<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: international]]></title>
    <link>http://securityratty.com/tag/international</link>
    <description></description>
    <pubDate>Wed, 27 Aug 2008 03:27:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for August]]></title>
      <link>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</link>
      <guid>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</guid>
      <description><![CDATA[Here's a concise summary of all of my posts at Zero Day for August. If interested, consider going through July's summary , subscribe yourself to my personal feed , or Zero Day's main feed , and stay...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/GbK1dWvgJFs/s1600-h/zeroday_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/5TbgDFTdET4/s200-R/zeroday_august.png" /></a>Here's a concise summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a> for August. If interested, consider going through <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summary</a>, subscribe yourself to <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal feed</a>, or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a>, and stay informed.<br />
<br />
Some of the notable articles are - <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a> ; <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a> and <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1620">Cuil's stance on privacy - "We have no idea who you are"</a><br />
<b>02. </b><a href="http://blogs.zdnet.com/security/?p=1641">Phishers increasingly scamming other phishers</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1655">Consumer Reports urges Mac users to dump Safari, cites lack of phishing protection</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1657">Fake CNN news items malware campaign spreading rapidly</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1664">CNET's Clientside developer blog serving Adobe Flash exploits</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1712">Researcher discovers Nokia S40 security vulnerabilities, demands 20,000 euros to release details</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1717">Intel proactively fixes security flaws in its chips</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1723">1.5m spam emails sent from compromised University accounts</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1741">Fortune 500 companies use of email spoofing countermeasures declining</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1743">China busts hacking ring, managed to penetrate 10 gov't databases</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1750">Scammers caught backdooring chip and PIN terminals</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1754">SpamZa - opt in spamming service fighting to remain online</a><br />
<b>15.</b> <a href="http://blogs.zdnet.com/security/?p=1765">FEMA's PBX network hacked, over 400 calls made to the Middle East</a><br />
<b>16.</b> <a href="http://blogs.zdnet.com/security/?p=1782">Typosquatting the U.S presidential election - a security risk?</a><br />
<b>17.</b> <a href="http://blogs.zdnet.com/security/?p=1788">Hundreds of Dutch web sites hacked by Islamic hackers</a><br />
<b>18.</b> <a href="http://blogs.zdnet.com/security/?p=1796">Twitter's "me too" anti-spam strategy</a><br />
<b>19.</b> <a href="http://blogs.zdnet.com/security/?p=1806">Malware detected at the International Space Station</a><br />
<b>20.</b> <a href="http://blogs.zdnet.com/security/?p=1814">Taiwan busts hacking ring, 50 million personal records compromised</a><br />
<b>21.</b> <a href="http://blogs.zdnet.com/security/?p=1815">MSN Norway serving Flash exploits through malvertising</a><br />
<b>22.</b> <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q40d6L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q40d6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EXTjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EXTjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E4X5Il"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E4X5Il" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZxvQTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZxvQTl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8PfjsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8PfjsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bOWuvL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bOWuvL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RGgc1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RGgc1l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/383219682" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 03:40:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/adobe flash exploits">adobe flash exploits</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/flash exploits">flash exploits</category>
      <category domain="http://securityratty.com/tag/undetectable malware">undetectable malware</category>
      <category domain="http://securityratty.com/tag/inside india">inside india</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/million personal records">million personal records</category>
      <category domain="http://securityratty.com/tag/clientside developer blog">clientside developer blog</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/383219682/summarizing-zero-days-posts-for-august.html">Summarizing Zero Day's Posts for August</source>
    </item>
    <item>
      <title><![CDATA[Malware Infects Space Station Laptop]]></title>
      <link>http://securityratty.com/article/70eeae7eeabcdc69d20b928bbb4f4b56</link>
      <guid>http://securityratty.com/article/70eeae7eeabcdc69d20b928bbb4f4b56</guid>
      <description><![CDATA[NASA has confirmed that malware has managed to get aboard the International Space Station and that it's not the first time a worm has been discovered on space station...]]></description>
      <content:encoded><![CDATA[NASA has confirmed that malware has managed to get aboard the International Space Station and that it's not the first time a worm has been discovered on space station computers.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=M60rkU"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=M60rkU" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/380148447" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 03:33:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/space station computers">space station computers</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/aboard">aboard</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/380148447/article.do">Malware Infects Space Station Laptop</source>
    </item>
    <item>
      <title><![CDATA[Exposing Indias CAPTCHA Solving Economy]]></title>
      <link>http://securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</link>
      <guid>http://securityratty.com/article/ad0c8efa28ec8caf66f9be4e96ae79f0</guid>
      <description><![CDATA[Are you a Human?&quot; - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/6poURrjAkGI/s1600-h/india_captcha_breakers9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLhSbUhErdI/AAAAAAAACI0/HZ5BF3hc6nY/s200-R/india_captcha_breakers9.JPG" /></a>"Are you a Human?" - once asked the CAPTCHA, and the question got answered by, well, a human, thousands of them to be precise. Speculations around one of the main weaknesses of CAPTCHA based authentication in the face of human CAPTCHA solvers, seems to have evolved into a booming economy in India during the past 12 months, with thousands of people involved.<br />
<br />
The following article - "<a href="http://blogs.zdnet.com/security/?p=1835">Inside India’s CAPTCHA solving economy</a>" aims to expose legitimate data entry workers, whose business models and techniques are in fact used by Russian cybercriminals not only for personal phishing, spamming and malware spreading purposes, but also, to resell the bogus accounts and earn a premium in the process :<br />
<br />
"<i>No CAPTCHA can survive a human that’s receiving financial incentives for solving it, and with an army of low-wagedIndia CAPTCHA breakers human CAPTCHA solvers officially in the business of “data processing” while earning a mere $2 for solving a thousand CAPTCHA’s, I’m already starting to see evidence of consolidation between India’s major CAPTCHA solving companies. The consolidation logically leading to increased bargaining power, is resulting in an international franchising model recruiting data processing workers empowered with do-it-yourself CAPTCHA syndication web based kits, API keys, and thousands of proxies to make their work easier, and the process more efficient.</i>"<br />
<br />
Cybercrime is just as outsourceable as CAPTCHA breaking is these days.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a><br />
<a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing </a><br />
<a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers</a><br />
<a href="http://blogs.zdnet.com/security/?p=1232">Microsoft’s CAPTCHA successfully broken</a><br />
<a href="http://ddanchev.blogspot.com/2007/03/vladuzs-ebay-captcha-populator.html">Vladuz's Ebay CAPTCHA Populator</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/spammers-and-phishers-breaking-captchas.html">Spammers and Phishers Breaking CAPTCHAs</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/diy-captcha-breaking-service.html">DIY CAPTCHA Breaking Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/which-captcha-do-you-want-to-decode.html">Which CAPTCHA Do You Want to Decode Today?</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HJ3QtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HJ3QtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m6hgDK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m6hgDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0TXeOk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0TXeOk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4jwe6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4jwe6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9clPFK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9clPFK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JCXayK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JCXayK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5ic3Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5ic3Pk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/378395296" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 13:03:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/captcha">captcha</category>
      <category domain="http://securityratty.com/tag/microsofts captcha">microsofts captcha</category>
      <category domain="http://securityratty.com/tag/indias major captcha">indias major captcha</category>
      <category domain="http://securityratty.com/tag/hotmails captcha">hotmails captcha</category>
      <category domain="http://securityratty.com/tag/unbreakable captcha">unbreakable captcha</category>
      <category domain="http://securityratty.com/tag/human captcha solvers">human captcha solvers</category>
      <category domain="http://securityratty.com/tag/human">human</category>
      <category domain="http://securityratty.com/tag/inside indias captcha">inside indias captcha</category>
      <category domain="http://securityratty.com/tag/captcha based authentication">captcha based authentication</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/378395296/exposing-indias-captcha-solving-economy.html">Exposing Indias CAPTCHA Solving Economy</source>
    </item>
    <item>
      <title><![CDATA[Fake Security Software Domains Serving Exploits]]></title>
      <link>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</link>
      <guid>http://securityratty.com/article/a2ffa8d411dc417bdb5a774ee6ab5207</guid>
      <description><![CDATA[Psychological imagination, &quot;think cybercriminals&quot; mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, I pointed out that

Ironically, the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/V4NpXSLdBEA/s1600-h/fake_software_client_side_exploits.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaDCa0a4yI/AAAAAAAACIU/6N2G2L2h2-0/s200-R/fake_software_client_side_exploits.png" /></a>Psychological imagination, "think cybercriminals" mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">I pointed out that</a> :<br />
<br />
"<i>Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that <a href="http://ddanchev.blogspot.com/2008/02/serving-malware-through-advertising.html">introducing client-side exploits courtesy of a third-party affiliate network</a>, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/WVx1enYkT0E/s1600-h/fake_security_client_side.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SLaJ9G1B_YI/AAAAAAAACIk/XSe4BHhrt2w/s200-R/fake_security_client_side.JPG" /></a>The next day, <a href="http://sunbeltblog.blogspot.com/2008/08/xp-antivirus-2008-now-with-sploits.html">client-side exploits start getting introduced</a> "in between" the fake security software sites :<br />
<br />
"<i>I've blogged before about the problem of Google Adwords pushing Antivirus XP Antivirus 2008. The situation is still ongoing.&nbsp; However, it's taken a turn for the worse, as these XP Antivirus pages are pushing exploits to install malware on the users system. This will also affect the many syndicators of Google Adwords.</i>"<br />
<br />
The domain in question <b>bestantivirus2009.com</b> - (68.180.151.21) is hosting the binary at <b>bestantivirus2009 .com</b>/setup_1096_MTYwM3wzNXww_.exe and has an IFRAME pointing to <b>huytegygle .com</b>/index.php (200.46.83.246).<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/UmA8sFcQCIA/s1600-h/antivirus0003.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLaOX5IUu2I/AAAAAAAACIs/YL8oDzvUAeY/s200-R/antivirus0003.png" /></a>Here's another example <b>antivirus0003.net</b> with an IFRAME pointing to a different location - <b>124.217.250.85 /~ave/etc/count.php?o=16</b>.<br />
<br />
Despite that these domains are part of the "International Virus Research Lab" fake domains portfolio, it remains to be seen whether others will start multitasking as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yRDO0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yRDO0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mEJFVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mEJFVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=74vKNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=74vKNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FMF6wk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FMF6wk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnoShK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnoShK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5q8hIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5q8hIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GNqd3k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GNqd3k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/377056323" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 02:41:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/client-side exploits courtesy">client-side exploits courtesy</category>
      <category domain="http://securityratty.com/tag/client-side exploits start">client-side exploits start</category>
      <category domain="http://securityratty.com/tag/start">start</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/google adwords">google adwords</category>
      <category domain="http://securityratty.com/tag/fake domains portfolio">fake domains portfolio</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/377056323/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</source>
    </item>
    <item>
      <title><![CDATA[Computer Worm Infects International Space Station Laptops]]></title>
      <link>http://securityratty.com/article/3aa31f809eee6f5bc755729eabd5ba31</link>
      <guid>http://securityratty.com/article/3aa31f809eee6f5bc755729eabd5ba31</guid>
      <description><![CDATA[NASA has confirmed that a computer worm that steals passwords managed to finds its way into laptops aboard the International Space Station. It is not the first time a NASA computer has become...]]></description>
      <content:encoded><![CDATA[NASA has confirmed that a computer worm that steals passwords managed to finds its way into laptops aboard the International Space Station. It is not the first time a NASA computer has become infected.
SpaceReg.com identified the infection as W32.TGammima.AG, a worm that spreads by copying itself to removable media devices. Once in place, it steals [...]]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 12:10:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/computer worm">computer worm</category>
      <category domain="http://securityratty.com/tag/removable media devices">removable media devices</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/nasa computer">nasa computer</category>
      <category domain="http://securityratty.com/tag/steals">steals</category>
      <category domain="http://securityratty.com/tag/steals passwords">steals passwords</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <source url="http://cyberinsecure.com/computer-worm-infects-international-space-station-laptops/">Computer Worm Infects International Space Station Laptops</source>
    </item>
    <item>
      <title><![CDATA[Best Western Rebuts Claims of Massive Data Breach]]></title>
      <link>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</link>
      <guid>http://securityratty.com/article/1f08218d0cf9d08a50a56ca3c551ece6</guid>
      <description><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global...]]></description>
      <content:encoded><![CDATA[Best Western International and the Sunday Herald newspaper of Scotland are duking it out over a story which reports that a hacker stole the records of 8 million customers from the hotel chain's global network in the "the greatest cyber-heist in world history." Best Western says 10 people were affected at one hotel.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b4a67e5ea9cc98c6e9393c741fea0fdd" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b4a67e5ea9cc98c6e9393c741fea0fdd" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TLFKNK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TLFKNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rGFaWk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rGFaWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IwFkSk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IwFkSk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AmXXuK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AmXXuK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=Guh3jK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Guh3jK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IFYaBk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IFYaBk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=sOvMck"><img src="http://feeds.wired.com/~f/wired/politics/security?i=sOvMck" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qFUDqK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qFUDqK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/376205367" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/376205368" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/western">western</category>
      <category domain="http://securityratty.com/tag/hotel chain">hotel chain</category>
      <category domain="http://securityratty.com/tag/western international">western international</category>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/sunday herald newspaper">sunday herald newspaper</category>
      <category domain="http://securityratty.com/tag/global network">global network</category>
      <category domain="http://securityratty.com/tag/million customers">million customers</category>
      <category domain="http://securityratty.com/tag/world history">world history</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/376205368/DATA_BREACH_DISPUTE">Best Western Rebuts Claims of Massive Data Breach</source>
    </item>
    <item>
      <title><![CDATA[Virus Infects the Space Station]]></title>
      <link>http://securityratty.com/article/be6e0f1492d31de6c800d92e920c6489</link>
      <guid>http://securityratty.com/article/be6e0f1492d31de6c800d92e920c6489</guid>
      <description><![CDATA[Laptops aboard the International Space Station have been infected with the W32.Gammima.AG worm. And it's not the first time this sort of thing has...]]></description>
      <content:encoded><![CDATA[<p>Laptops aboard the International Space Station <a href="http://www.spaceref.com/news/viewnews.html?id=1305">have</a> <a href="http://blog.wired.com/27bstroke6/2008/08/virus-infects-s.html">been</a> <a href="http://news.bbc.co.uk/2/hi/technology/7583805.stm">infected</a> with the W32.Gammima.AG worm.  And it's not the first time this sort of thing has happened.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=mdla2K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=mdla2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=a00rvK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=a00rvK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:27:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <category domain="http://securityratty.com/tag/sort">sort</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/gammima">gammima</category>
      <category domain="http://securityratty.com/tag/w32">w32</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/virus_infects_t.html">Virus Infects the Space Station</source>
    </item>
    <item>
      <title><![CDATA[Malware infects space station laptops]]></title>
      <link>http://securityratty.com/article/aeff2468dc20c1ddc70d74b79b272123</link>
      <guid>http://securityratty.com/article/aeff2468dc20c1ddc70d74b79b272123</guid>
      <description><![CDATA[Malware has managed to get onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has made it into...]]></description>
      <content:encoded><![CDATA[Malware has managed to get onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has made it into space.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=b2SKbR"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=b2SKbR" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/376461962" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/376461962/article.do">Malware infects space station laptops</source>
    </item>
    <item>
      <title><![CDATA[NASA infected with W32.TGammima.AG ]]></title>
      <link>http://securityratty.com/article/65c9e1c56e2e178d8e0cb128b63a0a9e</link>
      <guid>http://securityratty.com/article/65c9e1c56e2e178d8e0cb128b63a0a9e</guid>
      <description><![CDATA[A computer worm that ferrets out passwords managed to stow away on laptops aboard the International Space Station, NASA has confirmed. It is not the first time a NASA computer has become...]]></description>
      <content:encoded><![CDATA[A computer worm that ferrets out passwords managed to stow away on laptops aboard the International Space Station, NASA has confirmed. It is not the first time a NASA computer has become infected.]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 08:26:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/nasa computer">nasa computer</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <category domain="http://securityratty.com/tag/computer worm">computer worm</category>
      <category domain="http://securityratty.com/tag/stow">stow</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/ferrets">ferrets</category>
      <source url="http://digg.com/security/NASA_infected_with_W32_TGammima_AG">NASA infected with W32.TGammima.AG </source>
    </item>
    <item>
      <title><![CDATA[Doctoring Photographs without Photoshop]]></title>
      <link>http://securityratty.com/article/343f81e5ef64999b63085fa59a40a0d8</link>
      <guid>http://securityratty.com/article/343f81e5ef64999b63085fa59a40a0d8</guid>
      <description><![CDATA[It's all about the captions : ...doctored photographs are the least of our worries. If you want to trick someone with a photograph, there are lots of easy ways to do it. You don't need Photoshop. You...]]></description>
      <content:encoded><![CDATA[<p>It's all about the <a href="http://morris.blogs.nytimes.com/2008/08/11/photography-as-a-weapon/?ref=opinion">captions</a>:</p>

<blockquote>...doctored photographs are the least of our worries. If you want to trick someone with a photograph, there are lots of easy ways to do it. You don't need Photoshop. You don't need sophisticated digital photo-manipulation. You don't need a computer. All you need to do is change the caption.

<p>The photographs presented by Colin Powell at the United Nations in 2003 provide several examples. Photographs that were used to justify a war. And yet, the actual photographs are low-res, muddy aerial surveillance photographs of buildings and vehicles on the ground in Iraq. I'm not an aerial intelligence expert. I could be looking at anything. It is the labels, the captions, and the surrounding text that turn the images from one thing into another. Photographs presented by Colin Powell at the United Nations in 2003.</p>

<p>Powell was arguing that the Iraqis were doing something wrong, knew they were doing something wrong, and were trying to cover their tracks. Later, it was revealed that the captions were wrong. There was no evidence of chemical weapons and no evidence of concealment. Morris's mockery of the sweeping interpretations made in Powell's photographs.</p>

<p>There is a larger point. I don't know what these buildings were really used for. I don't know whether they were used for chemical weapons at one time, and then transformed into something relatively innocuous, in order to hide the reality of what was going on from weapons inspectors. But I do know that the yellow captions influence how we see the pictures. "Chemical Munitions Bunker" is different from "Empty Warehouse" which is different from "International House of Pancakes." The image remains the same but we see it differently.</p>

<p>Change the yellow labels, change the caption and you change the meaning of the photographs. You don't need Photoshop. That's the disturbing part. Captions do the heavy lifting as far as deception is concerned. The pictures merely provide the window-dressing. The unending series of errors engendered by falsely captioned photographs are rarely remarked on.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=agGdKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=agGdKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6dATMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6dATMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 03:27:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/photographs">photographs</category>
      <category domain="http://securityratty.com/tag/actual photographs">actual photographs</category>
      <category domain="http://securityratty.com/tag/captions">captions</category>
      <category domain="http://securityratty.com/tag/yellow captions influence">yellow captions influence</category>
      <category domain="http://securityratty.com/tag/powell">powell</category>
      <category domain="http://securityratty.com/tag/colin powell">colin powell</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/chemical weapons">chemical weapons</category>
      <category domain="http://securityratty.com/tag/photoshop">photoshop</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/doctoring_photo.html">Doctoring Photographs without Photoshop</source>
    </item>
  </channel>
</rss>
