nations population fund</category>
      <category domain="http://securityratty.com/tag/regional offices">regional offices</category>
      <category domain="http://securityratty.com/tag/york city">york city</category>
      <category domain="http://securityratty.com/tag/core network">core network</category>
      <category domain="http://securityratty.com/tag/agency">agency</category>
      <category domain="http://securityratty.com/tag/unfpa">unfpa</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <source url="http://www.networkworld.com/news/2008/072108-network-access-control-un.html?fsrc=rss-security">NAC secures U.N. agency</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Compromised Web Sites]]></title>
      <link>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</link>
      <guid>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</guid>
      <description><![CDATA[Despite that pure patriotic hacktivism is still alive and kicking, compromised sites are largely getting monetized these days, starting from hosting blackhat SEO junk pages, to redirecting to live...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/CA2dvGI0DL0/s1600-h/Municipal_de_Amparo.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/k2bP_iz48tA/s200-R/Municipal_de_Amparo.png" style="border: 0pt none ;" /></a>Despite that pure patriotic hacktivism is still alive and kicking, <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">compromised sites are largely getting monetized</a> these days, starting from hosting blackhat SEO junk pages, to redirecting to live exploit URLs and fake codecs where revenue is earned through their participation in an affiliate business model.<br />
<br />
With The Africa Middle Market Fund's site monetized by web site defacers who defaced it "in between" the blackhat SEO infrastructure they were hosting internally, in this I'll comment on the currently compromised and redirection to a fake porn sites, Camara Municipal de Amparo (<b>camaraamparo.sp.gov.br/r.html</b>). Basically, it's homepage is heavily linking to the Zlob variant (<b>camaraamparo.sp.gov.br/ video.exe</b>) in between loading an IFRAME to <b>61.162.230.12/ index.php</b>. As always, upon uploading their redirector, they've build enough confidence into their new hosting provider that the link to the redirector was instantly spammed across the web. The site is so heavily linking to the internal redirector itself, that upon clicking on the majority of links the user will inevitably come across it.<br />
<br />
Speaking of fake porn sites redirecting to Zlob variants, here are the very latest additions spammed across the web through blackhat SEO practices :<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/ZDNLECdRM1U/s1600-h/fake_porn_sites_zlob.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/TIqQ0wE9bQM/s200-R/fake_porn_sites_zlob.JPG" style="border: 0pt none ;" /></a><b>just-tube .com<br />
mypornmovies .net<br />
moms-galls .net<br />
porntubefilms .com<br />
porntubedot .com<br />
hot-porntube .com<br />
landmovieblog .com<br />
sexvidtube .com<br />
freelifevideo .com<br />
getyourfreemovie .com<br />
iubat .com<br />
sweetyjoly .com<br />
hardbizarre .com<br />
freeworldvideo .net<br />
hot-porntube .net<br />
qualitymovies .net<br />
porntube1con .net<br />
video-info .net<br />
videocityblog .com<br />
fuckedolder&nbsp; .com<br />
highpro1 .com<br />
max-graf.com .pl<br />
grandsupertds .info<br />
hot-porn-tube .net<br />
hot-porntube .com<br />
terryschulz .com<br />
show-sextube .com<br />
qualitymovies .net<br />
clubvideos .net</b><br />
<br />
No matter the high profile site that's been exploited in order to participate in such malicious operations, for the time being, crunching out new domain names and using the hosting services of the well known ISPs neglecting their removal, seems to be the tactic of choice. The long tail of SQL injected sites is however, clearly replacing the plain simple blackhat SEO web spamming, so that traffic to these rogue sites is driven through redirection of the the traffic from legitimate sites.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cEyKTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cEyKTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qsdYjJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qsdYjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVongj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVongj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4DJmRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4DJmRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=al8bCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=al8bCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nrE7PJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nrE7PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TCjewj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TCjewj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/334911319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue sites">rogue sites</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/web site defacers">web site defacers</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/redirector">redirector</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/334911319/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</source>
    </item>
  </channel>
</rss>
